Data Protection Policy (LGPD / GDPR)

Purpose

To ensure the protection, privacy, and proper processing of personal data handled by Amiggo, in compliance with the Brazilian General Data Protection Law (LGPD), the General Data Protection Regulation (GDPR), and all other applicable legislation.

Scope

This policy applies to employees, partners, service providers, suppliers, contractors, and third parties who process personal data on behalf of Amiggo.

Guidelines

  • Process personal data only for legitimate purposes.
  • Ensure transparency in data processing activities.
  • Protect personal data against unauthorized access.
  • Respect the rights of data subjects.
  • Share personal data only when supported by a lawful legal basis.
  • Report data protection incidents immediately.

Roles and Responsibilities

  • Employees: Handle personal data responsibly.
  • IT / Information Security: Implement appropriate security controls.
  • Legal Department / Data Protection Officer (DPO): Ensure regulatory compliance.
  • Management: Provide the necessary resources and approve policy guidelines.

Code of Ethics and Conduct

Purpose

To establish the ethical principles and standards of conduct for everyone representing Amiggo.

Scope

This Code applies to employees, executives, partners, consultants, suppliers, business partners, and third parties.

Guidelines

  • Act with integrity and transparency.
  • Comply with applicable laws and internal policies.
  • Reject all forms of discrimination, harassment, fraud, and corruption.
  • Avoid conflicts of interest.
  • Protect confidential information.

Roles and Responsibilities

  • Employees: Comply with this Code.
  • Managers and Leaders: Lead by example.
  • Legal / Compliance: Provide guidance and investigate potential violations.
  • Management: Approve the Code and ensure its implementation.

Information Security Policy

Purpose

To ensure the confidentiality, integrity, and availability of the information processed by Amiggo.

Scope

This policy applies to everyone who uses or has access to the company’s information assets.

Guidelines

  • Use company resources only for authorized purposes.
  • Maintain the confidentiality of information.
  • Protect passwords and devices.
  • Follow established security procedures.
  • Do not share access credentials without proper authorization.
  • Report security incidents immediately.

Roles and Responsibilities

  • Users: Follow information security best practices.
  • IT Department: Implement appropriate security controls.
  • Legal / Compliance: Support regulatory compliance.
  • Management: Ensure governance and provide the necessary resources.

Validity

This policy shall be reviewed annually or whenever significant changes occur.

Publication Date: July 29, 2026
Last Updated: July 29, 2026

Enterprise Solutions • Seamless Integration • Ongoing Support

Your next project starts with a conversation.

Intelligent solutions for capturing, viewing, processing, and automating documents.

🇧🇷 🇨🇴

Partners

Apryse

Other links