Doris
PRIVACY POLICY - DORIS MIRROR
Last updated: 06/02/2025 V7
pRIVACY POLICY
1. Introduction

1.1 This Policy describes the processing activities of Your Personal Data, which are essential for the operation of Doris.MOBI's Virtual Fitting Room, known as “Doris Mirror”, and for providing our services.

1.2 In order to function, Doris.MOBI’s Doris Mirror requires Personal Data provided by You, which is processed and used to enable and improve the services provided by Doris.MOBI and/or its Licensees.

1.3 When You use our services and products, You provide Doris.MOBI and/or its Licensees with information and Personal Data through the submission of images.

1.4 It is very important that You read the provisions of this Policy each time You use the Virtual Fitting Room, to understand how we collect and process Your Personal Data. We would like to emphasize that Doris.MOBI and its Licensees do not sell Your Personal Data to Third Parties.

2. Meaning of Terms Used in this Policy

2.1 The following terms, whenever used or capitalized, will have the meanings described below:

Anonymized Data: means any data related to the data subject that cannot be identified, considering the use of reasonable technical means available at the time of its processing. Anonymized Data will not be considered Personal Data for the purposes of this Policy.

Applicable Law: means any law, code, decree, regulation, regulatory requirement, rule, order, instruction, declaration, ruling, resolution, judicial, arbitral, or administrative decision by any Government Authority, including, but not limited to, the LGPD and the GDPR.

Consent: means the free, informed, unequivocal, and specific manifestation of the data subject, expressed through a clear affirmative action, by which they agree to the processing of their Personal Data. Consent can be withdrawn at any time without affecting the legality of processing carried out while the consent was valid.

Controller: means the natural or legal person, whether public or private, responsible for deciding on the processing of Personal Data. Doris.MOBI and/or its Licensees are the Controllers and, therefore, responsible for making decisions related to the processing of User Personal Data.

Content: means any content submitted, provided, or transmitted by You.

Database: means the structured set of Personal Data, stored in one or several locations, whether physical and/or electronic, generated as a result of activities carried out by Users through the use of Doris.MOBI's Doris Mirror.

Doris.MOBI: means DORIS.MOBI TECNOLOGIA S.L., located in Barcelona, Spain, at Calle Beethoven, 15, 5th Floor, CP 08021, with tax identification number B-55484471, and registered with the Barcelona Commercial Registry under number B-617736, the owner and/or holder of the right to use the Virtual Fitting Room.

Doris.MOBI Licensees: means the entities that have received a license for use and operation of Doris, granted by Doris.MOBI, including DORIS.MOBI TECNOLOGIA S.A., located in São Paulo, Brazil, at Avenida Brigadeiro Faria Lima, nº 2.092, 10th floor, rooms E102 and E104, sala 02, Jardim Paulistano, ZIP code 01451-905, registered under CNPJ nº 19.782.186/0001-06.

Elimination: means the exclusion of Personal Data or a set of Personal Data stored in a Database, regardless of the method used.

Garment Item: means the image of a specific wearable garment that allows its virtual projection, enabling the simulation of its use by a person.

GDPR:
means the General Data Protection Regulation, which governs the processing of data within the European Union and the European Economic Area.

Government Authority: means any government, authority, governmental entity, regulatory agency, public ministry, tax authority (including, but not limited to, the Brazilian Federal Revenue and state and municipal tax authorities), commission, board, council, stock exchange, agency, or any judicial, arbitral, or administrative body with jurisdiction over Doris.MOBI and/or its Licensees and/or Users. This includes, but is not limited to, the National Data Protection Authority (ANPD) in Brazil, and the data protection supervisory authorities established by the GDPR in the European Economic Area (EEA), such as the European Data Protection Board (EDPB).

Image: means, in reference to a natural person, any form of representation, including photographs, of the human figure, visual appearance, facial expression, gestures, distinct body parts, expressions of personality, name, surname, nicknames, aliases, and pseudonyms, as well as the audiovisual process resulting in the fixation of images with or without sound, with the purpose of creating, through reproduction, the impression of movement, regardless of the processes used to capture, store, or transmit the image, including, but not limited to (i) newspapers, magazines, brochures, marketing materials, catalogs, and/or any other printed media; (ii) fashion art, painting, sculpture, drawing, photography, reprography, caricature, or decorative design; (iii) sound images from phonography and broadcasting; and/or (iv) cinematography, television, and the internet. Your Image will be captured by the Virtual Fitting Room, following specific position and distance conditions mentioned in the equipment. It will be used to allow you to virtually try on selected clothing items without the need for a physical fitting room,

International Data Transfer: means the transfer of Personal Data from the Controller's territory to a foreign country or international organization that the country is a member of.

LGPD: means Brazilian Law No. 13,709/2018 and its respective regulations as they may be created or amended over time.

Personal Data: means any data related to a natural person that can identify or make identifiable, directly or indirectly, including but not limited to identification numbers, images, location data, electronic identifiers, IP addresses, or any other data that, individually or in combination, allows the formation of a behavioral profile of an identified or identifiable natural person. In reference to You, Personal Data will be understood as any Personal Data submitted and/or transmitted by You through the Virtual Fitting Room of Doris.MOBI.

Policy: means this document titled “Privacy and Personal Data Protection Policy,” which contains provisions on the processing of User Personal Data when using the Virtual Fitting Room. The terms must be fully accepted by You as a condition for use.

Processor: means the natural or legal person, whether public or private, residing or headquartered inside or outside the national territory, who processes Personal Data on behalf of the Controller.

Processing: means any operation performed with Personal Data, including but not limited to collection, production, reception, classification, use, access, reproduction, transmission, sharing, distribution, processing, archiving, storage, deletion, evaluation, or control of information, modification, communication, transfer, dissemination, or extraction.

Sensitive Personal Data: means any Personal Data related to racial or ethnic origin, religious beliefs, political opinions, union membership, or affiliation to a religious, philosophical, or political organization, Personal Data related to health or sexual life, genetic or biometric Personal Data when linked to a natural person.

Shared Use of Personal Data: means the communication, dissemination, international transfer, interconnection of Personal Data, or shared processing of Databases by public bodies in compliance with their legal duties, or between these and private entities, with specific authorization, for one or more processing activities permitted by public bodies, or between private entities.

Support: means the communication channel contained in our privacy portal, available at https://portallgpd.doris.mobi
.

Terms of Use: means the document titled “Terms of Use,” which, along with this Policy, contains the general terms and conditions for the use of Doris.MOBI's solutions by Users.

User: means, without distinction, any natural person who uses the Virtual Fitting Room.

Virtual Fitting Room: means the interactive digital kiosk used in physical establishments, allowing customers to virtually try on selected garments using Your Image captured by the equipment, without the need to use a physical fitting room.

Wearable: means, in reference to a garment, that the said garment meets the technical requirements for successful virtual projection, allowing the simulation of its use by a person.

You (and, when referring to You, the pronouns “Your” and “Yours”): means the natural person who is agreeing to the Terms of Use and this Policy. You must: (i) have legal capacity, or, if You are under 18 years of age, or lack legal capacity, You must be assisted or represented by Your parents or legal representatives, in accordance with the Applicable Law; and (ii) comply with all Applicable Laws as a User.

3. Legal Basis Data Processing

To use the Virtual Fitting Room, You need to grant us some specific authorizations:

3.1 BY USING THE VIRTUAL FITTING ROOM, YOU ACKNOWLEDGE THAT, EITHER ON YOUR OWN OR THROUGH THE OPERATOR, WE CONDUCT OPERATIONS OF COLLECTION, PRODUCTION, RECEIPT, CLASSIFICATION, USE, ACCESS, REPRODUCTION, TRANSMISSION, SHARING, DISTRIBUTION, PROCESSING, FILING, STORAGE, DELETION, EVALUATION OR CONTROL OF INFORMATION, MODIFICATION, COMMUNICATION, TRANSFER, DISSEMINATION, OR EXTRACTION, IN SHORT, ANY AND ALL PROCESSING OF YOUR PERSONAL DATA AND INFORMATION, IN ACCORDANCE WITH THIS POLICY AND THE APPLICABLE LAW, FOR THE PURPOSES OF (A) ALLOWING YOU TO USE THE SERVICES PROVIDED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI THROUGH THE VIRTUAL FITTING ROOM; (B) COMPLYING WITH THE LEGAL OBLIGATIONS AND THE OBLIGATIONS ASSUMED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI UNDER THE TERMS OF USE AND REQUIRING YOU TO FULFILL YOUR OBLIGATIONS UNDER THE TERMS OF USE; (C) IMPROVING YOUR EXPERIENCE; AND (D) MAINTAINING, PROTECTING, AND ENHANCING THE SERVICES PROVIDED.

3.2 IF YOU ARE UNDER THE AGE OF 18 (EIGHTEEN) YEARS AND/OR LACK LEGAL CAPACITY, YOU MUST BE ASSISTED OR REPRESENTED BY YOUR PARENTS OR LEGAL REPRESENTATIVES, WHO, BY AGREEING TO THIS POLICY, CONFIRM THE PROVISIONS IN ITEM 3.1.

3.3 DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI, EITHER INDEPENDENTLY OR THROUGH OPERATORS, WILL CARRY OUT INTERNATIONAL TRANSFERS OF YOUR PERSONAL DATA AND INFORMATION IN ACCORDANCE WITH THIS POLICY ANDAPPLICABLE LAW, FOR THE PURPOSE OF (A) ALLOWING YOU TO USE THE SERVICES PROVIDED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI; (B) COMPLYING WITH THE OBLIGATIONS ASSUMED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI UNDER THE TERMS OF USE; AND (C) MAINTAINING, PROTECTING, AND ENHANCING THE SERVICES PROVIDED.

3.4 THE PROCESSING OF YOUR PERSONAL DATA BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI, IN ACCORDANCE WITH THIS POLICY AND THE APPLICABLE LAW, IS AN ESSENTIAL CONDITION FOR YOU TO USE THE VIRTUAL FITTING ROOM.

3.5 TO EXERCISE ANY OF YOUR RIGHTS UNDER THIS POLICY AND/OR THE APPLICABLE LAW REGARDING YOUR PERSONAL DATA, YOU MUST CONTACT US THROUGH THE PORTAL AVAILABLE AT THE LINK HTTPS://PORTALLGPD.DORIS.MOBI/.

3.6 After Your Image is captured in the Virtual Fitting Room and and Image is generated with Wereable item, You will be able to access a webpage via QRCode. On this page, You can download Yours Images with the Wearable Item to your device for use and sharing if You desire. Upon accessing the webpage, Your Consent for Processing will be requested. If You provide Your Consent, You are freely, knowingly, and unequivocally agreeing to the Processing of Your Image by DORIS.MOBI and/or DORIS.MOBI licensees, so that the Image(s) generated through the Virtual Fitting Room can be processed and made available to You. Without Your express Consent, access to the webpage where the Images could be obtained will not be permitted. In any case, the Processing of Your Personal Data will be end 30 minutes after using the Virtual Fitting Room.

4. Processing of User Personal Data

4.1 Personal Data Collection. To use the Virtual Fitting Room, you provide Doris.MOBI with certain Personal Data, such as height and image.

4.2 When you use the Virtual Fitting Room, Doris.MOBI and/or the Licensees of Doris.MOBI collect your information and Personal Data to provide our services and allow the experience of viewing the product without physically trying it on.

4.3 When you use the Virtual Fitting Room, Your Image will be retained for 30 (thirty) minutes. During this period, You can access, through a QR Code available in the Virtual Fitting Room, a webpage where the photos of our experience will be available, and You may share them on Your social media. This option may not be available in all Virtual Fitting Rooms and, when available, will only be enabled after Your express Consent for the Processing of Your Personal Data. On some pages, your e-mail may also be requested to access the page.

4.4 Personal Data Processing. Once Doris.MOBI and/or the Licensees of Doris.MOBI have received and/or collected your Personal Data, they begin processing these Personal Data, particularly in relation to operations such as classification, use, access, reproduction, transmission, sharing, processing, filing, storage, deletion, evaluation or control, and communication.

4.5 Purpose of Processing. Doris.MOBI and/or the Licensees of Doris.MOBI process your data for the following purposes: (a) to allow you to use the services provided by Doris.MOBI and/or the Licensees of Doris.MOBI through the Virtual Fitting Room; (b) to fulfill legal obligations and those assumed by Doris.MOBI and/or the Licensees of Doris.MOBI in the Terms of Use and require you to fulfill your obligations under the Terms of Use; (c) to enhance your experience in the Virtual Fitting Room; and (d) to maintain, protect, and improve the services provided.

4.6 Doris.MOBI and/or the Licensees of Doris.MOBI will not process your Personal Data for purposes other than those established in this Policy, and the processing will be limited to the minimum necessary for the achievement of these purposes.

4.7 Legal Grounds for Processing Personal Data. You acknowledge and agree that the Processing of Your Personal Data by Doris.MOBI and/or the Licensees of Doris.MOBI, for the use of the Virtual Fitting Room, is based on the need for the execution of the contract between Doris.MOBI and/or the Licensees of Doris.MOBI and You, represented by the Terms of Use, and also to meet the legitimate interests of Doris.MOBI and/or the Licensees of Doris.MOBI, provided that Your fundamental rights and freedoms requiring the protection of your Personal Data are respected. In turn, the Processing carried out when making Your Image available on a webpage accessed via QRCode will be based on Your express Conset, wich is freely given and only required for You to access the webpage where Your Image can be viewed and downloaded to Your device.

4.8 You also acknowledge and agree that the processing of your Personal Data may, depending on the case, be based on the need to comply with legal or regulatory obligations by Doris.MOBI and/or the Licensees of Doris.MOBI, as applicable.

4.9 Data Controller. Doris.MOBI and/or a Licensee of Doris.MOBI is the Data Controller for the processing of your Personal Data and, therefore, is responsible for making decisions regarding the processing of your Personal Data. Doris.MOBI and/or the Licensees of Doris.MOBI will maintain records of all operations of processing your Personal Data that they carry out.

4.10 Contact Information for the Data Controller. You may contact Doris.MOBI and/or the Licensees of Doris.MOBI (Data Controller for the Processing of your Personal Data) through the Privacy Portal, which can be accessed at the link: https://portallgpd.doris.mobi.

4.11 Processors. The identification of Processors, that is, those responsible for processing Personal Data on behalf of Doris.MOBI and/or the Licensees of Doris.MOBI, in accordance with Doris.MOBI and/or the Licensees of Doris.MOBI’s guidelines, instructions, and decisions, in harmony with this Policy and the security and confidentiality measures established by Doris.MOBI and/or the Licensees of Doris.MOBI, is protected by trade secrets and/or industrial secrets, in accordance with applicable law.

4.12 Responsibilities of Processors. To the extent legally applicable, Processors shall, regarding the protection of your Personal Data: (a) maintain records of the processing operations they carry out; (b) comply with all applicable laws; (c) detect, prevent, and stop any fraud, technical violations, and security breaches; and (d) protect Doris.MOBI, the Licensees of Doris.MOBI, you, and the general public, as required and permitted by applicable law, from harm to rights, property, and security.

4.13 Support. The privacy portal (available at https://portallgpd.doris.mobi) is a channel for addressing data subject requests and serves as the support responsible for receiving data subject requests, as well as providing clarifications and taking actions regarding the processing of your Personal Data.

4.14 Shared Use of Personal Data. Doris.MOBI and the Licensees of Doris.MOBI do not share Personal Data with their partners.

4.15 Start of Personal Data Processing. The Processing of Your Personal Data will begin once You express Your intent to use the Virtual Fitting Room by making the corresponding gesture - raising Your hand - while facing the equipment and making eye contact with the equipment.

4.16 The processing operations of Your Personal Data will end, in any casem, 30 (thirty) minutes after the use of the Virtual Fitting Room.

4.17 Anonymized Data. Doris.MOBI may anonymize your Personal Data through a process that makes the data no longer identifiable as Personal Data. You acknowledge and agree that Anonymized Data is not considered Personal Data, unless the anonymization process it underwent is reversed using proprietary means or when it can be reasonably reversed (under applicable law). For the purposes of this Policy, Doris.MOBI and/or the Licensees of Doris.MOBI will not perform any process to reverse data anonymization.

4.18 In this regard, you acknowledge and agree that Anonymized Data will not be subject to the protections established in this Policy, and that Doris.MOBI and/or the Licensees of Doris.MOBI may publicly disclose Anonymized Data, including, but not limited to, for displaying trends about the use of the services by Doris.MOBI and/or the Licensees of Doris.MOBI.

5. Your Rights Regarding Your Personal Data

5.1 Doris.MOBI and/or its Licensors guarantee you the right to consult them, in a facilitated and free manner, through one of the communication channels available on our privacy portal at the link: https://portallgpd.doris.mobi/, about: (a) the manner and duration of the processing of your Personal Data; and (b) Doris.MOBI, its Licensors, and the Operators, subject to commercial and industrial secrets.

5.2 At any time, you may obtain from Doris.MOBI and/or its Licensors confirmation of the existence of the processing of your Personal Data, as well as access to your Personal Data held by Doris.MOBI and/or its Licensors.

5.3 Such confirmation and/or access will be provided upon your request, (a) in a simplified format, immediately; or (b) through a clear and complete statement that indicates the origin of the Personal Data, the absence of records, the criteria used, and the purpose of the processing, subject to the commercial and industrial secrets of Doris.MOBI and/or its Licensors, provided within a period of up to 15 (fifteen) business days from the date of your request.

5.4 The information will be provided (a) via a secure and appropriate electronic means for this purpose; or (b) in printed form, according to your preference.

5.5 Doris.MOBI and/or its Licensors will store your Personal Data in a format that facilitates the exercise of your right to access. You may request an electronic copy of your stored Personal Data, observing Doris.MOBI and/or its Licensors' commercial and industrial secrets and the terms of the applicable law, in a format that allows its subsequent use, including for other processing operations.

6. Privacy, Protection, and Security of Personal Data

6.1 Doris.MOBI and/or its Licensors consider your Personal Data valuable and understand that it must be protected from unauthorized access, accidental or unlawful destruction, loss, alteration, communication, or any form of improper or unlawful processing, in accordance with the Applicable Law.

6.2 In this regard, Doris.MOBI and/or its Licensors will adopt security measures, both technical and administrative, capable of: (a) protecting your Personal Data to the maximum extent possible and in accordance with industry standards, from unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or any form of improper or unlawful processing; and (b) preventing damage resulting from the processing of Personal Data.

6.3 When processing your Personal Data, Doris.MOBI and/or its Licensors will ensure compliance with security standards and confidentiality of records, Personal Data, and private communications, in accordance with the Applicable Law, and will observe at least the following security guidelines: (a) establishment of strict control over access to Personal Data, by defining the responsibilities of persons who will have access and exclusive access privileges for certain individuals; (b) provision of authentication mechanisms for accessing records, using, for example, two-factor authentication systems to ensure the identification of the person responsible for processing the records; and (c) creation of a detailed inventory of access to connection records and application access, containing the moment, the identity of the person responsible for the access as designated by Doris.MOBI.

6.4 Doris.MOBI and/or its Licensors will maintain the respective access records to Internet applications under confidentiality, in a controlled and secure environment, for a minimum period of 15 (fifteen) days from the respective collection.

6.5 Considering that the Internet is not a completely secure environment, it is not possible to assure or guarantee that your Personal Data will not be accessed, disclosed, altered, or destroyed due to a breach of any of the security, technical, or administrative protections employed, even if such protections meet industry standards. Nevertheless, Doris.MOBI and its Licensors will make their best efforts to preserve the confidentiality and security of the Personal Data provided by you. In this sense, Doris.MOBI and its Licensors will not share, sell, or otherwise provide your Personal Data to third parties, in any form, without your prior authorization, except: (a) in cases authorized by this Policy, such as sharing Personal Data with the Operator; (b) if Doris.MOBI and/or its Licensors are required to disclose such information pursuant to the Applicable Law or an order from a competent Government Authority; (c) to enforce the provisions of the Terms of Use applicable to you, this Policy, and/or any other document you have agreed to with Doris.MOBI and/or its Licensors; (d) for investigating potential violations by you; (e) to detect, prevent, or deal with technical issues, fraud, or security; (f) to protect the rights, property, and/or safety of the Virtual Try-On, Doris.MOBI, its Licensors, and/or you.

6.6 Doris.MOBI and/or its Licensors will not be liable for any damages incurred by you arising from third parties violating the security systems of Doris.MOBI and/or its Licensors to access this information.

7. International Data Transfer

7.1 The Personal Data we collect may be stored and processed on servers located in Brazil and the United States. Although the countries where we operate may not offer the same level of data protection as some jurisdictions, we adopt appropriate technical and organizational measures to ensure the security and protection of your Personal Data, as required by the Applicable Law.

7.2 By providing your Personal Data to Doris.MOBI, you expressly consent to the transfer, storage, and processing of your Personal Data in countries such as Brazil and the United States. Doris.MOBI ensures that any international data transfer will be carried out in compliance with the Applicable Law. The transfer will be supported by appropriate protection mechanisms and legal mechanisms to ensure an adequate level of security and privacy of the data.

8. Other Provisions

8.1 Requests from Government Authorities. Doris.MOBI and its Licensed Partners cooperate with Government Authorities to ensure copliance with the Applicable Laws, protect the integrity and security of the Virtual Fitting Room and its Users, prevent illegal activities, protect industrial and intellectual property rights, and prevent fraud. Whenever requested by Government Authorities, Doris.MOBI and/or its Licensed Partners will provide your Personal Data that they hold.

8.2 Compliance with Legal or Regulatory Obligations by Doris.MOBI. In addition to the above, Doris.MOBI and/or its Licensed Partners may perform any Personal Data processing operations required for compliance with a legal or regulatory obligation to which they are subject, without limiting other processing cases provided by the Applicable Law and this Policy.

8.3 The invalidity or unenforceability of any provision of this Policy will not affect the validity or enforceability of the other provisions. This Policy will be governed and interpreted in accordance with the laws of the Federative Republic of Brazil, and to resolve any disputes that arise directly or indirectly from it, the Court of São Paulo, State of São Paulo, is hereby elected, with the express waiver of any other, regardless of its privilege or potential privilege. In case of doubts, contact us through our privacy portal available at the link: https://portallgpd.doris.mobi/.
pRIVACY POLICY
1. Introduction

1.1 This Policy describes the processing activities of Your Personal Data, which are essential for the operation of Doris.MOBI's Virtual Fitting Room, known as “Doris Mirror”, and for providing our services.

1.2 In order to function, Doris.MOBI’s Doris Mirror requires Personal Data provided by You, which is processed and used to enable and improve the services provided by Doris.MOBI and/or its Licensees.

1.3 When You use our services and products, You provide Doris.MOBI and/or its Licensees with information and Personal Data through the submission of images.

1.4 It is very important that You read the provisions of this Policy each time You use the Virtual Fitting Room, to understand how we collect and process Your Personal Data. We would like to emphasize that Doris.MOBI and its Licensees do not sell Your Personal Data to Third Parties.

2. Meaning of Terms Used in this Policy

2.1 The following terms, whenever used or capitalized, will have the meanings described below:

Anonymized Data: means any data related to the data subject that cannot be identified, considering the use of reasonable technical means available at the time of its processing. Anonymized Data will not be considered Personal Data for the purposes of this Policy.

Applicable Law: means any law, code, decree, regulation, regulatory requirement, rule, order, instruction, declaration, ruling, resolution, judicial, arbitral, or administrative decision by any Government Authority, including, but not limited to, the LGPD and the GDPR.

Consent: means the free, informed, unequivocal, and specific manifestation of the data subject, expressed through a clear affirmative action, by which they agree to the processing of their Personal Data. Consent can be withdrawn at any time without affecting the legality of processing carried out while the consent was valid.

Controller: means the natural or legal person, whether public or private, responsible for deciding on the processing of Personal Data. Doris.MOBI and/or its Licensees are the Controllers and, therefore, responsible for making decisions related to the processing of User Personal Data.

Content: means any content submitted, provided, or transmitted by You.

Database: means the structured set of Personal Data, stored in one or several locations, whether physical and/or electronic, generated as a result of activities carried out by Users through the use of Doris.MOBI's Doris Mirror.

Doris.MOBI: means DORIS.MOBI TECNOLOGIA S.L., located in Barcelona, Spain, at Calle Beethoven, 15, 5th Floor, CP 08021, with tax identification number B-55484471, and registered with the Barcelona Commercial Registry under number B-617736, the owner and/or holder of the right to use the Virtual Fitting Room.

Doris.MOBI Licensees: means the entities that have received a license for use and operation of Doris, granted by Doris.MOBI, including DORIS.MOBI TECNOLOGIA S.A., located in São Paulo, Brazil, at Avenida Brigadeiro Faria Lima, nº 2.092, 10th floor, rooms E102 and E104, sala 02, Jardim Paulistano, ZIP code 01451-905, registered under CNPJ nº 19.782.186/0001-06.

Elimination: means the exclusion of Personal Data or a set of Personal Data stored in a Database, regardless of the method used.

Garment Item: means the image of a specific wearable garment that allows its virtual projection, enabling the simulation of its use by a person.

GDPR:
means the General Data Protection Regulation, which governs the processing of data within the European Union and the European Economic Area.

Government Authority: means any government, authority, governmental entity, regulatory agency, public ministry, tax authority (including, but not limited to, the Brazilian Federal Revenue and state and municipal tax authorities), commission, board, council, stock exchange, agency, or any judicial, arbitral, or administrative body with jurisdiction over Doris.MOBI and/or its Licensees and/or Users. This includes, but is not limited to, the National Data Protection Authority (ANPD) in Brazil, and the data protection supervisory authorities established by the GDPR in the European Economic Area (EEA), such as the European Data Protection Board (EDPB).

Image: means, in reference to a natural person, any form of representation, including photographs, of the human figure, visual appearance, facial expression, gestures, distinct body parts, expressions of personality, name, surname, nicknames, aliases, and pseudonyms, as well as the audiovisual process resulting in the fixation of images with or without sound, with the purpose of creating, through reproduction, the impression of movement, regardless of the processes used to capture, store, or transmit the image, including, but not limited to (i) newspapers, magazines, brochures, marketing materials, catalogs, and/or any other printed media; (ii) fashion art, painting, sculpture, drawing, photography, reprography, caricature, or decorative design; (iii) sound images from phonography and broadcasting; and/or (iv) cinematography, television, and the internet. Your Image will be captured by the Virtual Fitting Room, following specific position and distance conditions mentioned in the equipment. It will be used to allow you to virtually try on selected clothing items without the need for a physical fitting room,

International Data Transfer: means the transfer of Personal Data from the Controller's territory to a foreign country or international organization that the country is a member of.

LGPD: means Brazilian Law No. 13,709/2018 and its respective regulations as they may be created or amended over time.

Personal Data: means any data related to a natural person that can identify or make identifiable, directly or indirectly, including but not limited to identification numbers, images, location data, electronic identifiers, IP addresses, or any other data that, individually or in combination, allows the formation of a behavioral profile of an identified or identifiable natural person. In reference to You, Personal Data will be understood as any Personal Data submitted and/or transmitted by You through the Virtual Fitting Room of Doris.MOBI.

Policy: means this document titled “Privacy and Personal Data Protection Policy,” which contains provisions on the processing of User Personal Data when using the Virtual Fitting Room. The terms must be fully accepted by You as a condition for use.

Processor: means the natural or legal person, whether public or private, residing or headquartered inside or outside the national territory, who processes Personal Data on behalf of the Controller.

Processing: means any operation performed with Personal Data, including but not limited to collection, production, reception, classification, use, access, reproduction, transmission, sharing, distribution, processing, archiving, storage, deletion, evaluation, or control of information, modification, communication, transfer, dissemination, or extraction.

Sensitive Personal Data: means any Personal Data related to racial or ethnic origin, religious beliefs, political opinions, union membership, or affiliation to a religious, philosophical, or political organization, Personal Data related to health or sexual life, genetic or biometric Personal Data when linked to a natural person.

Shared Use of Personal Data: means the communication, dissemination, international transfer, interconnection of Personal Data, or shared processing of Databases by public bodies in compliance with their legal duties, or between these and private entities, with specific authorization, for one or more processing activities permitted by public bodies, or between private entities.

Support: means the communication channel contained in our privacy portal, available at https://portallgpd.doris.mobi
.

Terms of Use: means the document titled “Terms of Use,” which, along with this Policy, contains the general terms and conditions for the use of Doris.MOBI's solutions by Users.

User: means, without distinction, any natural person who uses the Virtual Fitting Room.

Virtual Fitting Room: means the interactive digital kiosk used in physical establishments, allowing customers to virtually try on selected garments using Your Image captured by the equipment, without the need to use a physical fitting room.

Wearable: means, in reference to a garment, that the said garment meets the technical requirements for successful virtual projection, allowing the simulation of its use by a person.

You (and, when referring to You, the pronouns “Your” and “Yours”): means the natural person who is agreeing to the Terms of Use and this Policy. You must: (i) have legal capacity, or, if You are under 18 years of age, or lack legal capacity, You must be assisted or represented by Your parents or legal representatives, in accordance with the Applicable Law; and (ii) comply with all Applicable Laws as a User.

3. Legal Basis for Data Processing

To use the Virtual Fitting Room, You need to grant us some specific authorizations:

3.1 BY USING THE VIRTUAL FITTING ROOM, YOU ACKNOWLEDGE THAT, EITHER ON YOUR OWN OR THROUGH THE OPERATOR, WE CONDUCT OPERATIONS OF COLLECTION, PRODUCTION, RECEIPT, CLASSIFICATION, USE, ACCESS, REPRODUCTION, TRANSMISSION, SHARING, DISTRIBUTION, PROCESSING, FILING, STORAGE, DELETION, EVALUATION OR CONTROL OF INFORMATION, MODIFICATION, COMMUNICATION, TRANSFER, DISSEMINATION, OR EXTRACTION, IN SHORT, ANY AND ALL PROCESSING OF YOUR PERSONAL DATA AND INFORMATION, IN ACCORDANCE WITH THIS POLICY AND THE APPLICABLE LAW, FOR THE PURPOSES OF (A) ALLOWING YOU TO USE THE SERVICES PROVIDED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI THROUGH THE VIRTUAL FITTING ROOM; (B) COMPLYING WITH THE LEGAL OBLIGATIONS AND THE OBLIGATIONS ASSUMED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI UNDER THE TERMS OF USE AND REQUIRING YOU TO FULFILL YOUR OBLIGATIONS UNDER THE TERMS OF USE; (C) IMPROVING YOUR EXPERIENCE; AND (D) MAINTAINING, PROTECTING, AND ENHANCING THE SERVICES PROVIDED.

3.2 IF YOU ARE UNDER THE AGE OF 18 (EIGHTEEN) YEARS AND/OR LACK LEGAL CAPACITY, YOU MUST BE ASSISTED OR REPRESENTED BY YOUR PARENTS OR LEGAL REPRESENTATIVES, WHO, BY AGREEING TO THIS POLICY, CONFIRM THE PROVISIONS IN ITEM 3.1.

3.3 DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI, EITHER INDEPENDENTLY OR THROUGH OPERATORS, WILL CARRY OUT INTERNATIONAL TRANSFERS OF YOUR PERSONAL DATA AND INFORMATION IN ACCORDANCE WITH THIS POLICY ANDAPPLICABLE LAW, FOR THE PURPOSE OF (A) ALLOWING YOU TO USE THE SERVICES PROVIDED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI; (B) COMPLYING WITH THE OBLIGATIONS ASSUMED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI UNDER THE TERMS OF USE; AND (C) MAINTAINING, PROTECTING, AND ENHANCING THE SERVICES PROVIDED.

3.4 THE PROCESSING OF YOUR PERSONAL DATA BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI, IN ACCORDANCE WITH THIS POLICY AND THE APPLICABLE LAW, IS AN ESSENTIAL CONDITION FOR YOU TO USE THE VIRTUAL FITTING ROOM.

3.5 TO EXERCISE ANY OF YOUR RIGHTS UNDER THIS POLICY AND/OR THE APPLICABLE LAW REGARDING YOUR PERSONAL DATA, YOU MUST CONTACT US THROUGH THE PORTAL AVAILABLE AT THE LINK HTTPS://PORTALLGPD.DORIS.MOBI/.

3.6 After Your Image is captured in the Virtual Fitting Room and and Image is generated with Wereable item, You will be able to access a webpage via QRCode. On this page, You can download Yours Images with the Wearable Item to your device for use and sharing if You desire. Upon accessing the webpage, Your Consent for Processing will be requested. If You provide Your Consent, You are freely, knowingly, and unequivocally agreeing to the Processing of Your Image by DORIS.MOBI and/or DORIS.MOBI licensees, so that the Image(s) generated through the Virtual Fitting Room can be processed and made available to You. Without Your express Consent, access to the webpage where the Images could be obtained will not be permitted. In any case, the Processing of Your Personal Data will be end 30 minutes after using the Virtual Fitting Room.

4. Processing of User Personal Data

4.1 Personal Data Collection. To use the Virtual Fitting Room, You provide Doris.MOBI with certain Personal Data, such as height and image.

4.2 When You use the Virtual Fitting Room, Doris.MOBI and/or the Licensees of Doris.MOBI collect Your information and Personal Data to provide our services and allow the experience of viewing the product without physically trying it on.

4.3 When You use the Virtual Fitting Room, Your Image will be retained for 30 (thirty) minutes. During this period, You can access, through a QR Code available in the Virtual Fitting Room, a webpage where the photos of our experience will be available, and You may share them on Your social media. This option may not be available in all Virtual Fitting Rooms and, when available, will only be enabled after Your express Consent for the Processing of Your Personal Data.

4.4 Personal Data Processing. Once Doris.MOBI and/or the Licensees of Doris.MOBI have received and/or collected your Personal Data, they begin processing these Personal Data, particularly in relation to operations such as classification, use, access, reproduction, transmission, sharing, processing, filing, storage, deletion, evaluation or control, and communication.

4.5 Purpose of Processing. Doris.MOBI and/or the Licensees of Doris.MOBI process Your data for the following purposes: (a) to allow You to use the services provided by Doris.MOBI and/or the Licensees of Doris.MOBI through the Virtual Fitting Room; (b) to fulfill legal obligations and those assumed by Doris.MOBI and/or the Licensees of Doris.MOBI in the Terms of Use and require you to fulfill your obligations under the Terms of Use; (c) to enhance your experience in the Virtual Fitting Room; and (d) to maintain, protect, and improve the services provided.

4.6 Doris.MOBI and/or the Licensees of Doris.MOBI will not process your Personal Data for purposes other than those established in this Policy, and the processing will be limited to the minimum necessary for the achievement of these purposes.

4.7 Legal Grounds for Processing Personal Data. You acknowledge and agree that the Processing of Your Personal Data by Doris.MOBI and/or the Licensees of Doris.MOBI, for the use of the Virtual Fitting Room, is based on the need for the execution of the contract between Doris.MOBI and/or the Licensees of Doris.MOBI and You, represented by the Terms of Use, and also to meet the legitimate interests of Doris.MOBI and/or the Licensees of Doris.MOBI, provided that Your fundamental rights and freedoms requiring the protection of your Personal Data are respected. In turn, the Processing carried out when making Your Image available on a webpage accessed via QRCode will be based on Your express Conset, wich is freely given and only required for You to access the webpage where Your Image can be viewed and downloaded to Your device.

4.8 You also acknowledge and agree that the processing of Your Personal Data may, depending on the case, be based on the need to comply with legal or regulatory obligations by Doris.MOBI and/or the Licensees of Doris.MOBI, as applicable.

4.9 Data Controller. Doris.MOBI and/or a Licensee of Doris.MOBI is the Data Controller for the processing of Your Personal Data and, therefore, is responsible for making decisions regarding the processing of Your Personal Data. Doris.MOBI and/or the Licensees of Doris.MOBI will maintain records of all operations of processing Your Personal Data that they carry out.

4.10 Contact Information for the Data Controller. You may contact Doris.MOBI and/or the Licensees of Doris.MOBI (Data Controller for the Processing of Your Personal Data) through the Privacy Portal, which can be accessed at the link: https://portallgpd.doris.mobi.

4.11 Processors. The identification of Processors, that is, those responsible for processing Personal Data on behalf of Doris.MOBI and/or the Licensees of Doris.MOBI, in accordance with Doris.MOBI and/or the Licensees of Doris.MOBI’s guidelines, instructions, and decisions, in harmony with this Policy and the security and confidentiality measures established by Doris.MOBI and/or the Licensees of Doris.MOBI, is protected by trade secrets and/or industrial secrets, in accordance with applicable law.

4.12 Responsibilities of Processors. To the extent legally applicable, Processors shall, regarding the protection of Your Personal Data: (a) maintain records of the processing operations they carry out; (b) comply with all applicable laws; (c) detect, prevent, and stop any fraud, technical violations, and security breaches; and (d) protect Doris.MOBI, the Licensees of Doris.MOBI, You, and the general public, as required and permitted by applicable law, from harm to rights, property, and security.

4.13 Support. The privacy portal (available at https://portallgpd.doris.mobi) is a channel for addressing data subject requests and serves as the Support responsible for receiving data subject requests, as well as providing clarifications and taking actions regarding the Processing of Your Personal Data.

4.14 Shared Use of Personal Data. Doris.MOBI and the Licensees of Doris.MOBI do not share Personal Data with their partners.

4.15 Start of Personal Data Processing. The Processing of Your Personal Data will begin once You express Your intent to use the Virtual Fitting Room by making the corresponding gesture - raising Your hand - while facing the equipment and making eye contact with the equipment.

4.16 The processing operations of Your Personal Data will end, in any case, 30 (thirty) minutes after the use of the Virtual Fitting Room.

4.17 Anonymized Data. Doris.MOBI may anonymize your Personal Data through a process that makes the data no longer identifiable as Personal Data. You acknowledge and agree that Anonymized Data is not considered Personal Data, unless the anonymization process it underwent is reversed using proprietary means or when it can be reasonably reversed (under applicable law). For the purposes of this Policy, Doris.MOBI and/or the Licensees of Doris.MOBI will not perform any process to reverse data anonymization.

4.18 In this regard, you acknowledge and agree that Anonymized Data will not be subject to the protections established in this Policy, and that Doris.MOBI and/or the Licensees of Doris.MOBI may publicly disclose Anonymized Data, including, but not limited to, for displaying trends about the use of the services by Doris.MOBI and/or the Licensees of Doris.MOBI.

5. Your Rights Regarding Your Personal Data

5.1 Doris.MOBI and/or its Licensors guarantee you the right to consult them, in a facilitated and free manner, through one of the communication channels available on our privacy portal at the link: https://portallgpd.doris.mobi/, about: (a) the manner and duration of the processing of your Personal Data; and (b) Doris.MOBI, its Licensors, and the Operators, subject to commercial and industrial secrets.

5.2 At any time, you may obtain from Doris.MOBI and/or its Licensors confirmation of the existence of the processing of your Personal Data, as well as access to your Personal Data held by Doris.MOBI and/or its Licensors.

5.3 Such confirmation and/or access will be provided upon your request, (a) in a simplified format, immediately; or (b) through a clear and complete statement that indicates the origin of the Personal Data, the absence of records, the criteria used, and the purpose of the processing, subject to the commercial and industrial secrets of Doris.MOBI and/or its Licensors, provided within a period of up to 15 (fifteen) business days from the date of your request.

5.4 The information will be provided (a) via a secure and appropriate electronic means for this purpose; or (b) in printed form, according to your preference.

5.5 Doris.MOBI and/or its Licensors will store your Personal Data in a format that facilitates the exercise of your right to access. You may request an electronic copy of your stored Personal Data, observing Doris.MOBI and/or its Licensors' commercial and industrial secrets and the terms of the applicable law, in a format that allows its subsequent use, including for other processing operations.

6. Privacy, Protection, and Security of Personal Data

6.1 Doris.MOBI and/or its Licensors consider your Personal Data valuable and understand that it must be protected from unauthorized access, accidental or unlawful destruction, loss, alteration, communication, or any form of improper or unlawful processing, in accordance with the Applicable Law.

6.2 In this regard, Doris.MOBI and/or its Licensors will adopt security measures, both technical and administrative, capable of: (a) protecting your Personal Data to the maximum extent possible and in accordance with industry standards, from unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or any form of improper or unlawful processing; and (b) preventing damage resulting from the processing of Personal Data.

6.3 When processing your Personal Data, Doris.MOBI and/or its Licensors will ensure compliance with security standards and confidentiality of records, Personal Data, and private communications, in accordance with the Applicable Law, and will observe at least the following security guidelines: (a) establishment of strict control over access to Personal Data, by defining the responsibilities of persons who will have access and exclusive access privileges for certain individuals; (b) provision of authentication mechanisms for accessing records, using, for example, two-factor authentication systems to ensure the identification of the person responsible for processing the records; and (c) creation of a detailed inventory of access to connection records and application access, containing the moment, the identity of the person responsible for the access as designated by Doris.MOBI.

6.4 Doris.MOBI and/or its Licensors will maintain the respective access records to Internet applications under confidentiality, in a controlled and secure environment, for a minimum period of 15 (fifteen) days from the respective collection.

6.5 Considering that the Internet is not a completely secure environment, it is not possible to assure or guarantee that your Personal Data will not be accessed, disclosed, altered, or destroyed due to a breach of any of the security, technical, or administrative protections employed, even if such protections meet industry standards. Nevertheless, Doris.MOBI and its Licensors will make their best efforts to preserve the confidentiality and security of the Personal Data provided by you. In this sense, Doris.MOBI and its Licensors will not share, sell, or otherwise provide your Personal Data to third parties, in any form, without your prior authorization, except: (a) in cases authorized by this Policy, such as sharing Personal Data with the Operator; (b) if Doris.MOBI and/or its Licensors are required to disclose such information pursuant to the Applicable Law or an order from a competent Government Authority; (c) to enforce the provisions of the Terms of Use applicable to you, this Policy, and/or any other document you have agreed to with Doris.MOBI and/or its Licensors; (d) for investigating potential violations by you; (e) to detect, prevent, or deal with technical issues, fraud, or security; (f) to protect the rights, property, and/or safety of the Virtual Try-On, Doris.MOBI, its Licensors, and/or you.

6.6 Doris.MOBI and/or its Licensors will not be liable for any damages incurred by you arising from third parties violating the security systems of Doris.MOBI and/or its Licensors to access this information.

7. International Data Transfer

7.1 The Personal Data we collect may be stored and processed on servers located in Brazil and the United States. Although the countries where we operate may not offer the same level of data protection as some jurisdictions, we adopt appropriate technical and organizational measures to ensure the security and protection of your Personal Data, as required by the Applicable Law.

7.2 By providing your Personal Data to Doris.MOBI, you expressly consent to the transfer, storage, and processing of your Personal Data in countries such as Brazil and the United States. Doris.MOBI ensures that any international data transfer will be carried out in compliance with the Applicable Law. The transfer will be supported by appropriate protection mechanisms and legal mechanisms to ensure an adequate level of security and privacy of the data.

8. Other Provisions

8.1 Requests from Government Authorities. Doris.MOBI and its Licensed Partners cooperate with Government Authorities to ensure copliance with the Applicable Laws, protect the integrity and security of the Virtual Fitting Room and its Users, prevent illegal activities, protect industrial and intellectual property rights, and prevent fraud. Whenever requested by Government Authorities, Doris.MOBI and/or its Licensed Partners will provide your Personal Data that they hold.

8.2 Compliance with Legal or Regulatory Obligations by Doris.MOBI. In addition to the above, Doris.MOBI and/or its Licensed Partners may perform any Personal Data processing operations required for compliance with a legal or regulatory obligation to which they are subject, without limiting other processing cases provided by the Applicable Law and this Policy.

8.3 The invalidity or unenforceability of any provision of this Policy will not affect the validity or enforceability of the other provisions. This Policy will be governed and interpreted in accordance with the laws of the Federative Republic of Brazil, and to resolve any disputes that arise directly or indirectly from it, the Court of São Paulo, State of São Paulo, is hereby elected, with the express waiver of any other, regardless of its privilege or potential privilege. In case of doubts, contact us through our privacy portal available at the link: https://portallgpd.doris.mobi/.
pRIVACY POLICY
1. Introduction

1.1 This Policy describes the processing activities of Your Personal Data, which are essential for the operation of Doris.MOBI's Virtual Fitting Room, known as “Doris Mirror”, and for providing our services.

1.2 In order to function, Doris.MOBI’s Doris Mirror requires Personal Data provided by You, which is processed and used to enable and improve the services provided by Doris.MOBI and/or its Licensees.

1.3 When You use our services and products, You provide Doris.MOBI and/or its Licensees with information and Personal Data through the submission of images.

1.4 It is very important that You read the provisions of this Policy each time You use the Virtual Fitting Room, to understand how we collect and process Your Personal Data. We would like to emphasize that Doris.MOBI and its Licensees do not sell Your Personal Data to Third Parties.

2. Meaning of Terms Used in this Policy

2.1 The following terms, whenever used or capitalized, will have the meanings described below:

Anonymized Data: means any data related to the data subject that cannot be identified, considering the use of reasonable technical means available at the time of its processing. Anonymized Data will not be considered Personal Data for the purposes of this Policy.

Applicable Law: means any law, code, decree, regulation, regulatory requirement, rule, order, instruction, declaration, ruling, resolution, judicial, arbitral, or administrative decision by any Government Authority, including, but not limited to, the LGPD and the GDPR.

Consent: means the free, informed, unequivocal, and specific manifestation of the data subject, expressed through a clear affirmative action, by which they agree to the processing of their Personal Data. Consent can be withdrawn at any time without affecting the legality of processing carried out while the consent was valid.

Controller: means the natural or legal person, whether public or private, responsible for deciding on the processing of Personal Data. Doris.MOBI and/or its Licensees are the Controllers and, therefore, responsible for making decisions related to the processing of User Personal Data.

Content: means any content submitted, provided, or transmitted by You.

Database: means the structured set of Personal Data, stored in one or several locations, whether physical and/or electronic, generated as a result of activities carried out by Users through the use of Doris.MOBI's Doris Mirror.

Doris.MOBI: means DORIS.MOBI TECNOLOGIA S.L., located in Barcelona, Spain, at Calle Beethoven, 15, 5th Floor, CP 08021, with tax identification number B-55484471, and registered with the Barcelona Commercial Registry under number B-617736, the owner and/or holder of the right to use the Virtual Fitting Room.

Doris.MOBI Licensees: means the entities that have received a license for use and operation of Doris, granted by Doris.MOBI, including DORIS.MOBI TECNOLOGIA S.A., located in São Paulo, Brazil, at Avenida Brigadeiro Faria Lima, nº 2.092, 10th floor, rooms E102 and E104, sala 02, Jardim Paulistano, ZIP code 01451-905, registered under CNPJ nº 19.782.186/0001-06.

Elimination: means the exclusion of Personal Data or a set of Personal Data stored in a Database, regardless of the method used.

Garment Item: means the image of a specific wearable garment that allows its virtual projection, enabling the simulation of its use by a person.

GDPR:
means the General Data Protection Regulation, which governs the processing of data within the European Union and the European Economic Area.

Government Authority: means any government, authority, governmental entity, regulatory agency, public ministry, tax authority (including, but not limited to, the Brazilian Federal Revenue and state and municipal tax authorities), commission, board, council, stock exchange, agency, or any judicial, arbitral, or administrative body with jurisdiction over Doris.MOBI and/or its Licensees and/or Users. This includes, but is not limited to, the National Data Protection Authority (ANPD) in Brazil, and the data protection supervisory authorities established by the GDPR in the European Economic Area (EEA), such as the European Data Protection Board (EDPB).

Image: means, in reference to a natural person, any form of representation, including photographs, of the human figure, visual appearance, facial expression, gestures, distinct body parts, expressions of personality, name, surname, nicknames, aliases, and pseudonyms, as well as the audiovisual process resulting in the fixation of images with or without sound, with the purpose of creating, through reproduction, the impression of movement, regardless of the processes used to capture, store, or transmit the image, including, but not limited to (i) newspapers, magazines, brochures, marketing materials, catalogs, and/or any other printed media; (ii) fashion art, painting, sculpture, drawing, photography, reprography, caricature, or decorative design; (iii) sound images from phonography and broadcasting; and/or (iv) cinematography, television, and the internet. Your Image will be captured by the Virtual Fitting Room, following specific position and distance conditions mentioned in the equipment. It will be used to allow you to virtually try on selected clothing items without the need for a physical fitting room,

International Data Transfer: means the transfer of Personal Data from the Controller's territory to a foreign country or international organization that the country is a member of.

LGPD: means Brazilian Law No. 13,709/2018 and its respective regulations as they may be created or amended over time.

Personal Data: means any data related to a natural person that can identify or make identifiable, directly or indirectly, including but not limited to identification numbers, images, location data, electronic identifiers, IP addresses, or any other data that, individually or in combination, allows the formation of a behavioral profile of an identified or identifiable natural person. In reference to You, Personal Data will be understood as any Personal Data submitted and/or transmitted by You through the Virtual Fitting Room of Doris.MOBI.

Policy: means this document titled “Privacy and Personal Data Protection Policy,” which contains provisions on the processing of User Personal Data when using the Virtual Fitting Room. The terms must be fully accepted by You as a condition for use.

Processor: means the natural or legal person, whether public or private, residing or headquartered inside or outside the national territory, who processes Personal Data on behalf of the Controller.

Processing: means any operation performed with Personal Data, including but not limited to collection, production, reception, classification, use, access, reproduction, transmission, sharing, distribution, processing, archiving, storage, deletion, evaluation, or control of information, modification, communication, transfer, dissemination, or extraction.

Sensitive Personal Data: means any Personal Data related to racial or ethnic origin, religious beliefs, political opinions, union membership, or affiliation to a religious, philosophical, or political organization, Personal Data related to health or sexual life, genetic or biometric Personal Data when linked to a natural person.

Shared Use of Personal Data: means the communication, dissemination, international transfer, interconnection of Personal Data, or shared processing of Databases by public bodies in compliance with their legal duties, or between these and private entities, with specific authorization, for one or more processing activities permitted by public bodies, or between private entities.

Support: means the communication channel contained in our privacy portal, available at https://portallgpd.doris.mobi
.

Terms of Use: means the document titled “Terms of Use,” which, along with this Policy, contains the general terms and conditions for the use of Doris.MOBI's solutions by Users.

User: means, without distinction, any natural person who uses the Virtual Fitting Room.

Virtual Fitting Room: means the interactive digital kiosk used in physical establishments, allowing customers to virtually try on selected garments using Your Image captured by the equipment, without the need to use a physical fitting room.

Wearable: means, in reference to a garment, that the said garment meets the technical requirements for successful virtual projection, allowing the simulation of its use by a person.

You (and, when referring to You, the pronouns “Your” and “Yours”): means the natural person who is agreeing to the Terms of Use and this Policy. You must: (i) have legal capacity, or, if You are under 18 years of age, or lack legal capacity, You must be assisted or represented by Your parents or legal representatives, in accordance with the Applicable Law; and (ii) comply with all Applicable Laws as a User.

3. Legal Basis Data Processing

To use the Virtual Fitting Room, You need to grant us some specific authorizations:

3.1 BY USING THE VIRTUAL FITTING ROOM, YOU ACKNOWLEDGE THAT, EITHER ON YOUR OWN OR THROUGH THE OPERATOR, WE CONDUCT OPERATIONS OF COLLECTION, PRODUCTION, RECEIPT, CLASSIFICATION, USE, ACCESS, REPRODUCTION, TRANSMISSION, SHARING, DISTRIBUTION, PROCESSING, FILING, STORAGE, DELETION, EVALUATION OR CONTROL OF INFORMATION, MODIFICATION, COMMUNICATION, TRANSFER, DISSEMINATION, OR EXTRACTION, IN SHORT, ANY AND ALL PROCESSING OF YOUR PERSONAL DATA AND INFORMATION, IN ACCORDANCE WITH THIS POLICY AND THE APPLICABLE LAW, FOR THE PURPOSES OF (A) ALLOWING YOU TO USE THE SERVICES PROVIDED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI THROUGH THE VIRTUAL FITTING ROOM; (B) COMPLYING WITH THE LEGAL OBLIGATIONS AND THE OBLIGATIONS ASSUMED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI UNDER THE TERMS OF USE AND REQUIRING YOU TO FULFILL YOUR OBLIGATIONS UNDER THE TERMS OF USE; (C) IMPROVING YOUR EXPERIENCE; AND (D) MAINTAINING, PROTECTING, AND ENHANCING THE SERVICES PROVIDED.

3.2 IF YOU ARE UNDER THE AGE OF 18 (EIGHTEEN) YEARS AND/OR LACK LEGAL CAPACITY, YOU MUST BE ASSISTED OR REPRESENTED BY YOUR PARENTS OR LEGAL REPRESENTATIVES, WHO, BY AGREEING TO THIS POLICY, CONFIRM THE PROVISIONS IN ITEM 3.1.

3.3 DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI, EITHER INDEPENDENTLY OR THROUGH OPERATORS, WILL CARRY OUT INTERNATIONAL TRANSFERS OF YOUR PERSONAL DATA AND INFORMATION IN ACCORDANCE WITH THIS POLICY ANDAPPLICABLE LAW, FOR THE PURPOSE OF (A) ALLOWING YOU TO USE THE SERVICES PROVIDED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI; (B) COMPLYING WITH THE OBLIGATIONS ASSUMED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI UNDER THE TERMS OF USE; AND (C) MAINTAINING, PROTECTING, AND ENHANCING THE SERVICES PROVIDED.

3.4 THE PROCESSING OF YOUR PERSONAL DATA BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI, IN ACCORDANCE WITH THIS POLICY AND THE APPLICABLE LAW, IS AN ESSENTIAL CONDITION FOR YOU TO USE THE VIRTUAL FITTING ROOM.

3.5 TO EXERCISE ANY OF YOUR RIGHTS UNDER THIS POLICY AND/OR THE APPLICABLE LAW REGARDING YOUR PERSONAL DATA, YOU MUST CONTACT US THROUGH THE PORTAL AVAILABLE AT THE LINK HTTPS://PORTALLGPD.DORIS.MOBI/.

3.5 After Your Image is captured in the Virtual Fitting Room and and Image is generated with Wereable item, You will be able to access a webpage via QRCode. On this page, You can download Yours Images with the Wearable Item to your device for use and sharing if You desire. Upon accessing the webpage, Your Consent for Processing will be requested. If You provide Your Consent, You are freely, knowingly, and unequivocally agreeing to the Processing of Your Image by DORIS.MOBI and/or DORIS.MOBI licensees, so that the Image(s) generated through the Virtual Fitting Room can be processed and made available to You. Without Your express Consent, access to the webpage where the Images could be obtained will not be permitted. In any case, the Processing of Your Personal Data will be end 30 minutes after using the Virtual Fitting Room.

4. Processing of User Personal Data

4.1 Personal Data Collection. To use the Virtual Fitting Room, you provide Doris.MOBI with certain Personal Data, such as height and image.

4.2 When you use the Virtual Fitting Room, Doris.MOBI and/or the Licensees of Doris.MOBI collect your information and Personal Data to provide our services and allow the experience of viewing the product without physically trying it on.

4.3 When you use the Virtual Fitting Room, Your Image will be retained for 30 (thirty) minutes. During this period, You can access, through a QR Code available in the Virtual Fitting Room, a webpage where the photos of our experience will be available, and You may share them on Your social media. This option may not be available in all Virtual Fitting Rooms and, when available, will only be enabled after Your express Consent for the Processing of Your Personal Data.

4.4 Personal Data Processing. Once Doris.MOBI and/or the Licensees of Doris.MOBI have received and/or collected your Personal Data, they begin processing these Personal Data, particularly in relation to operations such as classification, use, access, reproduction, transmission, sharing, processing, filing, storage, deletion, evaluation or control, and communication.

4.5 Purpose of Processing. Doris.MOBI and/or the Licensees of Doris.MOBI process your data for the following purposes: (a) to allow you to use the services provided by Doris.MOBI and/or the Licensees of Doris.MOBI through the Virtual Fitting Room; (b) to fulfill legal obligations and those assumed by Doris.MOBI and/or the Licensees of Doris.MOBI in the Terms of Use and require you to fulfill your obligations under the Terms of Use; (c) to enhance your experience in the Virtual Fitting Room; and (d) to maintain, protect, and improve the services provided.

4.6 Doris.MOBI and/or the Licensees of Doris.MOBI will not process your Personal Data for purposes other than those established in this Policy, and the processing will be limited to the minimum necessary for the achievement of these purposes.

4.7 Legal Grounds for Processing Personal Data. You acknowledge and agree that the Processing of Your Personal Data by Doris.MOBI and/or the Licensees of Doris.MOBI, for the use of the Virtual Fitting Room, is based on the need for the execution of the contract between Doris.MOBI and/or the Licensees of Doris.MOBI and You, represented by the Terms of Use, and also to meet the legitimate interests of Doris.MOBI and/or the Licensees of Doris.MOBI, provided that Your fundamental rights and freedoms requiring the protection of your Personal Data are respected. In turn, the Processing carried out when making Your Image available on a webpage accessed via QRCode will be based on Your express Conset, wich is freely given and only required for You to access the webpage where Your Image can be viewed and downloaded to Your device.

4.8 You also acknowledge and agree that the processing of your Personal Data may, depending on the case, be based on the need to comply with legal or regulatory obligations by Doris.MOBI and/or the Licensees of Doris.MOBI, as applicable.

4.9 Data Controller. Doris.MOBI and/or a Licensee of Doris.MOBI is the Data Controller for the processing of your Personal Data and, therefore, is responsible for making decisions regarding the processing of your Personal Data. Doris.MOBI and/or the Licensees of Doris.MOBI will maintain records of all operations of processing your Personal Data that they carry out.

4.10 Contact Information for the Data Controller. You may contact Doris.MOBI and/or the Licensees of Doris.MOBI (Data Controller for the Processing of your Personal Data) through the Privacy Portal, which can be accessed at the link: https://portallgpd.doris.mobi.

4.11 Processors. The identification of Processors, that is, those responsible for processing Personal Data on behalf of Doris.MOBI and/or the Licensees of Doris.MOBI, in accordance with Doris.MOBI and/or the Licensees of Doris.MOBI’s guidelines, instructions, and decisions, in harmony with this Policy and the security and confidentiality measures established by Doris.MOBI and/or the Licensees of Doris.MOBI, is protected by trade secrets and/or industrial secrets, in accordance with applicable law.

4.12 Responsibilities of Processors. To the extent legally applicable, Processors shall, regarding the protection of your Personal Data: (a) maintain records of the processing operations they carry out; (b) comply with all applicable laws; (c) detect, prevent, and stop any fraud, technical violations, and security breaches; and (d) protect Doris.MOBI, the Licensees of Doris.MOBI, you, and the general public, as required and permitted by applicable law, from harm to rights, property, and security.

4.13 Support. The privacy portal (available at https://portallgpd.doris.mobi) is a channel for addressing data subject requests and serves as the support responsible for receiving data subject requests, as well as providing clarifications and taking actions regarding the processing of your Personal Data.

4.14 Shared Use of Personal Data. Doris.MOBI and the Licensees of Doris.MOBI do not share Personal Data with their partners.

4.15 Start of Personal Data Processing. The Processing of Your Personal Data will begin once You express Your intent to use the Virtual Fitting Room by making the corresponding gesture - raising Your hand - while facing the equipment and making eye contact with the equipment.

4.16 The processing operations of Your Personal Data will end, in any casem, 30 (thirty) minutes after the use of the Virtual Fitting Room.

4.17 Anonymized Data. Doris.MOBI may anonymize your Personal Data through a process that makes the data no longer identifiable as Personal Data. You acknowledge and agree that Anonymized Data is not considered Personal Data, unless the anonymization process it underwent is reversed using proprietary means or when it can be reasonably reversed (under applicable law). For the purposes of this Policy, Doris.MOBI and/or the Licensees of Doris.MOBI will not perform any process to reverse data anonymization.

4.18 In this regard, you acknowledge and agree that Anonymized Data will not be subject to the protections established in this Policy, and that Doris.MOBI and/or the Licensees of Doris.MOBI may publicly disclose Anonymized Data, including, but not limited to, for displaying trends about the use of the services by Doris.MOBI and/or the Licensees of Doris.MOBI.
3. Legal Basis Data Processing

To use the Virtual Fitting Room, You need to grant us some specific authorizations:

3.1 BY USING THE VIRTUAL FITTING ROOM, YOU ACKNOWLEDGE THAT, EITHER ON YOUR OWN OR THROUGH THE OPERATOR, WE CONDUCT OPERATIONS OF COLLECTION, PRODUCTION, RECEIPT, CLASSIFICATION, USE, ACCESS, REPRODUCTION, TRANSMISSION, SHARING, DISTRIBUTION, PROCESSING, FILING, STORAGE, DELETION, EVALUATION OR CONTROL OF INFORMATION, MODIFICATION, COMMUNICATION, TRANSFER, DISSEMINATION, OR EXTRACTION, IN SHORT, ANY AND ALL PROCESSING OF YOUR PERSONAL DATA AND INFORMATION, IN ACCORDANCE WITH THIS POLICY AND THE APPLICABLE LAW, FOR THE PURPOSES OF (A) ALLOWING YOU TO USE THE SERVICES PROVIDED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI THROUGH THE VIRTUAL FITTING ROOM; (B) COMPLYING WITH THE LEGAL OBLIGATIONS AND THE OBLIGATIONS ASSUMED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI UNDER THE TERMS OF USE AND REQUIRING YOU TO FULFILL YOUR OBLIGATIONS UNDER THE TERMS OF USE; (C) IMPROVING YOUR EXPERIENCE; AND (D) MAINTAINING, PROTECTING, AND ENHANCING THE SERVICES PROVIDED.

3.2 IF YOU ARE UNDER THE AGE OF 18 (EIGHTEEN) YEARS AND/OR LACK LEGAL CAPACITY, YOU MUST BE ASSISTED OR REPRESENTED BY YOUR PARENTS OR LEGAL REPRESENTATIVES, WHO, BY AGREEING TO THIS POLICY, CONFIRM THE PROVISIONS IN ITEM 3.1.

3.3 DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI, EITHER INDEPENDENTLY OR THROUGH OPERATORS, WILL CARRY OUT INTERNATIONAL TRANSFERS OF YOUR PERSONAL DATA AND INFORMATION IN ACCORDANCE WITH THIS POLICY ANDAPPLICABLE LAW, FOR THE PURPOSE OF (A) ALLOWING YOU TO USE THE SERVICES PROVIDED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI; (B) COMPLYING WITH THE OBLIGATIONS ASSUMED BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI UNDER THE TERMS OF USE; AND (C) MAINTAINING, PROTECTING, AND ENHANCING THE SERVICES PROVIDED.

3.4 THE PROCESSING OF YOUR PERSONAL DATA BY DORIS.MOBI AND/OR THE LICENSEES OF DORIS.MOBI, IN ACCORDANCE WITH THIS POLICY AND THE APPLICABLE LAW, IS AN ESSENTIAL CONDITION FOR YOU TO USE THE VIRTUAL FITTING ROOM.

3.5 TO EXERCISE ANY OF YOUR RIGHTS UNDER THIS POLICY AND/OR THE APPLICABLE LAW REGARDING YOUR PERSONAL DATA, YOU MUST CONTACT US THROUGH THE PORTAL AVAILABLE AT THE LINK HTTPS://PORTALLGPD.DORIS.MOBI/.

3.5 After Your Image is captured in the Virtual Fitting Room and and Image is generated with Wereable item, You will be able to access a webpage via QRCode. On this page, You can download Yours Images with the Wearable Item to your device for use and sharing if You desire. Upon accessing the webpage, Your Consent for Processing will be requested. If You provide Your Consent, You are freely, knowingly, and unequivocally agreeing to the Processing of Your Image by DORIS.MOBI and/or DORIS.MOBI licensees, so that the Image(s) generated through the Virtual Fitting Room can be processed and made available to You. Without Your express Consent, access to the webpage where the Images could be obtained will not be permitted. In any case, the Processing of Your Personal Data will be end 30 minutes after using the Virtual Fitting Room.

4. Processing of User Personal Data

4.1 Personal Data Collection. To use the Virtual Fitting Room, you provide Doris.MOBI with certain Personal Data, such as height and image.

4.2 When you use the Virtual Fitting Room, Doris.MOBI and/or the Licensees of Doris.MOBI collect your information and Personal Data to provide our services and allow the experience of viewing the product without physically trying it on.

4.3 When you use the Virtual Fitting Room, Your Image will be retained for 30 (thirty) minutes. During this period, You can access, through a QR Code available in the Virtual Fitting Room, a webpage where the photos of our experience will be available, and You may share them on Your social media. This option may not be available in all Virtual Fitting Rooms and, when available, will only be enabled after Your express Consent for the Processing of Your Personal Data.

4.4 Personal Data Processing. Once Doris.MOBI and/or the Licensees of Doris.MOBI have received and/or collected your Personal Data, they begin processing these Personal Data, particularly in relation to operations such as classification, use, access, reproduction, transmission, sharing, processing, filing, storage, deletion, evaluation or control, and communication.

4.5 Purpose of Processing. Doris.MOBI and/or the Licensees of Doris.MOBI process your data for the following purposes: (a) to allow you to use the services provided by Doris.MOBI and/or the Licensees of Doris.MOBI through the Virtual Fitting Room; (b) to fulfill legal obligations and those assumed by Doris.MOBI and/or the Licensees of Doris.MOBI in the Terms of Use and require you to fulfill your obligations under the Terms of Use; (c) to enhance your experience in the Virtual Fitting Room; and (d) to maintain, protect, and improve the services provided.

4.6 Doris.MOBI and/or the Licensees of Doris.MOBI will not process your Personal Data for purposes other than those established in this Policy, and the processing will be limited to the minimum necessary for the achievement of these purposes.

4.7 Legal Grounds for Processing Personal Data. You acknowledge and agree that the Processing of Your Personal Data by Doris.MOBI and/or the Licensees of Doris.MOBI, for the use of the Virtual Fitting Room, is based on the need for the execution of the contract between Doris.MOBI and/or the Licensees of Doris.MOBI and You, represented by the Terms of Use, and also to meet the legitimate interests of Doris.MOBI and/or the Licensees of Doris.MOBI, provided that Your fundamental rights and freedoms requiring the protection of your Personal Data are respected. In turn, the Processing carried out when making Your Image available on a webpage accessed via QRCode will be based on Your express Conset, wich is freely given and only required for You to access the webpage where Your Image can be viewed and downloaded to Your device.

4.8 You also acknowledge and agree that the processing of your Personal Data may, depending on the case, be based on the need to comply with legal or regulatory obligations by Doris.MOBI and/or the Licensees of Doris.MOBI, as applicable.

4.9 Data Controller. Doris.MOBI and/or a Licensee of Doris.MOBI is the Data Controller for the processing of your Personal Data and, therefore, is responsible for making decisions regarding the processing of your Personal Data. Doris.MOBI and/or the Licensees of Doris.MOBI will maintain records of all operations of processing your Personal Data that they carry out.

4.10 Contact Information for the Data Controller. You may contact Doris.MOBI and/or the Licensees of Doris.MOBI (Data Controller for the Processing of your Personal Data) through the Privacy Portal, which can be accessed at the link: https://portallgpd.doris.mobi.

4.11 Processors. The identification of Processors, that is, those responsible for processing Personal Data on behalf of Doris.MOBI and/or the Licensees of Doris.MOBI, in accordance with Doris.MOBI and/or the Licensees of Doris.MOBI’s guidelines, instructions, and decisions, in harmony with this Policy and the security and confidentiality measures established by Doris.MOBI and/or the Licensees of Doris.MOBI, is protected by trade secrets and/or industrial secrets, in accordance with applicable law.

4.12 Responsibilities of Processors. To the extent legally applicable, Processors shall, regarding the protection of your Personal Data: (a) maintain records of the processing operations they carry out; (b) comply with all applicable laws; (c) detect, prevent, and stop any fraud, technical violations, and security breaches; and (d) protect Doris.MOBI, the Licensees of Doris.MOBI, you, and the general public, as required and permitted by applicable law, from harm to rights, property, and security.

4.13 Support. The privacy portal (available at https://portallgpd.doris.mobi) is a channel for addressing data subject requests and serves as the support responsible for receiving data subject requests, as well as providing clarifications and taking actions regarding the processing of your Personal Data.

4.14 Shared Use of Personal Data. Doris.MOBI and the Licensees of Doris.MOBI do not share Personal Data with their partners.

4.15 Start of Personal Data Processing. The processing of your Personal Data will begin as soon as you start using the Virtual Fitting Room.

4.16 The processing operations of your Personal Data will end 30 (thirty) minutes after the use of the Virtual Fitting Room.

4.17 Anonymized Data. Doris.MOBI may anonymize your Personal Data through a process that makes the data no longer identifiable as Personal Data. You acknowledge and agree that Anonymized Data is not considered Personal Data, unless the anonymization process it underwent is reversed using proprietary means or when it can be reasonably reversed (under applicable law). For the purposes of this Policy, Doris.MOBI and/or the Licensees of Doris.MOBI will not perform any process to reverse data anonymization.

4.18 In this regard, you acknowledge and agree that Anonymized Data will not be subject to the protections established in this Policy, and that Doris.MOBI and/or the Licensees of Doris.MOBI may publicly disclose Anonymized Data, including, but not limited to, for displaying trends about the use of the services by Doris.MOBI and/or the Licensees of Doris.MOBI.

5. Your Rights Regarding Your Personal Data

5.1 Doris.MOBI and/or its Licensors guarantee you the right to consult them, in a facilitated and free manner, through one of the communication channels available on our privacy portal at the link: https://portallgpd.doris.mobi/, about: (a) the manner and duration of the processing of your Personal Data; and (b) Doris.MOBI, its Licensors, and the Operators, subject to commercial and industrial secrets.

5.2 At any time, you may obtain from Doris.MOBI and/or its Licensors confirmation of the existence of the processing of your Personal Data, as well as access to your Personal Data held by Doris.MOBI and/or its Licensors.

5.3 Such confirmation and/or access will be provided upon your request, (a) in a simplified format, immediately; or (b) through a clear and complete statement that indicates the origin of the Personal Data, the absence of records, the criteria used, and the purpose of the processing, subject to the commercial and industrial secrets of Doris.MOBI and/or its Licensors, provided within a period of up to 15 (fifteen) business days from the date of your request.

5.4 The information will be provided (a) via a secure and appropriate electronic means for this purpose; or (b) in printed form, according to your preference.

5.5 Doris.MOBI and/or its Licensors will store your Personal Data in a format that facilitates the exercise of your right to access. You may request an electronic copy of your stored Personal Data, observing Doris.MOBI and/or its Licensors' commercial and industrial secrets and the terms of the applicable law, in a format that allows its subsequent use, including for other processing operations.

6. Privacy, Protection, and Security of Personal Data

6.1 Doris.MOBI and/or its Licensors consider your Personal Data valuable and understand that it must be protected from unauthorized access, accidental or unlawful destruction, loss, alteration, communication, or any form of improper or unlawful processing, in accordance with the Applicable Law.

6.2 In this regard, Doris.MOBI and/or its Licensors will adopt security measures, both technical and administrative, capable of: (a) protecting your Personal Data to the maximum extent possible and in accordance with industry standards, from unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or any form of improper or unlawful processing; and (b) preventing damage resulting from the processing of Personal Data.

6.3 When processing your Personal Data, Doris.MOBI and/or its Licensors will ensure compliance with security standards and confidentiality of records, Personal Data, and private communications, in accordance with the Applicable Law, and will observe at least the following security guidelines: (a) establishment of strict control over access to Personal Data, by defining the responsibilities of persons who will have access and exclusive access privileges for certain individuals; (b) provision of authentication mechanisms for accessing records, using, for example, two-factor authentication systems to ensure the identification of the person responsible for processing the records; and (c) creation of a detailed inventory of access to connection records and application access, containing the moment, the identity of the person responsible for the access as designated by Doris.MOBI.

6.4 Doris.MOBI and/or its Licensors will maintain the respective access records to Internet applications under confidentiality, in a controlled and secure environment, for a minimum period of 15 (fifteen) days from the respective collection.

6.5 Considering that the Internet is not a completely secure environment, it is not possible to assure or guarantee that your Personal Data will not be accessed, disclosed, altered, or destroyed due to a breach of any of the security, technical, or administrative protections employed, even if such protections meet industry standards. Nevertheless, Doris.MOBI and its Licensors will make their best efforts to preserve the confidentiality and security of the Personal Data provided by you. In this sense, Doris.MOBI and its Licensors will not share, sell, or otherwise provide your Personal Data to third parties, in any form, without your prior authorization, except: (a) in cases authorized by this Policy, such as sharing Personal Data with the Operator; (b) if Doris.MOBI and/or its Licensors are required to disclose such information pursuant to the Applicable Law or an order from a competent Government Authority; (c) to enforce the provisions of the Terms of Use applicable to you, this Policy, and/or any other document you have agreed to with Doris.MOBI and/or its Licensors; (d) for investigating potential violations by you; (e) to detect, prevent, or deal with technical issues, fraud, or security; (f) to protect the rights, property, and/or safety of the Virtual Try-On, Doris.MOBI, its Licensors, and/or you.

6.6 Doris.MOBI and/or its Licensors will not be liable for any damages incurred by you arising from third parties violating the security systems of Doris.MOBI and/or its Licensors to access this information.

7. International Data Transfer

7.1 The Personal Data we collect may be stored and processed on servers located in Brazil and the United States. Although the countries where we operate may not offer the same level of data protection as some jurisdictions, we adopt appropriate technical and organizational measures to ensure the security and protection of your Personal Data, as required by the Applicable Law.

7.2 By providing your Personal Data to Doris.MOBI, you expressly consent to the transfer, storage, and processing of your Personal Data in countries such as Brazil and the United States. Doris.MOBI ensures that any international data transfer will be carried out in compliance with the Applicable Law. The transfer will be supported by appropriate protection mechanisms and legal mechanisms to ensure an adequate level of security and privacy of the data.

8. Other Provisions

8.1 Requests from Government Authorities. Doris.MOBI and its Licensed Partners cooperate with Government Authorities to ensure copliance with the Applicable Laws, protect the integrity and security of the Virtual Fitting Room and its Users, prevent illegal activities, protect industrial and intellectual property rights, and prevent fraud. Whenever requested by Government Authorities, Doris.MOBI and/or its Licensed Partners will provide your Personal Data that they hold.

8.2 Compliance with Legal or Regulatory Obligations by Doris.MOBI. In addition to the above, Doris.MOBI and/or its Licensed Partners may perform any Personal Data processing operations required for compliance with a legal or regulatory obligation to which they are subject, without limiting other processing cases provided by the Applicable Law and this Policy.

8.3 The invalidity or unenforceability of any provision of this Policy will not affect the validity or enforceability of the other provisions. This Policy will be governed and interpreted in accordance with the laws of the Federative Republic of Brazil, and to resolve any disputes that arise directly or indirectly from it, the Court of São Paulo, State of São Paulo, is hereby elected, with the express waiver of any other, regardless of its privilege or potential privilege. In case of doubts, contact us through our privacy portal available at the link: https://portallgpd.doris.mobi/.