PRIVACY AND PERSONAL DATA PROTECTION POLICY

INTRODUCTION

MK BR is the licensed company of the AIWA brand for the commercialization of products and services in the national territory. This means that MK BR is responsible for officially operating, managing, and representing the AIWA brand in Brazil, including its commercial activities, service channels, and digital platforms.

This Privacy Policy aims to transparently inform how MK BR S/A (a member company of the "MK Group") collects, uses, stores, and protects the personal data of users who interact with our products, services, websites, and applications linked to the AIWA brand in Brazil. This Policy covers any and all Personal Data Processing carried out by the MK Group, regardless of the medium (physical or electronic), the audience (external or internal), and the purpose of the Processing performed.

This "Privacy and Personal Data Protection Policy" is inseparably integrated with other MK Group instruments and must be fully understood by all Users of our Platforms, all our employees and business partners, and especially by all Personal Data Subjects who, in some way, have provided us with their Personal Data due to any form of relationship with us.

 

APPLICABLE STANDARDS

By using our services, you acknowledge and agree to the practices described in this policy, which follow the guidelines of the General Data Protection Law (Law No. 13.709/2018 – LGPD) and other standards applicable to personal data protection.

In cases of International Transfer of Personal Data, the requirements established by Law No. 13.709/2018 (LGPD) and Resolution CD/ANPD No. 15/2024 will be observed, ensuring that the transfer occurs only to countries or international organizations that provide an adequate level of personal data protection or through the use of legitimate instruments recognized by the ANPD. Global Corporate Rules (Binding Corporate Rules), standard contractual clauses, seals, certificates, or codes of conduct approved by the ANPD will also be observed, as applicable.

 

 

DEFINITIONS

For the purposes of this Privacy and Personal Data Protection Policy, the terms defined below, when written in capital letters, whether in the singular or plural, shall have the following meanings:

  • Processing Agents: The Controller and the Processor.
  • Anonymization: The use of reasonable technical means available at the time of Processing, through which data loses the possibility of association, direct or indirect, with an individual.
  • National Data Protection Authority (ANPD): The Brazilian federal public administration body responsible for overseeing, implementing, and monitoring compliance with the LGPD throughout the national territory.
  • Database: A structured set of Personal Data, established in one or several locations, in electronic or physical format.
  • Blocking: The temporary suspension of any processing operation, through the storage of Personal Data or the Database.
  • Consent: A free, informed, and unequivocal manifestation by which the Subject agrees to the Processing of their Personal Data for a determined purpose.
  • Controller: The natural or legal person, of public or private law, who is responsible for decisions regarding the Processing of Personal Data.
  • Anonymized Data: Data relating to a Subject who cannot be identified, considering the use of reasonable technical means available at the time of Processing.
  • Personal Data: Information related to an identified or identifiable natural person.
  • Sensitive Personal Data: Personal data regarding racial or ethnic origin, religious conviction, political opinion, affiliation with a union or a religious, philosophical, or political organization ; data concerning health or sexual life, genetic or biometric data, when linked to a natural person.
  • Deletion: The exclusion of data or a set of data stored in a Database, regardless of the procedure used.
  • Officer (DPO): The person appointed by the Controller and/or Processor to act as a communication channel between the Controller, the Data Subjects, and the ANPD, also known as the Data Protection Officer (DPO).
  • General Data Protection Law (LGPD): Law No. 13.709 of August 14, 2018, which provides for the Processing of Personal Data, including in digital media, by a natural person or by a legal person of public or private law, with the aim of protecting the fundamental rights of freedom and privacy and the free development of the personality of the natural person.
  • Processor: The natural or legal person, of public or private law, who performs the Processing of Personal Data on behalf of the Controller.
  • Research Body: An organ or entity of direct or indirect public administration or a non-profit legal person of private law, legally constituted under Brazilian laws, with its headquarters and jurisdiction in the Country, which includes basic or applied research of a historical, scientific, technological, or statistical nature in its institutional mission or in its social or statutory objective.
  • Subject: The natural person to whom the Personal Data undergoing Processing refers.
  • International Data Transfer: The transfer of Personal Data to a foreign country or an international organization of which the country is a member.
  • Processing: Any operation performed with Personal Data, such as those referring to collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation or control of information, modification, communication, transfer, dissemination, or extraction.
  • Personal Data Protection Impact Assessment (DPIA): A document from the Controller that contains a description of the Personal Data Processing processes that may generate risks to civil liberties and fundamental rights, as well as measures, safeguards, and risk mitigation mechanisms.
  • Shared Use of Data: Communication, dissemination, international transfer, interconnection of Personal Data, or shared treatment of Personal Databases by public bodies and entities in the fulfillment of their legal competencies, or between these and private entities, reciprocally, with specific authorization, for one or more modalities of treatment permitted by these public entities, or between private entities.

 

PRINCIPLES OF PERSONAL DATA PROCESSING

The Processing of Personal Data carried out on behalf of the MK Group must observe the following principles, always in compliance with respect for the privacy, dignity, and rights of the Subjects, as well as respect for good faith in the relationship between the Subject and the MK Group:

  1. Purpose: Processing must occur only for legitimate, specific, explicit purposes informed to the Subject.
  2. Suitability: Processing must be compatible with the purposes informed to the Subject.
  3. Necessity: Processing must be carried out in a proportional and relevant manner, treating only the data necessary for the fulfillment of the legitimate purpose determined by the MK Group.
  4. Free Access: The Subject may, in a facilitated and free manner, consult the MK Group regarding the form and duration of the Processing of their Personal Data.
  5. Data Quality: Personal Data processed by the MK Group must always be updated, clear, and accurate.
  6. Transparency: The Subject must have easy access to clear and precise information about the processing of their Personal Data by the MK Group.
  7. Security: The MK Group must take all technical and administrative measures capable of protecting Personal Data from unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination.
  8. Prevention: The MK Group must adopt measures to prevent the occurrence of damage due to the Processing of Personal Data.
  9. Non-discrimination: The Processing of Personal Data for unlawful and/or abusive discriminatory purposes is expressly prohibited.
  10. Accountability and Reporting: The MK Group must demonstrate that it adopts effective measures capable of proving compliance and adherence to personal data protection standards.

 

SOURCES

The Personal Data we process comes from various sources, such as:

  • Company Platforms: Websites, mini-sites, or applications aimed at employees, collaborators, business partners, and customers, with their own domains and URLs, as well as those aimed at third parties in general.
  • Electronic Messages: E-mails, text messages, forms, among others, representing all electronic communications established between the Data Subject and the Company.
  • Offline Registration Forms: Printed or digital forms or analogous ways in which Personal Data is collected, such as correspondence via Mail, registrations of employees, collaborators, customers, and business partners, lists of claimants in administrative and judicial processes, and any other lists, forms, or registrations prepared in the legitimate interest of the Company.
  • Automated Interactions: Personal Data collected through MK Group advertisements on third-party sites or social networks, data obtained through market research, browsing and/or analytical data collected through automated forms, such as cookies.
  • Third-party Controllers: Personal Data collected, shared, or transferred due to mergers, acquisitions, incorporations, spin-offs, joint ventures, or due to other corporate institutes.
  • Contracts or Pre-contractual Forms: Personal Data of individuals who appear or may appear in contracts of various types signed or to be signed with the MK Group.

 

TYPES OF PERSONAL DATA AND LEGAL BASES

The Processing of Personal Data shall occur only if there are legitimate, specific, explicit purposes informed to the Subject, and only Personal Data strictly necessary for the fulfillment of the purposes informed by the MK Group should be processed.

The LGPD provides for the authorizing hypotheses ("legal bases") for the Processing of Personal Data; they are:

  • With the consent of the Subject;
  • For compliance with a legal or regulatory obligation by the Data Controller;
  • By the public administration, for the Processing and shared use of data necessary for the execution of public policies;
  • For the performance of studies by research bodies, ensuring, whenever possible, the Anonymization of Personal Data;
  • For the execution of a contract or preliminary procedures related to contracts;
  • For the regular exercise of rights in judicial, administrative, or arbitration proceedings;
  • For the protection of life and physical safety of the subject or a third party;
  • For health protection in procedures performed by health professionals, health services, or sanitary authorities;
  • To meet the legitimate interests of the controller or third parties, observing the fundamental rights and freedoms of the Subject;
  • For credit protection.

These legal bases will be classified according to the purpose of the Personal Data Processing performed by the MK Group.

 

DATA COLLECTED BY THE AIWA APP

The AIWA application may collect and process the following categories of common and personal data, depending on the functionalities used by the user:

  1. Device Identification Data: Model, operating system, and unique identifiers (e.g., Device ID).
  2. App Usage Data: Audio settings, temperature settings, user preferences, and interactions with app features.
  3. Connection Data: Bluetooth and/or Wi-Fi connection information with compatible devices.
  4. Technical and Diagnostic Data: Usage logs and app performance data.
  5. Device Permissions: Bluetooth (for connection), Location, and Wi-Fi.

The collected data is limited to the minimum necessary for the proper functioning of the application.

 

PURPOSE OF DATA PROCESSING IN THE APP

Personal data collected by the AIWA app is used to:

  • Allow connection and communication with AIWA devices;
  • Personalize audio and/or temperature settings and user preferences;
  • Ensure the proper and safe operation of the app;
  • Improve user experience and fix technical failures;
  • Comply with legal and regulatory obligations.

 

CONSENT

The consent of the Personal Data Subject is one of the authorizing hypotheses for the processing of Personal Data, whether sensitive or not, by the MK Group. When required, consent must be free, informed, and unequivocal, and the Subject must agree to the Processing for a legitimate and determined purpose, with the right to revoke it at any time.

 

DISCLOSURE AND SHARING OF PERSONAL DATA

Personal Data may be disclosed or shared whenever necessary to comply with legal or regulatory obligations, for the regular exercise of rights regarding contracts or judicial and administrative processes in which the MK Group is a party or interested, or to meet its own legitimate interests or those of third parties (e.g., credit protection or marketing purposes). Data may also be shared in the event of a judicial or administrative decision by a competent authority.

Hypotheses for disclosure or sharing include:

  • Disclosure by the Company: To comply with legal obligations (e.g., reports, minutes, official gazette publications).
  • Collaborators and Business Partners: To fulfill duties or contracts in a colligated form.
  • Service Providers: For data processing, operating platforms, market research, marketing, support services, analysis, auditing, legal, accounting, and consulting. Data should preferably be anonymized.
  • Judicial or Administrative Orders: When ordered by a competent authority.
  • Corporate Law Institutes: In cases of judicial recovery, bankruptcy, mergers, acquisitions, joint ventures, etc.

The MK Group is responsible for qualifying its providers to follow these guidelines and for training its employees, but it is not responsible for the processing of data controlled by third parties.

 

DATA RETENTION PERIOD

Personal data collected by the AIWA app will be stored for the following periods:

  • Usage data and technical logs: Stored for up to 30 days.
  • User account data: Kept while the account is active.
  • Legal obligations: Stored for the period required by applicable law.

After the retention period, data will be deleted or anonymized.

 

SENSITIVE PERSONAL DATA

Processing of Sensitive Personal Data will only occur under specific hypotheses, such as express consent, compliance with laws, public policies, studies by research bodies, regular exercise of rights, protection of life, health protection, or fraud prevention.

The AIWA app DOES NOT collect, store, or process sensitive personal data related to the health of users, nor does it monitor health conditions.

 

DATA OF MINORS OR LEGALLY INCAPACITATED PERSONS

The AIWA app is not directed at children or adolescents. If the collection of such data is necessary, it will occur exceptionally, always in the best interest of the minor, and requiring specific and highlighted consent from a parent or legal guardian. Consent is waived if the collection is strictly necessary to contact parents or guardians, in which case the data cannot be stored.

 

AUTOMATED DATA COLLECTION: COOKIES

Cookies are small text files stored on your device that allow access to information about your navigation. We may also use web beacons/pixel tags. These technologies are used to improve navigability, personalize experience, and target advertising.

Cookies can be:

  • Primary: From our own Platforms.
  • Third-party: From other platforms (e.g., social media plugins).
  • Session: Temporary.
  • Persistent: Remain for a specific period.

The MK Group uses cookies considered strictly necessary for navigability. While you can disable cookies in your browser, this may impair the functioning of the Platforms. The AIWA app may use technical identifiers for operation but does not use them for advertising tracking without user consent.

 

RIGHTS OF THE SUBJECT

Under the LGPD, you have the following rights:

  • Confirmation of the existence of processing;
  • Access to your Personal Data;
  • Correction of incomplete, outdated, or inaccurate data;
  • Blocking or deletion of unnecessary or unlawful data;
  • Data portability;
  • Revocation of consent.

Requests for deletion or blocking may be denied if the data is necessary for legal compliance or the exercise of rights.

Contact for Rights:

  • Officer (DPO): Benício Advogados, attn: Sandra Fátima de Sales Oliveira
  • Email: privacidade@aiwa.com.br

 

RESPONSIBILITIES

The MK Group is responsible for damages caused by data processing or lack of security measures.

Your Responsibilities:

  • Maintaining the confidentiality of access data.
  • Providing true and accurate information.
  • Abstaining from illegal acts, violating intellectual property, or transmitting offensive content.
  • Not using automated systems (bots) for mass operations or cyberattacks.

The Platforms and their content are the exclusive property of the MK Group. Unauthorized use is prohibited and subject to legal action.

 

FINAL PROVISIONS

This Policy may be revised at any time without prior notice. Cases of violation or suspicion should be reported to:

  • Officer: Gustavo Tadeu Lopes Miranda
  • Email: privacidade@emodial.com

This Policy is governed by the laws of the Federative Republic of Brazil. The Court of the District of Conceição do Jacuípe/BA is elected to resolve disputes.

Effective Date: March 30, 2026