_Version 2.0 | Effective as of August 4, 2026 | Last updated: 08/04/2026_
_Unofficial translation. The Portuguese version of this document prevails in the event of any discrepancy._
1. PRIVACY, DATA PROTECTION AND COMMUNICATIONS
1.0. Identification of the controller
1.0.1. The controller of the personal data processed within the AMAZOCA Platform is AMAZOCA GESTÃO DE DADOS E PLATAFORMA DIGITAL LTDA, a private legal entity registered under CNPJ (Brazilian corporate taxpayer registry) No. 62.416.583/0001-93, with:
- a) its tax address at Av. Frei Vicente, No. 800, Room 03, Aeroporto Velho neighborhood, ZIP code 68020-790, Santarém - PA, Brazil; and
- b) its administrative headquarters at Av. Frei Vicente, No. 800, Room 03, Aeroporto Velho neighborhood, ZIP code 68020-790, Santarém - PA, Brazil.
1.0.2. The contact channels for exercising data subject rights and for questions about this Policy are set out in item 1.7.
1.0.3. In the situations described in item 1.1-A.2, ASAAS GESTÃO FINANCEIRA INSTITUIÇÃO DE PAGAMENTOS S.A. acts as an independent controller, with its own channels set out in item 1.7-A.
1.1. Privacy Policy and the LGPD
1.1.1. The processing of personal data carried out by AMAZOCA shall be governed by this Privacy Policy, by the Platform's Terms of Use, available at https://www.amazoca.com/en/terms-of-security, and by Applicable Law, in particular Law No. 13,709/2018, the Brazilian General Data Protection Law (LGPD).
1.1.2. This Policy describes which data is collected, how it is used, with whom it may be shared, how long it is stored and what rights data subjects have.
1.1.3. This Policy is an integral part of the AMAZOCA Platform's Terms of Use. In the event of a conflict between the Terms and this Policy on data protection matters, the interpretation most protective of the data subject shall prevail, pursuant to the LGPD.
1.1-A. Roles in data processing and the BaaS model
1.1-A.1. AMAZOCA is the controller of the personal data processed to operate the Platform: User registration, listings, bookings, communication between Guests and Hosts, reviews, support and calculation of amounts.
1.1-A.2. ASAAS GESTÃO FINANCEIRA INSTITUIÇÃO DE PAGAMENTOS S.A., a payment institution authorized by the Central Bank of Brazil, is the independent controller of the personal data processed for the provision of financial and payment services, including opening and maintaining the payment account, identity verification (KYC), prevention of money laundering and terrorist financing (AML/CFT), fraud prevention, transaction processing and record retention required by regulation.
1.1-A.3. In the situations described in item 1.1-A.2, ASAAS's own privacy policy applies, made available to the user when the payment account is opened and through that institution's official channels.
1.1-A.4. AMAZOCA does not store sensitive payment instrument data, such as full card number, expiration date and security code (CVV), which are collected and processed directly within the ASAAS environment.
1.2. Personal data collected: overview
1.2.1. In general terms, AMAZOCA may collect the following categories of personal data:
- a) Registration data: full name, CPF/CNPJ (individual/corporate taxpayer registry), date of birth, e-mail, phone number, address, Guest/Host profile data, company data (where applicable);
- b) Platform usage data: information about browsing, searches, bookings made, Listings created, communication history, reviews and interactions with other Users;
- c) Payment and payout data: partially masked billing data, transaction status and identifiers, amounts, payouts, chargebacks, refunds and the receiving account indicated by the Host;
- d) Device and connection data: IP address, browser type, operating system, device identifiers, access date and time records, cookies and similar technologies;
- e) Approximate location data, when authorized by the User or inferred from the IP address;
- f) User Content: photos, descriptions, reviews, comments, messages and documents voluntarily submitted;
- g) Verification and compliance data: copies of identification documents, proof of address, corporate documents, licenses and permits, required for identity verification, Host regularity checks or fraud prevention.
1.2.2. The data described in items "c" and "g" may be collected directly by ASAAS, or required by it through the AMAZOCA interface, in order to comply with the regulatory obligations for opening and maintaining a payment account, KYC and AML/CFT.
1.3. Purposes and legal bases
1.3.1. The processing of personal data by AMAZOCA has the following main purposes:
- a) enabling User registration and authentication on the Platform;
- b) enabling technological intermediation between Guests and Hosts, including Booking management, calculation of amounts and support;
- c) enabling the opening and maintenance of the payment account with ASAAS and the processing of transactions, by sharing the necessary data;
- d) preventing fraud, unauthorized access and misuse of the Platform;
- e) complying with legal, regulatory, tax and accounting obligations;
- f) improving the User experience;
- g) sending transactional communications, such as booking confirmations, check-in/check-out notices, contractual changes or security notifications;
- h) sending marketing communications, where permitted.
1.3.2. The main legal bases used by AMAZOCA include:
- a) performance of a contract or preliminary procedures;
- b) compliance with a legal or regulatory obligation, including, in the case of ASAAS, obligations arising from Central Bank of Brazil regulations and anti-money laundering legislation;
- c) legitimate interest of AMAZOCA or third parties, duly assessed;
- d) consent of the data subject, where required by law.
1.3.3. The User, as a data subject, has the rights set out in the LGPD, such as confirmation of the existence of processing, access, correction, anonymization/blocking/deletion, portability, deletion of data processed on the basis of consent, information about sharing, and withdrawal of consent.
1.3.4. The exercise of rights relating to data processed by ASAAS as an independent controller (for example, KYC data and payment transaction data) must be directed to that institution through the channels set out in item 1.7-A. AMAZOCA may assist in forwarding the request.
1.3.5. The User acknowledges that certain data relating to financial transactions cannot be deleted upon request, due to the statutory retention periods imposed by Central Bank regulations and anti-money laundering legislation.
1.4. Sharing data with third parties
1.4.1. AMAZOCA may share personal data with third parties strictly necessary for the operation of the Platform, such as:
- a) ASAAS GESTÃO FINANCEIRA INSTITUIÇÃO DE PAGAMENTOS S.A., as the payment institution responsible for opening the payment account, processing transactions, settlement, payouts and compliance with regulatory obligations;
- b) other financial institutions, banks and payment arrangements involved in settling transactions;
- c) technology infrastructure providers, such as cloud hosting services, e-mail providers and monitoring and security systems;
- d) partner companies that assist with fraud prevention, risk analysis, identity verification and compliance;
- e) public authorities, regulators, police or judicial authorities, where there is a legal obligation, court order or legitimate request;
- f) legal and accounting advisors and other professional service providers, where necessary to defend rights or comply with AMAZOCA's obligations.
1.4.2. In any sharing scenario, AMAZOCA will make reasonable efforts to ensure that third parties observe adequate security and data protection standards, consistent with the LGPD.
1.4.3. Sharing data with ASAAS is a necessary condition for using the Platform's financial features (receipt of funds by Hosts and payment of Bookings by Guests). Refusal to provide the required data will prevent the use of those features.
1.5. Information security
1.5.1. AMAZOCA adopts reasonable technical and administrative measures to protect personal data against unauthorized access, accidental loss, destruction, alteration or improper disclosure, such as role-based access control, use of encryption and secure protocols, access monitoring and log records, and internal information security and confidentiality policies.
1.5.2. Despite the measures adopted, no digital environment is entirely immune to risk, which is why AMAZOCA cannot guarantee absolute security, undertaking to act with diligence and transparency in the event of security incidents, in accordance with the LGPD.
1.5.3. The security of the financial payment operation, including transaction authentication, anti-fraud monitoring and protection of payment instrument data, is the responsibility of ASAAS, even where the journey begins in the AMAZOCA interface.
1.6. Communications, notifications and marketing
1.6.1. By using the Platform and providing contact details, the User authorizes AMAZOCA to send essential and transactional communications, such as:
- a) confirmations of registration, bookings, payments and payouts;
- b) notices about relevant changes to the Accommodation, the Listing or the Booking;
- c) notifications about changes to the Terms of Use or to this Privacy Policy;
- d) security alerts, suspicious access attempts or password recovery.
1.6.1-A. Communications involving the movement or management of funds, such as the welcome e-mail for opening a payment account, payment confirmations, receipts and payout notices, identify ASAAS as the provider of the financial service, by means of a seal and/or textual mention.
1.6.2. AMAZOCA may send marketing communications, such as offers, content, news and promotions, on the basis of legitimate interest, where there is a prior relationship with the User, or on the basis of consent, where required by Applicable Law.
1.6.3. The User may, at any time, opt out of marketing communications through the unsubscribe link included in e-mail messages, through the notification settings available on the Platform, or through the official contact channels.
1.6.4. Opting out of marketing communications will not prevent the sending of transactional and essential communications required for the provision of the services.
1.7. Contact channels of the Data Protection Officer (DPO)
1.7.1. AMAZOCA's Data Protection Officer is Mr. Luydi Matheu Bentes Sousa.
1.7.2. Requests, questions, complaints and data subject petitions relating to personal data processed by AMAZOCA may be sent to the Data Protection Officer through the following channels:
E-mail: privacidade@amazoca.com.br
1.7.3. AMAZOCA will respond to data subject requests within the time frames and under the conditions set out in the LGPD, and may request additional information to confirm the identity of the requester before fulfilling the request.
1.7-A. ASAAS channels
1.7-A.1. Requests relating to personal data processed by ASAAS as controller, in particular payment account data, KYC, transactions and regulatory records, must be directed to ASAAS:
Phone: 0800 009 0037 (legal entities only)
Messages: 0800 009 0037 (messages only)
E-mail: contato@asaas.com.br