Version 2026-06-19 · as of June 19, 2026
Privacy Policy — PoM Wealth Management Platform
Version: 2026-06-19
Effective: as of June 19, 2026
Last revised: June 19, 2026
Table of Contents
4. Purposes and legal bases by processing activity
7. Sharing, processors, and subprocessors
11. Data subject rights (LGPD)
12. Automated decisions and artificial intelligence
15. GDPR Addendum (EU/EEA/United Kingdom)
16. United States Addendum (CCPA/CPRA and state laws)
18. Contact
1. Who we are and scope
1.1. Primary controller
PoM Wealth Management LTDA (CNPJ 46.019.534/0001-60), operator of PoM Wealth Management, a wealth tech platform for wealth consolidation, Avenida Angélica, 2529, 4th floor, Bela Vista, São Paulo/SP, ZIP 01227-200 (“PoM”, “we”).
1.2. PoM ecosystem — platform, MFO, group, and partners
This Policy covers data processing in the context of the PoM Wealth Management Platform and services within the PoM ecosystem: wealth consolidation (wealth tech), multi family office (MGN Investimentos), regulated group entities (MGN Corretora de Seguros, MGN Correspondente Bancário), and strategic partners (custodians, financial institutions, insurers, operators, travel providers, and technology integrations).
Entities within the ecosystem may act as joint controllers, independent controllers, or processors, depending on the service and applicable contract. When another entity is the controller of a specific processing activity, this will be indicated in the onboarding flow or corresponding contract.
1.3. Related documents
- Terms of Use
- Regulatory Notice
- Cookie Policy
- Security Notice
- Artificial Intelligence Use Notice
2. Principles and legal bases
We process personal data in compliance with the Lei Geral de Proteção de Dados (Law 13.709/2018 — LGPD), observing the principles of purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, and accountability (Art. 6, LGPD).
The most commonly used legal bases include:
| Legal basis (LGPD) | Typical application |
|--------------------|---------------------|
| Performance of contract (Art. 7, V) | Platform access, consolidation, reports, contracted features |
| Compliance with legal/regulatory obligation (Art. 7, II) | Regulatory records, AML/CFT, document retention |
| Legitimate interest (Art. 7, IX) | Security, fraud prevention, aggregated improvement, audit |
| Consent (Art. 7, I) | Non-essential cookies, optional features, marketing communications when applicable |
| Regular exercise of rights (Art. 7, VI) | Defense in proceedings, collection, compliance |
When processing depends on consent, it will be requested in a prominent, specific, and informed manner and may be withdrawn as set out in Section 11.
3. Personal data we process
3.1. Registration and account data
Name, email, phone (when provided), account identifiers, organization/tenant, access profile (RBAC), language, interface preferences.
3.2. Authentication and security
Credentials (password in hash format — we do not store passwords in plain text), session tokens, linked device metadata, login logs, IP address, user-agent.
3.3. Financial and wealth data
Positions, balances, transactions, returns, asset classifications, consolidated statements, and data from integrated custodians (BTG, XP, Avenue, and others as enabled by the Client).
3.4. Wealth planning and advisory
Declared wealth, income, liabilities, goals, existing pension and insurance plans, reported corporate/family structures, investment preferences, documents voluntarily submitted for planning.
3.5. FX, travel, and insurance (when used)
Identification data, documents, payment/settlement information, travel preferences, insurance proposals, health declarations when necessary for contracting — always limited to what is required for intermediation with Partners.
3.6. Technical and audit data
Access logs, audit trails, legal terms acceptance records (`UserLegalAcceptance`), relevant configuration changes, report/PDF generation metadata.
3.7. Communications
Content of emails and requests sent to hello@pomwm.com or official channels, including privacy requests (DSAR).
4. Purposes and legal bases by processing activity
| Purpose | Data involved | Typical legal basis |
|---------|---------------|---------------------|
| Provide access and authentication | Registration, authentication | Performance of contract; legitimate interest (security) |
| Provide wealth consolidation (wealth tech) | Financial, registration | Performance of contract |
| Generate reports and PDFs | Financial, registration | Performance of contract |
| Wealth planning and advisory | Declared wealth data | Performance of contract; consent when applicable |
| Intermediating FX, travel, insurance | Per module | Performance of contract; legal/regulatory obligation |
| Record terms acceptance | Registration, technical | Performance of contract; legal obligation |
| Fraud prevention and AML/CFT | Authentication, financial, logs | Legal obligation; legitimate interest |
| Support and customer service | Registration, communications | Performance of contract |
| Platform improvement (aggregated/anonymous metrics) | Aggregated technical | Legitimate interest |
| Compliance with court and regulatory orders | As requested | Legal obligation |
| AI-assisted asset enrichment | Minimized asset data | Legitimate interest; performance of contract |
We do not sell personal data. We do not use wealth data for third-party behavioral advertising.
5. Sensitive data
5.1. Categories
Under Art. 5, II, LGPD, we may process, when strictly necessary and on an adequate legal basis (Art. 11):
- Health data — in health/life insurance proposals or plans, subject to specific consent or applicable legal ground.
We do not currently collect biometric data on the Platform.
5.2. Minimization
We collect only what is necessary for the stated purpose. Sensitive data is not used for purposes incompatible with those that justified collection.
6. Source of data
- From the data subject or User — registration, declarations, uploads, planning/insurance/travel forms;
- From custodians and Partners — authorized integrations (APIs, files, feeds);
- From group entities — when the Client already has a contractual relationship;
- Automatically — logs, strictly necessary cookies, technical metadata.
7. Sharing, processors, and subprocessors
We share data only when necessary, with contractual data protection clauses (DPA/processing agreements). Subprocessors and data partners registered in current operations:
| Subprocessor / partner | Function | Data processed | Primary region |
|------------------------|----------|----------------|----------------|
| Amazon Web Services (AWS) — EC2, RDS, S3, SSM, CloudWatch, KMS | Hosting, persistence, logs, secrets | Registration, portfolio financial, authentication, technical logs | `us-east-1` (USA) |
| XP (Data Access APIs / contracted integrations) | Source of positions and transactions | Financial data and client/portfolio identifiers | Brazil (origin); PoM processing on AWS |
| BTG Pactual (contracted APIs) | Source of financial data | Portfolio, transactions, operational metadata | Brazil (origin); PoM processing on AWS |
| Avenue (contracted APIs) | Source of international financial data | Account, positions, portfolio events | USA/Brazil (origin); PoM processing on AWS |
| EBURY BANCO DE CÂMBIO S.A. | Partner FX institution (via MGN correspondent) | Registration and financial data for FX operations | Brazil |
| Google Gemini API | Assisted enrichment and extraction in authorized flows | Subset of documents/metadata sent to the flow | Provider infrastructure (outside Brazil) |
| Duffel | Flight search and quotes in the Travel module | Segments, dates, passengers, and search preferences | Provider international infrastructure |
| LiteAPI | Hotel search and quotes in the Travel module | Destination, dates, occupancy, rates, and availability | Provider international infrastructure |
| Groq Cloud API | AI-assisted processing in internal analytical flows | Minimized asset/metadata data for inference | Provider international infrastructure |
The effective list depends on integrations enabled for each Client.
8. International transfers
Part of the processing occurs outside Brazil, primarily due to hosting on AWS (`us-east-1`) and the Google Gemini API in authorized AI flows. We adopt safeguards compatible with the LGPD and, when applicable:
- Standard Contractual Clauses (SCC) of the European Commission;
- Transfer impact assessments (TIA), when necessary;
- Supplementary technical measures (encryption, minimization).
Data subjects in the EU/EEA may request information about safeguards as set out in the GDPR Addendum.
9. Retention and disposal
Periods applied in PoM operations (unless a higher legal obligation or court order applies):
| Data type | Standard retention |
|-----------|-------------------|
| Positions and transactions (primary database) | 10 years |
| Active Client registration data | Active relationship + 5 years after termination |
| Security and audit logs | 24 months (minimum; longer if an active investigation is underway) |
| Data subject rights request records | 5 years after case closure |
| Security/privacy incident artifacts | Duration of investigation + 5 years (minimum) |
| Generated PDF reports | 24 months in operational storage |
| PDF job metadata | 24 months |
| Legal acceptances (`UserLegalAcceptance`) | Applicable audit and rights-defense period |
| Data sent to AI | Only during authorized processing and minimum necessary audit trail |
Erasure requests are fulfilled except where legal retention grounds apply (Art. 16, LGPD). Disposal uses technical measures that prevent undue recovery, when applicable.
10. Information security
We employ technical and organizational measures, including:
- Encryption in transit (TLS/HTTPS);
- Role-based access controls (RBAC): `PLATFORM_ADMIN`, `ORG_OWNER`, `BANKER`, `INVESTOR`, `END_CLIENT`;
- Credential management and password policies;
- Hosting on AWS infrastructure with access controls;
- Monitoring and audit trails;
- Internal incident response processes.
User-facing details: Security Notice. No system is 100% secure; we encourage good User practices.
11. Data subject rights (LGPD)
Under Arts. 17 to 22 of the LGPD, you may request:
1. Confirmation of processing and access to data;
2. Correction of incomplete, inaccurate, or outdated data;
3. Anonymization, blocking, or erasure of unnecessary data or data processed in non-compliance;
4. Portability to another provider, when applicable;
5. Information about sharing and the possibility of withholding consent;
6. Withdrawal of consent, when consent is the legal basis;
7. Review of decisions made solely by automated means that affect interests, under Art. 20;
8. Objection to processing in applicable legal circumstances.
How to exercise
- Email: hello@pomwm.com (subject: “Privacy — data subject rights”)
- Form: Privacy Request
Timelines and validation
- Initial response: within 5 business days after request validation
- Completion: according to complexity and applicable legal deadlines (LGPD: as a rule, up to 15 calendar days, extendable with justification)
We may request identity confirmation before fulfilling requests.
12. Automated decisions and artificial intelligence
We use AI in authorized flows (asset enrichment, categorization, assisted content in reports). Details: Artificial Intelligence Use Notice.
- We do not make solely automated decisions with significant legal effects on the data subject without an adequate legal basis and prior information, under Art. 20, LGPD.
- AI outputs may contain inaccuracies; critical information should be confirmed against official sources.
13. Children and adolescents
The Platform is not intended for persons under 18 years of age. We do not intentionally collect data from children. If we identify improper processing, we will take deletion measures as applicable.
14. Security incidents
In an incident with relevant risk or harm to data subjects, we will adopt containment, mitigation, internal recording, and, when required, notification to the ANPD and affected data subjects, within LGPD deadlines. Data subjects in the EU: per the GDPR Addendum. Reporting channel: hello@pomwm.com (security urgency).
15. GDPR Addendum (EU/EEA/United Kingdom)
When applicable to data subjects in the European Union, European Economic Area, or United Kingdom:
| Topic | Provision |
|-------|-----------|
| Controller | PoM Wealth Management LTDA |
| Legal basis | Per Sections 2 and 4; Arts. 6 and 9 GDPR for sensitive data |
| Rights | Access, rectification, erasure, restriction, portability, objection, withdrawal of consent, not to be subject to automated decision-making (Art. 22), complaint to a supervisory authority |
| Transfers | SCC, TIA, and supplementary measures per Section 8 |
| Response deadline | Up to 30 days, extendable under GDPR |
| Contact | hello@pomwm.com |
16. United States Addendum (CCPA/CPRA and state laws)
For residents of U.S. states with applicable laws (e.g., California CCPA/CPRA):
- We do not sell personal information as defined under applicable law;
- We do not share for cross-context behavioral advertising without a legal basis;
- Rights may include knowledge, access, deletion, correction, and opt-out of “sale/sharing” when applicable;
- We will not discriminate for exercising privacy rights;
- Data categories and purposes: per Sections 3 and 4;
- Requests: hello@pomwm.com or privacy form.
17. Changes to this Policy
We may update this Policy to reflect legal, regulatory, technological, or operational changes. Material changes will be communicated (email, in-app, or notice on the Platform) and, when necessary, will require new acceptance under the Terms of Use.
The current version indicates the revision date at the top of this document.
18. Contact
Privacy channel: hello@pomwm.com
Form: Privacy Request
PoM Wealth Management LTDA
Avenida Angélica, 2529, 4th floor, Bela Vista, São Paulo/SP, ZIP 01227-200
National authority (Brazil): ANPD — www.gov.br/anpd