Navora

Privacy Policy

How we collect, use and protect your information.

This Privacy Policy describes the NAVORA System, developed to run as a Web-based application. The NAVORA System collects, uses, stores, shares and disposes of Personal Data and General Data of Data Subjects, including employees, in compliance with the Brazilian General Data Protection Law (LGPD).

The NAVORA System is committed to protecting the privacy and personal data of Data Subjects whose information is collected and processed within the platform.

This Policy aims to clarify how personal data is collected, used, stored, shared and deleted, in compliance with Law No. 13,709/2018 — General Personal Data Protection Law (LGPD) — and the guidelines of the National Data Protection Authority (ANPD).

1. SCOPE

This Policy applies to all NAVORA System activities involving the processing of personal data in digital format, including:

  • Clients;
  • Employees, former employees and job candidates (for a fixed term);
  • System users.

2. PARTIES RESPONSIBLE FOR DATA PROCESSING

In compliance with the General Data Protection Law and the determinations of the National Data Protection Authority (ANPD), the Controller and DPO have been designated to handle matters regarding the NAVORA System, respectively:

  • Data Processing Officer (DPO) / Data Controller:
  • Name: OLIMPIO SOLUTION LTDA
  • Email: suporte@olympio.dev.br

2.1.

The Controller and the DPO are responsible for ensuring compliance with data protection legislation, responding to requests from Data Subjects, collecting and storing Personal Data, applying Information Security guidelines, ensuring the regular application of the Privacy Policy and other measures necessary to comply with the General Data Protection Law (LGPD) and related Laws.

3. PERSONAL DATA COLLECTED

The NAVORA System collects only the data strictly necessary for the performance of its pre-programmed functional activities and for compliance with legal obligations, including:

3.1.1. The System may collect personal data of:

  • Clients;
  • Platform users.
  • Log data (date and time of access)
  • IP address of your device (IP)

3.1.2. Collected data may include, but is not limited to:

  • Full name;
  • Email;
  • Document number (CPF, Passport, Country-of-Origin Registration);
  • Information required for contractual execution;
  • IP address;
  • Date and time of log

3.2.

The NAVORA System does not collect sensitive personal data, except where a future need is duly justified and communicated to the Data Subject.

4. PURPOSE OF PROCESSING

Personal data collected, based on the General Data Protection Law, is processed for the following purposes:

  • Compliance with legal, tax and labor obligations;
  • Administrative and operational management of the NAVORA System;
  • User account registration and management;
  • Communication with the user;
  • System maintenance and improvement.

4.1.

Personal data of Data Subjects may be processed beyond the list above, in order to comply with legal duties and other purposes set forth in Article 7 of the General Data Protection Law.

Processing of personal data shall follow all principles set out in Article 6 of the General Data Protection Law.

6. APPLICABLE LEGAL BASES

Processing of personal data carried out by the NAVORA System is grounded on the following legal bases of the General Data Protection Law (LGPD):

  • Execution of contract (art. 7, item V);
  • Compliance with legal or regulatory obligation (art. 7, item II);
  • Legitimate interest (art. 7, item IX);
  • Consent of the Data Subject, when applicable (art. 7, item I).

7. USE OF COOKIES

The NAVORA System uses exclusively cookies necessary for the full functioning of the system, collected on first access and re-notified after System updates over time.

7.1.

If the User refuses, they will be informed of possible problems that may affect application functionality and possible resource limitations, including breakage and sudden closure of the System.

7.2.

Includes as a necessary Cookie: JWT token for authentication; user identification; organizational context (multi-tenant) and language preference.

7.3.

Marketing or advertising tracking cookies are not used.

8. DATA STORAGE AND SECURITY

The NAVORA System is hosted on external servers in Amazon Web Services (AWS) infrastructure, specifically located in Ireland, and may vary according to resource usage; in this last option it may be made available in the North America (US East) Region.

8.1.

Data Security measures on the servers shall follow the guidelines of Amazon Web Services, Inc., the support and hosting provider of the NAVORA System. AWS is responsible for the physical security of the data centers, hardware, network and infrastructure maintenance (shared responsibility model).

9. DATA SHARING

The NAVORA System does not share data externally, keeping data always on AWS Servers with access restricted by User login and password, corresponding to the User's use and resource of the system, with each User / Client accessing only their corresponding data, individually.

9.1.

The NAVORA System does not commercialize, disclose or share personal data for marketing purposes or any other improper use.

9.2.

The Data Subject, through a Consent Term, will be aware of the sharing, processing and collection of personal data in a clear, objective and unequivocal manner.

9.3.

Data may be shared by force of law, judicial decision or strictly for technical operations of support and maintenance, including for AWS Servers.

10. RETENTION AND DISPOSAL PERIOD

Personal data is stored only for the time necessary to fulfill the purposes that justified its collection and to observe legal time limits, as follows:

  • During the term of the contract or service provision;
  • For the legal period determined by labor, tax or accounting obligations;

10.1.

After the period, legal determination or contractual termination, data is securely eliminated through definitive deletion.

10.2.

Digital data will be definitively deleted from the Server and eventually from the Backup, with prior notification to the Data Subject of the retained data.

10.3.

Data retained by the NAVORA System may be consulted by the Data Subject upon Request to the Controller / Data Officer (DPO), aiming at: Rectification; Modification; Sharing Request (or portability); Deletion Request;

10.4.

In the case of a Deletion Request, feasibility will be analyzed and may be denied if the deletion violates the terms of item 6 of this Privacy Policy.

10.5.

The NAVORA System uses delimited Data collection fields and is not responsible for data collected in excess by the User.

11. CONFIDENTIALITY AGREEMENT

Users and Employees must sign the Confidentiality Agreement to ensure secrecy, confidentiality and protection of the information accessed in the NAVORA System, processed or obtained by the User or Employee, in compliance with the General Personal Data Protection Law (Law No. 13,709/2018), the Marco Civil da Internet (Law No. 12,965/2014) and other information security regulations.

11.1.

The Confidentiality Agreement is signed at the time of contracting access to the NAVORA System and shall remain in force for up to one year after the termination of the Contract, regardless of the reason for its termination;

11.2.

The Confidentiality Agreement may be updated and sent to Users / Clients to be signed for purposes of updating, rectification or inclusion of new terms;

11.3.

The Confidentiality Agreement includes, in addition to Data security terms, terms aimed at the protection and security of industrial secrets of the NAVORA System.

12. DATA SUBJECTS' RIGHTS

Pursuant to Article 18 of the General Data Protection Law (LGPD), the data subject may, at any time, request:

  • Confirmation of the existence of processing;
  • Access to their data;
  • Correction of incomplete, inaccurate or outdated data;
  • Anonymization, blocking or elimination of unnecessary or excessive data;
  • Data portability to another service provider;
  • Revocation of consent, when applicable;
  • Information about the sharing and storage of their data.

12.1.

Requests must be sent to the Officer (DPO) / Controller through the contacts made available in this Privacy Policy.

13. INFORMATION SECURITY AND INCIDENTS

In the event of a Security Incident of the NAVORA System or notification of a possible data leak, the following points will be assessed to determine possible causes of the data leak:

  • Access controls;
  • Date and time of last access;
  • IP of last access.

13.1.

In the event of a security incident, Users will be notified by the System itself about errors, leakage and data loss, if it has occurred directly on the AWS Servers.

13.2.

Should an Incident occur, it will be reported to the National Data Protection Authority (ANPD) and to the affected data subjects, as set forth in Article 48 of the General Personal Data Protection Law (LGPD).

13.3.

In the event of an incident, the Data Subjects whose data may have been affected will be notified through official communication, by Email or Postal mail.

13.3.1.

The communication will detail which data of the Data Subject was affected, classified as: Loss, corrupted, transferred or tampered with, as well as date, time and other information necessary to clarify the occurrence to the Data Subject.

14. UPDATE AND VALIDITY OF THIS POLICY

This Policy will be updated periodically and may be updated, if necessary, before the scheduled update period, due to legal, technological or operational changes.

14.1.

The most recent version will always be available upon request to the Controller / DPO and on the NAVORA System communication channels.

14.2.

Updates will occur every 6 (six) months from the date of publication of the first version.

14.2.1.

Should an update occur before the scheduled period, the next date will be counted from the last update.

15. CONTACT FOR QUESTIONS OR REQUESTS

For requests related to the rights set forth in this Policy and in the General Data Protection Law (LGPD), the data subject may contact:

  • Data Officer (DPO) / Data Controller: OLIMPIO SOLUTION LTDA
  • Email: suporte@olympio.dev.br

16. APPLICABLE LAW

This Privacy Policy shall be governed and interpreted in accordance with Brazilian legislation, especially the General Personal Data Protection Law (Law No. 13,709/2018), Marco Civil da Internet (Law No. 12,965/2014), and Normative Acts of the National Personal Data Protection Authority (ANPD), without prejudice to other applicable legislation.

17. JURISDICTION

The forum of the Judicial District of Belo Horizonte, MG is hereby elected to settle any disputes arising from this Policy, with express waiver of any other, however privileged.

The User hereby declares to be over 18 (eighteen) years of age and to have read this document carefully and in full, fully aware of and providing free, express and informed agreement with the terms set forth herein. If you do not agree with this Privacy Policy, you must discontinue your access to the site and the services provided.

Last updated: 2026-05-07