Data Protection and Security

Information Classification Policy

Criteria for classifying HABORA's information, guiding access, protection, sharing and retention.

Back to Compliance
Data Protection and SecurityIn effectReading time: 8 minutes
juridico@haborahub.com.br
Version
1.0
Published on
July 1, 2026
Last updated
July 1, 2026
Next scheduled review
July 1, 2027

1. Purpose

This Policy defines criteria for classifying information handled by HABORA, guiding access, protection, sharing and retention.

2. Classifications

Information may be classified as Public, Internal Use, Confidential or Restricted.

3. Public

Information intended for disclosure, such as the institutional website, approved commercial materials, public policies and marketing content.

4. Internal Use

HABORA's internal operational information, procedures, guidance and documents not intended for the public.

5. Confidential

Information about customers, contracts, documents, financial data, properties, reports, ESG, permissions and commercial data.

6. Restricted

Passwords, tokens, API keys, credentials, sensitive logs, security incidents, vulnerabilities, highly sensitive data and privileged access.

7. Controls

The higher the classification, the greater the restriction of access, the need for logs, encryption, confidentiality and permission review should be.

8. Responsibility

Users and employees must handle information according to its classification and authorized purpose.

Contact

Questions, legal requests, privacy requests, formal communications and requests related to this policy should be sent to juridico@haborahub.com.br.

Updates

This policy may be revised to reflect legal, regulatory, technical, commercial or operational changes. The current version will remain available in the HABORA Compliance area. Material changes may require new acceptance by users, where applicable.

Related documents