Privacy Policy
Last updated: July 3, 2026
INTRODUCTION AND COMMITMENT TO THE PROTECTION OF PERSONAL DATA
Taking Results e Informática Ltda. ("Taking", "we" or the "Company") recognizes privacy, personal data protection and information security as fundamental pillars of its activities and of the relationship of trust established with clients, employees, suppliers, business partners, users of its technology solutions and other data subjects.
Committed to responsible innovation and to best governance practices, Taking processes personal data in accordance with the applicable legislation on personal data protection, privacy and information security, including Law No. 13,709/2018 (the Brazilian General Data Protection Law — LGPD) and other relevant rules, guiding its conduct by the principles of legality, transparency, security, accountability and respect for the rights of data subjects.
Data protection is part of Taking’s Privacy Governance Program and is aligned with its internal Information Security policies, its Code of Ethics and Conduct and other corporate instruments intended to protect information and to continuously improve its processes.
As a technology company, Taking develops innovative solutions, including TATeAI, an Artificial Intelligence suite focused on knowledge management, process automation and support for project execution. Due to the specific characteristics of this solution, TATeAI has its own Privacy Policy, complementary to this Policy, available at taking.com.br/tategpt/politica-de-privacidade-tategpt.
This Policy represents the Company’s ongoing commitment to the protection of privacy, information security, legal and regulatory compliance and the responsible processing of personal data.
PURPOSE AND OBJECTIVE
The purpose of Taking’s Privacy Policy is to set out the guidelines applicable to the processing of personal data carried out by the Company, providing transparency about its activities and clarifying to data subjects how their data is collected, used, shared, stored and protected.
This Policy is informative and guiding in nature and must be interpreted together with the other instruments adopted by Taking, as well as any specific contracts and documents that may apply, which may establish complementary provisions on the processing of personal data, always in accordance with applicable law.
SCOPE
This Policy applies to all personal data processing activities carried out by Taking, regardless of the means used for their collection, use, storage, sharing, deletion or any other processing operation.
Its provisions cover the personal data processed in Taking’s relationship with clients, prospective clients, users of its technology solutions, employees, job applicants, suppliers, business partners, legal representatives, visitors and other data subjects whose information is processed by reason of its activities.
This Policy applies both to situations in which Taking acts as Controller, defining the purposes and means of processing, and to situations in which it acts as Processor, processing personal data on behalf of and in accordance with the instructions of its clients, subject to the applicable legal and contractual provisions.
DEFINITIONS
For the purposes of this Policy, and under the terms of the LGPD, the following definitions apply:
- Data Subject: the natural person to whom the personal data being processed relate.
- Personal Data: information relating to an identified or identifiable natural person.
- Sensitive Personal Data: personal data concerning racial or ethnic origin, religious belief, political opinion, membership of a trade union or of a religious, philosophical or political organization, data relating to health or sexual life, genetic or biometric data, when linked to a natural person.
- Processing: any operation carried out with personal data, such as those relating to collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation or control of the information, modification, communication, transfer, dissemination or extraction.
- Controller: the natural or legal person, governed by public or private law, responsible for the decisions regarding the processing of personal data.
- Processor: the natural or legal person, governed by public or private law, that processes personal data on behalf of the controller.
- Data Protection Officer (DPO): the person appointed by the controller and processor to act as a communication channel between the controller, the data subjects and the National Data Protection Authority (ANPD).
- National Data Protection Authority (ANPD): the public administration body responsible for overseeing, implementing and enforcing compliance with this Law throughout the national territory.
TAKING’S ROLE IN DATA PROCESSING
Taking may act, depending on the nature of the activity performed and the legal relationship established, either as Controller or as Processor of personal data, subject to the provisions of the General Data Protection Law (Law No. 13,709/2018).
As Controller, Taking is responsible for the decisions relating to the processing of the personal data necessary for the development of its institutional, commercial, administrative and labor activities, defining the respective purposes, legal bases and means of processing.
As Processor or Sub-processor, Taking processes personal data on behalf of its clients, solely for the performance of the contracted services and in accordance with the instructions received from the respective Controller, subject to the contractual limits, applicable law and the security measures adopted by the Company.
Regardless of the role performed, Taking undertakes to process personal data in an ethical, transparent and secure manner, compatible with the purposes that justified their collection, observing the principles and requirements established by applicable law.
WHICH DATA MAY WE PROCESS?
The personal data processed by Taking vary according to the nature of the relationship established with the data subject, the services contracted, the features used and the specific purposes of each processing activity.
Depending on the case, Taking may process the following categories of personal data:
- Identification data: name, CPF (taxpayer ID), RG (ID card), date of birth and other registration information.
- Contact data: address, telephone, email and other information necessary to communicate with the data subject.
- Professional data: position, company, résumé, academic background, professional experience and information related to selection processes.
- Contractual and financial data: information necessary for the formalization, performance and management of contracts, issuance of tax documents and compliance with legal and regulatory obligations.
- Browsing, authentication and usage data: access logs, electronic identifiers, device information, cookies and other data collected during the use of Taking’s websites, platforms or technology solutions.
- Data provided voluntarily: any information sent spontaneously by the data subject through forms, service channels or other means of communication made available by the Company.
In specific situations, Taking may process other categories of personal data, always observing the purpose of the processing, the applicable legal basis and the principles set out in applicable law.
As a rule, Taking does not request the provision of sensitive personal data. Should their processing be necessary in specific situations, it will occur only in the cases authorized by applicable law and upon the adoption of security measures compatible with the nature of such information.
When the processing arises exclusively from Taking’s role as Processor, the Company may process sensitive data in accordance with the instructions of the respective Controller and within the limits of the contract entered into.
PURPOSES OF PROCESSING AND LEGAL BASES
Taking processes personal data solely for legitimate, specific purposes compatible with its activities, always observing the principles set out in the General Data Protection Law and using the appropriate legal basis for each processing operation.
Processing activities may take place for the following purposes (with examples of the data processed and the corresponding legal basis):
- Handling requests submitted through Taking’s contact channels (clients, prospective clients, suppliers, business partners, candidates and other interested parties) — Data: name, company, position, email, telephone and message. Legal basis: preliminary procedures related to a contract or legitimate interest, depending on the nature of the request.
- Provision of the contracted services — Data: registration data, contact data and information necessary for the performance of the contract. Legal basis: performance of a contract.
- Management of the commercial relationship — Data: identification and contact data. Legal basis: legitimate interest.
- Recruitment and selection of candidates — Data: résumé, professional data, photos and information provided by the candidate. Legal basis: preliminary procedures related to a contract; legitimate interest.
- Administration and management of contracts with employees, suppliers, service providers and partners — Data: registration, financial and contractual data. Legal basis: performance of a contract; legal or regulatory obligation.
- Compliance with legal, regulatory, tax and labor obligations — Data: registration and financial data and mandatory documents. Legal basis: legal or regulatory obligation.
- Regular exercise of rights in judicial, administrative or arbitration proceedings — Data: data necessary to defend Taking’s interests. Legal basis: regular exercise of rights.
- Sending institutional communications and content related to Taking’s services — Data: contact data. Legal basis: consent; legitimate interest, as applicable.
The applicable legal basis will be defined according to the purpose of the processing, the nature of the relationship maintained between Taking and the data subject and the specific circumstances of each processing operation. Taking may process personal data for other purposes compatible with those described herein, provided that the principles of purpose, adequacy, necessity and transparency and the corresponding legal basis set out in applicable law are observed.
Whenever the processing depends on the data subject’s consent, it will be requested in a free, informed and unambiguous manner and may be revoked at any time, under the terms of applicable law, without prejudice to the lawfulness of the processing previously carried out.
In addition, whenever it bases a given processing on legitimate interest, Taking will assess the compatibility between its legitimate interests and the data subject’s fundamental rights and freedoms, adopting measures to preserve the transparency, necessity and proportionality of the processing.
When Taking acts exclusively as Processor or Sub-processor of personal data, it will process the data on behalf of and in accordance with the instructions of the respective Controller, subject to the limits established in applicable law and in the contractual instruments entered into between the parties. In such cases, the purposes and legal bases of the processing will be defined by the Controller, and it is incumbent upon Taking to carry out the processing operations necessary for the provision of the contracted services and to cooperate, where applicable, in responding to data subjects’ requests, within the limits of its legal and contractual duties.
DATA SHARING
Taking may share personal data only when such a measure is necessary for the development of its activities, for compliance with legal or regulatory obligations, for the performance of contracts or in the other cases authorized by applicable law, always observing the principles of necessity, purpose, adequacy and security.
Personal data may be shared, when necessary, with:
- companies within the same economic group, when indispensable to the development of administrative or operational activities;
- suppliers, service providers and business partners engaged to support the performance of its activities, always observing the limits of the respective engagements;
- law firms, audit firms, consultancies and other specialized service providers, when necessary for the regular exercise of rights or for the provision of the contracted services;
- public authorities, regulatory bodies or governmental entities, when there is a legal or regulatory obligation or a determination by a competent authority;
- Taking’s clients, when the processing takes place in the context of recruitment and selection processes, headhunting or other activities previously authorized by the data subject or based on an applicable legal basis;
- providers of technological infrastructure, cloud storage, communication, information security and other solutions necessary for the operation of its products and services.
Whenever possible, Taking adopts measures so that the personal data shared are limited to the minimum necessary to meet the specific purpose of the operation.
When acting as Processor, Taking may share personal data solely in accordance with the instructions of the respective Controller and to enable the performance of the contracted services.
Taking requires its suppliers, service providers and partners that process personal data on its behalf, or as sub-processors, to observe adequate standards of information security, confidentiality and data protection, as well as to comply with the obligations set out in applicable law and in the respective contractual instruments. Whenever applicable, the sharing will be formalized through contractual instruments containing confidentiality, information security and data protection obligations.
Taking does not sell personal data or carry out sharing for purposes incompatible with those informed in this Policy.
INTERNATIONAL DATA TRANSFER
Due to the nature of its activities and the technologies used in the provision of its services, Taking may carry out international transfers of personal data or use service providers that store or process information on servers located abroad.
Whenever there is an international data transfer, Taking will adopt the measures necessary to ensure that the processing takes place in accordance with applicable law, observing, where applicable, the guidelines established by the National Data Protection Authority (ANPD) and implementing mechanisms designed to ensure an adequate level of protection for personal data.
The international transfer may occur, among other cases, to enable the use of cloud computing services, technological infrastructure, corporate communication, information security, data storage, technical support or other solutions indispensable to the performance of its activities.
Taking prioritizes engaging suppliers that demonstrate commitment to the protection of personal data, adopt adequate information security standards and observe requirements compatible with applicable law.
DATA RETENTION AND DELETION
Taking will retain personal data only for the period necessary to fulfill the purposes that justified their collection and processing, observing the terms set out in applicable law, contractual obligations and the Company’s legitimate interests, where applicable.
Once the processing has ended or the purpose for which the data were collected has been achieved, they will be deleted, anonymized or stored for the period necessary to comply with legal or regulatory obligations, for the regular exercise of rights in judicial, administrative or arbitration proceedings, or in the other cases authorized by the General Data Protection Law.
Whenever technically feasible and compatible with the purpose of the processing, Taking will adopt measures to securely delete or anonymize personal data, preventing their misuse or unauthorized access.
RIGHTS OF DATA SUBJECTS
Taking ensures that data subjects may exercise the rights set out in the General Data Protection Law, subject to the cases, limitations and procedures established by applicable law.
Under the terms of the LGPD, the data subject may, among other rights:
- obtain confirmation of the existence of processing of their personal data;
- request access to the data processed by Taking;
- request the correction of incomplete, inaccurate or outdated data;
- request the anonymization, blocking or deletion of unnecessary or excessive data or data processed in breach of the law;
- request data portability, when applicable;
- request the deletion of personal data processed on the basis of their consent, except for the legal cases requiring their retention;
- obtain information about the public and private entities with which their data have been shared;
- obtain information about the possibility of not providing consent and about the consequences of refusal;
- revoke consent previously given, when this is the legal basis of the processing, under the terms of the Law;
- object to processing carried out in breach of applicable law.
These rights may be exercised through the channels indicated in this Policy, subject to the measures necessary to confirm the requester’s identity and to protect the security of the information.
Taking may decline to fulfill a given request when there is a legal ground authorizing the continuation of the processing, in which case it will provide the data subject with the applicable information, subject to the limits of applicable law.
When Taking acts exclusively as Processor or Sub-processor, the handling of data subjects’ requests will follow the instructions of the respective Controller and the limits of the duties conferred upon the Company by the applicable law and contractual instruments. Whenever necessary, Taking may direct the data subject to submit their request directly to the Controller responsible for the processing.
EXERCISE OF DATA SUBJECTS’ RIGHTS
Data subjects may exercise the rights set out in applicable law through the service channels made available by Taking, especially by contacting the Data Protection Officer (DPO) indicated in this Policy.
In order to guarantee the security of the information and prevent improper access, Taking may request additional information or documents that allow it to confirm the requester’s identity or the legitimacy of the request submitted.
Requests will be analyzed and answered within the terms and conditions established by applicable law, and Taking may request additional clarifications or decline to fulfill a given request when there is a legal ground justifying the continuation of the processing of the personal data, in which case the data subject will be duly informed.
Whenever possible, Taking will seek to fulfill requests in a simple, transparent and efficient manner, preserving the security of the information and the rights of data subjects.
INFORMATION SECURITY
Taking adopts appropriate technical, administrative and organizational measures to protect personal data against unauthorized access, destruction, loss, alteration, disclosure or any form of inadequate or unlawful processing, considering the nature of the data processed, the risks involved and the state of the art available. To this end, the Company implements security controls compatible with its activities, including, where applicable, access control mechanisms, credential management, environment monitoring, protection of technological infrastructure, employee training and other procedures intended to preserve the confidentiality, integrity and availability of the information.
Taking also requires its employees, suppliers and partners that have access to personal data to observe confidentiality obligations and to adopt adequate information security standards, as set out in contracts and internal policies.
Although measures compatible with market best practices are adopted, no system is completely immune to security incidents. Accordingly, Taking may not be held liable for events resulting from the exclusive fault of third parties, of the data subject or of unforeseeable and unavoidable situations, without prejudice to compliance with the obligations set out in applicable law.
SECURITY INCIDENTS
Should Taking identify a security incident that may entail relevant risk or harm to data subjects, it will adopt the measures necessary for its containment, investigation and mitigation, observing its internal incident response procedures and applicable law.
Whenever required by law or by the National Data Protection Authority (ANPD), Taking will communicate the incident to the affected data subjects and to the competent authorities, providing the necessary information and adopting the appropriate measures to minimize its impacts.
Taking maintains continuous improvement processes aimed at enhancing its security controls and preventing incidents.
USE OF COOKIES
Taking may use cookies and other similar technologies on its websites, platforms and digital solutions in order to ensure their operation, improve the browsing experience, analyze the performance of its services and, where applicable, personalize content and communications.
Cookies may be classified, according to their purpose, as:
- Necessary Cookies: indispensable to the operation of the websites and platforms;
- Performance or analytical Cookies: used for statistical analysis, monitoring website usage and continuously improving the browsing experience;
- Functional Cookies: intended to personalize the user experience;
- Marketing Cookies: used to present content and campaigns of interest to the user, where applicable.
Taking may use its own or third-party tools for statistical analysis, performance monitoring, information security and improvement of the user experience, observing the purposes described in this Policy and applicable law.
Whenever required by law, the use of non-essential cookies will depend on the user’s consent, which the user may manage or revoke at any time through the settings made available on the website, in any cookie management tool or in their browser settings.
Disabling certain cookies may limit the operation of some features of the platforms made available by Taking.
For additional information about the cookies used, their purposes and how to manage them, Taking may make a specific Cookies Policy available on its official channels.
DATA PROTECTION OFFICER
Taking maintains a Data Protection Officer, responsible for acting as a communication channel between the Company, data subjects and the National Data Protection Authority (ANPD), under the terms of applicable law.
The Data Protection Officer is responsible, among other duties, for:
- receiving and handling requests related to the exercise of data subjects’ rights;
- guiding employees and service providers on the data protection practices adopted by Taking;
- supporting the implementation and improvement of the Privacy Governance Program; and
- acting as a communication channel with the ANPD.
The role of Data Protection Officer is currently held by Giulianna Perrino Haddad, who may be contacted at the email address encarregado.lgpd@taking.com.br.
UPDATES TO THE PRIVACY POLICY
Taking may review and update this Privacy Policy at any time, especially to reflect legislative, regulatory, technological or operational changes related to its personal data processing activities.
The current version will always be available on its official channels, indicating the respective update date.
Whenever the changes entail relevant modifications to the manner of processing personal data, Taking may adopt reasonable measures to notify data subjects, subject to the requirements of applicable law.
FINAL PROVISIONS
This Policy comes into force on the date of its publication and applies to all personal data processing activities carried out by Taking, subject to the specific provisions set out in contracts and other applicable instruments.
Any omitted matters will be handled in accordance with applicable law and with the internal governance guidelines adopted by the Company.
In case of questions about this Policy or about the processing of personal data carried out by Taking, the data subject may get in touch through the channels indicated in this document.
UPDATE HISTORY
Document version: V6. Issuing area: Privacy and Data Protection Committee. Responsible: Juliana Araujo / Giulianna Haddad. Creation date: 06/28/2021. Last revision: 07/03/2026 (change of the person responsible and update of the provisions, on 05/27/2026).