◆ Legal Documents
Privacy Policy &
Data Protection
We are strongly committed to the protection of your personal data. This policy describes how we collect, use and protect your information in compliance with global privacy regulations.
01
Introduction and Purpose
Skander Capital ("Skander", "We", or "The Manager") is strongly committed to protecting and maintaining the confidentiality of the personal data of our website users and institutional clients. This Privacy Policy describes, with full transparency and in strict compliance with Brazil's General Data Protection Law (LGPD – Law No. 13,709/2018) and the European Union's General Data Protection Regulation (GDPR – Regulation (EU) 2016/679), how we collect, use, store and share your personal data.
02
Skander's Role
Data Controller
For the purposes of the LGPD and GDPR, Skander Capital's operational entities act as Data Controllers. This means we determine the purposes and means of processing the personal data we collect, assuming full fiduciary responsibility for its protection.
03
Personal Data We Collect
We collect only the data strictly necessary for the purposes described in this policy (Principle of Minimisation):
Navigation Data (Automatic Collection): IP address, browser type, operating system, pages visited, time spent and cookie data (subject to your consent via our Cookie Banner).
Contact Data: Name, corporate email address, telephone number and job title, when voluntarily submitted through our website forms or by direct communication with our Investor Relations team.
Compliance and Onboarding Data (For Clients): For Know Your Client (KYC) and Anti-Money Laundering (AML) procedures, we collect corporate identification data and information on Ultimate Beneficial Owners (UBOs), as required by global financial and regulatory authorities.
04
Legal Bases and Purposes of Processing
The processing of your data is based on the following legal grounds:
Performance of a Contract or Pre-contractual Due Diligence: For processing enquiries, onboarding new institutional clients and managing the ongoing relationship.
Compliance with a Legal or Regulatory Obligation: For record retention required by the CVM, SEC, CMVM or other regulatory bodies, as well as for audit and AML/CTF processes.
Legitimate Interests of the Controller: For the security of our digital platforms, fraud prevention and navigational analytics to improve website architecture.
Free, Informed and Unambiguous Consent: Where necessary for the use of non-essential cookies or one-off communications (always with a simple opt-out option).
05
International Data Transfers
LGPD & GDPR
As Skander is a global manager with offices in Brazil, Portugal, Uruguay and the USA, your data may be shared internally or stored on servers located outside your country of residence. Skander ensures that any international data transfer is carried out with an adequate level of protection, using:
Adequacy decisions from the European Commission or the National Data Protection Authority (ANPD).
Standard Contractual Clauses (SCCs) approved by the competent authorities.
Global Corporate Policies based on rigorous encryption and access segregation standards (Chinese Walls).
06
Data Storage and Information Security
Data security is managed with the same discipline applied to our financial risk management. We use advanced security architectures, including end-to-end encryption, institutional firewalls, rigorous physical and logical access controls, and periodic reviews by independent auditors. Personal data will be retained only for the period necessary to fulfil the purpose for which it was collected or to comply with applicable legal and regulatory obligations.
07
Sharing Personal Data with Third Parties
Skander does not sell your data. Sharing is strictly limited to:
Regulatory and Governmental Bodies: When required by law, court order or to fulfil Compliance obligations.
Qualified Service Providers: Such as independent auditors, cloud hosting services and legal consultants, all bound by rigorous confidentiality and data processing agreements.
08
Your Rights as a Data Subject
In accordance with the LGPD and GDPR, we guarantee the exercise of the following rights over your personal data:
Confirmation and Access: Obtain confirmation of the existence of processing and access the data processed.
Correction: Request the rectification of incomplete, inaccurate or outdated data.
Anonymisation, Blocking or Erasure: Request the erasure of data where the legal basis is exclusively consent or where the data is shown to be unnecessary, unless there is a legal retention obligation.
Portability: Transfer your data to another service provider (subject to technical feasibility).
Withdrawal of Consent: At any time, without affecting the lawfulness of processing carried out prior to withdrawal.
09
Updates to This Policy
Given the dynamic nature of global legislation (LGPD and GDPR), Skander Capital reserves the right to update this document periodically. The most recent and effective version is from April 2026. We recommend periodic review of this page.
10
Contact the Data Protection Officer
DPO — Data Protection Officer
To exercise your rights or clarify questions about our privacy practices, please contact our Data Protection Officer (DPO) through the dedicated channel.
Last updated: April 2026
