PL 1030-01 · Rev. 00 · 21/10/2025 · Public use

Privacy policy

Official 4MDG document — 4MDG Soluções Especialistas LTDA (ZH Soluções Especialistas LTDA), CNPJ 11.955.326/0001-99. Written by Paulo Roberto Viccari de Nobile and approved by Cesar Coelho on 21/10/2025.

1. Purpose

To define principles that guide 4MDG in the processing of personal data, including in the digital environment, ensuring the protection of the fundamental rights to freedom, privacy and the full development of the individual's personality, in accordance with the legislation in force in Brazil.

2. Scope of application

This privacy and personal data protection policy applies to all individuals and legal entities whose personal data is processed by 4MDG, whether acting as data controller or data processor, as defined by the legal guidelines in force.

3. Definitions

Processing agents: the controller and the operator;

Legal bases: the legal grounds that make the processing of personal data legitimate for a given prior purpose;

Consent: free, informed and unequivocal manifestation by which the data subject agrees to the processing of their personal data for a specific purpose;

Controller: a natural or legal person, governed by public or private law, responsible for the decisions regarding the processing of personal data;

Personal data: information related to an identified or identifiable natural person;

Sensitive personal data: personal data concerning racial or ethnic origin, religious belief, political opinion, membership of a trade union or of a religious, philosophical or political organization, data concerning health or sexual life, genetic or biometric data, when linked to a natural person;

Elimination: the deletion of data or of a set of data stored in a database, regardless of the procedure used;

Person in charge of personal data processing: a person appointed by the controller and the operator to act as a communication channel between the controller, the operator, the data subjects and the National Data Protection Authority (ANPD);

Operator: a natural or legal person, governed by public or private law, who carries out the processing of personal data on behalf of the controller;

Data subject: the natural person to whom the personal data being processed refers;

Processing: any operation carried out with personal data, such as those relating to collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, elimination, evaluation or control of the information, modification, communication, transfer, dissemination or extraction.

4.1.1 Processing of personal data as a controller

We act as the Controller in the following activities:

Data processed

Candidate and employee data: name, CPF, address, education, bank details, gender, health data, among others. Collected through tools such as Bizneo, Feedz and the Intranet.

Purpose

Onboarding, payroll, benefits administration, internal communication, performance management and other HR activities.

Responsibility for processing

We act as the Controller, responsible for defining the purposes and the means of processing the personal data of our employees and candidates.

Sharing

Data may be shared with accounting, legal and people management platforms, always for a legitimate purpose and in compliance with the data minimization principle.

Legal basis

Performance of a contract (Art. 7, V of the LGPD); Compliance with a legal or regulatory obligation (Art. 7, II); Consent (where applicable); Regular exercise of rights (Art. 7, VI).

Storage

Data is stored on digital platforms such as AWS, Bizneo and Locaweb, as well as in physical form, organized in individual folders per employee.

Deletion

In accordance with internal retention policies, generally after 5 years from the end of the contractual relationship, unless specific legal obligations require longer periods.

Security measures applied

Access control to systems and folders; authentication and user profiles; secure cloud storage; organizational controls in line with our ISMS, based on ISO 27001.

4.1.2 Processing of personal data as a processor

We act as a Processor when providing SaaS and data governance services to clients through our software. In these cases:

Data processed

Entered by the clients themselves or integrated via third-party systems (e.g., SSO), and may include name, email, phone number, CPF, address and other registration data according to the contracted service.

Purpose

Operation of master data services, centralized registration, cleansing, integration and corporate data management.

Responsibility for processing

The client is the data Controller. We act as the Processor, in accordance with contractual instructions.

Sharing

We do not share data with third parties, except when expressly authorized by the controlling client or required by law.

Legal basis

Processing carried out on the basis of the performance of the contract with the controlling client, under Art. 7, V of the LGPD.

Storage

Data stored in cloud infrastructure (AWS), with security and access control mechanisms, in line with ISO 27001 practices.

Deletion

Data deletion is carried out at the request of the controlling client, according to contractual instructions and agreed deadlines.

Security measures applied

Access segmentation by profile; continuous monitoring of the cloud infrastructure; backup and encryption at rest (where applicable); security controls based on ISO 27001; contractual confidentiality with employees and suppliers.

4.1.3 Processing of data collected via WhatsApp and audio transcription by artificial intelligence

When you contact us via WhatsApp, 4MDG may use artificial intelligence to conduct part of the service, including the conversion of audio messages into text.

Data processed

Phone number, content of the messages exchanged (text and audio) and the audio transcription.

Purpose

To continue the service and respond appropriately to what was said by audio.

Responsibility for processing

4MDG, as controller.

Sharing

Audio messages are sent to a provider specialized in speech-to-text conversion (OpenAI), strictly for that purpose.

Legal basis

Performance of preliminary procedures related to a contract and legitimate interest in providing service.

Storage

The audio itself is not stored by 4MDG; only the text transcription becomes part of the conversation history. The transcription provider may retain the audio and the text for up to 30 days, to monitor abusive use of its platform, without using them to train artificial intelligence models.

Deletion

The transcription follows the same life cycle as the conversation history and is deleted when the data subject requests the deletion of their data.

Security measures applied

Encrypted communication with the transcription provider; no audio file is written to disk by 4MDG at any stage of processing.

4.2 Your rights regarding your collected personal data

Data subjects have the following rights regarding their personal information:

Right to confirmation of processing: the data subject has the right to ask whether their personal data is being processed by 4MDG;

Right of access: the data subject has the right to request and obtain a copy of all personal data collected and stored by 4MDG;

Right to correction: the data subject has the right to request the correction of their personal data if it is incomplete, inaccurate or outdated, ensuring the accuracy of the information stored by 4MDG;

Right to erasure: the data subject has the right to request the removal of their information from the databases maintained by 4MDG, except where there is a legitimate justification for retaining it, such as compliance with legal obligations or the need to preserve it for studies conducted by research bodies;

Right to request the suspension of unlawful processing: the data subject may, at any time, request that 4MDG block or delete their personal data if a competent authority deems it unnecessary, excessive or processed in a manner incompatible with the provisions of the LGPD;

Right to object to data processing: where the processing of personal data is not based on the data subject's consent, they may file a formal objection with 4MDG. The request will be assessed according to the criteria defined by the LGPD;

Right to data portability: the data subject may request that 4MDG transfer their personal data to another service or product provider, subject to commercial and industrial secrecy and the technical limitations of 4MDG's infrastructure;

Right to withdraw consent: the data subject has the right to withdraw their consent at any time. However, such withdrawal will not affect the lawfulness of any processing carried out previously based on the consent given before its withdrawal.

If you wish to exercise any of your rights regarding your personal data, contact us by email at: dpo@4MDG.com.br.

4.3 Data management and deletion

4.3.1. 4MDG is not responsible for the accuracy, authenticity, completeness or currency of the information provided by its users, nor for the improper use of data shared by users or for fraud resulting from compromised passwords. Although we adopt robust information security measures, it is up to you to ensure the protection of your access credentials.

4.3.2. You are fully responsible for providing information that is correct, truthful, authentic, complete and up to date. You must also ensure the confidentiality of your password, avoiding sharing it with third parties. In addition, you are responsible for requesting that the administrator delete your access to the Mobile application and the Web Platform if you leave the USER company or are removed from your duties for any other reason.

4.4 Information security

4.4.1. 4MDG implements appropriate technical and organizational measures to ensure the security of your data. However, it is important that you are aware that no security system can offer absolute protection. Therefore, 4MDG is not liable for any data leaks resulting from criminal actions carried out by third parties unrelated to the established business relationship.

4.4.2. 4MDG reserves the right to monitor the entire Web Platform, mainly to ensure that the guidelines set out in this Privacy Policy are being followed, as well as to verify the absence of violations or abuses of the rules mentioned herein and those that apply by force of law.

4.4.3. 4MDG informs that all digital information related to its products and services is stored and protected through cloud infrastructure platforms.

4.5 Cookies

4.5.1 4MDG may use cookies to make your navigation on the Website easier and to monitor certain statistical data that help improve the user experience. Most browsers are set to accept cookies automatically. However, you can adjust your browser settings to block the use of cookies or delete cookies that already exist. It is worth noting that, by doing so, the quality of your navigation on the 4MDG Website may be affected.

4.5.2 Through the use of cookies, information such as IP address, geographic location, referral source, browser type used, visit duration and pages accessed is collected.

4.5.3 For more information about the use of cookies and how to configure them, please refer to your browser's help guide, where you will find detailed instructions on how to adjust the settings according to your preferences.

4.6 On the officer in charge of personal data processing

4.6.1. 4MDG has a professional responsible for personal data processing, both internally and externally, who can be contacted directly by e-mail.

Primary officer

Paulo Roberto Viccari De Nobile

dpo@4MDG.com.br

Deputy officer

Gustavo Baccan

dpo@4MDG.com.br

The responsibilities of the officer in charge of data processing include, but are not limited to: receiving complaints and communications from data subjects, providing clarifications and taking the necessary measures; receiving and responding to communications from the Brazilian National Data Protection Authority (ANPD), adopting the appropriate actions; guiding employees and third parties contracted by 4MDG on best practices related to the protection of personal data; carrying out other duties delegated by the controller or determined by complementary rules; assessing confirmed or potential incidents involving privacy and personal data protection breaches, taking appropriate measures as needed; guiding those responsible for implementing this policy, ensuring that adequate internal procedures and controls are developed and applied; and holding periodic meetings with internal leadership to ensure that internal processes are consistently aligned with the guidelines established in this policy.

4.7 Governing law and jurisdiction

4.7.1 This Privacy Policy is subject to the laws of the Federative Republic of Brazil, in particular the LGPD (Law No. 13,709/2018) and any amendments thereto, without limitation. Any dispute arising from this instrument shall be submitted to the courts of the city of São Paulo, which shall have jurisdiction to settle any legal matters.

4.8 Term and review

4.8.1 This policy takes effect in accordance with the Brazilian General Data Protection Law (LGPD), observing the official date on which it comes into force. We are committed to reviewing this policy periodically and, whenever necessary, making updates to reinforce our commitment to privacy and the protection of personal data. All changes will be duly communicated in a timely manner.

4.8.2 We reserve the right, at our discretion, to alter, modify, add to or remove parts of this Privacy Policy at any time. Continued use of our Website, Mobile Applications or Web Platform after such modifications are published implies acceptance of the changes. If updates to this policy require new consent, you will be informed through the contact channels provided.

5. References

ABNT. (2022). NBR ISO/IEC 27001:2022. Rio de Janeiro: ABNT.
ABNT. (2019). NBR ISO/IEC 27701:2019. Rio de Janeiro: ABNT.
Law No. 13.709/2018 – Brazilian General Data Protection Law (LGPD).

Reproduction of official document PL 1030-01, Rev. 00, classified for public use, issued on 21/10/2025. In case of divergence, the signed version maintained by 4MDG prevails.