The 10 principles of the LGPD

Wolkee supports and guides its clients in the correct use and mapping of the data they collect, following each of the principles below.

Purpose

Data is always used for a legitimate, specific purpose disclosed to the data subject. As a processor, Wolkee strictly follows the guidelines set out in the service agreement with the client company.

Adequacy

Data is processed in a way that is compatible with the purpose disclosed to and approved by the data subject. The client company ensures adequacy; Wolkee operates within the limits of the contract.

Necessity

Only strictly necessary data is processed, without exceeding what was communicated to and authorized by the data subject, following the client company's guidelines.

Free access

Data subjects have the right to see how their data is used. The client company guarantees this access to its end customers; data stored at Wolkee is not accessed directly by the data subject.

Data quality

Data subjects can review their data to ensure it is accurate and up to date. Updates made in the client company's databases are automatically replicated to Wolkee's systems.

Transparency

Clear information about how data is processed, leaving no doubt for the data subject. The client company ensures clarity for its audience, and Wolkee follows the contract guidelines.

Security

Technical and administrative measures protect data against incidents. Data is stored on the Microsoft Azure cloud, with encryption and internationally approved protocols, including the European GDPR.

Prevention

Security measures and internal training prevent harm in the processing of personal data. Employees, contractors and partners sign the Code of Ethics and Conduct every year.

Non-discrimination

No data is used for discriminatory or abusive purposes, whether related to racial or ethnic origin, political opinion, religion, geolocation, union membership, health or sexual orientation.

Accountability

Wolkee performs due diligence on each client company before signing the contract, demonstrating the adoption of effective measures for compliance and for protecting data subjects' data.

Environment and data transmission

All of Wolkee's infrastructure is built on the Microsoft Azure cloud, a global benchmark in security and compliance.

Azure environment

Wolkee's platforms run on Azure with two clusters: the Front-End Web Cluster, responsible for connection and initial authentication, and the Back-End Cluster, which handles subsequent interactions. Data is stored in Azure Blob Storage and Azure SQL Database.

Encrypted transmission

Transmission runs through an on-premises Data Gateway on a Windows server, which communicates with Azure through a secure tunnel with two-factor authentication, a unique 32-character password and 256-character token validation, using the AES-256 encryption standard.

How we keep your data secure

Technical

  • Data stored 100% on the Microsoft Azure cloud, with security concepts approved by programs such as the European GDPR.
  • Gateway with two-factor authentication and unique login, with 32-character passwords and 256-character tokens.
  • Semiannual review of all client, partner and employee access.
  • Data access authorized by the client company, with all access monitored and logged.

Administrative

  • Clients and partners notify Wolkee within 5 business days when people with data access leave.
  • Employees, contractors and partners sign the Code of Ethics and Conduct every year, with clear data protection responsibilities.
  • All contracts with clients and partners include a confidentiality clause (NDA), without exception.
  • Due diligence process with each client company before the contract is signed.

Questions about how we handle your data? Our team can answer any privacy and security question.

View official documents →