Governance and compliance
Last updated: 15 September 2026
This is a courtesy translation. In the event of any discrepancy, the Portuguese version prevails.
Making it happen includes protecting what is entrusted to us. Every day we work with campaigns that have not yet been published, third-party brands, personal data and clients’ intellectual property. This page summarises how we look after it all. The full policies, approved by the Executive Board, are made available to clients and partners on request.
Information security
We operate under an Information Security Policy covering acceptable use of resources, access management, backup and restoration, and incident response. In practice:
- All client information is treated as confidential until authorised publication.
- Materials are segregated by project and accessed only by the team involved.
- Access is tied to named individuals, limited to the minimum necessary, protected by two-factor authentication and revoked on the same day it is no longer needed.
- Credentials are kept in a password vault, never in code, spreadsheets or messages.
- Backups follow the 3-2-1 rule and are tested periodically.
- Everyone who acts on our behalf — team members, freelancers and partners — signs a Confidentiality Agreement before their first access.
Privacy and LGPD
Our Privacy and Personal Data Protection Policy follows the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and applies to all our services. When we process data on behalf of a client, we act as a processor: we follow only the instructions agreed in the contract, we do not use the data for our own purposes or to train artificial intelligence models, and we return or delete everything when the contract ends.
People’s image, voice and name are used in productions only with express authorisation. Incidents affecting client data are reported within 24 hours of confirmation.
Data Protection Officer: Lucas Godoi
Contact for individuals and clients: atendimento@espiralcrossmedia.com.br
For the data this site collects, see the Privacy Policy.
Artificial intelligence with human curation
We use artificial intelligence as a tool to amplify our work. It does not replace strategic direction, authorship or human review. Our AI Governance Policy, aligned with the NIST AI Risk Management Framework and the LGPD, sets out:
- People decide. No deliverable, decision or publication goes out without human review and approval.
- Approved tools. Personal data and client materials only go into tools that have been assessed and contracted on terms under which the data is not used for training.
- Inventory and ownership. We maintain a centralised inventory of all AI systems in use, with the purpose, scope, risk and person responsible for each, and a governance model with technical, compliance and business owners.
- Assessment before adoption. Higher-risk uses undergo a data protection impact assessment before they begin.
- Transparency. The use of AI in a deliverable is recorded and, where relevant, disclosed to the client. Synthetic content is not presented as captured material.
- Rights and representation. We check outputs for intellectual property issues, improper resemblances and bias, especially in the representation of people.
- Assessed providers. Each tool is assessed for security, privacy, bias, integrity and technological dependency, with the assessment recorded and reviewed periodically.
Continuity
A Business Continuity and Disaster Recovery Plan sets out priorities, recovery times and who is responsible, so that we keep delivering to clients even in the event of system failures, provider outages or loss of the office. The plan is tested at least once a year.
Ongoing training
Everyone is briefed on privacy and security before accessing client materials, and the whole team takes part in at least one formal training session a year, with attendance recorded, as part of our Privacy and LGPD Education Programme.
Documents available on request
Clients, partners and those conducting due diligence can request the full, signed versions of:
- Privacy and Personal Data Protection Policy
- Information Security Policy
- Confidentiality Agreement (template)
- Incident Management Procedure
- Business Continuity and Disaster Recovery Plan
- Privacy and LGPD Education Programme
- AI Governance Policy and AI Systems Inventory
Requests: atendimento@espiralcrossmedia.com.br · +55 11 3294-3902
We make it happen.