Legal & Compliance

Privacy Policy

Matera Systems is committed to protecting the personal data of everyone who interacts with our website, communications, and services. This policy explains, in plain language, exactly what information we collect, why we collect it, how we protect it, and what rights you hold over it — in accordance with Brazil's Lei Geral de Proteção de Dados (LGPD, Lei nº 13.709/2018) and the European Union's General Data Protection Regulation (GDPR, Regulation EU 2016/679), as well as other applicable privacy frameworks.

Last updated: July 1, 2025

Introduction

This Privacy Policy applies to all personal data processed by Matera Systems Informática SA ("Matera Systems", "we", "us", or "our") through our corporate website located at matera-us.site and through any associated communications, including email and telephone interactions. It applies to visitors, prospective clients, partners, and any other individual whose personal data we may handle.

Matera Systems acts as the data controller for all personal data described in this policy — meaning we are the legal entity that determines the purpose and means of processing. Where we engage third-party processors (such as analytics or communication service providers), we do so under binding data processing agreements that impose obligations consistent with LGPD and GDPR requirements.

We encourage you to read this policy in full. If you have questions, our data protection contact details are provided in the final section. Your continued use of this website indicates that you have read and understood this policy.

Who we are: Matera Systems Informática SA is a Brazilian technology company (CNPJ 57.040.040/0001-84) specialising in financial core banking software, payment infrastructure, and fintech integration solutions. Our registered address is Avenida Selma Parada (Bailarina), 505, Conj 701, Andar 7, Jardim Madalena, Campinas-SP, Brazil.

Information We Collect

a) Information you provide directly

When you contact us through the email address listed on this website, by telephone, or through any other direct channel (such as in-person meetings or professional networking events), you may share personal information with us voluntarily. This can include:

  • Your full name and professional title
  • Business email address and direct telephone number
  • Company name, industry sector, and approximate size
  • The content of your message or enquiry, including any attachments
  • Any other information you choose to share in the course of communication

b) Information collected automatically

Like virtually all modern websites, our server infrastructure and analytics tools collect certain technical data automatically each time your browser loads a page on this domain. This is standard operational practice and helps us keep the website secure, diagnose technical problems, and understand how visitors interact with our content. Automatically collected data may include:

  • IP address (which may indicate your country or city of origin)
  • Browser type and version, and operating system
  • Pages visited, time spent on each page, and navigation paths through the site
  • Referring URL (the website you came from, if applicable)
  • Date and time of each request, and HTTP response codes
  • Device type (desktop, tablet, or mobile) and screen resolution

c) Cookies and similar tracking data

We use cookies and similar browser-based technologies to enhance your experience and to gather aggregated analytics about site usage. A full description of the cookies we use and the options available to you is provided in the Cookies & Tracking Technologies section below.

d) Information we do not collect

We do not collect sensitive personal data as defined under LGPD and GDPR — this means we have no interest in, and no mechanism for collecting, data about racial or ethnic origin, political opinions, religious beliefs, trade union membership, health status, sexual orientation, biometric data, or criminal records. We do not operate user accounts, member portals, or any authentication system on this website, and we do not collect financial data such as payment card numbers.

How We Use Your Information

We process personal data only for legitimate, specified, and explicit purposes. We will never use your data in ways incompatible with those purposes without first informing you. The table below sets out each processing activity, the underlying legal basis, and whether we rely on a basis under both LGPD and GDPR:

Responding to your enquiries

When you email or call us, we use the information you provide solely to understand your question, provide an accurate and relevant response, and follow up if you have indicated that further communication is welcome. Legal basis: Legitimate interest (LGPD Art. 7 IX; GDPR Art. 6(1)(f)) — we have a genuine business interest in addressing professional enquiries in a prompt, helpful manner, and this interest does not override your fundamental rights.

Website analytics and performance

Automatically collected and cookie-derived data helps us identify pages that are difficult to navigate, content that is most relevant to visitors, and technical errors that require fixing. This data is used in aggregated, anonymised form wherever possible. Legal basis: Legitimate interest (LGPD Art. 7 IX; GDPR Art. 6(1)(f)) for functional analytics; consent (LGPD Art. 7 I; GDPR Art. 6(1)(a)) for any non-essential tracking cookies, which are activated only after you accept via the cookie consent banner.

Business development and prospecting

If you provide contact details in a clearly commercial context — for example, you represent a financial institution and are exploring our core banking platform — we may retain those details to facilitate a structured follow-up, share relevant product information, or invite you to webinars or industry events. You may opt out of such communications at any time by contacting us at the address below. Legal basis: Legitimate interest (LGPD Art. 7 IX; GDPR Art. 6(1)(f)).

Legal compliance and regulatory obligations

Certain data must be retained to comply with Brazilian tax law, accounting regulations, or other mandatory legal frameworks. Legal basis: Legal obligation (LGPD Art. 7 II; GDPR Art. 6(1)(c)).

We do not sell your personal data. We do not sell, rent, or trade personal information to data brokers, advertisers, or any other commercial third parties. Your data is used only for the purposes listed above.

Cookies & Tracking Technologies

A cookie is a small text file stored in your browser by a website you visit. Cookies serve a variety of functions: some are essential for the site to function at all, others remember your preferences, and others collect anonymous statistics that help us understand how visitors use our content.

Essential cookies

These cookies are strictly necessary for the website to operate and cannot be turned off in our systems. They are typically set in response to actions you take that amount to a service request — such as confirming your cookie preferences. They do not identify you personally. Examples include session management cookies and the cookie used to store your consent preferences.

Analytics cookies

Subject to your consent, we use Google Analytics 4 to collect aggregated data about page popularity, traffic sources, and visitor flow. Google Analytics sets cookies (including _ga and _ga_*) that persist for up to 24 months. IP addresses transmitted to Google are anonymised before storage. We have enabled data sharing restrictions and do not use Google Analytics advertising features such as remarketing or demographic reporting.

Third-party cookies

Certain pages on this website may embed content hosted by third-party services — for example, video content hosted on YouTube or LinkedIn share buttons. These third parties may set their own cookies when that content loads. We do not control those cookies and recommend you review the privacy policies of the relevant third parties directly.

Managing your cookie preferences

When you first visit our website, you are shown a cookie consent banner that allows you to accept or decline non-essential cookies. You can revisit or change your preferences at any time using the "Cookie Settings" link in the footer of every page. Additionally, all major browsers allow you to manage, block, or delete cookies through their settings menus — though doing so may affect some website functionality. Guidance specific to your browser is available from the browser's own help documentation.

For opt-out options relating specifically to Google Analytics, you may install the Google Analytics Opt-out Browser Add-on.

Sharing With Third Parties

We do not share your personal data with third parties for their own marketing or commercial use. We may share data only in the limited and specific circumstances described below:

Service providers and data processors

We engage a small number of technology service providers who act as data processors on our behalf. These include our hosting provider, email delivery infrastructure, and web analytics platform. Each processor is bound by a Data Processing Agreement (DPA) that restricts the use of personal data strictly to the services they provide to us, prohibits sub-processing without our consent, and requires them to maintain appropriate security measures. Processors we currently rely on include:

  • Cloud infrastructure providers for website hosting (data may be stored in Brazil or the European Economic Area)
  • Google LLC, for Google Analytics 4 (operating under Google's applicable data processing terms)
  • Email service providers used for operational communications

Legal requirements and law enforcement

We may disclose personal data if we are required to do so by applicable law, court order, or other lawful governmental or regulatory authority — for example, in response to a judicial order from a Brazilian court under Brazilian civil or criminal procedure. In such cases, we will disclose only the minimum information required by the specific legal obligation, and where legally permissible we will notify the affected individual in advance.

Corporate restructuring

In the event of a merger, acquisition, joint venture, or sale of all or part of our business assets, personal data held by us may be transferred to the acquiring entity as part of that transaction. We will take reasonable steps to ensure that any acquirer treats your data in a manner consistent with this policy, and we will notify you of material changes to data handling resulting from such a transaction.

International transfers

Our primary operations and data storage are located in Brazil. When personal data is transferred to service providers located outside Brazil — particularly to countries within the European Economic Area or the United States — we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the relevant authority, or reliance on an adequacy decision. We monitor ANPD guidance on international data transfers as Brazilian regulatory practice evolves.

Data Retention

We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable law. Our general retention standards are as follows:

  • Enquiry and communication records: Retained for up to 36 months from the date of last meaningful contact, after which they are permanently deleted or irreversibly anonymised. If a commercial relationship develops, records related to that relationship are retained for the duration of the contract plus 5 years, in line with standard Brazilian commercial statute of limitations.
  • Analytics and website logs: Aggregated analytics data is retained for up to 26 months (as configured in Google Analytics 4). Raw server access logs are retained for up to 90 days for security monitoring purposes, then deleted.
  • Cookie preference records: Consent logs are retained for 12 months, after which you will be asked to confirm your preferences again on your next visit.
  • Legal and regulatory records: Where law requires us to retain documentation — such as for fiscal, accounting, or anti-money-laundering compliance — we retain the minimum required data for the legally mandated period (typically 5–10 years under Brazilian law).

When data reaches the end of its retention period, we ensure it is securely deleted from active systems and purged from backups within a reasonable additional window of up to 90 days, depending on backup rotation cycles.

Data Security

Given that our core business is delivering security-critical financial infrastructure to banks and payment institutions, information security is foundational to how we operate — not an afterthought. We apply the same rigour to protecting our own website visitors' data as we apply to protecting our clients' financial systems.

Technical and organisational measures we maintain to safeguard personal data include:

  • Transport Layer Security (TLS 1.2 or higher) encryption for all data in transit between your browser and our servers
  • Encryption of sensitive data at rest using industry-standard algorithms
  • Access controls based on the principle of least privilege — only personnel with a genuine operational need can access personal data
  • Regular security reviews of third-party processors and assessment of their certification status (e.g. ISO 27001, SOC 2)
  • Internal data handling policies, including confidentiality obligations for all staff who handle personal data
  • Incident response procedures, including defined timelines for notifying ANPD and affected individuals in the event of a data breach that poses a risk to rights and freedoms

No transmission over the internet can be guaranteed to be completely secure. While we take all commercially reasonable precautions, we cannot provide an absolute guarantee against interception by unauthorised parties. If you believe your interaction with us has been compromised in any way, please contact us immediately using the details in the final section of this policy.

Your Rights

Under LGPD and GDPR, you hold a meaningful set of rights over your personal data. We are committed to honouring these rights fully and without undue delay — generally within 30 days of receiving a verifiable request, extendable by a further 30 days in complex cases with notice to you.

Right of Access

You may request a clear, readable copy of the personal data we hold about you, the purposes for which we process it, and the categories of recipients with whom it has been shared.

Right of Correction

If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected or supplemented promptly.

Right of Erasure

You may ask us to delete your personal data. We will do so unless retention is required for a legal obligation, the establishment of legal claims, or another compelling legitimate purpose.

Right to Portability

Where technically feasible and legally applicable, you may request that data you provided to us be transferred to another controller in a structured, machine-readable format such as CSV or JSON.

Right to Object

Where we rely on legitimate interest as the legal basis for processing, you may object to that processing. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.

Right to Withdraw Consent

Where processing is based on your consent (for example, analytics cookies), you may withdraw that consent at any time without affecting the lawfulness of prior processing.

Right to Restriction

In certain circumstances — for example, while a correction request is being verified — you may ask us to restrict processing of your data so it is stored but not actively used.

Right to Complain

If you are unsatisfied with our response, you have the right to lodge a complaint with Brazil's Autoridade Nacional de Proteção de Dados (ANPD) or, if you are in the EU/EEA, with your national data protection supervisory authority.

How to exercise your rights

To exercise any of the rights listed above, please send a written request to contato@matera-us.site with the subject line "Data Rights Request". To protect your privacy and prevent unauthorised access to your data, we may ask you to provide reasonable verification of your identity before processing the request. We will acknowledge receipt within 5 business days and respond fully within 30 calendar days. We will not charge a fee for requests made in good faith.

Children's Privacy

This website is directed exclusively at business professionals and corporate organisations operating in the financial services, fintech, and technology sectors. It is not intended for, and does not knowingly address, individuals under the age of 18. We do not knowingly collect personal data from minors. Under LGPD (Art. 14) and GDPR (Art. 8), special protections apply to the processing of children's data, and we take these obligations seriously.

If we become aware that we have inadvertently collected personal data from a person under 18 years of age — for example, through an unsolicited email — we will promptly delete that data from our records. If you are a parent or guardian and believe we may have received information from a minor, please contact us immediately at contato@matera-us.site so we can investigate and take appropriate action.

Changes to This Policy

Privacy law is a dynamic area, and our data practices may evolve over time as our services expand or as regulatory requirements change. We reserve the right to update this Privacy Policy at any time. When we make changes, we will update the "Last updated" date at the top of this page and, where the changes are material, we may take additional steps to bring them to your attention — such as placing a notice on our homepage for a period after publication.

We encourage you to review this page periodically, particularly if you are in regular contact with us. Your continued engagement with our website or communications following any update to this policy constitutes your acknowledgement of the revised version. If you have objections to any changes, please contact us using the details below.

Archived versions: Prior versions of this Privacy Policy are available on request. If you need a copy of the version in effect on a specific date, please write to us at contato@matera-us.site and we will provide it.

Contact & Data Controller

If you have any questions, concerns, or requests relating to this Privacy Policy or to the way we handle your personal data, please do not hesitate to contact us. We aim to respond to all privacy-related correspondence within 5 business days.

You may also write to us by post if you prefer. All data rights requests submitted by post will receive the same consideration as those submitted by email, though postal responses may take longer given international delivery times.

Matera Systems Informática SA

CNPJ: 57.040.040/0001-84

Registered Address: Avenida Selma Parada (Bailarina), 505, Conj 701, Andar 7, Jardim Madalena, Campinas — SP, Brazil

Privacy & Data Protection enquiries: contato@matera-us.site

If you are located in Brazil, you also have the right to submit a complaint directly to the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd. EU/EEA residents may contact their national supervisory authority.