DB1 Global Software

Privacy Policy

Version 8.0 · 19 August 2026

Introduction

We at DB1 Group and/or our affiliates, subsidiaries and associated companies understand and respect your privacy, and we undertake to adopt consistent measures and appropriate safeguards to protect the personal data processed on our websites, applications and other digital channels.

DB1 Group maintains an Information Security and Privacy Management System (ISPMS), with practices based on the international standards ISO/IEC 27001:2022 and ISO/IEC 27701:2019, which ensures technical and organizational controls to protect personal data against unauthorized access, loss, alteration or improper disclosure.

This Policy aims to inform you, clearly and accessibly, how we collect, use, store, share and protect your personal data, in compliance with the General Personal Data Protection Law (Law No. 13,709/2018), the Brazilian Civil Rights Framework for the Internet (Law No. 12,965/2014) and its regulating decree (Decree No. 8,771/2016), the Resolutions of the National Data Protection Authority (ANPD) applicable to the matter, and other related sector rules.

1. Definition of personal information

Under the applicable Personal Data Protection legislation, in the countries where DB1 Group provides its services and for the purposes of this Privacy Policy or Personal Data Processing, we shall consider the information provided by the user to be personal in nature, provided that it, alone or together with other data supplied or generated, causes a natural person to be identified or identifiable (the Data Subject). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social characteristics of that natural person.

2. Categories of personal data we collect

As permitted by applicable law, the personal data we collect directly from you may span various categories and types, always observing the principles of purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, and accountability and rendering of accounts. We may have access to:

  • (i) your contact information, such as, but not limited to, that used to communicate with you, such as name, job title, company name, email address, telephone or postal address;
  • (ii) account information, such as username, user ID, data on your registration or attendance at training sessions, webinars, or other events;
  • (iii) professional or employment-related information, such as résumé, cover letter, work history;
  • (iv) automatically captured information, such as IP address, location, date and time, browsing history, geolocation, referral source, browser type, visit duration and pages visited;
  • (v) inferences, meaning information drawn from the personal data collected in the previous item, such as the topics you may be interested in based on the areas of the site you visit, or which products you may be interested in based on purchase records.

3. Roles in data processing

DB1 Group may act as controller or processor of personal data, as provided for in the applicable legislation, in particular under Article 5, items VI and VII of the LGPD, depending on the nature of the relationship established with clients, employees, suppliers and other third parties, as well as on the obligations arising from the agreements entered into.

We undertake to inform you of our role in the processing of your data, whether through contractual instruments, terms of use, privacy policies or other related documents, ensuring the transparency required by Article 6, item VI of the LGPD.

4. How we obtain your personal data

DB1 Group obtains personal data directly through the interactions carried out with you, as well as through the use of our products and services. This includes, but is not limited to, situations in which you: request support; register for or attend a training session, webinar or other event; request information or materials, such as e-books or similar; take part in surveys or assessments, promotions; apply for a job; send questions or comments.

Personal data collected by online means may also be combined with information provided through offline channels, such as during job interviews or at events held or sponsored by DB1 Group in which you take part.

We may also collect information automatically, related to the use of our websites and the response to our emails, through the use of various technologies. Collecting information in this way allows us to analyze the effectiveness of our websites and our marketing efforts, enabling us to personalize your experience and improve our interactions with you.

5. On the use of your personal information

DB1 Group may use the personal data we collect for certain purposes, among them: identifying and authenticating you, verifying your identity when you access and use our services, and ensuring the security of your personal data. We process your personal information in order to fulfil our contractual obligations to you.

The processing purposes are tied to the legal bases set out in Article 7 of the LGPD, such as:

  • (i) Performance of a contract or of preliminary procedures related to a contract to which the data subject is a party (Art. 7, V);
  • (ii) Compliance with a legal or regulatory obligation by the controller (Art. 7, II);
  • (iii) Regular exercise of rights in judicial, administrative or arbitration proceedings (Art. 7, VI);
  • (iv) Credit protection (Art. 7, X);
  • (v) Legitimate interest of the controller or of third parties (Art. 7, IX), with due impact assessment and safeguarding of rights;
  • (vi) Consent of the data subject, where necessary (Art. 7, I).

Where processing is based on the legitimate interest of DB1 Group or of third parties, we shall prepare, where applicable, a Personal Data Protection Impact Assessment (DPIA), which may be made available to the National Data Protection Authority (ANPD) upon request, under Article 10, §3 of the LGPD. In such cases, the Data Subject has the right to object to processing carried out on the basis of legitimate interest whenever a breach of the provisions of the Law is found, under Article 18, §2 of the LGPD.

In other cases, it is in our legitimate commercial interest to be able to contact you — for example, if you request something from DB1 Group, such as a product or service, a callback, a newsletter subscription or specific marketing, or other materials, we will use the personal data you provide to respond to your request. We or our representatives may also contact you as part of customer satisfaction surveys or for market research purposes.

Where required by applicable law, we will obtain your consent before sending marketing messages. DB1 Group may also use your personal data to notify you about product and service offers, as well as about events we believe may be of interest to you, or to respond directly to your requests for information, including sign-ups for newsletters or other specific requests.

When you apply for a position at DB1 Group, we use the personal data you provide for the purpose of assessing your application, considering you for future positions and performing human resources functions in accordance with applicable law. DB1 Group will share the personal data provided during the application process with internal human resources professionals, as well as with professionals in our business functions who are taking part in the application and interview process.

Certain data that may be provided in the context of selection processes, such as information on health, disability, biometric data or other characteristics voluntarily disclosed in résumés, cover letters or interviews, may constitute sensitive personal data under Article 5, II of the LGPD. In such cases, DB1 Group will adopt differentiated and reinforced treatment, restricting access to and use of such data to the purposes strictly necessary for conducting the selection process, on the basis of Article 11 of the LGPD, and will observe additional security and confidentiality measures.

When you use our websites and/or respond to our emails, we use the personal data you provide in order to improve and personalize your experience on our websites and to deliver content and offers of products and services relevant to your interests, including targeted offers through our site, third-party sites or email (with your consent, where required by applicable law); we may also use this information to help us further improve and develop our websites, products and services.

We will not use your personal data in a manner inconsistent with the purpose of its original collection unless we have provided additional notice and you have consented. DB1 Group will retain your personal data for as long as necessary to fulfil the purposes for which the information is processed, or for other valid reasons to retain your personal information (for example, to comply with our legal and regulatory obligations, resolve disputes, enforce our agreements, and for the establishment, exercise or defence of legal claims).

6. How we share your data

DB1 Group may disclose personal data to business partners and service providers in order to support our operations. Such business partners and service providers are contractually obliged to keep the information received on behalf of DB1 Group confidential and secure and not to use it for any purpose other than that for which it was provided to them.

The information collected may be shared by DB1 Group with:

  • (i) other companies in the group for marketing activities or where necessary for the proper provision of the services that are the object of their activities;
  • (ii) for the protection of DB1 Group’s interests in any kind of dispute;
  • (iii) with commercial partners, for purposes such as performance of the service provision or product sale agreement, security, fraud prevention and credit analysis;
  • (iv) upon court decision or request from a competent authority.

DB1 Group may also disclose personal data as required by Law or legal process, as well as respond to requests from police or public authorities, to enforce or protect DB1 Group’s rights, where such disclosure is necessary or appropriate to avoid physical harm or financial loss as permitted by applicable law, or in connection with an investigation of suspected or actual illegal activity.

DB1 Group may carry out the international transfer of personal data, in particular by reason of cloud computing storage on servers located abroad. In such cases, all legal measures are adopted to ensure the protection of the transferred data, including, where necessary, obtaining the specific and highlighted consent of the data subject, under Article 33, item VIII of the LGPD, and Article 9, II, c, of ANPD Board Resolution No. 19, of 23 August 2024.

7. Right to access, control and delete your personal data

DB1 Group guarantees you, the Data Subject, various options as to what to do with your personal data collected, processed and stored, including its deletion and/or correction. You may: (i) request the deletion of your personal data; (ii) change or correct data, requesting updates, changes or corrections to your data in certain cases, particularly if it is inaccurate; (iii) raise objections, limits or restrictions on the use of data, requesting that the use of all or some of your personal data be stopped; (iv) access your data; (v) request the portability of your personal data to another service or product provider, upon express request and subject to trade and industrial secrets, under Article 18, V of the LGPD; and (vi) request review, by a natural person, of decisions taken solely on the basis of automated processing of personal data that affect your interests, under Article 20 of the LGPD.

Any consent given by the Data Subject may also be withdrawn at any time, by express manifestation, through a free and facilitated procedure, under Article 8, §5 of the LGPD, without prejudice to the lawfulness of the processing carried out on the basis of the consent in force until then.

Personal data will be stored for as long as necessary to fulfil the purposes for which it was collected, as well as to comply with legal and regulatory obligations. After processing ends, the data will be securely disposed of, or anonymized, in observance of Article 15 of the LGPD. By way of reference, and without prejudice to specific legal deadlines that may prevail: data processed on the basis of contract performance is retained for the duration of the relationship and for the applicable limitation period (as a rule, up to 10 years, under Article 205 of the Civil Code); tax and accounting data is retained for at least 5 years, in accordance with tax legislation; data of candidates not taken forward in selection processes is retained for the period necessary for any defence in administrative or judicial proceedings; and data collected through cookies and tracking technologies observes the periods indicated in the respective consent settings. DB1 Group maintains an internal data lifecycle table, administered by the Information Security area, detailing the applicable periods by data category and legal basis.

DB1 Group has a structured process for recording, tracking and responding to data subject requests, in accordance with the deadlines and requirements of the LGPD. Every request is recorded, analyzed and answered with reasons, and may be granted or justified on the basis of a legal obligation, legitimate interest or other applicable legal grounds. As a rule, confirmation of the existence of processing and access to personal data will be provided within 15 (fifteen) days, counted from the date of the request, and other requests may be answered within a reasonable period proportional to the technical complexity of the measure, subject to any extensions duly justified and communicated to the Data Subject, in accordance with Article 19 and other applicable provisions of the LGPD.

You may make the requests listed above by contacting our Data Protection Officer at the email address privacy@db1group.com, and these requests will be considered in accordance with applicable laws.

8. Processing of children’s and adolescents’ data

Where personal data of children and adolescents is processed on our websites, applications and other digital channels, such processing will observe the provisions of Article 14 of the LGPD, being carried out, as a rule, with specific and highlighted consent given by at least one of the parents or by the legal guardian, this requirement being waived where the collection of the data is necessary to contact the parents or legal guardian, used only once and without storage, or for the protection of the child or adolescent; and under no circumstances will processing be conditioned on the provision of personal information beyond that strictly necessary for the activity.

DB1 Group will further observe, insofar as applicable to its activities, Law No. 15,211/2025 (Digital Statute of the Child and Adolescent – Digital ECA), adopting, where required, age verification mechanisms, privacy and safety by design/default measures, and limits on advertising targeted at this audience.

9. Information security incidents

Under Article 48 of the LGPD and ANPD Board Resolution No. 15 of 24 April 2024, DB1 Group, when acting in the capacity of controller of personal data, will adopt a formal information security incident management procedure with defined roles and responsibilities, covering identification, containment, risk assessment and communication of security incidents that may pose relevant risk or harm to data subjects, communicating the event to the National Data Protection Authority (ANPD) and to affected data subjects, where applicable, within up to 3 (three) business days counted from awareness of the incident, and will keep the corresponding record for a minimum period of 5 (five) years.

This communication obligation does not apply in cases where DB1 Group acts as processor of personal data, in which case communication to the respective controller will observe what is established in the contract or equivalent instrument entered into between the parties.

The internal operational flow for identification, escalation, containment, assessment and communication of security incidents, including those responsible, activation channels and internal action deadlines, is defined in a specific internal document.

10. Data Protection Officer – DPO

DB1 Group has appointed Alexandre de Souza Dona as its Data Protection Officer (“DPO”). You, the Data Subject, may contact the DPO at the following physical address: Avenida Carneiro Leão, 563, Centro Empresarial Le Monde, 2nd floor, City of Maringá, State of Paraná, postal code 87.014-010, or through the email address privacy@db1group.com.

11. Cookie policy

This section supplements the Privacy Policy and details the use of cookies and similar technologies on DB1 Group websites.

11.1. What cookies are: cookies are small text files stored on the User’s device when they visit a website, used to recognize the browser, remember preferences and collect information about browsing.

11.2. Categories of cookies used:

  • Necessary cookies: essential to the operation of the site (e.g. navigation, security, remembering the User’s own cookie choice). They do not depend on consent, as they are indispensable to the provision of the requested service.
  • Performance and analysis cookies (analytics): used to measure audience and site usage (e.g. Google Analytics, Microsoft Clarity). Legal basis: consent.
  • Advertising cookies: used for targeting and measurement of advertising campaigns (e.g. Google AdSense/DoubleClick, Meta/Facebook Pixel). Legal basis: consent.
  • Social media cookies: set by social media plugins integrated into the site (e.g. Facebook, YouTube, Instagram, LinkedIn). Legal basis: consent.
  • Lead generation and marketing automation cookies: used by marketing tools to identify and track visitors with potential commercial interest. Legal basis: consent.

11.3. Consent and management: when accessing DB1 Group websites, the User sees a cookie banner that allows non-essential cookies to be accepted or rejected with the same ease between the two options, as well as choosing which categories they authorize individually. The User may change their choice at any time through the cookie settings link available on the site.

11.4. International transfer: some cookie providers (e.g. Google LLC, Meta Platforms) are based outside Brazil, so there may be an international transfer of the data collected through those cookies. In such cases, the adequacy mechanisms provided for in the LGPD apply (Articles 33 et seq.).

11.5. Retention: data collected through cookies is kept in accordance with each provider’s standard retention policy, or until consent is withdrawn by the User through the cookie banner.

12. Changes to the Privacy Policy

This Privacy Policy may undergo updates. We therefore recommend visiting this page periodically so that you are aware of such modifications. Before using your information for purposes other than those defined in this Privacy Policy, we will request your consent.

13. Governing law and jurisdiction

This document is governed by and shall be interpreted in accordance with the laws of the Federative Republic of Brazil. The Courts of the District of Maringá, State of Paraná, are elected as competent to settle any questions arising from this document, with express waiver of any other, however privileged it may be.

First conversation

What is holding back your operation?

Talk to our specialists about what your current system keeps you from doing, where the biggest hidden costs are and what the first step would be.

  • 30 minutes with our engineering and business team.
  • No commitment to hire.
  • You leave with clear next steps, even if you decide not to move forward.

DB1 Global Software · Agentic Software Engineering

I want to talk to DB1