Privacy policy
Effective date: February 1, 2025
CALIZA INSTITUIÇÃO DE PAGAMENTO LTDA. (“Caliza”, “us”, “we”, or “our”) is committed to respecting your privacy and has prepared this Privacy Policy (“Policy”) to explain what personal data is collected and how it is used by Caliza.
This Policy applies to “End Users” (as that term is defined in the “Terms & Conditions for Caliza Brasil”) of the Services (defined below). End Users are also referred to herein as “you” or “your”.
This Policy sets out the basis on which we will use any personal data related to you that you provide to us via the Services or our website (available at https://www.caliza.co), through our business partners, or that we collect or receive through other means and to the extent permitted by law.
For the purposes of this Policy, “Personal Data” means information that identifies or can be used to identify you directly or indirectly. Examples of Personal Data include but is not limited to, first and last name, email address, telephone number, IP address, device information, and bank account information. For the proper use of the Services, we need to have access to certain Personal Data about you.
This Policy describes the Personal Data collected and used by Caliza, the purposes for which Personal Data is used by Caliza, with whom Personal Data may be shared and for what purposes, and what resources are available for you to manage Caliza’s collection, use, and sharing of your Personal Data.
What this Policy covers:
- General Information
- Personal Data of minors under 18 years old
- What Personal Data we collect and use
- How we collect Personal Data
- How we use Personal Data
- When we delete your Personal Data
- Who else has access to the Personal Data and why
- What are your rights with respect to these Personal Data
- How we store and protect your Personal Data
- International Transfer of Personal Data
- Do you need to provide your consent for Caliza to use your Personal Data as described in this Policy?
- Website of third parties
- Changes to this Policy
- Contact Us
According to Law No. 13,709 of 2018 (the Brazilian General Personal Data Protection Law, or the “LGPD”), Caliza is considered the “Controller” of your Personal Data when it makes decisions related to the use of your personal data – for example, when you reach out to us by filling out the contact form on our website. In other instances, when using your Personal Data on behalf of a third-party, Caliza will be considered the “Processor” of your Personal Data – for example, in connection with the provision of Caliza’s services, as described in section 1 of this Policy.
After reading this Policy, if you still have any questions or, for any reason, need to contact us for matters involving your Personal Data, please, use the channel below:
Data Protection Officer (“DPO”): [Gabriel Pires]
DPO’s email address: [privacidade@caliza.com]
1. General Information
Caliza is a technology company that has developed a solution to facilitate access to financial services, including foreign exchange and/or acquisition of certain crypto assets abroad, among other services, provided by Caliza (“Services”).
The Services are provided by Caliza to you through a financial services entity (an “Integrator”) that accesses and uses an application programming interface (“API”) made available by Caliza. By connecting to Caliza’s API, Integrators can offer an End User digital dollar accounts abroad, managed by Caliza’s partners. Please read our Terms and Conditions for more information regarding our Services.
Caliza needs to collect and use certain Personal Data related to you in order to provide its Services. Your Personal Data can be used, among other purposes described in this Policy, to:
- Perform the authentication of your identity;
- Identify you when accessing and using the Services;
- Communicate with you whenever necessary within the scope of the Services;
- Share your Personal Data with our business partners, Integrators, and service providers when necessary; and
- Allow you to access the Services based on your registration, as described in our Terms and Conditions.
2. Personal Data of minors under 18 years old
We do not knowingly collect or request Personal Data from individuals under the age of 18. Individuals under the age of 18 should not attempt to access or use the Services or provide us with any Personal Data. If we become aware that we have collected Personal Data from an individual under the age of 18, we will delete the Personal Data, except for retaining some identification of the minor to prevent further registration attempts.
3. Personal Data we collect and use
Caliza receives or collects only the following types of Personal Data: (1) location and device information; (2) data for registration purposes of consumers that use or wish to use Caliza’s Services or that contact Caliza; and (3) financial data. While certain third parties may directly collect and use your biometric information for registration purposes, Caliza does not receive such biometric information or otherwise collect or use your biometric information when you use the Services. Caliza is not responsible for the privacy practices of these third parties, which are governed by their own privacy notices and practices.
- Location and Device Information. These are pieces of information are collected through technologies such as cookies, identifiers, among others, when End Users interact with the Services, whether registered or not:
- IP address;
- Mobile device or computer information;
- Website view paths; and
- Registration Data. Information provided by the End Users in order to use our Services (in this case, through our business partners and Integrators) and information provided by the End Users in order to contact Caliza (e.g., through our website or other means). When an End User registers to use the Services, the End User also give these business partners and Integrators permission and authority to act on the End User’s behalf to access and transmit such information to us. End Users can be either a natural person (individual) or a company (legal entity). Therefore, we can use the following categories of information:
- Individual. Examples of Personal Data we collect and use include:
- Full name;
- Date of birth;
- CPF number;
- ID (RG) number;
- Email address;
- Phone number;
- Address; and
- Profession
- Legal Entity. Examples of information (which may be considered Personal Data if related to an individual within the legal entity, such as a representative or point of contact) we collect and use include:
- Corporate name;
- Address;
- CNPJ number;
- Phone number; and
- E-mail address.
- Financial Data. To provide the Services, we need to use some financial information related to you. Examples of this information include:
- Bank account details (e.g., bank account number, routing number, and/or SWIFT code);
- Pix key;
- Balance;
- Transactional data (amount, counterparty, currency, date and time); and
- Cryptocurrency or asset purchase data.
- Individual. Examples of Personal Data we collect and use include:
- How we collect Personal Data
- We collect Personal Data when you use the Services, including:
- Directly from you: We collect Personal Data when you provide it to us (e.g., when you use our website).
- From business partners and Integrators: When you register to use the Services, our Integrators and business partners (including service providers to us like identity verification services) disclose information to us about your eligibility to register and use the Services.
- Through your use of the Services: We collect Personal Data about you when you access or use the Services (e.g., when you send or receive money using the Services, we collect information about your transaction).
- From your device: We collect technical data about your device when you use the Services (e.g., your mobile device shares mobile device information when you use the Services).
- From our service providers: We work with service providers that provide us with access to their platforms to help us provide the Services (e.g., service providers that help us verify your identity when you enroll in the Services provide us access to their platforms to review the results of their verification processes).
- We collect Personal Data when you use the Services, including:
- How we use Personal Data
- Caliza uses the Personal Data collected, for example, for the following purposes
- Register End Users and provide our Services to them;
- Respond to End Users’ Service requests;
- Comply with legal and/or regulatory requirements, including Know Your Client (KYC) obligations, to respond to lawful civil and government requests for production of your Personal Data, and to protect our own rights and/or property;
- Detect, investigate, respond to, prosecute, and help protect against security incidents and other malicious, deceptive, fraudulent, or illegal activity, and help protect the rights and property of Caliza and others;
- Respond to questions and concerns;
- Contact End Users (by email, mail, text messages, and/or telephone) through partners or Integrators about matters, including the use of the Services, as well as to send you technical notices, security alerts, support messages, and other transactional or relationship messages and to carry out customer satisfaction surveys;
- Perform our agreements with Integrators and business partners;
- Enforce our terms and conditions;
- Provide, maintain, and improve the Services, as well as simply the interaction with End User;
- Develop new products and services;
- Ensure the correct functioning of our Services to understand End Users' behavior;
- Monitor and analyze trends, usage, and activities in connection with our Services;
- Comply with a judicial order or request from a competent administrative authority to the extent required by law; and
- Verify the authenticity of documentation.
- Caliza uses the Personal Data collected, for example, for the following purposes
- When we delete your Personal Data
- The data we collect about the IP address and logs of access of End Users of the Services is stored for at least six (6) months, as established by article 15 of Law No. 12,965 of 2014 (Brazilian Internet Law).
- Who else has access to the Personal Data and why
- We may occasionally share your Personal Data with the third parties identified below. Any sharing of Personal Data by Caliza will be done in accordance with legal provisions and, most importantly, in a manner that protects your privacy.
- Other companies of the same group
- We may share your Personal Data with other companies belonging to the same group as Caliza for the following purposes
- Marketing, prospecting, market research, opinion surveys, and promotion of our products and services;
- Prevention and resolution of technical or security issues; and
- Compliance with legal or regulatory obligations.
- Service Providers
- We may share your Personal Data with our services providers for the following purposes
- Authentication and identification of End Users;
- Verification of the authenticity of information and documents;
- Fraud prevention and KYC (Know Your Client);
- Preventing risks, fraud, and ensuring security in identification and authentication processes;
- Provision of Services;
- Improvement of Services and operationalization of new products or services;
- Prevention and resolution of technical or security issues; and
- Support services, maintenance, and customer support.
- Business partners and Integrators
- In connection with the provision of our Services, we may share your data with certain third parties, such as our business partners (for example, the entity that will be responsible for the foreign account of the End User that will be used to provide U.S. dollar accounts to the End User) and the Integrator, the entity with whom the End User has a direct relationship.
- Authorities and Regulatory Bodies
- We may share your Personal Data with judicial, police, governmental authorities, regulatory bodies, or other third parties with whom we are obligated by law, regulatory requirements, or court orders to share Personal Data, to the extent permitted by law.
- Potential investors
- We may also share information, including Personal Data, in case of sale or transfer of part or the entire business, operation or Services provided by us to a third party, for purposes of due diligence, or for the carrying out of the transaction itself. In case of corporate restructuring, we reserve the right to disclose your Personal Data to the potential purchaser before or after the sale.
- Professional advisors
- We may share Personal Data with our legal, financial, insurance, and other professional advisors where necessary to obtain advice or otherwise protect and manage our business interests.
- To protect the rights of Caliza and others
- We may share Personal Data if we believe that your actions are inconsistent with our user agreements or policies, if we believe that you have violated the law, or if we believe it is necessary to protect the rights, property, and safety of Caliza, our End Users, the public, or others
- What are your rights with respect to these Personal Data
- The LGPD allows the data subject to exercise certain rights before the Controller of Personal Data. Therefore, in relation to the activities in which we act as a Controller of your Personal Data, you have the right to:
- Obtain confirmation that we process your Personal Data. In response to this request, we will inform you if we process your Personal Data or not. Note that, if you are our customer (i.e., an End User), we necessarily process your Data, as explained in this Policy.
- Access your Personal Data. If you are interested, you can receive a report in which we present the Personal Data held by you that are processed by us.
- Rectify incomplete, inaccurate or outdated Personal Data. If you consider that your Personal Data are incorrect, you can request the rectification, indicating what needs to be changed and why. It is possible that we request a proof to make this change.
- Request the anonymization, blocking or erasure of Personal Data deemed unnecessary, excessive or processed in breach of the LGPD. If you consider that we are processing your Personal Data in an unnecessary and excessive manner or in breach of the LGPD, you can request that the Personal Data be anonymized, blocked or erased.
- Request portability of your Personal Data to another service or product supplier, with due regard for our trade and industrial secrets, according to the regulation to be issued by the National Data Protection Authority (“ANPD”). You are the owner of your own Personal Data. Therefore, you can request that these Data be transferred to another service or product supplier, according to ANPD’s regulation, provided that the trade and industrial secrets are respected.
- Request erasure of Personal Data processed on the basis of your consent, except in the events of retention of Personal Data prescribed by law. If your Personal Data are processed based on consent, you may request the erasure of these data. However, the LGPD authorizes the preservation of data for fulfillment of legal or regulatory obligations; studies conducted by research bodies, ensuring, if possible, the anonymization; and transfers to a third party and exclusive use by the controller, to the extent that the data be anonymized.
- Obtain information about the entities with whom we share your Personal Data. You can request that we inform you of the entities with which we share your Personal Data.
- Obtain information about the possibility of refusing consent and the respective consequences. When the consent is used as legal basis for the processing of personal data, you are entitled to be informed about the possibility of refusing consent and the consequence of such refusal.
- Withdraw your consent to the processing of your Personal Data. If your Personal Data are processed based on consent, you can withdraw this consent. With that, any processing of your Personal Data that is made based on consent will be interrupted.
- Object to the processing that violates the LGPD. If you consider that we are processing your Personal Data in violation of the LGPD, you can object to this processing. The request will be carefully reviewed and, if we agree, the processing of your Personal Data that is in breach of the LGPD will be interrupted.
- Request the revision of decisions taken solely based on the automated processing of your Personal Data. It is possible that decisions are taken based on the automated processing of your Personal Data. If this happens, you can request the revision of these decisions.
- File a petition regarding your Personal Data with the National Data Protection Authority. If you consider necessary, you can file a petition regarding your Personal Data with the ANPD.
- You can exercise any rights above by sending an e-mail to privacidade@caliza.com.
- How we store and protect your Personal Data
- We take reasonable steps to store your Personal Data in a secure manner in third-party data centers located in the United States. We currently contract data center services provided by cloud computing service operators. Before sending your Personal Data for storage in other countries, we strive to adopt the measures required by law to ensure that they will be protected accordingly.
- The security of your information is important to us. We have implemented reasonable and appropriate technical and administrative measures to protect the Personal Data against unauthorized access, destruction, loss, alteration, communication, or any inadequate or unlawful processing.
- Nevertheless, no platform is completely secure. If you have any concern or suspicion that your Personal Data are at risk, for example, if someone had access to your password, please contact us immediately.
- International Transfer of Personal Data
- Your Personal Data will be transferred to other countries, such as to the service providers that store your Personal Data and the business partners in charge of your foreign account. The creation of End Users’ foreign accounts will only be completed with the transfer of the Personal Data to the foreign company.
- In cases where your Personal Data is transferred outside of your country of residence, we will take all appropriate measures, as well as those required by law, to ensure that your Personal Data remains properly protected and that this transfer is carried out in accordance with any mechanisms provided for in applicable regulations.
- Do you need to provide your consent for Caliza to use your Personal Data as described in this Policy?
- LGPD establishes several situations in which processing of Personal Data is allowed regardless of the consent of the data subject. These are the so-called “legal bases” for processing of Personal Data.
- This means that, if you choose to use our resources, in some cases we may collect and process your Personal Data without your consent (if there is a legal basis provided for in LGPD that allows us to do so), such as, for example, to perform measures prior to contracting or signing an agreement with you, to comply with legal and regulatory obligations, to exercise rights established in an agreement or required by judicial, administrative and arbitration proceedings, credit protection, to guarantee protection against fraud and security of the data subject, in the identification and authentication processes of registration in electronic systems, for the legitimate interests of Caliza or third parties, among others.
- In other cases, we may ask for your consent to use your Personal Data. Please note that the withdrawal of your consent will obligate us to cease the processing of Personal Data done exclusively based on your consent.
- Websites of third parties
- We may provide links to other websites on the Internet as a resource for our End Users. Caliza is not responsible for these websites and content, and does not share, subscribe, monitor, validate, or accept the methods used by these websites or content storage tools to collect, process, and transfer your personal and private data. The data or content of such other websites are governed by the privacy statements of such other websites. We encourage you to check the privacy policies of said websites to be properly informed on how your personal data is used by other websites or other tool
- Changes to this Policy
- We may change the provisions of this Policy at our discretion and at any time. Whenever this Policy is changed substantially, we will inform you through an alert after log-in or by email. We will also send you an annual email with a link to the Policy.
- End Users are advised to check the updated version of this Policy every time they use the Services.
- Contact Us
- You can make a complaint or ask questions through the Customer Service Channels provided below. You can also send a message to the ANPD, but we kindly request that you try to resolve any issues directly with us, as our main concern is to keep our End Users satisfied with our Services, and we will make every effort to fulfill this mission through easy and attentive communication with our End Users.
- E-mail: privacidade@caliza.com