Legal document

Privacy and Data Protection Policy

How Correa de Araujo collects, uses, shares and protects personal data on https://iclex-wb.com and inside the platform, in compliance with Brazil's General Data Protection Law (LGPD — Law 13.709/2018).

Effective from August 27, 2026Version 1.2

The 30-second summary

This summary is informative and does not replace the full text below, which is what actually binds us.

We do not sell data

We do not sell, rent or trade personal data, and we use no advertising cookies or third-party trackers.

Two distinct roles

We are the controller of our website and of account data; we are the processor of the data your company handles inside the platform.

Sensitive data protected

Harassment reports and occupational health data have their own protection regime — distinct from the protection given to leads and to platform users — with a specific legal basis, need-to-know access and a record of every single view.

Your rights, always

Confirmation, access, correction, erasure, portability, objection and withdrawal of consent — free of charge, through the DPO channel.

01

Scope and who this document applies to

This Policy applies to ICLex's institutional website, the contact form, the authenticated area of the platform, and the reporting channel made available to client companies — in the latter case, exclusively as regards our own activity, as set out in the next section.

By using our services you acknowledge the practices described here. This document is not a blanket consent to any processing: where consent is the applicable legal basis, it will be requested specifically and prominently.

  • It does not apply to third-party websites, apps or services we may link to.
  • It does not apply to each client company's own internal privacy, conduct or compliance policies — they are responsible for their own notices to data subjects.
  • It does not apply to anonymised data, which ceases to be personal data under art. 12 of the LGPD unless the anonymisation is reversed.
02

Our two roles: controller and processor

The distinction below determines who decides on the processing and where you should direct a request. It is the key to reading everything else in this document.

When acting as a processor, we handle data solely under the client company's documented instructions, set out in the contract and in a data processing agreement. We do not use that data for our own purposes, do not combine it across customers, and do not use it for marketing or to train artificial intelligence models.

RoleWhen it appliesExamples of data
ControllerProcessing that we decide on and carry out on our own behalf.Website visitors; sales enquiries; platform users' account records; authentication and security logs; billing data of corporate customers.
ProcessorProcessing we perform on behalf of and under the instructions of the client company, which is the controller.Report content; cases and investigations; evidence and its hashes; comments and tasks; psychosocial risks; occupational health data; data about employees and third parties involved.

If you are an employee, contractor or third party of a company that uses ICLex and wish to exercise rights over data processed inside the platform, please contact your company's DPO. If you come to us directly, we will forward the request to the controller and support it technically, under art. 39 of the LGPD, without being able to decide on its behalf.

03

Two categories of data subjects, two protection regimes

Not every data subject who interacts with ICLex is in the same position, so the protection that applies is not uniform. We distinguish three categories of data subjects, each under its own regime, and we never mix one category's data with another's.

  • Reporters: maximum protection regime. Where the client company enables anonymous reporting, there is no identity to protect — anonymity is structural, not just a promise. Where a person identifies themselves, that identity is sensitive data, handled on a need-to-know basis, with no correlation whatsoever to the institutional website or to commercial databases, and any form of retaliation is prohibited. See the "Reporting channel" section for the specific safeguards.
  • System users and operators: ordinary personal-data protection regime. Investigators, administrators, employees and other users with a platform account have their registration, access and activity data protected by the measures described in this document, with role-based access control, an audit trail, and the data subject rights covered in the corresponding section.
  • Prospects and commercial contacts (leads): data from whoever fills in the contact form or requests a demo on the institutional website. Used exclusively for commercial purposes — replying to the enquiry, qualifying the opportunity and, with consent, sending marketing communications. Never combined, cross-referenced or correlated with report, case or investigation data.

This separation is not merely organisational: commercial (lead) databases and platform databases (cases, reports, user accounts) are kept in distinct environments and for distinct purposes, and no sales team has access to case or report content.

04

Personal data we process

We collect only what each purpose requires, in line with the necessity principle (art. 6, III). The sets below describe what we process and how each one reaches us.

  • Provided by you on the website: name, work email, company and job title, phone number (optional) and the content of the message you write.
  • Platform account data: name, email, corporate login provider identifier (for example Google Workspace or Microsoft Entra ID), organisation, role and permissions, department, and language and theme preferences.
  • Collected automatically: IP address, date and time of access, user agent, routes visited, request correlation identifier and authentication logs.
  • Audit trail: author, action, affected entity and timestamp of every relevant operation in the platform — a record that is indispensable to the chain of custody and to the defensibility of investigations.
  • Processed as a processor, on behalf of the client company: report content and category, people and witnesses mentioned, attached evidence and its hashes, answers to the channel's form questions, comments, tasks, risks and action plans.

There is no checkout on this website and we do not process credit card or payment data: contracting is corporate, formalised through a contract and invoicing. Any page requesting payment details in our name should be treated as fraudulent and reported to us.

05

Sensitive personal data (art. 11 of the LGPD)

By the very nature of the service, the platform may receive sensitive personal data. We process this category on its own legal basis and under reinforced safeguards, and we do not use it for any purpose beyond the contracted investigation and compliance work.

Applicable legal bases, depending on the case: compliance with a legal or regulatory obligation (art. 11, II, “a”), notably Law 14.457/2022, which mandates a reporting channel and CIPA measures against sexual harassment, NR-1, which requires the management of occupational psychosocial risks, and Law 12.846/2013; regular exercise of rights, including in judicial, administrative or arbitral proceedings (art. 11, II, “d”); protection of health (art. 11, II, “f”); and specific, prominent consent (art. 11, I) where it is the only applicable basis.

  • Health and occupational health data, including psychological distress and information relating to psychosocial risk assessment.
  • Reports of moral and sexual harassment, which may reveal information about the sex life of the people involved.
  • Information that may reveal racial or ethnic origin, religious belief, political opinion or trade-union membership, when spontaneously narrated in a report.

Specific safeguards: access granted on a need-to-know basis, scoped by case and by department; a separate health compartment, enabled only when the client company opts into it; pseudonymisation and watermarking in exported reports; and a record of every view in the audit trail.

06

Purposes and legal bases for processing

Every processing activity has a defined purpose and a corresponding legal basis. Where we rely on legitimate interests, we carry out and document the balancing test, limiting the processing to what is strictly necessary and safeguarding your rights and freedoms.

Marketing communications depend on your consent, collected unambiguously, and can be cancelled at any time in any message we send or through the DPO channel, with no impact on the contracted services.

PurposeLegal basis (LGPD)
Responding to an enquiry or a demo requestPreliminary steps relating to a contract, at the data subject's request (art. 7, V), and legitimate interests (art. 7, IX)
Providing and operating the platform for the contracting companyPerformance of a contract (art. 7, V); as a processor, under the controller's instructions (art. 39)
Authenticating users, controlling access and preventing fraud and abuseLegitimate interests in information security (art. 7, IX) and performance of a contract (art. 7, V)
Maintaining the audit trail, chain of custody and evidence integrityCompliance with a legal and regulatory obligation (art. 7, II) and regular exercise of rights (art. 7, VI)
Receiving and investigating reports, including harassment, and mapping psychosocial risksLegal and regulatory obligation (art. 7, II and art. 11, II, “a” — Law 14.457/2022 and NR-1)
Sending marketing communications, content and newslettersConsent (art. 7, I), which may be withdrawn at any time
Understanding which pages, messages and channels on the institutional website generate more commercial contact (marketing effectiveness)Legitimate interests (art. 7, IX), preferably over aggregated data; never used to make decisions about you individually
Measuring aggregate product usage and improving featuresLegitimate interests (art. 7, IX), preferably over aggregated or anonymised data (art. 12)
Meeting tax, accounting and regulatory obligationsCompliance with a legal obligation (art. 7, II)
Defending our rights in judicial, administrative or arbitral proceedingsRegular exercise of rights (art. 7, VI and art. 11, II, “d”)

We do not profile people for behavioural advertising, do not enrich our databases with data bought from data brokers, and do not use customer data to train artificial intelligence models.

07

Personalisation and automated decisions

We do not make decisions based solely on automated processing that affect a data subject's interests, under art. 20 of the LGPD. Classifications, prioritisations, alerts and suggestions shown by the platform are decision-support tools: triage, the conclusion of an investigation and any resulting measure are decided by identified people, with author and timestamp recorded in the audit trail.

The personalisation we apply is limited to functional preferences you set yourself — language, theme and the order of menu items. We do not build behavioural profiles to target advertising.

Should an automated decision nevertheless affect you, you may request review by a natural person and clear information about the criteria used.

08

Cookies and local storage

We use the bare minimum. There are currently no advertising cookies, social network pixels or third-party trackers on our pages, which is why we show no consent banner — there is no non-essential cookie to consent to.

If and when we adopt an analytics tool or any non-essential cookie, we will update this document and ask for your consent beforehand, with the option to refuse and to withdraw later, keeping only strictly necessary cookies running.

NameTypePurposeDuration
app_session_idEssential cookieKeeps your authenticated session. Set as HttpOnly, Secure and SameSite=Lax: it cannot be read by scripts and is not sent along with requests originating from other sites.Up to 7 days, or until logout
iclex.langLocal storageStores your chosen interface language so the page does not load in the wrong one.Until you clear your browser
iclex.themeLocal storageStores your light, dark or system theme preference.Until you clear your browser

You can block or delete cookies in your browser settings. Blocking the session cookie prevents the authenticated area from working; browsing the public pages and the reporting channel remains possible.

09

Reporting channel, anonymity and the ban on retaliation

Where the client company enables anonymous reporting, the channel requires no identification and follow-up is done through a protocol number. We do not use IP addresses, device fingerprinting or any other technical data to try to identify an anonymous reporter, and we do not correlate website browsing with the reports we receive.

Where a person chooses to identify themselves, their identity is treated as confidential and access is restricted to the people assigned to the investigation, with every view recorded. The ban on retaliation follows from Law 14.457/2022 and from the client company's internal policies — it is up to the company to adopt the corresponding protective measures.

  • Attached evidence is cryptographically hashed at submission time, which makes it possible to later demonstrate that the file was not altered.
  • The channel's public pages carry no third-party scripts, analytics tools or tracking pixels.
  • Files are stored under an opaque identifier, so the original filename is never exposed in the URL.
  • Access to a case can be restricted by department and by assigned investigator, where the client company enables that control.

Important warning: do not send harassment reports, wrongdoing reports or sensitive data to our commercial addresses or through the contact form. They do not offer the confidentiality, anonymity and audit-trail guarantees of your company's reporting channel.

10

Sharing with third parties

We do not sell, rent or trade personal data. We share only what is necessary, with the categories below, always under a contract imposing confidentiality, limited purpose and security standards equivalent to our own.

  • Infrastructure and hosting: cloud, application platform and managed database providers that run the service.
  • Corporate identity providers: when you sign in with a Google or Microsoft account, those providers handle authentication and receive only what is needed to authenticate you.
  • Transactional messaging: email services used for invitations, notifications and platform alerts.
  • Implementation and consulting partners: only where the client company appoints them contractually, and limited to the scope it authorises. Commercial partners see only account status and billing information — never case or report content.
  • Independent lawyers, auditors and experts: in the regular exercise of rights and under a duty of confidentiality.
  • Public authorities and the courts: upon a lawful request, court order or regulatory obligation, limited to the subject matter of the request, recorded internally and, where legally permitted, notified in advance to the controller and to the data subject.

We do not engage a sub-processor that is not bound by the same obligations. An up-to-date list of relevant processors and sub-processors is provided to client companies on request, under the data processing agreement.

11

International data transfers

Files and other data processed on the platform are stored on servers located in the United States and the European Union, operated by cloud infrastructure providers engaged by ICLex. These international transfers rely on arts. 33 and 34 of the LGPD, supported by contractual guarantees ensuring a level of protection compatible with Brazilian law, such as specific or standard contractual clauses.

Client companies may at any time request information about the current storage location and the safeguards adopted, and may address data residency requirements contractually.

12

Retention and erasure

We keep personal data only for as long as necessary for the stated purposes, for compliance with a legal or regulatory obligation, and for the regular exercise of rights. Once the period ends, data is irreversibly erased or anonymised.

  • Sales enquiries: up to 24 months after the last interaction, unless a contractual relationship is under way.
  • Account and profile data: for the term of the contract with the client company and for the applicable legal periods after it ends.
  • Cases, reports, evidence and comments: for the period defined by the client company as controller, observing the applicable limitation periods, including the employment-law period and that of Law 12.846/2013. Once the period ends, the platform's retention routines anonymise or erase the content according to the configuration chosen.
  • Access logs and audit trail: for the minimum period of 6 months required by art. 15 of the Brazilian Internet Civil Framework, and for as long as needed to defend rights and demonstrate compliance.
  • Once the contract ends, data processed in our capacity as processor is returned and/or erased under the controller's instructions, except where retention is legally mandated.
13

Information security

We adopt technical and administrative measures proportionate to the risk, bearing in mind that we process sensitive data and investigation material. Among them:

  • Encryption in transit (TLS) and protection of data at rest at the storage layer.
  • Per-organisation isolation applied on every query, so that one customer's data is never reachable by another.
  • Role- and attribute-based access control, with least privilege, scoping by case and department, and four-eyes approval for sensitive access promotions.
  • Authentication through a corporate identity provider, sessions in an HttpOnly, Secure, SameSite cookie, and a restrictive content security policy.
  • A hash-chained audit trail, which makes any attempt to retroactively alter records evident.
  • Cryptographic hashing of evidence for integrity verification and to support the chain of custody.
  • Request rate limiting, correlation identifiers and security event monitoring.
  • Environment segregation, code review, automated testing and periodic access recertification.

No measure eliminates risk entirely. If you find a vulnerability, please tell us at the security address listed on the contact page: we welcome responsible disclosure and ask that you not run tests that degrade the service or expose other people's data.

14

Security incidents

We maintain an incident response plan covering containment, investigation, remediation and record-keeping. Where an incident may bring relevant risk or harm to data subjects, we will notify the Brazilian Data Protection Authority (ANPD) and the affected data subjects within a reasonable time, with the information required by art. 48 of the LGPD.

Where the incident involves data we process as a processor, we will notify the client company acting as controller without undue delay, providing the information it needs to meet its own notification duties.

15

Data subject rights and how to exercise them

The LGPD guarantees you the following rights at any time, free of charge, upon request (arts. 18 and 20):

  • Confirmation that processing exists, and access to the data.
  • Correction of incomplete, inaccurate or out-of-date data.
  • Anonymisation, blocking or erasure of unnecessary or excessive data, or data processed unlawfully.
  • Portability to another service or product provider, subject to commercial and industrial secrecy.
  • Erasure of data processed on the basis of consent, save where retention is legally authorised.
  • Information about the public and private entities with which we share data.
  • Information about the possibility of refusing consent and about the consequences of that refusal.
  • Withdrawal of consent at any time, through a free and straightforward procedure.
  • Objection to processing based on one of the grounds that dispense with consent, where the law has not been complied with.
  • Review of decisions taken solely on the basis of automated processing.
  • Petitioning the ANPD and complaining to consumer protection bodies.
Exercise my rightsprivacidade@iclex-wb.com

We will reply immediately in simplified form, or within 15 days where a full statement is required (art. 19). We may ask for additional information to confirm your identity — always the minimum necessary, and only to avoid disclosing data to someone who is not the data subject. If the request concerns data we process as a processor, we will forward it to the controller company and support it in responding.

16

Children and adolescents

The platform is a corporate product intended for adults over 18 acting in a professional capacity, and is not directed at children or adolescents. We do not knowingly collect minors' data through the website.

If an investigation involves an adolescent — for instance an apprentice — processing will observe the data subject's best interests under art. 14 of the LGPD, and the instructions of the client company acting as controller.

17

Data Protection Officer (DPO)

You can speak directly with our DPO to exercise your rights, clarify any point in this Policy or raise a concern about personal data. Publishing this channel meets art. 41, § 1, of the LGPD.

Data Protection Officer (Encarregado / DPO)

Osvaldo Correa

privacidade@iclex-wb.com
18

Changes to this Policy

We may revise this document to reflect legal, regulatory, technological or product changes. The current version and its date appear at the top of this page.

Material changes that broaden purposes or alter legal bases will be communicated through the usual channels — a notice in the platform, a communication to client companies, or email — and where the legal basis is consent, fresh consent will be requested. We keep previous versions and provide them on request.

19

Governing law and jurisdiction

This Policy is governed by Brazilian law, in particular Law 13.709/2018 (LGPD), Law 12.965/2014 (Internet Civil Framework) and, where applicable, Law 8.078/1990 (Consumer Protection Code). The courts of the data subject's domicile are elected for claims in which that prerogative is afforded to them; for all others, the courts of ICLex's registered office.

This document was originally drafted in Brazilian Portuguese. Versions in other languages are provided for convenience only; in the event of any conflict of interpretation, the Portuguese version prevails.