Monday, April 20, 2026

Global Tel*Link Corporation d/b/a ViaPath Technologies (“ViaPath”) Privacy Statement (the “Privacy Statement”)

 

Privacy Statement

Effective Date: June 30, 2025

  1. Overview and Scope

    Your privacy is important to us. This Global Tel*Link Corporation d/b/a ViaPath Technologies (“ViaPath”) Privacy Statement (the “Privacy Statement”) applies to the personal information that ViaPath or one of our Affiliates collects and explains our information practices and your related choices with regard to such information.

    ViaPath affiliates include, but are not limited to, TouchPay Holdings, LLC d/b/a GTL Financial Services, DSI-ITI, Inc., Innertainment Delivery Systems, LLC d/b/a ViaPath Technologies, Public Communications Services, Inc. d/b/a ViaPath Technologies, Renovo Software, Inc., and Value-Added Communications, Inc. d/b/a ViaPath Technologies (individually “Affiliate” and collectively “Affiliates”). Products and services provided by ViaPath or any Affiliate will be referred to in this Privacy Statement as the “Service” or “Services”. This Privacy Statement is part of, and is governed by our Terms of Use, which is available at https://www.viapath.com/terms-of-use/. For purposes of this Privacy Statement, “we”, “us” or “our” refers to ViaPath and any Affiliate where the Affiliate or its products or services are implicated.

    TouchPay Holdings, LLC d/b/a GTL Financial Services (“TouchPay”), a subsidiary of ViaPath, is the owner and operator of websites www.viapath.com, www.touchpayonline.com, www.connectnetwork.com, www.gettingout.com, and www.tpgovtpay.com (the “Site” or “Sites”).

    It is our policy to use the information we collect about you from the Service in a manner that is consistent with this Privacy Statement. Accordingly, this Privacy Statement advises you about the types of information we collect when you use the Service and how we may use that information.

    Not in scope of Privacy Statement

    This Privacy Statement does not apply to the personal information that we collect about employees, contractors and other personnel related to their working relationship with us, or the personal information that we collect about applicants and candidates for a position with ViaPath. This Privacy Statement does not apply to publicly available information. We may also collect, generate, use and disclose aggregate, anonymous, and other non-identifiable data related to our Services, which is not personal information subject to this Privacy Statement.

  2. Terms of Use

    This Privacy Statement is applicable as of the Effective Date posted above. This Privacy Statement is part of, and is governed by our Terms of Use, which is available at https://www.viapath.com/terms-of-use/. All capitalized terms that are used but not otherwise defined in this Privacy Statement have the definitions assigned to them in the Terms of Use.

  3. Contacting ViaPath

    If you have any questions regarding the Service or your account, or if you would like to cancel your account, please contact our Customer Service team using the information supplied through the “Contact Us” link on our website. If you have any questions about the Privacy Statement or our use of the information we collect from you in connection with the Service, you may contact us by email at privacyrights@viapath.com or by postal mail at c/o ViaPath Technologies, 3120 Fairview Park Drive, Suite 300, Falls Church, VA 22042, Attn: Legal Department.

  4. Correcting/Updating Your Information

    If your name, email address, mailing address, telephone number, or other contact information that you provide to us changes, you may update, correct or omit the relevant information by contacting our Customer Service team through the “Contact Us” link on our website.

  5. Service/Site Age Limits

    Must be over 18

    While our Services are not intended for individuals under the age of eighteen (18) years of age, we do provide certain services to youth who are incarcerated. We understand the unique needs and circumstances of incarcerated youth and aim to support their rehabilitation and education through our Services. With the exception of incarcerated youth or as required by a correctional facility, we do not knowingly solicit or collect information from individuals who are not at least eighteen (18) years old. Not Available for Use by Children We regret that the Service is not available to children under the age of thirteen (13). We will never knowingly collect contact information from children under the age of thirteen (13) without verifiable parental consent. If you are under the age of thirteen (13), please do not provide us with information of any kind whatsoever. If we become aware that a user is under the age of thirteen (13) and has submitted information to the Site without verifiable parental consent, we will remove his or her information from our files. We understand that children may not fully understand all of the provisions of this Privacy Statement or make informed decisions about the choices that are made available to adult users of the Site. We encourage parents and guardians to spend time with their children online and to be familiar with the websites they visit. If you are a parent or legal guardian and think that your child under 13 has given us their personal information you can email us at privacycentral@viapath.com and request this information be deleted. Please mark your request “Children's Privacy Request.”
  6. Categories of Personal Information We Collect

    Internet, Usage, and Activity Information

    When you visit or use our Site we send one or more “cookies” or “web beacons” to your computer or other device. A cookie is a small file containing a string of characters that is sent to your computer or other device when you visit a website. When you visit the website again, the cookie allows that site to recognize your browser. We use cookies to improve the quality of our service, including for storing user preferences. By clicking the “Accept” button when our cookie message displays, you agree to be bound by the terms of this Privacy Statement. Web beacons are web page elements that can recognize certain types of information on your computer or mobile device such as cookies and the time and date of a page viewed.

    Information that may be collected by cookies and web beacons when you use the Site may include, without limitation:

    • the pages you visit within the Site;
    • the date and time of your visit to the Site;
    • the amount of time you spend using the Site;
    • the websites you visit before or after visiting the Site;
    • the Internet Protocol (IP) address used to connect your computer or mobile device to the Internet;
    • geolocation information;
    • your computer or mobile device and connection information such as your browser type and version, operating system and platform; and/or
    • your purchase history.

    You may be able to set your browser to reject cookies or to notify you when you are sent a cookie. You can also purchase and download software that will allow you to use the Service without providing the information gathered by cookies. You are welcome to use the Service if you use this type of software, but your experience while visiting the Service may not be optimal.

    If you create an account to use the Service other than through the Site (such as through our Customer Service Representatives), and if you do not agree with or consent to the terms of this Privacy Statement, you will have thirty (30) days from the date you create the account with us to cancel the account. If you decide that you want to cancel the account within this thirty (30) day period, please contact our Customer Service team using the information supplied through the “Contact Us” link on the Site. If you cancel your account within the applicable thirty (30) day period, we will provide you with a refund of any fees you have paid and have not used in connection with the Service at the time of cancellation.

    Identifiers/Customer Information

    We may collect information from you that can be used to personally identify and/or contact you. Information collected through the Service may include your name, telephone number, physical address, mailing address, billing address, or email address. In addition to contact information, we may collect other personal information from you that may be associated with your contact information, such as your government issued form of identification, date of birth, username, and password. If you are using our Services to make payments, we are required to collect additional identification information, such as your driver's license number and the last four numbers of your social security number.

    Payment and Purchase Information

    If you are using our Services to make payments or to purchase products or services, we are required to collect certain financial information such as your credit card or other payment card information, the type of payment you are making, or information related to the purpose of the payment. We may need to run background checks on anyone involved in the transaction to satisfy our legal requirements.

    Commercial Information

    We collect information related to the products or services you purchase.

    Voice Data, Image, and Recordings

    When you use our Services to communicate with an incarcerated individual, ViaPath records and stores the communication, which may include your image and/or voice data. By using the Services, you are expressly providing consent for ViaPath to collect your voice and image and to use them as described in this Privacy Statement and in accordance with the Terms of Use. ViaPath may also collect a copy of a government issued form of identification bearing your photograph.

    Social Media

    If you choose to connect your social media account to our Facebook and other social media outlets, certain personal information from your social media account will be shared with us, which may include personal information that is part of your profile or your friends' profiles. You may revoke your consent to have the social media platform share information with us by changing your settings within such platform.

    Information About Incarcerated Individuals

    If you are a friend or family member of an incarcerated individual, we may also collect information from you about the identity of incarcerated individual(s) receiving funds from you or individuals with whom you communicate through the Service. If you provide this information, you represent and warrant that you have all necessary rights and authority to provide information about the applicable incarcerated individual(s) in connection with the Service and agree that you shall be solely liable in connection with your disclosure of any information regarding incarcerated individual(s) in connection with the Service.

    Communication and Correspondence

    If you send any personal communication or correspondence, by any means, to the Service, or to any of our employees, agents or representatives, the Service may collect additional information regarding that communication and include that information in our customer database.

    Location Information

    • Mobile Applications

    If you access the Service through one of our mobile applications, we may also be able to identify the location of your mobile device. You may choose not to share your location details with us by adjusting your mobile device's location services settings, or otherwise declining to provide access to your location when prompted to do so. For instructions on changing the relevant settings, please contact your service provider or mobile device manufacturer. If you choose not to share your location details with us, you may be denied access to the mobile application.

    • When You Receive a Phone Call through the Service

    We collect the location of the phone you are using when you use the Service to help ensure accurate billing practices as well as for correctional facilities' safety, security and investigative purposes.

    You will be advised through a prompt on calls placed from an incarcerated individual at a correctional facility to the phone you are using when you use the Service that your phone location information will be obtained. By accepting the call, you agree to have your phone location obtained for 60 minutes after you accept the call. Your location will not be obtained if you do not accept the call. The location information collected in connection with each call will only be stored for one year from the date of the call and then deleted from our records. If you would like to opt out of having your phone location information obtained for any time remaining between when you terminate your call with the incarcerated individual and the above referenced 60 minute period, please call 1-800-483-8314.

    Cellular Provider Information

    The Service is not a Cellular Provider application. If you use the Service, it may require your Cellular Provider to disclose your customer information, including mobile phone location information, to us or some other third party. By providing your consent through the opt-in process described below, you authorize your Cellular Provider to disclose your information to us and to third parties to enable the Service. Please review this Privacy Statement and our Terms of Use for more information about how the Service will collect, access, use or disclose your information. If you aren't comfortable with the terms of this Privacy Statement or our Terms of Use, you should not use the Service. You acknowledge and agree that (1) your relationship with us is separate from your relationship with your Cellular Provider; (2) your Cellular Provider is not responsible for the Service; and (3) you will hold harmless your Cellular Provider and its subsidiaries, affiliates, officers, employees, agents, successors and assigns from any judgments, claims, actions, losses, liabilities or expenses arising from or attributable to the Service or our acts or omissions.

    Information Collected and Used by Third Parties

    If you visit the Site from a third-party website the third-party website may give you a unique code, cookie or graphic which will uniquely identify you. This will only happen if you link directly from a third-party website to the Site. Your activities on the Site while this type of code is active may be reported back to the third-party website. The presence of a third-party navigation bar at the top of any page on the Site is an indication that the third-party website may be able to see your activity on the Site.

    The Site may also include third-party advertising, links to other websites, and other content from third-party businesses. These third-party sites, businesses, and advertisers, may use web beacons and cookies to measure the effectiveness of their ads, personalize or optimize advertising content and to track users who click on the links made available through the Site. These third-parties may use persistent identifiers to track the actions of users online over time and across different websites or platforms to deliver targeted electronic advertisements to an individual user. We do not have access to or control over web beacons, cookies or persistent identifiers that these third parties may use. We are not responsible for the privacy practices or the content of these third-party websites. You are encouraged to review the privacy policies of the different websites you visit. For information about how tracking works for online advertising purposes you can visit http://www.aboutads.info/choices.

    Some third-party advertising companies may provide a mechanism to opt-out of their technology. For more information about the opt-out process, you may visit the Network Advertising Initiative website, available at http://www.networkadvertising.org/managing/opt_out.asp.

    We may also use analytics software service providers to gather and analyze anonymous information about users of the Site. These service providers may use cookies to collect information about your purchase history, the content you view, what websites you visit immediately prior to and after visiting the Site, and your system information. The information gathered by these service providers about your use of the Site may be transmitted to and stored by these service providers. If we use these service providers, the information collected about you by these service providers would allow us to analyze your use of the Site and the Service. The Site uses Google Analytics, including its Demographics and Interests Reports feature, which in addition to the types of information described above, provides a breakdown of visitors to the Site on an anonymous aggregate basis by age group, gender and interests. To learn more about how Google Analytics collects and uses information, and how you can control information sent to Google you can visit https://policies.google.com/privacy.

    Aggregate Information

    We may share information relating to users of the Service with affiliated or unaffiliated third parties on an anonymous, aggregate basis. While this information will not identify you personally, in some instances these third parties may be able to combine this aggregate information with other data they have about you, or that they receive from third parties, in a manner that allows them to identify you personally.

  7. Purposes For Which We Collect, Use, and Process Your Personal Information

    We may use information described above for any of the following purposes:

    • To provide you with Services.
    • To manage and service your account.
    • To contact you when necessary about your account or your use of our Services.
    • To comply with regulatory requirements for the maintenance of records.
    • To send you information and promotional materials about our products and services as well as our company in general.
    • To send you information and promotional materials from our marketing partners and other third parties.
    • For marketing or advertising purposes.
    • To diagnose problems with our server.
    • To administer our Site.
    • To conduct internal reviews of our Service.
    • To help us better understand how users access and use or Sites and Services, and for other research and analytical purposes, such as to understand customer and market needs, evaluate and improve our Services and business operations, and to develop services and features.
    • To carry out our obligations and enforce our rights arising from any contracts entered into and between us and a correctional facility, or controlling entity, where an individual that you may communicate with is detained.
    • To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
    • To verify your identity.
    • To protect the security or integrity of our Service.
    • For any other business or marketing purposes that are not inconsistent with the terms of this Privacy Statement.
    • For purposes not provided for in this Privacy Statement, but if we do, we will notify you (and, if necessary, obtain your consent) before using your personal information in this way

    We may also combine information we collect about you through the Service with other information about you that we receive from third party sources. By way of example and not limitation, we may use a change of address or other list service to ensure that our records for your account are accurate.

    Description of Customer Proprietary Network Information (“CPNI”)

    CPNI is proprietary information about you that includes (1) information on the quantity, technical configuration, type, destination, location, and amount of your use of ViaPath telecommunications services, that you make available to ViaPath solely by virtue of the carrier-customer relationship; and (2) information contained in the bills you receive concerning your telecommunications service. It does not include (1) your name, address, or phone number; (2) aggregated customer information that does not identify specific individuals; or (3) information about non-telecommunications service, such as Internet access. Under the CPNI rules adopted by the Federal Communications Commission (“FCC”), you have the right, and ViaPath has the duty, to protect the confidentiality of CPNI.

    ViaPath's Use of CPNI

    Under FCC rules, ViaPath may use your CPNI without your prior approval for certain purposes. Specifically, ViaPath may use, disclose, or permit access to your CPNI without your consent, either directly or through its agents, for the purpose of (1) initiating, rendering, billing, and collecting for ViaPath Service; (2) protecting ViaPath's right or property, or protecting ViaPath users and other telecommunications carriers from fraudulent, abusive, or unlawful use of, or subscription to, ViaPath services; (3) maintenance and repair; and (4) complying with the orders or subpoenas of a court of competent jurisdiction. Other uses require your approval, as described below.

    Required Customer Approval

    As a leader in the corrections industry, ViaPath is continually developing new innovations in the fields of technology, education, and intelligence. From time to time, ViaPath may use and share your individually identifiable CPNI among its affiliates and agents to inform you about communications-related products and services or special promotions. Use of your individually identifiable CPNI enhances ViaPath's ability to offer products and services that are tailored to your needs.

    You have 30 days from the date of this notice to inform us (see “Contacting ViaPath” above) if you do not wish ViaPath to use your individually identifiable CPNI for this purpose. If you do not so inform us, ViaPath will assume you consent to this use of your individually identifiable CPNI.

    At any time after this 30-day period has elapsed, however, you have the right to disapprove this use, and limit or revoke access to your individually identifiable CPNI by contacting ViaPath. A denial of approval will not affect ViaPath's provision of services to you. Your approval or denial of ViaPath's use of your individually identifiable CPNI is valid until you affirmatively revoke or limit that approval or denial.

    ViaPath will never disclose your individually identifiable CPNI to unaffiliated third parties without your express, opt-in consent, other than as set forth in this Privacy Statement (see How We Share Your Information below).

  8. How We Share Your Information

    We may share the information we collect in connection with the Service with the following recipients: Correctional Facilities and Law Enforcement

    We may share contact information you provide, or location information we collect from your computer or mobile device, with correctional facilities or other law enforcement personnel or to fulfill our contractual obligations. We may also share information concerning any payment transaction completed through the Service including, without limitation, your image as captured when you use a payment services kiosk and the identities of the parties contributing and receiving payment under the transaction and the amount of the payment, with correctional facilities or other law enforcement personnel upon their request. Because safety and security are ViaPath's top priority, you may not opt out of the sharing of your communications with Law Enforcement, and all data associated with your communications. If you do not consent to the collection, use and disclosure of this type of data, please do not use the Sites or Services.

    Service Providers

    We may share your information with our service providers, vendors, suppliers and other services providers who provide services to us or on our behalf, such as operating and supporting the Service, analyzing data, performing marketing or consulting services, assisting us with the preparation and mailing of our business and marketing communications, and with service processing and fulfillment functions. For example, we may disclose your billing information to payment processors when you add money to your account or conduct other financial transactions through the Service.

    Our Affiliates

    We may share some or all of your information with our parent company, subsidiaries and corporate affiliates, joint ventures, or other companies under common control with us. We will require these entities to comply with the terms of this Privacy Statement with regard to their use of your information.

    Transfer or Assignment in Connection with Business Transfers or Bankruptcy

    In the event of a merger, acquisition, bankruptcy or other sale of all or a portion of our assets, any user information owned or controlled by us may be one of the assets transferred to third parties. We reserve the right, as part of this type of transaction, to transfer or assign your information and other information we have collected from users of the Service to third parties. Other than to the extent ordered by a bankruptcy or other court, the use and disclosure of all transferred user information will be subject to this Privacy Statement. However, any information you submit or that is collected after this type of transfer may be subject to a new privacy policy adopted by the successor entity.

    Government Agencies, Judicial and Quasi-Judicial Bodies, Regulators, and Other Public Bodies and Third Parties

    To the extent permitted by law, we may disclose your information to government and law enforcement agencies, judicial and quasi-judicial bodies, regulators, other public bodies, or third parties if: (a) required to do so by law, or in response to subpoenas, court orders, and/or other lawful requests by regulators; (b) we believe in our sole discretion that disclosure is reasonably necessary to protect against fraud, to protect our property or other rights or those of other users of the service, third parties or the public at large; or (c) we believe that you have abused the Service by using it to attack other systems or to gain unauthorized access to any other system, to engage in spamming or otherwise to violate applicable laws or in violation of our Terms of Use. You should be aware that, following disclosure to any third party, your information may be accessible by others to the extent permitted or required by applicable law.

  9. Do Not Track Requests

    Your Internet browser may allow you to adjust your browser settings so that “do not track” requests are sent to the websites that you visit. However, we will not disable tracking technology that may be active on the Site in response to any “do not track” requests that we receive from your browser.
  10. Do Not Sell

    ViaPath does not sell personally identifying information about the users of our Services to any third parties in exchange for monetary compensation.
  11. How We Protect Your Information

    ViaPath complies with all required PCI standards (https://www.pcisecuritystandards.org) regarding our treatment of payment card data. Additionally, we have implemented commercially reasonable measures designed to secure your personal information from unauthorized access, use, alteration and disclosure. However, the transmission of information via the internet is not completely secure. We cannot guarantee the security of your personal information transmitted via our sites or services. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the sites or services.

  12. Security of Information

    We seek to use industry standard physical, technical and administrative security measures designed to protect your personally identifiable information. However, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please immediately notify us in accordance with the “Contacting ViaPath” section above.

    Please note that emails you send to us through our Service are not encrypted, and we strongly advise you not to communicate any confidential information in your emails to us.

  13. Use of Information Outside of Your Country of Residence

    The sites and services are directed to users located in the United States. If you are located outside of the United States and choose to use the sites or services or provide your information to us, you should be aware that we may transfer your information to the United States and process it there. The privacy laws in the United States may not be as protective as those in your jurisdiction. Your consent to this Privacy Statement followed by your submission of information to us through the Site or in connection with the services represents your agreement to the transfer of your information to the United States.

  14. Changes to this Privacy Statement

    If we decide to change our Privacy Statement, we will post those changes to the Privacy Statement on our homepage, and other places we deem appropriate so that you are aware of what information we collect, how we use it, and under what circumstances we disclose it. We reserve the right to modify this Privacy Statement at any time, so please review it frequently. Any changes to this Privacy Statement will become effective when we post the revised Privacy Statement on our Services and Sites. Your continued use of the Services and Sites following these changes constitutes your acceptance of the revised Privacy Statement.

  15. Release

    By accessing and using our website, equipment, and services, you hereby release and forever discharge ViaPath, its Affiliates and employees, contractors, agents, and all applicable Law Enforcement Officials and the correctional facility from any and all liability, expense, cost or remedy which may arise as a result of your use of our websites and services as well as the use of the Data in the manner described herein.

  16. Your Privacy Rights and How to Exercise Them

    Certain U.S. states have adopted privacy laws that give certain rights to individuals over their personal data. We currently provide these rights to all consumers regardless of where they live. The rights available to consumers and how to exercise them are listed below.

    • Know/Access. The right to request to know and access the personal information we have collected about you, including the categories of personal information, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting, selling, or sharing personal information, the categories of third parties to whom we disclose personal information, and the specific pieces of personal information we have collected about them.
    • Correction. The right to request that we correct or update inaccurate personal information that we maintain about you.
    • Deletion. The right to request the deletion of your personal information that we have collected, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies. Please note there are situations where we are unable to delete your data, for example:
      • To complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
      • When we have an overriding interest in continuing to process the data, detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
      • To debug products to identify and repair errors that impair existing intended functionality.
      • To ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
      • To comply with applicable law.
      • To engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may likely render impossible or seriously impair the research's achievement, if you previously provided informed consent.
      • To enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
      • To comply with a legal obligation.
      • To make other internal and lawful uses of that information that are compatible with the context in which you provided it.
    • Data Portability. You may have the right to obtain a copy of the personal data that you previously provided to us in a portable and, to the extent technically feasible, readily usable format that allows you to transmit your personal data to another controller or business where the processing is carried out by automated means.
    • Opt out of sales and sharing: The right to opt-out of our sale and sharing of your personal information.
    • Limit uses and disclosure of sensitive personal information: The right to limit our use or disclosure of sensitive personal information to those authorized by the California Consumer Privacy Act (CCPA). As noted below, we do not use or disclose sensitive personal information beyond the purposes authorized under the CCPA; thus, this right is not available.
    • Non-discrimination. You have the right to not be discriminated against for exercising any of your privacy rights. Submitting a Privacy Rights Requests Your privacy rights can be exercised through one of the following methods:

      Logging into your account on one of our sites (a link to an Exercise Your Privacy Rights form will display on the site's dashboard).

      • Completing the online form available at https://gtlprod.service-now.com/privacy.
      • By emailing us at privacycentral@viapath.com
      • Calling us by phone (toll-free) at:
      • ConnectNetwork Customer Service: 877-650-4249
        • GettingOut Customer Service: 866-516-0115
        • VisManager Customer Service: 855-208-7349
        • TouchPay Customer Service: 866-204-1603

    Verifying Requests

    When you submit a request to know/access, correct or delete, we will take steps to verify your request by matching the information provided by you with the information we have in our records. You must provide your name and contact information to verify your request. In some cases, we may request additional information, where necessary to verify or process your request. We cannot respond to your request or provide you with personal information if we cannot verify your identity, your authority to make the request, and confirm that the personal information relates to you.

    Requests Made Through Agents

    Authorized agents may initiate a request on behalf of another individual by using the options listed above. Authorized agents must provide written proof of their authorization. We may also require that the relevant consumer directly verify their identity and the authority of the authorized agent.

    Response Timing

    We endeavor to respond to a verifiable consumer request within 45 days of its receipt. If we require more time, we will inform you of the reason and extension period in writing.

    Appeals Process

    If your request is denied you may have the right to appeal the denial in accordance with the instructions provided to you when the denial was made.

    If we deny your appeal, you may be able to contact your state's Attorney General to file a complaint related to the denial.

    Requests to opt out/Browser opt out

    Our Sites respond to global privacy control—or “GPC”—signals, which means that if we detect that your browser is communicating a GPC signal, we will process that as a request to opt that particular browser and device out of sales and sharing on our Site (e.g., via cookies and pixels). More information about GPC is available at: https://globalprivacycontrol.org/. You may also opt your browser out of targeting and most cookies on one of our Sites (other than essential cookies) by clicking the “Your Privacy Choices” button on our Sites which will take you to our Privacy Preference Center where you can choose not to allow certain cookie types, except those that are essential for our Site to function properly. Note that if you come back to the Site from a different device or use a different browser on the same device, you will need to opt out of (or set GPC for) that browser and device as well.

    Notice of Right to Opt-Out

    If you wish to opt out of processing of personal data that is gathered when you visit our websites and other web-based services for purposes of “sales” and/or targeted advertising, you may do so in one of the ways described below:

    If you are in the U.S., you can obtain more information and opt out of receiving targeted ads from participating third-party ad networks at info/choices(Digital Advertising Alliance). You may also download the DAA AppChoices (https://youradchoices.com/appchoices) tool in order to help control interest-based advertising on apps on your mobile device).

    Our Sites respond to global privacy control—or “GPC”—signals, which means that if we detect that your browser is communicating a GPC signal, we will process that as a request to opt that particular browser and device out of sales and sharing on our Site (e.g., via cookies and pixels). More information about GPC is available at: https://globalprivacycontrol.org/. You may also opt your browser out of targeting and most cookies on one of our Sites (other than essential cookies) by clicking the “Your Privacy Choices” button on our Sites which will take you to our Privacy Preference Center where you can choose not to allow certain cookie types, except those that are essential for our Site to function properly. Note that if you come back to the Site from a different device or use a different browser on the same device, you will need to opt out of (or set GPC for) that browser and device as well.

    TouchPay Exemption: Personal information that you provide in connection with TouchPay services are exempt from applicable state privacy laws and are not subject to the privacy rights listed above.

  17. Additional Information for California Residents

    Shine the Light

    California Civil Code Section 1798.83, also known as the “Shine the Light” law, permits our customers who are California residents to request and obtain from us once a year, free of charge, information about the personal information (if any) we disclosed to third parties for direct marketing purposes in the preceding calendar year. If applicable, this information would include a list of the categories of personal information that was shared and the names and addresses of all third parties with which we shared information in the immediately preceding calendar year. If you are a California resident and would like to make this type of request, please submit your request in writing to: privacy@viapath.com, or to c/o Global Tel*Link Corporation d/b/a ViaPath Technologies, 3120 Fairview Park Drive, Suite 300, Falls Church, VA 22042, Attn: Privacy.

    Sales and Sharing of Personal Information. Under the California Consumer Privacy Act (CCPA), “sales” and “sharing” are broadly defined, respectively, and include disclosing or making available personal information in exchange for monetary or other valuable consideration, or for purposes of cross-context behavioral advertising. While we do not disclose personal information to third parties in exchange for monetary compensation, we may “sell” or “share” (as defined by the CCPA) internet and electronic network activity information to/with third-party data analytic, marketing, and advertising partners. We do so in order to improve and evaluate our advertising campaigns and better reach customers and prospective customers with more relevant ads and content. We do not sell or share sensitive personal information, nor do we sell or share any personal information about individuals who we know are under sixteen (16) years old.

    Sensitive Personal Information. We do not use or disclose sensitive personal information beyond the purposes authorized by the CCPA. The right to limit the use of sensitive personal information lets you ask us to limit the use and disclosure of sensitive personal information if we use that information for purposes beyond what is needed to provide the products and Services you request or for other reasons specified in the law. The other reasons specified in the law include: (i) helping to ensure security and integrity, including preventing, detecting, and investigating security incidents, (ii) detecting, preventing and responding to malicious, fraudulent, deceptive, or illegal conduct, (iii) ensuring the physical safety of a person, (iv) providing customer service or to verify your information, (v) verifying or maintaining the quality and safety of our services, (vi) complying with our legal obligations, (vii) to our service providers who perform services on our behalf, and (viii) for purposes other than inferring characteristics about you. ViaPath does not use or disclose sensitive personal information for other purposes beyond the purposes authorized by the CCPA.

     

     

     Analysis 

     

     

    1. The "Surveillance State" Clause

    The most critical part of this policy is the unrestricted sharing with Law Enforcement.

  18. The Trap: ViaPath explicitly states that "safety and security are [their] top priority," which is legal shorthand for: You have zero expectation of privacy.

  19. The Scope: They record and store your voice data, image, and the literal content of your communications. * No Opt-Out: Unlike standard consumer apps, they explicitly state you cannot opt out of sharing your data with law enforcement. By clicking "Accept," you are granting a blanket warrant to any correctional facility to monitor your interaction in real-time or via logs.

2. CPNI and "Deemed Consent"

The policy references Customer Proprietary Network Information (CPNI). This is a federal designation (FCC) for data about your phone usage.

  • The 30-Day Ticking Clock: They use a "Negative Option" consent model. They assume you agree to let them share your CPNI with their affiliates for marketing unless you tell them "no" within 30 days.

  • Action Required: If you don't want your call patterns and billing data used for cross-selling, you must contact them immediately.

3. Location Tracking & Cellular Provider "Hold Harmless"

This is one of the more legally dense and risky sections:

  • Real-Time Tracking: By accepting a call, you consent to being tracked for 60 minutes even after the call ends.

  • Cellular Provider Indemnity: They force you to agree to a "Hold Harmless" clause. If your cellular provider (Verizon, AT&T, etc.) leaks your data because ViaPath requested it, you are effectively waiving your right to sue the cellular provider for that specific interaction.

4. The "Release" (Liability Shield)

Near the end, there is a Release clause. This is a massive legal hurdle for any future litigation.

  • The Language: You "release and forever discharge ViaPath... from any and all liability... which may arise as a result of your use of our websites and services."

  • The Reality: They are attempting to preemptively block lawsuits regarding data breaches, wrongful recording, or misuse of your personal info by law enforcement. While "blanket releases" are sometimes challenged in court, this puts you at a severe disadvantage from day one.

5. Third-Party "Shadow" Tracking

Despite saying they "do not sell" data for money (to satisfy CCPA/CPRA technicalities), they admit to "Sharing" (which is "selling" in the eyes of California law) for cross-context behavioral advertising.

  • GPC Response: They do respect Global Privacy Control (GPC) signals. If you are serious about privacy, you should use a browser (like Brave or Firefox with GPC enabled) to interact with their site to auto-signal your opt-out of "selling/sharing."

  1.  

Wednesday, April 15, 2026

Política de Privacidade e Segurança Recrutei - Analise

 Original

 

 

Faca uma analise juridica deste documento


      
        Política de Privacidade
 e Segurança Recrutei

        
          
            
          

          
            Olá!

            A Recrutei é o parceiro de tecnologia que ajuda a empresa
 em que você vai se candidatar a melhorar a experiência de candidatura e
 análise para vagas.

            Ao se inscrever na vaga ou no banco de talentos do seu 
interesse, solicitamos o seu aceite integral aos tópicos aqui 
apresentados, para podermos dar o devido tratamento dos seus dados, 
sempre com o seu consentimento.

            Você encontrará nesta Política de Privacidade todas as 
informações necessárias a respeito do tratamento e da proteção dos dados
 pessoais em todos os sites operados e mantidos pela Recrutei, assim 
como os dados coletados durante a navegação através de cookies e seus 
usos, com o objetivo de apresentar transparência a clientes e 
candidatos.

            Este documento foi criado conforme a Lei Geral de 
Proteção de Dados Pessoais (Lei 13.709/2018), Marco Civil da Internet 
(Lei 12.965/2014) e o Regulamento da UE n. 2016/679 (RGPD ou GDPR) e aplica-se a todos os clientes e candidatos da Recrutei.

            Ao acessar ou se candidatar a uma vaga publicada pela 
Recrutei, você estará aceitando os termos desta política. Isso demonstra
 que você entende e concorda totalmente com a maneira como usaremos seus
 dados e suas informações.

          

        

      

    

    
      
        
          
            
              01. Dados coletados de usuários/visitantes
              02. Cookies
              03. Quando coletamos os dados
              04. Finalidade e bases legais para coleta de dados
              05. Compartilhamento de dados
              06. Período de armazenamento dos dados
              07. Exclusão dos dados
              08. Segurança das Informações
              09. Responsabilidade
              10. Alertas de Segurança e Responsabilidades Financeiras
              11. Da eleição de foro
            

          

          
            
               


              
                01. Quais dados pessoais são coletados

                
                Para que os usuários possam ser identificados na 
nossa plataforma, é necessária a coleta obrigatória de alguns dados como
 e-mail e nome completo. Outros dados são opcionais e são coletados 
apenas caso o usuário/visitante tenha interesse em nos informar, como a 
foto de perfil.


                Dados pessoais que podem ser coletados de usuários/visitantes:


                
                Dados de identificação: nome completo, telefone, e-mail, CPF, data de nascimento, endereço e redes sociais.
Dados técnicos: Informações de acesso, como data, hora, local e endereço de IP, dados sobre o dispositivo utilizado e cookies.
Dados de conexão por serviços de terceiros: dados básicos de identificação e de autenticação com serviços terceiros.
Dados biométricos: foto de perfil, informações sensíveis específicas como o fato de você ser ou não portador de algum tipo de deficiência.
Outros dados: Dados eventualmente fornecidos em formulários, trocas de e-mails, chats e comentários.
Dados agregados: informações 
sobre seu histórico profissional, como empresas nas quais você 
trabalhou, cargos, funções, tempo de duração da experiência e também 
todas as informações presentes no arquivo de currículo que você poderá 
fazer upload no momento da sua candidatura.

                
                  Eventualmente, para melhorar sua experiência de navegação e ou/ experiência de
                  candidatura de vagas, poderemos coletar e analisar seus dados comuns de
                  navegação tais como, cidade de onde você está acessando, tipo de dispositivo do
                  qual você está acessando, tempo de permanência nas aplicações da plataforma,
                  registros de login e logout, características de cliques e monitoramento de ações
                  executadas.
                

                
                  Ao utilizar os nossos serviços, você concorda com a 
coleta e processamento dos seus 
                  dados pessoais para permitir a utilização desses 
serviços. Todos esses dados serão 
                  armazenados de forma segura em diferentes bancos de 
dados, localizados tanto na região leste dos 
                  Estados Unidos (us-east-1), quanto na região sudeste 
do Brasil (sa-east-1), ambos na Amazon Web Services (RDS), 
                  que é uma plataforma segura e confiável. Nós nunca 
compartilhamos seus dados pessoais com terceiros além dos 
                  mencionados aqui nestes termos, a menos que seja 
exigido por lei ou ordem judicial. De acordo com a Lei Geral 
                  de Proteção de Dados (LGPD), você tem o direito de 
acessar, corrigir ou excluir seus dados pessoais a qualquer 
                  momento. Sinta-se à vontade para entrar em contato 
conosco se tiver alguma dúvida sobre a nossa política de 
                  privacidade ou o tratamento dos seus dados pessoais.
                


                Quais tipos de comunicação você poderá receber via e-mail ou telefone

                
                  Ao se candidatar nas vagas e/ou base de talentos, você permite que a Recrutei e recrutadores,
                  gestores ou representantes da empresa entrem em contato com você pelos meios
                  que você inseriu, tais como e-mail, telefone ou Whatsapp.
                


                Essa comunicação poderá ser sobre:


                comunicação sobre a vaga em que você se candidatou;
oferta de novas vagas e processos seletivos;
pesquisas de satisfação;
comunicações institucionais da empresa;
pedido de atualização de dados cadastrais;
conteúdos relacionados ao mercado de trabalho, empregabilidade, preparação para processos seletivos;
atualizações da presente política de privacidades;
informações sobre a empresa, seu ambiente de trabalho e sobre suas oportunidades;

              

            





            
              


              
                02. Cookies


                Os sites e aplicações da Recrutei utilizam Cookies, 
que são pequenos arquivos de texto  enviados pelo site para o navegador 
do usuário, quando o usuário visita o site. 


                O uso de cookies é necessário para armazenar as suas 
preferências de acesso e garantir uma experiência eficiente e 
consistente para os visitantes e usuários da Recrutei, tanto nas visitas
 únicas (cookies de sessão), quanto nas visitas repetidas (cookies 
persistentes).



                OBJETIVOS DO USO DE COOKIES

                Os cookies podem ser usados ​​para diferentes 
propósitos. Alguns cookies são necessários para personalizar a 
experiência do usuário, enquanto outros são por motivos técnicos.

                Os cookies podem ser usados ​​para fins de marketing,
 para veicular anúncios aos usuários ou visitantes com base em suas 
preferências, mas também para fornecer estatísticas que ajudem a 
Recrutei a entender o comportamento dos visitantes da página, permitindo
 que desenvolvamos conteúdos cada vez mais interessantes e direcionados 
ao nosso público.


                TIPOS DE COOKIES

                Estes são os tipos de cookies utilizados nos sites da Recrutei:


                Essenciais:  Cookies estritamente necessários para funcionamento de funções básicas do site.
Funcionais:  Usados para armazenar informações sobre o uso de ferramentas específicas.
Estatístico:  Registram dados 
sobre interações dos visitantes nos nossos sites, como por exemplo, 
quantas vezes determinada página foi acessada, quantidades de usuários, 
local de acesso, e outras informações estatísticas.
Publicidade:  Utilizados para exibir conteúdos publicitários relevantes para os visitantes e usuários.
De terceiros / Conteúdo incorporado: 
 Cookies de serviços de terceiros, como redes sociais e plataformas de 
vídeo, que por meio de botões de compartilhamento ou conteúdos 
incorporados podem  rastrear sua atividade on-line, não tendo a Recrutei
 controle, nem direito sobre os dados coletados por esses cookies.

              

            


            
              


              
                03. Quando coletamos os dados


                Os dados de navegação e os dados pessoais podem ser coletados, conforme contexto, nas situações abaixo:


                No momento em que o site é acessado, coletamos 
dados de navegação (cookies) a fim de assegurar a melhor experiência 
possível ao usuário ou visitante.
                  
Estes dados geralmente são relacionados à páginas 
visitadas, endereço de IP, software de navegação, palavras-chaves 
usadas, endereço web de origem, transferências ou compartilhamentos de 
arquivos e outras que podem ser armazenadas ou retidas.
No momento em que o usuário ou o visitante se 
cadastra para vagas de empregos ou demais serviços fornecidos pela 
Recrutei, o usuário fornece à Recrutei, informações básicas de 
identificação já descritas acima.
Quando o visitante/usuário utilizar serviços de 
terceiros para se autenticar e acessar nossos sites, ou para interagir 
em publicações em nossos sistemas, podemos receber destes serviços as
                    informações básicas de identificação sobre o 
usuário. O uso destes dados, nesta situação, é autorizado pelos 
usuários, previamente, junto à empresa terceira usada.

              

            

            
              


              


                04. Tabela de Bases legais e Finalidades


                
                  
                    
                      Base Legal
                      Dados
                      Finalidade
                    
                  
                  
                    
                      Consentimento do titular
                      Dados de identificação opcionais e dados biométricos
                      Conectar seus dados a base de talentos da empresa, a fim de aumentar as chances de convocação
                    
                    
                      Dados de conexão por serviços de terceiros
                      Autenticar o acesso para utilização dos sistemas Recrutei.


                          Permitir dados de usuários que interagem em conteúdos publicados em nossos sites.
                    
                    
                      - Nome 
 - E-mail 
 - Outros dados opcionais
                      Envio de e-mails contendo comunicados 
informativos e material publicitário relacionado aos serviços, eventos e
 cursos oferecidos pela Recrutei.
                    
                    
                      Legítimo interesse
                      Informações sobre contato coletadas em formulários
                      Envio de e-mails contendo comunicados 
informativos e material publicitário relacionado aos serviços, eventos e
 cursos oferecidos pela Recrutei.
                    
                    
                      Informações de utilização
                      Compreender o uso de nossos sites e serviços pelos usuários para promover melhorias.
                    

                    
                      Cumprimento de obrigação legal
                      Dados técnicos
                      Dados de coleta obrigatória, conforme Lei 12.965/2014 (Marco Civil da Internet), 
                          serão fornecidos para terceiros apenas sob autorização expressa do usuário ou sob demanda judicial.
                    
                     

                

                Por quais motivos coletamos os dados pessoais citados acima?

                Nosso objetivo principal com a coleta e uso dos dados
 é garantir o uso adequado de nossos sistemas e serviços, visando sempre
 melhorar a experiência como usuário.


                Operacionalizar sua participação no processo seletivo
Conectar seus dados à base de talentos da empresa interessada para aumentar suas chances de convocação
Para que as empresa consigam se relacionar com você , diante das necessidades de avanço no processo seletivo
Para tirar sua dúvidas em relação às vagas
Para que a Recrutei possa Prestar suporte à pedido
 do cliente ou ao seu pedido, melhorando sua experiência em Processos 
seletivos
Para que as empresas analisem a compatibilidade do seu perfil e experiência profissional com as vagas ofertadas

              

            

            
              


              
                05. Compartilhamento de dados


                Para viabilizar nossos serviços online, são 
necessários parceiros de tecnologia e negócios que ajudam a manter a 
plataforma em bom funcionamento, da sua aplicação em vagas ao suporte. 
Deste modo, poderão receber seus dados pessoais, estritamente para a 
finalidade que você os informou:


                  Mail Gun: Disparo de e-mails.
Amazon Web Services: Armazenamento seguro em nuvem dos seus dados.
Whatsapp: Reconhecimento do seu número para conexão com recrutadores e gestores.
Google Sheets (planilha Online): Integração dos seus dados para que o Recrutador possa conectar com outras ferramentas de gestão do seu Recrutamento.
Hotjar: Ferramenta de 
monitoramento de uso com o intuito de melhorar a usabilidade do ambiente
 de candidatos assim como diagnosticar eventuais erros na plataforma e 
corrigi-los.
Google Analytics: Mapeamento de
 fontes de candidatura, acessos de página e comportamento de uso em 
geral. Utilizado para a melhoria da experiência de recrutadores e 
candidatos na plataforma Recrutei.

              

            


            
              


              
                06. Período de armazenamento dos dados

                Caso você não peça a exclusão, seus dados ficarão 
armazenados por 2 (dois) anos, por padrão. Ao aplicar-se na vaga e/ou 
base de talentos você declara seu total entendimento e aceite de cada um
 dos itens de coleta e tratamento dos seus dados pessoais

              

            


            
              


              
                07. Exclusão dos dados

                  Você poderá pedir a exclusão da sua conta, 
resguardados dados básicos essenciais que serão mantidos para fins de 
fiscalização dos órgãos competentes.

                  Solicitações de exclusões e esclarecimentos de dúvidas quanto ao tratamento dos dados podem ser feitas através e-mail privacidade@recrutei.com.br. O processo poderá levar até 72h úteis.




                  Em quais casos seus dados não serão usados 

                  Seus dados não poderão ser vendidos, transferidos 
ou fornecidos para empresas desconectadas ao seu interesse legítimo no 
mercado de trabalho para finalidade de vendas de produtos ou serviços ou
 outros objetivos desconexos ao seu interesse legítimo ao fornecê-los.


  
                  O que você pode solicitar em relação aos seus dados:

                  Acesso integral aos dados fornecidos, por meio do seu login e senha.
Atualização dos dados: Você mesmo poderá atualizar sempre que quiser, com seu login e senha.

              

            


            
              


              
                08. Segurança das Informações

                Todos os dados dos usuários (candidatos e empresas) 
são confidenciais e somente as pessoas com a devida permissão terão 
acesso a eles. Qualquer uso destes dados está de acordo com nossa 
política de privacidade. Nossos servidores estão localizados em 
diferentes lugares, garantindo mais segurança, redundância e 
disponibilidade, podendo ser acessado somente por pessoas autorizadas. 
Todas as informações, principalmente de caráter sensível, sempre que 
possível serão criptografadas ou anonimizadas, caso não inviabilizem o 
uso pelos sistemas operados pela Recrutei. A qualquer momento o usuário 
poderá requisitar uma cópia dos seus dados armazenados em nossos 
sistemas.

              

            


            
              


              
                09. Responsabilidade

                Com exceção dos casos de dolo ou culpa pela Recrutei,
 a Recrutei se exime de quaisquer responsabilidades por eventuais danos 
e/ou prejuízos decorrentes de falhas, vírus ou invasões.

                Consideramos a privacidade de nossos usuários 
extremamente importante e tomaremos todas as medidas necessárias para 
protegê-la. Porém, não podemos  garantir completamente que todas as 
informações e dados sobre estes usuários estarão livres de acessos não 
autorizados, principalmente caso haja compartilhamento indevido das 
credenciais de acesso por parte do usuário. Sendo assim, o usuário fica 
responsável por manter suas credenciais de acesso em lugar seguro, sendo
 vedado o compartilhamento desta com terceiros. O usuário se compromete 
em notificar imediatamente a Recrutei, por meio institucional e seguro, a
 respeito de qualquer uso não autorizado ou indevido de sua conta.



                Encarregado pelo Tratamento de Dados Pessoais

                Na Recrutei você conta com um profissional dedicado a
 cuidar dos seus dados, e realizar o tratamento de suas informações 
pessoais.

                O DPO auxilia você, titular dos dados, esclarecendo 
dúvidas e garantindo que os direitos dos mesmos serão tratados sempre 
que requeridos. Para entrar em contato com o DPO da Recrutei, entre em 
contato com privacidade@recrutei.com.br

              

            


            
              


              
                10. Alertas de Segurança e Responsabilidades Financeiras

                
                Importante: A Recrutei e seus clientes não cobram nada dos candidatos

                
                  A Recrutei e nenhuma empresa cliente autorizada cobra qualquer tipo de pagamento dos candidatos em nenhuma etapa do processo seletivo, incluindo mas não se limitando a:
                


                Taxas de inscrição em processos seletivos
Exames admissionais
Taxas de análise de currículo
Custos de treinamentos ou capacitações
Qualquer outro tipo de cobrança relacionada à candidatura ou contratação


                Alerta de Fraude

                
                  Recentemente foram identificados casos de pessoas 
mal-intencionadas que utilizaram indevidamente a marca Recrutei para 
criar vagas falsas e solicitar pagamentos de candidatos, especialmente 
para supostos exames admissionais.
                

                
                  Se você receber qualquer solicitação de 
pagamento durante um processo seletivo que afirme ser da Recrutei ou de 
uma empresa cliente, trata-se de uma tentativa de fraude.
                



                Como proceder em caso de suspeita de fraude

                
                  Caso você seja contatado com solicitação de pagamento em nome da Recrutei ou de uma empresa cliente:
                


                NÃO EFETUE NENHUM PAGAMENTO
Reporte imediatamente para privacidade@recrutei.com.br
Forneça todos os detalhes da comunicação fraudulenta (prints, e-mails, números de telefone, etc.)
Denuncie às autoridades competentes, se necessário


                Isenção de Responsabilidade

                
                  A Recrutei não se responsabiliza por danos, prejuízos 
financeiros ou de qualquer natureza decorrentes de ações fraudulentas de
 terceiros que utilizem indevidamente nossa marca, nome ou identidade 
visual para aplicar golpes ou solicitar pagamentos indevidos de 
candidatos.
                

                
                  A responsabilidade da Recrutei limita-se aos serviços 
efetivamente prestados através de nossos canais oficiais devidamente 
autenticados. Qualquer comunicação ou solicitação que não tenha origem 
em nossos sistemas oficiais não é de nossa responsabilidade.
                

                
                  Os candidatos devem sempre verificar a autenticidade 
das comunicações e, em caso de dúvida, entrar em contato conosco através
 dos canais oficiais antes de fornecer qualquer informação pessoal ou 
efetuar pagamentos.
                

              

            


            
              


              
                11. Da eleição de foro

                
                  Este documento é regido e deve ser interpretado 
conforme as leis da República Federativa do Brasil. Eventuais
                  divergências provindas do entendimento e/ou execução 
destes termos deverão ser dirimidos na comarca de Uberlândia,
                  Minas Gerais, com exclusão de qualquer outro.
                

                Todos os tópicos aqui se aplicam e devem ser interpretados de acordo com a Lei Geral de Proteção de Dados: Lei nº
                  13.709/2018.
                

              

            

            
              Caso tenha qualquer dúvida, sugestão, crítica ou 
solicitação de alteração e/ou remoção de informações pessoais, entre em 
contato com privacidade@recrutei.com.br. 

            

             Última Atualização: 08 de Junho de 2025

          

        

      

     

 

 

Análise de Riscos e Blind Spots

1. O Consentimento como "Cheque em Branco"

O documento afirma que, ao se candidatar, você dá "aceite integral". Juridicamente, a LGPD (Lei 13.709/2018) exige que o consentimento seja livre, informado e inequívoco.

  • A Falha: A política agrupa finalidades distintas (processo seletivo, marketing, base de talentos, compartilhamento com terceiros). Isso beira o "consentimento forçado".

  • Risco Profissional: Seus dados biográficos e profissionais (histórico, cargos, salários) tornam-se ativos da plataforma para treinar algoritmos ou alimentar bases de dados de terceiros por 2 anos.

2. Transmissão Internacional de Dados

Eles admitem armazenar dados na região us-east-1 (EUA) e sa-east-1 (Brasil) via AWS.

  • O que não dizem: Embora a AWS seja segura, a transferência internacional de dados exige salvaguardas contratuais específicas que não estão detalhadas. Se você preza pela soberania dos seus dados, saiba que eles estão sujeitos à jurisdição americana (Cloud Act).

3. O Perigo do "Legítimo Interesse" para Marketing

A Recrutei utiliza a base legal de Legítimo Interesse para enviar "comunicados informativos e material publicitário".

  • Dissecação da Lógica: Eles estão usando o fato de você querer um emprego para justificar o envio de propaganda. Isso é uma interpretação agressiva da lei que pode poluir sua atenção e vender sua "intenção de carreira" para anunciantes de cursos e eventos.

4. Isenção de Responsabilidade em Fraudes (Cláusula 10)

Esta é a parte mais crítica. Eles se isentam de danos financeiros por fraudes que utilizem a marca deles.

  • A Realidade: Como eles coletam dados via cookies de terceiros e possuem integrações com Google Sheets e MailGun, a superfície de ataque é grande. Se um vazamento de dados na plataforma facilitar um golpe contra você, a tentativa deles de se eximirem de culpa (Cláusula 9 e 10) pode ser contestada judicialmente, pois a responsabilidade do controlador de dados é, em regra, objetiva no que tange à segurança.


📋 Plano de Ação Estratégico

Para alguém que quer crescer profissionalmente e manter saúde financeira, você deve tratar seus dados como capital.

Mudança de Mentalidade

Pare de ver Políticas de Privacidade como "termos de uso chatos". Elas são contratos de cessão de ativos. Você está trocando sua privacidade pela chance de uma entrevista.

Ações Imediatas

  1. Limpeza de Rastro (Cookies): Utilize navegadores com proteção contra rastreamento (como Brave ou extensões tipo uBlock Origin) ao acessar o portal. A Recrutei utiliza Hotjar e Google Analytics para monitorar cada clique seu. Não dê a eles dados comportamentais de graça.

  2. E-mail Único para Candidaturas: Não use seu e-mail principal ou profissional para se cadastrar. Use um e-mail específico (ex: carreira_nome@provider.com). Isso isola o risco de phishing e o spam autorizado pela cláusula de "legítimo interesse".

  3. Gestão de Expiração: O prazo de 2 anos é longo. Se você não for chamado em 6 meses, envie um e-mail para privacidade@recrutei.com.br solicitando a exclusão dos dados (Art. 18 da LGPD). Não deixe seu currículo mofando em bancos de dados alheios.

  4. Autenticação: Nunca use "Login com LinkedIn/Google" se puder criar uma conta com e-mail e senha. A política menciona coleta de dados de "serviços de terceiros", o que permite que eles extraiam mais informações do seu perfil social do que o necessário.

Monitoramento de Carreira

  • Fique atento: Se começar a receber ofertas de cursos de "especialização" logo após uma negativa de vaga, você sabe que seu dado foi processado para fins de marketing (Cláusula 4).


🔗 Referências para Estudo Prático

Conclusão: A política é padrão para o mercado de RH Tech brasileiro, mas é agressiva na coleta e na tentativa de blindagem jurídica contra fraudes.

 

 

 

 

Executive Summary: Surface Transportation Cybersecurity

 


A comprehensive strategy for securing surface transportation (rail, transit, pipeline) against cyber threats, particularly focusing on the intersection of Information Technology (IT) and Operational Technology (OT). The common thread is a shift from reactive protection to operational resilience, emphasizing that agencies must be prepared to maintain service during and after an inevitable cyber incident.


1. Key Topics & Strategic Frameworks

The Threat Landscape

  • High-Profile Targets: Major events (e.g., FIFA World Cup, LA Olympics) increase the "attractiveness" of transit systems for adversaries looking for maximum visibility or disruption.

  • IT/OT Convergence: Modern transit relies on interconnected systems. A breach in a non-critical IT system (like payroll) can "pivot" into critical OT systems (signaling, dispatch, power) if they are not properly segmented.

  • Third-Party Risk: 30% of cyber incidents now involve third-party vendors. Trusting a vendor without rigorous access controls is identified as a major vulnerability.

Tactical Frameworks

  • MITRE ATT&CK Matrix: Used to provide a common language to describe adversary behavior (tactics) and specific methods (techniques).

  • The Cyber Kill Chain: A high-level view of an attack from reconnaissance to the final "action on objectives" (e.g., data deletion or service halt).

  • Zero Trust & Least Privilege: Moving away from a "trusted network" model. Access should be granted only to what is necessary, and "Trust is not a control; it is a vulnerability."

Risk Treatment Options

  • Mitigation: Reducing risk through controls (e.g., MFA, segmentation).

  • Avoidance: Not connecting legacy safety systems to the internet.

  • Transfer: Using cyber insurance for financial protection.

  • Acceptance: Consciously deciding to live with a risk, though this must be documented as a business decision.


2. Priority Actions for Stakeholders

Technical & Operational Actions

  • Segment Networks: Strictly separate IT and OT environments to prevent lateral movement by attackers.

  • Enforce Multi-Factor Authentication (MFA): Mandatory for all remote access and administrative accounts, including third-party vendors.

  • Monitor Logs: Actively review system health and access logs to identify anomalies before they become full-scale incidents.

  • Hardening Systems: Disable unnecessary services/ports and maintain a patch management lifecycle for both IT and OT.

Governance & Preparedness Actions

  • Tabletop Exercises (TTX): Regularly simulate cyber-attack scenarios (like the "Scranton Metro Rail" example) to test response times and clarity of roles.

  • Incident Response Plans (IRP): Develop and practice plans that focus on recovery time objectives. The goal is safety first, then service restoration.

  • Third-Party Oversight: Review and audit vendor access. Remove persistent admin rights for external partners.

  • Leverage TSA/CISA Resources: Utilize free federal services, such as:

    • Cybersecurity Assessments: Vulnerability scanning and architecture reviews.

    • Cyber Hygiene Services: Automated scans for internet-facing assets.

    • Information Sharing: Engage with the ST-ISAC (Surface Transportation Information Sharing and Analysis Center).


3. Recommended Resources (from TSA Stakeholder Guide)

Resource TypeSource/ProviderPurpose
Operational GuidanceOT Smart Practices GuideBaseline "must-dos" for securing rail and transit OT.
Threat MappingMITRE ATT&CKUnderstanding specific adversary techniques.
AssessmentsTSA CAD (Cyber Assurance Div)On-site or virtual cybersecurity architecture reviews.
Alerts & IntelCISA Shields UpReal-time threat alerts and mitigation steps.

Bottom Line: Cybersecurity is no longer an "IT issue"—it is a public safety and operational survival issue. Your focus must be on Speed of Decision Making and System Resilience.

Global Tel*Link Corporation d/b/a ViaPath Technologies (“ViaPath”) Privacy Statement (the “Privacy Statement”)

  Privacy Statement Effective Date: June 30, 2025 Overview and Scope Your privacy is important to us. This Global Tel*Li...