Appendix III - Standard Contractual Clauses (EU) - Annex II

ANNEX II - TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Hotmart's Information Security program consists of a broad process that, within the scope of the defined principles and objectives, guides the implementation of information management controls and instruments, among which stand out:

  • Data and information classification: The classification is determined based on the value of the information, its sensitivity, criticality, and applicable legal or contractual obligations. The Company defines labeling categories that must be observed and applied internally during the handling and processing of information.
  • Property rights: The Company ensures respect for all aspects of intellectual property present in its environment and operations. It is everyone's duty to refrain from using Hotmart's information or intellectual property for private purposes.
  • Management and definitions of information asset use: At Hotmart, information assets are protected against unauthorized access, and employees must observe the care required for each activity, acting with integrity and discernment when using Company equipment.
  • Access management: The Company adopts formal procedures for access management across its entire IT environment, encompassing Granting, Revocation, Transfer, Review, and Authentication of Accesses.
  • Change management: Hotmart employs various controls to manage code review processes, ensure the integrity and continuity of developed systems, track and version code, test, and manage the continuous integration cycle.
  • Network and encryption management: Through the management of its networks, Hotmart maintains the secure flow of data across its systems, ensuring network segmentation and the use of secure configuration standards and strong encryption.
  • Vulnerability management: Hotmart performs recurring scans and tests in its IT environment by a specialized security testing team to assess failures and vulnerabilities in its systems, whose remediation is handled by its cybersecurity and secure development teams.
  • Malware protection: Protection mechanisms are implemented against malicious code at entry and exit points of the company's systems. These points include, but are not limited to, firewalls, remote access servers, workstations, email servers, web servers, proxy servers, and mobile devices.
  • Vendor management: Based on the information received and internal verification, the risks associated with contracting each vendor are evaluated to ensure compliance with the Company's cybersecurity, data privacy, and information security rules, depending on the services provided.
  • Maintenance and analysis of audit logs: Automated audit trails are implemented across Hotmart's system components, enabling the tracking of security events, authentication, and user actions.
  • Information leakage prevention: Hotmart applies information transmission controls in its IT environment through automated solutions that detect, restrict, and alert to unauthorized data circulation. The controls are associated with the classification of this information.
  • Backup and contingency management: To securely maintain and safeguard Hotmart's data, periodic backups and recovery tests of its systems' functionality are conducted to ensure the continuity of its operations.
  • Information security training and awareness: With the objective of disseminating knowledge and promoting continuous improvement, the Company conducts periodic training and promotes awareness-raising initiatives related to Cybersecurity and Information Security, covering all employees and third parties who access the Company's technology environment.
  • Incident management: In the event of any inconsistency or failure in the Hotmart environment identified by the external public, the Company provides a channel for receiving the respective communication via email cybersecurity@hotmart.com.

The Company complies strictly with the applicable legislation and regulations governing information security and data protection. Our internal norms and procedures outline the criteria for communicating relevant incidents to specific regulatory and supervisory bodies.