TechFX Payroll, a platform operated by TECHFX LTDA, a private legal entity, enrolled with the CNPJ/MF under No. 68.914.427/0001-39, with its head office at Av. Paulista 777, Floor 15, Conj. 15, Room 3456, São Paulo/SP, ZIP Code: 01311-100. Last updated: September 2026 (Version 1.0)

Hey!

In Brazil, the protection of personal data is regulated by Law No. 13,709/2018, the Brazilian General Data Protection Law (“LGPD”). This Privacy Policy (“Policy”) explains, transparently, how TECHFX LTDA, a private legal entity, enrolled with the CNPJ/MF under No. 68.914.427/0001-39, with its head office at Av. Paulista 777, Floor 15, Conj. 15, Room 3456, São Paulo/SP, ZIP Code: 01311-100 (“OPERATOR” or “We”), operator of the TechFX Payroll platform (“PLATFORM”), processes personal data, that is, how it is collected, used, shared, stored and protected, and how you can exercise control over it.

AWARENESS OF AND ACCEPTANCE OF THIS POLICY ARE INDISPENSABLE FOR USE OF THE PLATFORM. ACCEPTANCE IS COLLECTED UPON THE COMPANY’S REGISTRATION AND UPON EACH ADMINISTRATOR’S FIRST ACCESS, AS SET OUT IN SECTION 3 AND IN THE TERMS OF USE, AND DOES NOT REPLACE THE SPECIFIC CONSENTS, COLLECTED SEPARATELY FOR THE OPERATIONS THAT RELY ON THEM. THE LEGAL BASES FOR EACH PROCESSING ACTIVITY ARE INDICATED IN SECTION 2.

THIS OPERATION INVOLVES INTERNATIONAL TRANSFER OF PERSONAL DATA: THE DATA IS STORED IN CLOUD INFRASTRUCTURE LOCATED IN THE UNITED STATES OF AMERICA AND MAY BE SENT TO DESTINATIONS ABROAD FOR THE EXECUTION OF PAYMENTS. SECTION 6 DETAILS THE SCENARIOS AND THE SAFEGUARDS UNDER ARTICLES 33 TO 36 OF THE LGPD.

This Policy applies regardless of the country of incorporation or the location of the COMPANY and of the other Data Subjects: the processing described in this Policy is carried out in Brazil and is subject to the LGPD (article 3), without prejudice to additional rights afforded by data protection legislation of other jurisdictions, where applicable. This Policy is written in Portuguese; courtesy translations may be made available and, in the event of divergence, the Portuguese version shall prevail.

For the purposes of this Policy, we adopt the following definitions:

Personal Data: any information relating, directly or indirectly, to an identified or identifiable natural person.

Processing: under article 5, X, of the LGPD, any operation carried out with Personal Data, such as those relating to collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation or control of information, modification, communication, transfer, dissemination or extraction.

Data Subject: the natural person to whom the Personal Data being Processed refers.

Controller: the party responsible for the decisions regarding the Processing, in particular as to its purposes and means.

Processor: the party that carries out the Processing of Personal Data on behalf of and according to the instructions of the Controller.

Data Protection Officer: the person appointed by the OPERATOR to act as the communication channel with Data Subjects and with the Brazilian National Data Protection Authority (“ANPD”).

Security Incident: any accidental, unlawful or unauthorized access, acquisition, use, modification, disclosure, loss, destruction or damage involving Personal Data.

COMPANY: the legal entity, Brazilian or foreign, that contracts the PLATFORM for the management of its international payroll, under the Terms of Use.

ADMINISTRATORS: the administrator users enabled by the COMPANY to operate the PLATFORM on its behalf, who accept this Policy on first access, as set out in Section 3 and in the Terms of Use.

PAYEE: the recipient of payments (employee or contractor of the COMPANY), located in Brazil or abroad, registered by the COMPANY on the PLATFORM. The PAYEE does not access the PLATFORM, but is the Data Subject of the Personal Data processed for the execution of payments.

LUMX: LUMX SOCIEDADE PRESTADORA DE SERVIÇOS DE ATIVOS VIRTUAIS LTDA., a private legal entity, enrolled with the CNPJ under No. 42.887.120/0001-00, with its head office at Avenida Ataulfo de Paiva, No. 391, room 606, Leblon, Rio de Janeiro/RJ, ZIP Code 22440-032, provider of the virtual asset services accessible through the PLATFORM (“Lumx Services”), an activity regulated by the Central Bank of Brazil, which acts as an independent Controller, as set out in Section 4.

1. Who this Policy applies to

This Policy applies to: (i) legal representatives and contacts of the COMPANIES; (ii) shareholders, officers and ultimate beneficial owners of the COMPANIES, whose data appears in the documentation submitted at registration; (iii) ADMINISTRATORS; (iv) PAYEES, even if they do not access the PLATFORM; and (v) visitors to the PLATFORM’s website. This Policy is publicly available, with no login required, precisely so that PAYEES and other Data Subjects may consult it at any time. The PLATFORM is not intended for persons under 18 (eighteen) years of age.

2. What Personal Data we process, for what purpose and on what legal basis

We collect the minimum Personal Data necessary to achieve the purposes below. We do not collect sensitive data for the operation of the PLATFORM and we do not carry out enrichment of PAYEE data with external sources.

Data Subjects Personal Data Purposes Legal bases (LGPD)
Representatives of the COMPANIES Full name, identification document (in Brazil, CPF and identity card; abroad, passport or equivalent), position, e-mail, telephone; records of acceptance of the Terms of Use (date, time, version, IP) Execution and performance of the contract; verification of powers; operational communication; evidence of contracting Consent (art. 7, I), Performance of a contract (art. 7, V); legal/regulatory obligation (art. 7, II); legitimate interest (art. 7, IX)
Shareholders, officers and ultimate beneficial owners of the COMPANIES Identification data contained in the corporate and representation documentation submitted at registration (in Brazil or abroad) and in the information on ultimate beneficial owners provided by the COMPANY Registration verification; compliance with requirements of the Lumx Services layer and of the applicable regulation; fraud prevention Consent (art. 7, I), Legal/regulatory obligation (art. 7, II); legitimate interest (art. 7, IX)
ADMINISTRATORS Functional identification, e-mail, access credentials, records of individual acceptance (date, time, version) and activity records on the PLATFORM (audit trails/logs) Authentication; security; evidence of individual binding; audit trails; fraud prevention Consent (art. 7, I), performance of a contract; legitimate interest in security; legal obligation (Brazilian Internet Civil Framework)
PAYEES Name, identification document, contact details, destination country and data required to direct payments, as registered by the COMPANY Organization and preparation of the COMPANY’s international payroll; reports and receipts; compliance with legal, regulatory and contractual obligations Legitimate interest (art. 7, IX); legal/regulatory obligation, where applicable
Website visitors Browsing data and cookies: IP, date and time of access, pages visited, browser type and version, operating system and device Operation and security of the website; usage statistics and improvement of services Legal obligation (art. 15 of the Internet Civil Framework, logs); legitimate interest (essential cookies and security)

 

Origin of PAYEE data. PAYEE data is provided exclusively by the COMPANY that registers it, which is responsible for ensuring the lawfulness of the collection at source, including under the legislation of the country in which it is established, and for maintaining, before its employees and contractors, the notices and information required by the applicable legislation, covering the sharing with the OPERATOR and with LUMX for the execution of payments. We do not collect PAYEE data directly.

Support records. We also process the contact details and the content of tickets, questions and complaints received through the support channels, for handling, recording and forwarding as set out in the Terms of Use, on the basis of legitimate interest and compliance with legal and contractual obligations.

Processing of Personal Data on behalf of the COMPANY. With regard to the Personal Data of PAYEES and the data relating to the payments it registers on the PLATFORM, the COMPANY acts as controller and the OPERATOR as processor, under article 5, VI and VII, of the LGPD, processing them exclusively on behalf of the COMPANY and according to the instructions contained in these Terms and in the settings made by the COMPANY on the PLATFORM, which include sending such data to LUMX for the provision of the LUMX SERVICES. In this Processing, the OPERATOR: (i) will maintain the confidentiality and security of the data, as set out in the Privacy Policy; (ii) may use the infrastructure and technology providers indicated by category in the Privacy Policy, under data protection obligations compatible with these Terms; (iii) will inform the COMPANY, without undue delay after its confirmation, of any Security Incident involving such data; (iv) will assist the COMPANY in responding to Data Subject requests; and (v) will observe, upon termination of the account, the provisions of Section 15.7. The COMPANY acknowledges that the OPERATOR acts as controller when it retains such data for compliance with its own legal, regulatory or contractual obligations, for the security of the PLATFORM or for the regular exercise of rights, for the periods set out in the Privacy Policy.

3. Acceptance of this Policy and specific consents

Awareness of and agreement with this Policy are recorded at two moments: (i) upon acceptance by the COMPANY’s representative, together with the Terms of Use; and (ii) upon each ADMINISTRATOR’s first access, to the extent applicable to them, in both cases with a record of date, time, accepted version and identification, retained for the periods in Section 7. PAYEES do not perform any acceptance: as they do not access the PLATFORM, transparency towards them is ensured by the public availability of this Policy and by the COMPANY’s duties of information at source, as set out in Section 2. Acceptance serves as evidence of awareness of and agreement with the conditions of this Policy.

Specific consents. For the processing operations based on consent, it is collected in a specific, informed, highlighted and granular manner, through the Data Subject’s own action (for example, checkboxes that are not pre-ticked), separately from the acceptance of this Policy, for the following purposes: (i) sending promotional communications and news about the PLATFORM; and (ii) non-essential cookies, if and when they come to be adopted (Section 10). Refusal or absence of consent does not prevent the use of the PLATFORM nor condition the provision of the services.

Withdrawal. Consents may be withdrawn at any time, free of charge and through a facilitated procedure, via the preferences panel, via the link present in the communications themselves or via the Data Protection Officer’s channel (Section 12), without retroactive effects on the processing carried out while they were in force. We keep a record of the consents obtained and of their withdrawals (date, time, version and scope), as set out in Section 7.

4. The Lumx layer: independent Controllers

Virtual asset services are an activity regulated by Law No. 14,478/2022 and by the regulation of the Central Bank of Brazil (BCB Resolutions No. 519, No. 520 and No. 521, of 2025). In fulfilling the obligations inherent to this activity, LUMX processes Personal Data as an independent Controller, according to its own purposes and legal bases, including identification and qualification procedures (KYC/KYB), transaction monitoring, prevention of money laundering and terrorist financing (AML/CFT), sanctions screening, reports to the competent authorities and other regulatory duties of a virtual asset service provider. The processing carried out by LUMX is described in LUMX’s own privacy notice, available at https://lumx.io/legal.

Data Subject requests relating to the Processing carried out by LUMX will be forwarded to LUMX, without retention, as set out in Section 9.

5. Who we share your Personal Data with

All information processed by the OPERATOR is confidential and under no circumstances will we sell your Personal Data. We share Personal Data only with:

LUMX: for the provision of the Lumx Services, as set out in Section 4;

The COMPANY itself: reports, receipts and audit trails that identify its ADMINISTRATORS and PAYEES, for purposes of internal control, accountability and compliance with the COMPANY’s obligations, as set out in the Terms of Use;

Infrastructure and technology providers: cloud hosting (with storage in the United States of America, as set out in Section 6), communication and transactional messaging, monitoring, security and electronic signature, engaged under contractual obligations of confidentiality and data protection compatible with this Policy. For security reasons, the providers are identified by category; the list of names is kept in the OPERATOR’s internal record of processing operations (article 37 of the LGPD) and presented to competent authorities and regulated partners when required;

Public authorities: when necessary to comply with a legal or regulatory obligation, to safeguard the OPERATOR’s rights or to respond to an order from a competent authority (the Judiciary, the Public Prosecutor’s Office, regulatory bodies, among others).

In all cases, Personal Data is shared only to meet the purposes described in this Policy, within the strict limit necessary. Whenever possible, we request that third parties maintain the confidentiality and security of the shared information.

6. Can your Personal Data be transferred abroad?

Yes. International transfer of Personal Data occurs in three situations: (i) storage: the PLATFORM operates on cloud infrastructure located in the United States of America, where Personal Data is stored, protected by encryption at rest; (ii) execution of payments: directing payments to PAYEES located abroad presupposes sending the necessary data to those destinations; and (iii) foreign COMPANY: reports, receipts and audit trails containing Personal Data are made available to the COMPANY in its country of origin.

Safeguards (articles 33 to 36 of the LGPD and ANPD Board Resolution No. 19/2024). Every international transfer carried out by the OPERATOR relies on one of the scenarios set out in article 33 of the LGPD: (i) for the cloud infrastructure and the other providers located abroad, the adoption of standard contractual clauses approved by the ANPD or of specific contractual clauses ensuring guarantees equivalent to those of the LGPD (article 33, II, and articles 34 and 35), incorporated into the contracts entered into with those recipients; (ii) for sending the data necessary for the execution of payments to the destinations indicated by the COMPANY, the necessity of the transfer for the performance of the contract (article 33, IX, in conjunction with article 7, V); and (iii) where applicable, the transfer to countries recognized by the ANPD as providing an adequate level of protection (article 33, I).

International transfer does not reduce your rights: Personal Data remains subject to this same standard of protection, purposes, retention, security and rights set out in the preceding Sections, and any material change to the guarantees adopted will be reflected in this Policy, under article 36 of the LGPD. Personal Data received from abroad, such as the data of PAYEES registered by a foreign COMPANY, is processed in Brazil under the LGPD and this Policy, without prejudice to the COMPANY’s obligations at source. The international transfers carried out by LUMX within the scope of the Lumx Services are the responsibility of LUMX, in its capacity as an independent Controller.

7. How long is Personal Data stored?

We retain Personal Data for as long as necessary for the purposes of this Policy and for the periods required by law, regulation or contract:

Category Period Grounds
Acceptance records (of the COMPANY and individual records of the ADMINISTRATORS) and evidence of display of notices 10 years Contractual and regulatory requirement of the operation
Application access records (logs and audit trails) Term of the agreement + 6 months Article 15 of Law No. 12,965/2014 (Internet Civil Framework)
Registration data and data of the contractual relationship (including corporate documentation and ultimate beneficial owners) Term of the agreement + 5 years from the termination of the account, without prejudice to statutory periods Regular exercise of rights (articles 205 and 206 of the Brazilian Civil Code)
PAYEE data linked to processed payrolls 5 years from the termination of the COMPANY’s account, without prejudice to legal and regulatory periods Legal and regulatory obligations; regular exercise of rights
Records of tickets and complaints Term of the agreement + 6 months Contractual obligations of the operation; regular exercise of rights
Records of specific consents and of their withdrawals Term of the agreement + 5 years from the termination of the account, without prejudice to statutory periods Article 8, paragraph 2, of the LGPD (proof of consent by the Controller)
Cookies and browsing data As set out in Section 10 Legitimate interest; consent, where applicable

 

Once these periods have elapsed, Personal Data is securely deleted or anonymized. Even after a deletion request by the Data Subject, we may retain Personal Data where retention is necessary for compliance with a legal or regulatory obligation, or for the regular exercise of rights, under article 16 of the LGPD.

8. How we protect your Personal Data

We adopt technical, administrative and organizational security measures compatible with market standards, including: role-based access controls and strong authentication for administrative access; encryption of data in transit and at rest; network security, with firewalls and intrusion detection; periodic security testing and remediation of vulnerabilities according to criticality; logging and monitoring of access; periodic backups; and an incident response plan. Only authorized persons, subject to a duty of confidentiality, have access to Personal Data.

You also contribute to the security of your data: keep the environment of your access device secure, with appropriate tools (antivirus, firewall) and updated versions of browsers and systems.

9. What your rights are and how to exercise them

Every Data Subject (including PAYEES, wherever they are located) may exercise, directly before the OPERATOR, the rights set out in article 18 of the LGPD:

Right What it means
Confirmation and access To confirm whether we process your Personal Data and to obtain access to the data processed.
Rectification To request the correction of incomplete, inaccurate or outdated data. In the case of PAYEE data registered by the COMPANY, the correction may be forwarded to the COMPANY, the source of the data, with notice to the Data Subject.
Anonymization, blocking or deletion To request the anonymization, blocking or deletion of unnecessary or excessive data or data processed in breach of the law, subject to the legal grounds for retention (Section 7).
Portability To request the portability of the data to another provider, in a structured format, subject to commercial and industrial secrets.
Information on sharing To obtain information on the public and private entities with which we share data (Sections 3 and 4).
Objection and review To object to processing based on legitimate interest, subject to assessment of the specific case, and to request the review of decisions taken solely on an automated basis, if any.

 

Requests may be submitted free of charge to the Data Protection Officer, through the channel in Section 12, in Portuguese or in English, and will be answered within the periods set out in the LGPD and in the ANPD’s regulation. Where the request concerns Processing carried out by LUMX or by the COMPANY (such as the correction of registration data held by the employer), we will forward the request to the competent Controller, without retention, and will inform the Data Subject of the forwarding.

10. Cookies

When you access the website or the PLATFORM, some data may be collected automatically through cookies, small files stored on your device that allow, for example, keeping your session authenticated and understanding how the website is used. Currently, we use only essential cookies, necessary for authentication, security and the functioning of the PLATFORM, which cannot be disabled without impairing its operation, and we do not use analytics, advertising or third-party tracking cookies. Should this change, this Policy will be updated and, for non-essential cookies, specific consent will be collected, as set out in Section 3. You can manage cookies in your browser settings.

11. Security incidents

In the event of a Security Incident that may result in relevant risk or damage to Data Subjects, we will take the measures and make the communications set out in article 48 of the LGPD and in ANPD Board Resolution No. 15/2024, including, where required, notification to the ANPD and to the affected Data Subjects.

12. Data Protection Officer and contact channel

The OPERATOR is always available to clarify matters relating to the Processing of your Personal Data. Data Protection Officer: Alan Sikora, dpo@techfx.com.br. We will use our best efforts to respond to all requests in the shortest time possible.

13. When may this Policy be amended?

This Policy may be updated to reflect changes in the operation, in the PLATFORM or in the legislation. The date of the last update appears at the beginning of this document. Material changes will be communicated prominently on the PLATFORM and, where they involve new processing based on consent, consent will be requested in a specific manner. Material changes may require renewed acceptance, as set out in the Terms of Use. The version history will be available upon request at hey@techfx.com.br.

TechFX Payroll: the virtual asset services are provided directly by LUMX SOCIEDADE PRESTADORA DE SERVIÇOS DE ATIVOS VIRTUAIS LTDA., enrolled with the CNPJ under No. 42.887.120/0001-00 (“Lumx”). TECHFX LTDA, a private legal entity, enrolled with the CNPJ/MF under No. 68.914.427/0001-39, with its head office at Av. Paulista 777, Floor 15, Conj. 15, Room 3456, São Paulo/SP, ZIP Code: 01311-100, operator of the TechFX Payroll platform, acts exclusively as a technological channel and relevant technology service provider to Lumx, under articles 32 to 42 of BCB Resolution No. 520/2025, and is not a virtual asset service provider, a payment institution or a financial institution, nor an agent or representative of Lumx. The relationship concerning the virtual asset services is established directly between the client and Lumx. To contact Lumx: support@lumx.io. “TechFX” and “TechFX Payroll” are trademarks used under license.