People BCPPeopleBCP

LGPD Policy

Last updated: September 15, 2026

This policy details how we comply with Brazil's Lei Geral de Proteção de Dados (Law No. 13,709/2018, "LGPD") in operating this website and the People BCP product.

1. Controller identification

MAP-PeopleBCP (CNPJ 31.231.620/0001-65) acts as data controller for personal data processed through peoplebcp.com and, together with each customer as joint operational context, for data registered inside a customer workspace.

2. Data subject rights under Article 18

Any data subject may request, free of charge: confirmation of the existence of processing; access to data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data; data portability; deletion of personal data processed with consent; information about public and private entities with which we have shared data; information about the possibility of denying consent and the consequences; and revocation of consent.

3. How requests are handled

Send requests to privacy@peoplebcp.com with enough detail to identify you and the request. We confirm identity before disclosing or changing data, and we respond within the legal deadline, extending only when the law allows and explaining why.

4. Legal bases used

We process personal data under one or more of the legal bases in Article 7 of the LGPD: consent (analytics cookies, marketing contact), legitimate interest (securing and operating the site), performance of a contract (product customers), and compliance with a legal obligation (tax and accounting records).

5. Security measures

Technical and administrative measures proportionate to the risk are described in our Information Security Policy, including workspace-level data isolation, restricted storage access, and managed authentication.

6. Data protection contact

For LGPD-related requests or questions, contact privacy@peoplebcp.com. This mailbox is monitored by the people responsible for privacy at MAP-PeopleBCP.

7. Incident notification

In the event of a security incident that creates relevant risk to data subjects, we will notify the National Data Protection Authority (ANPD) and affected data subjects as required by the LGPD, describing the nature of the affected data, the measures taken, and the risks involved.