Privacy Policy
Effective date: July 15, 2026·Version: 3.0·Replaces: 2.0 (July 15, 2026)
Applies to: Fenix DFA S.r.l. (Italy) · Fenix DFA Corp. (United States) · Fenix DFA Ltda. (Brazil)
1. Who We Are and How to Contact Us
This Privacy Policy is issued jointly by the following legal entities, collectively referred to as "Fenix DFA," "we," "us," or "our":
- Fenix DFA S.r.l., a company incorporated and registered under the laws of Italy, acting as data controller for individuals located in the European Economic Area (EEA). Registered address: Via Umberto Broggi, 3 – Arona (NO) – 28041, Italia. P.IVA: 02845390034.
- Fenix DFA Corp., a corporation organized under the laws of the State of Florida, United States, acting as data controller for individuals located in the United States and other territories not covered by the entities below. Registered address: 2 S. Biscayne Blvd, Ste 2450, Miami, FL 33131, USA.
- Fenix DFA Ltda., a company organized under the laws of Brazil, acting as data controller for individuals located in Brazil. Registered address: Rua Manoel Coelho, 676, Cj. 516, São Caetano do Sul, SP, Brasil – 09510-101. CNPJ: 54.241.446/0001-37.
Data Protection Contact
For privacy-related inquiries, requests to exercise your rights, or to contact our Data Protection Officer (DPO), please reach us at:
- Email: privacy@fenixdfa.com
- Postal address: Via Umberto Broggi, 3 – Arona (NO) – 28041, Italia (for GDPR matters)
For data subjects in Brazil, the Encarregado pelo Tratamento de Dados Pessoais (Data Protection Officer) as required by LGPD Art. 41 is reachable at the same address: privacy@fenixdfa.com.
2. Scope and Definitions
This Policy applies to Personal Data collected through:
- The Fenix DFA website and any subdomains (collectively, the "Site");
- The Fenix DFA SaaS platform and related software ("Platform");
- Marketing, contact, and sales communications, including by telephone and email;
- Partner onboarding and the Partner Program;
- The Resilience Gap Assessment and related service engagements.
Key Definitions
"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable law, including "personal information" under the CCPA, "dados pessoais" under the LGPD, and "personal data" under the GDPR.
"Processing" means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, erasure, or destruction.
"Third Party" means any entity that is not a Fenix DFA legal entity listed in Section 1, not a direct employee or contractor acting under a confidentiality obligation, and not an Essential Service Provider as defined in Section 6.
3. Information We Collect
3.1 Information You Provide Directly
- Identity and contact data: full name, job title, company name, business email address, and business telephone number;
- Assessment and engagement data: information provided during the Resilience Gap Assessment, including IT infrastructure details, backup tool inventories, and organizational contacts;
- Partner program data: company details, partner type, country, expected deal volume, and signatory information;
- Communications data: the content of emails, messages, or inquiries you send us.
3.2 Information We Collect Automatically
- IP address and approximate geolocation (country/city level);
- Browser type, device type, and operating system;
- Pages visited, time spent, referring URLs, and clickstream data;
- Cookies and similar tracking technologies (see Section 10).
3.3 Information We Do Not Collect
We do not collect special categories of sensitive Personal Data (e.g., health, biometric, racial or ethnic origin, political opinions) except where strictly required for regulatory compliance services and with your explicit consent. We do not collect payment card details directly, payment processing is handled by PCI-DSS-compliant third-party processors.
4. How We Use Your Information and Lawful Basis
We process Personal Data only for the purposes and on the lawful bases set out below. Where multiple jurisdictions apply, the most protective standard governs.
| Purpose | Examples | Lawful Basis (GDPR) | Lawful Basis (LGPD) |
|---|---|---|---|
| Responding to inquiries and providing requested services | Contact form responses, assessment delivery | Art. 6(1)(b): performance of a contract / pre-contractual steps | Art. 7(V): performance of contract |
| Marketing by email to existing or prospective clients | Newsletters, product announcements, event invitations | Art. 6(1)(f): legitimate interests (B2B) / Art. 6(1)(a): consent (B2C) | Art. 7(IX): legitimate interests / Art. 7(I): consent |
| Partner program administration | Onboarding, commission tracking, co-sell activities | Art. 6(1)(b): performance of a contract | Art. 7(V): performance of contract |
| Legal compliance and regulatory obligations | Responding to audits, court orders, DORA compliance | Art. 6(1)(c): legal obligation | Art. 7(II): compliance with legal obligation |
| Product improvement and analytics | Usage analytics on anonymized data | Art. 6(1)(f): legitimate interests | Art. 7(IX): legitimate interests |
| Security and fraud prevention | IP monitoring, anomaly detection | Art. 6(1)(f): legitimate interests | Art. 7(IX): legitimate interests |
5. Telephone Numbers and SMS Communications
We collect business telephone numbers when voluntarily provided through our contact, inquiry, or partner application forms, or in the course of a commercial engagement. In the United States, our SMS communications are sent via Zoom Phone, operating through registered 10-Digit Long Code (10DLC) channels in compliance with carrier requirements and applicable federal law.
5.1 How We Use Telephone Numbers
Telephone numbers are used solely to contact you in connection with your inquiry, engagement, or the services you have requested. SMS messages from Fenix DFA may include:
- Appointment confirmations and reminders for assessment calls or demo sessions;
- Follow-up messages related to your inquiry or engagement;
- Status updates on your Resilience Gap Assessment;
- Operational alerts relevant to your account.
We do not use telephone numbers for unsolicited marketing campaigns or bulk promotional SMS.
5.2 Consent
We send SMS messages only where you have provided affirmative prior consent, obtained through an explicit opt-in at the time your telephone number was provided. Consent records, including date, method, and the disclosure presented, are retained as required by applicable law.
5.3 Opt-Out and Assistance
You may withdraw your SMS consent at any time and at no cost by:
- Replying STOP to any SMS from Fenix DFA. You will receive a single confirmation and no further SMS will be sent;
- Emailing privacy@fenixdfa.com with subject line "SMS Opt-Out" and your mobile number.
Reply HELP to any message for assistance. Message frequency varies. Standard message and data rates may apply. Withdrawing SMS consent does not affect other communications (e.g., email) for which a separate basis exists.
Fenix DFA does not sell, rent, lease, or share telephone numbers with any third party for marketing, advertising, lead-generation, or any commercial purpose whatsoever. This restriction applies worldwide, without exception, and includes affiliates, resellers, and channel partners.
6. Data Sharing and Disclosure
6.1 General Principle
We do not sell, rent, lease, or trade Personal Data. We share Personal Data only in the limited circumstances described in this Section.
6.2 Essential Service Providers
We engage carefully selected third-party service providers ("Essential Service Providers") that support the operation of our Platform, Site, and business. These providers are authorized to process Personal Data only as necessary to perform their specific service function, under written data processing agreements that impose confidentiality, security, and data protection obligations at least equivalent to those in this Policy. Current categories of Essential Service Providers include:
- Cloud infrastructure and hosting providers;
- Customer relationship management (CRM) software providers;
- Email delivery and marketing automation platforms;
- Payment processing providers (who receive payment data directly from you and are independently PCI-DSS compliant);
- Analytics and performance monitoring tools;
- Legal, financial, and professional advisory services.
6.3 Regulatory Authorities and Law Enforcement
We may disclose Personal Data to regulatory authorities, courts, law enforcement agencies, or other government bodies where we are required to do so by applicable law, valid legal process, or a binding order. We will disclose only the minimum data necessary to satisfy the specific legal obligation.
6.4 Corporate Transactions
In connection with a merger, acquisition, divestiture, restructuring, or sale of all or substantially all of our assets, Personal Data may be transferred to the successor entity as part of that transaction. Any such transfer will be subject to the terms of this Policy, and individuals will be notified of any material change in data controller identity or processing purposes.
6.5 What We Do Not Do
Fenix DFA does not and will not:
- sell, rent, lease, or trade any Personal Data, including telephone numbers, to any Third Party for any commercial purpose;
- share Personal Data with affiliates, resellers, or channel partners for their own independent marketing activities;
- use Personal Data collected for one purpose to authorize any Third Party to contact you for a different purpose.
7. International Data Transfers
Fenix DFA operates across multiple jurisdictions. Personal Data collected in the EEA may be transferred to and processed in countries outside the EEA (including the United States and Brazil). Similarly, data collected in Brazil may be processed in Italy or the United States.
7.1 Transfers from the EEA
Where we transfer Personal Data from the EEA to a country not recognized by the European Commission as providing an adequate level of protection, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914/EU), incorporated into our data processing agreements with service providers.
7.2 Transfers from Brazil
Where we transfer Personal Data from Brazil to countries outside Brazil, we rely on standard contractual clauses or other mechanisms approved by the Brazilian Autoridade Nacional de Proteção de Dados (ANPD) under LGPD Article 33, or on adequacy recognition by the ANPD for the destination country, where available.
8. Data Retention
We retain Personal Data for no longer than necessary for the purposes for which it was collected, taking into account applicable legal, tax, accounting, and regulatory requirements.
| Category | Retention Period | Basis |
|---|---|---|
| Contact and inquiry data (no engagement) | 24 months from last interaction | Legitimate interests (follow-up) |
| Customer and partner data | Duration of relationship + 7 years | Legal obligation (accounting, tax, contractual) |
| Assessment engagement data | Duration of engagement + 5 years | Contractual, legal obligation |
| SMS / telephone opt-out records | Indefinitely (suppression list) | Legal obligation (to prevent re-contact) |
| Website analytics data | Up to 26 months | Legitimate interests |
| Security and access logs | 12 months | Legitimate interests, legal obligation |
Opt-out records are retained indefinitely to ensure that individuals who have opted out are never re-contacted through the channel they opted out of.
9. Your Rights
9.1 Rights Under GDPR (EEA Residents)
If you are located in the European Economic Area, you have the following rights under GDPR:
- Right of access (Art. 15): obtain confirmation of whether we process your Personal Data and receive a copy;
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data;
- Right to erasure (Art. 17): request deletion of your data, subject to legal retention obligations;
- Right to restriction of processing (Art. 18): request that we limit processing in certain circumstances;
- Right to data portability (Art. 20): receive your data in a machine-readable format or have it transferred to another controller;
- Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing purposes;
- Right to withdraw consent (Art. 7(3)): withdraw any previously given consent at any time without affecting the lawfulness of prior processing.
You also have the right to lodge a complaint with your national supervisory authority. In Italy: Garante per la protezione dei dati personali (garanteprivacy.it).
9.2 Rights Under LGPD (Brazilian Residents)
If you are located in Brazil, you have the following rights under LGPD (Art. 18):
- Confirmation of the existence of processing;
- Access to your Personal Data;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary or excessive data;
- Portability of data to another service or product provider;
- Deletion of Personal Data processed with your consent;
- Information about Third Parties with whom we share data;
- Revocation of consent (Art. 8, §5) at any time, free of charge. We will process revocation requests within 15 business days.
You have the right to file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
9.3 US Residents (State Privacy Laws)
Depending on your state of residence, you may have additional rights under applicable state privacy laws (e.g., California CCPA/CPRA, Virginia VCDPA, and others). We do not sell Personal Data as defined under any applicable US state privacy statute. To exercise your rights or submit a Do-Not-Sell-or-Share request, contact us at privacy@fenixdfa.com.
9.4 Exercising Your Rights
To exercise any of the above rights, contact us at privacy@fenixdfa.com. We will respond within 30 days (or the shorter period required by applicable law). We may need to verify your identity before processing your request.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to operate our Site, analyze traffic, and (where you have consented) to deliver targeted content. You can manage cookie preferences at any time through your browser settings or our cookie consent tool.
We do not use tracking technologies to collect telephone numbers or to associate telephone numbers with behavioral or advertising profiles.
11. Data Security
We implement technical and organizational security measures appropriate to the nature of the Personal Data we process, including encryption in transit and at rest, access controls, audit logging, and regular security assessments.
No method of electronic transmission or storage is 100% secure. If you believe your Personal Data has been compromised or you have identified a security vulnerability, contact us immediately at privacy@fenixdfa.com.
In the event of a Personal Data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authorities and, where required, affected individuals, within the timeframes required by applicable law (72 hours under GDPR Art. 33; as required under LGPD Art. 48).
12. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, applicable law, or our business. When we make material changes, we will:
- update the "Effective date" at the top of this Policy;
- provide a notice of key changes at the top of this page for 60 days following the update; and
- where required by applicable law or where the change materially affects your rights, notify you directly by email.
Your continued use of our Site or services following notification of a material change constitutes your acknowledgment of the updated Policy, to the extent permitted by applicable law. For changes that require fresh consent (e.g., new processing purposes, new categories of data), we will seek your consent before the change takes effect.
This Privacy Policy was last reviewed on July 15, 2026. Questions? Contact us at privacy@fenixdfa.com.