Skip to content
DFY
DFY

Information Security Policy (PSI)

May 3, 2025

1. Objective

This Information Security Policy aims to establish principles, guidelines, and responsibilities applicable to the protection of information handled within DFY, a technological platform operated by D Empreendimentos LTDA, ensuring the confidentiality, integrity, availability, and traceability of information, as well as the continuity and reliability of the services provided.

This Policy aims to preserve the safety of the technological environment, user trust, compliance with current legislation, and the integrity of the DFY operational model, considering information as an essential strategic asset.

2. Scope

This Policy applies to all employees, administrators, officers, users, operational partners, technological partners, suppliers, service providers, and any third parties who, directly or indirectly, have access to DFY information, systems, data, or technological infrastructure.

It covers all physical and digital environments, including systems, databases, APIs, cloud infrastructure, devices, networks, backups, logs, and communication channels used by the platform.

3. Information Security Principles

Information security at DFY is guided by the following principles:

Confidentiality guarantee that information is accessed only by duly authorized persons, according to functional need and defined permission levels.

Integrity guarantee that information remains complete, accurate, consistent, and protected against unauthorized or improper alterations.

Availability guarantee that data, systems, and services are accessible whenever necessary, according to defined service levels.

Authenticity guarantee of the legitimacy of the identity of users, systems, and processes interacting with the platform.

Traceability capability to record, identify, and audit all relevant actions performed within the DFY environment.

4. Information Classification

Information handled by DFY is classified according to its level of sensitivity and impact, observing criteria for access, storage, sharing, and disposal:

Public Information that whose disclosure is authorized and does not generate risk to the operation or the data subjects.

Internal Information information restricted to internal organizational activities.

Confidential Information sensitive, personal, strategic, or operational data, access to which is limited to authorized users.

Restricted Information critical information whose access is highly controlled, permitted only to specific profiles and upon justified need.

5. Access and Identity Management

Access to DFY information and systems is controlled based on the principle of least privilege, ensuring that each user has access only to the resources strictly necessary for the performance of their duties.

Access management includes individual authentication by exclusive credentials, definition of hierarchical access profiles, recording of authentication logs and activities, periodic review of permissions, and immediate revocation of access in cases of termination, inactivity, or suspicion of misuse.

6. Technological Environment Security

DFY adopts appropriate technical and administrative measures to protect its technological environments, including, among others:

Use of cloud infrastructure with security controls and redundancy;

Encryption of data at rest and in transit, when applicable;

Execution of periodic backups and contingency plans;

Continuous monitoring of vulnerabilities and security events;

Regular updates and corrections of systems and technological components.

7. Data Treatment and Protection

The processing of personal data and information on the DFY platform strictly observes current legislation, especially the General Data Protection Law (LGPD), being carried out in a lawful, transparent, secure manner and limited to the operational purposes of the platform.

Users undertake to insert and treat third-party data on the platform only when they have an adequate legal basis, being fully responsible for misuse, excessive use, or non-compliance with legislation.

8. Information Security Incidents

Information security incidents, such as unauthorized access, leaks, losses, relevant unavailability, or data compromise, must be communicated immediately to the responsible area.

DFY will adopt appropriate measures for incident containment, cause analysis, impact mitigation, recording, and documentation, as well as communication to competent authorities, when required by law.

9. Awareness and Training

DFY promotes awareness actions and periodic training in information security, directed at employees, partners, and service providers, compatible with their functions and access levels, aimed at strengthening the culture of information protection.

10. Monitoring and Audit

Information security controls are continuously monitored and may be subject to internal and external audits, aiming to evaluate their effectiveness, identify improvements, and ensure adherence to internal policies and applicable legislation.

11. Penalties and Disciplinary Measures

Non-compliance with this Policy may result in the adoption of applicable administrative, contractual, and legal measures, according to the severity of the infraction, without prejudice to other provisions provided for in DFY internal regulations.

12. Final Provisions

This Policy enters into force on the date of its approval and must be revised periodically or whenever there are relevant changes in the operational, technological, or regulatory environment of DFY.

D EMPREENDIMENTOS LTDA

45.810.376/0001-08

R. Pernambuco, Sala 09, 750, Chácara Brasil – São Luís, MA.

65066-851