Privacy Policy
1. Purpose
This Privacy Policy aims to explain, in a clear and accessible manner, how Sioux processes personal data in the context of its activities, including what data may be collected, for what purposes it is used, which legal bases may authorize the processing, with whom it may be shared, for how long it may be retained, and what rights are guaranteed to data subjects.
This Policy applies to users of the Sioux website, job applicants, employees, former employees, service providers, clients, potential clients, leads, business contacts, third parties, suppliers, business partners, and other natural persons who access or use Sioux's digital channels or who, in any way, maintain a relationship with Sioux.
2. Definitions used in this Policy
For the purposes of this Policy, the terms below shall have the following meanings:
- “User” means any and all persons who access or browse the Sioux website or interact with its digital channels.
- “Data subject” means the natural person to whom the personal data processed by Sioux relate.
- “Personal data” means information relating to an identified or identifiable natural person.
- “Sensitive personal data” means personal data concerning racial or ethnic origin, religious belief, political opinion, membership of a trade union or of a religious, philosophical, or political organization, data concerning health or sexual life, and genetic or biometric data, when linked to a natural person.
- “Processing” means any operation carried out with personal data, such as collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation, control of information, modification, communication, transfer, dissemination, or extraction.
- “Controller” means the legal entity responsible for decisions regarding the processing of personal data.
- “Processor” means the legal entity or natural person that processes personal data on behalf of the controller and in accordance with its instructions.
“Sioux” means:
- Sioux Social Agência de Publicidade Ltda., a private legal entity, registered under CNPJ No. 19.614.018/0001-01, with address at Av. Nova Independência, 87, conj. 92, sala 2, Brooklin, São Paulo/SP; and/or
- Sioux Consulting Ltda., a private legal entity, registered under CNPJ No. 00.316.268/0001-37, with address at Av. Nova Independência, 87, 9º andar, Brooklin, São Paulo/SP.
Depending on the relationship maintained with the data subject and the purpose of the processing, Sioux may act as the controller of personal data or, in certain situations, as the processor of personal data processed on behalf of clients, partners, or third parties.
3. Collection and processing of personal data
Sioux adopts the principle of data minimization and seeks to process only the personal data that is necessary, adequate, and proportionate to the purposes stated in this Policy, subject to the applicable legal bases.
3.1. Website users and digital channels
When the data subject accesses the Sioux website or interacts with its digital channels, technical data and browsing information may be processed, such as IP address, date and time of access, pages visited, cookie identifiers, consent preferences, browser type, device used, source of access, and interactions carried out on the website.
This data may be used for the operation of the website, security, fraud prevention, performance analysis, audience measurement, improvement of the browsing experience, cookie management, and marketing campaigns, subject to the user's consent preferences when required by applicable law.
3.2. Job applicants, employees, and service providers
Sioux may process personal data of job applicants, employees, former employees, service providers, and other professionals connected to its activities, as applicable, through its own forms, recruitment and selection platforms, internal systems, people management tools, onboarding documents, corporate channels, and other means necessary for conducting selection processes, hiring, contract management, and compliance with legal, regulatory, labor, social security, and tax obligations, as well as for the internal administration of its activities.
Among the data that may be processed, depending on the specific purpose and the needs of the particular case, are:
- Full name;
- Email;
- Telephone/mobile;
- Date of birth;
- Address;
- Professional and résumé information;
- Social media address or professional profile, when provided by the data subject or necessary for the selection process;
- Identification photo or image;
- Copy of ID card (RG);
- Copy of individual taxpayer registry (CPF);
- Copy of work and social security card (CTPS);
- Copy of PIS/NIS card, when applicable;
- Copy of voter registration card, when applicable;
- Copy of military service certificate, when applicable;
- Copy of driver's license, when applicable;
- Copy of birth or marriage certificate, when applicable;
- Copy of proof of address;
- Copy of proof of education;
- Copy of documents relating to dependents, when necessary for compliance with legal obligations, the granting of benefits, or labor routines;
- Banking details necessary for payments;
- Information on disability, race/color, occupational health, or other sensitive data, when strictly necessary and supported by an appropriate legal basis, including for compliance with a legal or regulatory obligation, the regular exercise of rights, occupational health and safety, and diversity and inclusion initiatives conducted in a proportionate manner and, whenever possible, aggregated or anonymized, subject to the applicable access controls.
- access records, logs, internal documents, corporate communications, and other information necessary for managing the relationship maintained with Sioux.
The data may be stored in physical or digital environments controlled by Sioux, including internal directories, management systems, recruitment platforms, cloud storage tools, electronic signature tools, people management systems, and other technology suppliers contracted to support the company's activities.
Access will be restricted to authorized persons, according to their duties, with the adoption of technical and administrative controls compatible with the nature of the data processed.
3.3. Third parties and suppliers
Sioux may process personal data of third parties, suppliers, business partners, legal representatives, operational contacts, and other natural persons connected to legal entities that are contracted or in the process of being contracted, for the purposes of registration, qualification, contracting, signing of documents, payment control, contract performance, compliance with legal and regulatory obligations, auditing, fraud prevention, and administrative management.
The data may be collected through registration forms, documents sent by the data subject themselves or by the company to which they are connected, electronic signature tools, internal systems, intranet, storage tools, spreadsheets, financial platforms, and other systems used by Sioux to manage suppliers and third parties.
Among the data that may be processed, as applicable, are:
- Full name;
- ID card (RG);
- Individual taxpayer registry (CPF);
- Telephone/mobile;
- Email;
- Position or role;
- Company to which the data subject is connected;
- Banking details, when necessary for payment, particularly in cases involving a natural person, self-employed professional, or individual microentrepreneur;
- Information contained in contracts, proposals, and corporate, tax, financial, or registration documents.
The data will be processed for as long as necessary to fulfill the purposes described in this Policy, including legal, regulatory, accounting, and tax periods and any period for the regular exercise of rights.
3.4. Clients, leads, and business contacts
Sioux may process personal data of clients, potential clients, leads, business contacts, and representatives of companies interested in its services, including when the data is provided through the site's forms, landing pages, marketing campaigns, events, meetings, interactions by email, telephone, messaging apps, social media, or other contact channels.
The data may be used for handling requests, sending proposals, business relationships, prospecting, institutional marketing, sending communications, opportunity management, responding to contacts received, drafting contracts, and complying with legal or regulatory obligations.
The data may be stored and processed in CRM systems, marketing automation tools, email marketing platforms, digital forms, business management tools, internal systems, cloud storage tools, and other technology platforms used by Sioux for its commercial and administrative activities.
Among the data that may be processed, as applicable, are:
- Name;
- Email;
- Telephone;
- Company;
- Department;
- Position;
- Professional profile address on social media, such as LinkedIn;
- Information voluntarily provided by the data subject at the time of contact;
- History of commercial interactions with Sioux.
Media campaigns and lead generation may also be carried out through third-party platforms, including social media and digital advertising tools. In such cases, the data may initially be collected by the platforms themselves, in accordance with their respective privacy policies, and subsequently shared with Sioux for the purposes described in this Policy.
4. Purposes of processing and legal bases
Sioux may process personal data for the following purposes, as applicable to the relationship maintained with the data subject:
- to enable the operation of the Sioux website and digital channels;
- to respond to contacts, questions, requests, and business proposals;
- to conduct prospecting, business relationship, and institutional marketing activities;
- to send communications, content, invitations, newsletters, and information about services, when applicable;
- to conduct selection processes, hiring, employee management, and internal human resources routines;
- to register, qualify, contract, and manage suppliers, service providers, third parties, and business partners;
- to perform contracts, fulfill pre-contractual obligations, and administer commercial, labor, corporate, and institutional relationships;
- to comply with legal, regulatory, tax, accounting, labor, social security, and occupational health and safety obligations;
- to exercise rights in judicial, administrative, or arbitration proceedings;
- to carry out audits, internal controls, access records, corporate governance, and process improvement;
- to measure campaigns, analyze traffic, improve the user experience, and optimize content and services.
The legal bases that may support the processing of personal data by Sioux include, depending on the specific case: consent, compliance with a legal or regulatory obligation, performance of a contract or preliminary procedures related to a contract, the regular exercise of rights, legitimate interest, protection of the life or physical safety of the data subject or a third party, health protection, and credit protection, when applicable.
In the case of sensitive personal data, Sioux will observe the specific applicable legal grounds, such as compliance with a legal or regulatory obligation, the regular exercise of rights, protection of life or physical safety, health protection, ensuring fraud prevention and the data subject's security, or specific and highlighted consent when necessary.
5. Sharing of personal data
Sioux does not sell personal data. Personal data may be shared only when necessary to fulfill the purposes set out in this Policy, for the performance of contracts, for compliance with legal or regulatory obligations, for the regular exercise of rights, or on another applicable legal basis.
Depending on the purpose of the processing, personal data may be shared with:
- companies within the same economic group;
- authorized employees and professionals of Sioux;
- suppliers of technology, hosting, cloud storage, information security, electronic signature, administrative management, CRM, marketing, recruitment and selection, people management, and internal tools;
- providers of administrative, accounting, legal, financial, tax, social security, labor, and audit services;
- social media, digital advertising, and campaign measurement platforms, when applicable;
- clients, business partners, or contracting parties, when necessary for the performance of services or contracts;
- public authorities, regulatory bodies, government entities, the Judiciary, or third parties, when there is a legal obligation, an order from a competent authority, or a need for the regular exercise of rights.
Whenever applicable, Sioux will adopt contractual and organizational measures to ensure that processors and suppliers process personal data in accordance with its instructions, with the contracted purposes, and with adequate standards of security and confidentiality.
6. International data transfer
Sioux may use technology suppliers, digital tools, storage platforms, communication services, social media, advertising tools, and corporate systems that store or process data in other countries.
In such cases, the international transfer of personal data will occur when necessary for the purposes described in this Policy and will be carried out in accordance with the applicable legal grounds, subject to the contractual, technical, and organizational measures appropriate for the protection of personal data.
Should a given processing activity be subject to foreign data protection legislation, including the European Union's General Data Protection Regulation (GDPR), when applicable, Sioux will assess the additional measures necessary to meet the corresponding requirements.
7. Retention and deletion of personal data
Personal data will be retained for the period necessary to fulfill the purposes that justified its collection and processing, subject to the applicable legal, regulatory, tax, accounting, labor, social security, contractual, and limitation periods.
Sioux may retain personal data, even after the end of the relationship with the data subject, when such retention is necessary for compliance with a legal or regulatory obligation, performance of a contract, the regular exercise of rights, protection against fraud and security incidents, response to audits, or in other cases authorized by applicable law.
Once the purposes have ended and in the absence of any obligation or legal basis for retention, the personal data will be deleted or anonymized. Where there is an applicable legal basis for retention, the data may be kept in a secure environment for the period necessary and proportionate to the respective purpose.
8. Use of browser cookies
Cookies are small units of data stored on the user's device by the browser. Some cookies are essential for the operation of the Sioux site, while others help improve the experience, analyze traffic, measure campaigns, and display relevant content.
Cookies allow the site to remember information about users' visits, such as preferred language, recurrence of sessions, and other variables that Sioux considers relevant to make the experience more efficient.
Analytics and marketing cookies help determine the usefulness, interest, and number of uses of the site, enabling faster and more efficient browsing. Strictly necessary cookies do not store identifiable personal data. Analytics and marketing cookies, in turn, may collect browsing identifiers and interactions, as detailed in the inventory below. All non-essential cookies will be stored only with the users' authorization, when required by applicable law.
Sioux may adopt analytical data collection technologies, such as traffic and performance analysis tools, to improve users' experience with the Sioux website. Whenever possible, this data will be processed in an anonymized or aggregated manner, without allowing the direct identification of the natural person to whom it relates.
The minimization of personal data is important to Sioux. We do not collect or process personal data beyond that which is necessary for the purposes described in this Privacy Policy.
8.1. Cookie inventory
The table below identifies the cookies used on this site, organized by category, with their respective purposes, data processed, classification, retention period, and origin.
| Category | Cookie | Purpose and data processed | Duration and origin |
|---|---|---|---|
| Strictly necessary | c15t-consent | Stores the user's cookie consent preferences. Processes the categories of cookies accepted or rejected, without identifiable personal data. | Persistent; 1 year; first-party (Sioux). |
| Analytics | _ga | Anonymous analytics tool identifier used to distinguish unique visitors. May process a random identifier, the date of the first visit, the visit count, and the traffic source. | Persistent; 2 years; third-party. |
| Analytics | _gid | Analytics tool session identifier used to group actions within a visit. May process a random session identifier and anonymized data. | Persistent; 24 hours; third-party. |
| Analytics | _gat | Limits the request rate in an analytics tool. Processes only rate-control information, without directly identifiable personal data. | Session; 1 minute; third-party. |
| Marketing | _fbp | Advertising tool identifier for conversion tracking and remarketing. May process the browser identifier, pages visited, and interactions with ads. | Persistent; 90 days; third-party. |
| Marketing | _fbc | Stores an ad click for conversion attribution. May process an ad-click identifier. | Persistent; 90 days; third-party. |
| Marketing | li_sugr | Social network tool identifier for browser matching. May process a browser identifier, which may be associated with the user's profile on the respective platform. | Persistent; 90 days; third-party. |
| Analytics/Marketing | AnalyticsSyncHistory | Synchronizes analytics data from a social network tool. May process analytics synchronization data. | Persistent; 30 days; third-party. |
The inventory must be reviewed whenever there is a relevant change in the technologies used on the website.
8.2. Use of third-party cookies and technologies
Sioux may use analytics cookies, marketing cookies, pixels, tags, and similar technologies made available by third parties, including traffic analysis platforms, social media, and digital advertising tools, to measure the performance of the website, understand users' interaction with its content, optimize campaigns, and present more relevant communications.
Non-essential cookies and technologies will be used in accordance with the consent preferences expressed by the user, when required by applicable law. For more information about the practices of these third parties, we recommend consulting their respective privacy policies.
8.3. How to prevent cookies from being stored and/or delete them
Most internet browsers are configured to automatically accept cookies. The user may change the settings to block the use of cookies or to receive an alert when a cookie is being sent to their device.
After authorizing the use of cookies, the user may always disable some or all cookies, in accordance with the functionalities made available in the consent banner, in the cookie preference center, or in the settings of the browser used.
All browsers allow the user to accept, refuse, or delete cookies, usually through the options or preferences of the respective browser.
By disabling cookies, some services or functionalities of the website may not work correctly, partially or fully affecting the browsing experience.
8.4. Documentation and periodic review
This cookie inventory is reviewed and updated periodically, at least every 6 months or whenever there is a relevant change in the tracking technologies used on the site.
The last review of this inventory was carried out in April 2026. Any relevant changes will be communicated through the update of this Privacy Policy.
8.5. Spam protection
Sioux may use tools to protect against spam, fraud, and automated abuse in its forms and digital channels. When interacting with the site's forms, technical information, such as IP address, user interactions, browser data, and device information, may be collected and processed by technology suppliers contracted for this purpose.
9. Controller information
When Sioux acts as the controller of personal data, for the purposes of this Privacy Policy, the controller shall be:
- Sioux Social Agência de Publicidade Ltda., a private legal entity, registered under CNPJ No. 19.614.018/0001-01, with address at Av. Nova Independência, 87, conj. 92, sala 2, Brooklin, São Paulo/SP; and
- Sioux Consulting Ltda., a private legal entity, registered under CNPJ No. 00.316.268/0001-37, with address at Av. Nova Independência, 87, 9º andar, Brooklin, São Paulo/SP.
10. Data Protection Officer contact details
Questions, suggestions, requests, or complaints about this Privacy Policy or about the way Sioux processes personal data may be sent directly to the Data Protection Officer through the following contact:
11. Information security
Sioux adopts reasonable technical and administrative measures compatible with the nature of the data processed to protect personal data against unauthorized access, loss, alteration, improper disclosure, or any form of inappropriate or unlawful processing.
Among the measures that may be adopted, as applicable, are access controls, restriction of permissions, log recording, environment segregation, use of security tools, credential management, internal policies, contracts with suppliers, and periodic review of data processing practices.
Although Sioux adopts security measures to protect personal data, no physical or digital environment is entirely immune to risks. In the event of a security incident that may result in relevant risk or harm to data subjects, Sioux will assess the appropriate measures, including notifications to the data subjects and to the National Data Protection Authority, when required by applicable law.
12. Rights of data subjects
Data subjects may exercise, under the terms of the Brazilian General Data Protection Law (LGPD), the following rights:
- The right to confirm the existence of processing of their personal data, pursuant to Article 18, I, of the General Data Protection Law;
- The right to access their personal data, pursuant to Article 18, II, of the General Data Protection Law;
- The right to correct incomplete, inaccurate, or outdated data, pursuant to Article 18, III, of the General Data Protection Law;
- The right to anonymize, block, or delete unnecessary or excessive data, or data processed in noncompliance with the General Data Protection Law, pursuant to Article 18, IV;
- The right to data portability, pursuant to Article 18, V, of the General Data Protection Law, subject to applicable regulations;
- The right to delete personal data processed on the basis of consent, pursuant to Article 18, VI, of the General Data Protection Law, subject to the legal grounds for retention;
- The right to information about the public and private entities with which Sioux has shared data, pursuant to Article 18, VII, of the General Data Protection Law;
- The right to information about the possibility of not providing consent and about the consequences of refusal, pursuant to Article 18, VIII, of the General Data Protection Law;
- The right to withdraw consent, easily and free of charge, pursuant to Article 18, IX, of the General Data Protection Law;
- The right to lodge a complaint against the controller before the National Data Protection Authority, consumer protection bodies, or the Judiciary, under the terms of applicable law;
- The right to request a review of decisions taken solely on the basis of automated processing of personal data that affect their interests, including decisions intended to define a personal, professional, consumer, or credit profile, or aspects of their personality, pursuant to Article 20 of the General Data Protection Law.
Requests may be sent to Sioux's Data Protection Officer through the contacts indicated in this Policy. Sioux may request additional information to confirm the data subject's identity and ensure the security of the service.
Some requests may not be fully met when there is a legal obligation to retain data, a need for the regular exercise of rights, protection against fraud, performance of a contract, or another legal basis that authorizes the retention or continuation of the processing of personal data.
13. Limitation of liability
Sioux adopts reasonable technical and administrative measures compatible with the nature of the data processed to protect personal data against unauthorized access, loss, alteration, improper disclosure, or any form of inappropriate or unlawful processing.
Nevertheless, certain breaches of the confidentiality or security of personal data may result from conduct, equipment, networks, systems, or digital environments beyond Sioux's reasonable control.
For this reason, subject to applicable law, users acknowledge that Sioux shall not be liable for damages arising exclusively from:
- Failures, viruses, malware, ransomware, or other harmful elements present in the equipment, systems, networks, or digital environments used by the user themselves or by third parties beyond Sioux's reasonable control;
- Improper access to personal data when such access results exclusively from a fault attributable to the user themselves, such as improper sharing of credentials, use of insecure passwords, access through unprotected networks, or failure to comply with basic security guidelines;
- Acts of third parties that are beyond Sioux's reasonable control, without prejudice to the applicable legal responsibilities and the measures that may be appropriate for mitigating incidents.
14. General provisions
The terms of this Privacy Policy may be amended at any time, according to the need to adapt to Sioux's activities, the technologies used, the purposes of processing, legal or regulatory requirements, and good practices for the protection of personal data.
It is up to data subjects to review this Policy from time to time.
Should substantial changes be made to the purposes for which Sioux collects personal data or to the legal bases that authorize the processing, the affected data subjects may be notified by email, a highlighted notice on the website, or another appropriate means, as the case may be.
In the event that any provision of this Privacy Policy is deemed illegal or invalid, the remaining provisions shall remain in full force and effect.
15. Applicable law and jurisdiction
This Privacy Policy shall be governed by and interpreted in accordance with the laws in force in the Federative Republic of Brazil, in particular the General Data Protection Law — Law No. 13.709/2018.
Any litigation or disputes related to this Privacy Policy shall be resolved before the Central Civil Court of the Judicial District of São Paulo, State of São Paulo, with express waiver of any other, however privileged it may be.