Information about the Data Controller and the Data Protection Officer (DPO)
HOLDING SIX SOCIEDADE ANÔNIMA, a private legal entity, registered under CNPJ no. 32.803.097/0001-67, with registered office at Alameda Xingu, 350, 14th floor, Alphaville, Barueri/SP, herein represented in accordance with its Bylaws ("HOLDING SIX"), undertakes to protect the personal data processed in the context of its activities.
This Privacy Policy ("Policy") explains how we process personal data when you interact with our website ("Site"), any platform/relationship area ("Platform") and/or in the context of the provision of services, business, institutional and compliance relationships.
Contact details of the controller: official channels provided on the Site/Platform.
Contact details of the DPO (Officer): luana.rogerio@eqr.com.br
.
HOLDING SIX Platform / Site Services
The HOLDING SIX Site/Platform may be used for: (i) providing institutional information; (ii) relationship management with interested parties, partners and customers; (iii) receiving requests and communications; (iv) supporting registration, analysis and formalization processes for operations/contracts, when applicable.
Important (roles under the LGPD): depending on the context, HOLDING SIX may process data as Controller (when it defines purposes and means) and/or as Processor (when it processes data on behalf of third parties, according to contractual instructions).
Examples:
If you are a user linked to a Customer/third-party Controller, certain requests (e.g., access to data in the Customer's system) may depend on the Controller itself, and HOLDING SIX may act in accordance with contractual instructions and limits.
If there is a specific communication channel made available to third parties, the processing may occur on behalf of the respective Controller, as applicable.
Categories of data that may be entered/generated on the Site/Platform:
direct identification (name, email, phone number);
indirect identification (job title, company, user identifier);
contractual/registration information (when necessary);
device and traffic data (IP, logs, access records);
any data voluntarily provided in forms, uploads and communications.
Types of processing operations: collection, recording, organization, storage, controlled access, retention, sharing with essential suppliers and, at the end, deletion/anonymization, according to the purpose and applicable obligations.
What personal data do we process?
Not all of the data below applies to all data subjects. In general, we process:
3.1. Data from leads and/or Site users
Identification and professional data: name, corporate email, phone number, job title, company/organization, country/city.
Browsing/metadata data: IP, logs and behavioral data on the Site, when permitted/consented to.
Preferences and needs: stated interests (e.g., requested materials) and basic inferences from interaction with content.
We collect this data through forms (contact, meeting/demo request, events), and eventually through legitimate sources (e.g., professional networks), always seeking to ensure compliance.
3.2. Data from customers, partners and representatives
corporate name, email and phone number, job title, company, communication and support data;
data necessary for contractual performance, billing/financial matters (when applicable) and compliance due diligence.
3.3. Data about minors
The Site/Platform is intended for adults. If we identify data from minors that was collected improperly, we may block/delete it and adopt reasonable measures to mitigate risks.
What are the purposes and legal bases for which we process the data? (the essentials of the original have been retained)
For clarity, we divide the purposes by data subject groups and legal basis, pursuant to the LGPD:
4.1. Leads and/or Site users
a) Based on consent (art. 7, I, LGPD)
The data subject may withdraw consent at any time.
Contact for commercial purposes and send institutional/commercial communications through different channels, when authorized.
Data processed: name, email, phone number, job title, company/organization, sector, country/city.
Manage participation in events, meetings, presentations, courses and/or webinars and communicate updates.
Data processed: name, email, phone number, job title, company/organization.
Share data with partners in joint actions, when there is specific consent for this.
Data processed: name, email, phone number, job title, company/organization.
Provide requested resources/materials (content, presentations, documents).
Data processed: name, email, company/organization.
Analyze behavior on the Site via cookies/devices (analytics/marketing), when applicable and according to preferences/consent.
Data processed: IP, identifiers, browsing data, interactions with pages/content.
Record meetings/videoconferences to improve the process experience, when informed and applicable.
Data processed: image/voice and meeting data.
b) Performance of contract and pre-contractual measures (art. 7, V, LGPD)
Finalizing proposals and agreements: prepare and send an economic proposal and conduct negotiations.
Data processed: job title, company/organization, indicated needs, contact data.
Manage access/account/restricted environment requests, when applicable (e.g., onboarding, credentials, settings).
Data processed: name, email, phone number, job title, company/organization.
c) Legitimate interest (art. 7, IX read in conjunction with art. 10, LGPD)
Institutional marketing and personalized communications based on a basic business profile, respecting rights and the option to object.
Data processed: job title, company/organization, sector, interactions with content, stated preferences.
Basic segmentation/scoring (lead scoring) to organize contacts and prioritize service, with the possibility of objection.
Data processed: job title, sector, size (by ranges), country/city, contact origin and interactions with content.
Contact to schedule a meeting/demo and conduct negotiation, when interest has been demonstrated.
Data processed: name, email/phone number, job title, company/organization and interaction records.
The data subject may object to processing based on legitimate interest, where applicable, via the DPO: luana.rogerio@eqr.com.br
.
4.2. Customers, partners and representatives
a) Consent (art. 7, I, LGPD)
participation in events/webinars and specific communications when authorized;
cookies/measurement, when applicable.
b) Performance of contract (art. 7, V, LGPD)
manage the contractual relationship, support, operational communications, billing/collection, feature activation, offboarding.
Data processed: corporate contact data, communications, data necessary for the contract and support.
c) Legal/regulatory obligation (art. 7, II, LGPD)
compliance with applicable legal duties, including fraud prevention measures and compliance due diligence, when applicable.
d) Legitimate interest (art. 7, IX read in conjunction with art. 10, LGPD)
service quality control, satisfaction surveys, service improvement, metrics and statistics (preferably in aggregated/anonymized form when possible).
Do we share personal data? Is there international transfer?
As a general rule, HOLDING SIX does not share data beyond what is necessary. We may share data with:
technology/hosting/support/security providers and operational tools (e.g., CRM, communications), only for the performance of services;
event/joint-action partners only when there is specific consent or an applicable legal basis;
public authorities/competent bodies, when required by law, court order or valid request;
advisors and auditors, when necessary for contractual performance, compliance and defense of rights.
International transfer: if it occurs through the use of technology providers, it will be carried out in accordance with arts. 33 to 36 of the LGPD, with adequate safeguards.
(References to the EU/EEA/Frankfurt and foreign regimes have been removed.)
Profiling and automated decisions
We may carry out basic commercial profiling and segmentation to improve communications and relationships, within the limits of art. 7, IX read in conjunction with art. 10 of the LGPD and/or consent, when applicable.
As a rule, we do not adopt exclusively automated decisions with significant legal effects without transparency and the possibility of human review when applicable.
Retention periods and criteria
We retain data for as long as necessary to: (i) fulfill purposes; (ii) comply with legal/regulatory obligations; (iii) safeguard rights and comply with limitation periods; (iv) prevent fraud and maintain security.
When they are no longer needed, the data will be deleted or anonymized, except in cases of retention/blocking due to legal obligation or the regular exercise of rights.
Data subject rights and how to exercise them
Pursuant to art. 18 of the LGPD, the data subject may request confirmation of processing, access, correction, anonymization, blocking, deletion, portability (when applicable), information about sharing, revocation of consent and objection (when applicable).
DPO channel: contato@eqr.com.br
.
We may request identity validation to prevent fraud.
Security measures
We adopt technical and organizational measures to protect personal data against unauthorized access and accidental or unlawful situations (art. 46, LGPD), including access controls, governance and incident response.
Changes to this Policy
This Policy may be updated periodically. The current version will be the one published on the Site/Platform.PRIVACY POLICY – HOLDING SIX SOCIEDADE ANÔNIMA
Information about the Data Controller and the Data Protection Officer (DPO)
HOLDING SIX SOCIEDADE ANÔNIMA, a private legal entity, registered under CNPJ no. 32.803.097/0001-67, with registered office at Alameda Xingu, 350, 14th floor, Alphaville, Barueri/SP, herein represented in accordance with its Bylaws ("HOLDING SIX"), undertakes to protect the personal data processed in the context of its activities.
This Privacy Policy ("Policy") explains how we process personal data when you interact with our website ("Site"), any platform/relationship area ("Platform") and/or in the context of the provision of services, business, institutional and compliance relationships.
Contact details of the controller: official channels provided on the Site/Platform.
Contact details of the DPO (Officer): contato@eqr.com.br
.
HOLDING SIX Platform / Site Services
The HOLDING SIX Site/Platform may be used for: (i) providing institutional information; (ii) relationship management with interested parties, partners and customers; (iii) receiving requests and communications; (iv) supporting registration, analysis and formalization processes for operations/contracts, when applicable.
Important (roles under the LGPD): depending on the context, HOLDING SIX may process data as Controller (when it defines purposes and means) and/or as Processor (when it processes data on behalf of third parties, according to contractual instructions).
Examples:
If you are a user linked to a Customer/third-party Controller, certain requests (e.g., access to data in the Customer's system) may depend on the Controller itself, and HOLDING SIX may act in accordance with contractual instructions and limits.
If there is a specific communication channel made available to third parties, the processing may occur on behalf of the respective Controller, as applicable.
Categories of data that may be entered/generated on the Site/Platform:
direct identification (name, email, phone number);
indirect identification (job title, company, user identifier);
contractual/registration information (when necessary);
device and traffic data (IP, logs, access records);
any data voluntarily provided in forms, uploads and communications.
Types of processing operations: collection, recording, organization, storage, controlled access, retention, sharing with essential suppliers and, at the end, deletion/anonymization, according to the purpose and applicable obligations.
What personal data do we process?
Not all of the data below applies to all data subjects. In general, we process:
3.1. Data from leads and/or Site users
Identification and professional data: name, corporate email, phone number, job title, company/organization, country/city.
Browsing/metadata data: IP, logs and behavioral data on the Site, when permitted/consented to.
Preferences and needs: stated interests (e.g., requested materials) and basic inferences from interaction with content.
We collect this data through forms (contact, meeting/demo request, events), and eventually through legitimate sources (e.g., professional networks), always seeking to ensure compliance.
3.2. Data from customers, partners and representatives
corporate name, email and phone number, job title, company, communication and support data;
data necessary for contractual performance, billing/financial matters (when applicable) and compliance due diligence.
3.3. Data about minors
The Site/Platform is intended for adults. If we identify data from minors that was collected improperly, we may block/delete it and adopt reasonable measures to mitigate risks.
What are the purposes and legal bases for which we process the data? (the essentials of the original have been retained)
For clarity, we divide the purposes by data subject groups and legal basis, pursuant to the LGPD:
4.1. Leads and/or Site users
a) Based on consent (art. 7, I, LGPD)
The data subject may withdraw consent at any time.
Contact for commercial purposes and send institutional/commercial communications through different channels, when authorized.
Data processed: name, email, phone number, job title, company/organization, sector, country/city.
Manage participation in events, meetings, presentations, courses and/or webinars and communicate updates.
Data processed: name, email, phone number, job title, company/organization.
Share data with partners in joint actions, when there is specific consent for this.
Data processed: name, email, phone number, job title, company/organization.
Provide requested resources/materials (content, presentations, documents).
Data processed: name, email, company/organization.
Analyze behavior on the Site via cookies/devices (analytics/marketing), when applicable and according to preferences/consent.
Data processed: IP, identifiers, browsing data, interactions with pages/content.
Record meetings/videoconferences to improve the process experience, when informed and applicable.
Data processed: image/voice and meeting data.
b) Performance of contract and pre-contractual measures (art. 7, V, LGPD)
Finalizing proposals and agreements: prepare and send an economic proposal and conduct negotiations.
Data processed: job title, company/organization, indicated needs, contact data.
Manage access/account/restricted environment requests, when applicable (e.g., onboarding, credentials, settings).
Data processed: name, email, phone number, job title, company/organization.
c) Legitimate interest (art. 7, IX read in conjunction with art. 10, LGPD)
Institutional marketing and personalized communications based on a basic business profile, respecting rights and the option to object.
Data processed: job title, company/organization, sector, interactions with content, stated preferences.
Basic segmentation/scoring (lead scoring) to organize contacts and prioritize service, with the possibility of objection.
Data processed: job title, sector, size (by ranges), country/city, contact origin and interactions with content.
Contact to schedule a meeting/demo and conduct negotiation, when interest has been demonstrated.
Data processed: name, email/phone number, job title, company/organization and interaction records.
The data subject may object to processing based on legitimate interest, where applicable, via the DPO: luana.rogerio@eqr.com.br
.
4.2. Customers, partners and representatives
a) Consent (art. 7, I, LGPD)
participation in events/webinars and specific communications when authorized;
cookies/measurement, when applicable.
b) Performance of contract (art. 7, V, LGPD)
manage the contractual relationship, support, operational communications, billing/collection, feature activation, offboarding.
Data processed: corporate contact data, communications, data necessary for the contract and support.
c) Legal/regulatory obligation (art. 7, II, LGPD)
compliance with applicable legal duties, including fraud prevention measures and compliance due diligence, when applicable.
d) Legitimate interest (art. 7, IX read in conjunction with art. 10, LGPD)
service quality control, satisfaction surveys, service improvement, metrics and statistics (preferably in aggregated/anonymized form when possible).
Do we share personal data? Is there international transfer?
As a general rule, HOLDING SIX does not share data beyond what is necessary. We may share data with:
technology/hosting/support/security providers and operational tools (e.g., CRM, communications), only for the performance of services;
event/joint-action partners only when there is specific consent or an applicable legal basis;
public authorities/competent bodies, when required by law, court order or valid request;
advisors and auditors, when necessary for contractual performance, compliance and defense of rights.
International transfer: if it occurs through the use of technology providers, it will be carried out in accordance with arts. 33 to 36 of the LGPD, with adequate safeguards.
(References to the EU/EEA/Frankfurt and foreign regimes have been removed.)
Profiling and automated decisions
We may carry out basic commercial profiling and segmentation to improve communications and relationships, within the limits of art. 7, IX read in conjunction with art. 10 of the LGPD and/or consent, when applicable.
As a rule, we do not adopt exclusively automated decisions with significant legal effects without transparency and the possibility of human review when applicable.
Retention periods and criteria
We retain data for as long as necessary to: (i) fulfill purposes; (ii) comply with legal/regulatory obligations; (iii) safeguard rights and comply with limitation periods; (iv) prevent fraud and maintain security.
When they are no longer needed, the data will be deleted or anonymized, except in cases of retention/blocking due to legal obligation or the regular exercise of rights.
Data subject rights and how to exercise them
Pursuant to art. 18 of the LGPD, the data subject may request confirmation of processing, access, correction, anonymization, blocking, deletion, portability (when applicable), information about sharing, revocation of consent and objection (when applicable).
DPO channel: luana.rogerio@eqr.com.br
.
We may request identity validation to prevent fraud.
Security measures
We adopt technical and organizational measures to protect personal data against unauthorized access and accidental or unlawful situations (art. 46, LGPD), including access controls, governance and incident response.
Changes to this Policy
This Policy may be updated periodically. The current version will be the one published on the Site/Platform.
