PRIVACY POLICY
MANAGER X
Last Updated: February 1, 2026
Effective Date: February 1, 2026
Version: 1.1
TABLE OF CONTENTS
1. Introduction
2. Information We Collect
3. How We Collect Your Information
4. How We Use Your Information
5. Legal Basis for Processing (GDPR)
6. Sharing and Disclosing Information
7. International Data Transfers
8. Data Retention
9. Data Security
10. Your Privacy Rights
11. Cookies and Similar Technologies
12. Children's Privacy
13. Third-Party Links
14. Changes to This Policy
15. Contact and Data Protection Officer
1. INTRODUCTION
1.1 Who We Are
Manager X LLC ("Manager X", "we", "our", or "us") operates the Manager X platform (the "Service" or "Platform"), a web and mobile application that allows users to participate in sports engagement programs through a virtual credit system (MGX) and collectible virtual representations (Player Tokens).
Contact Information:
Legal Entity: Manager X LLC
Jurisdiction: Wyoming, United States
Address: 150 SE 2nd Ave Ste 1403 - 6414, Miami, FL 33131, United States
General Email: legal@managerx.lat
Privacy Email: privacy@managerx.lat
Website: https://managerx.lat
1.2 Our Commitment to Privacy
At Manager X, we respect and protect our users' privacy. This Privacy Policy explains:
What personal information we collect
How and why we collect, use, store, and share that information
Your rights in relation to your personal information
How you can contact us about privacy matters
1.3 Acceptance of This Policy
By accessing, registering for, or using the Service, you agree to this Privacy Policy. If you disagree with the terms of this Policy, you must not use the Service.
This Privacy Policy supplements our Terms and Conditions and any other specific privacy notices we may provide to you.
1.4 Regulatory Compliance
This Privacy Policy has been designed to comply with:
GDPR: General Data Protection Regulation of the European Union (EU 2016/679)
CCPA/CPRA: California Consumer Privacy Act and its amendments
LGPD: Brazilian General Data Protection Law
PIPEDA: Personal Information Protection and Electronic Documents Act (Canada)
Uruguay Law 18.331: Personal Data Protection Law
Other applicable privacy laws depending on the user's jurisdiction
1.5 Changes to This Policy
We may update this Privacy Policy periodically. If we make significant changes, we will notify you through:
A prominent notice on the Platform
An email to the address registered to your account
A push notification in the mobile application (if applicable)
The "Last Updated" date at the top of this Policy indicates when the most recent revision was made.
2. INFORMATION WE COLLECT
We collect different types of information from and about users of our Service:
2.1 Personally Identifiable Information
Information that can directly identify you:
2.1.1 Registration Information
First and last name
Username
Email address or wallet address
Password (stored in encrypted hash form)
Government-issued ID number (national ID, passport)
Country of residence
Date of birth (to verify age)
Preferred sports club (optional)
2.1.2 Identity Verification Information (KYC/AML)
In accordance with United States Anti-Money Laundering policies, you must complete identity verification upon joining the platform. We collect:
Photo of identity document (front and back)
Selfie photo for facial verification
Proof of address (utility bill, bank statement)
Source of funds information (for significant transactions)
Tax identification number (if applicable)
Additional information required by AML/CFT regulations
2.1.3 Payment and Transaction Information
Credit/debit card data (processed by authorized payment processors; we do not store full card numbers)
Cryptocurrency wallet address (for transactions and withdrawals)
Transaction history (MGX purchases, player/milestone contributions, token conversions, withdrawals)
Third-party payment processing information
2.2 Usage and Activity Information
Information about how you use the Platform:
Account activity: MGX purchases, player contributions, milestone contributions, token conversions, withdrawals
Browsing history: Pages visited, players viewed, searches performed
Interactions: Clicks, time on each page, features used
Preferences: Account settings, notifications, language
Communications: Support messages, comments, feedback
Referral data: Referral code used, users referred by you
Status System: Experience points (XP), Status level (Pioneer, Fan, Patron, etc.)
Token information: Player Tokens acquired, Milestone Tokens, player phase
2.3 Technical and Device Information
Information automatically collected when you access the Service:
IP address
Device type (mobile, tablet, desktop)
Operating system (iOS, Android, Windows, macOS, Linux)
Browser type and version
Unique device identifiers
General location data (country, city) based on IP
Screen resolution
Time zone
Internet Service Provider (ISP)
Referral URL (site from which you arrived at our Platform)
Network and connection information
2.4 Cookies and Identifiers
We use cookies and similar technologies to collect:
Session cookies: To keep your session active
Preference cookies: To remember your settings
Analytics cookies: To understand how you use the Platform
Advertising identifiers: (if applicable) For personalized advertising
Web beacons and tracking pixels
See Section 11 for more details on cookies.
2.5 Social Network and Third-Party Service Information
If you sign in using Google or other third-party services:
Name and profile photo
Email address
User ID on the social platform
Other information you authorize to be shared
2.6 Derived and Inferred Information
We may create derived information from collected data:
User profile: Engagement level, player preferences
Risk score: For fraud prevention, AML, and security
Segmentation: Interest categories for personalization
Predictive analysis: Behavioral and usage patterns
2.7 Public Information
Information you voluntarily make public:
Public username (visible to other users if applicable)
Profile photo (if you upload one)
Public profile information (if you enable this feature)
Comments or public content (if we enable forums/communities in the future)
2.8 Third-Party Information
We may receive information about you from third parties:
Identity verification providers (Sumsub, Onfido, or other KYC providers)
Payment processors (Stripe, NOWPayments, payment service providers)
Fraud prevention and security providers
Public databases (sanctions lists, PEPs - Politically Exposed Persons)
Business partners (sports clubs, if they share data with consent)
Public blockchain sources (for cryptocurrency transactions)
3. HOW WE COLLECT YOUR INFORMATION
We collect information through the following methods:
3.1 Information You Provide Directly
When registering: When you create an account on the Platform
When verifying your identity: During the mandatory KYC/AML process
When making transactions: MGX purchases, player/milestone contributions, withdrawals
When contacting us: Customer support, inquiries, feedback
When participating in surveys or promotions: If we offer these opportunities
When using social features: Referral program, community interactions
3.2 Automatically Collected Information
Via cookies and similar technologies: When you browse the Platform
Via analytics tools: Google Analytics, Mixpanel, or other analytics tools
Via server logs: Technical information about each visit
Via mobile SDKs: If you use our mobile application
3.3 Information from Third Parties
KYC verification providers: Identity and AML verification
Payment processors: Transaction information
Data providers: Public and commercial information
Blockchain APIs: For cryptocurrency transactions
Social networks: If you use social login
4. HOW WE USE YOUR INFORMATION
We use your personal information for the following purposes:
4.1 Provision and Management of the Service
Create and manage your account
Process your transactions (MGX purchases, contributions, withdrawals)
Manage the Player Token and Milestone Token system
Calculate and update your XP and Status
Manage the referral program
Administer Distributions and the Inactive Player Insurance
Provide customer support
Communicate with you about your account and transactions
4.2 Legal and Regulatory Compliance
Verify your identity (KYC) in accordance with AML/CFT regulations
Comply with legal and regulatory obligations
Prevent money laundering, terrorism financing, and fraud
Detect and prevent illegal or prohibited activities
Respond to legal requests from government authorities
Enforce our Terms and Conditions
Protect the rights, property, and safety of Manager X, users, and third parties
4.3 Service Improvement
Analyze how the Platform is used
Develop new features and services
Improve user experience
Conduct research and analysis
Personalize your experience on the Platform
Optimize Platform performance and security
4.4 Communications and Marketing
Send transactional notifications (purchase confirmations, withdrawals, etc.)
Send important Service updates
Send marketing communications (with your consent where required)
Respond to your inquiries and support requests
Send surveys and request feedback
4.5 Security and Fraud Prevention
Detect and prevent fraud, abuse, and suspicious activity
Conduct risk assessments
Protect against security threats
Investigate violations of our Terms
Maintain the integrity of the Platform
4.6 Statistical and Analytical Purposes
Create aggregated and anonymized data for analysis
Generate statistical reports
Conduct trend analysis
Improve algorithms and systems
5. LEGAL BASIS FOR PROCESSING (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data under the following legal bases:
5.1 Performance of a Contract
Processing necessary to perform the contract between you and Manager X (Terms and Conditions):
Account creation and management
Transaction processing
Provision of Platform services
Customer support
5.2 Compliance with a Legal Obligation
Processing necessary to comply with legal obligations:
Identity verification (KYC)
Anti-money laundering (AML)
Tax compliance
Response to court orders and authority requests
Maintenance of legally required records
5.3 Legitimate Interests
Processing necessary for our legitimate interests or those of a third party, provided these are not overridden by your rights:
Fraud prevention and security
Service improvement
Data analysis
Direct marketing (subject to right to object)
Risk management
Internal business operations
5.4 Consent
For certain types of processing, we request your explicit consent:
Email marketing (where consent is required)
Non-essential cookies
Sharing data with third parties for specific purposes not covered by other legal bases
Processing of special categories of data (if applicable)
You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
5.5 Vital Interests
In exceptional cases, we may process data to protect your vital interests or those of another person.
6. SHARING AND DISCLOSING INFORMATION
We do not sell your personal information. We share your information only in the limited circumstances described below:
6.1 Service Providers
We share information with third parties that help us operate the Platform:
Payment Processors: Stripe, NOWPayments, and other payment and cryptocurrency processors
KYC/AML Providers: Sumsub, Onfido, or other identity verification providers
Hosting Services: AWS, Google Cloud, or other infrastructure providers
Analytics Tools: Google Analytics, Mixpanel
Email Services: SendGrid, Mailchimp, or other email providers
Support Tools: Zendesk, Intercom, or other customer service systems
Security Providers: Fraud prevention and cybersecurity services
All service providers are contractually obligated to:
Use your information only for the purposes for which they were engaged
Protect your information with appropriate security measures
Not disclose your information to third parties without authorization
Comply with applicable data protection laws
6.2 Business Partners
With your explicit consent, we may share information with:
Sports clubs with which we have collaboration agreements
Sponsors or advertisers (aggregated and anonymized information only, unless specific consent is given)
6.3 Legal Compliance and Rights Protection
We may disclose your information when we believe in good faith that it is necessary to:
Comply with laws, regulations, legal processes, or governmental requests
Enforce our Terms and Conditions
Detect, prevent, or address fraud, security, or technical issues
Protect the rights, property, or safety of Manager X, our users, or others
Respond to emergencies involving risk of death or serious injury
6.4 Corporate Transactions
In the event of a merger, acquisition, reorganization, asset sale, or bankruptcy:
Your information may be transferred to the successor entity
We will notify you before your information is transferred and becomes subject to a different privacy policy
Your rights under this Policy will remain in effect until you are notified of changes
6.5 Aggregated and Anonymized Information
We may share aggregated, anonymized, or statistical information that does not personally identify you:
With business partners
For industry analysis
For academic research
With the general public (e.g., Platform usage statistics)
6.6 With Your Consent
We may share your information with third parties when you:
Provide explicit consent for specific sharing
Specifically direct us to share information (e.g., when connecting third-party accounts)
7. INTERNATIONAL DATA TRANSFERS
7.1 Global Nature of the Service
Manager X operates globally. Your personal information may be transferred to, stored in, and processed in:
The United States (Manager X LLC's principal headquarters)
Other countries where our service providers operate
7.2 Transfer Safeguards
When we transfer data outside your country of residence, we implement appropriate safeguards:
For users in the EEA, United Kingdom, and Switzerland:
Standard Contractual Clauses (SCCs) approved by the European Commission
Adequacy decisions by the European Commission (where applicable)
Transfer impact assessments
Supplementary security measures as necessary
For users in Brazil (LGPD):
Appropriate contractual guarantees
Compliance with ANPD international transfer requirements
7.3 Requesting Information
You may request information about:
The specific safeguards applied to transfers of your data
A copy of the applicable standard contractual clauses
Further details about transfer mechanisms
Contact privacy@managerx.lat for these requests.
8. DATA RETENTION
8.1 Retention Principles
We retain your personal information only for as long as necessary to:
Fulfill the purposes for which it was collected
Comply with legal, regulatory, accounting, or reporting requirements
Resolve disputes
Enforce our agreements
Protect our legitimate interests
8.2 Specific Retention Periods
Account Information:
While your account is active
7 years after account closure (AML regulatory requirements)
Transaction Information:
10 years after the transaction (tax and AML requirements)
KYC/AML Information:
7 years after the last contact or transaction (AML/CFT regulations)
Support Communications:
3 years after resolution
Marketing Data:
Until you withdraw your consent
2 years of inactivity (if you have not engaged with communications)
Logs and Technical Data:
90 days to 2 years depending on log type
Fraud Prevention Information:
7 years or as required by ongoing investigations
8.3 Data Deletion
At the end of the retention period:
We securely delete or anonymize your personal information
Anonymized data may be retained indefinitely for statistical purposes
8.4 Exceptions
We may retain information for longer when:
Required by law
There is an ongoing legal dispute
Necessary to protect our legitimate interests
You have consented to extended retention
9. DATA SECURITY
9.1 Security Commitment
We take the security of your personal information very seriously. We implement technical, administrative, and physical measures designed to protect your information against unauthorized access, use, disclosure, alteration, and destruction.
9.2 Technical Security Measures
Encryption:
Data encryption in transit via TLS/SSL
Data encryption at rest for sensitive information
Passwords stored using secure hashing algorithms
Backup encryption
Network Security:
Firewalls and intrusion detection/prevention systems
Network segmentation
24/7 security monitoring
Regular penetration testing
Access Controls:
Multi-factor authentication (MFA) for administrative access
Principle of least privilege
Regular access permission reviews
Audit logs of access to sensitive data
9.3 Administrative Security Measures
Policies and Procedures:
Documented information security policies
Incident response procedures
Business continuity and disaster recovery plan
Vendor management policy
Staff Training:
Regular security and privacy training
Confidentiality agreements with employees and contractors
Background checks for personnel with access to sensitive data
Vulnerability Management:
Regular security updates and patches
Vulnerability scanning
Responsible vulnerability disclosure program
9.4 Physical Security Measures
Controlled access to data centers
Video surveillance
Protection against natural disasters
9.5 Third-Party Security
We carefully select service providers that:
Demonstrate strong security practices
Comply with industry standards (ISO 27001, SOC 2, etc.)
Provide contractual security guarantees
Undergo regular security audits
9.6 Your Security Responsibilities
You play an important role in protecting your information:
Use strong, unique passwords
Enable two-factor authentication (2FA) when available
Do not share your login credentials
Keep your device secure
Notify us immediately of suspicious activity on your account
Be wary of phishing attempts
9.7 Security Limitations
IMPORTANT NOTICE: No security system is impenetrable. While we implement industry-standard security measures, we cannot guarantee the absolute security of your information.
In the event of a data breach affecting your personal information, we will notify you in accordance with applicable laws.
9.8 Data Breach Notification
In the event of a security breach likely to result in a risk to your rights and freedoms:
We will notify you without undue delay (within 72 hours under GDPR)
We will provide details about the nature of the breach
We will describe the measures taken to address the breach
We will recommend steps you can take to protect yourself
We will notify regulatory authorities as required by law
10. YOUR PRIVACY RIGHTS
Your rights vary depending on your geographic location. Below we describe the main rights under different regulatory frameworks:
10.1 Rights under GDPR (EEA, United Kingdom, Switzerland)
Right of Access (Article 15):
Obtain confirmation of whether we process your personal data
Access your personal data
Receive information about how your data is processed
Right to Rectification (Article 16):
Correct inaccurate personal data
Complete incomplete personal data
Right to Erasure / "Right to be Forgotten" (Article 17):
Request deletion of your personal data when:
It is no longer necessary for the purposes for which it was collected
You withdraw your consent (when consent is the legal basis)
You object to processing and there are no overriding legitimate interests
The data has been processed unlawfully
It must be deleted to comply with a legal obligation
Note: This right is not absolute; we may have legal retention obligations.
Right to Restriction of Processing (Article 18):
Limit how we use your data in certain circumstances
Applicable when you question the accuracy of data, processing is unlawful, etc.
Right to Data Portability (Article 20):
Receive your personal data in a structured, commonly used, machine-readable format
Transmit that data to another controller
Right to Object (Article 21):
Object to processing based on legitimate interests
Object to processing for direct marketing (always applicable)
Rights related to Automated Decision-Making (Article 22):
Not be subject to decisions based solely on automated processing that produce legal effects
Request human intervention in such cases
Right to Withdraw Consent:
Withdraw consent at any time (when consent is the legal basis)
Does not affect the lawfulness of processing prior to withdrawal
Right to Lodge a Complaint:
Lodge a complaint with the data protection authority in your country
10.2 Rights under CCPA/CPRA (California)
California residents have specific rights:
Right to Know: Know what personal information we collect, use, disclose, and sell
Right to Delete: Request deletion of your personal information
Right to Correct: Correct inaccurate personal information
Right to Opt-Out: Opt out of the sale or sharing of personal information
Right to Limit Use: Limit use of sensitive personal information
Right to Non-Discrimination: Not be discriminated against for exercising your rights
10.3 Rights under LGPD (Brazil)
Confirmation of processing
Access to data
Correction of incomplete, inaccurate, or outdated data
Anonymization, blocking, or deletion of unnecessary or non-compliant data
Data portability
Deletion of data processed with consent
Information about data sharing with third parties
Information about the possibility of not consenting and consequences thereof
Revocation of consent
10.4 Other Jurisdictional Rights
For users in other jurisdictions, you may have similar rights under local data protection laws.
10.5 How to Exercise Your Rights
To exercise any of these rights, you may:
Send an email to: privacy@managerx.lat
Use the rights request form on the Platform (when available)
Write to our postal address (see Section 15)
Your Request Must Include:
Your full name
Email address associated with your account
Clear description of the right you wish to exercise
Sufficient identity verification information
10.6 Identity Verification
To protect your privacy, we must verify your identity before complying with rights requests. We may:
Ask you to log in to your account
Request additional information to verify your identity
Use third-party identity verification
10.7 Response Time
We strive to respond to rights requests within:
GDPR: 1 month (extendable to 3 months in complex cases)
CCPA: 45 days (extendable to 90 days in complex cases)
LGPD: 15 days (extendable)
10.8 Fees
We generally process requests at no charge. We may charge a reasonable fee in cases of:
Manifestly unfounded or excessive requests
Additional copies of information already provided
10.9 Authorized Agents
You may designate an authorized agent to make requests on your behalf. The agent must:
Provide proof of authorization
Verify their own identity
10.10 Limitations on Rights
Your rights are not absolute. We may refuse or limit requests when:
The law requires or permits us to retain the information
Necessary to comply with legal obligations
Necessary to establish, exercise, or defend legal claims
Necessary to protect the rights of others
The request is manifestly unfounded or excessive
11. COOKIES AND SIMILAR TECHNOLOGIES
11.1 What Are Cookies?
Cookies are small text files stored on your device when you visit websites. They help websites remember information about your visit.
11.2 Types of Cookies We Use
Strictly Necessary Cookies:
Essential for Platform operation
Enable basic navigation and access to secure areas
Cannot be disabled without affecting functionality
Examples: Session cookies, authentication cookies
Performance/Analytics Cookies:
Collect information about how you use the Platform
Help improve performance and user experience
Aggregated and anonymous information
Examples: Google Analytics
Functionality Cookies:
Remember your preferences and settings
Provide enhanced features and personalization
Examples: Preferred language, notification settings
Advertising/Marketing Cookies:
Track your activity across websites
Build a profile of your interests
Display relevant ads
May be set by third-party advertising networks
11.3 Third-Party Cookies
We use third-party services that may set cookies:
Google Analytics: Web traffic analysis
Facebook Pixel: (If applicable) Conversion tracking
Stripe: Payment processing
Advertising providers: (If applicable) Targeted advertising
11.4 Other Tracking Technologies
Web Beacons/Pixels:
Small images in web pages or emails
Track whether you opened an email or visited a page
Local Storage:
Data storage in your browser
Similar to cookies but can store more data
Mobile SDKs:
In mobile applications, equivalents to cookies
Collect usage and analytics information
11.5 Cookie Management
Browser Settings:
You can control and delete cookies through your browser settings:
Chrome: Settings > Privacy and Security > Cookies
Firefox: Options > Privacy & Security > Cookies
Safari: Preferences > Privacy > Cookies
Edge: Settings > Privacy > Cookies
Note: Disabling cookies may affect Platform functionality.
Cookie Preferences Panel:
You can manage cookie preferences through our cookie settings panel on the Platform.
Third-Party Opt-Out Options:
Google Analytics: tools.google.com/dlpage/gaoptout
Network Advertising Initiative: optout.networkadvertising.org
Digital Advertising Alliance: optout.aboutads.info
11.6 Do Not Track (DNT)
We currently do not respond to DNT browser signals, as there is no established industry standard for DNT.
11.7 Cookie Policy Updates
We may update our use of cookies. Significant changes will be communicated by updating this Policy and providing notice on the Platform.
12. CHILDREN'S PRIVACY
12.1 Age Restriction
Manager X is NOT directed at individuals under the age of 18. Information obtained about youth soccer players is provided by their parents or legal representatives following written consent.
12.2 Age Verification
During registration, we request your date of birth to verify that you are at least 18 years old (or the legal age of majority in your jurisdiction).
12.3 If We Discover Children's Data
If we discover that we have inadvertently collected personal information from a minor:
We will delete the information as soon as possible
We will close the minor's account
We will notify authorities as required by law
12.4 Reporting Minors
If you believe a minor has provided personal information to Manager X, please contact us immediately at: privacy@managerx.lat
12.5 COPPA Compliance
We comply with the Children's Online Privacy Protection Act (COPPA) in the United States, which requires verifiable parental consent before collecting information from children under 13. As we do not collect information from individuals under 18, we are in compliance with COPPA.
12.6 Underage Players on the Platform
IMPORTANT: Although the Platform presents information about soccer players under the age of 18 (youth categories, U-17, U-19, etc.), these players are NOT users of the Platform.
We do not collect personal information directly from minor players. Information about minor players comes from:
Public sources (clubs, leagues, federations, media)
Agreements with sports clubs (with appropriate consent from parents/legal guardians)
Public sports databases
This information is used exclusively to:
Provide sports information to Platform users
Enable the Player Token system
Facilitate the sports development support program
We protect the privacy of minor players by:
Not publishing sensitive personal information
Only displaying publicly available sports information
Complying with child protection laws
Respecting requests from clubs and parents/guardians to limit information
13. THIRD-PARTY LINKS
13.1 Third-Party Websites and Services
Our Platform may contain links to third-party websites, applications, or services, including:
Sports club websites
Social networks (Twitter/X, Facebook, Instagram, TikTok)
Payment processors (Stripe, cryptocurrency providers)
Authentication providers (Google)
Sports news sources
Video platforms (YouTube)
13.2 No Responsibility
We are not responsible for the privacy practices of these third parties. This Privacy Policy does NOT apply to third-party sites or services.
13.3 Review Third-Party Policies
We strongly encourage you to review the privacy policies of any third-party site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of third-party sites.
13.4 Social Login
If you use "Sign in with Google" or other social login options:
The provider (Google, etc.) may collect information about you
We may receive limited information from your profile (name, email, photo)
Your use of these services is subject to their own terms and privacy policies
You can revoke access at any time through the provider's account settings
13.5 Cryptocurrency Wallet Integration
If you connect a cryptocurrency wallet:
Blockchain information is public by nature
The wallet provider may have its own privacy policy
We do not control the privacy of transactions on public blockchains
14. CHANGES TO THIS POLICY
14.1 Right to Modify
We reserve the right to modify this Privacy Policy at any time to reflect:
Changes in our data processing practices
Changes in law or regulations
New Platform features
Better privacy practices
Feedback from users or regulatory authorities
14.2 Notification of Changes
14.2.1 Material Changes
For material changes that reduce your rights or expand our processing practices, we will notify you via:
Email to the address registered to your account (at least 30 days before taking effect)
Prominent notice on the Platform
Push notification in the mobile application (if available)
Request for renewed consent (when required by law)
Examples of material changes:
New uses of personal information
New categories of third parties with whom we share information
Changes to data retention periods
Changes to international data transfers
14.2.2 Minor Changes
For minor changes (typographical corrections, formatting updates, clarifications):
We will update the "Last Updated" date
We will post the revised version on the Platform
No separate notification is required
14.3 Reviewing Changes
We recommend reviewing this Policy periodically (at least every 6 months) to stay informed about how we protect your information.
14.4 Continued Use as Acceptance
Your continued use of the Service after changes are posted constitutes your acceptance of the revised Policy, unless the law requires explicit consent.
In jurisdictions where explicit consent is required for certain changes (such as under GDPR), we will request your consent before the changes take effect.
14.5 Archive of Previous Versions
We maintain an archive of previous versions of this Policy. You may request previous versions by contacting: privacy@managerx.lat
We will provide:
Requested version with effective date
Summary of main changes between versions (if available)
15. CONTACT AND DATA PROTECTION OFFICER
15.1 Questions or Concerns
If you have questions, concerns, or requests related to this Privacy Policy or our privacy practices, you may contact us:
Manager X LLC
Attn: Privacy Officer / Data Protection Officer
Email:
Privacy: privacy@managerx.lat
Legal matters: legal@managerx.lat
Mailing Address:
150 SE 2nd Ave Ste 1403 - 6414
Miami, FL 33131
United States
Website: https://managerx.lat
15.2 Data Protection Officer (DPO)
For users in the EEA, United Kingdom, or Switzerland, we have designated a Data Protection Officer in accordance with Article 37 of the GDPR:
Email: aldo.alvarez@managerx.lat
Address: 150 SE 2nd Ave Ste 1403 - 6414
Miami, FL 33131
The DPO oversees GDPR compliance and may be contacted for:
Exercising your GDPR rights
Questions about data processing
Complaints about privacy practices
Requests for information about data transfer safeguards
Guidance on your data protection rights
15.3 EU Representative
If required under GDPR Article 27 (for controllers outside the EU that offer goods/services to individuals in the EU), we will designate an EU representative and provide their contact details here.
Current Status: [Pending designation if required per legal assessment]
15.4 Supervisory Authorities
You have the right to lodge a complaint with a data protection authority, particularly in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
Main Supervisory Authorities:
European Union:
Full list of data protection authorities: edpb.europa.eu/about-edpb/board/members_en
Each member state has its own supervisory authority
United Kingdom:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
Email: casework@ico.org.uk
Brazil:
Autoridade Nacional de Protecao de Dados (ANPD)
Website: gov.br/anpd
Email: comunicacao@anpd.gov.br
Uruguay:
Unidad Reguladora y de Control de Datos Personales (URCDP)
Website: urcdp.gub.uy
Email: urcdp@minterior.gub.uy
15.5 Response Time
We strive to respond to all privacy inquiries in a timely manner:
General inquiries: Within 5 business days
Rights exercise requests: Per applicable legal deadlines (GDPR: 1 month; CCPA: 45 days; LGPD: 15 days)
Security incidents: Immediate response, notification per legal deadlines (72 hours under GDPR)
15.6 Information to Provide
To process your inquiry or request efficiently, please include:
Your full name
Email address associated with your account (if you have one)
Detailed description of your inquiry or request
Any relevant information to help us understand and respond
For rights exercise requests: Specify which right you wish to exercise
15.7 Available Languages
We provide support in:
Spanish (primary language)
English
Portuguese (for users in Brazil)
If you need assistance in another language, we will make reasonable efforts to accommodate your request.
ACKNOWLEDGMENT AND CONSENT
For Users Where Consent is Required by Law:
By checking the box during registration that reads:
[ ] "I have read and agree to the Manager X Privacy Policy"
You acknowledge and consent that:
You have read and understood this Privacy Policy in its entirety
You agree to the collection, use, and disclosure of your personal information as described in this Policy
You consent to the processing of your personal data in accordance with this Policy
You understand the purposes for which your information is collected and processed
You understand that certain information is mandatory for registration and use of the Service
You understand that you may exercise your privacy rights at any time
You understand that you may withdraw your consent at any time (subject to legal retention obligations)
Additional and Specific Consents
During your use of the Service, we may request additional and separate consents for:
Email marketing and promotional communications
SMS/WhatsApp marketing (if we offer this service)
Non-essential cookies (analytics, advertising)
Sharing information with specific third parties for particular purposes
Processing of special categories of data (if applicable in the future)
Use of your image or testimonials for marketing purposes
These consents will be requested separately and clearly, and may be withdrawn independently without affecting your ability to use the Service (except for features that directly depend on that processing).
Consent Not Required:
Please note that for certain types of processing, your consent is NOT required because we process your data under other legal bases:
Performance of contract (Terms and Conditions)
Compliance with legal obligations (KYC/AML, tax compliance)
Legitimate interests (fraud prevention, security, service improvements)
For these types of processing, your information will be processed regardless of consent, as permitted by law.
APPENDIX: GLOSSARY OF PRIVACY TERMS
Anonymization: An irreversible process of removing or modifying personal information so that it cannot be associated with a specific individual, even if combined with other available data.
Special Categories of Data / Sensitive Data: Information that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data about sex life or sexual orientation. Manager X generally does NOT process these categories.
Consent: A freely given, specific, informed, and unambiguous agreement by which an individual accepts, by statement or clear affirmative action, the processing of their personal data for one or more specific purposes.
Controller / Data Controller: The entity (natural or legal person, public authority, agency, or other body) that, alone or jointly with others, determines the purposes and means of processing personal data. Manager X LLC is the controller of the data it processes.
Personal Data / Personal Information: Any information relating to an identified or identifiable natural person ("data subject"). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
Processor / Data Processor: A natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. Examples: Our hosting providers, payment processors, KYC providers.
Legitimate Interest: A legal basis for processing under GDPR that allows processing when it is necessary for the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
Data Minimization: The principle that personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
Data Portability: The right of the data subject to receive personal data concerning them that they have provided to a controller, in a structured, commonly used, machine-readable format, and to transmit that data to another controller without hindrance.
Processing: Any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Pseudonymization: The processing of personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data cannot be attributed to an identified or identifiable natural person.
Data Subject: An identified or identifiable natural person to whom the personal data relates.
International Data Transfer: The movement of personal data from the country of origin (where it was collected) to another country or jurisdiction. Requires appropriate safeguards under GDPR and other laws.
Personal Data Breach / Security Breach: A security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
TRANSPARENCY AND ACCOUNTABILITY STATEMENT
Manager X LLC is deeply committed to transparency in our privacy practices and to the responsible protection of your personal information.
Our Commitments:
Transparency: This Privacy Policy has been written in clear, accessible, and understandable language to ensure you fully understand how we handle your personal information.
Data Minimization: We collect only the personal information we need to provide and improve our Service.
Security: We implement robust technical, administrative, and physical security measures to protect your information.
Respect for Your Rights: We facilitate the exercise of your privacy rights and respond to requests in a timely manner.
Legal Compliance: We comply with all applicable data protection laws in the jurisdictions where we operate.
Continuous Improvement: We regularly review and update our privacy practices to maintain the highest standards.
Your Role:
Privacy is a shared responsibility. We encourage you to:
Read and understand this Policy
Exercise your rights when you deem appropriate
Keep your account credentials secure
Contact us with questions or concerns
Provide feedback on our privacy practices
We Are Here to Help:
If anything in this Policy is unclear, if you have questions about our privacy practices, or if you wish to exercise your rights, please do not hesitate to contact us at:
privacy@managerx.lat
We are committed to responding to your inquiries in a timely, complete, and helpful manner.
CERTIFICATIONS AND COMPLIANCE
Manager X LLC is committed to the highest standards of data protection and privacy:
Regulatory Frameworks Complied With:
GDPR (General Data Protection Regulation - European Union)
CCPA/CPRA (California Consumer Privacy Act)
LGPD (Brazilian General Data Protection Law)
PIPEDA (Personal Information Protection - Canada)
Law 18.331 (Personal Data Protection - Uruguay)
Implemented Security Standards:
Encryption of data in transit and at rest
Role-based access controls
Regular security audits
24/7 security monitoring
Incident response plan
Regular staff training in privacy and security
Planned Certifications:
[Manager X plans to obtain additional certifications such as ISO 27001, SOC 2, as the business grows]
Last Privacy Audit: January 31, 2026
Last Updated: February 1, 2026
Next Scheduled Review: August 1, 2026
Version: 1.1
© 2026 Manager X LLC. All rights reserved.
END OF PRIVACY POLICY
To start using Manager X, you must:
Read and understand this Privacy Policy
Read and accept the Terms and Conditions
Check the acceptance box during registration
Complete the identity verification process (KYC/AML)
Thank you for trusting Manager X with your personal information. We take this responsibility very seriously.