Personal data owner privacy policy
1. OBJECTIVE
To present to the internal environment, external environment, market, clients, suppliers, partners, government authorities, consumer protection entities, judicial bodies, shareholders and the general public, the principles, guidelines, rules and organizational commitment defined by BLUETREE HOTELS & RESORTS DO BRASIL or simply BLUETREE as we will refer to it in this document, for the Protection of Personal Data and Information, with the objective of complying with applicable legislation and regulations to preserve the Privacy of the Personal Data Holder.
2. COMPROMISSO
BLUETREE declares and undertakes the following:
2.1. To safeguard privacy and protection when processing the personal data of clients, employees, and partners, in the course of their business activities;
2.2. Adopt guidelines that ensure compliance with legislation, regulations, and best practices for preserving the privacy of Personal Data Subjects, through the implementation of information security controls and personal data protection.
2.3. To promote transparency regarding how BLUETREE handles personal data;
2.4. Adotar medidas de minimização de riscos para incidentes de segurança que envolva dados pessoais.
3. SCOPE
3.1. Personal data and information that is the responsibility of BLUETREE.
3.2. BLUETREE is responsible for the following personal data:
a) Collected by BLUETREE, collected by product or service providers contracted by BLUETREE, or collected by partners and shared with BLUETREE.
b) Processed by BLUETREE or processed by product or service providers contracted by BLUETREE;
3.3. Controls required for compliance with the General Data Protection Law (Law 13.709/2018), as well as all national legislation that considers the protection of personal data, such as, but not limited to: the Federal Constitution, the Consumer Protection Code, the Civil Code, the Marco Civil da Internet (Brazilian Internet Bill of Rights), and sectoral regulations.
4. GUIDELINES
4.1 – Principles of this Policy
All existing or future actions related to the Processing of Personal Data and the Personal Data Subject must necessarily follow the following principles:
a. Purpose. Processing is carried out for legitimate, specific and transparent purposes for the Data Subject.
b. Necessity. Limitation of processing to the minimum amount of personal data necessary and exclusively for the fulfillment of its purpose.
c. Data Subject Rights. Data subjects have the right to know (consult) about their personal data: existing data, correction of incorrect data, objection to the processing of any specific personal data, type of processing, duration of processing, sharing with other organizations, data processed in violation of the law, and portability of their data to another organization.
d. Information Security. BLUETREE has an Organizational Information Security Program that defines, implements, and manages controls for the protection of information and personal data.
e. Non-discrimination. BLUETREE does not process personal data for illicit or abusive discriminatory purposes.
f. Transparency. BLUETREE is transparent in its procedures for handling personal data.
g. Data retention. Personal data is retained exclusively for the time necessary for BLUETREE to comply with legal regulations and ensure its protection.
4.2. Respeito ao Titular de Dados Pessoais
BLUETREE respects the individual data subject and is committed to implementing all necessary controls, considering the reasonableness of existing technology, to protect the personal data under its responsibility and enable the privacy of the data subject.
4.3. Processing of Personal Data
a. BLUETREE processes personal data exclusively for the specific purpose of its professional relationship with the Data Subject and collects the minimum amount of data necessary to fulfill this purpose.
b. A BLUETREE compartilha dados pessoais com outras organizações, administração pública ou órgãos do judiciário, exclusivamente para a gestão operacional do relacionamento com o Titular de Dados Pessoais e repassa exclusivamente os dados mínimos necessários para esta atividade.
c. All processing of personal data can be made known to the Personal Data Subject, should they wish to know, respecting BLUETREE's confidentiality and business intelligence.
d. Caso seja necessário transferência de dados para outros países para realização de serviços ou outros tratamentos, sempre limitados à finalidade existente, somente será realizada com países que possuam legislação de proteção de dados pessoais e com organizações que possuam gestão para a proteção de dados pessoais.
e. All processing of personal data carried out by BLUETREE is supported by at least one Legal Basis for the Processing of Personal Data, as defined in the General Data Protection Law.
f. BLUETREE has clearly defined the responsibilities of its professional collaborators regarding the processing of personal data and conducts ongoing training on personal data protection.
g. BLUETREE implements new procedures and continuous technological improvements to protect all personal data processed under BLUETREE's responsibility.
4.4. Use of Cookies
BLUETREE uses cookies on its website only to improve navigation, information security, and user experience. The generated cookies are used to collect internet users' access information, which is then shared with tools under BLUETREE's responsibility for managing navigation statistics and data protection.
A BLUETREE não utiliza os Cookies para nenhum outro propósito diferente das diretrizes desta política e os mesmos ficam armazenados dentro do ambiente organizacional.
4.5. Communication between the Personal Data Subject and BLUETREE
The Personal Data Subject may contact BLUETREE using the contact information provided on the BLUETREE website (www.bluetree.com.br), on the Contact Us page. In this case, please include "Personal Data" in the subject line. Alternatively, send an email to encarregado@bluetree.com.br.
5. REVISIONS
Este regulamento será revisado anualmente ou sempre que houver alguma alteração que afete o mesmo.

