How Correa de Araujo collects, uses, shares and protects personal data on https://iclex-wb.com and inside the platform, in compliance with Brazil's General Data Protection Law (LGPD — Law 13.709/2018).
This summary is informative and does not replace the full text below, which is what actually binds us.
We do not sell, rent or trade personal data, and we use no advertising cookies or third-party trackers.
We are the controller of our website and of account data; we are the processor of the data your company handles inside the platform.
Harassment reports and occupational health data have their own protection regime — distinct from the protection given to leads and to platform users — with a specific legal basis, need-to-know access and a record of every single view.
Confirmation, access, correction, erasure, portability, objection and withdrawal of consent — free of charge, through the DPO channel.
This Policy applies to ICLex's institutional website, the contact form, the authenticated area of the platform, and the reporting channel made available to client companies — in the latter case, exclusively as regards our own activity, as set out in the next section.
By using our services you acknowledge the practices described here. This document is not a blanket consent to any processing: where consent is the applicable legal basis, it will be requested specifically and prominently.
The distinction below determines who decides on the processing and where you should direct a request. It is the key to reading everything else in this document.
When acting as a processor, we handle data solely under the client company's documented instructions, set out in the contract and in a data processing agreement. We do not use that data for our own purposes, do not combine it across customers, and do not use it for marketing or to train artificial intelligence models.
| Role | When it applies | Examples of data |
|---|---|---|
| Controller | Processing that we decide on and carry out on our own behalf. | Website visitors; sales enquiries; platform users' account records; authentication and security logs; billing data of corporate customers. |
| Processor | Processing we perform on behalf of and under the instructions of the client company, which is the controller. | Report content; cases and investigations; evidence and its hashes; comments and tasks; psychosocial risks; occupational health data; data about employees and third parties involved. |
If you are an employee, contractor or third party of a company that uses ICLex and wish to exercise rights over data processed inside the platform, please contact your company's DPO. If you come to us directly, we will forward the request to the controller and support it technically, under art. 39 of the LGPD, without being able to decide on its behalf.
Not every data subject who interacts with ICLex is in the same position, so the protection that applies is not uniform. We distinguish three categories of data subjects, each under its own regime, and we never mix one category's data with another's.
This separation is not merely organisational: commercial (lead) databases and platform databases (cases, reports, user accounts) are kept in distinct environments and for distinct purposes, and no sales team has access to case or report content.
We collect only what each purpose requires, in line with the necessity principle (art. 6, III). The sets below describe what we process and how each one reaches us.
There is no checkout on this website and we do not process credit card or payment data: contracting is corporate, formalised through a contract and invoicing. Any page requesting payment details in our name should be treated as fraudulent and reported to us.
By the very nature of the service, the platform may receive sensitive personal data. We process this category on its own legal basis and under reinforced safeguards, and we do not use it for any purpose beyond the contracted investigation and compliance work.
Applicable legal bases, depending on the case: compliance with a legal or regulatory obligation (art. 11, II, “a”), notably Law 14.457/2022, which mandates a reporting channel and CIPA measures against sexual harassment, NR-1, which requires the management of occupational psychosocial risks, and Law 12.846/2013; regular exercise of rights, including in judicial, administrative or arbitral proceedings (art. 11, II, “d”); protection of health (art. 11, II, “f”); and specific, prominent consent (art. 11, I) where it is the only applicable basis.
Specific safeguards: access granted on a need-to-know basis, scoped by case and by department; a separate health compartment, enabled only when the client company opts into it; pseudonymisation and watermarking in exported reports; and a record of every view in the audit trail.
Every processing activity has a defined purpose and a corresponding legal basis. Where we rely on legitimate interests, we carry out and document the balancing test, limiting the processing to what is strictly necessary and safeguarding your rights and freedoms.
Marketing communications depend on your consent, collected unambiguously, and can be cancelled at any time in any message we send or through the DPO channel, with no impact on the contracted services.
| Purpose | Legal basis (LGPD) |
|---|---|
| Responding to an enquiry or a demo request | Preliminary steps relating to a contract, at the data subject's request (art. 7, V), and legitimate interests (art. 7, IX) |
| Providing and operating the platform for the contracting company | Performance of a contract (art. 7, V); as a processor, under the controller's instructions (art. 39) |
| Authenticating users, controlling access and preventing fraud and abuse | Legitimate interests in information security (art. 7, IX) and performance of a contract (art. 7, V) |
| Maintaining the audit trail, chain of custody and evidence integrity | Compliance with a legal and regulatory obligation (art. 7, II) and regular exercise of rights (art. 7, VI) |
| Receiving and investigating reports, including harassment, and mapping psychosocial risks | Legal and regulatory obligation (art. 7, II and art. 11, II, “a” — Law 14.457/2022 and NR-1) |
| Sending marketing communications, content and newsletters | Consent (art. 7, I), which may be withdrawn at any time |
| Understanding which pages, messages and channels on the institutional website generate more commercial contact (marketing effectiveness) | Legitimate interests (art. 7, IX), preferably over aggregated data; never used to make decisions about you individually |
| Measuring aggregate product usage and improving features | Legitimate interests (art. 7, IX), preferably over aggregated or anonymised data (art. 12) |
| Meeting tax, accounting and regulatory obligations | Compliance with a legal obligation (art. 7, II) |
| Defending our rights in judicial, administrative or arbitral proceedings | Regular exercise of rights (art. 7, VI and art. 11, II, “d”) |
We do not profile people for behavioural advertising, do not enrich our databases with data bought from data brokers, and do not use customer data to train artificial intelligence models.
We do not make decisions based solely on automated processing that affect a data subject's interests, under art. 20 of the LGPD. Classifications, prioritisations, alerts and suggestions shown by the platform are decision-support tools: triage, the conclusion of an investigation and any resulting measure are decided by identified people, with author and timestamp recorded in the audit trail.
The personalisation we apply is limited to functional preferences you set yourself — language, theme and the order of menu items. We do not build behavioural profiles to target advertising.
Should an automated decision nevertheless affect you, you may request review by a natural person and clear information about the criteria used.
Where the client company enables anonymous reporting, the channel requires no identification and follow-up is done through a protocol number. We do not use IP addresses, device fingerprinting or any other technical data to try to identify an anonymous reporter, and we do not correlate website browsing with the reports we receive.
Where a person chooses to identify themselves, their identity is treated as confidential and access is restricted to the people assigned to the investigation, with every view recorded. The ban on retaliation follows from Law 14.457/2022 and from the client company's internal policies — it is up to the company to adopt the corresponding protective measures.
Important warning: do not send harassment reports, wrongdoing reports or sensitive data to our commercial addresses or through the contact form. They do not offer the confidentiality, anonymity and audit-trail guarantees of your company's reporting channel.
Files and other data processed on the platform are stored on servers located in the United States and the European Union, operated by cloud infrastructure providers engaged by ICLex. These international transfers rely on arts. 33 and 34 of the LGPD, supported by contractual guarantees ensuring a level of protection compatible with Brazilian law, such as specific or standard contractual clauses.
Client companies may at any time request information about the current storage location and the safeguards adopted, and may address data residency requirements contractually.
We keep personal data only for as long as necessary for the stated purposes, for compliance with a legal or regulatory obligation, and for the regular exercise of rights. Once the period ends, data is irreversibly erased or anonymised.
We adopt technical and administrative measures proportionate to the risk, bearing in mind that we process sensitive data and investigation material. Among them:
No measure eliminates risk entirely. If you find a vulnerability, please tell us at the security address listed on the contact page: we welcome responsible disclosure and ask that you not run tests that degrade the service or expose other people's data.
We maintain an incident response plan covering containment, investigation, remediation and record-keeping. Where an incident may bring relevant risk or harm to data subjects, we will notify the Brazilian Data Protection Authority (ANPD) and the affected data subjects within a reasonable time, with the information required by art. 48 of the LGPD.
Where the incident involves data we process as a processor, we will notify the client company acting as controller without undue delay, providing the information it needs to meet its own notification duties.
The LGPD guarantees you the following rights at any time, free of charge, upon request (arts. 18 and 20):
We will reply immediately in simplified form, or within 15 days where a full statement is required (art. 19). We may ask for additional information to confirm your identity — always the minimum necessary, and only to avoid disclosing data to someone who is not the data subject. If the request concerns data we process as a processor, we will forward it to the controller company and support it in responding.
The platform is a corporate product intended for adults over 18 acting in a professional capacity, and is not directed at children or adolescents. We do not knowingly collect minors' data through the website.
If an investigation involves an adolescent — for instance an apprentice — processing will observe the data subject's best interests under art. 14 of the LGPD, and the instructions of the client company acting as controller.
You can speak directly with our DPO to exercise your rights, clarify any point in this Policy or raise a concern about personal data. Publishing this channel meets art. 41, § 1, of the LGPD.
We may revise this document to reflect legal, regulatory, technological or product changes. The current version and its date appear at the top of this page.
Material changes that broaden purposes or alter legal bases will be communicated through the usual channels — a notice in the platform, a communication to client companies, or email — and where the legal basis is consent, fresh consent will be requested. We keep previous versions and provide them on request.
This Policy is governed by Brazilian law, in particular Law 13.709/2018 (LGPD), Law 12.965/2014 (Internet Civil Framework) and, where applicable, Law 8.078/1990 (Consumer Protection Code). The courts of the data subject's domicile are elected for claims in which that prerogative is afforded to them; for all others, the courts of ICLex's registered office.
This document was originally drafted in Brazilian Portuguese. Versions in other languages are provided for convenience only; in the event of any conflict of interpretation, the Portuguese version prevails.