Home / Governance and Compliance / Privacy and Data Protection Policy
Privacy and Data Protection Policy
- Who is the controller of your data
- Data Protection Officer (DPO)
- Principles we follow
- Data we process and why
- Legal bases for each processing activity
- Cookies and browsing technologies
- Sharing and processors
- International transfer
- Retention and deletion
- Information security
- Your rights as a data subject
- How to exercise your rights
- Personal data incidents
- Effective date and changes
1. Who is the controller of your data
This Privacy Policy describes how Axia Mineração S.A., which operates in the market under the brand AXIA Resources, processes personal data in its activities, on its corporate website and in its relationship channels.
| Corporate name | Axia Mineração S.A. |
| CNPJ | 44.035.911/0001-20 |
| Administrative headquarters | SIA Trecho 3, Lote 1530, Parte — Zona Industrial (Guará), Brasília-DF, CEP 71.200-033 |
| Other units | Goiânia-GO and Bom Jardim de Goiás-GO |
| Corporate website | axiaresources.com.br |
| Privacy channel | dpo@axiaresources.com.br |
In most of the operations described here, AXIA acts as controller, that is, it determines the purposes and means of the processing. When we process personal data on behalf of and under the instructions of a client — which occurs in the provision of technological and administrative support services — we act as processor, and the applicable obligations are those set forth in the contract entered into with the controller.
2. Data Protection Officer (DPO)
In compliance with Article 41 of Law No. 13,709/2018 (LGPD), AXIA has formally appointed its Data Protection Officer (DPO), who is responsible for receiving communications from data subjects and from the ANPD (Brazilian National Data Protection Authority) and for providing guidance to internal departments.
Data Protection Officer (DPO) — principal
Ms. Nayaara Rodrigues de Brito
Board of Directors of AXIA Resources
Alternate — external and independent
Mr. Sanclé Albuquerque
Independent External Specialist
Acts in the absence or impediment of the principal and, mandatorily, when the request or incident involves the Board of Directors itself, thereby preserving the impartiality of the investigation.
3. Principles we follow
All processing of personal data carried out by AXIA observes the principles set out in Article 6 of the LGPD. In practice, this means:
| Principle | What we do to comply with it |
|---|---|
| Purpose | Each processing activity has a specific purpose declared before collection. We do not use data for any purpose incompatible with the one communicated. |
| Adequacy | The processing is compatible with the purpose communicated to the data subject at the time of collection. |
| Necessity | We collect the minimum necessary. Fields that are not indispensable to the purpose are not required. |
| Free access | We guarantee easy and free-of-charge consultation on the form, duration and completeness of the data processed. |
| Data quality | We keep data accurate and up to date; correction may be requested at any time. |
| Transparency | We clearly disclose who processes the data, for what purpose and with whom we share it — which is the objective of this policy. |
| Security | We apply technical and administrative protection measures, described in section 10. |
| Prevention | We assess privacy risks before starting new or high-risk processing activities. |
| Non-discrimination | We do not process data for discriminatory, unlawful or abusive purposes. |
| Accountability | We keep records of the operations, decisions and evidence that demonstrate compliance. |
4. Data we process and why
We process personal data only in the situations below. If you interact with us in any other way, the purpose and legal basis will be communicated at the time of collection.
| Situation | Data processed | Purpose |
|---|---|---|
| Contact form | Name, e-mail and message content | Respond to the request and keep a record of the interaction |
| Download of materials | Release the requested material and, with consent, send institutional communications | |
| Website browsing | IP address, device type, browser, pages visited and date/time | Keep the website running, ensure its security and produce aggregate audience statistics |
| Applications and résumés | Identification, contact, education and professional experience data | Conduct selection processes and build a talent pool, when authorized |
| Relationships with suppliers and partners | Data of legal representatives and contacts; shareholding structure in integrity due diligence | Perform contracts, comply with legal obligations and assess integrity risks |
| Ombudsman and reporting channel | Data voluntarily provided by the reporter — the report may be anonymous | Investigate the report with confidentiality and protection against retaliation |
| Visits to units | Name, identity document and time of entry and exit | Control physical access and the security of the facilities |
| Provision of services to clients | As defined by the controller client in the contract | Perform the contracted service, in the capacity of processor |
We do not process data of children and adolescents
Our channels and services are intended for adult and corporate audiences. We do not intentionally collect data from persons under 18 years of age. If we identify any such collection, the data is deleted. If you suspect this has occurred, write to dpo@axiaresources.com.br.
5. Legal bases for each processing activity
No processing is initiated without an identified legal basis, in accordance with Articles 7 and 11 of the LGPD.
| Processing | Legal basis (LGPD) | Note |
|---|---|---|
| Response to contact and customer service | Art. 7, IX — legitimate interest | The data subject initiated the contact and expects a response |
| Sending of institutional communications | Art. 7, I — consent | Revocable at any time, without prejudice to the service |
| Website security and operation | Art. 7, IX — legitimate interest | Minimal technical logs, retained for a short period |
| Selection processes | Art. 7, V — preliminary procedures related to a contract | The talent pool depends on specific consent |
| Performance of contracts with suppliers and clients | Art. 7, V — performance of a contract | Includes data of representatives and agents |
| Integrity due diligence | Art. 7, II and IX — legal obligation and legitimate interest | Law No. 12,846/2013 (Brazilian Anti-Corruption Law) and Decree No. 11,129/2022 |
| Retention of tax, accounting and labor records | Art. 7, II — compliance with a legal obligation | Periods defined in specific legislation |
| Access control at the units | Art. 7, IX — legitimate interest | Protection of people, information and property |
| Investigation of integrity reports | Art. 7, II and IX — legal obligation and legitimate interest | Confidentiality and non-retaliation ensured |
| Regular exercise of rights in proceedings | Art. 7, VI — regular exercise of rights | Judicial, administrative or arbitral |
When the legal basis is legitimate interest, we carry out a prior assessment that weighs the purpose, the necessity and the impact on the data subject, and we adopt safeguards to reduce that impact. You may request information about this assessment through the Data Protection Officer’s channel.
6. Cookies and browsing technologies
We use cookies and similar technologies to keep the website running, remember preferences and measure audience in aggregate form. The breakdown by category, and the purpose and duration of each cookie, are set out in the Cookie Policy.
| Category | Requires consent? | What it is used for |
|---|---|---|
| Necessary | No | Basic operation, security and language preference. Without them the website does not operate properly. |
| Performance and analytics | Yes | Aggregate browsing statistics, to improve content and usability. |
| Functional | Yes | Remember choices you have made, such as language and completed forms. |
You can manage your consent through the notice displayed on your first visit and review it at any time, in addition to blocking or deleting cookies in your browser settings. Refusing non-necessary cookies does not prevent browsing.
7. Sharing and processors
We do not sell personal data and do not share it for third-party advertising purposes. Sharing takes place only when necessary and always with contractual safeguards:
- Technology providers that host the website, corporate e-mail and cloud environments, acting as processors and under contracts containing data protection clauses;
- Partner universities and support foundations in research projects, within the limits of the instrument entered into and with defined ownership and confidentiality rules;
- Legal and accounting advisors, when indispensable to compliance with a legal obligation or to the regular exercise of rights;
- Public authorities, when there is a legal request, court order or legal duty of disclosure — in which case we assess the legitimacy of the request before complying.
Every processor engaged by AXIA contractually assumes obligations of confidentiality, information security, incident notification and deletion or return of the data at the end of the relationship. The engagement of sub-processors requires prior authorization.
8. International transfer
Personal data processed by AXIA is preferably stored in Brazilian territory. When an essential service requires processing outside the country, we adopt the safeguards provided for in Chapter V of the LGPD — specific contractual clauses, standard contractual clauses or another instrument accepted by the ANPD — and we record the transfer in our inventory of processing operations. The list of countries and organizations involved may be requested through the Data Protection Officer’s channel.
9. Retention and deletion
We retain data only for as long as necessary for the purpose for which it was collected, subject to the legal retention periods. Once the period has ended, the data is securely deleted or anonymized.
| Category | Reference period | Criterion |
|---|---|---|
| Contact and customer service messages | 2 years | Relationship history and defense of rights |
| Technical browsing logs | 6 months | Brazilian Internet Civil Framework (Law No. 12,965/2014), Art. 15 |
| Résumés of candidates not hired | 1 year | Only with consent for the talent pool |
| Contracts and tax documents | 5 to 10 years | Applicable civil, tax and labor legislation |
| Integrity reports and investigations | 5 years after closure | Integrity program and defense of rights |
| Access control at the units | 1 year | Property security |
10. Information security
The protection of personal data at AXIA is supported by the Information Security Management System, structured in accordance with ABNT NBR ISO/IEC 27001:2022. The measures applied include:
Access control
Access granted on a least-privilege basis according to the role, with named identity, periodic review and revocation within 24 hours upon termination.
Technical protection
Encryption in transit and at rest according to the classification of the information, network protection, anti-malware and vulnerability management.
Continuity
Backup routines with periodic restoration testing, with recovery time measured and verified.
Governance
Security policy approved by the Board of Directors, with formal acceptance recorded by employees and third parties.
Awareness
Periodic training in privacy and security, with verification of understanding and not merely recording of attendance.
Incident response
Defined process for detection, containment, eradication, recovery and communication, with assessment of the risk to the data subject.
11. Your rights as a data subject
Article 18 of the LGPD grants you the rights below. All of them may be exercised free of charge through the Data Protection Officer’s channel.
| # | Right | What it means in practice |
|---|---|---|
| 1 | Confirmation of the existence of processing | To know whether we process any of your personal data. |
| 2 | Access to data | To obtain a copy of the data we hold about you, in a readable format. |
| 3 | Correction | To correct incomplete, inaccurate or outdated data. |
| 4 | Anonymization, blocking or deletion | To address data that is unnecessary, excessive or processed in non-compliance with the law. |
| 5 | Portability | To transfer your data to another provider, in accordance with ANPD regulations. |
| 6 | Deletion of data processed with consent | To erase the data we process on the basis of your consent, except in cases of legally required retention. |
| 7 | Information about sharing | To know with which public and private entities we share your data. |
| 8 | Information about the possibility of not consenting | To be informed of the consequences of refusing consent. |
| 9 | Revocation of consent | To withdraw consent at any time, through a free and simplified procedure. |
| 10 | Review of automated decisions | To request review of a decision made solely on the basis of automated processing. AXIA does not adopt automated decisions with legal effect on data subjects. |
You may also object to processing carried out on the basis of one of the cases in which consent is waived, in the event of non-compliance with the LGPD, and petition the Brazilian National Data Protection Authority directly.
12. How to exercise your rights
Official Data Protection Officer channel
Send your request to dpo@axiaresources.com.br, stating your name, the right you wish to exercise and the data necessary for your identification.
- Receipt and registration. Every request is recorded with a date and a protocol number, which is provided to you.
- Identity confirmation. We may request additional information to confirm that you are the data subject — this is a protective measure against fraudulent requests, and the data used for this confirmation is not used for any other purpose.
- Analysis and response. We respond within 15 days of receipt, in accordance with Article 19, II, of the LGPD. For confirmation or access requests, the response may be immediate in simplified format.
- Refusals are substantiated. If it is not possible to comply — for example, when there is a legal retention obligation — we inform you of the reason and the legal grounds.
- No cost. The exercise of rights is free of charge, pursuant to Article 18, § 5.
13. Personal data incidents
If a security incident occurs that may result in relevant risk or damage to data subjects, AXIA notifies the Brazilian National Data Protection Authority and the affected data subjects within a reasonable period, in accordance with Article 48 of the LGPD and ANPD regulations. The notification states the nature of the data involved, the data subjects affected, the technical measures adopted, the risks and the mitigation measures.
Internally, every incident is recorded, classified by severity, contained, investigated as to its cause and used to adjust controls. The assessment of risk to the data subject is conducted by the Data Protection Officer.
14. Effective date and changes
This policy may be updated to reflect changes in our activities, in legislation or in ANPD regulations. The version in force is always the one published on this page, with the revision date indicated below. Relevant changes are communicated through our channels.
| Current version | 1.0 |
| Revision date | September 23, 2026 |
| Approval | Board of Directors of Axia Mineração S.A. |
| Next review | Annually or upon a relevant change in processing, legislation or technology |
| Corresponding internal document | POL-008 — Privacy and Data Protection Policy of the Integrated Management System |
Questions about this policy may be sent to the Data Protection Officer (DPO) at dpo@axiaresources.com.br.