Purpose
The purpose of this document is to inform and document the security and data protection measures implemented by B2 Mídia, demonstrating its commitment to ensuring the privacy and security of the personal information of its customers, employees, and partners, in accordance with the regulations established by Brazil's General Data Protection Law (LGPD). The document highlights the security practices and policies adopted, as well as the company's ongoing commitment to maintaining and improving these measures, promoting a culture of security within the organization.
Security Measures
B2 Mídia is committed to ensuring the privacy and security of the personal information of our customers, employees, and partners, as established by the General Data Protection Law (LGPD). In this document, we detail the security measures we implement to protect the personal data we collect and process.
- Restricted Access: We implement restricted access policies for personal data. Only authorized employees, who perform specific functions related to data processing, are permitted to access personal information. Access is granted based on the need-to-know principle, ensuring that only people who need this data have access to it.
- Data Encryption: We use encryption to protect personal data in transit and at rest. This means information is encoded so that only authorized people can interpret it. Encryption is applied at every stage of data processing.
- Authentication Measures: We implement robust authentication systems to ensure that only authorized users can access personal data. This includes requiring strong passwords, two-factor authentication, and other identity verification methods.
- Security Audits: Regular security audits are planned to identify potential vulnerabilities in our systems and processes. These audits will be conducted by information security professionals and will help ensure the integrity of personal data.
- Protection Against Malware and Cyber Threats: We keep security systems up to date to protect our systems against malware, viruses, and other cyber threats. This includes implementing firewalls, antivirus software, and proactive threat detection measures.
- Data Backup: We perform regular data backups to ensure the availability and recovery of information in the event of unexpected events, such as hardware failures or cyberattacks.
- Security Training: All employees undergo regular information security training. They are educated on best security practices and made aware of the importance of protecting personal data.
- Incident Management: Our incident response plan for handling any data breach that may occur includes proper notification to authorities and data subjects, as required by the LGPD.
- Vendor Assessment: When working with partners and vendors who have access to personal data, we require them to maintain rigorous information security standards and comply with the LGPD.
- Continuous Improvement: We are committed to regularly reviewing and updating our security measures as new threats emerge and technologies evolve. Our goal is to maintain the highest standards of data protection.
This document reflects our unwavering commitment to information security and compliance with the LGPD. We are dedicated to protecting the personal data of data subjects and promoting a culture of security throughout the organization.