Privacy Policy

Privacy Policy for Cali

  1. Introduction

Cali Instituição De Pagamentos Ltda (the “Company,” “Cali,” “We,” “our,” “us”) is committed to complying with national and international data protection regulations as the Company is aware of the importance of safeguarding the privacy, confidentiality, and trust of the Data Subject by keeping their personal data secure against any theft, damage, or misuse, either knowingly or unknowingly.

Personal Data as defined under the applied General Data Protection Law “Lei Geral de Proteção de Dados” (LGPD), which came into effect in August 2020, and its terms and conditions and mandatory implementation and any subsequent amendment.

This Privacy Policy is to inform you about:

  • The purpose for which your personal data is collected;
  • The personal information we may process about you;
  • How your personal data is processed (used or shared) in the course of your business relationship with us;
  • Your rights with respect to our Privacy Policy;
  • The process by which you can communicate your requests or complaints regarding the processing of your personal data;
  • Why certain non-personal information is collected automatically.

Data processing includes any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction of personal data.

Cali is the controller of your personal data, and by accessing or using our services, you agree to the terms set out in this Privacy Policy.

  1. Data We Collect

In order to address your request and to provide our services and ensure compliance with legal obligations, we collect the following types of personal data:

Personal Identification Data:

  • Full name, CPF (individual tax number), CNPJ (business tax number), RG (general registry), proof of address, government-issued IDs, and date of birth.

Financial and Economic Data:

  • Information related to your financial situation, such as Corporate Income Tax (IRPJ), Personal Income Tax Form (IRPF), balance sheets, proof of income, and other financial documents.
  • Details of transactions made through our platform, including payment method information (e.g., bank account numbers, credit/debit card numbers, and other payment methods).

Behavioral and Usage Data:

  • Information about how you interact with our website or mobile app, such as IP addresses, device information (e.g., type of device, operating system), cookies, browsing history, transaction history, and log files.

Communications Data:

  • Emails, text messages, or other forms of communication between you and our customer support team, as well as your preferences and feedback.
  1. How We Use Your Data

We will use the collected data for the following purposes:

Service Provisioning and Account Management:

  • To create and manage your account, process transactions, and enable payment processing services.

Legal and Regulatory Compliance:

  • To comply with Brazilian tax, accounting, and regulatory requirements, including anti-fraud measures and reporting to financial authorities.

Fraud Prevention and Security:

  • To detect, prevent, and address security breaches, fraud, and other criminal activities.

Personalization of Services:

  • To personalize your experience on our platform by providing tailored offers, promotions, and other relevant communications based on your preferences and activity.

Marketing Communications:

  • We may send you information about new services, promotions, and other updates. You can opt out of receiving marketing emails at any time by clicking on the “Manage Preferences” link in any of our marketing emails or by contacting our support team at privacy@cali.com with the subject “Unsubscribe.” We will promptly process your request.
  1. Sharing Your Data

In order to fulfill our obligation with the above-mentioned legislation for the products and services that we provide to you, we may share your data with third parties under the following circumstances:

Service Providers and Partners:

  • We work with trusted third-party partners to provide specific services such as payment processing, fraud prevention, and customer support. These partners may include payment gateways, card networks, and financial institutions. We ensure that these providers comply with data protection standards.

Supervisory Authorities and Law Enforcement:

  • We may be required to disclose your personal data without your prior consent to governmental authorities, regulators, or law enforcement to comply with legislative and regulatory requirements, including fighting money laundering, terrorism financing laws, and all related predicate offenses.

Business Transfers:

  • Where Cali is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of the transaction, subject to the applicable privacy policy at the time.

Anonymization and Aggregated Data:

  • We may also share aggregated, anonymized data for research, analytics, and marketing purposes, where such data does not personally identify you.
  1. Data Retention

Cali will abide by its information retention policies with respect to your personal information and will ensure that it is securely deleted at the end of the appropriate retention period as described below:

  • Complying with legal obligations (e.g., tax, accounting, regulatory).
  • Resolving disputes.
  • Enforcing agreements.
  • For ongoing fraud prevention and account maintenance. When your data is no longer needed for these purposes, we will securely delete or anonymize it.
  1. Your Rights Under LGPD

As a data subject under Brazil’s LGPD, you have the following rights:

Right to Access:

  • You have the right to request information about the personal data we hold about you and how it is processed.

Right to Correction:

  • You can request corrections to any inaccurate or incomplete data.

Right to Deletion:

  • You can request that we delete your personal data under certain conditions, such as when it is no longer necessary for the purposes it was collected.

Right to Portability:

  • You have the right to request your data in a commonly used format so that you can transfer it to another service provider.

Right to Withdraw Consent:

  • You can withdraw consent at any time for specific data processing activities (e.g., marketing communications). However, this will not affect the lawfulness of processing prior to the withdrawal.

Right to Objection:

  • You may object to the processing of your personal data for certain purposes (e.g., profiling or marketing).

To exercise any of these rights, please contact our Data Protection Officer (DPO) at privacy@cali.com.

  1. Security of Your Data

We implement stringent security measures to protect your personal data, including:

  • Encryption: All sensitive data, including payment information, is encrypted during transmission (via SSL/TLS) and at rest.
  • Access Control: Only authorized personnel have access to your personal data, based on the principles of least privilege.
  • Security Audits: Regular security audits and vulnerability assessments are performed to identify and mitigate potential threats.
  • Firewalls and Intrusion Detection Systems: These are used to prevent unauthorized access to our systems.
  • Incident Response Plan: In case of a data breach, we have a plan in place to promptly respond and notify affected individuals in compliance with legal requirements.
  1. Data breach and Incident Response Plan

Cali has a robust Incident Response Plan to address data breaches or security incidents swiftly and effectively. This plan includes:

Detection and Assessment:

  • Continuous monitoring systems to detect unauthorized access or anomalies in data processing.
  • Immediate assessment of the scope and impact of any suspected breach

Containment:

  • Isolating affected systems to prevent further unauthorized access or data leakage.
  • Implementing temporary fixes or additional security measures as needed.

Notification:

  • Promptly notifying affected individuals if their personal data is compromised, in compliance with LGPD requirements.
  • Reporting incidents to the National Data Protection Authority (ANPD) and other relevant authorities within the legally required timeframe.

Investigation and Remediation:

  • Conducting a thorough investigation to determine the root cause of the incident.
  • Implementing long-term solutions to prevent similar incidents in the future.

Communication:

  • Keeping all stakeholders, including customers, informed about the status of the incident and the steps taken to address it.
  1. International Data Transfers

We may transfer your personal data to countries outside Brazil that do not have the same level of data protection as Brazil. In such cases, we take necessary steps to ensure your data is protected, such as entering into data transfer agreements with third parties to meet LGPD requirements, including the use of Standard Contractual Clauses (SCCs) or reliance on adequacy decisions.

  1. Children’s Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect or solicit personal data from children. If we learn that we have inadvertently collected personal data from a child, we will take steps to delete that information as quickly as possible. If you are a parent or guardian and believe that we have collected personal data from a child under the age of 18, please contact us immediately at privacy@cali.li so we can take appropriate actions.

  1. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our platform. These technologies allow us to:

  • Remember your preferences.
  • Analyze usage patterns to improve our services.
  • Display relevant advertisements.

We use the following types of cookies:

  • Session Cookies: Temporary cookies that store information during your session and are erased when the session ends.
  • Analytical Cookies: These cookies help us analyze how you interact with our website to improve functionality and user experience.

You can manage your cookie preferences through your browser settings or the cookie consent manager on our website.

  1. Privacy Policy Amendments

We constantly review our policies and attempt to keep them up-to-date. Accordingly, we may amend this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make significant updates, they will be posted on this page, and we will notify you through email or other means. Please review this policy periodically for any changes.

  1. Contact Us

If you have any questions, concerns, or requests related to your privacy, please contact our Data Protection Officer at:

  • Email: privacy@cali.li

Start your
Cali journey today