Last updated on 12/30/2020
1. Who is the controller of your personal data?
Multiplan is the controller of personal data for the purposes of processing personal data described herein. For the purposes of the applicable data protection legislation, the controller is responsible for decisions regarding the processing of personal data.
The personal data we collect depends on the context of your interactions with Multiplan and its Malls. To facilitate your understanding, we herein explain how we treat the data (i) of customers who attend the Malls (“Customers”) and (ii) of users of the Website (“User”), who may also be our Customers.
It is important that you know that specific privacy policies may apply to some of our products and services (such as, for example, our loyalty programs, promotions and applications). More information about these policies will be provided from time to time when you interact with such products and services.
2.1. What personal data do we collect?
Generally speaking, when a Customer (or, for the purposes of this section, “You”) visits a Mall, contacts us to seek information about our Services or, in any other way, uses or interacts with us, we collect his/her personal data. These data can be divided into three categories, according to the origin and form of collection, as follows:
(i) Data you provide to us directly. Such data may include:
- Full name, email, address, phone and cell phone numbers;
- Numbers and, exceptionally, copies of your identity documents (such as ID and Individual Taxpayer ID);
- Date of birth, age group and gender;
- Educational and professional background;
- Your car’s or other motor vehicle license plate;
- Payment data;
- Feedback about experiences in our Malls and about our Services;
- Information on purchased products and evaluation or preference about the establishments existing in the Malls;
- Other data you have spontaneously shared with us.
(ii) Data we collect automatically while interacting with you, for example, when you connect to our Wi-Fi network or walk through our Malls. Such data may include:
- Data from your devices, such as your IP address, operating system, geolocation information and your device’s identifier;
- Images of fixed or retractable security cameras of the Malls;
- Vehicle license plate recognition;
- Photos and videos of events.
(iii) Data we collect from other sources. On some too specific occasions, we may collect personal data about you from other sources, such as on third party complaint sites, public databases or authorized partners, public profiles or interactions with us on social networks or through companies providing services on the premises of our Malls.
As a rule, Multiplan does not collect sensitive data from its Customers. However, should this type of data collection occur, Multiplan shall take all the measures required to ensure the legality of the processing and inform you about the referred processing (by updating this Policy or by communicating directly with you).
2.2. What do we use your personal data for?
We use Customer’s personal data collected or received for the following purposes:
- Receiving feedbacks and questions through our channels, such as Contact Forms;
- Allowing your access to the internet through the Wi-Fi network provided by the Malls;
- Managing promotions and events and ensuring you can take part in if you are interested; enabling communications with you, including sending and receiving emails and text messages (SMS). This may include, but is not limited to, marketing communications about products and services available at our Malls, as well as promotions and events that may interest you;
- Disclosing our events and promotions on our websites and social networks;
- Enriching data on attendance at Malls and direct promotions of interest;
- Enabling equipment loans from our Malls, according to availability, such as baby strollers, Smart strollers, wheelchairs and motorized chairs, cell phone chargers and pet strollers;
- Providing services in baby changing facilities and concierges;
- Recording loss of objects and making returns of objects found in our Malls;
- Storing your objects, such as purchases and bags, in our lockers;
- Calling or locating people;
- Issuing invoices related to the Services with your Individual Taxpayer ID, as applicable;
- Ensuring the booking and provision of specific Services offered by some of the Malls;
- Managing the Customer Service and performing related activities and Services;
- Making reports in our Malls (vehicle and store breakdowns, for example) and promoting eventual reimbursements;
- Ensuring the physical and patrimonial security of our Customers, of our Malls and Stores;
- Controlling entrance, permanence and exit of vehicles in the parking lots of the Malls;
- Carrying out the charge for the permanence in the parking lots;
- Checking card losses at the Malls' parking lots and allowing vehicles to leave, as applicable;
- Ensuring your attendance at the Malls’ ambulatory, as applicable;
- Defending Multiplan's rights, as required, and complying with legal and regulatory obligations;
- Serving our legitimate interests, as long as it does not pose any risk to your rights and freedoms.
Aiming at achieving some of the above purposes, the processing of your data may be based on your consent. Should this situation occur, we will ensure that this consent is freely-given, informed and unambiguous in relation to the purpose of collection.
2.3. Third-party establishments
Given the nature of the Services provided by Multiplan, you will be able, on several occasions, to share personal data with establishments on the premises of the Malls - such as stores, cinemas, restaurants and parking management companies. Unless otherwise stated, Multiplan does not interfere with the purposes for which personal data are collected by these establishments, nor does it participate in its processing, so that the responsibility for the protection of your data and the legality of the data processing will be exclusively on those third parties.
3.1. What personal data do we collect?
In general, when a User (or, for the purposes of this section, “You”) browses our Website, we collect personal data automatically*. Such data may include:
- Browsing data (for example, IP address, location - country, information about the pages visited by the User within the Website, access time on the Website, browsing time on each page, hit tracking analysis);
- Cookies, that is, small text files that can be sent and registered on the User’s computer that resemble the websites visited, providing a better experience for the User the next time the websites are visited. For more information on Cookies, see subsection 3.3. bellow.
(*) For processing of personal data that starts on the Website but directs you to other Multiplan services (such as applications or loyalty programs), please refer to the specific policies of those services.
3.2. What do we use your personal data for?
We collect personal data during your browsing on the Website for the following purposes:
- Developing, keeping and improving the features and functionalities of the Website;
- Enabling access and use of the website’s features and functionalities;
- Analyzing the performance and measuring the audience of the Website and of the establishments and services disclosed, checking the browsing habits of the Users and the way in which they reached the Website page (for example, through links from other websites, search engines or directly by address), evaluating statistics related to the number of accesses and use of the Website;
- Analyzing the redirection to third party websites and services from the access by links on the Website;
- Improving Users’ browsing experiences;
- Allowing the provision of services that are more personalized and suited to the needs of Users, such as profile pages, updates, content and relevant advertisements;
- Identifying the profiles, habits and needs for possible service offerings and strategy development of Multiplan and the Malls.
Multiplan may use electronic instructions, known as “cookies”, which will be sent to the browser and stored on your computer’s disk.
Some cookies are necessary for the functioning of the Website. These cookies are generally set in response to actions taken by you, such as setting privacy preferences, logging in or filling out forms.
Another purpose of cookies is to collect information about how you use the Website. Performance cookies help us, for example, to identify especially popular areas of our website. In this way, we can adapt the content of our sites more specifically to your needs and, thus, improve the customer experience and, eventually, facilitate your browsing with the characteristics, preferences and quality of the information conveyed to your browsing. These cookies are used to send relevant advertising and promotional information to you, for example, based on the web pages you have visited, within the limits authorized by law.
We inform you that Multiplan does not currently use a technical solution that allows us to fully respond to the “do not track” signals from your browser. Still, you can manage your cookie settings in your browser settings any time you want. While disabling all cookies in your browser settings, it is possible that certain sections or features of the Website may not work or cause a too long delay to load the content, as your browser may prevent us from setting the required cookies.
3.4. Third-party websites
Third-party websites that may be accessible from the Multiplan website are under the responsibility of the respective third parties. Multiplan will not be responsible for ordering and/or providing personal data on third-party websites. We recommend that you consult the respective privacy policies of such websites to get informed about the use of your personal data on such occasions.
4. With whom do we share your personal data?
We may share the personal data collected with other companies in Multiplan's economic group, with third parties and business partners, which are relevant for the purpose of enabling the provision of the Services and to achieve the purposes described herein. Said sharing occurs based on the following criteria and for the purposes described below.
- Multiplan group’s companies: Companies and entities managed by Multiplan (under its direct or indirect management) may share among themselves the personal data collected from the provision of the Services in order to operate, execute, improve, understand, personalize, support, advertise our Services, develop strategies, exercise rights and prevent fraud.
- Third-party service providers: We work with third-party service providers to help us operate, execute, improve, understand, personalize, support and advertise our Services. When we share data with third-party service providers, we require them to use your data in accordance with our instructions and terms or with your express consent, where applicable.
- Business partners: We may share your personal data with business partners in specific cases (for example, for the purposes of joint events and promotions). In such cases, we will ensure that you are aware of the sharing and, when required, we will collect your consent to do so.
- Credit Protection Entities: in too specific cases, we may share your registration data with entities dedicated to reducing credit risk and protecting companies and individuals against fraud, in order to validate the information provided by you.
- Regulatory bodies, judicial or administrative authorities: we may share your personal data to provide the competent authorities with all information requested in relation to the Customer. In addition, we may share your personal data with public authorities or private entities to fight fraud and abuse in the use of the Services, to investigate suspected violations of the law, to defend our rights or to fight any other suspected non-compliance with our policies and contracts.
- Asset Transfer: if Multiplan's corporate structure is reorganized and its assets are transferred to a new owner, your personal information can be transferred to the buyer regardless of your authorization to ensure the continuity of the services;
- With your authorization: In other cases not provided for above, with the purpose of sharing personal data and information, if necessary, we will send you a notification with information regarding such sharing to request your consent, for a determined purpose.
5. Transfers of your personal data outside of Brazil
Exceptionally, Multiplan may transfer some of your personal data to partners or service providers located abroad, including providers of cloud technology services. When personal data is transferred outside Brazil, Multiplan will take appropriate measures to ensure adequate protection of personal data in accordance with the requirements of the applicable data protection legislation, including by entering into relevant data transfer agreements with third parties when required.
6. How long do we store your personal data?
We store and keep your information: (i) for as long as required by law; (ii) until the end of the processing of personal data, as mentioned below; or (iii) for the time required to preserve Multiplan's legitimate interest (as, for example, during applicable periods of limitation or compliance with legal or regulatory obligations).
The end of the processing of personal data will occur when it is verified:
- That the purpose for which the data was collected has been achieved, and that the personal data collected is no longer required or relevant to the achievement of the pursued specific purpose;
- A statement by the Customer in this regard, at the end of the relationship between Multiplan and the Customer; or
- Legal order.
In the case of revocation of consent or request for the deletion of your personal data, some information may still be kept as required to comply with legal obligations, regular exercise of rights, attendance of legitimate interest, and fraud detection and prevention.
7. What are your rights in relation to the personal data processed?
You have rights regarding to your personal data, including:
- Confirmation of the existence of personal data processing: Upon request of the Customer, Multiplan will confirm the existence of personal data processing, under the terms of the applicable legislation;
- Access to personal data: The Customer can request access to his/her personal data processed and stored by Multiplan;
- Correction of incomplete, inaccurate or outdated data: The Customer can and must, at any time, correct and update his/her personal data, being responsible for the data reported;
- Information on shared data usage: The Customer may have access to additional information on the possible sharing of his/her personal data;
- Objection to data processing: The Customer may express his/her willingness not to have his/her data processed by Multiplan at any time, by means of a free and facilitated statement, if he/she understands that the processing of the data is unnecessary, excessive or violates any provision of the applicable data protection legislation. In relation to marketing communications, the Customer may also stop receiving them, indicating the option of unsubscribing, which will be made available in all messages sent to him/her. The processing carried out before the opposition is ratified. The objection will not automatically imply the end of the processing of personal data that is kept by Multiplan based on other legal grounds;
- Petition before the ANPD: The Customer has the right to petition before the National Data Protection Authority (ANPD) in relation to the processing of his/her personal data by Multiplan.
To exercise any of the above rights, contact our Supervisor through the website available at https://www.multiplan.com.br. In some cases, we may not be able to respond to your request. Should this situation occur, we will properly explain the de facto and legal grounds that prevent us from attending to you.
8. How do we treat your data and ensure your security?
Personal data will be processed exclusively in accordance with the terms described herein and in accordance with the principles of transparency, necessity, mitigation and legality provided for in the applicable data protection and privacy legislation.
Personal data can be processed in printed form or in automatic electronic format and through post, email, phone, facsimile and any other electronic channel.
Multiplan uses appropriate technical and organizational measures to protect personal data against unauthorized or illegal processing and against accidental loss, destruction or damage. Personal data is securely stored on protected equipment and servers with controlled access.
Despite the best efforts made by the Multiplan Group to protect and preserve the data made available to it, it is important that the individuals are aware that such measures may not be sufficient to prevent any incidents, invasions or leaks that occur beyond our protection range.
9. Children Data
As a rule, we do not process children data to provide our Services for purposes other than the protection of life and physical safety. However, exceptionally, the collection of registration data from children may occur (as, for example, within the scope of the provision of specific services available in some of our Malls, such as children events). In such cases, we will ensure that the child’s legal guardians are aware of the processing of the data and give their consent to do so.
10. Person in Charge