Privacy Policy
We use our own and third-party cookies to improve your experience and our services, by analyzing the navigation of our website. By continuing to browse, we consider that you accept their use. Learn about Corstone’s privacy and personal data policy.
Welcome to Corstone’s Privacy and Personal Data page!
Ensuring the privacy and control of your data is, above all, a matter of respect and trust in our relationship. On this page you will have access to the Privacy and Personal Data Policy (“Policy”) to have a complete understanding of what we collect, for what purpose and how we process data, what the legal bases are, the duration of processing, and other fundamental issues. The information refers to Corstone – across all digital platforms.
In summary, the data we collect relates to the identification necessary for registrations, processing and sending marketing information, and optimizing your experience on the website, always with your consent and/or legal basis for it.
Our direct channels for topics related to this subject are:
Email of our Data Protection Officer (“Data Protection Officer”):
contato@corstone.com
Corstone’s online contact platform, selecting the “Privacy and Personal Data” category: https://corstone.com/politica-de-privacidade/
ABOUT THIS PRIVACY AND PERSONAL DATA POLICY:
This Privacy and Personal Data Policy (“Policy”) aims to demonstrate the commitment of Corstone, a private legal entity registered under CNPJ No. 16.678.601/0001-98, with headquarters in Pomerode/SC, to the privacy and protection of personal data collected from its users, establishing rules for the collection, registration, storage, use, sharing, and elimination of data collected within the scope of the company’s electronic website services and functionalities or in person, in accordance with current legal regulations, notably Law 13.709/2018 (General Personal Data Protection Law – LGPD). The terms of this document are valid for interactions with Corstone, its companies and brands, on websites administered by the Group as controller of personal data.
This Policy considers, for all purposes, that only individuals aged 18 (eighteen) years or older are registered on the Corstone website, as the registration of children under 18 (eighteen) years of age is not permitted. Therefore, if you have not yet reached this age, please stop Browse now and call your parents or legal representatives to complete the registration.
By accepting the terms of this policy and continuing to interact on Corstone’s online and in-person platforms, we consider that you have understood the objectives, purposes, and legal bases for the use of data, and are providing your consent for the processing by Corstone and its third parties. We also consider that your consent refers to the specific points of this Policy, individual to each data subject, collected in a clear and legitimate manner.
If you do not agree with this Policy and its terms, you should discontinue the use of our platforms.
1) WHY WE USE AND PROCESS YOUR PERSONAL DATA:
In summary, we will use your personal data (collected online or in person) to manage your user registration, manage your purchases, fulfill legal obligations, protect you, answer questions, and, if you wish, send our personalized communications.
The data we hold in our databases is collected when you voluntarily enter or accept it by accessing, using, and interacting with the functionalities or services provided online and/or in person by Corstone.
Depending on the purpose for which we will process your data at each moment, as summarized above, we need to process some personal data which, in general, are:
Identification data
Full name, email, CPF, RG (or other official identification documents), date of birth, gender, address, language, telephone numbers, and Corstone website access password.
Digital identification data
Cookies, IP Address (and Logical Origin Port), interaction records with Corstone brands, and mobile device data if authorized (geolocation, installed applications and device, connection, and other necessary data).
Economic and transactional information
Credit and/or debit card data (number, name, validity, security code, and cardholder identification data), bank details (digital or otherwise), and purchase profile. Important: credit and/or debit card data is only viewed by the company that performs the financial transaction, and Corstone receives the information already encrypted, which increases the protection of this data.
Other data
Data related to company registrations (CNPJ) if applicable (on Corstone’s website aimed at legal entities), collected data and consumer surveys.
The table below shows the purposes for the processing of this data by Corstone:
Purpose Observations
Management of registration as a user of the electronic platform. If you decide to become a user of our platform, it will be necessary for us to process your data so that we can identify you and grant access to its resources, products, and services. Also to protect you.
Inglês: Development and Execution of Services. In this modality, your data will be processed primarily for: Sending updates and information inherent to resources and products, including quality surveys to establish the degree of customer satisfaction; For customer service and marketing-related actions. When accessing Corstone’s electronic sites, we will only use data strictly necessary to meet your requests and orders, as well as for marketing purposes: If you subscribe to the Newsletter, the company will use your data to manage your registration and send personalized information about the products sold. We are not responsible for the accuracy, veracity, or lack thereof in the information that users provide to Corstone or for its outdatedness. The data subject must contact the company’s channels to request the update of their registrations on the different platforms. Among Corstone’s professionals and areas, collected data is accessed only by those duly authorized and designated, respecting the principles of proportionality, necessity, and relevance to business objectives, in addition to the commitment to confidentiality and privacy preservation under the terms of this Policy.
2) WHY WE ARE LEGALLY AUTHORIZED TO PROCESS YOUR DATA:
The information collected by the company with consent aims to establish a contractual link or manage, administer, provide, expand, and improve the user’s experience on the company’s website, adapting it to their preferences and tastes. The permission to process your personal data also depends on the purpose for which we process it. In this sense:
PURPOSE AND LEGITIMACY
Consumer Support
Legitimate Interest. By responding to requests and queries sent by the consumer through the different available and existing service channels.
We understand that the use of certain data for this purpose is beneficial to the user inasmuch as it allows the company to adequately assist them and answer the questions raised.
Marketing
Legitimate Interest. With authorization, the company has a legal premise to process your data for marketing purposes, for example: sending personalized information about promotions via email.
We understand that the use of information such as Browse data and preferences provided by the user can be beneficial in the sense of allowing us to improve the user’s experience when visiting the website, generating value for them.
Development and Execution of Purchases.
Legitimate Interest. The use and processing of your data at the time of purchase will be necessary for the company to process the order placed, for example: collection of payment data (credit card).
In these cases, the processing we do of your data is based on your own consent in making the purchase. We understand that we have a legitimate interest in carrying out the necessary verifications in order to avoid possible fraud at the time of purchase, establishing measures to protect the user, as well as our legitimate interest in receiving payment for the product.
Should any provision of this Policy be considered illegal or illegitimate by an authority in your place of residence or internet connection, as well as by interpretations of regulatory agents on the subject, the other conditions will remain in full force and effect, and the incorrect item will be adjusted.
3) DATA RETENTION PERIOD:
The information provided to the company by the user’s free consent will be automatically deleted from the servers when it ceases to be useful for the purposes for which it was collected, or when the user requests the deletion of personal data under the company’s custody, provided there is no legal obligation to retain it. The collected data and activity records will be stored in a secure and controlled environment, and the period for which we will retain your data will depend on the purposes for which we process it. The minimum stipulated periods are:
PERSONAL DATA RETENTION PERIODS
Registration Data. 05 (five) years after the end of the relationship – Arts. 12 and 34 of the Consumer Defense Code (“CDC”).
Digital Identification Data. 06 (six) months – Art. 15, Brazilian Civil Rights Framework for the Internet.
Economic and Transactional Information. 05 (five) years after the end of the relationship – Arts. 12 and 34 of the Consumer Defense Code (“CDC”).
Other Data. As long as the relationship between the parties lasts and there is no request for removal or revocation of consent – Art. 9, Item II of the General Personal Data Protection Law (“LGPD”).
Should the user request it, the collected data may be deleted before this period; however, it may be necessary to retain the aforementioned data for longer periods due to law, court order, fraud prevention (Art. 11, II, “a” of the General Personal Data Protection Law “LGPD”, Law No. 13.709/2018), credit protection (Art. 7º, X, LGPD), among other legitimate interests provided for in Art. 10 of Law No. 13.709/2018.
4) ON OPPOSITION, RECTIFICATION, LIMITATION, AND DELETION OF PROVIDED DATA:
The user may request the display or rectification of their personal data. You can exercise your right free of charge by writing an email to the following electronic address contato@corstone.com, simply stating the reason for your request and the right you wish to exercise. You can also access Corstone’s contact page https://corstone.com/contato, provide your identification data, select the “Privacy and Personal Data” category, and send the message.
Should the company deem it necessary for security and fraud prevention purposes, we may request a copy of identification documents to confirm the data and make the desired changes.
Through what has been highlighted above, the user may make the following requests:
request the deletion of their collected personal data, provided that any access accounts have been canceled by the user and that the minimum legal period related to data retention has expired;
request access to their personal data held by the company, remembering that if you are an already registered user on the platform, you can consult this information in the corresponding area of your account;
request the rectification or limitation of the use of their personal data by the company;
For security purposes, fraud control, and preservation of rights, we may keep the user’s data registration history for a longer period in cases provided by law or regulatory standards that so establish.
5) SHARING OF COLLECTED DATA:
For the effective provision of services and functionalities and to achieve the desired purposes described in this privacy policy, the company may share access to your data with third parties that support the services offered to you, namely: a) customer support service providers; b) advertising and marketing partners; c) logistics, transport, and delivery partners; c) technology service providers and d) financial institutions. These third parties are charged and monitored regarding data protection and information security, and receive only the information strictly necessary for the execution of their services.
Corstone may also share your data and registered activities with competent judicial, administrative or governmental authorities, whenever (and only if) there is a legal determination, request, requisition or court order, as well as to comply with obligations established by the ANPD – National Data Protection Authority, the agency that regulates the “LGPD”.
The data may also be shared in case of corporate movements, such as merger, acquisition or incorporation, provided they have the same purposes and nature of operation. Otherwise, Corstone will request new consent, if necessary.
6) ABOUT “COOKIES” AND THEIR USE:
Cookies are files or information that can be stored on your devices when you visit the company’s internet pages. We use cookies to facilitate the use and better adapt the pages to your interests and needs, as well as to gather information about the use of our websites and services, helping to improve their structures and contents. For example: your chosen language for navigation is captured through cookies and we load the website adapted to the model, without suggesting translation or adaptation in the layout. There are different types of cookies, which can be permanent or “session” cookies. Among the subcategories, there are “necessary” cookies, and as the name suggests, they are essential for the loading of the website and the use of the services. Most internet browsers already have settings to automatically accept cookies. The website does not collect cookies automatically, therefore, you can adjust the settings and the cookies you wish to share. If you choose not to authorize certain cookies, some website functionalities may not work correctly.
7) CHANGES TO THE PRIVACY POLICY:
The company may make changes to the information contained in this Policy to reflect changes in current legislation or in our practices and services. In this sense, it is your responsibility, as a user and data subject, to check this document whenever you access Corstone’s platforms and use our services, ensuring you are aware of the latest updates. Should there be a relevant change in this policy or in our internal processes, it may be necessary to obtain new consents and terms of acceptance, in which case we will contact you requesting them through the means informed in your registration.