Privacy Policy

This document describes how we collect, use, store, and protect the personal data of customers and users of the My Menthor platform. The customer is the contracting and subscribing legal entity responsible for authorizing and managing the users who have access to the platform on its behalf. The users are the employees or authorized representatives of the customer who have access to the platform and are subject to the policies and terms of use established between the service provider and the customer.

Description of Collected Information

This section specifies the types of data collected, the purposes, and the uses of the collected information.

The types of data collected relate to the registration of the customer and its legal representatives, login and account data of authorized users, usage and activity data, device information, cookies and tracking technologies, communications, payment information, and location data.

Purpose of Collecting and Using Personal Information

  • Customer Registration Data: Used for sending proposals, contracts, and signing services, setup, maintenance, and payment of services. We collect CNPJ/EIN, address, country, phone number, and personal data of the customer's legal representatives, such as name, position, and email address. This information needs to be updated during the contract term for continued platform usage.
  • Account Creation: To access our services, the customer's account must be created, for which we use the company's and the legal representative's data.
  • Login Data: Login information such as username, password, and other account credentials are used to grant and manage access to the platform.
  • User Registration Data: Used for granting access, communications related to service provision, technical support, user identification or visibility relative to other users, or customization of the user experience on the platform. This includes contact information and personal identification information such as corporate email address, position, department, phone number, and location. We may also request a photo, time zone, and language, although these are optional. This information is collected directly from the user or provided in a list format by the customer (employer).
  • Strategic Data: The My Menthor platform primarily handles strategic and confidential information related to the customer's business management, such as Mission, Vision, Values, Strategy, Cultural Aspects, Processes, Projects, Risk Inventories, Competencies, Incentives, Data, Systems, Resources, Infrastructure, Documents, and other organizational components. In the Organizational Structure functionality, information related to the organizational chart (name of the area, subarea, position/level, and seniority) is collected without linking names or personal information of employees.
  • Usage and Activity Data: Information about how users interact with the platform, such as activity logs, time spent in certain areas of the platform, and actions taken.
  • Device Information: This may include the type of device used to access the platform, the operating system, the web browser, and other relevant technical details.
  • Cookies and Tracking Technologies: Information collected through cookies and other tracking technologies that may be used to personalize the user experience and collect analytical data.
  • Communications: Records of communications between users and the platform, such as support messages, emails, and other types of correspondence.
  • Payment Information: We collect corporate credit card data or information for inclusion on the invoice for processing setup and monthly subscriptions, including billing information and transaction history. This information is shared with third-party payment processors and is subject to the security and privacy policies established by the customer.
  • Location Data: In some cases, the platform may collect geographic location information from users, especially if this is relevant to service provision.

In addition to the purposes mentioned above, we may use your information for the following purposes:

  • To communicate with you (e.g., via email) about service updates or changes to this Privacy Policy, changes to the Terms of Service, or important notices;
  • To keep you informed about new products and services, upcoming events, and other information we believe may be of interest to you;
  • To request that you participate in surveys or provide feedback on our products and services;
  • To set up and maintain your access and perform all other necessary actions to provide our services;
  • To understand how users use our products and services, monitor and prevent problems, and improve our products and services;
  • To provide customer support and analyze and improve our interactions with them;
  • To detect and prevent fraudulent transactions and other illegal activities, report spam, and protect the rights and interests of My Menthor, users, and third parties;
  • To update, expand, and analyze our records, identify new customers, and provide products and services that may be of interest to you;
  • To analyze trends, manage our websites, and track visitor navigation on our sites to understand what visitors are looking for and better assist them;
  • To monitor and improve marketing campaigns and make relevant suggestions to the customer.

Methods of Collecting User Information

We collect information about you only if we need it for a legitimate purpose and only if:

  • You, as the user, have provided the information yourself.
  • The information was automatically collected through My Menthor channels, an internal customer system, or a third-party channel as provided below.

Information You Provide Us

  • Event Records and Other Form Submissions: We record the information you submit when you (i) register for any event, including webinars or seminars; (ii) subscribe to our newsletter or any other mailing list; (iii) submit a form to download any product, white paper, or other materials; (iv) participate in contests or respond to surveys; or (v) submit a form to request customer support, get a quote, or contact us for any other reason.
  • Testimonials: When you authorize us to publish testimonials about our products and services on our sites, we may include your name and other personal information in the testimonial. You will have the opportunity to review and approve the testimonial before publication. If you wish to update or delete your testimonial, you can contact us through official channels.
  • Interactions: We may record, analyze, and use your interactions with us, including email, phone, and chat conversations with our professionals and customer support partners, to improve our interactions with you and other customers.

Information We Collect Automatically

  • Browser, Device, and Server Information: When you visit our site, we collect the information that internet browsers, mobile devices, and servers make available, such as IP address, browser type, language preference, time zone, referring URL, date and time of access, operating system, information about the mobile device manufacturer, and mobile network information. We include this information in our log files to understand more about the visitors to our sites.
  • Cookies and Tracking Technologies Information: We use temporary and permanent cookies to identify users of our services and improve their experience. We incorporate unique identifiers in our downloadable products to track the use of these products. We also use cookies, beacons, tags, scripts, and other similar technologies to identify visitors, track internet navigation, collect demographic information about visitors and users, understand the effectiveness of email campaigns, and engage with target users and visitors by tracking their activities on our sites. We primarily use our own cookies and do not use third- party cookies or other third-party tracking technologies on our sites for non- essential or intrusive tracking. We also use our own Local Storage Objects (LSOs), such as HTML5, to store content information and preferences to provide certain features.
  • Application Log and Mobile App Analytics Information: We collect information about your use of our products, services, and mobile applications from application logs and internal usage analysis tools and use it to understand how your use and needs can improve our products. This information includes clicks, scrolls, features accessed, time and frequency of access, errors generated, performance data, storage used, user settings and configurations, and devices used for access and their locations.

Information We Collect Automatically

  • Signups Using Federated Authentication Service Providers: You can log in to the platform using compatible federated authentication service providers, such as LinkedIn, Microsoft, and Google. These services will authenticate your identity and give you the option to share certain personal information with us, such as your name and email address.
  • Recommendations: If someone has recommended any of our products or services to you through any of our recommendation programs, that person may have provided us with your name, email address, and other personal information. You can contact us at privacy@mymenthor.com to request that we remove your information from our database. If you provide us with information about another person or if another person provides us with your information, we will use that information only for the specific reason for which it was provided to us.
  • Information from Our Authorized Partners: If you contact any of our partners or otherwise express interest in any of our products or services to them, the sales partner may pass your name, email address, company name, and other information to us. If you register for or participate in an event sponsored by us or our partners, the event organizer may share your information with us. We may also receive information about you from review sites if you comment on any reviews of our products and services and from other third-party service providers we hire to market our products and services.

Information from Internal Customer Systems

  • Employee Registration Information: When signing up for the platform, the customer may provide us with a list of authorized users containing data such as ID number, name, email, position, department, photo, and other identification or contact information. This list may be provided manually or through APIs with legacy systems. At any time, upon the employer's request or the termination of the contract between the customer and the user, the user's name will be removed from the list, and their access to the platform will be revoked.

Data Protection

This section describes aspects of data sharing, user rights, and security measures to protect data against unauthorized access or misuse.

Who We Share Your Information With

Customer information, legal representatives, and authorized users may be shared with My Menthor's authorized partners for ticket support, service provision such as mentoring, and project execution.

Authorized partners have an NDA with My Menthor and are required to sign an NDA with the customer to access both the business's strategic information and the personal information of users and/or legal representatives (name, email, phone) to perform service provision.

  • Technology Partner: Our low-code platform owner partner (Zoho Group) has access to the information covered in Part I and maintains rigorous security, privacy, and confidentiality policies, as well as technologies and mechanisms for protecting customer and user data.
  • Employees and Independent Contractors: We may grant access to your service data to our employees and independent contractors involved in service provision (collectively our 'employees') to (i) identify, analyze, and correct errors; (ii) manually verify emails reported as spam to improve spam detection; or (iii) manually verify scanned images submitted by you to verify the accuracy of optical character recognition. We ensure that access to your service data by our employees is restricted to specific individuals and is logged and audited. Our employees also have access to the data you knowingly share with us for technical support or data import into our products or services. We communicate our privacy and security guidelines to our employees and strictly enforce privacy protections.
  • Third-Party Service Providers: In certain circumstances, we may need to share your personal information, as well as aggregated or anonymized information, with third-party service providers hired by us. These service providers are authorized to use your personal information only to the extent necessary to provide us with the contracted services.
  • Collaborators and Other Users: Our software allows you to collaborate with other users. As a result, other collaborators may view some or all of your profile information. For example, when you edit a document shared with others for collaboration, your name and profile photo will be displayed alongside your edits to let your collaborators know you made those edits.
  • Legal Basis for Collecting and Using Information: If you are from Brazil, our legal basis for collecting and using information depends on the personal information in question and the context in which we collect it. Most of our data collection and processing activities generally rely on (i) contractual necessity; (ii) one or more legitimate interests of My Menthor or a third party not overridden by your data protection interests; or (iii) your consent. Sometimes, we may be legally required to collect your information or need your personal information to protect your vital interests or those of another person.

Revoking Consent

Where we rely on your consent as the legal basis, you have the right to revoke your consent at any time, but this will not affect any processing that has already occurred.

Notification of Legitimate Interests: Where we rely on legitimate interests as the legal basis, and those legitimate interests are not specified above, we will clearly explain those legitimate interests at the time we collect your information.

Your Choice in the Use of Information

  • Opting Out of Non-Essential Electronic Communications: You may opt out of receiving newsletters and other non-essential messages by using the 'unsubscribe' function included in all such messages. However, you will continue to receive essential notifications and emails, such as account notifications (password changes, reminders, etc.), security incident alerts, privacy and security updates, and transactional emails.
  • Disabling Cookies: You may disable browser cookies before visiting our sites. However, if you do so, you may not be able to use certain site features properly.
  • Optional Information: You may choose not to provide optional profile information, such as your photo. You may also delete or change your optional profile information. You can always choose not to fill in non-mandatory fields when submitting any form linked to our sites.

Your Rights as a Data Owner (Controller)

  • Right of Access: You have the right to access (and obtain a copy of, if necessary) the categories of personal information we hold about you, including the source of the information, purpose, and period of processing, and the people with whom the information is shared.
  • Right to Rectification: You have the right to update the information we hold about you or to rectify any inaccuracies. Based on the purpose for which we use your information, you may instruct us to add supplementary information about you to our database.
  • Right to Erasure: You have the right to request the deletion of your personal information from us in certain circumstances, such as when it is no longer necessary for the purpose for which it was originally collected.
  • Right to Restriction of Processing: You may also have the right to request the restriction of the use of your information in certain circumstances, such as when you have objected to the use of your data, but we need to verify whether we have overriding legitimate grounds to use it.
  • Right to Object: You have the right to object to the use of your information in certain circumstances, such as the use of your personal information for direct marketing.
  • Right to Complain: You have the right to complain to the competent supervisory authority if you have any complaints against the way we collect, use, or share your information.

Retention of Information

Data in your access account will be maintained for as long as the contract lasts. If you are terminated, your data will eventually be deleted from the active database during the next cleanup, which occurs every 6 months. Data deleted from the active database will be removed from backups after 3 months.

Personal Information of Minors

Our products and services are not intended for minors under 16 years old. We do not knowingly collect personal information from minors. If we learn that a minor under 16 has provided us with personal information, we will take steps to delete such information. If you believe that a minor under 16 has provided us with personal information, please email privacy@mymenthor.com with the relevant details, and we will take the necessary steps to delete the information we hold about that minor. If you process information related to minors, you acknowledge and agree that you will be responsible for complying with applicable laws and regulations related to the protection of such personal information.

How Secure Is Your Information

We take data security very seriously. We take appropriate measures to implement administrative, technical, and physical protections to prevent unauthorized access, use, modification, disclosure, or destruction of the information you entrust to us. If you have any concerns about the security of your data, we recommend that you consult our Security Policy or email privacy@mymenthor.com with any questions.

Data Protection Officer (DPO)

If you have any questions or concerns about our privacy practices regarding your personal information, you can contact our Data Protection Officer by emailing privacy@mymenthor.com.

Locations and International Transfers

My Menthor and the CRM use a unified management system that allows data to be accessed from both Brazil and the United States. These transfers are subject to appropriate data protection contracts to ensure an adequate level of protection as required by GDPR.

External Links on Our Site

Some pages of our sites may contain links to sites not governed by this Privacy Policy. If you submit your personal information to any of these third-party sites, your personal information will be governed by their privacy policies. As a security measure, we recommend that you do not share any personal information with these third parties unless you have verified and ensured their privacy policies and practices.

Blogs and Forums

Our site and blog offer the opportunity for users to share information and engage with the community. While we encourage participation, we recommend that users be cautious when disclosing personal information. Remember that any information shared publicly can be accessed by other users and used to contact you. While we take steps to protect your privacy, we cannot guarantee the security of information shared publicly. If you wish to remove your information from our blogs and forums, please contact us at privacy@mymenthor.com for assistance.

Social Media Widgets

Our site may include social media widgets that allow you to share articles and other information. These widgets may collect information such as your IP address and the pages you browse on the site and may set a cookie to allow the widgets to function properly. Your interactions with these widgets are governed by the privacy policies of the companies that provide them.

Disclosures in Compliance with Legal Obligations

We may be required by law to preserve or disclose your personal information and service data to comply with any applicable law, regulation, legal process, or governmental request, including to meet national security requirements.

Enforcement of Our Rights

We may disclose personal information and service data to a third party if we believe that such disclosure is necessary to prevent fraud, filter spam, investigate any suspected illegal activities, enforce our contracts or policies, or protect the safety of our users.

Business Transfers

We do not intend to sell our business. But if this happens, we will ensure that the new company respects our commitments to you. If there are changes in ownership or the use of your personal information, we will notify you by email or with a notice on the site. We will also inform you of any options you may have regarding your data.

Compliance with This Privacy Policy

We are committed to ensuring that your personal information is used in accordance with our Privacy Policy. If you have any concerns about the use of your personal information, please contact us at privacy@mymenthor.com. We will address your concerns and, if necessary, work with regulatory authorities to resolve any issues efficiently.

Notification of Changes

We may update our Privacy Policy occasionally and will notify you of significant changes through official channels. If the changes significantly affect your rights, you will be informed at least 30 days in advance via your primary email. However, please check your email regularly to avoid missing these notifications. If you feel that the changes affect your rights, you may choose to terminate the use of our services. Continuing to use our services after the changes will be considered acceptance of the new conditions. Minor changes to the Privacy Policy may not be notified by email. If you have questions about the use of your personal information, please contact us at privacy@mymenthor.com.