Skip to content
SM-SCOPO

Monitor Scopo / Legal documents

LGPD and data protection in SM-SCOPO — Monitor Scopo

Guidelines for processing personal data in SM-SCOPO, data subject rights and responsibilities when using the platform, under the LGPD and applicable ANPD regulations.

Version 1.0Effective from:

LGPD in SM-SCOPO

SM-SCOPO, presented in this application as Monitor Scopo, is a platform provided by Neoplace Tecnologias Ltda. This document sets out data protection guidelines for using the service and supplements the Terms of Service and Privacy Policy.

Personal data processing must comply with Law No. 13,709/2018 (Brazil’s General Personal Data Protection Law — LGPD), as amended, and applicable ANPD regulations. Service agreements may detail each party’s operations and obligations, respecting statutory rights.

Controller, processor and data protection officer

The controller determines the purposes and essential elements of processing. The processor processes data on the controller’s behalf and must follow lawful instructions. Each party’s role depends on the operation.

Neoplace acts as controller for processing it defines for Monitor Scopo registration, contractual relationships, support and security. For data entered by an organization that determines its processing, that organization may be controller and Neoplace processor, according to the service and agreement.

The data protection officer is the communication channel for data protection matters. This role does not transfer the processing agents’ legal liability to the officer. Neoplace’s contact channels appear in the requests section and Privacy Policy.

Personal data, sensitive data and public sources

Personal data is information relating to an identified or identifiable person. Monitor Scopo may process registration data, contacts, access logs, user-entered content, public-source information and authorized integration data, depending on the feature.

Political opinions, membership of political organizations, health, biometrics and other LGPD categories may constitute sensitive personal data. Processing requires a specific ground under Article 11; legitimate interests are not a legal basis for these categories.

Public availability does not authorize unrestricted reuse. Purpose, necessity, disclosure context and data subject rights must be assessed. Aggregating data or replacing names with identifiers does not guarantee anonymization if people can still be identified by reasonable means. The service is not directed at children; situations involving children and adolescents require attention to their best interests and applicable rules.

Principles and legal bases

Operations must have a defined purpose, be compatible with the stated context and be limited to necessary data. Transparency, data quality, free access, security, prevention, non-discrimination and accountability must guide platform use.

The legal basis must be established per operation, without blanket authorization for the entire platform. Applicable grounds may include contractual performance or procedures requested by the data subject, legal or regulatory obligations, regular exercise of rights, consent or legitimate interests, among those established by law. Where applicable, legitimate interests require assessing necessity, data subject expectations, impact on rights and safeguards.

Sensitive data follows the LGPD’s specific grounds. The responsible organization must document decisions supporting the processing under its control.

Consent, login and integrations

Where processing relies on consent, it must be freely given, informed, unambiguous and tied to specific purposes, with an accessible withdrawal procedure. Browsing, reading this document or accepting contractual conditions does not mean consenting indiscriminately to all processing.

TikTok, Google or Facebook login uses the data and permissions described in the Privacy Policy. Authorizing login does not automatically grant access to other provider functions. Additional integrations must respect the requested feature and granted permissions.

Revoking a connection may interrupt its functionality. It is not equivalent to deleting all data already processed by Monitor Scopo: the data subject may request deletion, subject to statutory retention grounds. Login and cookie preferences serve different purposes.

Responsibilities when using the platform

For processing under its control, the organization using SM-SCOPO must:

  • Define purpose and legal basis before entering, importing, querying or sharing personal data.
  • Properly inform data subjects and handle rights requests for which it is responsible.
  • Restrict access to authorized people, keep permissions current and train its team on data use and protection.
  • Assess the legitimacy of sources, data quality and integration usage limits.
  • Avoid excessive data and unjustified sharing, especially in contacts, messages and reports.
  • Observe contractual obligations and inform Neoplace of instructions, incidents or requests requiring its action.

These responsibilities do not remove Neoplace’s own duties as a processing agent.

Data subject rights

Subject to statutory conditions and exceptions, data subjects may request:

  • Confirmation of processing and access to their data.
  • Correction of incomplete, inaccurate or outdated data.
  • Anonymization, blocking or deletion of unnecessary, excessive or unlawfully processed data.
  • Portability under applicable regulations, preserving trade and industrial secrets.
  • Deletion of data processed with consent, subject to statutory retention grounds.
  • Information about sharing with public and private entities.
  • Information about withholding consent and its consequences, and withdrawal of consent.
  • Objection to processing exempt from consent where it breaches the LGPD.
  • Review of decisions based solely on automated processing that affect their interests, and information about criteria and procedures under Article 20.

Data subjects may also petition the ANPD concerning the controller and contact consumer protection bodies where applicable.

How to exercise your rights

Email contato@neoplace.com.br with the subject “LGPD — SM-SCOPO / Monitor Scopo”. The data protection officer’s contact provided by Neoplace is giselle@neoplace.com.br.

Describe the right you wish to exercise and provide sufficient information to locate the account or processing. Do not send passwords or tokens. Proportionate identity or representation verification may be requested to prevent unauthorized access. Exercising rights is free of charge.

If the request concerns data controlled by a client organization, the response must follow the processing roles and responsibilities. Where Neoplace acts as processor, it follows the controller’s lawful instructions and its legal and contractual obligations.

For confirmation and access, Article 19 provides for an immediate simplified response or a complete statement within 15 days of the request. Other requests follow applicable deadlines and conditions. Obstacles or refusals must be justified; the need to retain particular data does not prevent assessment of other rights requested.

Security and incident notification

Processing agents must adopt technical and administrative measures proportionate to risk to protect data against unauthorized access, loss, alteration and improper disclosure. Security duties cover development, operation and termination of processing.

Report suspected improper exposure of Monitor Scopo data to the privacy channel with sufficient context and without expanding the exposure. A processor learning of an incident must inform the controller without undue delay, providing information needed for its response.

The controller must assess significant risk or harm and make legally required notifications. Resolution CD/ANPD No. 15/2024 governs incident notification; as a general rule, the ANPD and data subjects must be notified within three business days of learning that the incident affected personal data, subject to applicable criteria, exceptions and specific rules. Not every technical event is a notifiable incident.

Retention, termination and deletion

Data must be retained for the period necessary for its purpose and applicable obligations. Durations may differ for registration, access logs, contractual documents, organizational content and integration data. No single period applies indiscriminately to all categories.

Once the purpose ends, deletion or another legally permitted outcome must be assessed. The LGPD permits retention on specific grounds, such as legal or regulatory obligations, subject to Article 16.

Account cancellation, provider disconnection and data deletion are distinct operations. The need to preserve particular records must be justified and does not authorize incompatible uses. Return or export of organizational content depends on the contracted service and statutory rights.

Sharing and international transfers

Sharing must relate to a legitimate purpose, have a legal basis and be limited to what is necessary. Supplier and integration selection must consider security, confidentiality and data protection obligations. Monitor Scopo’s sharing categories are described in the Privacy Policy.

International transfers must comply with the grounds in Article 33 of the LGPD and applicable mechanisms and safeguards, such as adequacy decisions or contractual clauses permitted by regulation. Resolution CD/ANPD No. 19/2024 governs this topic and approves standard contractual clauses.

A foreign integration does not remove the need to assess the particular operation or properly inform data subjects about processing.

Analyses, automated decisions and governance

SM-SCOPO indicators, simulations and AI-assisted analyses must be used with regard to purpose, data quality, model limitations and potential effects on people. Results must not be treated as indisputable facts or used for unlawful discrimination.

The responsible team must assess context and results before decisions affecting data subjects. For decisions based solely on automated processing that affect their interests, Article 20 rights and conditions apply.

Processing records, risk assessments, team guidance and access reviews form part of governance duties according to the activity. Impact assessments must be prepared when required and considered for higher-risk processing. Platform use does not exempt controllers from their own obligations.

Legislation, regulations and updates

Official references for these guidelines include:

Regulatory changes and other rules applicable to each operation must be considered, including sectoral and electoral rules where relevant. This page summarizes guidance for SM-SCOPO use; official sources contain the complete provisions. The document version and effective date appear at the beginning of the page.

LGPD and data protection in SM-SCOPO — Monitor Scopo