Privacy Policy and Personal Data Protection
The privacy and security of your personal data are fundamental values for the Trucks Control Group (comprising the companies Trucks Control Serviços de Logística Ltda., Trucks Comércio e Tecnologia de Rastreadores e Comunicações Ltda., and Trucks Provedora de Comunicações e Serviços de Satélite Ltda.). This policy reaffirms our commitment to transparency and clearly explains how and why we collect, use, store, share, and protect your personal data, as well as the options, controls, and rights you have to manage your information.
The purpose of this External Privacy and Personal Data Protection Policy is to clearly and objectively explain how the Trucks Control Group—comprising Trucks Control Serviços de Logística Ltda., Trucks Comércio e Tecnologia de Rastreadores e Comunicações Ltda. and Trucks Provedora de Comunicações e Serviços de Satélite Ltda., processes personal data in its dealings with customers, users, partners, suppliers, service providers, representatives, and visitors to its digital channels.
This document applies to the collection, use, storage, sharing, retention, disposal, and protection of personal data carried out in the context of service provision, contract management, support, billing, tracking, telemetry, institutional communications, and other external activities of the Trucks Control Group.
1.1 Commitment to the Protection of Personal Data
The Trucks Control Group recognizes privacy and the protection of personal data as key components of its corporate governance, its relationship of trust with the market, and the security of its services. Data processing activities comply with the General Personal Data Protection Law (LGPD), the supplementary regulations of the National Data Protection Authority (ANPD), applicable contractual obligations, and best practices in information security.
1.2 Technical and Organizational Security Measures
The Trucks Control Group implements technical, administrative, and organizational measures appropriate to the nature of the data being processed, the purposes of the processing, and the risks involved. These measures are designed to protect personal data against unauthorized access, loss, alteration, improper disclosure, inappropriate or unlawful processing, and other security incidents.
The measures adopted may include access controls, segregation of permissions, logging, encryption where applicable, environment monitoring, vendor management, controlled retention, and training and awareness programs for teams involved in the processing of personal data.
1.3 Scope
This policy applies to the processing of personal data by the Trucks Control Group in the following contexts:
Provision of tracking, telemetry, communication, support, and related services;
Management of contracts, proposals, purchase orders, invoicing, collections, and customer relations;
Providing service to customers, users, partners, suppliers, and other external parties;
Use of websites, systems, applications, portals, digital platforms, and customer service channels under the responsibility of the Trucks Control Group;
Security operations, fraud prevention, auditing, compliance with legal obligations, and the regular exercise of rights;
Institutional, commercial, promotional, and marketing activities, where applicable and in accordance with the relevant legal requirements.
1.4 Geographic Scope
This policy applies to data processing operations conducted in Brazil and, where applicable, to operations involving the storage, support, remote access, sharing, or international transfer of personal data, in accordance with the relevant legal, contractual, and regulatory requirements.
2.1 Policy Objectives
| PURPOSE | DESCRIPTION |
|---|---|
| To inform individuals whose personal data is held by Trucks Control | Explain how the Trucks Control Group processes the personal data of customers, users, partners, suppliers, representatives, and visitors to its digital channels. |
| Ensure transparency regarding the purposes | List the main categories of data processed, their purposes, and the primary legal bases for processing. |
| Provide guidance on rights | Outline the rights of data subjects and the channels for requesting information, correction, deletion, objection, portability, and other requests provided for in the LGPD. |
| Clarifying Sharing | Describe when personal data may be shared with group companies, suppliers, partners, authorities, service providers, and other authorized recipients. |
| Demonstrate institutional commitment | Demonstrate the adoption of practices related to governance, information security, privacy, and personal data protection. |
2.2 Compliance with Standards and Regulations
The Trucks Control Group processes personal data in accordance with applicable laws, particularly the LGPD, the Brazilian Civil Rights Framework for the Internet, ANPD regulations and guidelines, contractual obligations, and internal policies on governance, information security, and personal data protection.
Where applicable, the Trucks Control Group also follows best-practice guidelines, including ISO/IEC 27001, ISO/IEC 27701, and ISO/IEC 29100, in a manner consistent with its operational context and the risks associated with data processing operations.
The categories below represent the main types of personal data that may be processed by the Trucks Control Group in its external relationships. The actual data collected will depend on the service contracted, the channel used, the relationship with the data subject, and the applicable purpose.
| CATEGORY | EXAMPLES | MAIN OBJECTIVES | PREDOMINANT LEGAL BASES |
|---|---|---|---|
| Registration and Identification Information | Name, CPF, ID number, email address, phone number, job title, company, identification documents, information on legal representatives, license plate number, and fleet information when linked to an individual. | Registration, identification, contact, employment verification, hiring, service provision, and customer relations. | |
| Contract and Relationship Information | Proposals, contracts, billing requests, service history, requests, support records, communications, and evidence of the business relationship. | Contract management, customer service, support, auditing, verification of requests, and the regular exercise of rights. | |
| Financial, Tax, and Billing Data | Payment information, bank account information (when necessary), invoices, payment slips, billing information, and financial history. | Billing, collections, financial reconciliation, and compliance with tax, accounting, and regulatory obligations. | |
| Browsing Data and Digital Channel Usage | IP address, logs, date and time of access, session identifiers, cookies, browsing preferences, device type, and browser. | Digital channel operations, security, fraud prevention, user experience improvement, and statistical analysis. | |
| Operational data related to services | Location, trip history, telemetry events, access logs, images or videos from the contracted solution, voice/call recording data, and technical information related to the service. | Performance of contracted services, tracking, telemetry, operational support, asset security, auditing, and investigation of misuse. | |
| Information on suppliers, partners, and agents | Name, title, email, phone number, company, registration information, banking information, tax information, contractual information, and qualification or compliance documentation. | Supplier and partner management, procurement, payments, due diligence, contractual compliance, and legal obligations. | |
| Marketing and Communication Data | Communication preferences, interaction history, survey responses, campaign opt-ins, and browsing data used for marketing communications. | Sending institutional communications, surveys, campaigns, and business communications, when applicable. | |
| Physical Security and Access Control Data | CCTV footage, visitor logs, physical access data, and biometric data when strictly necessary. | Property security, personal safety, access control to restricted areas, and incident prevention. |
3.1 Processing of Data Pertaining to Children and Adolescents
The services provided by the Trucks Control Group are not intended for children or adolescents. Personal data from this demographic is not processed intentionally, except when necessary, legitimate, adequately justified, and in compliance with applicable law.
If the inadvertent collection of personal data from a child or adolescent is identified as being inconsistent with the purpose of the service or the applicable legal basis, the Trucks Control Group will take measures to review, block, delete, or rectify the processing, as appropriate.
| TERM | DEFINITION |
|---|---|
| Personal data | Information relating to an identified or identifiable natural person. |
| Sensitive personal information | Data regarding racial or ethnic origin, religious beliefs, political opinions, membership in a labor union or an organization of a religious, philosophical, or political nature, data concerning health or sex life, and genetic or biometric data linked to a natural person. |
| Starter | A natural person to whom the personal data refers. |
| Controller | A natural or legal person responsible for decisions regarding the processing of personal data. |
| Operator | A natural person or legal entity that processes personal data on behalf of the data controller. |
| Treatment | Any operation performed on personal data, including collection, access, use, storage, sharing, disposal, and other forms of processing. |
| Consent | A free, informed, and unambiguous statement by which the data subject consents to the processing of his or her personal data for a specific purpose. |
| Security incident | A confirmed or suspected incident that could compromise the confidentiality, integrity, or availability of personal data. |
| Cookies | Small files stored in the user's browser or device to enable features, record preferences, or support usage analytics. |
| Logs | Technical logs regarding access to, operation of, or use of systems, applications, and platforms. |
| Cryptography | A protection technique that renders data unreadable to unauthorized third parties, using specific keys or technical mechanisms. |
| Anonymization | The process by which data can no longer be associated, either directly or indirectly, with a natural person, provided that reasonable and available technical measures are implemented. |
| Pseudonymization | A process by which data is no longer directly linked to a data subject without the use of additional information that is maintained separately and protected. |
5.1 Applicable Law
| REFERENCE | APPLICATION |
|---|---|
| Law No. 13,709/2018 — LGPD | It regulates the processing of personal data in Brazil, establishes principles, legal bases, data subjects’ rights, the obligations of data processors, and administrative sanctions. |
| Law No. 12,965/2014 — Civil Framework for the Internet | It establishes principles, safeguards, rights, and obligations regarding Internet use in Brazil, including rules on connection logs and applications. |
| ANPD Regulations and Guidelines | Additional rules and guidelines on incidents, international transfers, cookies, data processors, oversight, and other topics related to personal data protection. |
| Applicable civil, tax, labor, regulatory, and procedural laws | It serves as the basis for the retention of documents, compliance with legal obligations, and the regular exercise of rights. |
| STANDARD | APPLICATION |
|---|---|
| ISO/IEC 27001 | Information Security Management System and controls for protecting information assets. |
| ISO/IEC 27701 | Extension for privacy management and personal data protection. |
The Trucks Control Group’s processing of personal data must comply with the principles set forth in the LGPD, including purpose, appropriateness, necessity, free access, data quality, transparency, security, prevention, non-discrimination, responsibility, and accountability.
In practice, personal data must be processed only for legitimate, specific, and explicit purposes that have been communicated to the data subject, and such processing must be limited to the minimum necessary to achieve those purposes. The processing must also be consistent with the relationship with the data subject and protected by technical and organizational controls that are proportionate to the risks involved.
When processing sensitive personal data, the specific legal grounds set forth in Article 11 of the LGPD must be observed, including those in Article 11, I and/or II, depending on the circumstances and the purpose of the processing.
When processing is based on consent, the data subject may revoke that consent at any time through a simple and free procedure, subject to legal provisions authorizing the retention of data and the validity of processing carried out previously.
7.1 Sharing of Personal Data
Personal data may only be shared when necessary, appropriate for the purpose disclosed to the data subject, and supported by a valid legal basis, contract, legal or regulatory obligation, the regular exercise of rights, or the data subject’s consent, when applicable.
The Trucks Control Group may share personal data with the following recipients:
| RECIPIENT | PURPOSE OF SHARING |
|---|---|
| Companies in the Trucks Control Group | Performing administrative, operational, commercial, financial, and support activities related to the services provided. |
| Service Providers and Suppliers | Hosting, technical support, infrastructure, customer service, billing, payment methods, security, auditing, communication, and other activities necessary for operations. |
| Business and operational partners | Carrying out authorized integrations, performing contracted services, and providing support for tracking, telemetry, communications, and customer service operations. |
| Customers and Authorized Users | Provision of operational information when necessary for the performance of the contracted service or when there is authorization, a contractual obligation, or an applicable legal basis. |
| Financial institutions, payment processors, and anti-fraud mechanisms | Payment processing, billing, fraud prevention, transaction validation, and compliance with legal obligations. |
| Public authorities, regulators, and judicial or administrative bodies | Compliance with the law, a court order, a valid administrative request, the protection of rights, or regulatory cooperation. |
| Auditors, consultants, and potential successors in corporate transactions | Conducting audits, due diligence, corporate reorganizations, business transactions, the defense of rights, and risk assessments, always in compliance with applicable confidentiality and security safeguards. |
7.2 Data Retention and Deletion
Personal data will be retained for as long as necessary to fulfill the purposes that justified its collection and processing, in accordance with legal, regulatory, contractual, tax, accounting, and auditing requirements, as well as information security requirements and the regular exercise of rights.
At the end of the applicable retention period, personal data must be deleted, anonymized, or blocked, except when its retention is permitted or required by law, by contract, by order of a competent authority, or to defend the rights of the Trucks Control Group.
| DATA TYPE | PURPOSE | RETENTION PERIOD | PRIMARY LEGAL BASIS |
|---|---|---|---|
| Customer/User Registration and Contract Information | Identification, communication, service delivery, and contract management. | During the term of the contractual relationship and, after its termination, for the period necessary to ensure the proper exercise of rights—generally up to 5 years. | |
| Financial, Tax, and Billing Data | Payments, collections, issuing invoices, and accounting/tax obligations. | For the applicable statutory period, generally 5 years after the end of the fiscal year. | |
| Tracking and telemetry data and/or data linked to an individual | Service delivery, operational safety, support, auditing, and investigation of misuse. | Up to 5 years from the date the data is received in the database, in accordance with applicable internal and contractual rules. | |
| Video tracking data that can be linked to an individual | Provision of video surveillance and operational security services. | Up to 6 months from the date the data is received in the database, unless retention is required by law or to defend legal rights. | |
| Application Access Logs | Security, auditing, fraud prevention, and traceability. | At least 6 months, in accordance with the Brazilian Civil Rights Framework for the Internet, or for a longer period when necessary and permitted. | |
| Cookies, analytics, and digital preferences | Website functionality, security, statistics, personalization, and communication. | Until consent is revoked, the purpose is fulfilled, or for up to 24 months, depending on the cookie category. | |
| Information on suppliers, partners, and agents | Contract management, procurement, payments, due diligence, and client relations. | During the term of the contract and, after its termination, generally for up to 5 years. | |
| CCTV footage and physical access logs | Property security, access control, and personal protection. | As a general rule, up to 6 months, unless retention is necessary due to an incident, investigation, or the defense of rights. | |
| Marketing and Communication Data | Institutional and business communications, research, and public relations. | Until consent is revoked, the data subject objects, or the purpose is fulfilled. |
To ensure that all customers have sufficient time to familiarize themselves with and adapt to the new guidelines, the deadline for deleting tracking/telemetry data will take effect after a transition period of one (1) year from the date of publication.
7.3 Cookies and Tracking Technologies
The Trucks Control Group may use cookies and similar technologies on its websites, platforms, and digital channels to ensure the proper functioning of its services, enhance security, analyze performance, record preferences, and, where applicable, support communications and campaigns.
| COOKIE TYPE | PURPOSE | LEGAL BASIS |
|---|---|---|
| Essentials | They enable the website to function, provide authentication and security, and offer essential features. | |
| Analytics | They support usage statistics, performance measurement, and the improvement of digital channels. | Consent or legitimate interest, depending on the circumstances and impact. |
| Staff | They record user preferences and customize features. | Consent or legitimate interest. |
| Advertising and Third Parties | They support campaigns, analytics, ad personalization, and third-party integrations. | Consent, when required. |
Users can manage cookies through the preferences panel, when available, or through their browser settings. Disabling essential cookies may affect the operation of certain features.
The Trucks Control Group has procedures in place to identify, record, analyze, contain, mitigate, and address security incidents that may involve personal data.
8.1 Procedures in the Event of an Incident
Identification, recording, and preliminary classification of the event;
Containment and implementation of immediate measures to reduce risks;
Assessment of the nature of the data involved, the volume of data, the affected individuals, and the potential impacts;
Definition of corrective and preventive actions;
Notification to the ANPD and data subjects when the incident could pose a significant risk or cause significant harm;
Documenting lessons learned and improving controls.
8.2 Incident Reporting
When a security incident involving personal data is confirmed that may pose a significant risk or cause significant harm to data subjects, the Trucks Control Group will make the appropriate notifications to the ANPD and the affected data subjects within the applicable legal timeframe, taking into account the available information, the risk assessment, and regulatory requirements.
8.3 Preventive Measures
Access controls and permission reviews;
System monitoring and event logs;
Training and raising awareness among employees and relevant third parties;
Vulnerability management and patch management;
Internal information security policies, standards, and procedures;
Business continuity management, backups, and disaster recovery, where applicable.
Data subjects may exercise the rights provided for in the LGPD, subject to applicable legal, contractual, and technical limitations.
| LAW | DESCRIPTION |
|---|---|
| Treatment Confirmation | Confirm whether the Trucks Control Group processes your personal data. |
| Access to data | Request access to the personal data being processed and information about its use. |
| Correction | Request that incomplete, inaccurate, or outdated information be corrected. |
| Anonymization, blocking, or deletion | Request action regarding data that is unnecessary, excessive, or processed in violation of the LGPD. |
| Portability | Request the portability of data to another service or product provider, subject to commercial and industrial confidentiality and applicable regulations. |
| Deletion of Data Processed with Consent | Request the deletion of data processed on the basis of consent, subject to any legal grounds for retention. |
| Information About Sharing | Request information about public and private entities with which data has been shared. |
| Information on Consent | To be informed of the option to withhold consent and of the consequences of doing so, when applicable. |
| Withdrawal of Consent | Withdraw consent at any time, when consent is the legal basis used. |
| Opposition | To object to a processing activity carried out on the basis of an exemption from consent, when there is a violation of the LGPD. |
| Review of Automated Decisions | Request a review of decisions made solely on the basis of automated processing that affect your interests, where applicable. |
9.1 How to Request the Exercise of Your Rights
Requests regarding personal data should be sent to the Data Protection Officer via email at [email protected].
To protect personal data, the Trucks Control Group may request additional information to confirm the identity of the data subject or the legitimacy of their representative. Responses will be provided within a reasonable time frame and in accordance with applicable law.
9.2 Limitations and Circumstances Under Which Full Compliance May Not Be Possible
Some requests may not be fully granted when there is a legal or regulatory obligation to retain data, a need to defend rights, prevent fraud, protect third parties, maintain trade secrets, or due to a justified technical impossibility. In such cases, the data subject will be appropriately informed, in accordance with legal limits.
10.1 Implementation of Measures
Failure to comply with this policy, contractual obligations, or applicable law may result in administrative, contractual, disciplinary, judicial, or regulatory measures, depending on the severity of the incident and the liability of each party involved.
10.2 Responsibilities of Suppliers, Partners, and Service Providers
Suppliers, partners, and service providers that process personal data on behalf of or for the benefit of the Trucks Control Group must comply with contractual obligations regarding confidentiality, information security, data protection, purpose limitation, support for data subject requests, and incident reporting.
Failure to comply with these obligations may result in measures such as a requirement to implement a corrective action plan, suspension of access, withholding of payments where provided for in the contract, termination of the contract, notification to the competent authorities, and the pursuit of appropriate legal action.
10.3 Administrative Penalties Provided for Under the LGPD
Failure to comply with the provisions of the LGPD may subject the data controller to administrative sanctions imposed by the ANPD, subject to due administrative process, the severity of the violation, and the applicable legal criteria.
| TYPE OF SANCTION | DESCRIPTION |
|---|---|
| Warning | Setting a deadline for implementing corrective measures. |
| Simple fine | A fine of up to 2% of the legal entity’s revenue, capped at R$ 50 million per violation. |
| Daily fine | A daily penalty will be imposed until the violation is resolved, in accordance with legal limits. |
| Public Disclosure of the Violation | Disclosure of the violation after it has been duly investigated and confirmed. |
| Blocking of Personal Data | Temporary suspension of the processing of the data in question until the matter is resolved. |
| Deletion of Personal Data | Requirement to delete personal data related to the violation. |
| Suspension or prohibition of treatment | Restrictive measures applicable under the LGPD, depending on the severity of the case. |
| VERSION | DATE | TYPE | DETAILS | RESPONSIBLE |
|---|---|---|---|---|
| 1.0 | 06/07/2026 | Preparation/Update | Update to the External Personal Data Policy. | Technology Department |
Access all of our documentation
anti-corruption
Standards that ensure integrity, transparency, and accountability in our operations.
View policyCode of Ethics
Values that guide the company’s actions, decisions, and professional relationships.
Look up codepay equity
A commitment to fairness, transparency, and inclusion in all workplace relationships.
View reportQuality Code
Guidelines that ensure quality, continuous improvement, and trust.
Understanding code
