Updated: January 1, 2025.
Wish Group S/A
Headquarters: Sao Paulo
CNPJ: 07.687.928/0001-35
The purpose of this Policy is to demonstrate the Wish Group's commitment to safeguarding your privacy and protecting your Personal Data, establishing the rules on Processing, as well as explaining what your rights are and how to exercise them, within the scope of the services and features of the websites listed below (“Website”) and the application called Exclusive Guest (“Application”), in accordance with the laws in force, with transparency and clarity:
Please read this Policy carefully and, if you still have questions, feel free to contact us through the Service Channels available here.
For a better understanding of this Policy, the following definitions should be considered:
If you are over 60 years old, please be aware that we are aware of the risk of processing your personal data and we are committed to taking all appropriate measures to protect it. Furthermore, we are committed to processing it in a manner that:
How we process Data. Data may be processed when you interact with Our Environments
Notify about any changes to this Policy, if necessary and in the event of legitimate interest.
Algorithmic instruction: the database formed will be used to instruct algorithms in order to improve the browsing experience and data may be collected automatically, such as characteristics of the access device, browser, IP (with date and time), origin of the IP, information about clicks, pages accessed, the next pages accessed after leaving the Pages, or any search term entered on the website or in reference to it, among others. For such collection, standard technologies may be used, such as cookies, pixel tags, beacons and local shared objects, which are used with the purpose of improving the User's browsing experience on the Pages, according to their habits and preferences.
Data Update and Accuracy. You are solely responsible for the accuracy, accuracy or updating of the data you provide to us. We are not obliged to process your data if there are reasons to believe that such processing may impute us to a violation of any applicable law, or if you are using our environments for any illegal or illicit purposes.
Database. The database created through the collection of Data is our property and is under our responsibility, and its use, access and sharing, when necessary, will be done within the limits and purposes described in this Policy.
Data sharing hypotheses. The Data processed and the recorded activities (logs) may be shared:
If you have any questions about who we share your Data with, please contact us through the Service Channels provided at the end of this Policy.
Data Anonymization. For the purposes of market intelligence research, press releases and advertising, the Data will be shared in an anonymized manner, in a way that does not allow your identification.
Security and Governance Practices. To safeguard your privacy and protect your Data, we have a governance program that contains rules of good practices, internal policies and procedures, which establish conditions for organization, training, educational actions and mechanisms for supervision and mitigation of risks related to the Processing of Personal Data.
Access to Data, proportionality and relevance. Internally, the Data processed is accessed only by duly authorized professionals, respecting the principles of proportionality, necessity and relevance for the objectives of our business, in addition to the commitment to confidentiality and preservation of your privacy under the terms of this Policy. In the event of individual leaks or unauthorized access to your Personal Data, we may promote, provided that these represent significant harm or risk to you and you agree, direct conciliation under the terms of art. 52, § 7, of the General Personal Data Protection Law.
Sharing passwords. You are also responsible for the confidentiality of your Personal Data and must always be aware that sharing passwords and access data violates this Policy and compromises the security of your Personal Data and the Website and Application.
Precautions You Should Take. It is very important that You take the necessary precautions against unauthorized access to your computer/smartphone, account or password, and that You always click “Exit” when ending your browsing on a shared computer. WISH GROUP never sends emails requesting data confirmation or with attachments that can be executed (extensions: .exe, .com, among others) or links for possible downloads. If You identify or become aware of a compromise in the security of Your Data, please contact our Officer through the Service Channels provided at the end of this Policy.
Information Security. All credit card payment transactions are executed using SSL (secure socket layer) technology, ensuring that your Personal Data is not unlawfully disclosed. In addition, this technology aims to prevent information from being transmitted or accessed by third parties.
External links. When using the Website and Application, You may be directed, via link, to third-party platforms that may collect your information and have their own Data Processing Policy. It is Your responsibility to read the Privacy Policies of such third-party platforms, and it is Your responsibility to accept or reject them. We are not responsible for the Privacy Policies of third parties or for the content or services of any websites other than our own.
Processing by third parties under our guidelines. We seek to carefully evaluate our partners and service providers and enter into contractual obligations with them regarding confidentiality, information security and data protection, with the aim of protecting you.
Email Communication. In order to optimize and improve our communication, when we send you an email, we may receive a notification when it is opened, provided that this option is available. It is important that you be aware that emails are only sent from the domains “@grupowish.com” or “@exclusiveguest.com”.
Storage location. The Data processed and activity records (logs) are stored in a secure and controlled environment, which may be on our servers located in Brazil, as well as in an environment where resources are used or servers in the cloud (cloud computing), which may require the transfer and/or processing of your Data outside of Brazil. These transfers only involve companies that demonstrate compliance with applicable laws, maintaining a level of compliance similar to or more rigorous than that provided for in Brazilian law.
Storage period. We store Data only for as long as necessary to fulfill the purposes for which it was processed or to comply with any legal or regulatory obligations or to preserve rights.
Data Disposal. After the maintenance period and legal necessity have expired, the Data will be deleted using secure disposal methods or used in an anonymized form for statistical purposes.
Your basic rights. The Data is yours and the applicable Legislation provides a series of rights related to it, which may be exercised by you by making a request to our Officer through the Customer Service Channel available at the end of this Policy.
Request. For your security, whenever you submit a request to exercise your rights, we may request additional information to verify your identity, seeking to prevent fraud.
Failure to comply with requests. We may fail to comply with a request to exercise rights if such compliance violates our intellectual property or trade secrets, or when there is a legal or regulatory obligation to retain Data. In addition, we may fail to comply with your request if we need to retain the Data to enable our defense or that of third parties in disputes of any nature.
Responses to requests. We undertake to respond to all requests within a reasonable time and always in compliance with applicable legislation.
Change of content and updating. You acknowledge our right to change the content of this Policy at any time, depending on the purpose or need. If there are relevant updates to the Policy, you will be notified through the contact details you provide us or by posting them on our official profiles.
Inapplicability. If any point of this Policy is considered unenforceable by a Data Authority or court, the remaining conditions will remain in full force and effect.
Service Channels. If you have any questions regarding the provisions contained in this Policy, including the exercise of your rights, you may contact our Officer, who is available at the following addresses:
Applicable Law. This Policy shall be interpreted in accordance with Brazilian law, in the Portuguese language.
Update: 01/01/2025