Legal
Privacy Policy
In accordance with LGPD (Law No. 13,709/2018)
Introduction
Approach Comunicação Integrada LTDA is committed to protecting your fundamental right to Privacy and Personal Data Protection, dedicating its best efforts to provide adequate protection in all activities it performs, in accordance with the General Data Protection Law (Law No. 13,709/2018), with the aim of protecting the rights of freedom and privacy, creating rules to be followed by companies for the collection and processing of Personal Data.
In order to foster and ensure transparency and integrity in the processing of personal data, we have prepared this Privacy Policy in simple, accessible language, making public how your personal data are processed by the agency. We ask that you, as Data Subject, examine this document carefully for a full understanding of the purposes of processing your personal data and of your rights.
1. What is this Privacy Policy and what is it for?
This policy informs all personal data Subjects of the privacy and data protection good practices instituted by Approach Comunicação Integrada Ltda, indicating the options to be adopted in the collection and use of data.
2. Glossary
To keep the message clear, we provide a glossary of expressions and acronyms used in this presentation:
LGPD: Brazil’s General Personal Data Protection Law, namely Law No. 13,709/2018.
Personal data: any data related to a natural person through which it is possible to identify the individual or make them identifiable.
Processing: any operation performed with personal data, such as collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, evaluation, information control, modification, communication, transfer, dissemination or extraction, among others.
Personal data processing agents: the Controller and the Processor of personal data.
Data subject: the natural person to whom the personal data being processed by the Controller and/or Processor relate. In Approach’s case, this may be an employee and their dependents, an individual client, an employee of a corporate client whose data Approach holds, a journalist, an influencer, a service provider, freelancers, and others.
Controller: natural or legal person with decision-making power over how personal data processing is carried out.
Processor (Operador): natural or legal person that processes personal data on behalf of the Controller, without decision-making power over how processing is carried out.
Data Protection Officer (DPO): person who must be appointed by the Controller or Processor to act as a communication channel with data subjects and the National Data Protection Authority (ANPD). The DPO is responsible for coordinating and ensuring the compliance of the Controller or Processor that hired them with the LGPD and other applicable laws.
Sensitive personal data: data relating to racial or ethnic origin, religious conviction, political opinion, membership of a trade union or of a religious, philosophical or political organization, data concerning health or sex life, genetic or biometric data, whenever related to a natural person.
Collection: gathering of personal data, which must have a specific purpose.
National Data Protection Authority (ANPD): public administration body responsible for overseeing, implementing and enforcing the LGPD throughout Brazilian territory.
Commercial partners: in Approach’s context, natural or legal persons with whom it maintains a commercial relationship.
Press kit: set of publicity materials distributed by press offices to influential people in the media to promote a given brand and/or product/service.
Mailing marketing: email marketing or advertising by electronic mail is the use of email as a marketing tool, operated by third-party service providers.
Landing page: a website page containing a form used for lead generation. This page revolves around an offer, such as an e-book or a webinar, and captures visitor information in exchange for content of interest to the reader.
Leads: a person or company that has shown interest in one of your products. They may have filled in a form, subscribed to a blog or shared contact information in exchange for specific content.
3. Who is it for?
This Privacy Policy applies to the processing of personal data of our employees, collaborators, suppliers, service providers, job candidates, clients and potential clients, as well as their users/consumers and visitors to our website and social networks, influencers and journalists.
4. How and which personal data do we collect from you?
Approach may collect personal data and information:
I. Through direct contact with Data Subjects. Approach will receive from you, the Subject, personal data and information necessary to carry out a given activity. Examples include job candidates who provide name, phone, email, CPF etc. in their résumé; or an influencer hired by an Approach client who provides bank details to formalize a contract.
II. Directly from clients. In this case, processing is carried out according to the client’s instructions, so Approach acts as Processor and the client as Controller. An example is the client sending Approach an email list to send internal mailing to that client’s employees. Clients are responsible for obtaining users’ consent directly and instructing Approach on how data processing should be carried out.
III. Through service providers, partners or publicly available sources. If we do not obtain your personal information directly from you, we may seek it through other means: publicly available data (for example in public records or on the internet), social media, as well as through service providers (third-party public data providers and software). However, Approach does not control the origin of data and information collected and shared by service providers. In those cases, it is the service providers who use, disclose and protect personal data according to their respective Privacy Policies. They are also responsible for obtaining users’ consent directly and then collecting, managing and processing the data. Nevertheless, once those data are processed by Approach, the company adopts all technical and organizational measures to protect them against unauthorized access.
IV. Via interaction on social networks. In those cases, you yourself transmit your data to us, for example to forward complaints to our clients’ customer service. Our practice is to transmit data received via social-network interaction directly to the respective clients, removing them from Approach’s database. Any question or request regarding your data should therefore be obtained directly from the social-network holder to whom they were sent.
V. Through lead capture via landing page. The landing page directs users/consumers to fill in forms, registrations and similar actions; “lead” refers to a person or company that has shown interest in a given subject. You may revoke, at any time, the consent given for the collection of your personal data so that we no longer send marketing communications and emails, easily done through the unsubscribe option in the email footer.
5. Do we collect data of children and adolescents?
Approach declares that, in relation to Children and Adolescents (that is, persons under 16 years of age), it limits itself to collecting personal data:
I. Of employees’ dependents for family-allowance payment and, if applicable, alimony deduction pursuant to a court order, always obtaining the specific consent of the respective legal representative;
II. Of child digital influencers or children of adult influencers, for contracting or sending press kits, always obtaining the specific consent of the legal representative.
6. And sensitive data?
Approach restricts itself to collecting the sensitive data below in the following cases:
I. Photos of journalists and influencers for accreditation at large events;
II. Photos of our clients’ employees, for reports and internal corporate campaigns;
III. Information such as sex life and/or sexual orientation, comorbidities, political opinion and belief of influencers/journalists, when considered data made manifestly public;
IV. Union membership, when informed by an Approach employee for deduction of union dues;
V. Media training, it being understood that images obtained are deleted as soon as the purpose is fulfilled (delivery of videos and feedback to clients).
In all these cases, we obtain the data subjects’ prior consent and take all technical and organizational measures to protect sensitive data against unauthorized access.
7. For what purposes and on what legal bases do we use the personal data collected?
We take care to use the personal data we collect and process only for the specific purpose for which they were collected. For example:
Identification of the client, supplier and/or legal representative (registration): we collect data strictly necessary to provide services, whether to formalize a contract, payment and/or issue an invoice, such as name, marital status, address, CPF, RG, email, phone/mobile and bank information.
Legal basis
Performance of a contract
Identification of an Approach employee: we collect data strictly necessary to formalize an employment contract and also to provide meal and transport vouchers, when applicable, in addition to those relevant to family allowance and union-dues deduction, such as name, phone, address, CPF, RG, work card, NIT, information about dependents and union membership.
Legal basis
Consent of the Subject and/or compliance with a legal or regulatory obligation, mainly in labor law, as well as performance of a contract with the Subject.
Identification of candidates for Approach vacancies: we collect data provided by the Subject in their résumé, such as name, date of birth, phone, address, email, education and professional experience.
Legal basis
Legitimate interest
Identification of visitors to the Approach website: we collect data such as name, email, phone, company and role, in order to offer our products and services to you, as well as connection and service-use details such as IP address and cookies for technical improvement.
Legal basis
Consent of the Subject and/or legitimate interest
Mapping of influencers and journalists: we collect data and information directly from Subjects, as well as data and information made manifestly public and/or provided by specialized service providers, for recruitment according to the profile desired by the client and mailing. In this case, the data we collect include email and/or phone, birthday, clothing size, shoe size, preferences, professional history.
Legal basis
Legitimate interest
Identification of influencers and/or journalists: we collect, directly from the influencer, the data needed to formalize contractual instruments and for day-to-day business dealings, such as name, RG, CPF, address, phone, email and bank information.
Legal basis
Performance of a contract
Execution and management of our business operations and/or as part of the services we provide to our clients and their employees/contractors, as well as to users/consumers: we may collect data when we operate the client’s customer service, for marketing mailing, sending press kits, depending on the category of Subject involved. Example: Approach commonly sends press kits to digital influencers, either on behalf of a specific client or in Approach’s own name.
Legal basis
Consent of the Subject
Social listening: we identify and analyze what is being said about our clients on social media (only publicly accessible content) in order to capture sentiment, intent, disposition and market trends, as well as to identify stakeholder needs and thereby improve our services. We do this through keyword searches (“buzzWords”); our goal is to capture insights on trends over a specific period and not to identify an individual. To succeed in this strategy, we analyze and monitor conversation flows and follow publicly available opinions, statements and other interactions on social-media channels.
Legal basis
Legitimate interest
Preparation of media briefing: we condense relevant information about a given journalist and the media outlet where they work, in order to promote relationship actions with our clients.
Legal basis
Legitimate interest and performance of a contract
Event accreditation: we collect data provided directly by journalists and influencers for accreditation at events we organize on behalf of our clients, such as name, CPF, RG, email, phone/mobile, media outlet, role and photo.
Legal basis
Consent of the Subject
8. With whom do we share your personal data?
Approach declares, for all purposes, that it may share personal data in the following cases:
1. With its clients and employees, to enable the performance of marketing services and only when their access to the collected personal data is necessary;
2. With logistics service providers to enable delivery of press kits;
3. With the accounting firm responsible for certain tax, labor and regulatory obligations;
4. With companies specialized in recruiting new employees and collaborators;
5. With payment intermediaries essential to operating credit and/or debit card payments;
6. With third-party service providers specialized in data storage, marketing mailing and landing-page operations;
7. To protect the company’s interests in any type of dispute, including legal actions;
8. In the event of transactions and corporate changes involving Approach, in which case the transfer of information will be necessary for continuity of services;
9. Pursuant to a court order, law or determination of administrative authorities with legal competence for the request.
Whenever there is sharing, Approach adopts all adequate measures to protect your personal data, to ensure that third parties acting on its behalf (Processors) treat them within the terms of contractual instructions and in observance of the LGPD and the company’s Personal Data Governance Policy.
9. Do we include links to third-party sites and programs?
Our site may include: links from/to sites of our partner networks, advertisers and affiliates; certain third-party programs (widgets and apps). When that is the case, it is important that you be aware that such third parties may process personal data collected through those programs for their own purposes, independently of any interference or determination by Approach.
We have no responsibility and cannot be held liable for third-party sites and programs to which you provide your personal data. Please check third parties’ terms of use and privacy before using or providing information on their sites or apps.
10. How do we use the personal data we collect on our sites?
We use Personal Data for the purposes described in the chapter on purposes and legal bases above, as well as to provide information you request, such as: for surveys and research questionnaires; to personalize your experience on our site; to contact you for marketing purposes, if you have given your consent to that end.
See the item on Cookies below for more information.
11. What security measures do we adopt to protect your personal data?
For greater security of your data, we adopt technical measures in line with reasonable market practices, such as MFA (Multi-Factor Authentication), which provides password-verification confirmation.
In addition, Approach stores information collected and/or shared with it on its own servers, protected against unauthorized access, and only previously authorized persons are allowed to access it.
Regarding protection of personal data in printed format, Approach implemented a “clean desk” policy, and once processing purposes are fulfilled, physical documents are shredded and discarded appropriately.
12. How long do we store your personal data?
We store your personal data until: 1. you decide to delete them or so request; 2. your personal data cease to be useful for the purposes for which they were collected; 3. the legal retention period stipulated in applicable law expires; 4. by court order or order of a competent body.
In some cases, even after processing of personal data ends, Approach may keep some data for certain purposes, such as compliance with a legal or regulatory obligation. For example, tax legislation requires invoices to be kept for 5 (five) years.
13. What are your rights as a personal data subject?
As a personal data Subject, you have the right to:
1. Know whether Approach processes your personal data and, if so, have access to all data that are processed;
2. Request and receive a copy of all personal data processed by Approach;
3. Have your data corrected if they are incomplete, inaccurate or outdated;
4. Request deletion of your personal data held in Approach’s databases, with a reservation as to this right when there is a legitimate reason to keep data, such as a legal obligation;
5. Have your data anonymized, block processing or request elimination of your data if they are unnecessary, excessive or processed in non-compliance with the LGPD;
6. Object to Approach regarding processing of personal data not based on consent, which will be assessed under the criteria set out in the LGPD;
7. Request portability of your personal data, that is, request that your data be sent to other institutions, respecting Approach’s commercial and industrial secrets as well as the technical limits of its infrastructure to implement portability;
8. Not consent to processing of your data and be informed of the consequences of refusal;
9. Withdraw consent previously given, it being understood that such withdrawal will not affect the lawfulness of processing carried out before withdrawal;
10. Be informed about which data were shared with which third parties and how.
14. How do we use cookies?
Cookies are a kind of browsing history stored on your computer and accessed every time you enter the Approach website. These small text files help the site bring a better experience to you and other visitors.
Approach uses technical-improvement cookies on its site to provide better navigability. You may, at any time, block the use of cookies by configuring your internet browser.
15. How to follow possible changes to our Privacy Policy?
Approach may modify this Privacy Policy at any time, aiming at its improvement and full commitment to legislation on Privacy and Personal Data Protection. In the event of any change, the new version will be published on the site: https://www.approach.com.br
16. How can you contact Approach if you have questions?
The DPO appointed by Approach has the following duties: 1. Monitor compliance with personal-data protection legislation; 2. Ensure the integrity and effectiveness of this Privacy Policy; 3. Conduct periodic training with Approach employees; 4. Receive and respond to Subjects’ requests; 5. Maintain direct communication with the ANPD in order to provide clarifications, submit reports (if required) and communicate security incidents.
Therefore, if you have any question about how to consult your data and exercise your rights as Subject, contact us at: dpo@approach.com.br
If you have questions, comments or suggestions related to this Privacy Policy or Approach’s practices regarding personal-data processing, you may write to: dpo@approach.com.br
For us to serve you quickly and effectively, your request should contain at least: 1. Full name; 2. Email; 3. Description of the question or reasons for the request.
17. Useful information
Emails sent with our newsletter have an unsubscribe button, made clearly available to all users, which guarantees the privacy and ethics of our activities. Feel free to unsubscribe at any time.