Privacy and Personal Data Protection Policy
RAILTECH - Railway Maintenance and Technology Management Ltd.
1. PURPOSE
This policy aims to inform all visitors, clients, and partners of RailTech about the application of the Brazilian General Data Protection Law (LGPD - Law No. 13,709/2018), clarifying how we handle your personal data and what your rights are.
2. SCOPE OF APPLICATION
This policy applies to all individuals whose personal data is processed by RAILTECH - Railway Maintenance and Technology Management Ltd. (hereinafter "RailTech"), whether through use of our website, execution of our services, or communication with our technical or commercial teams.
3. KEY DEFINITIONS
Personal data: Any information relating to an identified or identifiable natural person.
Sensitive data: Data regarding racial or ethnic origin, religious beliefs, political opinions, health, sexual life, biometrics, etc.
Data subject: The individual to whom the personal data refers.
Controller: RailTech, when it determines how and why personal data is processed.
Processor: Third parties that process personal data on behalf of RailTech.
DPO (Data Protection Officer): The person designated as the communication channel with data subjects and the Brazilian Data Protection Authority (ANPD).
4. DATA WE COLLECT
RailTech may collect personal data through various means:
- When filling out forms on our website (name, phone number, email, company).
- Through commercial communication by email or phone.
- During the performance of contracted services, when operational data is shared.
- At technical events, meetings, and industry fairs.
- Via cookies and web analytics tools.
Examples of data collected:
- Name, job title, corporate email, phone number, company.
- Website access IP, approximate location.
- Contractual or operational data required to provide our services.
5. PURPOSES OF DATA PROCESSING
Personal data is processed for legitimate purposes, such as:
- Enabling the provision of contracted technical and digital services.
- Communicating with interested parties or clients.
- Issuing reports, proposals, and contracts.
- Promoting events and technical communication related to railways.
- Complying with legal, tax, and regulatory obligations.
- Managing website usage and improving user experience.
6. DATA SHARING
RailTech does not sell or trade personal data. Data is only shared when necessary, such as:
- With authorized service providers (e.g., cloud, IT, information security).
- With strategic partners involved in delivering solutions.
- With regulatory bodies, when required by law or contract.
7. DATA SUBJECT RIGHTS
As a data subject, you have the following rights:
- Access to your personal data.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of unnecessary data.
- Data portability.
- Information about data sharing.
- Withdrawal of consent.
To exercise your rights, please contact us at: dpo@railtech.com.br
8. INFORMATION SECURITY
RailTech adopts technical and organizational measures to ensure the protection of personal data under its responsibility, including:
- Use of secure servers and cloud services with encryption.
- Restricted access based on authorization profiles.
- Continuous monitoring of vulnerabilities and unauthorized access attempts.
- Confidentiality agreements with employees and partners.
9. COOKIES AND BROWSING TECHNOLOGIES
Our website uses cookies and traffic analysis tools (such as Google Analytics) to understand how visitors interact with the platform, aiming to improve the browsing experience. Users can configure their browsers to reject cookies, but this may affect some website functionalities.
10. CHANGES TO THIS POLICY
This Privacy Policy may be updated periodically to reflect improvements or changes in legislation. The current version will always be available on our website.
11. CONTACT CHANNEL
For questions or requests related to data protection, please contact our DPO: +55 (11) 98891-4019
12. FINAL PROVISIONS
RailTech is committed to fully complying with the principles of the LGPD and reinforces its commitment to ethics, information security, and respect for the privacy of its clients, partners, and users.