Privacy Policy
AboveMap
Last updated: 01/10/2025
1. PURPOSE
Below we present ABOVEMAP’s Privacy Policy, created to demonstrate our commitment to your personal data. Based on the pillars of Security, Privacy, and Transparency, our goal is to explain, in a clear, simple, and objective way, our practices and the method by which we will process your personal data.
We want you to understand how we collect, store, share, and retain your data. For that reason, reading this policy is important and essential.
2. DEFINITIONS
Data subject:
the natural person to whom the personal data being processed refers, that is, the owner of the personal data.
Processing of personal data:
any operation carried out with personal data, such as collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation or control of information, modification, communication, transfer, dissemination, or extraction.
Personal data:
information related to an identified or identifiable natural person. This data may be classified as:
- Direct Data: data that can be attributed to a specific person without the use of additional information, such as ID or tax number.
- Indirect Data: data that cannot be attributed to a specific person without additional information, such as IP address or car plate.
- Sensitive Data: personal data that, by its nature, is particularly sensitive in relation to fundamental rights and freedoms and therefore deserves specific protection because the context of its processing may create significant risks to those rights and freedoms.
Consent:
the free, informed, and unequivocal expression by which the data subject agrees to the processing of their personal data for a specific purpose.
Controller:
a natural person or private legal entity, public authority, agency, or other body that, individually or jointly with others, determines the purposes and means of processing personal data.
Operator:
a natural person or private legal entity, public authority, agency, or other body that processes personal data on behalf of the Controller.
Data Protection Officer (DPO):
provides guidance on the implementation of appropriate measures and on demonstrating compliance by the Controller or the processing party, acting as a communication channel between the controller, data subjects, and the National Data Protection Authority.
3. GUIDELINES
The practices described in this Privacy Policy apply to the processing of personal data in Brazil and are subject to applicable local laws, especially Law No. 13,709/2018 (General Personal Data Protection Law or LGPD) as of its effective date.
3.1 Data Collection and Use
ABOVEMAP keeps all personal data it collects for as long as necessary to provide the services made available to its customers and for legitimate and essential business purposes.
ABOVEMAP may collect data directly or through other channels such as customer relationship portals, order channels, sales, recruitment processes, social networks, business partners, and cookies.
ABOVEMAP may also obtain personal information about individuals from other publicly or commercially available sources it considers reliable.
3.2 Types of Collected Data
Personal contact information:
Includes any information that allows ABOVEMAP to contact you or verify your registration, such as full name, taxpayer number, date of birth, gender, postal address, email address, and phone number.
Account login information:
Any information required to give you access to your specific account profile, such as username and login details.
Website/communication usage information:
As you browse and interact with ABOVEMAP websites and portals, automatic data collection technologies may be used to collect information about your actions and business relationship data.
Device information:
We may collect information about the device you are using, including the type of device, operating system, unique device identifiers, and network information.
Sensitive personal data:
ABOVEMAP always seeks to process as little Sensitive Personal Data as possible. Whenever it is necessary to process such data, the intended purpose will be informed so that consent can be obtained.
Personal data of minors:
Data from minors is collected only when necessary and with the express consent of parents or legal guardians.
Images and recordings at events:
This information includes photos, videos, and audio from meetings, webinars, and ABOVEMAP’s own events, as well as events jointly sponsored with business partners.
Images and recordings as products and services provided:
This information includes biometrics and video images collected within monitoring tools and used only to fulfill contractual obligations between ABOVEMAP and customers purchasing such services.
Visitor information:
We record individuals who visit our websites and premises, including name, identification, and business contact information, and we use camera monitoring for security and protection of people and belongings, as well as for regulatory purposes.
Customer Service calls:
Communications with Customer Support may be recorded or monitored, in accordance with applicable laws, for local operational needs such as quality assurance or training. Where legally required, you will be informed of such recording at the beginning of the call.
3.3 Purposes for Data Collection
- •Serve ABOVEMAP’s legitimate interest, including those inherent to employment agreements.
- •Respond to bids and requests for proposals that require personal data and employee certifications in order to demonstrate technical knowledge.
- •Prepare contracts, terms, and agreements.
- •Operationalize contracts, authorizations, terms, and agreements.
- •Provide services, products, or information described in executed contracts.
- •Comply with legal obligations.
- •Comply with ancillary obligations linked to contracts signed with Data Subjects.
- •Maintain relationships with the Data Subject.
- •Send messages by email, proprietary apps, or messaging applications.
- •Provide support for data subject requests.
- •Improve services offered to Data Subjects.
- •Set up and manage user accounts in assets, systems, portals, and applications.
- •Apply terms of use for systems, applications, and portals.
- •Provide assistance, support, and training to users of systems, portals, and applications.
- •Prevent and resolve technical or security issues.
- •Offer and suggest access to content, news, training, and workshops promoted by the ABOVEMAP GROUP.
- •Maintain compliance, internal controls, and internal and external audits.
- •Ensure the security of access to ABOVEMAP buildings and physical locations and its property when we collect visitor data.
- •Improve and personalize the user experience when using services.
- •Analyze service usage by system users.
- •Conduct management, statistical, and analytical evaluations, anonymizing data whenever applicable.
- •Conduct satisfaction and market research.
- •Improve the products and services offered.
- •Reach Data Subjects through marketing actions within legally permitted parameters.
- •Protect ABOVEMAP’s rights and property and exercise the right of defense in legislative, normative, or regulatory instances.
- •Prevent, detect, and contribute to the investigation of fraud, legal violations, and matters arising from notices by judicial authorities, police, regulators, and governmental institutions.
- •Provide, whenever requested by the data subject, information about the collection, processing, archiving, handling, and deletion of their data.
- •Provide, maintain, protect, improve, and develop new services.
- •Use information to send communications such as updates, alerts, and newsletters related to our services.
3.4 Data Sharing
Your collected data may be shared with partners, third-party partners, suppliers, auditors, authorities, and regulatory bodies for different purposes whenever necessary. These sharing operations are covered by commercial agreements and contractual clauses on information security and data protection.
Whenever carried out, the sharing of personal data will occur within the limits and purposes of our business and in accordance with applicable law.
3.5 Data Retention Period
Your collected data will be retained for the duration of the contractual relationship and, after its end, within the limits permitted by applicable laws, for as long as necessary to fulfill the purposes set out in this Privacy Policy, protect ABOVEMAP from legal claims, and manage our business.
3.6 Data Storage
The personal data collected and processed is stored on servers and/or on-premises cloud infrastructure, colocation environments, or providers hired to deliver this type of service to ABOVEMAP, in secure environments and in accordance with market best practices.
3.7 International Transfer of Personal Data
Some or all of your personal data may be transferred abroad, for example when stored on cloud computing servers located outside Brazil. For this purpose, ABOVEMAP complies with all requirements established by current legislation and adopts best security and privacy practices.
3.8 Rights of Data Subjects
By using the website and customer service portals, signing contracts, or accessing ABOVEMAP products and services, you consent to this Privacy Notice and may, where applicable, exercise the rights provided by law:
- ✓Confirm the existence of processing.
- ✓Request details about how your information is being used.
- ✓Request correction and updating of data.
- ✓Obtain access to your personal data.
- ✓Request data portability.
- ✓Request blocking and deletion of excessive personal data.
- ✓Request deletion, except where retention is authorized by law.
- ✓Request restriction of the use of certain data.
- ✓Withdraw consent.
- ✓Refuse to receive advertising or content.
3.9 Data Protection
ABOVEMAP, considering the nature of its Information Technology operations and aware of the importance of strengthening management and governance controls to ensure the integrity, protection, and confidentiality of information, maintains an Information Security Policy that defines guidelines to protect your information based on legal, contractual, and business requirements.
In addition to these measures, all employees are trained to adopt methods, procedures, and safeguards to protect the data we collect. We make reasonable efforts to protect Data Subjects’ data, but due to the nature of the internet and the existence of malicious actors, we cannot guarantee that improper access will never occur. If that happens, the procedures established by the General Data Protection Law will be followed, including notification to the National Data Protection Authority and to the Data Subject whenever the security incident may result in risks or damage.
ABOVEMAP also states in its Code of Conduct that, in case of non-compliance with this Privacy Policy, an investigation process will be initiated and, after verification and assessment, the applicable penalties will be imposed according to the severity of the act.
3.10 Cookies and Tracking Technology
Websites and applications used by ABOVEMAP or third-party providers may use cookies to collect information about user activities in applications, websites, or other services, according to their function and purpose.
3.11 Support Channel
If you have questions, complaints, or would like to contact ABOVEMAP regarding how we process your data, you may reach us by email at:
dpo@ABOVEMAP.com.br3.12 Updates to this Privacy Policy
Occasionally, ABOVEMAP may unilaterally change the content of this Privacy Policy as required by purpose, necessity, or legal compliance with laws or regulations of equivalent legal force, and it is the data subject’s responsibility to review it whenever accessing the site.
Therefore, it is essential that every individual make sure to read any communication sent by ABOVEMAP carefully. Such communication occurs through the registered email address, which the data subject declares to be their own and valid for communication purposes.
4. REVISION HISTORY
01/10/2025
Creation of the ABOVEMAP Data Privacy Policy