PRIVACY POLICY
VERDETHOS BRAZIL LTDA (“Verdethos”), a private legal entity, registered with the CNPJ under No. 61.220.766/0001-76, with its registered office at R. Caldas Novas, 50 – Room 85 – Bethaville I, Barueri – SP, 06404-301, provides a multi-tenant SaaS platform. For content provided by tenants and processed on the platform, Verdethos acts as a Processor and each tenant acts as a Controller, defining the purposes and means of processing. Verdethos acts as a Controller only for limited service operation data necessary to conduct our business (for example, account administration, authentication and security logs, billing/charging, and website/application telemetry, when permitted by law).
Verdethos recognizes the importance of privacy and the protection of personal data and adopts all necessary measures to ensure the lawful, fair, transparent, and secure processing of information, in compliance with the Brazilian Law No. 13,709/2018 (LGPD – Brazilian General Data Protection Law) and other applicable regulations.
This Privacy Policy (“Policy”) aims to establish and clearly communicate to our Tenants how their information and data are collected, used, stored, processed, and protected in the context of the use of our website, mobile application, and platform.
This Policy extends to the processing of personal data carried out through our website, SaaS platform, mobile application, customer service channels, social media (such as LinkedIn, Instagram, and Facebook), communication tools (including, but not limited to, WhatsApp, Google Meet, Zoom, and Microsoft Teams), as well as data collected through integrated services and third-party systems, such as WordPress Engine and HubSpot.
We reserve the right to modify this Privacy Policy at any time and whenever necessary in order to comply with legislative updates and continue offering the highest level of security and convenience. Therefore, we recommend that you review this Policy periodically. By continuing to access or use our services after such revisions take effect, you agree to be bound by the revised terms.
If you have any questions, you may always contact us through our support channels.
1. Glossary
“Verdethos” refers to Verdethos Brazil LTDA, responsible for the development and operation of the platform. Verdethos acts as a Processor for tenants’ content and as a Controller only for the service operation data described in this Policy, as well as to other companies within the same group responsible for the development, operation, and maintenance of the Verdethos platform, which is dedicated to the management and traceability of sustainable supply chains, as well as to the implementation and oversight of the privacy and data security practices described in this Policy.
“Tenant” refers to any natural person or representative of a legal entity who accesses, uses, interacts with, or provides data to Verdethos through its applications, portals, APIs, or other means, including producers, exporters, importers, auditors, logistics operators, regulatory authorities, and corporate clients.
“Privacy Policy” refers to this document, which establishes the rules and principles applicable to the collection, use, storage, sharing, and protection of personal data in the context of Verdethos’ activities, in compliance with applicable data protection laws in Brazil and abroad.
“Personal Data” or “Data” refer to any information relating to an identified or identifiable natural person, directly or indirectly.
“Sensitive Data” refer to special categories of personal data that reveal racial or ethnic origin, religious beliefs, political opinions, membership in a trade union or religious, philosophical, or political organization, data concerning health or sex life, genetic or biometric data, which are not processed by Verdethos, except in strictly necessary situations and supported by a legal basis.
“Processing” refers to any operation performed with personal data, including, but not limited to, collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, deletion, evaluation, control, modification, communication, transfer, and extraction of data.
“Cookies” are small text files stored on the Tenant’s device, used to collect information about preferences, navigation, and platform performance, enabling the personalization of the Tenant’s experience, the optimization of system performance, and the generation of analytical usage metrics.
“Platform” refers to the digital environment maintained by Verdethos that enables the integration, traceability, and automation of supply chain operations, including web interfaces, mobile applications, APIs, dashboards, and other systems associated with the provision of its services.
“Services” correspond to the functionalities and technological solutions offered by Verdethos to its Tenants, such as product traceability, publication and consultation of ESG data, automation of import and export processes, report generation, and information integration among the parties involved in transactions.
“Account” refers to the individualized electronic registration created by the Tenant for authenticated access to the Verdethos platform, allowing the customization of permissions, data visualization, transaction history, and the management of privacy and communication preferences.
“Third Parties” refer to natural or legal persons that are not part of Verdethos’ corporate structure but may interact with the platform or receive personal data in connection with the provision of services, such as technology providers, cloud storage companies, independent auditors, importers, business partners, and government authorities.
“Confidential Information” refer to all technical, commercial, strategic, operational, contractual, financial, or any other information obtained or shared in the context of Verdethos’ activities that is not public and whose unauthorized disclosure may compromise the legitimate interests of Verdethos, its Tenants, or partners. Such information must be handled in a restricted manner, in accordance with internal security and confidentiality policies.
2. What Data and Information Do We Collect and For What Purpose?
Scope of roles for this section. For Operational and Supply Chain Data, Verdethos acts as a Processor and each tenant is the Controller. For Account/Usage/Security/Billing items, Verdethos acts as the Controller of service operation data.
Verdethos collects and processes personal data in strict compliance with Law No. 13,709/2018 (LGPD – Brazilian General Data Protection Law), the European Union General Data Protection Regulation (GDPR), and other applicable international standards.
All data are processed confidentially, for legitimate, specific, and transparent purposes, and are used exclusively for the purposes described in this Policy or upon the express consent of the data subject.
Data are collected both when voluntarily provided by the Tenant and automatically through interaction with our platforms, websites, APIs, and integrated services. This includes information collected through our website and social media channels (such as LinkedIn, Instagram, and Facebook) for business development and lead generation purposes. Such data may be shared between Verdethos Inc. and Verdethos Brazil and may also be collected or tracked through third-party applications, such as WordPress Engine (website), HubSpot (CRM), and communication tools, including WhatsApp, Google Meet, Zoom, and Microsoft Teams.
Collected Data and Purposes
| Data Category |
Description / Examples |
Purpose of Processing |
Legal Basis (LGPD) |
| Registration Personal Data |
Full name, corporate email, phone number, company, job title, country of operation, preferred language. |
Identify and authenticate the Tenant; enable registration and access to the Verdethos platform; allow technical or commercial contact; send institutional and compliance communications. |
Performance of contract (art. 7, V); Consent (art. 7, I). |
| Usage and Browsing Data |
IP address, access and activity logs, browser type and version, operating system, device data, cookies, approximate geolocation, and browsing behavior. |
Improve the Tenant experience; personalize content; ensure session security; perform performance metrics; prevent fraud and unauthorized access. |
Legitimate interest (art. 7, IX); Consent when involving non-essential cookies (art. 7, I). |
| Operational and Supply Chain Data |
Name and contact details of producers, logistics operators, drivers, exporters, importers, and technical officers; information contained in shipping documents, invoices, and certificates of origin. |
Enable platform functionalities and integrations exclusively under the tenant’s instructions, including traceability, document management, and regulatory workflows; Verdethos processes such data as a Processor. |
Processing under the Controller’s (tenant’s) instructions and contract;
Verdethos as Processor. Tenants determine their legal bases (e.g., art. 7, II; V; IX). |
| Financial and Payment Data |
Banking details, billing information, transaction history, and accounting records linked
to the corporate account. |
Process payments, issue invoices, and perform contractual transfers; comply with financial and tax obligations. |
Compliance with legal obligation (art. 7, II); Performance of contract
(art. 7, V). |
| Support and Communication Data |
Messages sent via email, chat, contact form, support API, or helpdesk tool. |
Register service requests; provide technical support; improve services and platform security. |
Performance of contract (art. 7, V); Legitimate interest (art. 7, IX). |
Secondary Purposes and Complementary Use
For tenants’ content, any secondary use is determined by the tenant (Controller); Verdethos does not reuse tenants’ content beyond the tenant’s documented instructions and the contract.
Verdethos may use personal data for purposes compatible with the original objectives of collection and within the legitimate expectations of the data subject, such as:
- Compliance with audits, investigations, or requests from competent authorities (national or foreign);
- Generation of sustainability (ESG) reports and indicators;
- Improvement of the platform’s functionalities and security;
- Development of new solutions and regulatory integrations.
Any processing that goes beyond these purposes will be carried out only upon the specific and informed consent of the data subject.
Transparency and Control
Requests related to tenants’ content must be directed to the respective tenant (Controller). Verdethos will support the tenant’s response in accordance with our agreement.
Requests related to Verdethos’ service operation data may be sent to
privacy@verdethos.io and will be answered within the timeframes required by law.
3. How Verdethos Uses Cookies
When accessing the website, the application, or any digital environment maintained by Verdethos, cookies and similar technologies (such as web beacons, tags, and local storage) may be used to optimize navigation, ensure session security, and provide a personalized and efficient experience to the Tenant.
Cookies are small text files that contain unique identifiers and are stored on the Tenant’s device (computer, tablet, smartphone, etc.) when accessing the Platform. These files allow the system to recognize the Tenant, record preferences, and understand how the services are used, thereby contributing to the continuous improvement of performance and usability.
Types of Cookies Used
Verdethos may use necessary, functional, analytical, and third-party cookies, as described below:
| Type of Cookie |
Description |
Purpose |
| Strictly Necessary Cookies |
Ensure the basic operation of the website and the secure authentication of the Tenant. Include session tokens (JWTs via AWS Cognito), access controls (Role-Based Access Control – RBAC), and audit logs. |
Ensure the technical operation of the platform and Tenant authentication.
Legal basis: legitimate interest (art. 7, IX, LGPD) and performance of contract (art. 7, V). |
| Legal basis: legitimate interest (art. 7, IX, LGPD) and performance of contract (art. 7, V). |
| Functional or Preference Cookies |
Record the Tenant’s choices, such as language, unit of measure, or country of operation, maintaining personalized settings for future visits. |
Improve the Tenant experience and facilitate recurring interactions. |
| Legal basis: consent (art. 7, I, LGPD). |
| Analytical and Performance Cookies |
Collect information about the use of the platform (pages visited, time spent, navigation errors) for internal statistical analysis through secure and auditable tools. |
Support the continuous improvement of services and the Tenant experience. |
| Legal basis: consent (art. 7, I, LGPD). |
| Third-Party Cookies (Integrators or Cloud Providers) |
Set by technology partners that provide hosting, security, and authentication functionalities, such as AWS, CloudFront, and reCAPTCHA. These cookies do not allow direct access to personal data without authorization. |
Ensure security, performance, and protection against fraud. |
| Legal basis: legitimate interest (art. 7, IX, LGPD). |
Management and Control by the Tenant
The Tenant may manage non-essential cookies in their browser/device settings and, when available, through controls within the application itself. When required by law, we obtain consent for non-essential cookies/SDKs (for example, analytical ones).
Verdethos recommends that the Tenant keep strictly necessary cookies enabled, as blocking these cookies may compromise essential functionalities, such as secure login, session recording, and authenticated access to dashboards and reports.
Sharing and Retention
Technical access logs (for example, IP, UserID, TenantID, date and time, event type) are retained for at least 6 months, as required by Brazilian legislation, and may be retained for a longer period when necessary to comply with legal obligations or to establish, exercise, or defend rights in judicial or administrative proceedings.
Transparency and Consent
Details about non-essential cookies and their purposes are available in our documentation. You can manage consent through your browser or device settings and, when available, through controls in the application.
4. In Which Cases Do We Share Personal Data?
The sharing of personal data may occur only under the circumstances described below, duly supported by a legal basis and subject to appropriate technical and contractual safeguards:
Data Sharing Scenarios
a) Compliance with Legal or Regulatory Obligations
Verdethos may disclose personal data to public authorities, regulatory bodies, and supervisory entities, domestic or foreign, when necessary to:
- Comply with legal, tax, regulatory, or environmental obligations (for example, EUDR – European Deforestation Regulation, SEC Scope 3 Carbon Disclosure);
- Respond to formal requests, court orders, or administrative determinations;
- Exercise or defend rights in judicial, administrative, or arbitration proceedings.
Legal basis: art. 7, II, and art. 11, II, “a”, of the LGPD.
b) Data Sharing and Use of Processors
In its capacity as a Processor with respect to tenants’ content, Verdethos engages sub-processors, such as hosting, authentication, monitoring, and related service providers, to operate the platform, under contracts that require appropriate safeguards, confidentiality obligations, and security measures compatible with the LGPD.
In addition, the platform may share data with other participants in the supply chain, such as business partners, exporters, importers, and upstream actors (including farms and producers). Such sharing occurs exclusively under the tenant’s instructions, with the tenant remaining the Controller of all such processing activities.
When participants choose to voluntarily provide personal information, narratives, origin stories, or other identifiable details, such as name, image, or information about their farm, for purposes of storytelling, product contextualization, or market engagement, such processing and disclosure will occur only upon the free, informed, and unequivocal consent of the data subject, as required by the LGPD. The tenant, in its capacity as Controller, is responsible for obtaining and recording such consent.
Legal basis: art. 7, V (performance of contract), art. 8 (data subject consent, when applicable), and art. 39 (joint liability) of the LGPD.
c) International Transfer of Personal Data
Verdethos operates globally, connecting exporters, importers, and industries across multiple countries. For this reason, certain personal data may be transferred internationally, in compliance with Articles 33 to 36 of Law No. 13,709/2018 (Brazilian General Data Protection Law – LGPD) and with the International Data Transfer Regulation approved by CD/ANPD Resolution No. 19, of August 23, 2024.
I – Method, Duration, and Purpose of the Transfer
Transfers may occur on an ongoing basis through the platform or integrations. Retention periods are defined by the competent Controller and by applicable law or contract.
II – Destination Countries
Data may be transferred to countries where importers, processors, industries, or the exporter’s business partners are located. In all cases, Verdethos will ensure that the destination country provides a level of personal data protection recognized as adequate by the ANPD, or that standard contractual clauses or other valid safeguard mechanisms are in place. Transfers are based on mechanisms permitted by the LGPD (for example, standard contractual clauses), with appropriate safeguards.
III – Shared Use of Data and Purposes
Data may be shared with technology providers, cloud platforms (AWS, CloudFront), authentication and security partners (AWS Cognito, MFA), importers, manufacturers, processors, and independent auditors, always for the following legitimate purposes:
- compliance with international legal or regulatory obligations;
- enablement of traceability and origin verification;
- audits, certifications, and secure communication between contracting parties;
- cloud hosting and processing, without unauthorized access by third parties.
IV – Responsibilities and Security Measures
Both Verdethos and all agents involved in the transfer (controllers, processors, and
sub-processors) undertake to:
- process data exclusively in accordance with Verdethos’ documented instructions;
- adopt appropriate technical and organizational measures (for example, encryption, access control, MFA, security logs) and process data only in accordance with documented instructions;
- not use or disclose personal data for their own purposes;
- ensure traceability and continuous monitoring, with regular internal and external audits.
V – Security and Compliance with Principles
All transfers are carried out in a secure, traceable, and auditable manner, in compliance with the principles of purpose limitation, necessity, transparency, security, and accountability,
pursuant to Articles 6 and 46 of the LGPD and Article 2 of CD/ANPD Resolution No. 19/2024, ensuring an equivalent level of protection for transferred data, regardless of the location of processing.
Legal basis: arts. 33 (items I and II) and 34 of Law No. 13,709/2018 (LGPD); arts. 9 and 15 to 21 of CD/ANPD Resolution No. 19/2024.
d) Corporate Transactions
In the event of a merger, acquisition, incorporation, spin-off, asset sale, or corporate reorganization, personal data may be shared strictly for purposes of evaluation and ensuring the continuity of business activities, provided that:
- the new controller maintains the same level of data protection;
- data subjects are informed of the transfer of control, in accordance with Article 20 of the LGPD.
Legal basis: art. 7, item IX, of the LGPD (legitimate interest).
5. What Are the Rights of Personal Data Subjects?
Verdethos ensures that all personal data subjects, whether individual Tenants, representatives of legal entities, producers, importers, or logistics operators, are guaranteed the full exercise of their rights, as provided for in the Brazilian General Data Protection Law (LGPD) and in supplementary regulations issued by the National Data Protection Authority (ANPD).
These rights may be exercised at any time, free of charge, in a transparent and secure manner, through a request sent to our official privacy channel:
privacy@verdethos.io.
Rights Guaranteed to the Data Subject
| Right |
Description and Scope |
| Confirmation and Access |
Right to obtain confirmation as to whether Verdethos processes their personal data and, if so, to access information regarding the origin, purpose, usage criteria, and categories of data processed. |
| Correction and Updating |
Right to request the correction of incomplete, inaccurate, or outdated data, ensuring the accuracy and reliability of the stored information. |
| Anonymization, Blocking, or Deletion |
Right to request the anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data, subject to legal exceptions (for example, compliance with legal obligations, exercise of rights in judicial proceedings, or audits). |
| Data Portability |
Right to request the transfer of their personal data to another service or product provider, upon express request and subject to the protection of Verdethos’ commercial and industrial secrets. |
| Deletion of Data Processed with Consent |
Right to request the deletion of data processed on the basis of consent, except where retention is required by law. |
| Information on Data Sharing |
Right to be informed about the public or private entities with which Verdethos shares their personal data. |
| Withdrawal of Consent |
Right to withdraw previously granted consent at any time, in a simple and free manner, upon express request. Withdrawal does not affect processing carried out prior to the request. |
| Objection to Processing |
Right to object to processing carried out based on one of the legal grounds that waive consent (art. 7, IX, LGPD), when there are indications of irregularity or incompatibility with the stated purpose. |
| Review of Automated Decisions |
Right to request the review of decisions made solely on the basis of automated processing of personal data that affect their interests, such as decisions related to eligibility, risk, or profiling. |
| Restriction of Processing |
Right to request the restriction of processing when the accuracy of the data is contested, when the processing is unlawful or unnecessary, or when a formal objection has been submitted. |
Principles Governing Data Processing
Verdethos ensures that all personal data processing complies with the fundamental principles of the LGPD, which guide our technological, contractual, and compliance operations:
- Purpose: processing for legitimate and specific purposes, clearly informed to the data subject;
- Adequacy: compatibility of the processing with the informed purpose and with the context;
- Necessity (Data Minimization): collection limited to the minimum necessary for operational purposes;
- Transparency: easy access to information about data processing and sharing practices;
- Security and Integrity: adoption of appropriate technical and administrative measures (encryption, RBAC, security logs, and multi-factor authentication);
- Prevention: proactive actions to mitigate security risks and data breach incidents;
- Accountability: continuous demonstration of compliance and data governance practices;
- Accuracy: maintenance of correct, up-to-date, and verifiable data;
- Storage Limitation: retention only for the period necessary for the declared purposes, in accordance with internal retention policies and legal requirements (for example, audits, ESG reports, and EUDR).
How to Exercise Your Rights
Data subjects may exercise their rights by:
- Sending requests related to tenants’ content to the respective tenant (Controller); Verdethos supports the tenant’s response in accordance with our contract and applicable legislation.
- Sending requests related to Verdethos’ service operation data to privacy@verdethos.io.
- We respond within the timeframes required by law. We may verify identity; requests submitted by an authorized representative require appropriate proof.
Requests will be handled by Verdethos’ Privacy and Compliance Team, under the supervision of the Data Protection Officer (DPO). Additional proof of identity may be required when necessary to ensure the data subject’s security.
6. What Data Security Measures Do We Adopt?
Verdethos applies administrative, technical, and organizational measures proportional to risk to protect personal data, including encryption in transit and at rest when appropriate, access controls, monitoring, and incident response.
We are committed to applying technical, administrative, and organizational measures to ensure the confidentiality, integrity, availability, and ongoing resilience of the information
under our responsibility, in compliance with the standards of Law No. 13,709/2018 (LGPD), the best practices of the ANPD, and ISO/IEC standards 27001, 27002, and 27701.
Security Architecture and Access Control
Verdethos uses certified cloud infrastructure (AWS Cloud) with multiple layers of control to
ensure that only duly authorized Tenants have access to data and platform functionalities.
The main measures include:
- Role-Based Access Control (RBAC): ensures that each Tenant accesses only the information and functionalities strictly necessary for their role. Access profiles (for example, Publisher, Receiver, Compliance, Finance) are assigned and periodically reviewed by the administrators of each account (tenant).
- Secure Authentication and MFA (Multi-Factor Authentication): all access is validated through JWT tokens (AWS Cognito), and multi-factor authentication is required for sensitive profiles, significantly reducing the risk of unauthorized access or misuse of credentials.
Cryptographic Protection and Secure Storage
- Encryption of Data in Transit and at Rest: all personal data and documents are protected using AES-256 encryption during storage and TLS 1.2+ during transmission.
- Controlled Publication and Sharing: documents are shared through single-use access.
- Secure Storage and Redundancy: data are hosted on servers with high availability and geographic redundancy, located in Brazil (São Paulo/SP), and may, when necessary, be securely replicated to other countries, in compliance with the LGPD’s international data transfer requirements.
Audit, Monitoring, and Traceability
- Security Logs and Audit Trails: every action of viewing, downloading, publishing, or modifying data is recorded with UserID, TenantID, IP address, date and time, and event type, and stored in logs (PublicationAccessLog, InquiryAccessLog). These records enable forensic auditing, incident detection, and demonstration of regulatory compliance (EUDR, SEC, LGPD).
- Continuous Monitoring and Security Alerts: Verdethos performs automated anomaly detection, monitoring unauthorized access attempts and authentication failures, with real-time alerts sent to the security team.
- Periodic Audits and Assessments: regular internal and external audits are conducted based on data governance policies and the Incident Response Plan (IRP), ensuring continuous improvement of the security system.
Incident Management and Notification to the ANPD
In compliance with Article 48 of the LGPD, Verdethos maintains a Security Incident Response Plan (SIRP) that provides for:
- immediate detection and logging of security incidents;
- containment, investigation, and root cause analysis;
- if an incident affects tenants’ content, Verdethos will notify the tenant (Controller) without undue delay and will support any notifications the tenant must make under the LGPD/ANPD. If an incident concerns Verdethos’ service operation data (as Controller), Verdethos will notify as required by the LGPD/ANPD.
All incidents will be documented and handled transparently, with records of corrective and preventive actions.
Privacy and Compliance Culture
Verdethos maintains an internal awareness and continuous training program for employees, contractors, and partners, promoting the ethical and secure use of information.
All contracts entered into with third parties include specific data protection, confidentiality, and information security clauses, in compliance with Article 46, §2, of the LGPD.
Contact and Support
If you have any questions about Verdethos’ data security practices or wish to exercise any of your rights as a data subject, please contact our Data Protection Officer
(DPO):
privacy@verdethos.io.
Verdethos remains available to provide clarifications, receive requests, and ensure transparency at all stages of personal data processing.
Last updated: December 12, 2025.