PRIVACY EXPLAINED, WITHOUT FINE PRINT

Your data.
Your choices.

This Policy explains how OM DTVM LTDA, “Ourominas”, processes personal data through the OurominasApp and its channels, why each use takes place and how you can exercise the rights established by Brazil’s General Data Protection Law (LGPD).

Last updated: July 26, 2026 · Effective for an indefinite term · Legal basis: Law No. 13,709/2018

01 · OVERVIEW

The commitment begins with three questions.

Before processing personal data, it is necessary to know why it will be used, how much is actually needed and how the data subject will remain informed and protected.

01

Purpose before collection

Each use of personal data must have a legitimate, specific and disclosed purpose.

LGPD · Art. 6(I) and (II)
02

Only what is necessary

Collection must be limited to what is relevant and proportionate for each purpose.

LGPD · Art. 6(III)
03

You remain in control

Access to information and the exercise of rights must be clear, free of charge and facilitated.

LGPD · Art. 6(IV) and (VI), and Art. 18
Who is who?

A data subject is the natural person to whom the data relates. The controller decides how processing takes place; under this Policy, that controller is OM DTVM LTDA. A processor handles data according to the controller’s instructions. The Data Protection Officer is the contact point between the organization, data subjects and Brazil’s data protection authority.

Concepts from Article 5 of the LGPD.
CONTROLLEROM DTVM LTDA“Ourominas” · CNPJ 11.495.073/0001-18
DATA PROTECTION OFFICER (DPO)Adriano Nascimento Felipedpo@ourominas.com
02 · DATA AND COLLECTION

Which data may be part of this relationship?

The specific category depends on how you interact with OM DTVM LTDA. A simple contact does not require the same data set as a contractual relationship or transaction.

Identification

Name, identity document, CPF, driver’s license, marital status, gender, occupation, nationality, date of birth, parentage, foreigner registration or passport, according to the relationship established.

Contact

Address, postal code, telephone number and email address.

Financial and transactional

Banking details, income information and data related to transaction history.

Browsing and device

IP address, language, browser settings, time zone, identifiers and interaction with pages.

Received from third parties

Information supplied by financial institutions, partners and public sources when there is a legal basis for processing.

1

You provide it

Through registrations, contracts, forms, support contacts and requests.

2

Use of the channel generates it

Access, device, browser and interaction records, according to the purpose.

3

Third parties provide it

Partners, institutions and public sources may provide data when an applicable legal basis exists.

Sensitive personal data requires stronger safeguards.

The categories listed above are non-sensitive personal data. If a specific operation uses biometric data or any other sensitive data defined by Article 5(II), OM DTVM LTDA must disclose that operation and identify one of the specific legal grounds under Article 11. This Policy does not claim that unconfirmed sensitive collection takes place.

03 · PURPOSES AND LEGAL BASES

Consent is not the answer to everything.

The LGPD provides different legal grounds for processing. The ground must correspond to the concrete purpose and operation and cannot be selected generically.

01

Provide and manage services

Identify the data subject, respond to requests, maintain the relationship and provide requested products, services and procedures.

Data involved
Identification, contact, financial and transactional data.
Legal basis
Performance of a contract or preliminary procedures — Article 7(V).
Example: using the registration data required to open and administer the relationship requested by the customer.
02

Comply with legal or regulatory duties

Meet obligations applicable to OM DTVM LTDA’s activities and respond to competent authorities.

Data involved
Registration, financial and transactional data and required records.
Legal basis
Compliance with a legal or regulatory obligation — Article 7(II).
Example: retaining a record when an applicable obligation prevents its immediate deletion.
03

Prevent fraud and protect transactions

Verify identity, authenticate access and reduce the risk of unauthorized transactions.

Data involved
Identification, access, device and security records.
Legal basis
The basis is defined for the specific operation; when sensitive data is used for authentication and fraud prevention, Article 11(II)(g) applies.
Example: analyzing access signals to assess whether an attempt is consistent with legitimate account use.
04

Exercise legal rights

Produce and retain information required for defense in judicial, administrative or arbitration proceedings.

Data involved
Data related to the fact, contract, support contact or transaction under discussion.
Legal basis
Regular exercise of rights — Article 7(VI).
Example: retaining evidence of a request and the response that was provided.
05

Improve the experience and services

Understand the use of channels and measure quality and satisfaction, using data minimization and anonymization when appropriate.

Data involved
Interactions, browsing, preferences and support history.
Legal basis
Legitimate interest, when a concrete assessment demonstrates necessity and respect for the data subject’s expectations and rights — Articles 7(IX) and 10.
Example: identifying a step with a high abandonment rate in order to make it clearer, without reusing the data for an incompatible purpose.
06

Communicate news and offers

Send information about products, services, news, offers or promotions related to the OM Group and its partners.

Data involved
Name, email address, telephone number and contact preferences.
Legal basis
Consent or another ground applicable to the specific context, with transparency and a right to object or unsubscribe.
Example: stopping promotional messages when the data subject asks through the privacy channel.
05 · DATA SUBJECT RIGHTS

See the right and understand how it works.

Open each item to review an example request and the corresponding legal reference. Exercising rights is free of charge and may require identity verification in order to protect the data itself.

01
Confirm processing and access data“I want to know whether you process my data and receive a copy.”

You may request confirmation that processing exists and access to the data. The LGPD provides for an immediate simplified response or a clear and complete statement within up to 15 days, subject to the applicable legal conditions.

LGPD · Articles 18(I) and (II), and 19
02
Correct data“My telephone number has changed and my registration is out of date.”

You may request the correction of incomplete, inaccurate or outdated data.

LGPD · Article 18(III)
03
Anonymize, block or delete“This data is excessive or was used in breach of the Law.”

You may request one of these measures for unnecessary or excessive data or data processed in violation of the LGPD. The request will be assessed according to the context and applicable retention duties.

LGPD · Article 18(IV), and Article 16
04
Request portability“I want to transfer my data to another service provider.”

Portability may be requested expressly, subject to the applicable regulation and protection of trade and industrial secrets.

LGPD · Article 18(V)
05
Learn about sharing“Which public or private entities received my data?”

You may request information about the entities with which your personal data has been shared.

LGPD · Article 18(VII)
06
Decide about consent“What happens if I do not authorize this use?”

When consent is the legal basis, you must be informed of the possibility of refusing it and the consequences of that choice.

LGPD · Article 18(VIII)
07
Withdraw consent“I changed my mind and want to withdraw my authorization.”

Withdrawal must be free and facilitated. It does not invalidate processing lawfully carried out before the request.

LGPD · Articles 8(5) and 18(IX)
08
Request deletion of consent-based data“I want the data processed under my consent to be deleted.”

You may request deletion of personal data processed on the basis of consent, subject to the retention situations authorized by the LGPD.

LGPD · Articles 18(VI) and 16
09
Object to unlawful processing“No consent was required, but I believe the Law is not being followed.”

You may object to processing based on a legal ground that does not require consent when the LGPD has been breached.

LGPD · Article 18(2)
10
Review automated decisions“An automated decision affected my interests and I want to understand it.”

You may request review and clear information about the criteria and procedures used in decisions made solely through automated processing, subject to trade and industrial secrecy.

LGPD · Article 20
HOW TO REQUEST

Write to the privacy channel.

  1. State which right you wish to exercise.
  2. Describe the data or relationship to which the request refers.
  3. Wait for instructions on secure identity verification.
Send request ↗
06 · SHARING AND INTERNATIONAL TRANSFERS

Sharing does not mean unrestricted use.

Access by another organization must be connected to a purpose, limited to what is necessary and protected by duties compatible with the LGPD.

Who may receive data

  • Companies in the same economic group, when necessary and compatible with the disclosed purpose.
  • Government bodies, competent authorities and courts when an applicable legal basis exists.
  • Financial institutions and partners involved in carrying out transactions and services.
  • Technology, infrastructure, support, security and other contracted service providers acting as processors.
  • Participants in a corporate transaction when sharing is necessary for negotiations or restructuring.
INTERNATIONAL TRANSFER

What if a provider is outside Brazil?

Service providers involved in processing may be located abroad. When this constitutes an international transfer of personal data, the operation must meet one of the conditions in Article 33 and preserve the principles and rights established by the LGPD.

Legal references: Articles 33 to 36.
07 · RETENTION, SECURITY AND INCIDENTS

Protection throughout the data life cycle.

Security must be present from the design of a service and continue for as long as processing or a duty of protection remains.

Measures already described

Access limitation, authentication mechanisms, multi-factor authentication and an inventory of connection records are among the measures described by OM DTVM LTDA.

Retention period

Processing ends when the purpose has been achieved, the period expires, an applicable withdrawal takes place or the authority issues a determination. Retention may continue in the situations listed in Article 16.

Relevant incident

If an incident may create a relevant risk or harm, the controller must notify the authority and affected data subjects with the information and measures provided by Article 48.

Legal references: Articles 15, 16 and 46 to 49 of the LGPD.

08 · CHILDREN AND ADOLESCENTS

Best interests come first.

The purposes described in this Policy are not specifically directed at children or adolescents and do not, by themselves, create an age requirement for use of the application. If data relating to this audience is processed, best interests, appropriate transparency and the specific conditions in Article 14 of the LGPD must be observed.

09 · COOKIES AND PREFERENCES

You choose what is optional.

Cookies are small records stored on or read from a device. When their use involves personal data, the LGPD’s principles, rights and legal bases also apply.

Manage my preferences
10 · EFFECTIVE TERM AND UPDATES

Transparency also applies when something changes.

This Policy remains effective for an indefinite term and may be changed whenever compliance adjustments related to the LGPD are required, including changes to products, services, processes, structure or applicable requirements. Changes affecting essential information under Article 9 will be highlighted; when consent is required, the data subject may withdraw it if they disagree with a new purpose.

This translated version is provided to improve accessibility. The LGPD is a Brazilian law and its official Portuguese text remains the controlling legal reference.

DATA PROTECTION OFFICER AND PRIVACY CHANNEL

Adriano Nascimento Felipe

Data Protection Officer (DPO) of OM DTVM LTDA. Use the email below for questions or data subject requests. Do not send passwords or complete financial information in the first message.
dpo@ourominas.com