Information Classification Policy
Criteria for classifying HABORA's information, guiding access, protection, sharing and retention.
- Version
- 1.0
- Published on
- July 1, 2026
- Last updated
- July 1, 2026
- Next scheduled review
- July 1, 2027
1. Purpose
This Policy defines criteria for classifying information handled by HABORA, guiding access, protection, sharing and retention.
2. Classifications
Information may be classified as Public, Internal Use, Confidential or Restricted.
3. Public
Information intended for disclosure, such as the institutional website, approved commercial materials, public policies and marketing content.
4. Internal Use
HABORA's internal operational information, procedures, guidance and documents not intended for the public.
5. Confidential
Information about customers, contracts, documents, financial data, properties, reports, ESG, permissions and commercial data.
6. Restricted
Passwords, tokens, API keys, credentials, sensitive logs, security incidents, vulnerabilities, highly sensitive data and privileged access.
7. Controls
The higher the classification, the greater the restriction of access, the need for logs, encryption, confidentiality and permission review should be.
8. Responsibility
Users and employees must handle information according to its classification and authorized purpose.
Contact
Questions, legal requests, privacy requests, formal communications and requests related to this policy should be sent to juridico@haborahub.com.br.
Updates
This policy may be revised to reflect legal, regulatory, technical, commercial or operational changes. The current version will remain available in the HABORA Compliance area. Material changes may require new acceptance by users, where applicable.