ARARA.CO PRIVACY POLICY
Last Updated: [October 15, 2025]
This Privacy Policy (“Policy”) is provided by ARARA.CO “Arara,” “We,” or “Controller,” with the purpose of informing and clarifying the practices related to the collection, use, storage, sharing, and other forms of processing of personal data (“Personal Data”) through our digital platforms (websites, applications, social networks) and as a result of the provision of our advertising agency and film production services.
By interacting with Arara.co, whether through our services, digital platforms, or any other means of communication, you, as a data subject, acknowledge and agree to the terms of this Policy.
- ARARA.CO’S ROLE AS A PROCESSING AGENT
In compliance with Law No. 13.709/2018 (Brazilian General Data Protection Law – LGPD), Arara.co may act as:
Personal Data Controller: When it determines the purposes and means of Personal Data processing, which occurs, for example, in the management of its own direct clients, employees, talents, suppliers, and in Arara.co’s institutional marketing.
Personal Data Processor: In certain situations, Arara.co may act as a Processor, processing Personal Data on behalf of and according to the instructions of its clients (who, in these cases, will be the Controllers), within the context of executing contracts for the provision of advertising, digital marketing, and audiovisual production services. In these hypotheses, the primary responsibility for the legality of Personal Data processing lies with the client-Controller, and Arara.co is obligated to comply with contractual and legal instructions inherent to the security and confidentiality of Personal Data.
- PERSONAL DATA COLLECTED AND PURPOSES OF PROCESSING
Arara.co may collect, process, and store Personal Data provided directly by you or collected automatically, always observing the applicable legal bases provided in the LGPD and the specific purposes:
2.1. Personal Data Voluntarily Provided by You:
We may collect Personal Data that you voluntarily provide to us when interacting with us, such as:
Contact and Identification Information: Full name, email, telephone number, address, CPF (Brazilian Individual Taxpayer Registry), RG (Brazilian Identity Document), date of birth.
Professional Information: Position, company, resume, portfolio, agency information, professional licenses, image and voice data (especially for talents such as actors, models, voice actors).
Financial Information: Bank details, payment information, for invoicing and remuneration purposes.
Other Information: Any other Personal Data you send us when contacting us for requests, inquiries, commercial proposals, or job applications.
Purposes:
Contractual and Operational Management: To enter into and execute service provision contracts (advertising, marketing, audiovisual production), manage relationships with clients, suppliers, and partners, carry out payments and collections.
Human Resources and Talent Management: For recruitment, selection, hiring, and management of employees and talents for productions, including management of copyrights and image rights.
Communication and Support: To respond to your requests, inquiries, and provide technical or commercial support.
Marketing and Prospecting: To send institutional communications, newsletters, and commercial proposals, always in accordance with the preferences expressed by the data subject.
Fulfillment of Legal Obligations: To comply with fiscal, accounting, labor, and regulatory requirements.
Applicable Legal Bases: Performance of a contract or preliminary procedures related to a contract to which the data subject is a party (Article 7, V, LGPD); Compliance with a legal or regulatory obligation (Article 7, II, LGPD); Consent (Article 7, I, LGPD), especially for Sensitive Personal Data or specific marketing purposes; Legitimate Interest (Article 7, IX, LGPD), for support and service improvement.
2.2. Personal Data Collected by Automated Means:
To optimize your experience on our website and other digital platforms, we may automatically collect certain information, such as:
Browsing Data: IP address, browser type, operating system, Internet Service Provider (ISP), device characteristics, language preferences, referring URLs, approximate geolocation data.
Usage Data: Pages visited, time spent, clicks, downloads, browsing flow, dates, and times of access.
Purposes:
Analysis and Performance Improvement: To analyze traffic, identify usage patterns, enhance the usability and functionality of our digital platforms and services.
Experience Personalization: To adapt the content and presentation of our platforms to your preferences.
Security and Diagnostics: To diagnose technical problems, monitor the security of our systems, and prevent fraud.
Applicable Legal Bases: Legitimate Interest (Article 7, IX, LGPD); Consent (Article 7, I, LGPD) for certain categories of cookies.
2.2.1. Cookies and Similar Technologies:
Cookies are small text files stored on your device that allow us to recognize your browser and store information about your visit. We use cookies and other tracking technologies for the aforementioned purposes, including statistical data analysis.
You have the prerogative to manage your cookie preferences, being able to configure your browser to refuse all or some cookies or to alert you when a cookie is sent. However, disabling cookies may impact the functionality and access to certain parts of our website. For more detailed information on the use of cookies, please consult our [link to Cookie Policy, if a separate, more detailed policy exists].
2.2.2. Third-Party Plug-ins and Links:
Our website may contain links to third-party websites, applications, tools, and plug-ins. Arara.co has no control over the privacy practices and data collection of these third parties. We recommend that you review the respective privacy policies of each external entity before providing any Personal Data.
- SHARING OF PERSONAL DATA
Arara.co may share your Personal Data with third parties, always in compliance with the LGPD and for the specific purposes outlined herein:
With Related Entities: With companies belonging to the same economic group as Arara.co, for internal administrative and operational purposes, under the same security and privacy guidelines.
With Arara.co’s Clients: Data of talents (actors, models, etc.) or information related to specific projects may be shared with our clients for the execution of contracted services (e.g., casting approval, campaign reports). In these cases, the client will act as Controller or Processor, depending on the context, and Arara.co will require the client to have appropriate legal bases for processing.
With Service Providers and Partners: Subcontracted companies that assist us in the provision of our services, such as casting agencies, audio and video production companies, post-production studios, IT providers (hosting, cloud computing), data analytics tools, marketing platforms, legal and accounting consultants. Such third parties will be contractually obligated to protect the privacy and security of Personal Data.
With Governmental and Judicial Authorities: In response to legal requests, court orders, to comply with legal, regulatory obligations, or to protect the rights, property, or safety of Arara.co, our clients, employees, or the public.
In Cases of Corporate Reorganization: In the event of a sale, merger, acquisition, reorganization, dissolution, or transfer of part or all of our business or assets, your Personal Data may be transferred to the successor entity.
Arara.co reaffirms that it does not commercialize, rent, or share Personal Data with third parties without a legitimate purpose and without the backing of the LGPD’s legal bases.
- INTERNATIONAL DATA TRANSFER
Eventually, your Personal Data may be transferred to other countries if our partners or service providers are located outside Brazilian territory or use servers in other jurisdictions. In such cases, Arara.co will ensure that such transfers occur in compliance with the LGPD, adopting appropriate safeguards, such as standard contractual clauses, global corporate rules, seals, certificates, or codes of conduct approved by the Brazilian National Data Protection Authority (ANPD), or through your specific consent when required.
- SECURITY OF PERSONAL DATA
Arara.co implements robust technical and administrative security measures to protect your Personal Data against unauthorized access, destruction, loss, alteration, communication, or any form of improper or illicit processing. Our security solutions consider (i) adequate techniques and technology; (ii) the nature, context, and purposes of the processing; (iii) the criticality and sensitivity of the Personal Data; and (iv) the risks to the rights and freedoms of data subjects.
Among the measures adopted are [Examples: data encryption, role-based access control, firewalls, continuous system monitoring, regular information security training for our employees].
Notwithstanding Arara.co’s commitment to security, it is important to note that no security system is infallible. In accordance with Article 48 of the LGPD, Arara.co will notify you and the Brazilian National Data Protection Authority (ANPD) in the event of a security incident that may entail a relevant risk or damage to your Personal Data.
- RETENTION OF PERSONAL DATA
Personal Data will be retained by Arara.co only for the period strictly necessary to fulfill the purposes for which it was collected, respecting the applicable legal and regulatory deadlines, as well as the statutory limitation periods for the regular exercise of rights in judicial, administrative, or arbitration proceedings. After the retention period ends, Personal Data will be securely deleted or anonymized, except in cases of mandatory retention by law or for the defense of the Controller’s legitimate interests.
- PRIVACY OF CHILDREN AND ADOLESCENTS
This website and our services are not intentionally directed at children and adolescents under 12 (twelve) years of age. We do not deliberately collect Personal Data from individuals in this age group without the specific and prominent consent of at least one parent or legal guardian. If you identify that Personal Data of children or adolescents under 12 has been provided to Arara.co without due consent, please contact us immediately so that we can arrange for its deletion.
- YOUR RIGHTS AS A PERSONAL DATA SUBJECT
In strict observance of the LGPD, you, as a Personal Data subject, have the following rights:
Confirmation: Obtain confirmation of the existence of processing of your Personal Data.
Access: Access the Personal Data we process about you.
Correction: Request the correction of incomplete, inaccurate, or outdated Personal Data.
Anonymization, Blocking, or Deletion: Request the anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed Personal Data.
Data Portability: Request the portability of Personal Data to another service or product provider, upon express request, observing Arara.co’s commercial and industrial secrets.
Deletion: Request the deletion of Personal Data processed based on your consent, except in cases of mandatory retention by law or for defense in proceedings.
Withdrawal of Consent: Withdraw consent at any time, without affecting the legality of processing carried out before the withdrawal.
Information on Sharing: Obtain information about public and private entities with which Arara.co has shared your Personal Data.
Information on Consent: Be informed about the possibility of not providing consent and the consequences of refusal.
Opposition: Oppose processing carried out based on other legal bases, in case of non-compliance with the LGPD.
Review of Automated Decisions: Request a review of decisions taken solely based on automated processing of Personal Data that affect your interests, including decisions intended to define your personal, professional, consumer, and credit profile, or aspects of your personality.
To exercise any of these rights, please contact our Data Protection Officer (DPO) through the channels indicated in item 10 of this Policy.
- CHANGES TO THIS PRIVACY POLICY
The terms of this Policy may be updated or adapted periodically to reflect new data processing practices, legislative or regulatory changes, or to incorporate new technologies and best practices in privacy and Personal Data protection. The most updated version will always be available on our website, with the “Last Updated” indication. We encourage you to review this Policy regularly to stay informed about how we protect your information.
- HOW TO CONTACT US
For any questions about this Privacy Policy, requests related to your rights as a Personal Data subject, or to contact our Data Protection Officer (DPO), please use the following channel:
Email: arara@arara.co
When contacting us, for your security, confidentiality, and the inviolability of your Personal Data, we may request additional information or procedures to confirm your identity.