Privacy and Data Protection at Rio Bravo

Learn how Rio Bravo collects, processes and protects your personal data, the principles guiding our privacy practices, the rights of data subjects, the channels available for data protection requests, and how to contact our Data Protection Officer (DPO).

See below the full version of our Privacy Policy and our Cookie Policy

Privacy Policy

Rio Bravo is responsible for maintaining the protection and security of personal data obtained from the data subject (“clients” or “users”), and is committed to safeguarding the privacy, confidentiality and security of such data. Accordingly, this Privacy Policy – Privacy Statement (“Policy”) establishes the guidelines for the implementation and enforcement of the institutional commitment to privacy and personal data protection undertaken by Rio Bravo Investimentos Holding S.A. and its subsidiaries, including Rio Bravo Investimentos DTVM Ltda., hereinafter referred to as (the “Group” or “Rio Bravo”).

This Policy applies to any personal data processed by Rio Bravo and is constituted, established and implemented pursuant to Law No. 13,709, of August 14, 2018 (the “General Data Protection Law” or “LGPD”) and other applicable legislation.

Rio Bravo has always been committed to protecting its clients’ data, using it to provide increasingly better services, in a transparent manner and in accordance with clients’ expectations. In addition, Rio Bravo has an adequate structure in place to meet the requirements of the data protection legislation.

Accordingly, Rio Bravo will continue to process all personal data it handles correctly and keep it secure, and will further adopt practices capable of documenting this diligence and fulfilling the rights guaranteed to the data subject regarding sensitive data or information under the LGPD, based on the principles detailed below:

  • Transparency: lawful, clear, comprehensive and transparent processing of personal data;
  • Purpose and adequacy: personal data collected and processed only for specific, legitimate and disclosed purposes;
  • Necessity: processing limited to the minimum personal data necessary to fulfill each purpose;
  • Data quality: processing of accurate and up-to-date personal data, using means of rectification whenever possible;
  • Non-discrimination: prevention of data processing for discriminatory, unlawful or abusive purposes; and
  • Security and prevention: adoption of technical and organizational measures aimed at preventing unauthorized or unlawful use of data, and preventing its accidental loss, destruction or damage.

Pursuant to Article 5 of the LGPD, the following definitions apply:

  1. personal data: information related to an identified or identifiable natural person;
  2. sensitive personal data: personal data concerning racial or ethnic origin, religious belief, political opinion, membership of a trade union or of a religious, philosophical or political organization, data concerning health or sex life, and genetic or biometric data, when linked to a natural person;
  3. anonymized data: data relating to a data subject that cannot be identified, considering the use of reasonable and available technical means at the time of its processing;
  4. database: a structured set of personal data, stored in one or more locations, in electronic or physical format;
  5. data subject: the natural person to whom the personal data being processed relate;
  6. data controller: a natural or legal person, governed by public or private law, responsible for decisions regarding the processing of personal data;
  7. data processor: a natural or legal person, governed by public or private law, that processes personal data on behalf of the data controller;
  8. data protection officer: a person appointed by the controller and processor to act as a communication channel between the controller, the data subjects and the ANPD (National Data Protection Authority);
  9. processing agents: the data controller and the data processor;
  10. processing: any operation carried out with personal data, such as those relating to collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation or control of information, modification, communication, transfer, disclosure or extraction;
  11. anonymization: the use of reasonable and available technical means at the time of processing, through which data loses the possibility of being directly or indirectly associated with an individual;
  12. consent: a free, informed and unambiguous statement by which the data subject agrees to the processing of their personal data for a specific purpose;
  13. blocking: the temporary suspension of any processing operation, through the retention of the personal data or database;
  14. deletion: the removal of data or a set of data stored in a database, regardless of the procedure used;
  15. international data transfer: the transfer of personal data to a foreign country or international organization of which the country is a member;
  16. shared use of data: the communication, disclosure, international transfer, interconnection of personal data or shared processing of personal databases by public bodies and entities in the performance of their legal duties, or between such bodies and private entities, reciprocally, with specific authorization, for one or more forms of processing permitted by such public entities, or between private entities;
  17. data protection impact assessment report: documentation prepared by the controller containing a description of the personal data processing operations that may generate risks to civil liberties and fundamental rights, as well as measures, safeguards and risk mitigation mechanisms;
  18. research body: a body or entity of the direct or indirect public administration, or a private, non-profit legal entity legally established under Brazilian law, with head office and jurisdiction in the country, whose institutional mission or corporate or statutory purpose includes basic or applied research of a historical, scientific, technological or statistical nature; and
  19. national authority: the public administration body responsible for overseeing, implementing and enforcing compliance with this Law throughout the national territory.

This Policy applies to any personal data collected and processed by the Group in relation to its clients and users, and was created to clearly and objectively set out:

  • The principles and grounds for data processing;
  • The information collected by Rio Bravo, including from other sources;
  • What data is collected;
  • The reasons why data is collected, shared and disclosed;
  • How such data is used;
  • Compliance with the LGPD in connection with the domestic and international transfer of data;
  • How long Rio Bravo retains such data;
  • The rights of the data subjects to whom such personal data relate;
  • The precautions implemented to protect the personal data of our clients and users; and
  • Contact information for the data protection officer responsible for the processing of personal data, as appointed by the controller.

5.1 – Principles for data processing

The Group processes personal data with the aim of offering, or providing information about, products and services of the highest possible quality to its clients. For this reason, the ongoing compliance measures implemented by Rio Bravo are intended not only to meet the requirements of the LGPD, but also to ensure the standards of quality, security and reliability expected by our clients. Accordingly, any and all processing of personal data carried out by Rio Bravo will be based on the definitions set out in item 3, as well as on applicable legislation, and will be conducted in a manner appropriate to the purpose for which the data was collected.

5.2 – Grounds for data processing

Your personal data may be processed for the following purposes:

  • Entering into an agreement between Rio Bravo and the data subject in the context of the use of our products and services;
  • Compliance with the legal, regulatory or self-regulatory obligations to which the company is subject;
  • The regular exercise of rights in legal proceedings;
  • Credit protection;
  • Serving the legitimate interests of Rio Bravo, its partners and third parties;
  • Protection of the life or physical safety of the data subject or of third parties; or
  • Fraud prevention.

All the cases mentioned above refer to situations in which data processing is inseparable from the product and/or service offered. In all cases, the processing of personal data will be subject to the data subject’s consent or to compliance with a legal or regulatory obligation.

5.3 – Information collected

  • Registration data: name, mother’s name, gender, date and place of birth, home address;
  • Contact details: email, telephone number, etc.;
  • Information related to your identity: ID number (RG), individual taxpayer number (CPF), photograph;
  • Marketing research: information and opinions gathered in Rio Bravo surveys;
  • Server information: your IP address, the type of browser software used, metadata, etc.;
  • Other information collected through registration forms or in communications with us by email, telephone calls, etc.;
  • Politically exposed person declaration, where applicable; and
  • Information relevant to the regular exercise of rights in judicial, administrative or arbitration proceedings, pursuant to applicable law.

5.4 – Information collected from other sources

Please note that there are situations in which consent may be waived under the LGPD, including in particular:

  • Information concerning banking data held at other financial institutions;
  • Information obtained to prevent fraud and to combat money laundering and the financing of terrorism and of the proliferation of weapons of mass destruction; and
  • Manifestly public information.

5.5 – Use of data

Rio Bravo will only use personal data on the grounds of a legal or regulatory obligation, the performance of an agreement or preliminary measures thereto, upon obtaining the free and express consent of the data subject, for the purpose of credit protection and/or as a result of the Group’s legitimate interest, in the latter case aligned with the data subject’s expectations. The processing of personal data may, for example, serve the following purposes:

  • Confirming identity and address;
  • Improving the use of and experience on Rio Bravo’s websites;
  • Improving products and services and recording interest in such products and services;
  • Sending marketing communications;
  • Offering products and services that we consider of interest based on the data subject’s profile, with the right to opt out of receiving such information;
  • Responding to your requests for information;
  • Keeping registration data up to date for contact purposes by email, telephone or other means of communication;
  • Cooperating with and/or complying with a court order or a request from an administrative authority;
  • Building a database to carry out statistical studies to develop the Group’s knowledge base;
  • Using such data in the regular exercise of rights in judicial, administrative or arbitration proceedings; and
  • Preventing fraud, money laundering, the financing of terrorism and other precautions involving Compliance and risk analysis.

5.6 – Data sharing

Your personal data will be shared only exceptionally, for the purpose of complying with obligations under applicable laws, rules or regulations, in respect of any investment that constitutes or shows evidence of the offences set out in Law No. 9,613 (known as the “Anti-Money Laundering Law”) and other supplementary regulations, as well as for the performance of agreements entered into with Rio Bravo that depend on data sharing, or where requested by the data subject. Such sharing may take place with the other companies of the Fosun Group (Rio Bravo’s controlling shareholder), partner institutions and information technology suppliers, which must likewise be subject to confidentiality and data protection obligations, pursuant to applicable law and to the provisions of this Policy.

5.7 – International data transfer

Your personal data may be sent to a location outside Brazil, in particular to Shanghai, China, where the Fosun Group’s head office is located. When this occurs, the transfer will take place in accordance with the legal bases established in the LGPD and in international legislation, in the latter case where applicable, which means that we will ensure that the recipients of your information maintain an adequate level of personal data protection.

It should be noted that, where an international data transfer takes place, except in the cases provided for in applicable legislation, the data subject’s consent will be requested.

5.8 – Data storage

Rio Bravo will retain the personal data collected and processed as described in this Policy for as long as the data subject maintains a relationship with the Group and/or for as long as the data subject’s consent remains in effect, where applicable. Once these circumstances end, the data will be retained on the grounds of legal obligations or our legitimate interest, in order to address legal demands and/or audits, and for other reasons, such as combating fraud and responding to requests from regulatory bodies, with anonymization of the data ensured whenever possible.

The data will be retained for a defined period in accordance with applicable legislation, based on criteria of necessity and/or purpose, pursuant to Article 15 of the LGPD.

6.1 – Precautions implemented for data protection

The Group adopts security measures for the processing of all personal data collected, especially sensitive data. These technical and organizational measures have been implemented to prevent unauthorized access and the accidental, intentional or unlawful alteration, loss or destruction of personal data.

Likewise, the personal information of clients and visitors is restricted to those employees or other parties who require the data to carry out and perform their duties.

6.2 – Data subjects and their rights

Rio Bravo will ensure that data subjects may exercise the rights provided for under applicable law, including:

  • Confirmation of the existence of processing of personal data;
  • Access to such data;
  • Correction of incomplete, inaccurate or outdated data;
  • Anonymization, blocking or deletion of unnecessary or excessive data, or data processed in violation of the LGPD;
  • Portability of personal data, upon express request;
  • Deletion of data processed with the data subject’s consent, subject to applicable retention periods;
  • Information on public and private entities with which Rio Bravo has shared the data subject’s data;
  • Information on the possibility of not providing consent and on the consequences of refusal; and
  • Withdrawal of consent, pursuant to the LGPD.

The Group will monitor the mandatory requirements set forth by the LGPD and by the National Data Protection Authority (“ANPD”).

6.3 – Contact information for Rio Bravo’s Data Protection Officer

The person responsible for the processing of personal data, also known as the Data Protection Officer (“DPO”), is responsible for data protection and compliance with this Policy, a role held by Rio Bravo’s COO. For further information and to exercise data subject rights, please contact us at [email protected].

If requested by the ANPD, the DPO may prepare a data protection impact assessment report containing the information requested and/or required under applicable law.

This Policy is subject to periodic updates due to our commitment to continuous improvement in line with the requirements of the LGPD and any applicable rules or regulations; we therefore recommend that it be reviewed periodically.

Although the Group is responsible for the data collected and processed as described herein, the client or user understands and agrees that misuse or improper handling of systems resulting in the loss or alteration of the data subject’s personal data, caused by the data subject, releases the Rio Bravo Group from any liability, particularly in cases of negligent or willful misconduct resulting from acts or omissions of the data subject or of an unauthorized third party acting on their behalf.

It should be noted that the password and electronic signature are valid as a digital signature for logging into the third-party (White Label) platform, and may be blocked at any time upon detection of irregular use, pursuant to applicable regulations and the internal security procedures of the responsible institution.

The Rio Bravo Group is not liable for damages suffered by its clients due to failures in services provided by third parties. This includes, without limitation, cases related to the worldwide web.

Contact the DPO

Channel for clarifying questions, submitting requests and addressing other matters related to privacy and personal data protection. Identifying yourself is optional. To send files, please contact us at [email protected].