Privacy Policy
At Garre Solutions Ltda., privacy, security and transparency in how we handle data are priorities. This Privacy Policy sets out how we collect and process the information provided by data subjects, in accordance with Brazilian Federal Law 13.709/2018 (LGPD, the General Personal Data Protection Law) and other applicable regulations.
PURPOSE
The data we collect is used to:
- Enable sales
- Run marketing campaigns
- Support participation in recruitment and selection processes
CONSENT
Data is collected through forms on Garre Solutions communication channels and processed only after your consent — that is, the free, informed and unambiguous statement by which you authorize Garre Solutions to process your data.
By consenting, you declare that you are fully aware of this Privacy Policy and of your rights as a data subject. You may withdraw your consent at any time, at no cost.
DATA SUBJECT RIGHTS
Garre Solutions guarantees the rights set out in the LGPD:
- Confirm that processing of your data is taking place
- Access your data in a readable format
- Correct, update or edit your data
- Restrict the processing of unnecessary or excessive data
- Request data portability
- Delete data processed on the basis of consent
- Withdraw consent for data processing
RETENTION
Personal data is retained for as long as necessary to fulfil the purposes listed above. Once that period ends, the data is deleted, except in the cases set out in Article 16 of the LGPD.
DATA SHARING
Garre Solutions uses RD Station for campaigns and the Gupy platform for recruitment. Data may be shared with consultants and affiliated companies, subject to contractual terms and applicable law.
DATA SECURITY
We use physical, electronic and administrative safeguards to protect personal data, ensuring confidentiality, integrity and availability. All our contracts include confidentiality clauses.
DATA PROTECTION OFFICER (DPO)
Our appointed Data Protection Officer is Ms. Valeri Levada, who acts as the channel of communication between the controller, data subjects and the ANPD (Brazil's National Data Protection Authority).
Contact: encarregado.lgpd@garresolutions.com
Last updated: 29 August 2026
Information Security Program
Our Information Security Program is built by cybersecurity and data privacy specialists. It covers technical, administrative and physical measures that protect information against unauthorized access, alteration, disclosure or destruction.
Commitment to continuous improvement: we run regular audits and penetration tests, alongside training and awareness programs for all employees.
Environment RTO and RPO
Our business continuity targets:
RTO (Recovery Time Objective): 4 hours
The time to restore critical services after an outage.
RPO (Recovery Point Objective): 1 hour
We can recover data from up to 1 hour before an incident.
We meet these targets through disaster recovery plans, resilient infrastructure with frequent backups, continuous training and proactive monitoring.
Asset Control and Inventory
We maintain a comprehensive system for managing all assets:
- Identification and registration: critical assets recorded in a centralized system
- Continuous monitoring: periodic inventory reviews
- Access control: only authorized personnel can reach critical assets
- Licence management: a detailed record of every software licence
- Maintenance and disposal: established secure procedures
LGPD Compliance
Our privacy management system includes:
- Privacy policies: reviewed and communicated on a regular basis
- DPIA: data protection impact assessments for new projects
- Technical measures: encryption, access control and audits
- Consent: obtained clearly and unambiguously
- Data subject rights: clear procedures for access, correction and deletion
We are committed to protecting the privacy and personal data of our clients, and we keep improving how we do it.