PRIVACY POLICY
Hashdata values the privacy and protection of personal data and operates in compliance with applicable legislation, specifically Law No. 13,709/2018 (Brazilian General Data Protection Law – LGPD). This Privacy Policy describes how personal data is processed in the context of Hashdata’s websites, applications, and services, as well as the rights of data subjects.
This Policy should be interpreted in conjunction with applicable agreements, including the Data Processing Agreement (DPA), reflecting Hashdata’s business model predominantly as a Data Processor in a B2B SaaS environment.
1. Who We Are
Hashdata is a technology company that provides a data collection, analysis, and management platform in a Software as a Service (SaaS) model, accessible via the website www.hashdata.app and related applications.
For data protection legislation purposes:
- Hashdata acts as a Data Processor when processing personal data on behalf of its corporate clients, who act as Data Controllers and define the purposes and means of processing.
- Hashdata acts as a Data Controller only in specific and limited situations, such as in the processing of personal data related to visitors of its institutional websites, business contacts, suppliers, partners, and its own administrative or contractual relationships.
2. Scope of this Policy
This Privacy Policy applies to personal data processed by Hashdata in the following contexts:
- access and browsing of its institutional websites;
- commercial, contractual, and administrative interactions with Hashdata; and
- operation of the Hashdata platform, exclusively in cases where Hashdata acts as a Data Controller.
When Hashdata processes personal data on behalf of its clients, as a Data Processor, the processing will be governed by the agreements signed with the client, including the DPA, with the client Data Controller being responsible for defining the purposes, legal bases, and other aspects of the processing.
3. Personal Data Processed
3.1 Personal data processed as Data Controller
When acting as a Data Controller, Hashdata may process the following categories of personal data:
- identification and contact data, such as name, corporate email, and professional information;
- account, access, and authentication data related to the use of Hashdata’s websites and services;
- technical and browsing data, such as IP address, browser and device type, date and time of access, as well as security records and access logs.
3.2 Personal data processed as Data Processor
Personal data entered, uploaded, or processed on the Hashdata platform by clients or authorized users are processed exclusively on behalf of and under the responsibility of the respective client, who acts as the Data Controller.
Hashdata does not define the content, nature, purposes, or legal bases of this data, limiting itself to processing it according to the Data Controller’s documented instructions and the applicable contractual terms.
4. Purposes of Processing
When acting as a Data Controller, Hashdata processes personal data for the following purposes:
- to allow access and use of its websites and services;
- to manage commercial, contractual, and administrative relationships;
- to ensure security, integrity, monitoring, and fraud prevention; and
- to comply with legal and regulatory obligations.
When acting as a Data Processor, Hashdata processes personal data exclusively for the provision of contracted services, including data storage, organization, processing, and visualization, always in accordance with the Data Controller’s instructions.
Hashdata does not use personal data processed on the platform for its own purposes, such as internal analytics, benchmarking between clients, marketing, advertising, training of artificial intelligence models, monetization, or any use unrelated to the contract and the Data Controller’s instructions.
5. Legal Bases for Processing
The processing of personal data is carried out based on the legal bases provided for in the LGPD, which may include:
- performance of a contract or preliminary procedures related to a contract;
- compliance with a legal or regulatory obligation;
- legitimate interest, when applicable and proportionally assessed; and
- consent, only when required by law.
In the case of data processed on behalf of clients, the definition of the applicable legal basis is the exclusive responsibility of the Data Controller.
6. Data Sharing and Sub-processors
Hashdata does not sell personal data.
Personal data may only be shared:
- with suppliers and technology partners strictly necessary for the provision of services, such as cloud infrastructure providers; and
- when required by law, court order, or competent authority.
All third parties and sub-processors are subject to contractual obligations of confidentiality, information security, and personal data protection.
7. International Data Transfer
Personal data may be transferred and processed in other countries, including the United States, for hosting, processing, backup, and operational contingency purposes.
International transfers are carried out in compliance with the LGPD, through the adoption of adequate safeguards, including contractual clauses, technical and administrative security measures, and governance mechanisms compatible with the risk.
8. Information Security
Hashdata adopts technical and administrative security measures that are reasonable and proportionate to the risks, the nature of the data processed, and the size of the organization, including, among others:
- data encryption in transit and at rest, where applicable;
- access control based on profiles and permissions;
- authentication mechanisms;
- records and monitoring of relevant accesses and operations; and
- use of reliable infrastructure providers and good information security practices.
Although no system is absolutely secure, Hashdata makes continuous efforts to prevent, detect, and mitigate risks.
9. Data Retention and Deletion
Personal data is retained only for the period necessary to fulfill the stated purposes, for the execution of contracts, or for compliance with legal and regulatory obligations.
After the applicable retention period ends, data is securely deleted or anonymized. There may be residual technical retention in backup and contingency systems for a limited period, during which the data remains inaccessible for operational use and protected by security controls.
10. Data Subject Rights
Under the terms of the LGPD, personal data subjects have rights, including confirmation of the existence of processing, access, correction, anonymization, blocking or deletion, data portability (when applicable), and revocation of consent.
When Hashdata acts as a Data Controller, requests may be submitted through the channels indicated in this Policy. When Hashdata acts as a Data Processor, requests should be directed to the respective client Data Controller, who is responsible for responding to data subjects.
11. Security Incidents
In the event of a security incident involving personal data, Hashdata will adopt appropriate containment, mitigation, and response measures.
When acting as a Data Processor, Hashdata will communicate the incident to the Data Controller within a reasonable timeframe, considering the nature, severity, and complexity of the event, in accordance with applicable legislation, including Article 48 of the LGPD. The assessment and eventual communication to the National Data Protection Authority and data subjects will be the responsibility of the Data Controller.
12. Data Protection Officer (DPO) and Contact
For clarifications regarding this Policy or to exercise applicable rights when Hashdata acts as a Data Controller, the data subject may contact us through the following channel:
Email: LGPD@hashdata.app
Company: Hashdata
13. Updates to this Policy
This Privacy Policy may be updated at any time to reflect legal, regulatory, technological, or operational changes. The most recent version will always be available on the Hashdata website, with an indication of the last update date.
