Back

PM RUN Software/App Privacy Policy

Last updated: 07/28/2025

I. Initial Considerations

I.1. Ensuring privacy in a broad and effective manner, taking into account the most diverse challenges and scenarios that exist, has already become a reality for our team, especially as it is a pressing demand from the market and from society and, for this reason, it is treated as a priority by the team involved in the management and operation of the PM RUN Software/App ("PM Run").

I.2. Your privacy is important to us!

Starting from this premise, this Privacy Policy provides information about the processing of the personal data of users who access PM Run and aims to ensure the data subject's right to informational self-determination, through maximum transparency and the clarification of all stages, legal bases, and user rights.

I.3. This policy observes Federal Law No. 13,709, of August 14, 2018 (the Brazilian General Data Protection Law, LGPD), and Federal Law No. 12,965, of April 23, 2014 (the Brazilian Civil Rights Framework for the Internet, Marco Civil da Internet).

I.4. The User hereby declares that they have read these rules fully and carefully and that, being fully aware of them, they grant their free and express agreement to the terms, clauses, and principles set forth herein.

I.5. If you do not agree with these regulations and their future amendments, you must immediately cease accessing PM Run. The user is aware that failing to discontinue access, as well as failing to request the rights provided for herein, is understood as tacit acceptance of this Policy.

I.6. It is important to emphasize that this Policy will always be in constant evolution and updating, in view of legislative updates as well as the upgrades and other modifications that may occur in our Software/App. For this reason, you are hereby invited to access this Policy periodically.

II. Legal Basis for the Processing of Personal Data

II.1. To use PM Run, certain data is required for the user's registration and the operation of the application; therefore, failure to provide it prevents its functioning and, as a corollary, the use license and any provision of services.

II.2. Data is collected when the User, or the client (data controller) to whom the User is linked, voluntarily enters or provides it when accessing PM Run and the features made available through it.

II.3. During the use of PM Run and the provision of services, with respect to the users and personal data involved, in accordance with the LGPD, ITSS SOLUCOES EM TECNOLOGIA (the exclusive intellectual owner and the party responsible for the management and operation of PM Run) acts, occasionally and when necessary, as a Data Processor, in cases where it is necessary to perform maintenance or support of the software/App in question.

II.3.1. ITSS SOLUCOES EM TECNOLOGIA may be contacted through the following channels: Address: Avenida C-255, No. 400, Quadra 600, Lote 02, Edifício Eldorado Business Tower, Sala 215, Setor Nova Suíça, Goiânia/GO, ZIP code 74280-010. Phone: (62) 3434-0991. Email: elisa.zafalao@grupoitss.com.br.

II.4. With respect to its users, ITSS SOLUCOES EM TECNOLOGIA is responsible for processing data according to the instructions of the Controllers (clients), to be identified on a case-by-case basis and under the terms of the appropriate Contractual Instrument.

II.5. Any access carried out for maintenance or support occurs only through PM Run itself or through the SAP platform, with the authorization and agreement of the client (data controller).

II.6. Any Personal Data that may be processed by our team is collected strictly to enable the scope and execution of the products, solutions, and services offered.

II.7. The grounds authorizing such processing are provided for in items I, II, V, VI, and IX of Article 7 of the LGPD and in Article 33, IX of that same Law, and in any other cases of which the user is informed in advance.

II.8. Let us look at these provisions: Article 7. The processing of personal data may only be carried out in the following cases: I, with the consent of the data subject; II, for compliance with a legal or regulatory obligation by the controller; V, when necessary for the performance of a contract or of preliminary procedures related to a contract to which the data subject is a party, at the request of the data subject; VI, for the regular exercise of rights in judicial, administrative, or arbitration proceedings, the latter under the terms of Law No. 9,307, of September 23, 1996 (the Arbitration Law); and Article 33. The international transfer of personal data is only permitted in the following cases: (...) IX, when necessary to meet the cases provided for in items II, V, and VI of Article 7 of this Law.

III. Security of Personal Data

III.1. The data collected by PM Run is accessed, internally and only when necessary, by duly authorized professionals who are tracked and registered for such purpose, observing the principles of security, privacy, ownership, informational self-determination, reasonableness, and necessity for achieving its objectives, which include offering and delivering services, products, and solutions of excellence to its clients.

III.2. The ITSS SOLUCOES EM TECNOLOGIA professionals responsible for PM Run do not have external access to the application, nor do they access the server and database of the client (data controller). If necessary, express authorization must be requested, and such access will be assisted by the client's IT team.

III.3. PM Run allows the client (data controller) to block third-party access to the users' data.

III.4. PM Run does not use any kind of automated decision-making that affects the user.

III.5. The cloud hosting service, in the case of services provided under the SaaS (Software as a Service) model, made available for and through PM Run, is currently outsourced to ORACLE DO BRASIL, which currently holds several ISO certifications, among them ISO 20000 and ISO 27001, and which may be contacted at:

ORACLE DO BRASIL SISTEMAS LTDA. (registered under CNPJ No. 59,456,277/0001-76), headquartered at Rua Dr. José Áureo Bustamante, No. 455, Anexo Morumbi, Business Center, Santo Amaro, São Paulo/SP, ZIP code 04710-090.

Any change of the outsourced cloud hosting service provider will be communicated to the user and to the Contracting Party through an amendment to this Policy.

III.6. PM Run uses an SSL (Secure Socket Layer) certificate, which creates an encrypted channel between a web server and a browser in order to ensure that all transmitted data is confidential and secure.

III.7. PM Run may not be held liable for the exclusive fault of third parties, such as, but not limited to: attacks by hackers and crackers, and/or the exclusive fault of the user.

IV. Rights of the User/Data Subject

IV.1. As a Data Processor, in accordance with the LGPD, ITSS SOLUCOES EM TECNOLOGIA guarantees the following rights to users who are data subjects:

  1. Confirmation of the existence of processing;
  2. Access to personal data;
  3. Correction and updating of personal data;
  4. Anonymization, blocking, or deletion of unnecessary or excessive data, or of data processed in noncompliance with the provisions of the LGPD, notwithstanding the fact that we will make every effort never to process data in noncompliance with the principle of data-collection minimization and/or in a manner that deviates from the purposes set out in this Policy;
  5. Withdrawal of consent (pursuant to Article 8, §5 of the LGPD).

IV.2. Should the user wish to exercise their rights, they are requested to send a written communication to the Data Protection Officer (see item XII of this Policy). In this communication, the following additional specifications are required from the outset:

  • A) Title/Subject: "Data Subject Right (LGPD)"
  • B) Identification of the requester: Full name, CPF number or CNPJ of the client (data controller) to which the user is linked, and email address of the user and/or of their legal representative;
  • C) Right requested: State the right you wish to exercise;
  • D) Request details: Place and date of the request and signature (handwritten, electronic, or digital) of the requesting user;
  • E) Documentation: If possible, documentation supporting the user's request.

V. Responsibilities of PM Run

V.1. PM Run's responsibilities are:

  • To ensure that the personal data collected, when necessary, is accessed internally only by duly authorized professionals who are tracked and registered for such purpose, solely for legitimate and predetermined purposes, ensuring appropriate use limited to the processing objective, as well as observing the principles of security, privacy, ownership, informational self-determination, reasonableness, and necessity for achieving the objectives of PM Run.

V. Duty Not to Provide Personal Data

V.1. The user must provide, accurately and up to date, only their own personal data and never the personal data of third parties.

V.2. PM Run will not transfer users' data to third parties that are not provided for contractually, whether directly or indirectly, by the very nature of the use license and the contracted provision of services, without specific authorization.

V.3. The user's personal data entered into PM Run may be shared with the SAP Platform, which may be contacted at the following address: SAP Platform, SAP BRASIL LTDA. Address: Avenida das Nações Unidas, No. 14171, 5th to 8th Partial Floors, Marble Tower, Vila Gertrudes, São Paulo/SP. Phone (11) 5503-2334 / (11) 5503-2856.

V.4. The data collected and the activities recorded may also be shared:

  • With competent judicial, administrative, or governmental authorities, whenever there is a legal determination, request, requisition, or court order;
  • Automatically, in the event of corporate transactions such as merger, acquisition, and incorporation.

VI. Data That Will Be Collected

VI.1. The use of PM Run and of its features will depend on registration; thus, for this purpose, the following personal data of the user will be collected:

  1. User's Name;
  2. User's registration (ID) number;
  3. User's password on the PM Portal;
  4. User's corporate email, if any.

VI.2. Access Logs

VI.2.1. The user's access logs will be collected and stored for a period of 06 (six) months, in observance of the provisions of Article 15 of Law No. 12,965/2014 (the Brazilian Civil Rights Framework for the Internet).

VI.2.2. The SAP platform is able to generate an information-tracking document, which records: who the user is that is or was logged in on a given screen; how long they remained logged in on that screen; and what information they changed.

VII. Purpose of the Processing of Personal Data

VII.1. The personal data required for the user's registration and any other data entered by the client (data controller) and/or by the user during the use of PM Run will be used to authorize and record the user's access to PM Run and its features, to track their activities, as well as to ensure the full use, operation, and performance of PM Run.

VIII. Personal Data Retention Period

VIII.1. The user's personal data will be processed by PM Run only during the term of the Use License and Service Agreement entered into with the client (data Controller).

VIII.2. Personal data will only be processed for a period longer than the term of the Agreement (see item VIII.1) by reason of law, court order, and other legitimate interests, pursuant to Article 10 of the LGPD. Once the period and the legal necessity have ended, it will be excluded and securely deleted from any record of PM Run, and will never again be processed, handled, and/or used by PM Run.

VIII.2. The users' personal data, once entered into PM Run, becomes part of a database that is extracted from the SAP platform and will be handled only during the provision of the services offered by PM Run, as per the contract. The client (data controller) is the one who holds the power of definitive deletion of personal data. ITSS SOLUCOES EM TECNOLOGIA only has access to the data in order to perform maintenance or support of PM Run.

VIII.3. In the event of termination, cancellation, or ending of the Use License and Service Agreement and its annexes signed with the Contracting Party, all files relating to the Users and to the Contracting Party, as well as other information possibly entered by the Contracting Party and/or the Administrator User into PM Run, will be made available to the relevant data Controller for a period of 30 (thirty) days for access (reading) and verification within the system, under the terms of the contract. Should the extraction and sending of data be necessary, the considerations and counter-considerations required for this must be analyzed together with the commercial department, where feasible.

IX. App Cookies

IX.1. Cookies are small files installed on the hard drive, with a limited duration, that help personalize services and improve the user experience, and may offer personalized content.

X. Who Is the Personal Data Controller?

X.1. The Personal Data Controller is the natural or legal person, governed by public or private law, to whom the decisions regarding the processing of personal data pertain.

X.2. With respect to PM Run, the Controller of the data collected from users is the client itself, that is, the party who contracts the use license and the provision of services related to PM Run with ITSS SOLUCOES EM TECNOLOGIA. Should you have any question in this regard, as to who the Controller of your Data is, simply contact us through the channels provided for in this Policy (see item XII).

XI. Who Is the Personal Data Processor?

XI.1. The Personal Data Processor is the natural or legal person, governed by public or private law, who carries out the processing of personal data on behalf of the controller.

XI.2. With respect to PM Run, the Processor of the collected data is ITSS SOLUCOES EM TECNOLOGIA, the exclusive holder and owner of PM Run.

XI.3. With respect to its clients and users, ITSS SOLUCOES EM TECNOLOGIA acts as a data Processor and is therefore responsible for processing data according to the instructions of the Controllers (clients), to be identified on a case-by-case basis and under the terms of the appropriate Contractual Instrument.

XII. Who Is the Data Protection Officer (DPO)?

XII.1. In this application, the data protection officer is Elisa Miranda Zafalão, who may be reached at the email: elisa.zafalao@grupoitss.com.br; address: Ed. Eldorado Business, Av. C-255, No. 400, Sala 215, Setor Nova Suíça, Goiânia/GO, 74280-010. Phone: (62) 3434-0991.

XIII. Regarding Updates to This Policy

XIII.1. This Privacy Policy was last updated on: 07/28/2025.

XIII.2. We hereby emphasize the validity of the right to modify this Privacy Policy at any time and without prior notice. Therefore, the user is invited to consult this page periodically in order to check for updates.

XIV. Competent Jurisdiction and Applicable Law

XIV.1. The Courts of the Judicial District of Goiânia/GO are hereby elected to settle any questions and/or disputes arising from this Privacy Policy, waiving any other, however privileged it may be. Furthermore, Brazilian Law will be applied exclusively with respect to any discussions concerning this Privacy Policy.