Privacy

Privacy Statement

Last updated: March/2024

Introduction

We are committed to protecting your privacy.

This Privacy Notice explains what Personal Information we Deloitte Brazil collects about users, what we use it for, who we share it with and how we protect it. It also sets out your rights and who you can contact for more information or queries.

When used in this Privacy Notice, “we”, “us” and “our” refer to Deloitte Brazil. In this Privacy Notice, information about you, which may be referred to as personal data in some jurisdictions, is referred to as “Personal Information”. Personal Information refers to information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual.

We may also sometimes collectively refer to handling, collecting, protecting, and storing your Personal Information as “processing”  or “treatment" of such Personal Information.

By reading this Privacy Notice you will acknowledge our commitment with treating personal data in an ethical and responsible way, according with our principles and values and, above all, according with Law 13.709/2018 – General Personal Data Protection Law “LGPD”, and other applicable laws.

As used in this Privacy Notice, "Deloitte Network" refers to one or more of Deloitte Global, its network of member firms and their related entities. DTTL and each of its member firms are legally separate and independent entities. Please see www.deloitte.com/about for a detailed description of the legal structure of DTTL and its member firms. “Deloitte Brasil” refers to the Deloitte member firm that provides services in Brazil.

About other areas of Deloitte.com

Deloitte.com includes webpages provided by other DTTL member firms or their related entities, which are designated according to the geography identified in the upper right-hand corner of the webpage. These webpages are provided by the designated entities and are not the responsibility of DTTL. Such webpages, as well as other websites that may be linked to the Website, are not governed by this Privacy Notice. We encourage you to review the applicable privacy notices on those webpages, which will inform you about who the related controller is and provide further information with respect to its processing of your Personal Information.

What Personal Information we collect

We may collect and process your data because:

i.  you give it to us (for example, (1) through the webpages of this website or any other website or application of Deloitte Brazil which links to this Privacy Notice (collectively referred to as the “Website”), or (2) through any other mode of interacting with you relating to Deloitte communications, such as online or offline newsletters and magazines, that reference this Privacy Notice or link thereto (“Communication”));

ii.  other people give it to us (for example, other entities of the Deloitte Network or third- party service providers that we use to help operate our business); or

iii.  it is publicly available.

When other entities of the Deloitte Network or other third parties give us Personal Information about you, we make sure they have complied with the relevant privacy laws and regulations. This may include, for example, that it has informed you of the processing, and has obtained any applicable and necessary permission for us to process that information as described in this Privacy Notice.

Log information, cookies and web beacons: We may process Personal Information from you when you interact with the Website or Communications. For example, we or our service provider(s) may also use cookies (small text files stored in a user's browser) or web beacons (electronic images that allow us to count users who have accessed particular content and to access certain cookies) to collect aggregate data. Where applicable, additional information on how we may use cookies and other tracking technologies, and how you can control these, can be found in the Cookie Notice on the applicable Website. 

More information on how we use cookies and other tracking technologies on Deloitte Global’s Deloitte.com website can be found in its Cookie Notice

The Personal Information we process may include your: your name; age; date of birth; sex; email address; home address; Country of Residence; lifestyle and social circumstances (e.g. your hobbies); family circumstances (e.g. your marital status and dependents); employment and education details (for example, the organization you work for, your role and your educational details); financial and tax information (e.g. your income and tax residency); your posts on blogs, forums, wikis and any other social media applications and services we provide; your IP address; your browser type and language; your access times; details of the complaint; details of how you use our products and services; information relevant to entities in the Deloitte Network to provide services to you; details of how you use Deloitte products or services; details of how you like to interact with us and other similar information relevant to our relationship; information we collect when you access our facilities; CV; geolocation; certificate or license number; account number; photograph, video or audio recording identifiable to an individual, and any other information you voluntarily provide to us. We may also collect or obtain personal information from you because of the way you interact with us or others. and other similar information.

Where we do not usually seek to collect ‘sensitive’ or ‘special categories’ of Personal Information (e.g., data relating to race or ethnic origin, religious or philosophical beliefs, trade union membership, political opinions, medical or health conditions, or information specifying the sex life or sexual orientation of an individual), the Personal Information we collect may include so called ‘sensitive’ or ‘special categories’ of Personal Information, such as details about your:

  • dietary requirements (for example, when we would like to provide you with lunch during a meeting);
  • health (for example, so that we can make it easy for you to access our buildings, events).
  • sexual orientation (for example, if you provide us with details about your spouse or partner).

The types of personal data and special categories of personal data we collect may vary depending on the nature of the services we provide to you or our client, or how you use our website. In some rare circumstances, we may also collect other special categories of personal data about you, either because you provide that data to us or because we are obliged to collect it because of legal requirements imposed on us.

If you choose not to provide or, where applicable, object to the processing of the information we collect (see “Your Rights” section below), we may not be able to process your instructions or provide you with personalized communications, services or assistance.

We understand the importance of protecting the privacy and personal data of children and adolescents. Our website and services are not designed or intentionally directed at children and adolescents. It is not our policy to intentionally collect or store information about this type of audience, however, in eventual situations in which the collection and use of these types of personal data is necessary, such as in the provision of services that involve analysis of personal data of minor dependents, the treatment will take place in the best interests of the child and/or adolescent, in accordance with current legislation.

Information use

Use of Personal Information for our Website

We may use your Personal Information for the purposes of, or in connection with:

  • verifying your identity when you log in to a Website;
  • managing and/or improve our Website;
  • managing and promoting collaboration and communication;
  • providing and documenting training and qualifications;
  • tailoring the content of our Website to provide you with a more personalized experience; 
  • managing our relationship with you and responding to any request you submit through our Website; 
  • drawing your attention to information about products and services that may be of interest to you;
  • conducting data analysis including, for example, regarding usage of the Website and demographics analyses of Website users;
  • carry out due diligence checks relating to the services;
  • preventing fraud or criminal activity and safeguarding our technology systems and data security;
  • monitoring and enforcing compliance with applicable terms of use, and that only authorized parties are accessing the Website.
  • applicable legal or regulatory requirements;
  • requests and communications from competent authorities;
  • relationship management, which may involve: (i) sending you thought leadership or details of products and services provided by entities within the Deloitte Network that may be of interest to you; (ii) contacting you to receive feedback on these services; and (iii) contacting you for other market or research purposes; 
  • inviting you to attend events, seminars, participate in forums, etc.;
  • surveys on Deloitte or business or societal related or relevant topics;
  • recruitment and business development;
  • investigating or preventing security incidents;
  • conducting and analyzing our marketing activities;
  • protecting our rights and/or those of other entities of the Deloitte Network.

Legal basis for processing information

We are required by law to establish in this document the legal basis for processing your personal data, mainly related to the legal hypotheses defined by the LGPD. As a result, your personal data will be processed in the following cases:

  • by providing your consent to the processing of your data, for example, to grant you access to a platform maintained by the Deloitte Network or to make marketing material available. If you no longer wish to receive any marketing material from us, simply click on the unsubscribe function contained in the communication or email received.
  • when there are legitimate interests of the Deloitte Network, in offering and delivering our services to you or our client, as well as for the effective and lawful functioning of our business, provided that such interests are not outweighed by your interests, rights and fundamental freedoms.
  • compliance with applicable legal and regulatory obligations that may require the collection, storage and sharing of your personal data in order to comply with legal and regulatory provisions, such as (i) maintaining records for tax purposes or providing information to a public body or law enforcement body; (ii) compliance with labor and social security obligations; (iii) compliance with obligations to combat corruption, money laundering, fraud and irregular conduct.
  • to execute any contract, as well as to provide our services to you or our client.
  • to regularly exercise our rights, such as, for example, to exercise our right to defend ourselves in any judicial or administrative process.
  • protection of the life or physical safety of you or a third party;
  • protection of your health.

To the extent that we process any sensitive Personal Information relating to you for any of the purposes described above, we will do so because: (i) you have given us your explicit consent to process that data; (ii) we are required by law to process this data; (iii) processing is necessary for the establishment, exercise or defense of legal claims; (iv) we need to guarantee fraud prevention and security of the holder; (v) we are protecting the life or physical safety of the holder or third party; or (vi) we are exercising health protection, exclusively, in a procedure carried out by health professionals, health services or health authorities.

Please note that in certain circumstances it may still be legally acceptable for us to continue processing your information for separate purposes even if you have withdrawn your consent, if one of the other legal bases described above applies.

Sending you marketing information

We and other members of the Deloitte Network may use your information from time to time to inform you by letter, telephone, email and/or other electronic methods about products and services (including those of third parties) that may be of interest to you. Where we are legally required to obtain your consent to provide you with certain marketing materials, we will only provide you with those marketing materials when we have obtained such consent from you.

You may request at any time that we not send you marketing information by following the unsubscribe instructions in our communications or by contacting us using the “Contact Information” section below.

Disclosure of information to third parties

In connection with one or more of the purposes described in the “Use of Information” section above, we may disclose details about you to: other members of the Deloitte Network for legitimate business purposes; third parties that provide services to us and/or the Deloitte Network; as part of a corporate transaction (such as a sale, divestiture, reorganization, merger or acquisition); competent authorities (including courts and authorities that regulate us or another member of the Deloitte Network) and other third parties who reasonably require access to Personal Information relating to you for one or more of the purposes described in the “Use of information” section above.

We may also need to disclose your personal data if required to do so by law, regulator or during legal proceedings.

Please note that some of the recipients of your personal data mentioned above may be located in countries outside Brazil or outside the European Union, whose laws may not offer the same level of data protection. In such cases, we will ensure that we take all possible steps to protect your personal data in accordance with our legal obligations. When the recipient is not a member of the Deloitte Network, the appropriate safeguard may be a data transfer agreement with the recipient, based on standard contractual clauses.

We also provide further details about the transfers described above and the appropriate safeguards used by Deloitte in respect of such transfers via Privacy Form.

We may share non-personal, de-identified and aggregated information with third parties for a variety of purposes, including data analysis, research, contributions, eminence content and promotional purposes.

Selling of information

We do not sell your personal information.

Blogs, forums, wikis, and other social media

The Website may host various blogs, forums, wikis and other social media applications or services that allow you to share content with other users (collectively referred to as “Social Media Applications”). Any Personal Information or other information that you contribute to any Social Media Application can be read, collected and used by other users of that Social Media Application over whom we have little or no control. Therefore, we are not responsible for any other user's use, misuse or misappropriation of any Personal Information or other information that you contribute to any Social Media Application.

Privacy practices of third parties

This Privacy Notice addresses only the use and disclosure of information we collect through your interaction with the Websites or Communications. Other websites or applications that may be accessible through links from the Websites and Communications have their own privacy notices and Personal Information collection, use and disclosure practices. We encourage you to familiarize yourself with the privacy notices provided by these other parties prior to providing them with information.

Do not track

"Do Not Track" is a preference you can set in your web browser to let websites and applications you visit know that you do not want them collecting information about you. The Websites do not currently respond to a "Do Not Track" or similar signal.

Information security

We use a range of physical, electronic and managerial measures to keep your Personal Information secure, accurate and up to date. These measures include:

  • education and training to relevant staff so they are aware of our privacy obligations when handling Personal Information;
  • administrative and technical controls to restrict access to Personal Information on a ‘need to know’ basis;
  • technological security measures, including fire walls, encryption and anti-virus software; and
  • physical security measures, such as staff security passes to access our premises.

Although we use appropriate security measures once we have received your Personal Information, the transmission of data over the internet (including by e-mail) is never completely secure. We endeavor to protect Personal Information, but we cannot guarantee the security of data transmitted to us or by us over the internet.

Information retention

We will keep your personal data on our systems for the longest of the following periods:

(i) as long as it is necessary for the relevant activity or services in terms of the execution of contracts, preliminary procedures or legitimate interests;

(ii) any retention period required by law;

(iii) for the period permitted by law for the regular exercise of rights in judicial, administrative or arbitration proceedings;

(iv) while your consent is valid, in applicable cases;

(v) in accordance with current legislation.

Your rights

You have various rights in relation to your Personal Information. In particular, you have a right to:

  • obtain confirmation that we are processing your Personal Information and request a copy of the Personal Information we hold about you;
  • ask that we update the Personal Information we hold about you, or ask that we correct such Personal Information that you think is incorrect or incomplete;
  • ask that we delete Personal Information that we hold about you, or restrict the way in which we use such Personal Information; withdraw consent to our processing of your Personal Information (to the extent such processing is solely based on previously obtained consent);
  • receive a copy of the Personal Information concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and to transmit such Personal Information to another party (to the extent the processing is based on consent or a contract); and
  • object to our processing of your Personal Information.

To help us maintain the accuracy of your Personal Information, please contact us by using the “Contact information” section below if any of your personal details have changed.

If you are not satisfied with the way we treat your personal data or with any question or request related to your privacy, you can register your complaint or request to our DPO/In-Charge, Cristina Arantes de Almeida Berry, through the Privacy Form.

Verification of Personal Information requests

For certain Personal Information requests, we must first verify your identity before processing your request. To do so, we may ask you to provide us with your full name, contact information, and relationship to Deloitte. Depending on your request, we may ask you to provide additional information. Once we receive this information, we will then review it and determine whether we are able to match it to the information Deloitte maintains about you to verify your identity.

Contact information

To exercise any of your rights, or if you have other questions about the use of your personal data, please contact us or contact our DPO/Manager, Cristina Arantes de Almeida Berry, through the Privacy Form.

Changes to this Privacy Notice

We may modify or amend this Privacy Notice from time to time.

To let you know when we make changes to this Privacy Notice, we will amend the date at the top of this page. The new, modified, or amended Privacy Notice will apply from that revision date. Therefore, we encourage you to periodically review this Privacy Notice to be informed about how we are protecting your information.

By providing information through this website, you agree to the information described above.