Alvoar Lácteos

Privacy policy

English translation of the policy published on the Brazilian site.

This English translation is provided for convenience. The original Portuguese policy remains the source document. It states that it was last updated March 15, 2021. Its data-rights request service remains external.

Alvoar Lácteos S.A. recognizes its responsibility to protect the personal data of people who use its products and services. It values and respects the privacy of employees, service providers, customers, suppliers and partners, and understands that personal data must be used responsibly and in line with Brazilian law, especially Law 13,709/2018, the General Data Protection Law (LGPD) ↗.

Alvoar provides a channel through which data subjects can exercise their rights: Personal data request form ↗.

1. Purpose

1.1 This policy guides Alvoar’s conduct on protecting the personal data of users of its products and services and of third parties generally.

2. Application

2.1 This policy applies to and forms part of Alvoar’s broader measures for protecting personal data.

3. Concepts and definitions

3.1 A data subject is a natural person to whom the personal data used by the company relates.

3.2 Personal data is information that allows a natural person to be identified, directly or indirectly.

3.3 Processing means any operation carried out using personal data.

4. Principles

4.1 Alvoar observes these principles when processing personal data:

  • Purpose: use data for legitimate, specific and explicit purposes, without subsequent processing incompatible with those disclosed to the data subject.
  • Adequacy: use data consistently with the purposes explained to the data subject and the context of processing.
  • Necessity: limit use to the minimum data relevant and proportionate to the purpose.
  • Free access: provide easy, free consultation of the personal data the company uses.
  • Data quality: update personal data as needed for its purpose.
  • Transparency: provide clear, accurate and accessible information about processing.
  • Security: use technical and administrative measures against unauthorized access and accidental or unlawful destruction, loss, alteration, communication or disclosure.
  • Prevention: take steps to prevent harm from processing.
  • Nondiscrimination: do not use data for discriminatory, unlawful or abusive purposes.
  • Accountability: use effective measures that demonstrate compliance with data-protection rules.

5. Data subjects

5.1 The policy covers employees, prospective employees, customers and prospective customers, visitors, and other third parties who contact the company through its service channels or at its facilities.

5.2 Alvoar’s services are intended for people over 18 or emancipated minors. Children’s or adolescents’ data is collected in the context of legal or regulatory duties or the exercise of rights in administrative or judicial proceedings, subject to legal requirements.

6. Data-subject rights

6.1 A data subject may exercise rights directly or through a legally appointed representative.

6.2 Rights include requesting confirmation of processing; access; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary, excessive or unlawfully processed data; portability to another product or service provider; and information about public or private entities with which data is shared.

6.3 Requests should be made through Alvoar’s available service channel.

6.4 Inaccurate or outdated data will be corrected when the data subject reports the issue. A historical record of the correction will be kept.

7. Data collected

7.1 Personal data may be collected to provide services and to meet obligations as an employer or supplier.

8. How data is collected

8.1 The policy lists these main sources:

  • Websites: consumer, customer and supplier sites managed by or for Alvoar, including its own domains and pages on third-party social networks such as Facebook.
  • Websites and mobile apps: consumer, customer and supplier services managed by Alvoar, Embaré, Camponesa and Betânia Lácteos.
  • Electronic communications: emails, text messages and other messages exchanged with these companies.
  • Customer service: communications with consumer-service teams.
  • Offline registration forms: printed, digital or similar forms used for mail, promotions, events and other purposes.
  • Advertising interactions: information received when a person interacts with Alvoar advertising on another website.
  • Data created by Alvoar: records that arise during interactions, such as purchases made through its applications.
  • Other sources: third-party social networks, market research where responses are not anonymized, data aggregators, promotional partners and public sources.

9. Purposes and legal bases

9.1 Alvoar processes data to answer requests made in person or online; register customers; comply with legal obligations; prepare reports and plan business; exercise or defend rights in administrative and judicial proceedings; provide services; conduct campaigns; and maintain commercial relationships with customers, employment relationships with employees, and customer relationships with suppliers.

9.2 The data collected is used only for the purposes described above and is treated as confidential while respecting the data subject’s privacy.

9.3 Legal bases listed in the policy are: consent, where the person may choose whether to participate, such as donating to a supported institute; legal or regulatory obligation; contract performance, including product supply; regular exercise of rights in legal and administrative disputes; legitimate interests, such as satisfaction surveys, public-perception campaigns and checks for irregularities; and execution of public policies under agreements with public authorities.

10. Retention

10.1 Data is retained during Alvoar’s contractual relationship with the data subject and afterward when necessary for legal or regulatory obligations; research by a research body, with anonymization where possible; transfer to a third party in compliance with the law; or the controller’s exclusive use, without third-party access and after anonymization.

10.2 Alvoar uses technical measures to support data availability, confidentiality and integrity, together with security measures appropriate to the risks and access controls for stored information.

10.3 When the processing purpose ends, information will be discarded or anonymized under suitable procedures and policies.

11. Sharing with third parties

11.1 Data may be shared when the data subject gives formal consent; a transfer is needed to meet legal obligations; a transfer is needed to exercise rights in judicial, administrative or arbitration proceedings; a contract requires it; or it is needed for the legitimate interests of the data subject or Alvoar.

11.2 Customer data may be shared with public bodies under specific agreements for that purpose.

11.3 Exceptionally, where a data subject represents a foreign company or a contract requires it, Alvoar may transfer data abroad. In that case, Alvoar will require appropriate safeguards by contract.

11.4 The policy states that personal data is never sold to third parties.

12. Cookies

12.1 A cookie is a browser-stored file containing an identifier, usually a sequence of letters and numbers. The browser sends the identifier back whenever it requests a page. Cookies normally do not themselves contain information that personally identifies a user, but personal information stored about that user may be connected to data stored in or obtained from cookies.

12.2 The source websites may use essential cookies, needed for navigation and site functions; analytics cookies, which show how visitors use the site and where they encounter difficulties; and marketing cookies, used for advertising.

12.3 Users may configure their browser to block nonessential cookies. This static English edition does not install analytics or marketing cookies.

13. Safeguards

13.1 Alvoar uses physical, electronic and management tools chosen in light of the data collected, the processing context and purpose, and the risks to data subjects’ rights and freedoms.

13.2 Only authorized people can access data and only after a confidentiality commitment. Data is stored in a suitable secure environment. Employees handling personal data receive continuing training in privacy-management practices.

13.3 Alvoar commits to strong practices to prevent incidents while noting that no virtual system is entirely secure or risk-free. Problems may still arise from third-party cyberattacks or a user’s own negligence or imprudence.

13.4 If a security incident could create significant risk or harm, Alvoar says it will notify affected people and Brazil’s National Data Protection Authority as required by the LGPD.

14. Changes to this policy

14.1 The original policy states that it was formulated and last updated on March 15, 2021.

14.2 Alvoar reserves the right to modify it at any time, especially because of changes to its website or the law, and recommends frequent review.

14.3 Changes take effect when published on the website, and the policy says users will be notified of changes.

14.4 The policy states that continued use of services and provision of personal data after a change indicates consent.

15. Responsibility

15.1 Alvoar addresses the responsibility of people and entities involved in processing under Articles 42–45 of the LGPD.

15.2 It commits to keeping the policy up to date, following it and seeking technical and organizational conditions suitable for protecting processing.

15.3 If the National Data Protection Authority requires measures concerning Alvoar’s processing, Alvoar says it will follow them.

16. Disclaimer

Although Alvoar applies high security standards, no system is entirely risk-free. The original policy states that Alvoar is not responsible for:

  1. Consequences of a user’s negligence, imprudence or lack of skill regarding their individual data. Alvoar accepts responsibility for the security of its own processing and its stated purposes; users are responsible for keeping access details confidential.
  2. Malicious acts by third parties, such as hacking, unless Alvoar’s negligent or deliberate conduct is shown. If an incident creates significant risk or harm, Alvoar says it will notify affected people and the authority and take necessary measures.
  3. False information entered by a user in records required for Alvoar’s services. Consequences of false or bad-faith information are the user’s responsibility.