Privacy policy

PRIVACY AND DATA PROTECTION POLICY:

This Privacy and Data Protection Policy ("Privacy Policy") establishes and informs the conditions under which FELISA COSMÉTICOS LTDA collects, processes, uses, stores, and shares your information and personal data.

### **Introduction and Definitions**
When you make a purchase or hire a service on FELISA.COM.BR, you provide us with some personal data to enable your transaction. Similarly, when you access, interact with, or browse the FELISA website or social media, especially when registering to receive the newsletter, you provide us with personal data. In this Policy, you will find information related to the use of your personal data by FELISA COSMÉTICOS, such as the reasons why we collect and use your personal data, how it is shared, and your rights and options regarding your personal data.

FELISA COSMÉTICOS is committed to respecting the fundamental right to privacy and the personal data protection standards established by the Federal Constitution, Law No. 13.709 of August 14, 2018 (General Data Protection Law - LGPD), and other applicable laws and regulations.

By accepting the terms of this Privacy Policy, you acknowledge that the controller of your personal data within the scope of the relationship established with you is FELISA COSMÉTICOS. For the purposes of applicable legislation, the controller is the entity responsible for decisions regarding the processing of personal data. For more information, contact us at sac@felisa.com.br.

Whenever the terms "FELISA," "we," or "our" are mentioned, we are referring to FELISA; similarly, whenever the terms "you," "your," or "yours" are mentioned, we are referring to you.

For the purposes of this Privacy Policy, the following definitions apply:

- **Internet Protocol Address (IP Address):** The code assigned to a terminal on a network to allow its identification, defined according to international parameters.
- **Internet:** The system consisting of a set of logical protocols, structured on a global scale for public and unrestricted use, aimed at enabling data communication between terminals through different networks.
- **Website:** FELISA websites, including www.felisa.com.br.
- **Social Media:** FELISA accounts or groups on YouTube, Pinterest, Instagram, Telegram, Twitter, Facebook, and any other accounts or groups managed by FELISA on other social media platforms.
- **Terminals (or "Terminal," when individually considered):** Computers, notebooks, netbooks, smartphones, tablets, smart TVs, palm tops, and any other devices that connect to the Internet.
- **You or User:** Any individual who interacts with FELISA, accesses, or uses the Websites and/or Social Media.

### **Personal Data That May Be Processed**
Within the limits permitted by applicable legislation, FELISA may process personal identification, qualification, and contact data such as: full name; email; address; date of birth; CPF number; phone number, among others.

The above personal data is processed only in specific cases and when necessary to achieve the purposes mentioned in this Privacy Policy, especially for the commercialization of products, content production, image, media space, and brand and product promotion.

FELISA may collect or receive this personal data in various ways. It may be collected directly from you via email, provided by you when registering on the Websites to receive the FELISA newsletter, and collected from your interactions with the Websites or Social Media, such as your IP address, searches (including date and time), browsing history, content, details of third-party application usage in connection with the Websites or Social Media, and others. By filling in the delivery address and payment method, we will collect billing address, delivery address, and credit card data when chosen as the payment method. During the analysis and monitoring of your purchases on the Website, registration data, product type, quantity, unit price, and total purchase value may be processed. Regardless of the source of the data, the processing will be governed by this Privacy Policy, and you may contact us at sac@felisa.com.br in case of questions.

Just like access to the Websites, access to Social Media is also optional and free, in this case, being equally subject to the acceptance of the terms of service and privacy policy of each Social Media platform accessed or used. The User declares to be aware that browsing the Websites or Social Media will not generate any intellectual property rights or patrimonial copyright over the content published on the Website or FELISA accounts on Social Media, owned by FELISA. FELISA may, at any time, perform any acts as an administrator of a group or account on Social Media, such as, for example, including, excluding, or altering content, silencing chats, or excluding members, without prior notice or the possibility of interference by members. Similarly, FELISA reserves the right to, at any time, change, manage, suspend, or remove FELISA accounts or groups from Social Media, without prior notice.

When posting content on FELISA Websites or Social Media, the User may not: (i) address topics unrelated to beauty, (ii) promote political campaigns, (iii) advocate for crimes, (iv) act anonymously, (v) violate copyright or intellectual property rights of third parties, (vi) propagate fake news, false content, offenses, or illegal content that tarnishes the reputation of third parties. The User declares to be solely responsible for the content they post and for any civil and criminal consequences, exempting FELISA from any burden or liability. Any tolerance by FELISA regarding non-compliance with the provisions herein by any User does not invalidate this Privacy Policy nor does it impose any burden or liability on FELISA.

Except in cases where we are required by law, it is necessary to exercise or defend FELISA's rights, or we have a legitimate interest under applicable legislation, we will not perform Processing activities with your Personal Data without obtaining your consent.

We do not sell or trade Personal Data. However, we may share Personal Data with our employees, contractors, or business partners, in Brazil or abroad, provided that such employees, contractors, and partners are also subject to this Privacy Policy, so that such sharing occurs only for the purposes of the Websites or FELISA Social Media.

If required by an order issued by a competent authority in the exercise of its legal duties, or in case of violations or suspected violations of this Privacy Policy or the LGPD, FELISA may be required to provide stored Personal Data. However, FELISA is committed to providing the information limited to the minimum necessary to achieve the required purposes.

### **Correction, Update, and Deletion of Personal Data**
FELISA guarantees you the possibility of updating, correcting, or deleting your Personal Data. As permitted by applicable legislation, you may request the correction, update, or deletion of your Personal Data. In this case, you must send an email to sac@felisa.com.br.

When required by applicable legislation, we may send you a copy of all your Personal Data that we have under our control, as well as ensure portability to another service or website. To do so, you must send an email to sac@felisa.com.br.

If you request the deletion of your Personal Data, we will comply with your request except for Personal Data that may be necessary to prove that our services were provided properly, according to the applicable statute of limitations.

### **Purpose of Personal Data Processing**
Your personal data may be processed under the terms of applicable legislation, and notably for the purposes of the Websites or FELISA Social Media, which are dedicated to (i) the preparation and dissemination of informative materials and content through written, image, and video formats, (ii) the promotion of beauty brands and products, and (iii) the commercialization of such products.

Therefore, we use personal data for the following purposes:
- To enable your purchases on FELISA.COM.BR.
- To correctly identify the User.
- To send purchased products or communications about offers.
- To contact you when necessary. This contact may cover various topics, such as communications about promotions, launches, and offers, responses to questions, complaints, and requests, updates on orders placed, and delivery information.
- To assist in diagnosing and resolving technical issues.
- To develop new features and improvements, enhancing your experience with our Websites.
- To consult your information in credit bureau databases.
- To conduct investigations and measures to prevent and combat illegal activities, fraud, financial crimes, and money laundering and/or terrorism financing.
- To ensure compliance with legal or regulatory obligations or to ensure the regular exercise of FELISA's rights. In these cases, we may even use and present the information in judicial and administrative proceedings, if necessary.
- To collaborate with the fulfillment of court orders, competent authorities, or regulatory bodies.

Additionally, we may process your personal data to maintain our relationship with you through:
- Sending newsletters, institutional communications, and event invitations;
- Organizing events, including managing registrants, reminders, and acknowledgments; and
- Conducting satisfaction surveys and feedback on our materials and content.

### **Sharing of Personal Data**
FELISA may share your personal data, whenever necessary, with our employees, contractors, or business partners, in Brazil or abroad, provided that such employees, contractors, and partners are also subject to this Privacy Policy. We never trade personal data.

When your personal data is transferred outside Brazil by FELISA, we will adopt appropriate administrative and technical measures to ensure adequate protection of your personal data in accordance with the requirements of applicable data protection legislation.

We may also share personal data with judicial, police, or governmental authorities, in compliance with court orders, requests from administrative authorities, legal or regulatory obligations, as well as to act collaboratively with governmental authorities, generally in investigations involving illegal activities.

Finally, we may share your personal data with other companies with which FELISA concludes a sale or transfer of part or all of FELISA's commercial activity, business, or operation. If the sale or transfer is not completed, we will request that the potential buyer does not use or disclose your personal data in any way or form, deleting it entirely.

### **Rights of Personal Data Subjects**
Regarding your personal data collected and used by FELISA, you have:
- **Right to confirmation of existence and access:** The right to be informed and request access to the personal data processed by us.
- **Right to withdraw consent at any time:** The right to revoke the consent given for the processing of your personal data.
- **Right to rectification:** The right to request that we change or update your personal data when it is incorrect or incomplete.
- **Right to erasure:** The right to request the deletion of your personal data.
- **Right to restriction:** The right to request that we temporarily or permanently stop processing all or some of your personal data.
- **Right to object:** The right to object, at any time, to the processing of your personal data for reasons related to your particular situation; the right to object to the processing of your personal data for direct marketing purposes.

### **Retention and Removal of Personal Data**
We store and maintain your information (I) for the time required by law; (II) until the end of the processing of personal data, as mentioned below; (III) for the time necessary to preserve FELISA's legitimate interest, as the case may be; (IV) for the time necessary to safeguard the regular exercise of FELISA's rights in judicial, administrative, or arbitral proceedings; (V) during the applicable statute of limitations or as long as necessary to comply with legal or regulatory obligations.

The termination of personal data processing will occur in the following cases:
- When the purpose for which the personal data of the data subject was collected is achieved or the collected personal data is no longer necessary or relevant to achieve such purpose.
- When the data subject exercises a legitimate right to request the termination of processing and the deletion of their personal data.
- When there is a legal determination in this regard.

In these cases of termination of personal data processing, except for the hypotheses established by applicable legislation or this Privacy Policy, personal data will be removed.

### **Personal Data Protection and Security**
FELISA is committed to the security of your personal data and maintains caution and diligence to promote and preserve this protection, employing reasonable and available security systems and managerial, technical, and operational procedures.

However, we emphasize that no platform is completely secure. If you have any concerns or suspect that your data is at risk, please contact us at sac@felisa.com.br, and we will be happy to assist you promptly.

Your personal data will be retained for the entire period that you are an active FELISA customer or newsletter subscriber. After this period, we may store your personal data for an additional period for audit purposes, to enable compliance with legal or regulatory obligations. We will retain your data for the necessary period, respecting the deadlines established in applicable legislation.

### **Advertisements and Third-Party Websites**
As a feature of the Websites, we may display advertisements and links to other websites on the Internet. FELISA is not responsible for these websites and their content and does not share, subscribe to, monitor, validate, or accept how these websites handle your personal data. We recommend that you consult the respective privacy policies of such websites to be properly informed about the processing of your personal data by third parties.

### **Children**
In the case of FELISA Users who are still children, the processing of personal data can only occur with the specific and highlighted consent of a parent or legal guardian. If we become aware that we have collected the personal data of a child without the consent of the guardian, we will take reasonable measures to remove their personal data.

### **Use of Cookies**
There are monitoring technologies called "cookies," which can be used to provide personalized information from a website. A "cookie" is a data element that a website can send to your browser, which can then store it on your system. The FELISA Website uses cookies to better serve you when you return to our website and to collect information about activities performed on our Site. These technologies are used to perform performance metrics, identify usage issues, capture User behavior in general, and collect data on content impressions. You can configure your browser to notify you when you receive a cookie, giving you the option to accept it or not. We assume that you agree to the use of cookies, but you can choose to block them if you wish.

### **Changes to the Privacy Policy**
This Privacy Policy may be edited and updated without prior notice, including to comply with subsequent legislation and regulations, and it is the sole responsibility of the User to consult the Privacy Policy to know its full content and updates.

### **Contact**
If you have any questions about personal data protection, as well as any requests to exercise your rights, the User should contact the FELISA Data Protection Officer at sac@felisa.com.br. Assistance does not imply any cost to the User, and requests will be handled by the Officer as soon as possible.

This Privacy Policy was last updated on January 25, 2023.