Privacy Policy
1. Who we are
This Privacy Policy describes how SIGMAIS RODOVIAS LTDA, registered under CNPJ no. 68.400.386/0001-62, with its registered office at Juiz de Fora, Minas Gerais, Brasil ("Rodovias Online", "we"), processes personal data within the Sigmais Rodovias platform (the sites sigmais.rodovias.online, auth.rodovias.online, www.rodovias.online and the related mobile application).
This document complies with Brazilian Federal Law no. 13,709/2018 — the General Personal Data Protection Law (LGPD).
2. Roles in the processing
The Sigmais platform is contracted by highway concession companies ("Contracting Client"), which use it to manage inspections, enforcement and their relationship with service providers.
- Controller of the personal data entered into the platform: the contracting concession company.
- Processor, acting on the Controller's behalf and instructions: Rodovias Online.
- Sub-processors: service provider companies authorised by the Controller.
For browsing data on the institutional site www.rodovias.online (unauthenticated visitors, contact forms), Rodovias Online acts as Controller.
3. Data Protection Officer (DPO)
- Name: Sandro Coelho
- Email: [email protected]
Any question, request to exercise rights, or incident report should be addressed to the DPO through the channels above.
4. Personal data we process
4.1. Platform user account data
- Full name, corporate email address, Keycloak identifier;
- Association with a company (concession company or service provider) and profile/role;
- Encrypted password.
4.2. Data on adjoining landowners and right-of-way occupations
Entered by inspectors: name or company name, taxpayer number (CPF/CNPJ), address, phone, city, state and postcode. Collection is indirect, based on compliance with a legal and regulatory obligation (art. 7, II) and the legitimate interest of the concession company in managing the right of way (art. 7, IX).
4.3. Geolocation data of field operators
When the mobile inspection application is used, the system collects latitude, longitude, accuracy, speed, highway/section and timestamp. Retention is 48 hours for the current position and 7 days for the history.
Legal basis: performance of a contract (art. 7, V) between the operator and their employer, together with the concession company's regulatory obligation.
4.4. Audit data
Every record created, changed or deleted is linked to the responsible user (legitimate interest — art. 7, IX).
4.5. Browsing data and technical logs
IP address, user agent, session cookies (NextAuth) and error monitoring data (Sentry, collected only when an error occurs).
4.6. Inspection photographs
Stored in Cloudflare R2. Operators are instructed to avoid unnecessary capture of images of third parties, and we provide a channel for requesting anonymisation or removal.
5. What we use the data for (purposes)
- Enabling authenticated user access to the platform;
- Delivering the features contracted by the concession company;
- Securing the platform (logs, audit trails, fraud prevention);
- Meeting legal, regulatory and contractual obligations (including those of Brazil's ANTT);
- Notifying users of relevant operational updates;
- Responding to data subject requests;
- Defending our rights in judicial, administrative or arbitration proceedings.
We do not use the data for marketing, behavioural advertising, profiling, or sale to third parties.
6. Legal bases (arts. 7 and 11 of the LGPD)
- Performance of a contract (art. 7, V) — operating the platform;
- Legal/regulatory obligation (art. 7, II) — regulatory registrations;
- Legitimate interest (art. 7, IX) — audit trails and security;
- Consent (art. 7, I) — the contact form on the institutional site and non-essential cookies.
We do not process sensitive personal data in the platform's regular operation.
7. Sharing with third parties (sub-processors)
- KingHost — application server hosting (Brazil);
- Cloudflare, Inc. — CDN, protection, TLS and R2 storage (USA);
- Functional Software, Inc. (Sentry) — monitoring (USA);
- Google LLC (Workspace) — corporate email (USA);
- GitHub, Inc. — repository and registry (USA).
We also share data with authorities where required by law, court order or a legitimate administrative request. We do not sell, rent or assign personal data to third parties.
8. International data transfers
Cloudflare, Sentry, Google and GitHub process part of the data in the United States. The transfer is grounded in art. 33, V and IX of the LGPD, with data processing agreements in place and international security standards (ISO 27001, SOC 2 Type II) adopted by the sub-processors.
9. Data subject rights (art. 18 of the LGPD)
You may exercise at any time:
- Confirmation that processing exists;
- Access to your data;
- Correction of incomplete, inaccurate or outdated data;
- Anonymisation, blocking or deletion of unnecessary data;
- Portability to another provider;
- Deletion of data processed on the basis of consent;
- Information about the entities we share data with;
- Information about the possibility of withholding consent;
- Withdrawal of consent;
- Objection to processing that does not comply with the LGPD;
- Review of automated decisions.
To exercise any of these rights, contact the DPO: [email protected]. We will respond within 15 (fifteen) calendar days.
Important: where your data was entered by the contracting concession company (for example, a record as an adjoining landowner), the request may be directed primarily to that company, as Controller.
10. Retention and disposal
- Active user account: for the term of the contract + 2 years after deactivation;
- Records and inspections: 5 years after the contract ends (aligned with ANTT requirements);
- Current location: 48 hours;
- Location history: 7 days;
- Keycloak logs: 6 months;
- Sentry logs: 30 days;
- Cloudflare/Traefik logs: 90 days;
- Operational backups: 35 days.
11. Information security
We adopt technical and administrative measures consistent with the state of the art: TLS, Keycloak authentication with JWT, RBAC, soft delete and audit trails, database IP allowlisting, backups, continuous updates and Docker images pinned by digest. In the event of an incident, we will notify Brazil's ANPD and the data subjects within 3 business days of becoming aware of it.
12. Cookies
We use only strictly necessary cookies and, subject to consent, functional and analytics cookies. Details in our Cookie Policy.
13. Children and adolescents
The platform is intended for professional use by adults. We do not knowingly collect data from anyone under 18.
14. Changes to this Policy
This Policy may be revised at any time. Material changes will be communicated to authenticated users at least 30 days in advance.
15. How to reach us
- Data Protection Officer: Sandro Coelho — [email protected]
- Postal address: Juiz de Fora, Minas Gerais, Brasil
- Brazilian Data Protection Authority (ANPD): www.gov.br/anpd
