At CARGOSOFT, privacy, information security and compliance with data protection regulations (in particular the General Law on Personal Data Protection - LGPD, Law No. 13.709/18) are fundamental pillars of our corporate governance and our ESG (Environmental, Social and Governance) commitments.
This Privacy Policy aims to demonstrate, transparently, how we collect, use, store, share and protect the personal data of our customers, business partners, employees (drivers, contractors and third parties), suppliers and visitors, both in our national and international operations in the transport of pharmaceutical products, based on the principles set out in art. 6 of the LGPD.
Therefore, we collect only the data necessary to hire personnel (internal and external), to perform contracted storage and transport services, and, occasionally, to suggest to contracting parties other services we may have or develop, ensuring, in the latter case, the anonymization of the data.
Personal data are stored in our own data centers or in third-party data centers, which may be located in Brazil or in other countries.
Normally, CARGOSOFT does not handle data of minors. Should this become necessary, processing of minors' data will occur in a restricted and specific manner to comply with legal and contractual obligations (such as registering dependents for fiscal/labor benefits of employees) and in the hiring of Minor Apprentices (adolescents), always in the best interest of the minor (in accordance with art. 14 of the LGPD).
CARGOSOFT maintains appropriate internal procedures for the identification, containment, handling and notification of security incidents that may result in risk or significant harm to data subjects.
Whenever the nature of the processing so requires, CARGOSOFT may prepare Data Protection Impact Assessments (RIPD), in accordance with ANPD guidelines.
To facilitate the reading of this document, we adopt the following definitions:
Personal data: Any information relating to an identified or identifiable natural person.
Sensitive personal data: Data concerning racial or ethnic origin, religious conviction, political opinion, membership in a trade union or organization of a religious, philosophical or political nature, data related to health or sexual life, genetic or biometric data.
Data subject: The natural person to whom the personal data refer (examples: drivers, representatives of clients, suppliers).
Controller: The entity responsible for decisions regarding the processing of personal data. CARGOSOFT will act as controller in most of its direct relationships.
Processor: The entity that performs processing of personal data on behalf of the controller. In certain logistics flows (e.g., transport contracted where the client determines the rules and recipients), CARGOSOFT will act as processor.
Data Protection Officer (DPO): Person designated by CARGOSOFT to act as a communication channel between the controller, data subjects and the National Data Protection Authority (ANPD).
Privacy Committee: The Privacy Committee acts as an institutional channel for assisting data subjects, under the coordination of the Data Protection Officer appointed by CARGOSOFT.
The nature of our operation requires the collection of different categories of personal data, depending on your relationship with CARGOSOFT:
When someone enters into a contract or even when considering doing business with CARGOSOFT, we collect information related to those processes.
We also need to work with other companies or use third-party platforms. In those interactions we also collect information.
To enable contracting and the execution of national and international transport services of pharmaceutical inputs and products, we collect:
Registration Data: Full name, corporate e-mail, phone number, position, CPF and RG of partners, attorneys-in-fact, representatives or the Responsible Technician (RT) / Pharmacist of the client/partner company (regulatory requirement of ANVISA).
Purpose: Formalization of contracts, billing, issuance of tax and transport documents (CT-e, MDF-e), operational communications and compliance with sanitary requirements.
We collect information from people interested in working at CARGOSOFT. If you apply for a vacancy through a specific platform we use for recruitment, we will request some data. This includes documents, résumé data, education history, as well as assessments that help understand your psychological, technical and behavioral profile, your work experience, and even details such as race, ethnicity or whether you have any disability. We use this information to ensure compliance with laws and to support our diversity and inclusion policies.
Due to the high added value and sensitivity of CARGOSOFT’s activities, security and logistics control is strict:
Registration and Professional Data: Full name, RG, CPF, driver's license (CNH, with indication of remunerated activity - EAR), proof of residence, bank details and contact information.
Health Data (Sensitive): Occupational medical examinations (ASO) for CLT drivers (compliance with labor legal obligation).
Security and Telematics Data (Geolocation): Real-time location of the transport vehicle, routes, speed, stop histories and biometric data (if the vehicle has ignition systems or cabins with biometric/facial validation), not used for abusive monitoring of the employee’s private life.
Biometric data: Biometric data are stored in a protected environment, with restricted access and use exclusively for authentication and security control.
Registration and Risk Check Data: Employment history and validation with Risk Management (GR) companies and insurers, strictly within the limits authorized by applicable law and jurisprudence.
Purpose: Ensuring cargo security (prevention of losses/thefts), compliance with insurance policy requirements, monitoring temperature and humidity of drug cargo (RDC ANVISA requirement) and fleet management.
These data are collected exclusively to comply with legal obligations, affirmative actions, diversity and inclusion, and are not used for discriminatory decisions.
Visitors are always welcome at CARGOSOFT headquarters. However, for everyone's safety, some data will be captured:
Physical Facilities: Name, CPF, photo (reception) and closed-circuit TV (CCTV) images for physical access control and asset security.
Website and Portals (Cookies): Browsing data, IP address, approximate geographic location and essential cookies for site functionality (according to our Cookie Policy).
CARGOSOFT processes personal data only on valid legal bases authorized by the LGPD, such as:
To perform our national and international transport operations with excellence, sharing data with third parties may be necessary.
We share personal data with other data processing agents, including audit and consulting firms, third-party service providers, developers and business partners that help improve user experience, provide technical support and ensure effective delivery of our services.
For this purpose, transparency is the basis of our cooperation. Each of these partners is carefully selected and commits to protect your data with the same seriousness as we do, observing the principles and requirements of the General Law on Personal Data Protection (LGPD).
Such sharing is carried out under strict information security standards and contractual data protection clauses:
Subcarriers and Independent Drivers (TAC): Sharing of data strictly necessary for the physical execution of delivery.
Risk Managers and Insurers: Transmission of drivers' and vehicles' data for security background checks, cargo tracking, route monitoring and activation of insurance coverages against losses.
Customs Brokers and Freight Forwarders: In international operations, for customs clearance and border authority procedures.
Regulatory Bodies and Public Authorities: ANTT, ANVISA, Federal Revenue, State Finance Departments, Highway Police and judicial authorities, whenever there is a formal legal or regulatory request.
Technology Service Providers: Suppliers of ERP, TMS systems, cloud storage services and telematics software.
As CARGOSOFT operates in cross-border transport (Mercosur and other countries), personal data of drivers, assistants and commercial representatives may be transferred to recipients located abroad (such as foreign customs authorities, international logistics partners or branches).
To provide the best functionalities, we rely on services and APIs from specialized partners — including global technology and artificial intelligence providers. When these services involve processing data outside Brazil, we adopt the safeguards and protection mechanisms required by the LGPD and by ANPD Resolution CD/ANPD No. 19/2024.
International transfer will occur in accordance with one of the hypotheses authorized by the LGPD, including adequacy decisions, standard contractual clauses or other guarantees approved by the ANPD.
The physical and digital integrity of the data under our custody is an absolute priority, especially considering the transport of high-sensitivity and high-value cargo, such as pharmaceutical inputs and products. We adopt robust technical and administrative measures, which include:
Strict controls of logical access to internal systems (multi-factor authentication - MFA, differentiated access levels);
Encryption of data at rest and in transit;
Continuous monitoring of our IT environments against intrusions and unauthorized access;
Strict physical security policies at CARGOSOFT premises and in transport vehicles;
Ongoing training of our employees on best practices in information security and the LGPD;
ESG Integration: Our IT and logistics suppliers and partners undergo technical homologation (due diligence) to ensure they also adopt sustainable and ethical data governance practices.
Personal data will be retained by CARGOSOFT only for the period necessary to fulfill the purposes for which they were collected, or to comply with legal, regulatory or contractual obligations:
Tax and Transport Data (CT-e, MDF-e): Kept for the periods required by tax legislation and ANTT (generally, 5 years).
Employment and Driver Records: Maintained in accordance with labor and social security prescriptive periods.
Access Control Data (CCTV): Disposed of periodically in accordance with our physical security policies (generally, up to 30 days, unless required for incident investigations).
After the retention period ends, data will be securely deleted or subjected to an irreversible anonymization process.
The LGPD guarantees you, as a data subject, several rights. You may exercise them at any time by making a direct request to CARGOSOFT:
Confirmation and Access: Know whether we process your data and obtain access to it.
Rectification: Request correction of incomplete, inaccurate or outdated data.
Anonymization, Blocking or Deletion: Request these measures for unnecessary, excessive or unlawfully processed data.
Portability: Request the transfer of your data to another service provider, respecting CARGOSOFT's trade and industrial secrets.
Information about Sharing: Know with which public and private entities we have shared your data.
Revocation of Consent: Revoke, at any time, consent previously given (for processing based solely on that legal basis).
If you have questions about this Privacy Policy, about how we process your personal data, or if you wish to exercise any of your rights under the LGPD, contact our Data Protection Officer (DPO) directly:
Name/Department: Privacy and Information Security Committee CARGOSOFT
Contact e-mail: dpo@cargosoft.com.br
Postal address: Rua Antônio Todeschini, 125, bairro Canguiri, em Colombo/PR, Brasil, CEP: 83.412-500
We will respond to your requests within the legal and regulatory deadlines established by the National Data Protection Authority (ANPD).
This document may be amended periodically to reflect regulatory changes, new ANVISA, ANTT or ANPD guidelines, or modifications to our internal operational structures. We recommend regularly consulting this channel to stay updated.
| Purposes | Legal basis | Classification of processed data |
|---|---|---|
| Audit and preparation of reports for statistical analysis. | Legitimate interest (Law No. 13.709/2018, art. 7, IX) | Registration data. Administrative data. |
| Query of the data subject's information in credit protection systems and inclusion in records. | Legitimate interest (Law No. 13.709/2018, art. 7, IX); regular exercise of rights (Law No. 13.709/2018, art. 7, VI) and Credit protection (Law No. 13.709/2018, art. 7, X) | Registration data. Administrative data |
| Compliance with judicial, administrative and/or police orders. | Legal/regulatory obligation (Law No. 13.709/2018, art. 7, II) | Registration data. Financial data.Digital log data.Sensitive data. Data of minors.Multimedia data |
| Defense of CARGOSOFT's interests, using the data subject's information in administrative, judicial and arbitration proceedings, if necessary. | Regular exercise of rights (Law No. 13.709/2018, art. 7, VI) | Registration data. Financial data. Administrative data. Digital log data. Sensitive data. Data of minors. Multimedia data. |
| Preparation of reports and indicators for regulatory and supervisory bodies. | Legal/regulatory obligation (Law No. 13.709/2018, art. 7, II) | Registration data. Administrative data |
| Sending newsletters and mailings | Consent (Law No. 13.709/2018, art. 7, I) | Registration data. Digital log data. |
| Study for launching new products, services, features and improvements in customer service and in its platforms, sites, applications and systems. | Legitimate interest (Law No. 13.709/2018, art. 7, IX) | Registration data. Administrative data.Digital log data. |
| Identification of the data subject on the site, application, system or other platform (login and password). | Performance of a contract or preliminary procedures (Law No. 13.709/2018, art. 7, V) | Registration data. Administrative data. Digital log data |
| Identification and recommendation of services and content on websites and applications. | Legitimate interest (Law No. 13.709/2018, art. 7, IX) | Registration data. Administrative data. Digital log data |
| Investigation and preventive measures to combat illicit acts, fraud, crimes, unauthorized changes in records, among other similar cases. | Legitimate interest (Law No. 13.709/2018, art. 7, IX) | Registration data. Administrative data. Digital log data |
| Offer of products, gifts and services to customers in the database. | Legitimate interest (Law No. 13.709/2018, art. 7, IX) | Registration data. Administrative data. Digital log data. |
| Offer of products, gifts and services to non-clients (prospecting/acquisition of clients). | Consent (Law No. 13.709/2018, art. 7, I) | Registration data |
| Development and offering of new products and services to customers in the database. | Legitimate interest (Law No. 13.709/2018, art. 7, IX) | Registration data. Administrative data. Digital log data |
| Enabling the operation of the platform, system, sites and applications. | Legitimate interest (Law No. 13.709/2018, art. 7, IX) | Registration data. Administrative data. Digital log data |
| Provision and maintenance of services offered by CARGOSOFT (preparation of hiring terms, continuity contracts, lease contracts, customer service, password resets, opening and recording of tickets, handling inquiries and questions, sending communications, technical support, recording of telephone and messaging app interactions, billing for provided services, issuance of invoices and payment slips, etc.). | Performance of a contract or preliminary procedures (Law No. 13.709/2018, art. 7, V) | Registration data. Administrative data. Digital log data. Financial data. Multimedia data |
| Prevent and/or identify technical and security issues, as well as illegal, suspicious or fraudulent activities. | Legitimate interest (Law No. 13.709/2018, art. 7, IX) | Registration data. Administrative data. Digital log data |
| Protect CARGOSOFT's rights and property. | Legitimate interest (Law No. 13.709/2018, art. 7, IX); and regular exercise of rights (Law No. 13.709/2018, art. 7, VI) | Registration data. Administrative data. Digital log data. |
| Recruitment, selection and hiring of candidates. | Consent (Law No. 13.709/2018, art. 7, I)Legal or regulatory obligation compliance by the controller (Law No. 13.709/2018, art. 11, II, "a") | Registration data. Administrative data. Sensitive data. Data of minors |
| Monitoring by cameras in internal and external environments. | Legitimate interest (Law No. 13.709/2018, art. 7, IX); | Multimedia data. Digital log data |
| Validation of biometric data | Guarantee of fraud prevention and the data subject's security in identification and authentication processes in electronic systems (Law No. 13.709/2018, art. 11, II, "g") | Registration data. Administrative data. Digital log data |