PRONTO LIVE MARKETING LTDA
Public Information Security Policy for the Website
- Classification
- Public
- Version
- 01
- Updated on
- July 31, 2026
1. Purpose
PRONTO LIVE MARKETING LTDA, headquartered in São Paulo/SP and operating nationally and internationally in the Live Marketing and Brand Experience segment, hereby establishes this Information Security Policy for the purpose of defining guidelines for the protection, processing and appropriate use of corporate information, seeking to contribute to business continuity, the trust of clients, partners, suppliers and employees, as well as compliance with the applicable legal and regulatory obligations.
2. Information classification
This Policy is classified as public and may be made available on Pronto's institutional website for consultation and download by clients, partners, suppliers, employees, candidates and other interested parties.
3. Information Security principles
- Confidentiality: to promote measures ensuring that information is accessed only by duly authorized individuals and for legitimate purposes related to Pronto's activities.
- Integrity: to adopt measures intended to keep information complete, accurate and up to date, and protected against improper, accidental or unauthorized alteration, deletion, loss or modification.
- Availability: to seek to ensure that information is available to authorized users whenever necessary for the performance of corporate activities and the delivery of services.
- Accountability: to guide employees, service providers, partners and third parties on the appropriate use of the resources, systems, documents and information under their responsibility.
4. Organizational commitment
Pronto recognizes information as a strategic asset that is essential to conducting its business, executing its projects and maintaining the trust of clients, suppliers, partners, employees and other interested parties.
All employees, service providers, partners and other third parties who have access to Pronto's information must handle it in a responsible, ethical, secure and professional manner, in compliance with this Policy, the applicable agreements, internal regulations and information security best practices.
5. General guidelines
- Use information, documents, systems, devices, access credentials and technological resources solely for professional and authorized purposes.
- Avoid the improper sharing of confidential, strategic, commercial, financial or legal information, or information relating to clients, suppliers, employees or third parties.
- Safeguard passwords, credentials, access rights and permissions for personal use, not sharing them with third parties.
- Store and transmit corporate information through channels, tools and environments authorized by Pronto, except in exceptional situations that have been duly authorized.
- Exercise special care with client information, briefings, proposals, agreements, personal data, intellectual property, strategic materials and project documents.
- Immediately report, or as soon as possible, any incident, suspected leak, loss, improper access, fraud, unauthorized use or weakness identified in systems, documents or processes.
6. Legal and regulatory compliance
Pronto observes and seeks to maintain compliance with the legislation applicable to the protection of information, personal data, intellectual property and commercial relations, including but not limited to:
- the Brazilian General Data Protection Law – Law No. 13,709/2018 (LGPD);
- the Brazilian Internet Civil Framework – Law No. 12,965/2014, where applicable;
- the Brazilian Copyright Law – Law No. 9,610/1998;
- contractual obligations undertaken with clients, suppliers, partners and employees;
- other standards, regulations and best practices relating to information security, privacy and data protection.
7. Responsibilities
All employees, service providers, partners, suppliers and third parties with access to Pronto's information are responsible for:
- protecting confidential information against unauthorized disclosure, access, copying, alteration or deletion;
- using technological resources in an appropriate, ethical and secure manner;
- preserving the integrity of the information under their responsibility;
- complying with agreements, confidentiality clauses, internal policies and corporate guidelines;
- immediately reporting, or as soon as possible, any incident or suspected information security breach;
- cooperating with continuous improvement initiatives, risk prevention and the strengthening of the security culture.
8. Management System and continuous improvement
Pronto seeks to continuously improve its information security processes, controls and practices, with a view to promoting greater transparency, organization, commitment and accountability in its relations with clients, suppliers, partners, employees and other interested parties.
This Policy may be reviewed periodically or whenever there are relevant changes in processes, technologies, legislation, organizational structure or client and stakeholder requirements.
9. Incident reporting
Any incident or suspected incident relating to information security must be reported through the internal channels defined by Pronto for assessment, recording, handling and adoption of the appropriate measures.
Where an incident involves personal data, its analysis will observe the provisions of the applicable legislation, in particular the Brazilian General Data Protection Law (LGPD), as well as the guidelines set out in Pronto's Personal Data Privacy and Protection Policy, including with respect to the need to notify the competent authorities and the data subjects where required by law.
Version history
| Version | Date | Description |
|---|---|---|
| 00 | June 11, 2026 | Initial issue for legal review and publication on the website. |
| 01 | July 31, 2026 | Legal amendments. |