Privacy Policies
PRIVACY AND COOKIES POLICY (LGPD/ANPD)
1. DATA CONTROLLER AND CONTACTS.
- Controller: INLAZE LTDA. (Commizzion) – CNPJ 61.239.904/0001-69
- DPO: dpo@commizzion.com
- Legal: legal@commizzion.com
- Support: brasil@commizzion.com
2. SCOPE.
- This policy applies to natural persons in Brazil who interact with the Platform and its website.
3. DATA PROCESSED.
- Identification and contact details
- Account and usage data (IP logs, timestamps)
- B2B operational data (invoicing, KYB/KYC)
- Marketing and support communications
- Cookies
4. PURPOSES AND LEGAL BASES FOR PROCESSING.
- Data is processed for the performance of a contract, to comply with legal obligations, for legitimate interests (subject to a balancing test), and, for non-essential cookies, based on user consent.
5. DATA SUBJECT RIGHTS.
- Data subjects have the right to confirmation of processing, access, correction, anonymization, portability, deletion, information about data sharing, and review of automated decisions.
6. DATA SHARING AND TRANSFERS.
- Data may be shared with service providers acting as processors. International data transfers are conducted with appropriate safeguards in place.
7. SECURITY AND INCIDENT RESPONSE.
- We implement technical and administrative security measures. The ANPD and affected data subjects will be notified of any data breach as required by law.
8. COOKIES AND CONSENT.
- A two-layer cookie banner is used: Level 1 (Accept/Reject/Manage) and Level 2 (granular controls). Non-essential cookies are disabled by default, and consent can be withdrawn at any time.
9. DATA RETENTION AND DELETION
- Data is retained only as long as necessary for the specified purposes or as required by law, after which it is securely deleted or anonymized.
ADDENDUM – DPA-LGPD (DATA PROCESSING AGREEMENT)
1. PARTIES AND ROLE.
- Commizzion acts as a Controller of Publisher data and, depending on the data flow, may act as a Controller or Joint Controller with Operators. The Publisher is the Controller of its own data.
2. INSTRUCTIONS AND PURPOSES.
- Data will be processed according to the written instructions of the Controller and for contractual and legal purposes.
3. SECURITY AND CONFIDENTIALITY.
- Reasonable security measures are in place, including encryption, access control, monitoring, segregation, and backups. All personnel and sub-processors are bound by confidentiality obligations.
4. SUB-PROCESSORS AND TRANSFERS.
- Sub-processors may include providers for cloud services, analytics, anti-fraud, KYC, and payment processing. International transfers are protected by safeguards accepted by the ANPD.
5. INCIDENTS NOTIFICATION, RIGHTS, AUDITS, RETENTION, AND LIABILITY.
- Notification: Incidents will be reported without undue delayNotification without undue delay.
- Cooperation: We will assist with data subject rights requests.
- Audits: Reasonable audits are permitted.
- Retention: Data is retained as required by law.
- Liability: Indirect damages are excluded, and liability is limited to the economic cap of the main agreement, except in cases of willful misconduct or gross negligence
6. CONTACTS.
- DPO: dpo@commizzion.com
Legal: legal@commizzion.com