Investor Presentaiton slide image

Investor Presentaiton

Л ||| Governance and integrity Risk management At Viveo, risk management is based on three lines of defense, permeating the processes of evaluation, identification, analysis, treatment, monitoring, and communication of events that adversely affect the achievement of the company's objectives. Risks are communicated in a clear and objective manner, with all pos- sible relevant information, to all affected and/ or responsible parties, and in particular to those responsible for the determination and develop- ment of risk treatment measures. As an integral part of this management, Viveo promotes poli- cy training, applicable to all employees. In 2021, the certification process according to ISO 37001 was initiated. This evaluation of the company's processes and practices as meeting the require- ments of the standard is expected to be com- pleted in 2022. Office Ribeirão Preto (SP) Information security GRI 418-1 In order to comply with the General Data Protection Law (GDPT), in 2020 the company also began devel- oping activities aligned with the best practices, such as mapping of personal data, flow of the life cycle of personal data, construction of the risk matrix, and evaluation of criticality of processes. These actions involved more than a thousand mapped processes and 200 hours of interviews with Viveo employees, resulting in a specific action plan. After the appointment of the Data Protection Of- ficer (DPO), the multidisciplinary Data Protection Committee was established in 2021, responsible for the dissemination of good practices. In the first months of operation, the committee drew up regu- lations and suggested a set of clauses for inclusion in the contracts signed by the company in order to ensure the protection and privacy of data under the management of Viveo. The entire process of adaptation to the GDPT in- cluded the training of employees, with educational content regarding risks and acceptable practices related to the topic. A service channel was also cre- ated for the owners of personal data and is widely disseminated, contributing to preserve the rights list- ed in the GDPT. In 2021, Viveo received three formal requests re- garding the treatment of personal data, which have since been resolved. None of the requests were from regulatory agencies and were not related to leaks, theft, or loss of customer data. viveo 34 Sustainability Report 2021
View entire presentation