Roles: controller and processor
Under the LGPD (Brazilian General Data Protection Law, 13.709/2018), the contracting customer is the controller of the personal data of their employees and monitored contacts, and VoxTeamsChat acts as the processor, handling that data strictly under the instructions and purposes set out in the service contract.
Legal basis for processing
Personal data is processed on the basis of the controller's legitimate interest in auditing and corporate compliance, fulfillment of legal or regulatory obligations of the controller, and regular exercise of rights in judicial, administrative or arbitration proceedings. Monitored employees must be informed in advance by the controller about the monitoring, as required by Article 9 of the LGPD.
Rights of the data subject
The data subject (monitored employee) may exercise the rights set out in Article 18 of the LGPD — confirmation, access, correction, anonymization, portability, deletion, information about sharing, consent withdrawal — directly with the controller (their employing organization). As processor, VoxTeamsChat fulfills requests routed through the controller within 15 days.
Security and incidents
We apply technical and administrative measures to protect personal data against unauthorized access, loss, alteration or improper disclosure. In case of a security incident that could pose a significant risk or damage to data subjects, we notify the controller and the ANPD within the deadlines set by the LGPD and the National Data Protection Authority regulations.