Skip to main content

Axia Mineracao SA

Home / Governance and Compliance / Privacy and Data Protection Policy

Law No. 13,709/2018 — LGPD (Brazil’s General Data Protection Law)

Privacy and Data Protection Policy

This policy explains which personal data we process, for what purpose and on what legal basis, with whom we share it, how long we retain it and how you exercise the rights that the LGPD grants you.

1. Who is the controller of your data

This Privacy Policy describes how Axia Mineração S.A., which operates in the market under the brand AXIA Resources, processes personal data in its activities, on its corporate website and in its relationship channels.

Corporate nameAxia Mineração S.A.
CNPJ44.035.911/0001-20
Administrative headquartersSIA Trecho 3, Lote 1530, Parte — Zona Industrial (Guará), Brasília-DF, CEP 71.200-033
Other unitsGoiânia-GO and Bom Jardim de Goiás-GO
Corporate websiteaxiaresources.com.br
Privacy channeldpo@axiaresources.com.br

In most of the operations described here, AXIA acts as controller, that is, it determines the purposes and means of the processing. When we process personal data on behalf of and under the instructions of a client — which occurs in the provision of technological and administrative support services — we act as processor, and the applicable obligations are those set forth in the contract entered into with the controller.

2. Data Protection Officer (DPO)

In compliance with Article 41 of Law No. 13,709/2018 (LGPD), AXIA has formally appointed its Data Protection Officer (DPO), who is responsible for receiving communications from data subjects and from the ANPD (Brazilian National Data Protection Authority) and for providing guidance to internal departments.

Data Protection Officer (DPO) — principal

Ms. Nayaara Rodrigues de Brito
Board of Directors of AXIA Resources

dpo@axiaresources.com.br

Alternate — external and independent

Mr. Sanclé Albuquerque
Independent External Specialist

Acts in the absence or impediment of the principal and, mandatorily, when the request or incident involves the Board of Directors itself, thereby preserving the impartiality of the investigation.

3. Principles we follow

All processing of personal data carried out by AXIA observes the principles set out in Article 6 of the LGPD. In practice, this means:

PrincipleWhat we do to comply with it
PurposeEach processing activity has a specific purpose declared before collection. We do not use data for any purpose incompatible with the one communicated.
AdequacyThe processing is compatible with the purpose communicated to the data subject at the time of collection.
NecessityWe collect the minimum necessary. Fields that are not indispensable to the purpose are not required.
Free accessWe guarantee easy and free-of-charge consultation on the form, duration and completeness of the data processed.
Data qualityWe keep data accurate and up to date; correction may be requested at any time.
TransparencyWe clearly disclose who processes the data, for what purpose and with whom we share it — which is the objective of this policy.
SecurityWe apply technical and administrative protection measures, described in section 10.
PreventionWe assess privacy risks before starting new or high-risk processing activities.
Non-discriminationWe do not process data for discriminatory, unlawful or abusive purposes.
AccountabilityWe keep records of the operations, decisions and evidence that demonstrate compliance.

4. Data we process and why

We process personal data only in the situations below. If you interact with us in any other way, the purpose and legal basis will be communicated at the time of collection.

SituationData processedPurpose
Contact formName, e-mail and message contentRespond to the request and keep a record of the interaction
Download of materialsE-mailRelease the requested material and, with consent, send institutional communications
Website browsingIP address, device type, browser, pages visited and date/timeKeep the website running, ensure its security and produce aggregate audience statistics
Applications and résumésIdentification, contact, education and professional experience dataConduct selection processes and build a talent pool, when authorized
Relationships with suppliers and partnersData of legal representatives and contacts; shareholding structure in integrity due diligencePerform contracts, comply with legal obligations and assess integrity risks
Ombudsman and reporting channelData voluntarily provided by the reporter — the report may be anonymousInvestigate the report with confidentiality and protection against retaliation
Visits to unitsName, identity document and time of entry and exitControl physical access and the security of the facilities
Provision of services to clientsAs defined by the controller client in the contractPerform the contracted service, in the capacity of processor

We do not process data of children and adolescents

Our channels and services are intended for adult and corporate audiences. We do not intentionally collect data from persons under 18 years of age. If we identify any such collection, the data is deleted. If you suspect this has occurred, write to dpo@axiaresources.com.br.

5. Legal bases for each processing activity

No processing is initiated without an identified legal basis, in accordance with Articles 7 and 11 of the LGPD.

ProcessingLegal basis (LGPD)Note
Response to contact and customer serviceArt. 7, IX — legitimate interestThe data subject initiated the contact and expects a response
Sending of institutional communicationsArt. 7, I — consentRevocable at any time, without prejudice to the service
Website security and operationArt. 7, IX — legitimate interestMinimal technical logs, retained for a short period
Selection processesArt. 7, V — preliminary procedures related to a contractThe talent pool depends on specific consent
Performance of contracts with suppliers and clientsArt. 7, V — performance of a contractIncludes data of representatives and agents
Integrity due diligenceArt. 7, II and IX — legal obligation and legitimate interestLaw No. 12,846/2013 (Brazilian Anti-Corruption Law) and Decree No. 11,129/2022
Retention of tax, accounting and labor recordsArt. 7, II — compliance with a legal obligationPeriods defined in specific legislation
Access control at the unitsArt. 7, IX — legitimate interestProtection of people, information and property
Investigation of integrity reportsArt. 7, II and IX — legal obligation and legitimate interestConfidentiality and non-retaliation ensured
Regular exercise of rights in proceedingsArt. 7, VI — regular exercise of rightsJudicial, administrative or arbitral

When the legal basis is legitimate interest, we carry out a prior assessment that weighs the purpose, the necessity and the impact on the data subject, and we adopt safeguards to reduce that impact. You may request information about this assessment through the Data Protection Officer’s channel.

6. Cookies and browsing technologies

We use cookies and similar technologies to keep the website running, remember preferences and measure audience in aggregate form. The breakdown by category, and the purpose and duration of each cookie, are set out in the Cookie Policy.

CategoryRequires consent?What it is used for
NecessaryNoBasic operation, security and language preference. Without them the website does not operate properly.
Performance and analyticsYesAggregate browsing statistics, to improve content and usability.
FunctionalYesRemember choices you have made, such as language and completed forms.

You can manage your consent through the notice displayed on your first visit and review it at any time, in addition to blocking or deleting cookies in your browser settings. Refusing non-necessary cookies does not prevent browsing.

7. Sharing and processors

We do not sell personal data and do not share it for third-party advertising purposes. Sharing takes place only when necessary and always with contractual safeguards:

  • Technology providers that host the website, corporate e-mail and cloud environments, acting as processors and under contracts containing data protection clauses;
  • Partner universities and support foundations in research projects, within the limits of the instrument entered into and with defined ownership and confidentiality rules;
  • Legal and accounting advisors, when indispensable to compliance with a legal obligation or to the regular exercise of rights;
  • Public authorities, when there is a legal request, court order or legal duty of disclosure — in which case we assess the legitimacy of the request before complying.

Every processor engaged by AXIA contractually assumes obligations of confidentiality, information security, incident notification and deletion or return of the data at the end of the relationship. The engagement of sub-processors requires prior authorization.

8. International transfer

Personal data processed by AXIA is preferably stored in Brazilian territory. When an essential service requires processing outside the country, we adopt the safeguards provided for in Chapter V of the LGPD — specific contractual clauses, standard contractual clauses or another instrument accepted by the ANPD — and we record the transfer in our inventory of processing operations. The list of countries and organizations involved may be requested through the Data Protection Officer’s channel.

9. Retention and deletion

We retain data only for as long as necessary for the purpose for which it was collected, subject to the legal retention periods. Once the period has ended, the data is securely deleted or anonymized.

CategoryReference periodCriterion
Contact and customer service messages2 yearsRelationship history and defense of rights
Technical browsing logs6 monthsBrazilian Internet Civil Framework (Law No. 12,965/2014), Art. 15
Résumés of candidates not hired1 yearOnly with consent for the talent pool
Contracts and tax documents5 to 10 yearsApplicable civil, tax and labor legislation
Integrity reports and investigations5 years after closureIntegrity program and defense of rights
Access control at the units1 yearProperty security

10. Information security

The protection of personal data at AXIA is supported by the Information Security Management System, structured in accordance with ABNT NBR ISO/IEC 27001:2022. The measures applied include:

Access control

Access granted on a least-privilege basis according to the role, with named identity, periodic review and revocation within 24 hours upon termination.

Technical protection

Encryption in transit and at rest according to the classification of the information, network protection, anti-malware and vulnerability management.

Continuity

Backup routines with periodic restoration testing, with recovery time measured and verified.

Governance

Security policy approved by the Board of Directors, with formal acceptance recorded by employees and third parties.

Awareness

Periodic training in privacy and security, with verification of understanding and not merely recording of attendance.

Incident response

Defined process for detection, containment, eradication, recovery and communication, with assessment of the risk to the data subject.

11. Your rights as a data subject

Article 18 of the LGPD grants you the rights below. All of them may be exercised free of charge through the Data Protection Officer’s channel.

#RightWhat it means in practice
1Confirmation of the existence of processingTo know whether we process any of your personal data.
2Access to dataTo obtain a copy of the data we hold about you, in a readable format.
3CorrectionTo correct incomplete, inaccurate or outdated data.
4Anonymization, blocking or deletionTo address data that is unnecessary, excessive or processed in non-compliance with the law.
5PortabilityTo transfer your data to another provider, in accordance with ANPD regulations.
6Deletion of data processed with consentTo erase the data we process on the basis of your consent, except in cases of legally required retention.
7Information about sharingTo know with which public and private entities we share your data.
8Information about the possibility of not consentingTo be informed of the consequences of refusing consent.
9Revocation of consentTo withdraw consent at any time, through a free and simplified procedure.
10Review of automated decisionsTo request review of a decision made solely on the basis of automated processing. AXIA does not adopt automated decisions with legal effect on data subjects.

You may also object to processing carried out on the basis of one of the cases in which consent is waived, in the event of non-compliance with the LGPD, and petition the Brazilian National Data Protection Authority directly.

12. How to exercise your rights

Official Data Protection Officer channel

Send your request to dpo@axiaresources.com.br, stating your name, the right you wish to exercise and the data necessary for your identification.

  1. Receipt and registration. Every request is recorded with a date and a protocol number, which is provided to you.
  2. Identity confirmation. We may request additional information to confirm that you are the data subject — this is a protective measure against fraudulent requests, and the data used for this confirmation is not used for any other purpose.
  3. Analysis and response. We respond within 15 days of receipt, in accordance with Article 19, II, of the LGPD. For confirmation or access requests, the response may be immediate in simplified format.
  4. Refusals are substantiated. If it is not possible to comply — for example, when there is a legal retention obligation — we inform you of the reason and the legal grounds.
  5. No cost. The exercise of rights is free of charge, pursuant to Article 18, § 5.

13. Personal data incidents

If a security incident occurs that may result in relevant risk or damage to data subjects, AXIA notifies the Brazilian National Data Protection Authority and the affected data subjects within a reasonable period, in accordance with Article 48 of the LGPD and ANPD regulations. The notification states the nature of the data involved, the data subjects affected, the technical measures adopted, the risks and the mitigation measures.

Internally, every incident is recorded, classified by severity, contained, investigated as to its cause and used to adjust controls. The assessment of risk to the data subject is conducted by the Data Protection Officer.

14. Effective date and changes

This policy may be updated to reflect changes in our activities, in legislation or in ANPD regulations. The version in force is always the one published on this page, with the revision date indicated below. Relevant changes are communicated through our channels.

Current version1.0
Revision dateSeptember 23, 2026
ApprovalBoard of Directors of Axia Mineração S.A.
Next reviewAnnually or upon a relevant change in processing, legislation or technology
Corresponding internal documentPOL-008 — Privacy and Data Protection Policy of the Integrated Management System

Questions about this policy may be sent to the Data Protection Officer (DPO) at dpo@axiaresources.com.br.

FILL IN YOUR EMAIL TO RELEASE THE DOWNLOAD

PREENCHA COM O SEU EMAIL PARA LIBERAR O DOWNLOAD