carregando...

Excelia Data Privacy Policy

LGPD Channel: lgpd@excelia.com.br

Version 1.0 | Author: Enzo Guimarães | Reviewed by: Afonso Chebib | Approved by: Leonardo Toscano | Date: August 1, 2025

1. About Excelia

Excelia Consultoria is a business consultancy specialized in generating value for companies at different stages of development — from complex restructurings to expansion processes and capital raising. With a strategic, multidisciplinary approach, Excelia combines executive experience, analytical insight, and execution capability to understand, transform, and resolve its clients’ challenges.

Its portfolio spans eight solutions: Turnaround and Interim Management (TGI), Governance & Human Value (GVH), Transformation Consulting (CET), Judicial Administration and Expert Assessments (AJP), M&A and Capital Markets (MMC), Operational and Financial Efficiency (EOF), Real Estate Consulting & Business (CNI), and Technical Assistance and Monitoring (ATM).

Excelia’s methodology is centered on three pillars: Understand, through in-depth data analysis and financial and operational diagnostics; Transform, by implementing action and restructuring plans aimed at generating sustainable value; and Resolve, by delivering concrete results, whether that means turning companies around, optimizing capital structures, or executing strategic transactions.

Excelia’s culture is guided by the values that form the company’s own name — EXperience, Capability, Equilibrium, Leadership, Integrity, and Attitude — reflecting its commitment to conducting every project with technical excellence and professional ethics. Its mission is straightforward: Generate value.

With a team that brings together specialists from a range of fields — finance, management, governance, legal, engineering, and human resources — Excelia positions itself as a trusted partner to business owners, investors, and stakeholders seeking solid, executable solutions. Each project is handled individually, with a focus on measurable results, confidentiality, and strategic alignment between purpose, performance, and value.

2. Purpose of the Privacy Policy

This Privacy Policy is intended to reaffirm Excelia’s commitment to protecting personal data and strategic data, and to transparency in handling such information, in accordance with Law No. 13,709/2018 — Brazil’s General Data Protection Law (LGPD) — and with market best practices.

This document accordingly describes, clearly and accessibly, how Excelia collects, uses, shares, stores, protects, and disposes of strategic data, ensuring that such processing is carried out lawfully, ethically, and responsibly. By publishing this policy, Excelia seeks to ensure that all data subjects understand the principles governing its practices and the measures adopted to keep the information in its custody secure.

3. Applicable Rules

Excelia fully complies with Brazilian privacy and data protection legislation, in particular the General Data Protection Law (Law No. 13,709/2018), the Brazilian Civil Rights Framework for the Internet (Law No. 12,965/2014), and other related regulations. Beyond legal requirements, the company adopts governance, compliance, and information security best practices consistent with international data protection standards.

4. Scope

This policy applies to all individuals whose personal and strategic data may be processed by Excelia, including clients, partners, suppliers, service providers, potential investors, job candidates, employees, and other individuals who interact with the company through its institutional channels.

5. Definitions and Types of Data Processed

For purposes of this Policy, the following are considered data subject to processing:

Personal Data: Information that identifies or may identify a natural person, such as name, national taxpayer ID (CPF), ID card (RG), address, phone number, email, banking details, and professional history. Where applicable, sensitive personal data may be processed, including racial or ethnic origin, health information, and genetic or biometric data, always with enhanced protection and in accordance with legal requirements. This data is processed for legitimate purposes, such as recruitment, personnel management and administration, payment processing, and compliance with legal and regulatory obligations. Internally, this includes information about candidates and employees — resumes, contact details, time records, performance reviews, banking data, and, where necessary, health information for occupational health purposes.

Client and Lead Data: Includes name, corporate taxpayer ID (CNPJ), contact information, financial data, and documents related to merger, acquisition, or restructuring processes. Data may also be collected for contact with financial institutions or investors, particularly in international dealings. In such cases, Excelia adopts anonymization measures or withholds the client’s identity until a confidentiality agreement is formalized.

Third-Party Data: Includes information about business partners, such as lawyers, auditors, insurance brokers, and financial institutions that collaborate with Excelia on projects, as well as data on potential investors or buyers. This data is processed solely for the execution and development of Excelia’s business activities.

6. Purposes and Legal Bases

Excelia uses the data it collects exclusively for legitimate purposes related to the services it provides. These purposes include: (a) planning and executing mergers, acquisitions, joint ventures, and capital-raising transactions; (b) conducting due diligence and asset valuations; (c) preparing management and progress reports for clients; (d) developing corporate transformation projects; (e) providing legal advisory in judicial and administrative proceedings; (f) recruiting and selecting job candidates; (g) administering payments, benefits, and labor obligations; (h) tracking time and resource allocation via timesheets; and (i) complying with legal and regulatory obligations.

The legal bases for data processing vary according to purpose: performance of a contract or pre-contractual procedures, compliance with a legal or regulatory obligation, Excelia’s legitimate interest in providing its services, and, where necessary, the data subject’s consent.

7. Data Collection and Processing

Data is collected through the completion of forms, submission of resumes, execution of contracts, or the exchange of information during meetings and communications. We also collect data through internal platforms such as Timesheet (tracking of hours worked), Podio (lead and project management), and Microsoft tools (Outlook, Teams, OneDrive, and SharePoint). All of these systems have access controls and log records, enabling traceability and auditing of changes.

Excelia applies the principles of purpose limitation and necessity, collecting only the information essential to each phase of a project. Sensitive employee data is kept under restricted access and used solely for personnel management purposes and compliance with legal obligations.

8. Data Sharing

Internally, Excelia’s directors have full access to data for strategic management purposes. Employees and service providers have limited access to the information necessary to carry out their duties; they do not receive sensitive data such as financial statements, CPF numbers, or full client financial information, except when working directly on projects that require this type of information. We share personal data with third parties only in the following circumstances:

Clients and parties involved in projects: we provide reports and documents containing only the information strictly necessary for the progress of the project, with client identities protected during the initial stages of contact. A client’s name is disclosed only after a non-disclosure agreement (NDA) has been signed between the parties.

Suppliers and partners: technology, accounting, legal, audit, banking, and other firms that contribute to service delivery. Before sharing any sensitive information, we require the signing of an NDA or equivalent confidentiality guarantees.

Regulatory or judicial authorities: when necessary to comply with a legal obligation or respond to requests from regulators and judicial authorities.

We do not sell personal data and are committed to not disclosing names or information that identifies our clients in preliminary contacts with interested parties (e.g., international investors) until NDAs or contracts have been formalized.

9. International Transfers

Although most of our clients are based in Brazil, in some cases we contact banks and investors abroad for capital raising or asset sales. In these transactions, we may transfer personal data to countries with data protection legislation that differs from Brazil’s. These transfers take place only after a confidentiality agreement has been concluded and when necessary to move the business forward.

Excelia seeks to ensure that its international partners observe data protection standards equivalent to those of the LGPD and enters into specific contractual clauses to that end.

10. Data Retention and Disposal

Personal data processed by Excelia will be kept active for as long as necessary to perform the contracted services and, after the contractual relationship ends, will remain stored for up to five years. This period applies to data on clients, prospects, leads, and employees, for the purpose of safeguarding rights, complying with legal obligations, and enabling any potential defense in judicial or administrative proceedings.

At the end of that period, the corresponding documentation and reports will be moved to a restricted, secure archive environment, accessible only to directors and legal teams, and kept solely for historical record-keeping and compliance purposes.

In cases involving litigation, audits, or specific legal obligations, data may be kept active for up to ten years, after which it will be archived under the same confidentiality and access-control conditions. Once archived, the company will periodically assess whether the information should continue to be preserved or should be permanently anonymized, always in accordance with legal deadlines and LGPD principles.

11. Information Security

Excelia adopts technical and administrative measures to protect data against unauthorized access, leaks, loss, alteration, or destruction.

Key measures include: strict, role-based access control, use of Multi-Factor Authentication (MFA), encryption of emails for sensitive communications, application of retention policies and link expiration for shared documents, sensitivity labeling of files (Microsoft Information Protection), auditing of access and download logs, and restriction of file sharing to authorized users only.

We use Microsoft 365 infrastructure (OneDrive, SharePoint, Teams, Outlook), which maintains encryption at rest and in transit and offers Data Loss Prevention (DLP) tools to block the transmission of sensitive data. We continually invest in employee training on information security best practices and apply internal acceptable-use policies for our systems, as described in our Best Practices Manual.

12. Data Subject Rights

Data subjects whose personal data is processed by Excelia have the right to request: (a) confirmation of the existence of processing; (b) access to their data; (c) correction of incomplete, inaccurate, or outdated data; (d) anonymization, blocking, or deletion of unnecessary data or data processed in noncompliance with the law; (e) portability of data to another service provider; (f) deletion of personal data processed with consent; (g) information about the entities with which we share data; and (h) review of automated decisions.

Excelia may request proof of identity to process such requests and will respond within a reasonable time, in accordance with legal deadlines.

13. Exercising Your Rights and Contact

If you would like to exercise any of the rights above or have questions about this Policy, please contact us at lgpd@excelia.com.br. This channel is available to data subjects, regulatory authorities, and business partners. Requests will be reviewed by the designated person in charge and answered within the timeframes set out in the LGPD.

Excelia does not currently have a formally appointed Data Protection Officer (DPO), but maintains a compliance and legal team that serves as the point of contact for privacy matters.

14. Changes to This Policy

Excelia reserves the right to amend this Privacy Policy at any time to reflect changes in legislation, in our internal practices, or in our services. Whenever material changes are made, we will publish the updated version of the Policy on our channels and, if necessary, notify data subjects directly.

The processing of personal data will continue to comply with applicable law and LGPD principles, including purpose limitation, necessity, transparency, security, and accountability.

15. Final Remarks

By using Excelia’s services or interacting with us through our channels, you acknowledge that you have read and understood this Privacy Policy. We are committed to ensuring that your data is handled with respect, security, and transparency, safeguarding the confidentiality of information while we provide high-quality advisory and consulting services. Should you have any questions, we are available at the address indicated above.

WhatsApp