Privacy Policy and Cookie Policy

At Base, we value the privacy and security of your personal information. This Privacy and Cookie Policy ("Policy") outlines how we collect, use, store, and protect the personal data of our employees, customers, partners, and visitors. Our mission is to handle your information with the utmost respect and confidentiality, in compliance with applicable laws and regulations, such as the General Data Protection Law (LGPD).

We are committed to providing transparency about our privacy practices and ensuring that your information is always protected. We appreciate your trust in Base and are always available to clarify any questions you may have regarding our privacy practices.

Objective

The Privacy Policy ("Policy") aims to inform how Base Exchange ("Base") handles personal data collected through internet applications and to reaffirm its commitment to the privacy, confidentiality, and security of all those who use our institutional channels, including employees, potential clients, and potential employees.

All personal information will be processed in accordance with the applicable Brazilian legislation regarding privacy and personal data protection, particularly Law No. 12.965/2014, known as the "Brazilian Internet Civil Framework," and Law No. 13.709/2018, known as the General Data Protection Law ("LGPD").

Application and Scope

This Policy applies to the personal data processing activities of our employees, as well as our clients and their users, potential clients, potential employees, visitors to our website, users of our platform or support systems such as WhatsApp, Skype, Email, suppliers, and others.

Definitions and Abbreviations

Cookies

Cookies are files stored on your computer when you visit our website. When our website is visited, it sends the cookie to your computer or mobile device, where it is stored in a folder within your browser. Cookies do not transfer viruses or malware to your computer or mobile device because the information in a cookie does not change when moving between pages on the website, and it does not alter the functioning of your device. They act as logs (user activities) and are updated every time the website is accessed. We may collect information about your browsing when you consent to cookie collection through our website.

Why do we use Cookies?

We use cookies to analyze how users navigate our website, as well as to record and improve its performance and functionality. We may use cookies to track which pages on the website are most popular and what is the most effective way to link them. This also helps us identify if you found us through another website, allowing us to improve our future advertising campaigns.

Types of Cookies We Use

Necessary Cookies: These cookies are essential for the operation of our website. Without these, our website would not function properly. They are stored temporarily as session data and expire when the browser is closed.

Statistical Cookies: The information provided by analytical cookies allows us to analyze user behavior patterns, and this information is used to improve the overall user experience or identify areas of the website that need maintenance. This information is anonymous (it cannot be used to identify you and does not contain personal information such as your name or email address) and is only used for statistical purposes. Behavioral cookies are similar to analytical cookies and track your visit to the website, using this information to provide content tailored to your interests.

Preference Cookies: Preference cookies allow the website to remember information that alters its behavior or visual appearance, such as preferred language or region.

Processing of Personal Data

Why Does Base Exchange Process Personal Data?

Base is committed to offering high-quality products and services and works daily to enhance its security measures and ensure the protection of Personal Data necessary for its activities. Data security involves respect and commitment to the proper use of this information, ensuring that it does not exceed the expectations of the Data Subjects and the purposes for which it was shared.

In addition to legal compliance, we follow strict internal procedures and develop technologies suited to the volume and sensitivity of the data being processed.

When interacting with Base’s products and services, the user may transfer information containing their Personal Data through the available functionalities in the channels, and these collections are limited to the minimum necessary to achieve our purposes.

Whenever possible, we process anonymized information so that the Data Subject cannot be identified, considering the use of reasonable and available technical means at the time of processing (especially through cookies).

When registering, it is important that the user enters only the information requested by Base, ensuring that the information is true and up to date. The responsibility for the accuracy, precision, and authenticity of the information provided in our registrations lies with the user.

If you are a teenager, make sure to be assisted and obtain your parents' or guardians' consent before applying for a job or submitting any information.

2. What Personal Data Is Collected?

Base may collect personal data provided directly by the user, by third parties, or automatically collected depending on the service being provided.

The data collected may be of various types, depending on the user's interaction (through the website, systems, email, phone, third-party social media, among others), as described below:

For security purposes, Base may request additional data to prevent fraud attempts.

Purpose of Processing Personal Data

Base processes Personal Data primarily to offer products and services, facilitate commercial relationships, comply with contractual, legal, and regulatory obligations, and may, in certain cases, collect data for specific purposes, as outlined below:

Sharing of Personal Data

Given Base's business sector, there are a number of mandatory data sharing requirements with regulators and market agents, such as Authorized Participants, Clearing Members, Custody Agents, and Government Authorities. Additionally, Base partners with other companies to facilitate its operations and provide its services. As such, Personal Data may be shared with other companies, service providers, authorities, and regulatory bodies in accordance with the purposes of data collection and the roles of each agent within the market infrastructure relationship chain. Below are some situations in which Base shares Personal Data:



User Rights

As provided by Brazilian legislation, the User, as the data subject, has rights regarding their personal information, including the following:

  • Request confirmation of the existence of data processing: You can ask if your personal data is being processed.
  • Request a copy of your processed personal data: You can request a copy of the personal data that has been processed.
  • Request correction and/or rectification of personal data: If you identify that any of your personal data is incorrect, you can request its correction or update.
  • Request anonymization, blocking, or deletion of personal data: You can request that your personal data be anonymized, blocked, or deleted from the database.
  • Request deletion of personal data collected and used based on consent: You can request the deletion of data that was collected with your consent.
  • Withdraw consent or refuse to consent: If data processing requires your consent, you have the right to refuse consent or to revoke it at any time.
  • Object to certain data processing: You can oppose specific data processing activities.
  • To exercise these rights, Base may request additional information and documents in order to prevent fraud and comply with applicable legal provisions and guidelines from the National Data Protection Authority (ANPD).

    Base may refuse to fulfill a user’s request regarding the exercise of the rights listed above if there are legitimate reasons for doing so. Examples of legitimate reasons include: (a) if the disclosure of information would violate Base's or third parties' trade secrets; (b) if the request for anonymization, blocking, or deletion of data conflicts with legal or regulatory obligations applicable to Base, or would prevent the broad and unrestricted defense of Base’s or third parties' rights, including in disputes of any nature.

    Some requests may require a longer response time due to their complexity or potential impacts.

    Data Retention Periods

    Base follows the data retention periods for Personal Data in accordance with the applicable legislation.

    Personal Data is stored for the time necessary to fulfill the purposes for which it was collected, unless there is any other reason for its retention, such as the fulfillment of legal, regulatory, or contractual obligations, as long as these are based on a legal foundation.

    Periodically, Base technically analyzes the appropriate retention period for each type of Personal Data collected, considering its nature, the necessity of its collection, and the purpose for which it will be processed.

    International Transfer of Personal Data

    Base may transfer and process personal data in other countries, in accordance with the conditions set forth in the General Data Protection Law (LGPD) and will be subject to the obligations outlined in this Privacy Policy.


    Data Security

    Base adheres to all necessary security standards to preserve the confidentiality and integrity of Personal Data, as outlined in our applicable institutional policies, especially the Information Security and Cybersecurity Policy. This includes:

    Base follows security protocols and measures to protect Personal Data. Access to information will be restricted to authorized individuals who are trained to use this information appropriately. Employees who misuse the information, violating this Privacy Policy, will be subject to legal measures as well as the penalties outlined in Base's disciplinary and ethical procedures.

    Communications

    If you have any further questions, comments, or suggestions related to this Policy, or if you suspect improper use of your Personal Data, please contact Base Exchange through the support channels available on our website or directly with the Data Protection Officer at encarregadodedados@baseexchangebr.com.

    Base Exchange is not responsible for any false emails sent in its name, including misleading promises, fake offers, fraudulent forms, or any type of communication sent by third parties. Therefore, in case of doubt, please contact us through our official channels.

    Base Exchange may change this Privacy Policy at any time. Any time a relevant condition of this Privacy Policy is altered, those changes will be valid, effective, and binding once the new version is published on our website.

    Changes to this Privacy Policy

    Base may modify this Privacy Policy at any time. Whenever a relevant condition of this Privacy Policy is changed, those changes will be valid, effective, and binding once the new version is published on our website.

    To comply with the applicable data protection legislation, we inform you of the name and email address of the Data Protection Officer (DPO) at Base: Felipe Deco – encarregadodedados@baseexchnge.com.br. Through this address, you can exercise your data subject rights, request clarifications, and ask any questions regarding the LGPD.