ING Privacy Policy

Privacy Policy

ING INDÚSTRIA NACIONAL DE GUINDASTES LTDA. (CNPJ nº 11.897.872/0001-10) is characterized as a manufacturer of machines, equipment, and devices for cargo transport and lifting, as well as parts and accessories, and is established at Rodovia RSC-453, KM 79, Pavilion 02, number 600, Pioneiro, Caxias do Sul - RS - ZIP Code – 95042190 and here is referred to as ING.

WHAT IS THE DATA PROTECTION AND PRIVACY POLICY

Through the Personal Data Protection and Privacy Policy (the “Policy”) we will clarify how we handle your personal data, the purposes of the processing, as well as for how long, the security criteria observed, and your rights as a data subject and how these can be exercised, all in accordance with legal provisions regarding the protection of personal data, especially Law 13.709/18 (General Data Protection Law | LGPD).

 

DEFINITIONS

Some definitions are important to obtain a better understanding of this Policy.

GENERAL DATA PROTECTION LAW, or LGPD: Law No. 13.709, of August 14, 2018, which regulates the processing of personal data, including in digital media, by a natural person or a legal entity under public or private law, with the purpose of protecting the fundamental rights of freedom and privacy and the free development of the natural person's personality.

CONTROLLER: a natural or legal person, under public or private law, responsible for decisions regarding the processing of personal data.

PROCESSOR: a natural or legal person, under public or private law, who processes personal data on behalf of the controller.

PERSONAL DATA: Any information related to an identified (e.g., name, CPF, address, phone number) or identifiable natural person (e.g., data cross-referencing).

SENSITIVE PERSONAL DATA: According to Article 5, II, of the LGPD, these are data that reveal intimate aspects of the data subject and require enhanced protection, such as personal data on racial or ethnic origin, religious belief, political opinion, union membership or affiliation to religious, philosophical or political organizations, data concerning health or sexual life, genetic or biometric data, when linked to a natural person.

REGISTRATION PERSONAL DATA: Information that directly identifies or describes a natural person, including identification, contact, document data, and others.

FINANCIAL PERSONAL DATA: Information linked to an individual's economic condition, referring to their accounts, operations, and financial profile, such as: income, credit score, bank account number, agency, credit card number, among others.

BEHAVIORAL PERSONAL DATA: Information about habits, preferences, behaviors, and usage patterns of individuals, related to profiling or behavior tracking, such as: browsing and usage habits (cookies, page history), consumption and purchase profile, performance, and others.

PROCESSING: Any operation performed with personal data, including but not limited to the following activities: collection, storage, consultation, use, sharing, transmission, classification, reproduction, deletion, and evaluation.

DATA SUBJECT: A natural person to whom personal data refers.

COOKIES: Small files that websites store on a computer through the browser. The purpose of storing these files is to identify the visitor, thereby customizing the page according to their preferences.

 

HOW WE PROCESS PERSONAL DATA

ING processes personal data for specific, determined, and legitimate purposes necessary for the execution of its business activities, such as those listed in this policy, respecting the principles of the LGPD. The processing of personal data will generally observe the information listed below, and the availability of personal data as well as confirmation of its processing can be requested through the official channels provided in this Policy.

Access data may include information such as registration data for contacts, as well as data like the IP address of the Data Subject's device (for example, IP address), browser type, browser version, while behavioral data refers to those such as visited pages, time and date of the visit, time spent on these pages, as well as professional history data when provided for recruitment and selection purposes.

 

USE OF COOKIES AND PLUG-INS

ING's institutional website uses necessary, performance, and targeting cookies to respectively: store the access record consisting of IP, date and time; evaluate usage and identify users when accessing the site; and collect preference information to link to advertisements, for example. Necessary cookies will be employed regardless of consent, and at any time, it is possible to activate in your browser or mobile device settings, mechanisms to notify you when cookies are triggered or to prevent them from being triggered. Your mobile device or browser has functions to remove them at any time. Performance cookies will depend on your consent to be activated.

Necessary cookies are intended to enable navigation on the Platform and ensure that its functionalities are effectively available to the User, such as: (i) enabling essential features; (ii) displaying content properly according to screen size, connection speed, and browser type; (iii) remembering your login; and (iv) understanding your browsing behavior and how the platform is being used.

You can better understand the context, use, and purpose of the necessary cookies used through the list below:

Cookie name: PHPSESSID

Maximum duration: During session

Purpose: Track and analyze visitor behavior, allowing understanding of how users interact with the software and website when applicable.

 

Cookie name: _ga

Maximum duration: 1 year and 1 month

Purpose: This cookie name is associated with Google Universal Analytics, which represents a major update to Google's most widely used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in every page request in a site and used to calculate visitor, session, and campaign data for the site's analytics reports.

 

Targeting cookies collect data about user behavior and preferences online (pages visited, clicks, browsing history), in order to create profiles or segments to display personalized ads:

Cookie name: _gcl_au

Maximum duration: No expiration

Purpose: Used by Google AdSense to test ad effectiveness on sites that use its services

Cookie name: _fbp

Maximum duration: 2 months and 4 weeks

Purpose: Used by Meta to deliver a range of advertising products, such as real-time bidding from third-party advertisers

 

Cookie management can be done through your browser, whether Chrome or another. For that, we recommend reading the guidelines provided in the cookie banner.

Any third-party website links possibly provided on the Website do not constitute endorsement or sponsorship by ING. Such websites are subject to their own terms of use and privacy policies and are not under the responsibility of the Website. It is also recommended that you read those terms and policies.

 

SHARING AND LIFECYCLE OF PERSONAL DATA

Regarding the sharing of personal data, it is important to emphasize that ING will not commercialize it with third parties.

Your personal data will only be shared with third parties when strictly necessary to meet the stated purposes, considering contractual and legal requirements. In this process, there is strict attention to the principles of necessity and purpose, and any sharing will undergo prior compliance verification and observe the Data Subject's expectations.

Your personal data will have a lifecycle in processing by ING, which is directly linked to current legislation and contract compliance, always observing the applicable legal bases in each case. That is, personal data will remain in processing for as long as necessary to fulfill the purpose for which it was collected, as well as to fulfill legal, regulatory, and even contractual obligations.

 

INTERNATIONAL DATA TRANSFERS

ING may occasionally transfer your personal data internationally if it chooses to hire business partners offering cloud data storage services on servers located outside Brazil.

If international transfers occur, ING guarantees that it will only hire service providers with the technical, organizational, and administrative structure to ensure the security and integrity of your personal data and that are compliant with the principles and obligations set forth in the LGPD and other applicable laws.

 

DATA SUBJECT RIGHTS

You have always been the holder of your personal data and always had rights regarding it. This is not a novelty introduced by the LGPD. However, the LGPD, through Article 18, expanded your rights, which can be exercised at any time and are described below:

  • confirmation of data processing existence;
  • access to data;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion of unnecessary, excessive or non-compliant data with LGPD provisions;
  • data portability to another service or product provider, upon express request, in accordance with national authority regulations, subject to commercial and industrial secrets;
  • deletion of personal data processed with the data subject’s consent, except in cases provided for in the LGPD;
  • information on public and private entities with which the controller has shared data;
  • information about the possibility of not providing consent and the consequences of refusal;
  • withdrawal of consent.

To exercise these rights, ING provides a channel for the Data Subject to clarify any doubts about how their personal data is processed and demand their inherent rights. If necessary, contact us at dpo.ingguindastes@zna.adv.br

 

SECURITY OF YOUR PERSONAL DATA

As long as your personal data is being processed by ING, we will be responsible for safeguarding it, observing the already stated purposes. All your personal data is protected by information security technologies and procedures in compliance with legislation and technical regulations, including but not limited to backup security, user authentication and authorization factors, and adherence to the "need to know" principle to access your personal data, which ensures only necessary and authorized persons will access your personal data.

Although ING's efforts to guarantee the security of personal data are not restrained, and despite adopting high standards of information security, ING acknowledges that no system is absolutely invulnerable. Aware of this, ING follows the guidelines published by the National Data Protection Authority for responding to personal data incidents, and you will be immediately informed if, eventually, any incident involving your personal data occurs and there are risks to civil liberties and fundamental rights.

 

CONTACT

9.1. In case of any doubt, concern or request related to this Policy, please contact ING, through the Data Protection Officer (DPO), Zulmar Neves Advocacia, represented by Gustavo Tonet Fagundes, via the provided support channels.

Email: dpo.ingguindastes@zna.adv.br
Address: Rodovia RSC-453, KM 79, Pavilion 02, number 600, Pioneiro, Caxias do Sul - RS - ZIP Code – 95042190
Caxias do Sul, Rio Grande do Sul


June 18, 2025.

Version 1.0

 

Garantia