Sandbox environment: no real transactions are processed.

Public document

Privacy Policy

This Policy explains how Raims collects, uses, shares, stores, and protects personal data of business representatives and users, end customers, payers, and visitors across its sites, platform, checkout, authorized integrations, communications, and support.

1

Who we are and when this Policy applies

Raims processes personal data to operate a financial infrastructure technology platform for companies of different sizes, built for security, scale, and operational availability, with authentication, charges, statements, support, fraud prevention, and compliance.

This Policy applies to Raims public sites, platform environment, Raims checkout, transparent checkouts integrated by business customers, support channels, communications, onboarding, and other official surfaces. It also applies when Raims needs to process data for security, fraud prevention, compliance, audit, availability, and defense of rights.

When business customers use the platform for their own customers and payers, they are usually controllers of data related to the offer and commercial relationship, and Raims acts as processor under their instructions. Raims may act as controller for its own processing needed for platform security, payment execution and records, fraud prevention, legal compliance, dispute management, and defense of rights.

2

Raims roles in data processing

Raims role may vary according to context, purpose, contractual relationship, resource used, and applicable obligation.

Controller

Raims decides means and purposes when processing data to create and administer its own platform, authenticate users, protect accounts, prevent fraud, comply with legal and regulatory obligations, manage support, measure availability, investigate incidents, and defend rights.

Processor

Raims usually acts on behalf of the business customer when processing end-customer and payer data supplied by the business or collected at checkout under its instructions for charge issuance, notifications, receipts, and operational queries.

Own or shared processing

In payment, compliance, risk, dispute, audit, security, or legal order flows, Raims may need to process certain data for its own purposes or purposes required by regulated third parties.

3

Personal data we may process

The categories below describe data that may be processed depending on the resource used, account type, business customer configuration, payment stage, and applicable obligations.

Raims does not request bank passwords. In the current scope, the platform operates with Pix and boleto and may process registration, financial, and operational data linked to the company's account in Raims, always to the extent necessary for charge issuance, payment monitoring, balances, statements, settlements, withdrawals to a registered bank account under the same ownership, limits, reconciliation, receipts, support, fraud prevention, AML/CFT, and compliance with legal obligations.

Account and registration

Name, email, phone, role, company, tax ID, representatives, invited users, and access permissions to create accounts, authenticate users, administer tenants, provide support, and perform contracts.

Authentication and security

Password protected by hash, sessions, tokens, MFA, passkeys, trusted devices, access logs, and audit trails to protect accounts, prevent fraud, investigate abuse, and apply security controls.

Payments and financial operations

Charges, payment identifiers and status, amounts, Pix, boleto, checkout data, balances, statements, settlements, withdrawals to a registered bank account under the same ownership, limits, reconciliation, and other data needed to process and evidence payments, monitor the business account, and comply with legal obligations.

End customers and payers

Data registered by the business customer or entered by the payer at checkout, such as name, email, phone, document, address, charge history, and payment events, for identification, customer management, charges, payment, receipts, and support.

Compliance, risk, and disputes

KYB/KYC data, corporate documents, representatives, dispute evidence, refunds, payment reversals, antifraud signals, and operational reviews to verify identity, prevent illicit activity, respond to disputes, and protect the payment ecosystem.

Site usage and support

IP, technical identifiers, essential cookies, language, browser, device, accessed pages, support messages, and feedback to maintain service, diagnose incidents, improve experience, and measure availability.

4

Processing purposes

Raims processes personal data only when there is a legitimate purpose and applicable legal basis. Main purposes include:

  • Perform contracts, preliminary procedures, and platform provision, including registration, authentication, charges, statements, withdrawals, authorized integrations, and support.
  • Provide charges, payment links, reconciliation, receipts, transactional communications, integrations, and other contracted features.
  • Process support, onboarding, request responses, account notices, security alerts, technical messages, and commercial relationships.
  • Protect data subjects, business customers, and the platform against fraud, abuse, unauthorized access, disputes, security incidents, unavailability, and suspicious operations.
  • Comply with legal, regulatory, tax, accounting, financial, antifraud, AML/CFT, dispute investigation, and competent authority response obligations.
  • Improve stability, performance, availability, usability, security, support materials, and system reliability.
  • Perform marketing, institutional communications, or use non-essential cookies when there is consent or another applicable legal basis.
  • Exercise rights in administrative, judicial, arbitral, or extrajudicial proceedings.
5

Legal bases

Legal bases may include contract performance, preliminary contract procedures, compliance with legal or regulatory obligations, regular exercise of rights, credit protection, fraud prevention, data subject security in identification and authentication processes, legitimate interest, consent, and other hypotheses set out in the LGPD according to context.

Presenting this Policy and acknowledging it at checkout do not constitute generic consent to all processing. When a purpose depends on consent, it will be requested specifically and may be withdrawn through available channels, subject to legal retention requirements and processing based on other legal bases.

6

Cookies, identifiers, and technical records

Raims may use cookies, local storage, session identifiers, server records, and similar technologies to maintain login, security, language preference, abuse protection, routing, availability measurement, and site improvement. Strictly necessary cookies may be used without an opt-out because they support authentication, security, session, payment flow integrity, and essential operation. For non-required cookies, when used, Raims may present a consent card or banner so the user can accept, refuse, or adjust preferences.

Technical logs may contain IP, time, browser, accessed route, request identifiers, response status, failures, security events, and operational metadata. These records help prevent incidents, fix errors, and maintain platform reliability.

7

Data sharing

Raims may share personal data proportionally, according to operational need, contract, legal obligation, security, defense of rights, and informed purpose.

Raims does not sell personal data. Sharing occurs to operate the platform, comply with obligations, protect rights, execute transactions, prevent fraud, respond to requests, or meet purposes described in this Policy.

When necessary to provide services, comply with legal and regulatory obligations, prevent fraud, support AML/CFT controls, process or settle payments, Raims may share data with financial institutions, payment institutions, processing partners, operational partners, infrastructure providers, and competent authorities. Additional information about partners involved in a specific processing activity may be requested through Raims' contact channel, subject to legal, contractual, security, and trade secret limits.

  • With the business customer identified as the supplier, its authorized users, and account administrators when data relates to the purchase, charge, payment, receipt, support, or contractual obligation.
  • With technology infrastructure, hosting, communication, support, security, antifraud, analytics, storage, backup, and service providers.
  • With financial and payment institutions, processing partners, operational partners, reconciliation partners, and payment methods when necessary to execute the contracted operation.
  • With identity verification, compliance, KYB/KYC, fraud prevention, dispute, refund, reversal, and credit protection providers.
  • With public authorities, regulators, courts, auditors, legal, accounting, or technical advisors when necessary due to legal obligation, valid order, or defense of rights.
  • With third parties involved in corporate reorganization, financing, audit, asset sale, or similar transaction, subject to confidentiality and continued protection duties.
8

International transfers

Raims may process or store data in infrastructure and with providers located in Brazil or abroad, including global cloud providers. When an international transfer of personal data occurs, Raims will adopt mechanisms and safeguards compatible with the LGPD and ANPD regulations, including, when applicable, the standard contractual clauses provided for in Resolution CD/ANPD No. 19/2024, recognized equivalent clauses, approved specific clauses, binding corporate rules, adequacy decisions, or other mechanisms permitted by law. The chosen mechanism will observe applicable contracts, business customer instructions, and practices proportional to the processing risk.

9

Information security

Raims adopts technical and administrative measures to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or improper processing. These measures may involve access control, permission segregation, authentication, logs, encryption when applicable, monitoring, backups, incident response, and secure development practices.

No system is absolutely immune to risk. Business customers and their users must also protect credentials, devices, emails, authentication factors, authorized integrations, and permissions.

10

Retention and deletion

Personal data is kept for as long as necessary to fulfill the purposes described in this Policy, perform contracts, respond to requests, comply with legal, tax, accounting, and regulatory obligations, prevent fraud, comply with AML/CFT controls, resolve disputes, exercise rights, and maintain security and audit evidence.

  • When the purpose ends and there is no obligation or legal basis for retention, data may be deleted, anonymized, or blocked.
  • Financial, transactional, accounting, antifraud, audit, compliance, and AML/CFT data may have longer retention periods due to legal, regulatory, or contractual obligations, regulated partner requirements, or the defense of rights.
  • When deletion, anonymization, or blocking is requested and a retention obligation applies, Raims may keep only the minimum data necessary under restricted access, for a limited purpose, and without incompatible reuse.
  • Business customers may have their own export, correction, retention, or deletion controls according to contract and available features.
11

Data subject rights

Under the LGPD, data subjects may request confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, review of automated decisions when applicable, consent revocation, and opposition to processing carried out in violation of the law. Responses will observe legal retention grounds, regulatory obligations, fraud prevention, AML/CFT, security, and the defense of rights.

Requests may be sent to dpo@raims.com and will be reviewed for legitimacy, the data subject's identity, Raims' role in the processing, and the applicable legal basis. When Raims acts as controller for its own purposes, it will act immediately whenever possible; complete statements confirming the existence of processing or providing access will be supplied within 15 (fifteen) days from receipt of a valid request and validation of the data subject's identity. Responses will observe restricted-retention grounds arising from legal or regulatory obligations, fraud prevention, AML/CFT, security, and the defense of rights. When Raims acts as processor on behalf of a business customer, the request may need to be forwarded to the respective controller or handled according to contractual instructions.

12

Automated decisions and data subject rights

In security, fraud prevention, compliance, AML/CFT, and operational review controls, Raims may use automated processing, analytical models, and artificial intelligence technologies to generate alerts, classify risk signals, prioritize review, and protect the platform.

Raims seeks not to base relevant measures only on isolated signals when the context requires proportional analysis, and may route atypical situations to human review by authorized teams without disclosing sensitive parameters that could facilitate fraud or evasion.

When an automated decision produces relevant effects and an applicable right exists, the data subject may request information and review through the contact channel. The response will observe the LGPD, applicable contracts, trade secrets, platform security, and limits needed to avoid exposing fraud prevention or evasion controls.

13

Children and adolescents data

The Raims platform is directed to companies and professional users. Raims does not intentionally seek to collect data from children or adolescents for direct platform registration. If this type of data is processed by business customers or in a transactional context, processing must observe applicable law, controller instructions, and the best interest of the data subject.

14

Privacy and security incidents

In the event of a security incident involving personal data, Raims will assess the nature, data category, affected data subjects, mitigation measures, risks, and legal or contractual obligations. When Raims acts as controller and the incident may cause relevant risk or damage, it will make the applicable communications to the ANPD and data subjects according to the LGPD, ANPD rules, and current contracts. When acting as processor on behalf of a business customer, Raims will inform the controller without undue delay, provide the information needed for the controller to assess and make the applicable communications, and follow contractual and legal instructions.

15

Changes to this Policy and contact

This Policy may be updated to reflect legal, regulatory, contractual, operational, technical, or product changes. When a relevant change affects processing purposes, the form or duration of processing, controller identification, sharing, legal bases, or data subject rights, Raims will inform the applicable data subjects with specific prominence through registered email, a dashboard notice, a notice in this Policy, or another reasonable channel when it has appropriate contact details or a legal obligation applies. When processing depends on consent, the data subject may withdraw consent if they disagree with the change. Merely editorial changes, corrections, or clarifications without a material change may be made by updating the version and date without individual notice. Urgent changes required by law, an authority, or security may take effect immediately, with communication as soon as reasonably possible.

Questions, requests, or privacy communications may be sent to dpo@raims.com.