SUIDChain Privacy and Personal Data Protection Policy

 

Privacy and the protection of personal data are important to SUIDChain.

This Privacy Policy explains how we collect, use, store, share, and protect personal data related to the use of the website, the platform, SUIDs, SUID Passes, QR codes, APIs, integrations, and other services provided by SUIDChain.

This Policy should be read in conjunction with the Terms of Use, the Personal Data Processing Agreement (DPA), the commercial contracts, the Cookie Notice, and any other documents applicable to the contracted services.

1. About Us

SUIDChain is a platform for digital identification, traceability, and data analytics for products, batches, collections, and supply chains.

Through the Sustainable Unique Identifier (SUID), the platform makes it possible to organize, link, and provide information on, among other things:

  • source;
  • authorship;
  • production;
  • materials and raw materials;
  • territory;
  • logistics;
  • compliance;
  • socio-environmental impact;
  • market evidence;
  • commercial presence of the registered products.

For the purposes of this Policy, SUIDChain is operated by:

Sautlink Information Technology and E-Commerce Import and Export, Ltd.
CNPJ: 12.031.849/0001-01
Address: Rua Prof. José Leite e Oiticica, 530, Conj. Jarecu 221, São Paulo, SP, ZIP Code 04705-080
Privacy andDataSubject Support Channel: contato@sautlink.com
Data Controller: [INSERT NAME OR COMPANY, WHEN APPLICABLE]

In this Policy, the company may be referred to as “SUIDChain,” “we,” “our,” or “us.”

2. Applicable Law

SUIDChain’s processing of personal data will be conducted in accordance with Brazilian law, specifically:

  • Law No. 13,709/2018 — General Personal Data Protection Law — LGPD;
  • Law No. 12,965/2014 — Brazilian Civil Rights Framework for the Internet;
  • Decree No. 8,771/2016;
  • Law No. 8,078/1990 — Consumer Protection Code, where applicable;
  • Law No. 8,069/1990 — Statute on Children and Adolescents;
  • Law No. 15,211/2025 — Digital Statute for Children and Adolescents, where applicable;
  • regulations, resolutions, and guidelines issued by the National Data Protection Agency (ANPD).

When a particular transaction involves data subjects or organizations located in other countries, foreign data protection laws may also apply, without superseding Brazilian law when its application is mandatory.

3. To Whom This Policy Applies

This Policy applies to individuals who:

  • visit the SUIDChain website;
  • view public product pages;
  • read QR codes linked to SUIDs;
  • access a SUID Pass;
  • request a contact, quote, presentation, or demo;
  • create or use accounts on the platform;
  • represent clients, partners, or contracting organizations;
  • work as artisans, producers, suppliers, or employees;
  • are members of registered cooperatives, associations, communities, or production chains;
  • use APIs, integrations, or features connected to SUIDChain;
  • receive institutional, commercial, or support communications;
  • participate in programs, pilot projects, projects, events, or initiatives related to SUIDChain.

4. Principles Adopted

SUIDChain seeks to process personal data in accordance with the principles set forth in the LGPD, including:

  • purpose;
  • suitability;
  • need;
  • open access;
  • data quality;
  • transparency;
  • safety;
  • prevention;
  • non-discrimination;
  • accountability and transparency.

This means that we seek to collect and use only the data necessary for legitimate, specific, and clearly defined purposes.

5. SUIDChain’s Roles in Data Processing

Depending on the activity being carried out, SUIDChain may act as a controller or processor of personal data.

5.1 SUIDChain as a controller

SUIDChain acts as a controller when it makes decisions regarding the purposes and means of processing, for example, to:

  • create and manage user accounts;
  • respond to contacts and requests;
  • present proposals and demonstrations;
  • handle billing and contract management;
  • manage relationships with customers and partners;
  • protect the platform against fraud and unauthorized access;
  • maintain access and security logs;
  • analyze the use of the website and the platform;
  • send institutional or commercial communications;
  • comply with legal and regulatory obligations;
  • to exercise or defend rights.

5.2 SUIDChain as an operator

SUIDChain may act as a data controller when a company, brand, cooperative, association, organization, institution, or project uses the platform to process personal data under its responsibility.

This could happen, for example, when a customer enters data regarding:

  • artisans;
  • producers;
  • suppliers;
  • employees;
  • cooperative members;
  • project participants;
  • representatives of organizations;
  • other people involved in a production chain.

In these situations, the client will generally be the controller, and SUIDChain will handle the process in accordance with:

  • the client's lawful and documented instructions;
  • the contract entered into between the parties;
  • the Personal Data Processing Agreement (DPA);
  • account settings;
  • the features included in the contract;
  • the applicable law.

The customer must ensure that it has a legal basis for collecting, recording, sharing, and, where applicable, publishing the personal data entered into the platform.

The fact that the client acts as a controller does not relieve SUIDChain of its legal responsibilities for the operations it carries out as a processor.

6. Personal information we may collect

The data processed may vary depending on how the website, platform, and services are used.

6.1 Registration and Account Information

We may collect:

  • full name;
  • email;
  • phone;
  • position or role;
  • company or organization;
  • CPF, when necessary;
  • CNPJ and the organization's registration information;
  • username;
  • password stored securely;
  • plan or service purchased;
  • account preferences;
  • language;
  • country;
  • users and permissions;
  • access and usage history.

SUIDChain should not store passwords in plain text.

6.2 Contact and Relationship Information

When someone contacts us, we may process:

  • name;
  • email;
  • by phone or WhatsApp;
  • company or organization;
  • position;
  • subject of the request;
  • message content;
  • service history;
  • information provided during meetings, presentations, or demonstrations;
  • records needed to track the request.

6.3 Traceability Data

Customers will be able to enter information related to products, lots, collections, and supply chains, such as:

  • product name and description;
  • brand;
  • category;
  • SKU;
  • EAN, GTIN, ASIN, or other identifiers;
  • lot number;
  • collection;
  • production order;
  • materials and raw materials;
  • geographic origin;
  • country, state, and municipality;
  • community or territory;
  • dates of production, processing, updating, or issuance;
  • production processes;
  • logistics records;
  • information about suppliers;
  • certificates;
  • documents;
  • photographs;
  • videos;
  • files;
  • evidence of compliance;
  • sustainability and impact information;
  • indicators of market presence and validation.

Not all of this information constitutes personal data. However, some of it may identify or be related to individuals.

6.4 Information on artisans, producers, and members of the supply chain

Depending on the project and the settings defined by the client, the following may be processed:

  • name;
  • image;
  • voice, when video or audio is available;
  • professional activity;
  • organization, association, or cooperative;
  • role performed in the supply chain;
  • municipality, state, region, or territory of operation;
  • career path or history;
  • production techniques;
  • information about authorship;
  • participation in production;
  • testimonials;
  • records of participation in projects;
  • social impact information;
  • professional information authorized by the data subject.

The client must limit the information collected to what is necessary and consistent with the purpose of the project.

6.5 Sensitive Personal Data

SUIDChain is not designed to collect or process sensitive personal data.

Data related to racial or ethnic origin, religion, political opinion, union membership, health, sex life, genetics, or biometrics may only be processed when:

  • are actually necessary;
  • there is a specific legal basis;
  • the purpose is clearly defined;
  • additional security measures are implemented;
  • the processing is contractually authorized when SUIDChain acts as the data controller.

Descriptions of territory, community, culture, traditional techniques, or professional activities must not be used to create discriminatory profiles or to improperly infer sensitive data.

6.6 Data Collected When Querying a SUID Pass

When a person accesses a SUID Pass or scans a QR code, we may collect technical data, such as:

  • IP address;
  • date and time of access;
  • browser;
  • operating system;
  • device type;
  • pages viewed;
  • ID of the SUID accessed;
  • source email address;
  • approximate location derived from the IP address, when available;
  • browser language;
  • page interaction events;
  • security logs.

This data may be used for:

  • ensure the security of the consultation;
  • prevent fraud and abuse;
  • maintain technical records;
  • track visits;
  • produce aggregate statistics;
  • assess the reach of the products;
  • improve the user experience;
  • Generate metrics for the client responsible for the product.

Whenever possible, reports provided to customers will use aggregated information or information limited to what is necessary for the stated purpose.

6.7 Data from integrations

When a customer enables an integration, SUIDChain will be able to receive or send data via:

  • business management systems;
  • e-commerce platforms;
  • marketplaces;
  • inventory systems;
  • logistics solutions;
  • freight rate quotation services;
  • label printing services;
  • payment methods;
  • storage systems;
  • customer service tools;
  • Third-party APIs and services.

Data processing should be limited to the data necessary to carry out the authorized integration.

The customer may disable available integrations through their account or request that they be disabled, subject to technical and contractual conditions.

6.8 Financial and Billing Information

For contracting, billing, and payment, we may process:

  • name or business name;
  • CPF or CNPJ;
  • billing address;
  • financial officer's contact information;
  • subscription plan;
  • payment history;
  • invoices;
  • information required for billing;
  • Subscription status.

Complete card information may be processed directly by financial institutions or payment providers.

When a payment is processed by a third party, SUIDChain may only receive information such as confirmation, status, amount, and transaction ID.

6.9 Data Received from Partners or Third Parties

We may receive personal data from:

  • contracting companies;
  • cooperatives;
  • associations;
  • partner organizations;
  • embedded systems;
  • technology providers;
  • e-commerce platforms;
  • logistics providers;
  • event and program organizers;
  • publicly available sources, when their use is permitted.

Receiving data from third parties does not preclude the need for a legitimate purpose, a legal basis, and transparency toward the data subject.

7. Cookies and Similar Technologies

The website and platform may use cookies, pixels, server logs, local storage, and similar technologies.

Cookies can be classified as:

7.1 Necessary Cookies

They are used for:

  • to enable the website to function;
  • authenticate users;
  • keep sessions active;
  • preserve security settings;
  • prevent fraud;
  • ensure that the resources requested by the user are provided.

These cookies may be used without consent when they are strictly necessary for the operation or provision of the requested service.

7.2 Preference Cookies

They can be used to remind you of:

  • language;
  • region;
  • settings;
  • choices made by the visitor;
  • browsing preferences.

7.3 Analytics and Performance Cookies

They can be used to understand:

  • number of visits;
  • most visited pages;
  • how the pages work;
  • errors;
  • performance;
  • how to use the website and the platform.

7.4 Advertising and Marketing Cookies

When used, they can help:

  • measure campaigns;
  • limit ad repeats;
  • present content related to users' interests;
  • evaluate the results of promotional communications.

Non-essential cookies that require consent should only be enabled after the visitor has made their choice.

The cookie panel or banner must allow users, as applicable, to:

  • accept;
  • reject non-essential cookies;
  • manage preferences;
  • change your choices later.

Disabling certain cookies may affect non-essential features of the website.

More detailed information may be provided in a specific Cookie Notice or Cookie Policy.

8. SUID Passes and Public Information

The SUID Pass is a digital page linked to a product, batch, collection, process, or traceability record.

Depending on the client's settings, information such as the following may be made publicly available:

  • product name and image;
  • brand;
  • category;
  • source;
  • materials;
  • production processes;
  • lot or collection;
  • organization in charge;
  • territory;
  • evidence and certificates;
  • impact information;
  • attendance data or market validation;
  • name and professional profile of artisans or producers;
  • authorized professional photo;
  • authorized testimonials.

The customer responsible for registration must:

  • determine which information will be made public;
  • verify the accuracy of the data;
  • have a legal basis for publication;
  • obtain permission to use images, voice recordings, testimonials, or stories, when necessary;
  • notify the account holders about the public disclosure;
  • keep the information up to date;
  • respond to requests for corrections or removals.

The following should not be published in SUID Passes:

  • CPF;
  • ID;
  • passport;
  • personal documents;
  • banking information;
  • full home address;
  • home phone;
  • personal email address;
  • passwords;
  • health data;
  • information about children or adolescents;
  • sensitive personal data without a specific legal basis;
  • confidential information;
  • protected documents;
  • trade or industrial secrets;
  • information that could expose the data subject to undue risk.

SUIDChain may restrict, block, or remove content that:

  • violate the law;
  • improperly expose a person;
  • infringe on the rights of third parties;
  • were published without a legal basis;
  • compromise safety;
  • violate this Policy or the Terms of Use.

When SUIDChain receives a request regarding information published by a customer, it may forward the request to the responsible controller and take provisional measures to protect the data subject, when necessary.

9. Blockchain and Integrity Records

SUIDChain may use blockchain or other distributed ledger technologies to produce technical evidence of:

  • existence;
  • integrity;
  • authenticity;
  • date;
  • affiliation;
  • history of certain records.

Whenever technically feasible and appropriate, blockchain entries should be limited to:

  • hashes;
  • technical identifiers;
  • transaction references;
  • timestamps;
  • cryptographic proofs;
  • evidence of integrity.

SUIDChain is not intended to record personal data directly, in plain text, on a public or immutable blockchain.

The data presented in SUID Pass may remain stored in separate databases and be linked to a technical test recorded on the blockchain.

When a technical transaction that has already been recorded cannot be deleted due to the characteristics of the network being used, measures such as the following may be taken:

  • removal of information from the public page;
  • correction of the data stored in the associated systems;
  • deregistration;
  • block;
  • access restriction;
  • anonymization;
  • deletion of information stored outside the blockchain.

The customer should not enter personal information in fields intended for permanent or unchangeable records.

10. What we use personal data for

Personal data may be used for:

  • create and manage accounts;
  • authenticate users;
  • manage permissions;
  • provide the contracted services;
  • issue and manage SUIDs;
  • generate and make SUID Passes available;
  • generate QR codes;
  • process traceability information;
  • provide dashboards, reports, and metrics;
  • operate APIs and integrations;
  • respond to support requests;
  • present proposals and demonstrations;
  • execute contracts;
  • collect payments;
  • issue tax documents;
  • provide training and implementation;
  • maintain the security of the platform;
  • to prevent fraud, abuse, and unauthorized access;
  • investigate failures and incidents;
  • maintain access logs;
  • improve products, services, and the user experience;
  • generate aggregate statistics and analyses;
  • report changes to services;
  • send institutional communications;
  • send commercial communications, when permitted;
  • to comply with legal, regulatory, or judicial obligations;
  • to exercise or defend rights;
  • to protect the rights and security of SUIDChain, its customers, users, and third parties.

11. Legal Basis Used

The processing of personal data may be based on one or more of the legal grounds set forth in the LGPD, including:

  • consent;
  • compliance with a legal or regulatory obligation;
  • performance of a contract;
  • conducting preliminary procedures related to a contract;
  • regular exercise of rights;
  • protection of life or physical integrity;
  • health care, where applicable;
  • the legitimate interests of SUIDChain or third parties;
  • credit protection, where applicable;
  • fraud prevention and cardholder security;
  • other cases permitted by law.

The legal basis will be determined by taking into account:

  • the purpose;
  • the data category;
  • the relationship with the account holder;
  • the context of the treatment;
  • the risks involved;
  • the role played by SUIDChain.

When processing is based on legitimate interest, SUIDChain must assess:

  • the legitimacy of the purpose;
  • the need for treatment;
  • the holder's reasonable expectations;
  • the potential impacts on their rights;
  • the applicable safeguards and transparency measures.

When processing is based on consent, the data subject may withdraw that consent through the channels provided.

The revocation will not render previously carried out processing unlawful and will not prevent the retention of data when another applicable legal basis exists.

12. Data entered by customers

Customers should not enter personal data unless it is necessary, serves a legitimate purpose, and has an appropriate legal basis.

By entering third-party data, the customer represents that:

  • has a legal basis for the processing;
  • informed the data subjects about the use of their data;
  • has obtained consent when that is the applicable legal basis;
  • complies with the principles of purpose, appropriateness, and necessity;
  • keeps the data accurate and up to date;
  • has authorization to use images and testimonials, when necessary;
  • defined what information may be made public;
  • will take measures to ensure the rights of data subjects;
  • will not record data obtained illegally or through abusive means;
  • will not use the platform for discrimination or undue surveillance.

SUIDChain may request clarification, restrict processing, or remove content that violates:

  • the law;
  • this Policy;
  • the DPA;
  • the Terms of Use;
  • the rights of rights holders or third parties.

13. Data Sharing

SUIDChain may share personal data when necessary for the purposes described in this Policy.

Information may be shared with:

  • web hosting and cloud computing providers;
  • database services;
  • information security companies;
  • email and communication providers;
  • customer service platforms;
  • monitoring tools;
  • analytical tools;
  • video conferencing and scheduling platforms;
  • payment processors;
  • accounting and tax systems;
  • logistics services;
  • freight rate quotation services;
  • label printing services;
  • ERPs;
  • marketplaces;
  • integrated platforms;
  • consultants;
  • auditors;
  • meters;
  • legal advisors;
  • contracting companies;
  • data controllers;
  • public authorities, pursuant to a legal obligation or a valid request.

Suppliers acting as operators or sub-operators shall receive only the necessary data and shall be subject to obligations consistent with:

  • the purpose specified in the contract;
  • confidentiality;
  • safety;
  • the applicable law.

Some third parties may act as independent data controllers, particularly financial institutions, marketplaces, logistics providers, and platforms contracted directly by the customer.

SUIDChain does not sell or rent personal data as a product.

14. International Data Transfer

Due to the use of technology, cloud, communication, analytics, support, and integration services, certain data may be stored or processed outside of Brazil.

International data transfers must comply with the LGPD and ANPD regulations.

Depending on the operation, mechanisms such as the following may be used:

  • adequacy decision issued by the ANPD;
  • standard contractual clauses approved by the ANPD;
  • standard clauses recognized as equivalent;
  • specific contractual provisions that have been previously approved;
  • approved global corporate standards;
  • international legal cooperation;
  • performance of a contract;
  • regular exercise of rights;
  • protection of life;
  • specific and explicit consent, when legally valid;
  • other mechanisms authorized by law.

When Brazilian standard contract clauses are used, they must be incorporated into the applicable instruments in accordance with the ANPD’s official template.

SUIDChain must take reasonable measures to verify that the international recipient provides protection consistent with the nature of the data and the risks associated with the processing.

Additional information regarding specific transfers may be provided to the data subject upon request.

15. Retention and Disposal

Personal data will be retained for as long as necessary to:

  • to fulfill the stated purposes;
  • execute contracts;
  • keep accounts and services active;
  • to comply with legal or regulatory obligations;
  • maintain security records;
  • prevent fraud;
  • resolve disputes;
  • to exercise or defend rights;
  • respond to requests from authorities;
  • Perform backup and recovery procedures.

Deadlines may vary depending on:

  • the data category;
  • the purpose;
  • the contract;
  • the legal basis;
  • the user type;
  • the risk involved;
  • the applicable law.

When SUIDChain is subject to the data retention obligation set forth in the Brazilian Civil Framework for the Internet, application access logs will be maintained confidentially in a controlled and secure environment for the applicable legal period.

Once the purpose or retention period has ended, the data may be:

  • eliminated;
  • anonymized;
  • aggregates;
  • blocked;
  • retained on a limited basis when there is a legal obligation or a need to defend rights.

Deleting an account does not necessarily mean that all data will be immediately deleted.

Residual copies may remain temporarily in backups until they are replaced through normal retention cycles, without being used for any new purposes.

Anonymized data may be retained for statistical purposes, research, security, and service improvement, provided that it is not reasonably possible to re-identify the data subjects.

16. Information Security

SUIDChain implements technical and administrative measures designed to protect personal data against:

  • unauthorized access;
  • loss;
  • destruction;
  • amendment;
  • leak;
  • improper sharing;
  • unavailability;
  • unlawful or inappropriate treatment.

Depending on the nature and risk of the processing, the measures may include:

  • access control;
  • authentication;
  • credential management;
  • permission segregation;
  • protection of data in transit;
  • activity log;
  • backups;
  • monitoring;
  • system updates;
  • vulnerability fixes;
  • internal policies;
  • incident response procedures;
  • supplier evaluation;
  • restricting access based on professional needs;
  • business continuity and disaster recovery processes.

No system is completely immune to risks.

Users must also:

  • use strong passwords;
  • keep your credentials confidential;
  • review authorized users;
  • keep your devices secure;
  • Immediately report any suspected unauthorized access.

SUIDChain does not claim to hold any security certifications, seals, or audits that have not been formally obtained.

17. Security Incidents

In the event of a security incident involving personal data, SUIDChain will take measures to:

  • identify and contain the incident;
  • investigate their causes;
  • reduce potential impacts;
  • preserve records and evidence;
  • fix vulnerabilities;
  • assess the risks to data subjects;
  • document the measures taken.

When SUIDChain acts as a data controller and the incident could pose a significant risk or cause significant harm to data subjects, notifications will be made to the ANPD and to the data subjects within the timeframes and under the conditions established by applicable laws and regulations.

When SUIDChain acts as an operator, it will notify the controlling client without undue delay and provide the available information to assist with the assessment and necessary communications.

Communications to data subjects should use clear language and, where applicable, include the following information:

  • the nature of the incident;
  • the affected data categories;
  • the related risks;
  • the measures taken;
  • the recommendations to the incumbent;
  • the channel for obtaining information.

18. Rights of Data Subjects

Under the LGPD, the data subject may request, where applicable:

  • confirmation that processing is taking place;
  • access to data;
  • correction of incomplete, inaccurate, or outdated data;
  • anonymization of unnecessary, excessive, or improperly processed data;
  • block;
  • elimination;
  • portability, in accordance with applicable regulations;
  • information about public and private entities with which data was shared;
  • information about the option to withhold consent;
  • information about the consequences of a refusal;
  • withdrawal of consent;
  • deletion of data processed with consent, except as required by law;
  • objection to processing carried out in violation of the LGPD;
  • the right to review decisions made solely on the basis of automated processing that affect your interests;
  • information on the criteria and procedures for automated decisions, while respecting trade and industrial secrets;
  • submission of a petition or complaint to the ANPD.

These rights may be subject to limitations when retention or processing is necessary to:

  • compliance with a legal obligation;
  • regular exercise of rights;
  • fraud prevention;
  • safety;
  • protection of third-party rights;
  • compliance with an order issued by a competent authority;
  • other cases provided for by law.

When SUIDChain acts as an operator, the request may be forwarded to the responsible controller client.

To protect the account holder from fraud, we may request information necessary to verify your identity or authority to act on their behalf.

19. Automated Analytics and Data Intelligence

SUIDChain may use automated mechanisms to:

  • organize information;
  • identify inconsistencies;
  • sort records;
  • generate indicators;
  • generate reports;
  • present trends;
  • assist with operational analyses;
  • assist with business analysis;
  • support logistics decisions;
  • analyze traceability data.

These mechanisms will serve an informational and supportive purpose.

When a decision is made solely on the basis of automated processing that affects the interests of a natural person, the data subject may exercise the rights provided for in the LGPD.

SUIDChain must not use automated mechanisms to promote unlawful or abusive discrimination.

20. Children and Adolescents

The SUIDChain website and platform are not intended for children.

Accounts must be created by legally competent individuals or by authorized representatives of an organization.

Data on children and adolescents should not be entered into SUID Passes or traceability records without:

  • legitimate and necessary purpose;
  • consideration of the best interests of the child or adolescent;
  • appropriate legal basis;
  • transparency for those in charge;
  • enhanced security measures;
  • compliance with the LGPD, the Statute of Children and Adolescents, and the Digital Statute of Children and Adolescents.

When the law requires consent, it must be obtained in a specific and prominent manner from at least one parent or legal guardian.

Information about children and adolescents should not be published on public pages without a specific assessment of the risks and applicable legal conditions.

If improper handling is identified, SUIDChain may restrict, block, or delete the information.

21. Communications and Marketing

SUIDChain may send communications related to:

  • accounts;
  • contracts;
  • safety;
  • support;
  • changes to the platform;
  • maintenance;
  • events;
  • content;
  • research;
  • products and services.

Communications necessary for the performance of the contract, customer service, security, or compliance with a legal obligation may be sent regardless of whether consent has been given for marketing purposes.

Promotional communications will be sent in accordance with the appropriate legal basis and must include an option to unsubscribe.

Opting out of commercial communications will not prevent us from sending necessary operational or contractual messages.

22. Links, Integrations, and Third-Party Services

The website and platform may contain links to or integrations with third-party services.

These third parties may process data such as:

  • operators;
  • suboperators;
  • independent controllers.

Third-party services have their own policies and terms.

SUIDChain does not control the privacy practices of independent websites or platforms and recommends that its users review the respective privacy policies before providing personal data.

When the integration is contracted or enabled by the customer, the customer will also be responsible for evaluating the third party and the purposes of the data sharing.

23. Changes to This Policy

This Policy may be updated to reflect:

  • changes to the platform;
  • new features;
  • changes in internal processes;
  • use of new suppliers;
  • legal or regulatory changes;
  • ANPD decisions;
  • improvements in privacy and security practices.

The updated version will be posted on the website along with the date of the last revision.

When the changes have a significant impact on account holders, we may communicate the update via:

  • email;
  • notice on the platform;
  • message on the website;
  • another suitable channel.

24. How to Exercise Your Rights

For questions, requests, or complaints regarding personal data, please contact us through the following channels:

Email: contato@sautlink.com
Operator: Sautlink Tecnologia da Informação e Comércio Eletrônico Imp. e Exp. Ltda.
CNPJ: 12.031.849/0001-01
Address: Rua Prof. José Leite e Oiticica, 530, Conj. Jarecu 221, São Paulo, SP, ZIP Code 04705-080
Person in Charge: [INSERT NAME OR COMPANY, WHEN APPLICABLE]

Account holders may also use the SUIDChain Contact page.

The request should include the following information, whenever possible:

  • name of the account holder;
  • email address used on the platform;
  • company or related organization;
  • SUID or the page involved;
  • a clear description of the request;
  • the right you wish to exercise.

SUIDChain may request additional information necessary to:

  • locate the data;
  • verify the account holder's identity;
  • verify the representative's authority;
  • prevent fraud;
  • protect third-party data.

Requests will be responded to within the timeframes set forth in the applicable laws and regulations.

If the data subject believes that their request has not been adequately addressed, they may file a complaint with the National Data Protection Agency.

25. Final Provisions

This Policy shall be interpreted in accordance with Brazilian law.

If any provision is found to be invalid, it shall not affect the remaining provisions of this document.

This Policy is for informational purposes only and does not replace:

  • commercial contracts;
  • Terms of Use;
  • Personal Data Processing Agreements;
  • specific authorizations;
  • notices displayed during collection;
  • Documents required for specific transactions.

SUIDChain — Sustainable Unique Identifier

Traceability, digital identity, and intelligence to transform origin, production, and impact into verifiable evidence.