PRIVACY POLICY

PRIVACY POLICY

  1. INTRODUCTION 

Stella Importação e Exportação de Luminárias Ltda., a legal entity governed by private law, registered with CNPJ (Corporate Taxpayer ID) No. 10.691.158/0001-09 (“Stella”), with head offices in the cities of Itajaí, Santa Catarina (SC) and Sapiranga, Rio Grande do Sul (RS), is committed to respecting the privacy of its users and customers, as well as the protection and security of their personal data. 

This Privacy Policy is the document through which Stella conveys to the personal data subjects all the practices and processes adopted to make the relationship transparent, informing them of all rights, guarantees, forms of use, data collected, processing, and disposal of all personal information, in keeping with the legal norms of Brazilian laws, especially Law 13.709/2018 (“LGPD”, General Data Protection Regulation, GDPR).

  1. GUIDELINES AND DEFINITIONS 

In September 2020, the General Data Protection Law (Law 13.709/2018), popularly known as LGPD, came into force in Brazil. The law’s scope is to govern the processing of Personal Data with transparent, legitimate, express, and informed purposes to the subject, abiding by the principles of compatibility of treatment with the informed purposes and the limitation of processing to what is necessary.

Given this premise, Stella has prepared this policy so that you, as subject, can understand how your personal data is processed. 

Hence, any information and/or data forwarded by our employees will be protected under confidentiality standards and will only be used for the purposes for which they were collected.

Thus, for a better understanding, we highlight some concepts founded on Article 5 of LGPD: 

Personal Data: any and all information about an identified or identifiable natural person. In short, personal data refers to all information that directly or indirectly identifies an individual. 

Sensitive Personal Data: all personal data about racial or ethnic origin, religious belief, political opinion, union affiliation or organization of a religious, philosophical or political nature. Also, information relating to health, sex life, genetic or biometric data. 

Processing Agents: those responsible for making decisions regarding data processing and for its effective. 

Processing: means any and all operations, such as the collection, production, reception, sorting, use, access, reproduction, transmission, distribution, processing, archiving, storage, deletion, assessment or control of information, modification, communication, transfer, diffusion, or extraction, conducted with personal data. 

Controller: natural or legal person, public or private, which is responsible for decisions regarding the processing of personal data; 

Operator: natural or legal person, public or private, which processes personal data on behalf of the controller; 

Officer: a person appointed by the controller and operator to act as a communication channel between the controller, the data subjects and the ANPD (Brazilian Data Protection Authority); 

Brazilian Data Protection Authority/ANPD: is the public administration authority responsible for ensuring, implementing, and supervising compliance with the said Law throughout the Brazilian territory. 

Security Incident: comprises unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination, as well as any other event that results in the illegal or abusive Processing wherein Personal Data and/or Sensitive Personal Data may be involved;

Demand(s): any claim, collection, grievance and/or out-of-court demand, as well as any action, litigation, investigation, inquiry, inspection, procedure or process (whether judicial, arbitration or administrative) filed or initiated; 

Subject(s): natural person to whom the personal data that are subject to processing refer; 

  1. PERSONAL DATA COLLECTED AND PROCESSED BY STELLA

Stella collects, uses, and processes personal data to provide you with services, products, and information of your interest. The collection shall be completely transparent, and you, the subject, will have the chance to decide whether or not to provide it. 

The personal data processed may range according to the purposes of use, including those stated in this Privacy Policy, as in the activities carried out.

When applicable, Stella may request your consent through the “Consent Form.” If you choose not to provide any requested data, Stella may be unable to complete your transaction or provide you with information about the services or products requested. 

Furthermore, Stella may collect information, including personal data, when you send a form or request, such as name, telephone numbers, email addresses, occupation, and any other personal data you provide to Stella. 

  1. PURPOSE OF COLLECTION OF PERSONAL DATA BY STELLA

Stella collects personal data in order to register people interested in receiving information about the products provided by the company, sending content or receiving information about new products. The data will be collected through spontaneous supply by the personal data subject. In other words, the purpose of collecting personal data is to provide you with personalized services and content relevant to your specific needs and interests.

It is important to note that Stella may use your information to fulfill our contractual obligations, authenticate you as a user and allow you to access certain areas of our website, applications, social media websites, or for you to apply for an opportunity at Stella.

  1. LEGAL BASIS FOR PROCESSING PERSONAL DATA COLLECTED 

As provided in Article 7 of Law 13.709/2018, Stella processes personal data for the following purposes: 

I – upon the provision of consent by the subject;

II – for compliance with a legal or regulatory obligation by the controller;

III – by the public administration, for the processing and shared use of data necessary for the accomplishment of public policies provided for in laws and regulations or established in contracts, agreements, or similar instruments, subject to the provisions of Chapter IV of this Law;

IV – for carrying out studies by research agencies, ensuring, whenever possible, the anonymization of personal data;

V – when necessary for the performance of a contract or preliminary procedures of a contract to which the data subject is a party, at the request of the data subject;

VI – for the regular exercise of rights in judicial, administrative or arbitration proceedings, the latter under Law 9.307, dated September 23, 1996 (Arbitration Law);

VII – for the protection of life or physical safety of the subject or third parties;

VIII – for the protection of health, exclusively in a procedure carried out by health professionals, health services or health authorities;

IX - when necessary to meet the legitimate interests of the controller or third parties, except in the case of the subject’s fundamental rights and freedoms that require the protection of personal data prevail; or

X – for credit protection, including the provisions of the applicable laws.

For all operational processes that imply the due processing of Stella, they meet at least one legal requirement referred to above. 

  1. WHICH ARE THE SUBJECTS’ RIGHTS? 

Transparency regarding the processing of your personal data is a priority for Stella.

In addition to the information provided in this Privacy Policy, the subject may also exercise the rights provided for in the General Data Protection Law, described in Article 18, namely:

  1. Right of confirmation and access: refers to confirmation about the subject’s data ownership, indicating the existence or absence of this information in the processing and, if applicable, the right to access your personal data;
  2. Right to rectify your data: referring to the rectification of incomplete, inaccurate, or outdated personal data; 
  3. Right to delete or eliminate data: right of the subject to have their data erased from the controller’s database; 
  4. Right to data portability: the subject may request the controller to transfer the data to a new controller if the latter desires. 
  5. Right of opposition: the data subject may, at any time, oppose, for reasons about their particular situation, the processing of personal data concerning them. Furthermore, the subject may object when their data is used for the purposes of the said commercialization. 
  6. Right to limit the processing of data: the subject is entitled to limit the processing of their personal data, being able to secure it when the accuracy of data is concerned, when the treatment is unlawful, when the controller no longer needs the data for the purposes reported and when they have objected to the processing of data and in the case of unnecessary data processing; 
  7. Right to review automated decisions: the data subject is entitled not to be subjected to any decision made exclusively based on the authorized processing, including profiling, which produces effects in the legal sphere or significantly affects them in a similar way. In general, they have the right to obtain human intervention, to obtain justification for the decision obtained after an assessment, and to challenge the decision. 

The subject may exercise their rights through written communication on our service channels, establishing the rights they wish to exercise before the controller. 

  1. SECURITY OF PROCESSED PERSONAL DATA 

The security of your personal data is essential for Stella, as we are committed to protecting all information we collect. We apply appropriate administrative, technical, and organizational measures intended to exclusively protect the personal data that you provide or that we collect against accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use. 

To guarantee security, solutions that consider adequate technical considerations, application costs, nature, scope, context, and purposes of the processing, as well as risks to the rights and freedoms of the data subject shall be adopted. Nonetheless, owing to the nature of internet communications, we cannot guarantee that your transmission to us will be secure. 

  1. COOKIES POLICY 

Cookies are temporary files saved on your computer, tablet, or phone when you visit a website. They are used to improve navigation functionalities and facilitate user access, always aiming at improving content and services, such as:

  • Enabling secure login
  • Remembering where you are during an order
  • Remembering your login details
  • Remembering what is in your shopping cart
  • Ensuring the website has a consistent layout
  • Allowing to share pages on social networks
  • Allowing the submission and dissemination of comments
  • Providing advertisements relevant to your interests

If you do not want cookies to be accessible, you can, at any time, adjust the settings in your browser to deny or disable the use of cookies. However, denying or disabling cookies or similar technologies may prevent you from accessing some of our content or using some of the features on the website.

It should be remarked that cookies are not used to determine the personal identity of users visiting our website.

Mandatory Cookies

These cookies are necessary to enable website functionality.

Functional Cookies

These cookies are used to improve navigation features and facilitate user access, always aiming to improve content and services. 

Advertising Cookies

These cookies are used to publish advertisements relevant to your interests.

Social Media Information

Social Media Information is any information you allow a third-party social media to share with application developers. To learn how Stella may obtain your information from social media, please visit the social media settings page.

  1. DATA SHARING WITH THIRD PARTIES

Depending on the purpose and need, Stella may share personal data within its workgroup or with third-party partners and regulatory authorities.

We may share your data with:

  • Third parties from whom we request delivery of a product or service to the subject, such as couriers or post office that deliver the products you have ordered;

 

  • Third-party service providers, such as companies that process data for Stella;

 

  • Inspection agencies or public authorities, when they have followed due legal process to request that we make the information available.

In addition, Stella may also share your personal data with companies, organizations or individuals if it believes that such sharing is necessary for legal reasons, such as (i) to enforce the applicable terms of use for the Websites or Applications; (ii) to investigate possible violations of applicable laws; (iii) to spot, prevent, and protect against fraud and any technical or security vulnerability; and (iv) to comply with applicable laws and regulations, cooperate in any lawful investigations and to comply with orders from public authorities.

  1. INTERNATIONAL DATA TRANSFER

Stella may transfer your data to other countries to process personal data with affiliates or partner entities of Stella.

To carry out the international data transfer, Stella will check whether there is a legal restriction on the partner company to carry out the processing and whether the destination country offers an adequate level of data protection if the country of destination does not offer it. Stella shall contractually establish that the receiving company should have a commensurate standard of data protection and information security consistent with this Policy and the General Data Protection Law (Law 13.709/18).

  1. RETENTION, RECTIFICATION, AND DELETION OF PERSONAL DATA 

Your personal data shall be stored in a safe and protected environment for the period necessary to accomplish the purposes indicated in item 4. However, at any time, you can request rectification or deletion of your personal data contained in our databases through our service channels.

If you make a deletion request, Stella points out that it may store your personal data for an additional period for the purposes of legal or regulatory obligations, regular exercise of rights or for the period under the legal basis that justifies such retention.

  1. AMENDMENTS AND UPDATES TO THIS PRIVACY POLICY 

Stella reserves the right to modify this Policy under applicable laws at any time. If a recent version is made, it will be published on this website, indicating its update date. If the subject does not agree with the changes, they may immediately discontinue use and may use the contact channels to submit requests of interest to them and exercise their rights. 

  1. DATA PROTECTION OFFICER – “DPO”

As stated in Article 41 of Law 13.709, Stella Importação e Exportação de Luminárias Ltda. The person in charge of data is Ana Gabriela Michel de Mello, who can be contacted through the email privacidade@stella.com.br 

  1. APPLICABLE LAW AND JURISDICTION 

This Policy shall be governed, interpreted, and enforced under Brazilian laws, especially Law 13.709/2018, with the district court of Sapiranga, Rio Grande do Sul being the jurisdiction competent to settle any disputes arising from this document. 

  1.  CONTACT INFORMATION 

If you have any questions, comments, suggestions about our privacy policy, or if you want to access, rectify, update, or delete your personal data, please contact us through the emails below: 

Controller: contato@stella.com.br

DPO: privacidade@stella.com.br

Last update: September 09, 2021.

 

Sapiranga-RS, September 09, 2021.