Komatsu Bank Privacy Policy


1. Introduction

At BANCO KOMATSU DO BRASIL (BKB), we strive to find the best way to meet our customers’ needs. We are part of a global economic conglomerate that is a leader in the production and sale of construction and mining machinery. We build relationships based on ethics and transparency, which is why we are presenting this document (Privacy Policy).

When you access or interact with our website or use our services (Financial Services), we may collect certain information (Personal Data). Therefore, we have drafted this Privacy Policy to clarify what personal data may be collected, used, shared, and/or stored.

To provide a better experience for our customers and business partners, this document has been written in a simple and accessible manner to ensure a clear understanding of how BKB uses personal data in the course of its activities.

As a financial institution duly established in accordance with the regulatory framework issued by the Central Bank of Brazil (BACEN) and the laws in force in the country, BKB collects and maintains personal data in the course of its activities, primarily regarding procedures related to the granting and management of credit operations for individuals and legal entities.

 

2. Definitions

For the purposes of this policy, personal data (Data) refers to any and all information related to an identified or identifiable natural individual.

In addition to the above definition, sensitive personal data (Sensitive Data) includes all information about natural individuals related to: racial or ethnic origin, religious beliefs, political opinions, membership in a union or an organization of a religious, philosophical, or political nature, data regarding health or sexual life, and genetic or biometric data.

In accordance with current legislation, additional definitions are listed below, to be considered by BKB in the management of “Data” and “Sensitive Data” pertaining to its: customers, employees, correspondent banks, suppliers, and other agents that maintain a relationship with the institution:

  • Data Subject: the individual to whom the “Data” and “Sensitive Data” processed by BKB refer;

  • Controller: a natural or legal individual, governed by public or private law, who is responsible for decisions regarding the processing of “Data” and “Sensitive Data.” Due to the nature of its operations, in most of the processing activities mentioned in this policy, BKB itself will act as the “Controller”;

  • Processor: a natural or legal individual, governed by public or private law, that processes “Data” and “Sensitive Data” on behalf of the Controller. Given the nature of BKB’s operations, the role of “Processor” will primarily be fulfilled by its correspondent banks and specialized service providers;

  • Data Protection Officer (DPO): a person appointed by the Controller and Processor to serve as a point of contact between the Controller, Data Subjects, and the National Data Protection Authority (ANPD).

  • National Data Protection Authority (ANPD): an agency under the Office of the President of Brazil, endowed with technical and decision-making autonomy and having jurisdiction throughout the national territory, whose purpose is to protect the fundamental rights to freedom and privacy and the free development of the personality of natural persons within the framework of current legislation.

 

3. What types of personal data does BKB collect?

In the course of its activities, BKB collects “Data” and “Sensitive Data” for various processing purposes, primarily registration data related to the process of granting and managing credit transactions.

To comply with requirements regarding the recording of “Data” and “Sensitive Data” processing activities, the main purposes and their respective legal bases for processing are mapped and available to interested parties.

 

4. With whom does BKB share personal data?

BKB may collaborate with other companies in various activities, including data hosting, consulting, and general advisory services. Accordingly, we reserve the right to share information, including “Data” and “Sensitive Data,” solely with the companies, suppliers, and government entities listed below. BKB will, whenever possible, adopt mechanisms for anonymizing and pseudonymizing such data, with the aim of preserving the privacy of Data Subjects to the greatest extent possible.

  • Our Business Partners: BKB uses a number of vendors that must be engaged to operate and provide financial services (banks, law firms, data hosting providers, credit risk history platforms, etc.). As such, for some of these vendors, it may be necessary to share and process “Data” and “Sensitive Data” collected by BKB. Business partners contracted as Processors are required by law or by contract to protect the shared “Data” and “Sensitive Data” and to use them only in accordance with BKB’s instructions.
  • Banking Correspondents: In order for a customer to access a financial service, it is necessary to share “Data” and “Sensitive Data” with banking correspondents accredited by BKB, who, for the purposes of this document, are classified as Processors. The data collected by Processors and sent to BKB is necessary for: customer prospecting, to finalize a transaction, or to address pending issues and/or problems that may arise in the relationship with Data Subjects. Our authorized Banking Correspondents are duly identified on the BKB website, and all are required by law or by contract to protect the shared “Data” and “Sensitive Data” and to use them only in accordance with BKB’s instructions.
  • Government Agencies: Due to accountability requirements and specific regulatory obligations in the financial sector, there is a need to share “Data” and “Sensitive Data” regarding customers, suppliers, and employees with government agencies and regulatory bodies (e.g., BACEN and BNDES). Under current Brazilian law, government agencies and regulatory bodies are required to protect “Personal Data” shared by the entities they regulate.
  • Komatsu Group Companies: Given that BKB is part of a Japanese-based business group with operations in various countries, BKB may occasionally share “Data” and “Sensitive Data” among Komatsu Group companies (the “Group”) for the purpose of improving its products and services. All Group companies are subject to strict internal procedures and policies designed to ensure the privacy of their customers, suppliers, and employees. In some cases, privacy obligations are also subject to contractual obligations, under which they commit to handling your “Data” and “Sensitive Data” with the same level of security and in accordance with the laws applicable to BKB.

In addition, BKB reserves the right to access, read, retain, and disclose any personal data that may be necessary to comply with a legal obligation or a court order, or to protect the rights, property, or safety of the institution and its employees.

 

5. Where is personal data stored, and with whom is it shared?

BKB is headquartered in Brazil; therefore, the “Data” and “Sensitive Data” collected are governed by Brazilian law. The personal data and information collected are stored on servers located in Brazil. In addition, for certain situations, cloud servers are used, with services provided by companies that are recognized for maintaining data security and protection standards in accordance with the Group’s policies.

In specific situations, certain “Data” and “Sensitive Data” may be transferred internationally, exclusively to Group companies, which will be subject to local legislation and the relevant rules of each country or jurisdiction. In such cases, whenever possible, BKB will employ anonymization or pseudonymization techniques for personal information and data.

 

6. What are the rights of the data subject?

Under current law, all individuals whose personal data is processed have rights regarding the privacy and protection of their information.

The following is a list of these rights, along with a brief explanation of the concepts and scope of each:

  • Request for access to your personal data: This right allows the Data Subject to request information about the processing of their data and to receive a copy of the information held by BKB.
  • Request to correct your personal data: This right allows the Data Subject to request, at any time, the correction and/or rectification of their personal data if they identify any incorrect information. However, in order for this correction to be made, it may be necessary to verify the information provided.
  • Request to delete or cancel your personal data: This right allows the Data Subject to request the deletion of their personal data from BKB’s database. In this case, the “Data” and “Sensitive Data” collected must be deleted from BKB’s servers, provided that such data is no longer necessary or relevant for the provision of services or for the conduct of the institution’s activities with the Data Subject, and provided that there is no legal obligation to retain this data to comply with regulatory provisions or to safeguard BKB’s rights.
  • Right to object to the processing of personal data: This right allows the Data Subject to challenge where, how, and in what context BKB uses their personal data in the course of its activities. In such situations, BKB is required to demonstrate, clearly and unequivocally, the legitimate grounds for processing the personal data, which, in this case, override the Data Subject’s rights.
  • Request data portability: This right allows the Data Subject to request that their personal data be made available to them or to a third party they have duly designated, in a structured and interoperable format.
  • Right to withdraw consent at any time: This right allows the Data Subject to withdraw their consent to the use of their personal data by BKB; however, this will not affect the lawfulness of any processing carried out prior to the withdrawal of consent. Withdrawal of consent may result in the inability to provide certain services, and in such cases, it does not override the retention obligation based on a legitimate purpose.
  • Right to review automated decisions: This right allows the Data Subject to request a review of decisions that are made exclusively by automated means and based solely on the processing of their personal data, and that affect the Data Subject’s interests in any way.

To exercise their rights, Data Subjects must use the communication channels provided by BKB. To process these requests, BKB may request specific information to verify the Data Subject’s identity, ensuring that their rights are exercised in the most secure manner possible.

Confirmation of the Data Subject’s identity must occur within 48 hours of the initial contact, as this is a necessary security measure to ensure that “Data” or “Sensitive Data” is not disclosed to anyone who is not entitled to receive it.

It may be necessary to interact with the Data Subject to obtain further information regarding their request and, in this way, respond to the request as quickly as possible.

BKB must respond to all legitimate requests within 30 (thirty) days from the time the requester’s identity is verified. In some cases, if the request is particularly complex, the response period may be extended to 60 (sixty) days. In this case, the Data Subject must be notified and kept informed of the status of their request.

Specifically, in the case of requests related to the right of access, BKB must respond to such a request within a maximum of 15 (fifteen) days from the date of confirmation of the requester’s identity.

 

7. How long will personal data be stored?

BKB will retain “Data” and “Sensitive Data” only for as long as necessary to fulfill the purposes for which they were collected, including to comply with any legal, contractual, or accountability obligations or requests from competent authorities.

To determine the appropriate retention period for personal data, the institution considers the amount, nature, and sensitivity of such information; the potential risk of harm arising from unauthorized use or disclosure of personal data; the purpose of the processing; and whether such purposes can be achieved by other means, in addition to applicable legal requirements.

Once all purposes and retention periods that justified the processing of personal data by BKB have been fulfilled, such data will be securely deleted using available technical means and within a reasonable timeframe necessary for operational purposes.

 

8. How do we protect personal data?

BKB takes technical, administrative, and organizational measures to protect “Data” and “Sensitive Data” against loss, unauthorized use, and/or other misuse. Personal data is generally stored in a secure operating environment that is not accessible to the public.

To ensure the security of personal data in its relationships with customers, suppliers, service providers, and employees, BKB will adopt the best available information security practices, including:

  • Strict access controls for personal data under our responsibility. Different levels of access to information are granted based on the needs established for the employee’s position;

  • Maintenance of an inventory of access to systems and databases;

  • Standard and industry-standard methods for securing collected data, such as antivirus software, firewalls, IDS/IPS, and disk encryption;

  • Adoption of preventive procedures against information security incidents, such as penetration testing and vulnerability assessments.

In the event of an incident related to a breach of information security, BKB has internal mechanisms and procedures for identification and response that comply with the security protocols required by the Group.

 

9. How do I contact BKB?

Through its website, BKB provides communication channels for the general public via its Customer Service Department (SAC) and Ombudsman’s Office.

In addition to the existing communication channels, the following service channels have been made available for matters related exclusively to the data protection and privacy of Data Subjects:

Point of contact: Alexandre Oliveira Araújo
Email: bkb.privacidade@komatsu.com.br

Mail
Banco Komatsu do Brasil S.A. – Proteção de Dados e Privacidade

Avenida Manuel Bandeira 291
Condomínio Atlas Office Park - Bloco D - Conj. 11
Vila Leopoldina - CEP 05317-020 - São Paulo – SP

 

10. Changes to the Privacy Policy

BKB is always striving to improve its services; therefore, this Privacy Policy may be updated from time to time.

Last modified: January 2025.