{"id":11706,"date":"2021-10-08T11:53:49","date_gmt":"2021-10-08T08:53:49","guid":{"rendered":"https:\/\/snov.io\/knowledgebase\/?p=11706"},"modified":"2024-07-05T16:29:05","modified_gmt":"2024-07-05T13:29:05","slug":"lgpd-faq-for-third-party-data-subjects","status":"publish","type":"post","link":"https:\/\/snov.io\/knowledgebase\/lgpd-faq-for-third-party-data-subjects\/","title":{"rendered":"LGPD FAQ (for third-party data subjects)"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">In some cases, our data processing activities fall under Brazilian data protection laws. Snov.io complies with Brazil\u2019s General Data Protection Act (LGPD) and implements appropriate technical and organizational measures to ensure secure processing and transfer of personal data.<\/span><\/p>\n<h2><b>What is the LGPD?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Brazil's General Data Protection Act (Lei Geral de Prote\u00e7\u00e3o de Dados), or LGPD, is a privacy and security law created for protection of personal data in Brazil. LGPD was enacted on August 14, 2018.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Under the LGPD, any information that makes it possible to identify an individual can be considered personal data.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The key definitions of the LGPD are similar to the GDPR. For example, there are two main roles that a company can take on when processing personal data -\u00a0 <\/span><b>data controller<\/b><span style=\"font-weight: 400;\"> and <\/span><b>data processor<\/b><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A <\/span><b>data controller<\/b><span style=\"font-weight: 400;\"> is an entity in charge of making the decisions regarding the processing of personal data, while a <\/span><b>data processor<\/b><span style=\"font-weight: 400;\"> is an entity that processes personal data on behalf of a data controller. However, unlike the GDPR, the LGPD does not explain the definition of a joint controller, but the concept of <\/span><b>joint controllership <\/b><span style=\"font-weight: 400;\">was introduced by ANPD (Brazil\u2019s data protection authority) in its guidelines.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If a company fails to comply with LGPD requirements, a national authority, i.e. ANPD may apply the administrative sanctions against such a company, including fines of up to 2% of the company\u2019s revenue in its last fiscal year, excluding taxes, capped at R$ 50,000,000 (approximately USD 10,000,000) per infraction.<\/span><\/p>\n<h2><b>How long do we process your personal data?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">We process your personal data either as a joint data controller with our clients or as a data processor on behalf of and under the directions of our clients.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When we act as a <\/span><b>data controller<\/b><span style=\"font-weight: 400;\"> jointly with other controllers, we store your personal data for the entire period the particular client uses our services and 3<\/span><span style=\"font-weight: 400;\"> months<\/span><span style=\"font-weight: 400;\"> after the termination of their account on our platform.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In some cases, two or more clients provide your data to us simultaneously. In such a case, we store your personal data during the entire period during which one of such clients uses our services and <\/span><span style=\"font-weight: 400;\">3 months<\/span><span style=\"font-weight: 400;\"> after.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When we act as a <\/span><b>data processor<\/b><span style=\"font-weight: 400;\">, we process your personal data only for the period of time specified by the client.<\/span><\/p>\n<h2><b>What is the legal basis for your personal data processing?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">When we act as a <\/span><b>joint data controller<\/b><span style=\"font-weight: 400;\"> with a client, we process your personal data on the basis of our, the clients\u2019, and your legitimate interests. These interests are specified in our <\/span><a href=\"https:\/\/snov.io\/privacy-policy\"><span style=\"font-weight: 400;\">Privacy Policy<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When we act as a <\/span><b>data processor<\/b><span style=\"font-weight: 400;\">, we process your personal data only on the \u0441lients\u2019 behalf and due to their directions.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We urge our clients to ensure the presence of the legal grounds for the processing of your personal data in accordance with requirements provided by <\/span><span style=\"font-weight: 400;\">Article 7 of the LGPD<\/span><span style=\"font-weight: 400;\"> and believe that clients have the appropriate legal basis to transmit your personal data to us, including by obtaining valid consent from data subjects to do so.<\/span><\/p>\n<h2><b>What rights do you have under the LGPD?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Article 18 of the LGPD<\/span><span style=\"font-weight: 400;\"> provides you with the following rights:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">right to confirmation of the existence of the processing;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">right to access the data;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">right to correct incomplete, inaccurate or out-of-date data;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">right to anonymize, block, or delete unnecessary or excessive data or data processed in non-compliance with the provisions of the LGPD;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">right to the portability of data to another service or product provider, by means of an express request;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">right to delete personal data processed with the consent of the data subject;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">right to obtain the information about the possibility of not giving consent and about the consequences of the refusal;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">right to obtain the information about public and private entities with which the controller has shared data;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">right to revoke consent.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">You may exercise these rights by submitting your request at <\/span><a href=\"mailto:snovio_dpo@snov.io\"><span style=\"font-weight: 400;\">snovio_dpo@snov.io<\/span><\/a> <span style=\"font-weight: 400;\">\u00a0<\/span><span style=\"font-weight: 400;\">or via live chat in the lower right corner.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Please note that we cannot fulfil the request if we cannot verify your identity and confirm the personal data relates to you. So make sure to provide your name, contact information, and details in your request. We process such information only to verify your identity and not for anything else.\u00a0\u00a0<\/span><\/p>\n<h2><b>Can you request to provide you with a copy of your personal data?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Yes, you can by submitting your request at <\/span><a href=\"mailto:snovio_dpo@snov.io\"><span style=\"font-weight: 400;\">snovio_dpo@snov.io<\/span><\/a> <span style=\"font-weight: 400;\">or via live chat in the lower right corner.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You may also request the following information regarding the processing of your personal data under the LGPD:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">the specific purpose of the processing;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">the type and duration of the processing, being observed commercial and industrial secrecy;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">identification of the controller;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">the controller\u2019s contact information;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">information regarding the shared use of data by the data controller and the purpose;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">responsibilities of the agents that will carry out the processing;\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">the data subject\u2019s rights;<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Most of this information is already provided in our <\/span><a href=\"https:\/\/snov.io\/privacy-policy\"><span style=\"font-weight: 400;\">Privacy Policy<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We are committed to providing you with a copy of your personal data within a period of 15 days from the date of your valid request, subject to commercial and industrial secrecy unless otherwise implied by Brazil\u2019s laws.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We cannot fulfil the request if we cannot verify your identity and confirm the personal data relates to you, so please make sure to provide your name, contact information, and details in your request. We process such information only to verify your identity and not for anything else.\u00a0<\/span><\/p>\n<h2><b>Can you delete your data?\u00a0<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Yes, you can by submitting a deletion request at<\/span> <a href=\"mailto:snovio_dpo@snov.io\"><span style=\"font-weight: 400;\">snovio_dpo@snov.io<\/span><\/a> <span style=\"font-weight: 400;\">, via live chat in the lower right corner, or by removing your email address manually via the <\/span><a href=\"https:\/\/app.snov.io\/clear-email\"><span style=\"font-weight: 400;\">Clear email<\/span><\/a><span style=\"font-weight: 400;\"> feature.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You have the right to anonymize, block, or delete unnecessary or excessive data or data that is not being processed in compliance with the LGPD. In your request, please provide enough details to allow us to understand your justifications, evaluate and respond to the request.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You also have the right to delete personal data processed with the consent of the data subject. You have a right to request permanent deletion of your data, subject to certain exceptions (for example, if we have other legal grounds to process your personal data.)<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We cannot fulfill the request if we cannot verify your identity and confirm the personal data relates to you, so please make sure to provide your name, contact information, and details in your request. We process such information only to verify your identity and not for anything else.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In some cases, our data processing activities fall under Brazilian data protection laws. Snov.io complies with Brazil\u2019s General Data Protection Act (LGPD) and implements appropriate technical and organizational measures to ensure secure processing and transfer of personal data. What is the LGPD? Brazil&#8217;s General Data Protection Act (Lei Geral de Prote\u00e7\u00e3o de Dados), or LGPD, [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[620],"tags":[],"_links":{"self":[{"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/posts\/11706"}],"collection":[{"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/comments?post=11706"}],"version-history":[{"count":0,"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/posts\/11706\/revisions"}],"wp:attachment":[{"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/media?parent=11706"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/categories?post=11706"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/snov.io\/knowledgebase\/wp-json\/wp\/v2\/tags?post=11706"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}