PRIVACY POLICY AND PERSONAL DATA PROTECTION POLICY
ILS BRAZIL – V2.0
Version: 2.0
Publication date: September 2026
Applicability: Brazil
1. OBJECTIVE
ILS BRASIL TECNOLOGIA LTDA. (“ILS Brasil,”“ILS,”“we,” or“our company”), a subsidiary of ILS ASSET HOLDINGS LIMITED, headquartered in Ireland, values privacy and the protection of personal data processed in the course of its business activities.
The purpose of this Privacy and Personal Data Protection Policy (“Policy”) is to explain, in a clear, transparent, and accessible manner, how ILS collects, uses, stores, shares, protects, and deletes personal data, as well as to outline the rights of data subjects and the means available for exercising those rights.
This Policy applies to personal data processed by ILS in its dealings with customers, prospective customers, suppliers, business partners, representatives, users of its websites and platforms, visitors, job applicants, and other individuals whose data is processed by ILS in its capacity as a Data Controller.
When ILS acts exclusively as a Processor, processing personal data on behalf of its clients and in accordance with their documented instructions, such processing shall also comply with the contractual provisions established with the respective Controller.
2. GLOBAL PRIVACY STANDARDS AND APPLICABLE LAWS
ILS Brasil is part of an international business group led by ILS ASSET HOLDINGS LIMITED, headquartered in Ireland, with subsidiaries and operations in various jurisdictions.
The ILS Group adheres to global privacy and data protection standards applicable to its member companies, without prejudice to compliance with the applicable local laws in each country where its companies operate.
In Brazil, ILS Brasil complies, in particular, with Law No. 13,709/2018—the General Personal Data Protection Law (“LGPD”)—as well as the applicable regulations, guidelines, and decisions issued by the National Data Protection Authority (“ANPD”).
Depending on the nature of the processing, the location of the data subjects, the companies involved, or the personal data, data protection laws from other jurisdictions in which the ILS Group operates may also apply, including, where applicable, the European Union’s General Data Protection Regulation (EU GDPR – Regulation (EU) 2016/679), the UK GDPR and the United Kingdom’s data protection legislation, South Africa’s Protection of Personal Information Act, 2013 (POPIA), and other applicable local regulations.
The possible application of foreign law does not preclude the application of Brazilian law when a particular processing activity is subject to the LGPD.
Some companies or subsidiaries of the ILS Group may be subject to additional requirements under the data protection laws of their respective countries. In such cases, specific notices or privacy statements may be provided, depending on the applicable jurisdiction and the nature of the data processing.
3. WHO IS ILS BRASIL?
For processing activities carried out in Brazil in which ILS determines the purposes and means of the processing, ILS BRASIL TECNOLOGIA LTDA. acts as the Data Controller for personal data, subject to the specific characteristics of each operation.
Company Name: ILS BRASIL TECNOLOGIA LTDA.
CNPJ: 43.460.643/0001-20
Address: Rua Leopoldo Couto de Magalhães Júnior, 1098, Unit 54, Itaim Bibi, São Paulo – SP, ZIP Code 04542-001, Brazil.
In certain operations, particularly when providing services related to the scanning, processing, storage, management, and provision of documents, ILS may act as a Data Processor, processing personal data on behalf of its clients and in accordance with their instructions.
Whether an ILS is classified as a Controller or an Operator will depend on the nature and circumstances of each processing operation.
4. IMPORTANT CONCEPTS
For the purposes of this Policy:
Personal data: information relating to an identified or identifiable natural person.
Sensitive personal data: personal data regarding racial or ethnic origin, religious beliefs, political opinions, membership in a labor union or an organization of a religious, philosophical, or political nature, data concerning health or sex life, and genetic or biometric data, when linked to a natural person.
Data Subject: the individual to whom the personal data refers.
Controller: a natural or legal person who is responsible for decisions regarding the processing of personal data.
Processor: a natural or legal person that processes personal data on behalf of the Controller.
Data Protection Officer: a person appointed by the Controller to serve as a channel of communication between the Controller, data subjects, and the ANPD, in accordance with applicable law.
Processing: any operation performed on personal data, including collection, creation, receipt, classification, use, access, reproduction, transmission, distribution, processing, storage, disposal, evaluation, control, modification, disclosure, transfer, dissemination, or extraction.
5. WHAT PERSONAL DATA MAY WE PROCESS?
Depending on the relationship established with ILS and the purpose of the processing, we may process different categories of personal data.
5.1. Identification and Qualification Information
These may include:
- first and last name;
- CPF;
- ID card or other form of identification;
- date of birth;
- signature;
- information necessary for identification and verification.
5.2. Contact Information
These may include:
- address;
- ZIP Code;
- city and state;
- phone;
- cell phone;
- email address.
5.3. Professional Information
These may include:
- company;
- position or role;
- department;
- business address;
- business phone;
- professional email address;
- information related to the representation of companies or organizations.
5.4. Website and Platform Usage Data
These may include:
- IP address;
- date and time of access;
- device used;
- browser;
- browser version and language;
- operating system;
- pages viewed;
- navigation information;
- access logs;
- technical information necessary for the safety and operation of the platforms.
5.5. Data Provided During the Provision of Services
When ILS provides services related to the scanning, processing, storage, management, or making available of documents, it may process personal data contained in the documents submitted by the client.
In such situations, ILS may act as a Processor, with the client generally being responsible for defining the purposes, legal bases, and other decisions related to the processing, as set forth in the contract.
The documents processed may contain general personal data and, depending on the nature of the collection, sensitive personal data, including health-related information.
6. HOW WE COLLECT DATA
Personal data may be collected:
- directly from the account holder;
- through forms, contracts, proposals, and documents;
- during business or customer service interactions;
- while using ILS's websites and platforms;
- through customers, suppliers, or partners, when necessary for the provision of services;
- through physical or digital documents submitted for processing;
- automatically, through browsing technologies, cookies, and technical logs;
- from public sources or sources lawfully made available, where permitted by applicable law.
ILS seeks to limit data collection to information that is necessary, appropriate, and relevant to the stated purposes.
7. WHAT WE USE PERSONAL DATA FOR
Personal data may be used for the following purposes:
7.1. Provision of Services
- execute contracts;
- provide the contracted services;
- provide platforms and systems;
- provide customer service;
- process documents;
- to digitize, classify, index, store, and make information available;
- provide technical and operational support.
7.2. Business Relationship
- respond to requests;
- develop proposals;
- conduct negotiations;
- maintain relationships with clients and prospective clients;
- send information related to the requested services.
7.3. Customer Service and Support
- identify users;
- answer questions;
- resolve requests;
- record patient visits;
- provide technical support.
7.4. Safety
- protect systems and platforms;
- prevent fraud;
- identify unauthorized access;
- monitor security incidents;
- maintain technical records;
- investigate incidents.
7.5. Compliance with Legal Obligations
The data may be processed to comply with legal or regulatory obligations applicable to ILS.
7.6. Regular Exercise of Rights
The data may be used to defend ILS's rights and interests in judicial, administrative, or arbitration proceedings, or in dispute resolution procedures.
7.7. Product and Service Improvement
The data may be used, within legal limits, to evaluate, develop, and improve products, services, systems, processes, and the user experience.
7.8. Commercial Communications
Where permitted by applicable law, ILS may send communications regarding products, services, events, and information that may be relevant to the recipient.
When processing is based on consent, the data subject may withdraw that consent at any time.
8. LEGAL BASIS FOR DATA PROCESSING
ILS processes personal data only when there is an appropriate legal basis provided for in applicable law.
Depending on the situation, the following legal bases may be used:
Purpose | Possible legal basis |
Contract Performance | Performance of a contract or preliminary procedures |
Handling Requests | Performance of a contract, preliminary proceedings, or legitimate interest, as applicable |
Compliance with a Legal Obligation | Compliance with legal or regulatory obligations |
Information Security | Legitimate interest or compliance with a legal obligation, as applicable |
Fraud Prevention | Legitimate interest and/or the lawful exercise of rights |
Legal Defense in Lawsuits | Regular exercise of rights |
Commercial Communications | Consent or legitimate interest, where legally applicable |
Service Improvements | Legitimate interest or another applicable legal basis |
Handling of Sensitive Data | One of the scenarios provided for in Article 11 of the LGPD, as applicable |
The use of legitimate interest will be preceded by an assessment of the compatibility between the intended purpose, the interests of ILS, and the fundamental rights and freedoms of the data subjects and their legitimate expectations, where applicable.
9. PROCESSING OF SENSITIVE PERSONAL DATA
ILS may process sensitive personal data when necessary for the performance of its activities or services, provided there is an appropriate legal basis.
When acting as a Processor, particularly in document management services, ILS will process sensitive personal data in accordance with the documented instructions of the respective Controller and within the limits established by contract.
ILS will implement technical and administrative measures commensurate with the risks involved to protect sensitive personal data against unauthorized access and accidental or unlawful disclosure.
10. PROCESSING OF CHILDREN'S AND ADOLESCENTS' DATA
ILS does not primarily aim to collect data from children and adolescents.
When the processing involves the personal data of children or adolescents, the provisions of the LGPD and other applicable regulations will be observed, taking into account the best interests of the minor.
When the law requires specific and explicit consent from legal guardians, such consent will be obtained in accordance with the applicable requirements.
11. SHARING OF PERSONAL DATA
ILS may share personal data when necessary and in a manner consistent with the purposes of the processing and with applicable law.
Information may be shared with:
- companies that are part of the ILS Group;
- suppliers and service providers;
- technology providers;
- companies responsible for infrastructure, hosting, storage, and security;
- partners necessary for the provision of services;
- professional consultants and advisors;
- public authorities, regulatory agencies, or government entities;
- third parties involved in judicial, administrative, or arbitration proceedings;
- companies involved in corporate transactions, reorganizations, mergers, acquisitions, or similar transactions.
The sharing of information will be limited to what is necessary for the corresponding purpose and will comply with the requirements of applicable law.
ILS does not sell the personal data of data subjects.
12. ILS AS AN OPERATOR
For certain services, particularly those related to the digitization, processing, storage, management, and provision of documents, ILS may act as a personal data processor.
In these situations:
- As a general rule, the client will be the Data Controller;
- The customer will determine the purposes and means of the processing;
- ILS will process the data in accordance with the client's documented instructions;
- ILS will use the data solely for the purposes set forth in the contract;
- ILS will implement technical and administrative security measures commensurate with the risks;
- ILS will assist the Controller, where applicable, in fulfilling its data protection obligations;
- Any subcontractors will be engaged in accordance with the applicable contractual terms.
The actions taken by ILS in its capacity as an Operator do not transfer to ILS the responsibility for decisions that fall exclusively within the Controller’s purview.
13. INTERNATIONAL DATA TRANSFERS
Given the ILS Group’s international structure, the provision of certain services, and the use of technological resources, systems, infrastructure, or international support, international transfers of personal data may occur.
The international transfer may involve companies within the ILS Group located in other countries, including ILS ASSET HOLDINGS LIMITED, as well as service providers, technology providers, or other authorized third parties, when necessary for the legitimate and specific purposes of the processing.
In the context of providing services to customers, personal data may be transferred internationally when necessary for the performance of the contracted services, technical or operational support, the use of systems and infrastructure, business continuity, or to fulfill other contractually agreed-upon purposes.
When ILS acts as a Processor, any international transfer of personal data processed on behalf of a client will comply with the documented instructions of the respective Controller, the applicable contractual provisions, and the relevant legal requirements.
When an international transfer subject to the LGPD occurs, ILS will comply with the requirements set forth in Articles 33 through 36 of the LGPD and in the applicable ANPD regulations, particularly the International Data Transfer Regulation.
The transfer may be carried out through a legally valid mechanism, as applicable to the specific case, including:
- adequacy decision;
- standard contract terms;
- global corporate standards;
- specific contractual provisions, where legally applicable;
- other cases provided for by law.
ILS will adopt measures designed to ensure an adequate level of protection for personal data and the rights of data subjects, in accordance with the principles of security, transparency, necessity, and accountability.
International transfers will be limited to the data necessary for the corresponding purposes and will not involve the indiscriminate disclosure of personal data to third parties.
Where applicable, additional information regarding a specific international transfer may be provided in this Policy, on a specific page, in a specific privacy notice, or in a separate contractual document.
14. COOKIES AND SIMILAR TECHNOLOGIES
ILS may use cookies and similar technologies to ensure the proper functioning of its websites and platforms, improve the user experience, conduct usage analytics, and, where applicable, support communication and marketing activities.
Cookies can be classified, based on their purpose, into:
Essential cookies
They are used to ensure the operation, security, and availability of websites and services.
Performance and analytics cookies
They can be used to understand how users interact with websites and to identify opportunities for improvement.
Functionality cookies
They may enable the recognition of certain preferences and features.
Advertising or marketing cookies
When used, they may support communication and advertising activities in accordance with applicable law.
Whenever necessary, ILS will provide appropriate mechanisms to allow users to manage their cookie preferences.
Essential cookies may be used without consent when they are necessary for the service to function, while cookies that require consent will be handled in accordance with the user's choices.
15. DATA RETENTION AND DISPOSAL
ILS will retain personal data for as long as necessary to fulfill the purposes for which it was collected.
The retention period may vary depending on:
- purpose of the processing;
- nature of the data;
- contractual relationship;
- legal and regulatory obligations;
- the need to preserve evidence;
- regular exercise of rights;
- safety requirements;
- fraud prevention;
- decisions by competent authorities.
When the data is no longer needed and there is no legal basis for its retention, it will be deleted, anonymized, or subject to another form of processing permitted by law.
A request by the data subject to delete data shall have no effect when retention is necessary to comply with a legal or regulatory obligation, to exercise rights in the ordinary course of business, or in any other legally authorized circumstance.
16. PERSONAL DATA SECURITY
ILS implements technical and administrative measures designed to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, disclosure, or dissemination.
Among the measures adopted, as applicable to the environment and the service, are:
- access controls;
- authentication and credential management;
- access restriction based on a need-to-know basis;
- infrastructure protection mechanisms;
- monitoring of environments and systems;
- use of secure connections and encryption mechanisms when applicable;
- internal security procedures;
- physical and logical access controls;
- confidentiality agreements;
- employee training and awareness;
- backup and recovery procedures;
- risk assessment and management;
- measures for prevention and incident response.
Access to personal data is limited to authorized individuals who need this information to perform their duties.
ILS also requires employees, contractors, and authorized partners to maintain the confidentiality of the information to which they have access.
No electronic transmission or storage system is completely secure. Therefore, although ILS implements security measures commensurate with the risks, it is not possible to guarantee that a given environment is immune to all security incidents.
17. SECURITY INCIDENTS
ILS has procedures in place to identify, assess, address, and respond to security incidents involving personal data.
When an incident is identified, ILS will assess its nature, scope, the categories of data involved, the number of potentially affected data subjects, the risks, and other relevant circumstances.
When ILS acts as an Operator, it shall notify the respective Controller in accordance with the obligations established in the contract and in applicable law, providing the necessary available information so that the Controller may fulfill its obligations.
When ILS acts as the Data Controller, it will provide notifications to the authorities and data subjects as required by law.
The reporting of security incidents shall comply with applicable ANPD regulations, including ANPD Resolution No. 15/2024.
18. RESPONSIBILITY FOR THE USE OF CREDENTIALS
When ILS makes platforms or systems available to customers, each user must keep their access credentials confidential.
Sharing usernames, passwords, or other individual authentication methods may compromise information security.
The user must:
- keep your credentials confidential;
- Do not share passwords;
- use only your own account;
- immediately report any suspected misuse;
- Follow the safety guidelines provided by ILS.
When technically feasible, ILS may implement additional authentication and access control mechanisms.
19. LINKS TO THIRD PARTIES
ILS websites and platforms may contain links to third-party websites, applications, or services.
This Policy does not apply to processing carried out by third parties acting independently of ILS.
We recommend that users review the privacy policies of the respective third parties before providing their personal information.
20. RIGHTS OF DATA SUBJECTS
Under the LGPD, data subjects may exercise rights related to their personal data, subject to the conditions, limitations, and exceptions set forth in the law, including:
- confirmation that processing is taking place;
- access to personal data;
- correction of incomplete, inaccurate, or outdated data;
- anonymization, blocking, or deletion of unnecessary, excessive, or improperly processed data;
- data portability, in accordance with ANPD regulations;
- deletion of data processed on the basis of consent, where applicable;
- information about the public and private entities with which the data was shared;
- information about the option to withhold consent and the consequences of refusing to give consent;
- withdrawal of consent;
- objection to the processing carried out in certain cases;
- review of decisions made solely on the basis of automated processing, where applicable;
- other rights provided for in data protection laws.
The exercise of these rights may be subject to the conditions, limitations, and exceptions set forth in applicable law.
21. HOW TO EXERCISE YOUR RIGHTS
The data subject may submit requests related to privacy and the protection of personal data to:
Email:
slourens@infologistics.co.za
When submitting a request, ILS may ask for additional information to verify the requester’s identity and prevent the improper disclosure of personal information to third parties.
Requests will be reviewed and responded to within the timeframes and under the conditions set forth in applicable law.
ILS may maintain records of requests received for purposes of monitoring, security, demonstrating compliance, and the regular exercise of rights.
22. PERSON RESPONSIBLE FOR THE PROCESSING OF PERSONAL DATA
ILS will maintain a communication channel dedicated to issues related to the protection of personal data and its relationship with data subjects and the ANPD, in accordance with applicable law.
Data Controller:
Shawn Lourens
Contact channel:
slourens@infologistics.co.za
The Data Protection Officer’s identification and contact information must be kept up to date and made publicly available in an accessible manner, as applicable.
23. GOVERNANCE AND ACCOUNTABILITY
ILS maintains institutional measures designed to protect personal data and promote a culture of privacy.
These measures may include:
- internal policies and procedures;
- access control;
- employee training;
- confidentiality agreements;
- risk assessment;
- supplier management;
- procedures for assisting account holders;
- incident management;
- periodic review of security measures;
- monitoring legislative and regulatory changes.
ILS seeks to implement effective measures to demonstrate its compliance with applicable laws, taking into account the nature, scope, context, and risks of each processing activity.
Where applicable, ILS Brasil’s privacy governance may also adhere to global standards, policies, and procedures adopted by the ILS Group, provided they are consistent with applicable Brazilian law.
24. UPDATES TO THIS POLICY
This Policy may be updated periodically to reflect:
- legislative changes;
- ANPD regulations;
- changes to ILS services;
- changes in treatment processes;
- technological advances;
- changes in security practices;
- improvements in transparency and governance;
- changes to the ILS Group's global privacy practices and standards.
The updated version will be made available on ILS's official channels.
When a change requires specific notification or consent, ILS will take the necessary measures in accordance with applicable law.
25. FINAL PROVISIONS
This Policy must be interpreted in conjunction with the contracts, terms of use, specific privacy notices, cookie policies, data processing agreements, and other documents applicable to a particular product, service, or relationship.
In the event of a conflict between this Policy and a specific contractual provision regarding the processing of personal data, the applicable law and, where relevant, the specific contractual provision agreed upon by the parties shall be taken into account.
Nothing in this Policy limits the rights guaranteed to data subjects under Brazilian law.
26. CONTACT
For questions, requests, or information regarding privacy and the protection of personal data, please contact us:
ILS BRASIL TECNOLOGIA, L.L.C.
1098 Leopoldo Couto de Magalhães Júnior Street, Unit 54
, Itaim Bibi – São Paulo – SP
ZIP Code 04542-001 – Brazil
Email: slourens@infologistics.co.za
PRIVACY AND PERSONAL DATA PROTECTION POLICY – ILS BRASIL
Version 2.0 – September 2026