PRIVACY POLICY

Updated on June 14, 2024.

1. Privacy Statement

Charlie understands how important it is for you to know and feel secure about how your personal data is used, as well as the data of our clients. That is why we are committed to clarifying and explaining our Privacy Policy.

We recognize the need for proper protection and management of personal information collected on our website, as well as information shared with us by our clients. This Privacy Policy will help you understand what types of information we may collect, how this information may be used, and with whom it may be shared.

2. General Principles Applicable to Data Processing by Charlie

In terms of general principles relating to the processing of personal data, Charlie commits to ensuring that the processed Data is:

  • Subject to lawful, fair, and transparent processing;
  • Collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes;
  • Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed;
  • Accurate and updated whenever necessary, with all appropriate measures taken to ensure that inaccurate data, considering the purposes for which they are processed, are erased or rectified without delay;
  • Kept in a form that allows the identification of the User only for the period necessary for the purposes for which the data is processed;
  • Processed in a manner that ensures their security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, with appropriate technical or organizational measures adopted.

2.1. Lawfulness of Data Processing

Data processing carried out by Charlie is lawful when at least one of the following conditions is met:

  • The User has given explicit consent for the processing of their Data for one or more specific purposes;
  • The processing is necessary for the performance of a contract to which the User is a party, or for pre-contractual steps taken at the User's request;
  • The processing is necessary for compliance with a legal obligation to which Charlie is subject;
  • The processing is necessary to protect the vital interests of the User or another natural person;
  • The processing is necessary for the legitimate interests pursued by Charlie or by third parties (except where such interests are overridden by the interests, rights, and fundamental freedoms of the User that require the protection of personal data).

2.2. Consent and Storage

Charlie commits to ensuring that the processing of User Data is only carried out under the conditions listed above and in accordance with the principles mentioned above.

When the processing of User Data is carried out by Charlie based on the User's consent, the User has the right to withdraw their consent at any time. However, the withdrawal of consent does not affect the lawfulness of the processing carried out by Charlie based on the consent previously given by the User.

The period during which data is stored and retained varies according to the purpose for which the information is processed.

There are legal requirements that mandate data retention for a minimum period. Therefore, whenever there is no specific legal requirement, data will be stored and retained only for the minimum period necessary for the purposes that motivated their collection or subsequent processing, after which they will be deleted.

3. What Personal Information We Collect

The personal information we obtain may be collected in the following ways:

Website: Personal information is collected when the user interacts on our website through forms, comments, testimonials, and surveys. This personal information includes, among others, the user's name, email, and phone number. When collecting information, the user chooses whether or not to give consent for the processing of this data for sending news, articles, and promotions. Users of our portal are under no obligation to provide any personal data to browse the website pages, so any information is provided voluntarily. The following data must be collected: Full name, Date of Birth, City, State, CPF or Passport, Image/photo of identification document, Email, Mobile phone number, and Facial photo (selfie) when the user wishes to make a reservation directly through the Charlie website. All Personal Information is collected in a fair and non-invasive manner, with your voluntary consent. Personal Information is not accessible to anyone outside the specific function for which the respective information was collected.

Cookies: Personal data may be collected through cookies, with the user's consent. For more information, please see our Cookie Policy.

Registration: We collect our clients' data necessary to complete registration on our website. The data is required to identify the user and allow them to book accommodations or services through our platform. The data collected for registration includes the user's name, surname, email, and CPF.

Geolocation: We collect the platform user's geolocation to provide a better experience, presenting products and services available in their region. When the user uses the platform, they can choose whether or not to share their location.

Contract: When the user acquires a rental, accommodation, or service on our platform, we collect the data necessary for drafting the contract and issuing a receipt or invoice. This data includes, among others, the contact email and possible electronic invoice delivery, name, CPF, CNPJ, Company Name, Full Name of the Responsible Person, Phone, Full business address with ZIP code, Neighborhood, City, and State, and State Registration when applicable.

Sharing: We may have access to personal data shared by our partners such as Booking or Airbnb. The data is necessary for drafting contracts and/or issuing invoices. This data includes, among others, the contact email and possible electronic invoice delivery, name, CPF, CNPJ, Company Name, Full Name of the Responsible Person, Phone, Full business address with ZIP code, Neighborhood, City, and State, and State Registration when applicable.

Employees: We collect personal data from our employees and job applicants. This data is necessary for the execution of employment contracts, employee registration, and compliance with labor legislation.

Satisfaction Surveys: We collect our clients' data through forms sent via email or other public discussion group platforms in order to understand sentiment, motivation, intention, disposition, and market trends, as well as the needs of our stakeholders, thereby improving our services.

4. Social Media

Charlie also uses Social Media to communicate and interact with its clients and consumers through third-party websites such as Instagram. These third-party websites are Internet-based technology that is not operated or controlled by Charlie. By interacting with, sharing, or "Liking" Charlie's page on Instagram or other social media, you may reveal certain personal information to Charlie or to third parties.

We use "social buttons" to allow our users to share or bookmark web pages. These are buttons from third-party social media websites that may record information about your online activities, including on this website. Please review the respective terms of use and privacy policies of these websites to understand exactly how they use your information, how to opt out, or how to delete such information.

The amount of visible personal information will depend on your own social media privacy settings.

5. Purposes and Legal Bases

Below we list the purposes and legal bases for Charlie's data processing:

To comply with terms and conditions established in contracts with our clients. Necessary for the performance of a contract to which you, your company, or a controller of your data is a party.

Recruitment and evaluation of suitability for job positions. Justified based on our legitimate interests in ensuring that we recruit suitable employees.

To facilitate communication with you (including in emergencies and to provide you with requested information). Justified based on our legitimate interests in ensuring proper communication and emergency management within the organization.

To comply with legal requirements. Necessary for compliance with a legal obligation to which we are subject.

To monitor your use of our systems (including monitoring the use of our website and any applications and tools you use). Justified based on our legitimate interests in preventing non-compliance and protecting our reputation.

Social listening (identifying and analyzing what is being said about Charlie on social media [only publicly accessible content] in order to understand sentiment, intention, disposition, and market trends, as well as the needs of our stakeholders, thereby improving our services). Justified based on our legitimate interests in preventing non-compliance and protecting our reputation.

Justified based on our legitimate interests in protecting our assets and brand on social media. Justified based on our legitimate interests in preventing non-compliance and protecting our reputation.

To improve the security and functioning of our website, networks, and information. Justified based on our legitimate interests in ensuring that you have an excellent user experience and that our networks and information are secure.

To perform data analysis, i.e., applying analytics to business operations and data to describe, predict, and improve business performance within Charlie and/or provide a better user experience. (More details on how we use analytics on our website can be found in our cookie policy). Justified based on our legitimate interests in ensuring the proper functioning of our business operations.

To offer our products and services to you (unless you have objected to such processing). Justified based on our legitimate interests in ensuring that we can conduct and improve our business.

To manage employee benefits. Justified based on Charlie's legitimate interests in ensuring that our employees receive appropriate benefits.

Delivery of necessary information to government agencies. For compliance with a legal obligation.

6. About Information Sharing and Transfer

Charlie does not practice the disclosure of information that may identify the user and never shares, sells, or rents personal data to third parties. This data is for the company's exclusive and internal use to achieve the purposes stated in the previous section.

Data may be shared with third parties only in the following situations:

By judicial order or request from government oversight agencies.

Data transferred to public agencies to comply with current legislation, for example, personal data contained in electronic invoices and respective XMLs, or data from our employees necessary for INSS or FGTS payments.

Data transferred to accounting or human resources service providers to comply with tax and labor obligations;

Data transferred to financial institutions to enable payment options for our clients, or for salary payments to our employees and service providers;

Data transferred for business purposes to third-party service providers who provide services to us, such as collections, payment processing, customer services, email delivery, advertising and marketing, security and performance monitoring, repair and maintenance services, order processing and fulfillment, consumer registration information verification, research, data storage, auditing, and data processing;

Data transferred for the purpose of contract execution requested by the user, such as data sent to property owners of properties rented through our platform, or to third parties that provide products or services acquired by users of our platform.

7. Information Security

To ensure that your personal information is secure, we communicate our privacy and security guidelines to Charlie employees and strictly follow privacy precautionary measures within the company.

We strive to protect your personal information, and that entrusted to us by our clients, through physical, technical, and organizational measures to reduce the risks of loss, misuse, unauthorized access, improper disclosure, and alteration of this data.

8. Data Subject Rights

Data subjects have certain rights regarding their personal data and may exercise them by contacting us at: dpo@staycharlie.com.br.

Data subject rights include:

  • Confirmation of the existence of personal data processing;
  • Access to personal data, under applicable legislation;
  • Correction of incomplete, inaccurate, or outdated data;
  • Data portability;
  • Deletion of data when processed based on the data subject's consent or when the data is unnecessary, excessive, or processed in non-compliance with applicable legislation;
  • Request for information about shared data use;
  • Withdrawal of consent, when applicable.

8.1. Requests and Security

Certain requests may be made by the user directly through Charlie's platform, accessed via email and password. Therefore, it is very important that the user has a strong password and does not share it with third parties. The user assumes full responsibility for third-party access to the platform using their account and password.

For security reasons, for requests made through dpo@staycharlie.com.br, we can only fulfill the request if we are certain of the user's identity. Therefore, we may request additional data or information to confirm the data subject's identity and authenticity. This data and information will be protected during the storage period and deleted when no longer useful.

9. Termination of Data Processing

This Privacy Policy applies to the above-mentioned circumstances throughout the entire period in which Charlie stores personal data. We store and maintain your information: (a) for the time required by law; (b) until the termination of personal data processing, as mentioned below; or (c) for the time necessary to preserve Charlie's legitimate interest. Thus, we will process your data, for example, during applicable statute of limitations periods or as long as necessary to comply with a legal or regulatory obligation.

The termination of personal data processing will occur in the following cases: (a) when the purpose for which the personal data was collected has been achieved and/or the collected personal data is no longer necessary or relevant to achieving such purpose; (b) when the data subject requests the deletion of their data; and (c) when there is a legal determination to that effect.

In cases of termination of personal data processing, subject to the exceptions established by applicable legislation or this Privacy Policy, personal data will be deleted.

10. Data Protection Officer (DPO)

Charlie provides below the contact information of the Data Protection Officer (DPO), who is responsible for addressing any and all requests from users or the National Authority related to personal data.

For any questions, requests, or complaints regarding personal data processing, please contact our Data Protection Officer: Flávio Ghelfond, dpo@staycharlie.com.br.

If, despite our commitment and efforts to protect your data, you believe that your data protection rights have not been met, we ask that you contact our DPO. Additionally, you have the right, at any time, to file a complaint directly with the National Data Protection Authority.

11. Changes to the Privacy Policy

Charlie reserves the right to update or modify this Policy at any time and without prior notice. However, we will always publish the new revised version on our communication channels. If there are changes to how we process personal data, you will be informed so you can decide whether you wish to continue using our services.