Privacy policy for our customers

This policy provides detailed information on how Komatsu Forest handles personal data and covers all companies that are part of Komatsu Forest (hereinafter referred to as "Komatsu Forest" or "we").

Privacy and Personal Data Protection Policy

1. Purpose

To establish the duties and responsibilities of Komatsu Forest Ltda employees and service providers, as well as to provide guidelines and standards for conducting activities involving the processing of, and for ensuring privacy and protection for, the personal data of natural persons or data owners with whom the company interacts for carrying out its business activities.

All activities related to the business of Komatsu Forest Ltda that involve personal data must be guided by this policy, which aims to protect the fundamental rights of freedom and privacy and the free development of the natural person's personality.

 

2. Compliance with Laws and Regulations

This policy was drafted to meet the requirements of Law No. 13.709/2018, as amended by Law No. 13.853/2019 (LGPD or the “Law”)—known in Brazil as the “General Data Protection Law”—particularly under Article 50, which addresses “Good Practices and Governance” regarding personal data security, as reproduced below:

Art. 50. Controllers and operators, within the scope of their respective competencies regarding personal data processing, may—acting individually or through associations—formulate good practice and governance rules. These rules may establish organizational conditions, operational frameworks, and procedures (including those for handling complaints and requests from data subjects), as well as security standards, technical specifications, specific obligations for the various parties involved in processing, educational initiatives, internal supervision and risk mitigation mechanisms, and other aspects related to personal data processing.

§1 - When establishing rules of good practice, the controller and operator will take into account, in relation to processing and data, the nature, scope, purpose and probability and severity of the risks and benefits arising from the processing of the data owner's data.

§2 - In the application of the principles set forth in items VII and VIII of the *main section* of Article 6 of this Law, the controller, taking into account the structure, scale and volume of its operations, as well as the sensitivity of the data processed and the likelihood and severity of harm to data owners, may:

I - Implement a privacy governance program that, at a minimum:

a) demonstrate the controller's commitment to adopting internal processes and policies that ensure comprehensive compliance with standards and best practices regarding the protection of personal data;

b) apply to the entire set of personal data under its control, regardless of the manner in which the data was collected;

c) be adapted to the structure, scale, and volume of its operations, as well as to the sensitivity of the data processed;

d) establish appropriate policies and safeguards based on a systematic process for assessing privacy impacts and risks;

e) aims to establish a relationship of trust with the data owner through transparent conduct that ensures mechanisms for the data subject's participation;

f) be integrated into its overall governance structure and establish and implement internal and external oversight mechanisms;

g) have incident response and remediation plans in place; and

h) be constantly updated based on information obtained from continuous monitoring and periodic assessments;

II - Demonstrate the effectiveness of its privacy governance program when appropriate and, in particular, at the request of the national authority or another entity responsible for promoting compliance with good practices or codes of conduct that independently foster adherence to this Law.

§3 - The rules on best practices and governance must be published and periodically updated, and may be recognized and disseminated by the national authority.

 

3. Definitions of Personal Data and for Personal Data Protection

Personal data is information relating to an identified or identifiable living person. Personal data also includes the set of distinct pieces of information that can lead to the identification of a specific person.

In accordance with Article 5 of the General Personal Data Protection Law (LGPD) and other similar legal references, the following is considered:

I. personal data: information relating to an identified or identifiable natural person.

II. sensitive personal data: personal data concerning racial or ethnic origin, religious conviction, political opinion, membership in a trade union or an organization of a religious, philosophical, or political nature, data concerning health or sex life, or genetic or biometric data, when linked to a natural person.

III. anonymized data: data relating to a data owner who cannot be identified, taking into account the use of reasonable technical means available at the time of processing.

Personal data is required for various business activities at Komatsu Forest Ltda and may take various forms of representation, storage, and transport, with its meaning and value depending on the context in which it is found, which may include, for example:

• on paper: attendance lists, registration forms, reports, memos, letters, etc.

• on digital media: digital files stored on hard drives, SSDs, flash drives, tapes, CDs, etc.

• in sound: recordings of meetings and other activities, answering machines, etc.

• in an image: photos of people and their documents, videos containing people, etc.

Personal data protection must safeguard fundamental principles and individual rights, such as respect for privacy, dignity, and self-determination; freedom of expression, information, communication, and opinion; the inviolability of intimacy, honor, and image; free enterprise and free competition; consumer protection; and other human rights related to personality and the exercise of citizenship.

To achieve the objectives regarding personal data protection, employees and service providers of Komatsu Forest Ltda must adhere to the practices set forth in this Personal Data Protection and Privacy Policy, the operational procedures related to this document, and the Information Technology and Security Policy (PTSI)—a document establishing general security guidelines and standards for all the company's information assets, including personal data as well as other types of sensitive and business-critical data.

 

4. Duties and Responsibilities

In general, all persons (employees, consultants, temporary staff, third parties, and other individuals) working for Komatsu Forest Ltda are responsible for adopting information security best practices when handling personal data.

Listed below are the specific duties and responsibilities of each role within the Komatsu Forest Ltda structure.

 

4.1 Executive Directorate

It is the responsibility of the Executive Board to ensure that personal data protection policies and procedures are followed and implemented, so that the company remains in compliance with the law.

The responsibilities of the Executive Board include:

a) to ensure that the principles of personal data protection—namely purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, responsibility, and accountability—are applied at Komatsu Forest Ltda.

b) to appoint the Data Protection Officer and facilitate their training.

c) to authorize notification in the event of a violation of the General Personal Data Protection Law.


4.2 Personal data owner

Data owners are the managers responsible for the business processes or activities related to the collection, use, and/or processing of each personal data database at Komatsu Forest Ltda.

The responsibilities of the personal data owner include:

a) ensuring compliance with regulations, policies, and procedures regarding the protection of personal data.

b) defining who may have access to personal data under their responsibility.

c) defining the controls to be applied to ensure quality, management of risks, and protection of personal data under their responsibility.

d) ensuring that any new personal data processing activity is duly communicated to the Data Protection Officer, including involving them so that personal data protection risks are fully assessed and addressed.

e) ensuring that all newly collected data, as well as any events involving changes to the structures of personal data databases under their management—in addition to events involving the alteration, correction, or deletion of personal data records—are always duly communicated to the Personal Data Officer, so that the latter may keep the personal data inventory up to date.


4.3 Operator

Operators are external, outsourced service providers that, in various ways, collect, use or process personal data for which the company acts as the controller.

Each operator is responsible for ensuring, maintaining records of, and—whenever required—demonstrating the adoption of all processes and the application of all necessary resources for personal data protection, in accordance with the law and as defined in this policy, following the same standards required for Komatsu Forest Ltda business units.


4.4 Personal Data Officer

At Komatsu Forest Ltda, the role of Data Protection Officer (DPO) is performed by a group of individuals coordinated by the "Processes" department, as defined by Executive Management.

The primary responsibility of the Personal Data Officer is to ensure that Komatsu Forest Ltda processes personal data in compliance with applicable laws and regulations, as well as to act as a communication channel between the company, data processors, data owners, and the National Data Protection Authority (ANPD).

The responsibilities of the Personal Data Officer include:

a) implement appropriate organizational measures to ensure and demonstrate that the processing of personal data is carried out in accordance with the Law.

b) implement policies and procedures appropriate for the protection of personal data.

c) inform and instruct persons (employees, consultants, temporary staff, third parties, and other individuals) working for Komatsu Forest Ltda regarding the requirements of the Law and the importance of compliance with it.

d) address potential risks for the protection of personal data in a proactive and continuous manner.

e) maintain a record of all activities and processes involving the use and processing of personal data carried out by the company, including the purposes of such activities and processes, the personal data involved, the data owner within Komatsu Forest Ltda, and the data retention period.

f) monitor the performance of actions taken to protect personal data and provide recommendations regarding their impact.

g) coordinate internal communications related to personal data protection management, identifying those responsible for each activity and monitoring their execution.

h) act as a point of contact between Komatsu Forest Ltda and data owners to inform them about how their personal data is being used, the right to data erasure, and the measures the company adopts to protect their personal data, thereby facilitating the exercise of data subject rights.

i) make personal data available to the data owner upon express request.

j) act as the point of contact between Komatsu Forest Ltda. and the National Data Protection Agency (ANPD).

k) prepare, when requested by the ANPD, a personal data protection impact assessment—including regarding sensitive data—concerning its personal data usage and processing operations, which must contain, at a minimum:

• the description of the types of personal data.

• the methodology used for the collection and for ensuring the security of personal data.

• a Komatsu Forest Ltda analysis regarding the measures, safeguards, and risk mitigation mechanisms adopted.

l) with the due authorization of the Executive Board, notify the ANPD and the data owners of the occurrence of security incidents that may result in significant risks or harm to the data subjects, in compliance with the company's obligations to provide notification in the event of a violation of the Law.


4.5 Information Technology (IT)

Regarding Privacy and Personal Data Protection, the Information Technology (IT) Department is responsible for ensuring that Komatsu Forest Ltda processes personal data using appropriate protective controls and technological resources, thereby guaranteeing the confidentiality, integrity, and availability of such data.

IT responsibilities include:

a) implement the technological controls, resources, and processes to comply with the Technology and Information Security Policy (PTSI), so as to ensure and demonstrate that the collection, processing, and storage of personal data are carried out securely, in accordance with the requirements of the Law.

b) ensure the protection and security of personal data within data storage and processing environments, as well as across digital communication channels (email, intranet, internal and external social networks, instant messaging systems, file exchange systems, web services, etc.), by adopting, providing, and implementing sufficient measures, processes, and technical resources to protect personal data against unauthorized access and against accidental or unlawful destruction, loss, alteration, disclosure, or any form of improper or unlawful processing.


4.6 Information Security (IS)

At Komatsu Forest Ltda, the Information Security (IS) function—carried out within the IT Department—is responsible for defining guidelines and standards, supporting implementation, and controlling and monitoring other business and support areas regarding all matters related to the confidentiality, integrity, and availability of company information, including personal data.

The responsibilities of Information Security regarding privacy and personal data protection include:

a) define, develop, disseminate, and support the implementation of an appropriate Information Technology and Security Policy (PTSI), also aligned with this Privacy and Personal Data Protection Policy. The PTSI is the document containing the guidelines and standards to ensure that the collection, processing, and storage of personal data are carried out securely, in accordance with the requirements of the Law.

b) in conjunction with Information Technology, support the Data Protection Officer and personal data owners by providing information and guidelines on security, enabling them to perform their duties, for example: details regarding the standards and controls for the protection of personal data, which are a subset of the information processed by the company.


4.7 Internal Audit

Internal Audit is responsible for testing processes and controls related to the protection of personal data and the proper performance of the Personal Data Officer, in order to ensure compliance with the Law.

Therefore, Internal Audit must include such tests in its Annual Schedule, aligned with the Executive Board of Komatsu Forest Ltda.

When evaluating processes and controls related to personal data protection, Internal Audit must also report its findings to the Personal Data Officer to assist in aligning controls with policies and procedures.

 

5. Rights of Data Owners

The data owners whose data is collected and processed by Komatsu Forest Ltda have the following rights regarding their personal data processed by the company:

a) confirmation of the existence of processing their personal data.

b) free access to consult their personal data.

c) correction of their personal data, when the data is incomplete, inaccurate or outdated.

d) deletion of their personal data when the data is unnecessary, excessive or processed in non-compliance with the Law—including where consent has been given by the data owner—provided that the personal data is not used to comply with legal and regulatory obligations.

e) portability of their personal data to another service or product provider, upon the express request of the data owner.

f) information regarding the public and private entities with which the company has shared personal data.

g) information regarding the possibility of not providing consent for the processing of personal data.

h) revocation of consent for the processing of personal data.

 

6. Collection, Usage and Processing of Personal Data

Komatsu Forest Ltda collects, uses and processes personal data to serve the company's legitimate interests, committing to compliance with all applicable legislation regarding personal data protection and ensuring that such data is collected, used, and processed in accordance with the provisions of the LGPD and other applicable laws and regulations, if any.

Personal data should not be collected without a specific purpose. Collection may take place when necessary to establish the business relationship between Komatsu Forest Ltda and its employees and business partners, for the performance of a contract, or to comply with a legal obligation to which the company is subject.

When collecting personal data, Komatsu Forest Ltda must provide prior, transparent, clear and unequivocal notice regarding the purposes for which such personal data will be processed and the duration for which it will be retained and processed; it may also state that the retention period is indefinite.

In all cases where the collected personal data are not anonymized and the collection is not for the purposes of (I) compliance with a legal or regulatory obligation, (II) performance of a contract or preliminary procedures related to a contract to which the data owner is a party, (III) regular exercise of rights in judicial, administrative, or arbitration proceedings, and (IV) credit protection, Komatsu Forest Ltda must obtain the data subject's express consent, and such consent must be recorded and archived on digital or printed media.

Whenever there are changes to the purpose, Komatsu Forest Ltda must inform the data owner of the changes in advance and request new consent; the data subject may revoke consent if they disagree with the changes.

When the processing of personal data is a condition for Komatsu Forest Ltda to provide a product or service, or for the exercise of its rights, the data owner must be prominently informed of this fact and of the means by which they may exercise the rights set forth in the aforementioned Law.


6.1 New projects and processes regarding changes to personal data

Any new personal data processing activity must be duly communicated by the owners to the Data Protection Officer—including involving the latter in the planning of new projects that may entail the collection and processing of personal data—so that risks to the protection of such data are fully assessed and addressed.

In the normal course of business operations, any change to personal data must be communicated to the Personal Data Officer—whether manually or automatically (via system integration)—so that they can update the records in their control tool(s). This communication/integration process includes changes to both the data structure and the records, for example:

• new personal data collected in current systems/processes.

• alteration, correction, or deletion of personal data in current systems/processes.

• changes to the structure of personal databases in existing systems/processes.
 

6.2 Processing of personal data collected by units outside of Brazil

Komatsu Forest Ltda units outside Brazil also collect personal data to enable their operations and business activities. In some of these instances it may occur that part of the processing and protection of such data takes place at the unit located in Brazil.

It is the policy of Komatsu Forest Ltda to treat and protect such data with the same levels of protection and by following the same procedures and controls adopted for data collected in Brazil.

 

7. Disposal of Personal Data

Upon the conclusion of the usage period or when the purpose for which certain personal data were collected and processed has been fulfilled, the data controllers must delete the related personal data using secure disposal methods or anonymize them for statistical purposes. Whenever possible, these disposals must be verifiable.

In cases where Komatsu Forest Ltda cannot delete personal data due to legal requirements or other legitimate needs, such data must be securely archived and isolated from any further processing until deletion becomes possible.

 

8. Communication Processes with Data Owners and the ANPD

Komatsu Forest Ltda must establish a communication channel enabling the ANPD and data owners to contact the company whenever they wish to exercise their rights. The person responsible for the operation of this communication channel is the Personal Data Officer.

This communication channel must be published on the internet and/or via other means that facilitate disclosure to data owners and the ANPD.

Additionally, whenever required, the Personal Data Officer must handle requests for information, the issuance of impact reports for the ANPD, and matters concerning incidents, among other legal demands that may be regulated by the ANPD in the future.

 

9. Protection Measures

9.1 Protection of personal data in paper format

To ensure the proper protection of locations containing personal data in paper format, the following controls must be implemented:

a) physical structure adequate to withstand impacts, flooding, or fires.

b) controlled and monitored physical access.

c) the use of photographic and other equipment that allows unauthorized copying of documents must be prohibited.

Paper documents containing personal data that are under the responsibility of Komatsu Forest Ltda may not be removed from the company without the prior express authorization of the Personal Data Officer and the owner of such data.


9.2 Protection for personal devices and systems

The use of personal devices and systems (laptops, tablets, smartphones, portable data storage media, cloud-based messaging and collaboration systems, etc.) can pose risks to the security of personal data.

Employees who need to use any resource not provided by the company for the processing of personal data must request prior authorization from the Information Technology (IT) Department and the Personal Data Officer; these parties, in turn, if they determine that such use is indeed necessary, must assess the context and implement the required protective measures.

The analysis and authorization process must consider:

a) the need to use the resource.

b) the risks to personal data protection arising from the use of this resource.

c) the performance of activities only after ensuring the adoption of necessary protective measures.


9.3 Protection of personal data in electronic format

9.3.1 Access controls

Access to Komatsu Forest Ltda systems and networks containing personal data must be granted through identification, authentication, and login/password certification processes, with the necessity of such access for the performance of duties requiring verification.

It is the responsibility of the owner of each personal data repository to determine the appropriate controls regarding access rights, the granting of privileges, and the management of access granted to the personal data under their management.

9.3.2 Use of software

The installation of software not approved by Komatsu Forest Ltda or the modification of information technology equipment configurations (computers, laptops, printers, etc.) must be prohibited for users who do not have authorization for such tasks.


9.3.3 External access

External access to systems and equipment must be granted only to personnel who actually require this resource, in cases of genuine necessity for the performance of business activities, and provided it does not entail high risks to the protection of personal data.

External access must consider: 

a) the person (employee, consultant, temporary worker, third party, and other individuals) providing services to Komatsu Forest Ltda must obtain specific authorization for the remote use of equipment.

b) equipment must not be left unattended in public areas and must always be carried by its users.

c) It is advisable to carry portable devices and computers as hand luggage and, whenever possible, to disguise them so as not to attract unwanted attention.

d) equipment must not be used in areas where people circulate, such as airports, hotel lobbies, restaurants and bars.

e) precautions regarding personal data security must be reinforced.

f) any issue regarding the protection of personal data must be reported immediately to the Personal Data Officer and the respective owner of such data.

 

9.4 Protection of personal data transfers

As the risk of information leakage is higher in processes involving transfers between different devices and/or systems, the following guidelines must be followed by all employees and service providers to ensure the security and protection of personal data:

a) the use of connections to internal network systems and the Internet is permitted for all business purposes, support, services, and specific objectives of Komatsu Forest Ltda. The use of these resources for other purposes is strictly prohibited.

b) any computer owned by Komatsu Forest Ltda or by service providers working for the company that is connected to the internal network or the Internet must be properly configured with protection systems against virus or malicious software infestation.

c) all computers, networks, systems, and software shall be subject to monitoring; therefore, Komatsu Forest Ltda may, at its discretion, maintain a history of access and transactions performed via corporate (internal) network connections or the Internet (external).

d) Probing, scanning, or any other form of attempted intrusion using testing mechanisms may not be conducted without proper and express authorization, as doing so constitutes a threat and an attempt at the misappropriation of personal data.

e) all connections between Komatsu Forest Ltda's internal networks and other external networks, including the Internet, must pass through a specific configured and approved firewall system.

f) workstations must be equipped with specific, approved software and configured for access to the internal network and the Internet; such access may be restricted upon the formal request of the manager of the relevant department, the data owner, or the Personal Data Officer, or in order to maintain personal data security levels.

g) email, remote connection, and file transfer services should preferably be disabled for users whose roles do not require these services.

h) user connection to networks (internal and external) must take place solely and exclusively through processes of identification, authentication, and certification involving access keys and passwords.

i) control and security devices (proxy server, firewall and the like) must be implemented to ensure the confidentiality and integrity of personal data in transit across these networks.

j) do not download unauthorized software, as it may contain malicious code and pose threats to the security of personal data.

k) keep file-sharing options and automatic connection to Wi-Fi and Bluetooth networks disabled.

l) In all situations, regardless of what has been previously noted, any and all files originating from external networks or users must be scanned by virus and malicious software protection systems.

m) Any and all transfers of personal data to systems and persons external to Komatsu Forest Ltda, via any communication means, must take place securely, taking into account the following controls:

1) Avoid sending personal data via email or other messaging services. Ideally, personal data should be accessed and transferred using only the built-in features of the company's management systems and applications.

2) If it is not possible to transfer personal data via the systems that store them, transfers of personal data via messaging (such as email attachments, for example) may only take place if the files are encrypted or anonymized.

3) If the transmission of personal data via email or electronic messages in general is unavoidable, the sender must ensure that the data is sent only to those who genuinely need to receive that information, while also taking care to transmit the minimum amount of information necessary and using only the channels authorized by the company.

4) do not use public networks (e.g., public Wi-Fi) to exchange or transmit personal data, unless security and encryption measures (such as SSL and VPN) are employed for the communication.

 

10. Creating Profiles for Decision-Making

Komatsu Forest Ltda does not employ techniques for automated decision-making based on personal data—including individual profiling—that have legal effects or significantly affect data owners.

 

11. Communication in the Event of Incidents

A security incident can be any event that compromises the protection of personal data and sensitive personal data.

In accordance with the law, Komatsu Forest Ltda must notify the ANPD and the data owner of the occurrence of a security incident that may result in significant risk or harm to the data subjects.

The person responsible for Information Security (IS) must carry out activities related to monitoring, alerting, accountability, response, communication among stakeholders, and incident documentation and logging, encompassing the following activities:

a) the monitoring and management of security incidents related to personal data, i.e., incidents involving system databases, files, and network locations containing personal data.

b) the handling and recording of incident responses and the respective corrections applied.

c) notification to the parties responsible for personal data protection, the Data Protection Officer, and the respective data owner regarding any incident involving the loss or misappropriation of personal data.

It is the responsibility of the Personal Data Officer to analyze the severity of incidents in conjunction with the Legal Department and the Executive Board. If an incident is deemed to entail significant risk or harm to data owners, the Personal Data Officer must prepare and carry out the appropriate notification to the ANPD and the data subjects.

As provided by law, the notification must contain, at a minimum, the following information regarding the incident:

a) the description of the nature of the affected personal data;

b) information regarding the data owners involved;

(c) a description of the technical and security measures used to protect the data, while respecting trade and industrial secrets;

d) the risks related to the incident;

e) the reasons for the delay, in the event that the communication was not immediate;

f) the measures that have been or will be adopted to reverse or mitigate the effects of the loss.

 

12. Policy Update

Komatsu Forest Ltda may, at any time, make timely revisions or updates to this policy. Updates to this policy will take effect as soon as they are published on the website www.komatsuforest.com.br.

 

13. Glossary

• Anonymization: use of reasonable technical means available at the time of processing, whereby data loses the possibility of being associated, directly or indirectly, with an individual.

• ANPD: National Data Protection Authority – an agency of the indirect public administration responsible for overseeing, implementing, and monitoring compliance with the LGPD.

• Database: structured set of data, which may contain personal data in electronic or physical form.

• Block: temporary suspension of any processing operation, subject to the retention of the personal data or the database.

• Consent: a free, informed and unequivocal expression by which the data owner agrees to the processing of their personal data for a specific purpose.

• Controller: a natural or legal person responsible for determining the purpose and means of the processing of personal data carried out by the company itself or by the operator.

• Anonymized Data: data relating to a data owner who cannot be identified, taking into account the use of reasonable technical means available at the time of processing.

• Personal Data: information relating to an identified or identifiable natural person.

• Sensitive Personal Data: personal data concerning racial or ethnic origin, religious conviction, political opinion, membership in a trade union or an organization of a religious, philosophical, or political nature, data concerning health or sex life, or genetic or biometric data, when linked to a natural person.

• Elimination: deletion of a piece of data or a set of data stored in a database, regardless of the procedure employed.

• Personal Data Officer: role at Komatsu Forest Ltda designated to serve as a communication channel between the company, data owners and the ANPD.

• Law: the same as the LGPD.

• LGPD: General Personal Data Protection Law, Law No. 13.709/2018.

• Operator: an external, outsourced service provider that carries out the collection, use and/or processing of personal data for which Komatsu Forest Ltda is the controller.

• Personal Data Portability: transfer of personal data processing to another service or product provider, upon the express request of the data owner.

• Owner of Personal Data: person or group of persons responsible for the collection and processing of personal data.

• PTSI: Information Technology and Security Policy: a document establishing general security guidelines and standards for all information assets of Komatsu Forest Ltda, including personal data and other types of sensitive and business-critical data.

• Data Owner: natural person to whom the personal data for processing relates.

• Handling: any operation performed on personal data, such as those relating to the collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, evaluation or control of information, modification, communication, transfer, dissemination, or extraction.

 

14. Effectiveness and Approval

This policy enters into force on this date and remains in effect indefinitely, until the next review or its revocation.

Date

Version

Summary

01/08/2020

001.00

Creation of the policy.

01/04/2024

002.00

Policy Update