COMPLIANCE / INFORMATION ACCESS
Information Access & Confidentiality Policy
Principles of data and record management and confidentiality.
Dear Stakeholder,
Orbis Strato's Information Access & Confidentiality Policy reflects our commitment to transparency, accountability, and the responsible management of information across all levels of our operations. Through a consistent and structured framework, we have established clear standards for the collection, handling, disclosure, and protection of information.
Our principles are grounded in integrity, transparency, and ethical responsibility, ensuring a balanced approach between public access to information and the protection of privacy, as well as the proper management of sensitive and confidential data.
We recognize the critical importance of safeguarding the personal data and records of our stakeholders. For this reason, Orbis Strato strictly adheres to all applicable legal and regulatory requirements related to data protection, while implementing appropriate technical and organizational measures to preserve security, confidentiality, and data integrity.
Our policy also defines clear procedures for the responsible disclosure of information and the proper administration of project-related records, ensuring compliance, traceability, and operational consistency throughout all business activities.
This statement provides an overview of the measures adopted by Orbis Strato to ensure data protection, as well as the types of information we collect and the purposes for which such information is used.
Cordially,
Luís Felipe L. Monjardim Founding Principal, Partner & CEO
Ethical Commitment & Corporate Responsibility
At Orbis Strato, we are committed to engaging with our internal and external stakeholders lawfully, ethically, and transparently. We believe that data and information must be handled responsibly, appropriately, and strictly limited to what is necessary, relevant, and legitimate for each specific purpose.
Our reputation is one of our most valuable assets, and every member of our organization shares the responsibility of protecting and strengthening it. The way we conduct our business, deliver our services, and interact with our partners, clients, suppliers, communities, and stakeholders directly shapes how people perceive Orbis Strato.
Established in 2026 by engineer Luís Felipe L. Monjardim, Orbis Strato was built upon its founder's longstanding expertise in engineering, retrofits, construction, construction management, facilities management, and strategic advisory services.
At the core of our operations lies a strong commitment to technical excellence, innovation, integrity, and sustainability. Our multidisciplinary methodology is guided by environmental responsibility, operational efficiency, and high-quality standards, enabling us to deliver ambitious and sophisticated solutions while ensuring the most effective cost-benefit balance for our clients.
Through this commitment, Orbis Strato seeks to build long-term relationships based on trust, performance, compliance, and standards of excellence.
Our five governing principles are:
- Process information with integrity and fairness.
- Use data solely for transparent and defined purposes.
- Limit information to what is relevant and necessary.
- Comply with established policies and regulatory standards.
- Ensure accuracy, confidentiality, and reliability.
Privacy Policy
### 2.0 General Rules
Orbis Strato is committed to ensuring that all information is managed responsibly, ethically, and in accordance with the highest standards of transparency, confidentiality, and regulatory compliance. Our approach to information access and management is guided by the following core data privacy principles.
### 2.1 Transparency
Information must be handled with clarity and openness, ensuring that stakeholders understand how data is collected, processed, stored, and disclosed, whenever applicable.
### 2.2 Legitimate Purpose
Data collection and processing shall only occur for specific, lawful, and clearly defined purposes directly related to business operations, contractual obligations, or legal requirements.
### 2.3 Principle of Proportionality
Only the minimum amount of information necessary to achieve the intended purpose shall be collected, accessed, or processed, avoiding excessive or unnecessary data handling.
### 2.4 {{ título do 4º princípio }}
All information must be maintained accurately, securely, and with appropriate controls to preserve integrity, confidentiality, and traceability throughout its lifecycle.
### 2.5 What is expected of all involved
Every employee, consultant, contractor, and business partner acting on behalf of Orbis Strato is responsible for maintaining the confidentiality, integrity, and proper use of information. All individuals are expected to:
- Handle information with professionalism, discretion, and ethical responsibility;
- Access information strictly on a need-to-know basis;
- Protect confidential, sensitive, and proprietary information against unauthorized access, disclosure, or misuse;
- Ensure that information shared internally or externally is accurate, relevant, and up to date;
- Comply with all internal policies, confidentiality agreements, and applicable legal requirements;
- Report any actual or suspected information security incident, unauthorized disclosure, or data breach immediately;
- Preserve records and documentation in accordance with retention, contractual, and compliance requirements.
Failure to comply with these responsibilities may result in disciplinary, contractual, or legal actions.
Personal Data Protection
Orbis Strato recognizes the protection of personal data as a critical component of its governance and compliance framework. We are committed to ensuring that personal data is processed lawfully, fairly, and securely, in accordance with applicable data protection laws and international best practices.
To achieve this, Orbis Strato adopts appropriate technical and organizational measures to:
- Protect personal data against unauthorized access, disclosure, alteration, or destruction;
- Ensure data accuracy and integrity throughout processing activities;
- Restrict access to personal information based on operational necessity and authorization levels;
- Maintain secure storage, retention, and disposal procedures;
- Safeguard the privacy rights of clients, employees, partners, and stakeholders.
Particular care shall be applied when handling sensitive personal data, confidential project information, and records involving institutional, diplomatic, or private high-profile clients.
Intellectual Property and Proprietary Information
Orbis Strato recognizes that intellectual property and proprietary information are strategic assets essential to the integrity, competitiveness, and long-term value of the company and its stakeholders. All information related to designs, methodologies, technical solutions, project documentation, commercial strategies, and operational processes shall be treated with the highest level of confidentiality and protection.
### Confidential Information
Confidential information includes, but is not limited to, technical documents, project specifications, financial data, contractual records, client information, internal procedures, strategic plans, and any non-public information disclosed in the course of business operations.
All employees, consultants, contractors, and business partners are required to:
- Protect confidential information from unauthorized access, disclosure, duplication, or misuse;
- Use confidential information solely for legitimate business purposes;
- Respect all confidentiality obligations established through contracts, Non-Disclosure Agreements (NDAs), and internal policies;
- Ensure secure storage, transmission, and disposal of confidential records.
Unauthorized disclosure or misuse of confidential information may result in disciplinary action, contractual liability, and legal consequences.
Orbis Strato's sample Security Information Compliance Term is available for reference as Appendix 1 to this Policy. It is not distributed from this website; see section 9.
Due Diligence
Prequalification program for subconsultants, vendors, and business partners.
Orbis Strato is committed to conducting comprehensive due diligence across all professional, contractual, and operational relationships in order to ensure the lawful, ethical, and secure management of proprietary and confidential information.
As part of this commitment, our due diligence framework includes:
- Assessing confidentiality and information security risks prior to engaging with third parties;
- Verifying legal ownership and authorized use of technical documents, designs, and project-related materials;
- Ensuring compliance with intellectual property rights, licensing requirements, and contractual obligations;
- Identifying and mitigating risks associated with data sharing, access controls, and information protection.
To uphold the highest standards of quality, reliability, and professional integrity, Orbis Strato requires all subconsultants, vendors, and business partners to undergo a formal prequalification process before being considered eligible to participate in our projects and operations. This process is designed to evaluate the suitability and capability of each prospective partner, ensuring alignment with our operational standards and commitment to excellence.
Our selection criteria include, but are not limited to:
- Financial stability and organizational reliability;
- Technical qualifications and specialized expertise;
- Operational capacity and resource availability;
- Demonstrated track record of successful project delivery.
These criteria are carefully reviewed to ensure that each partner is fully capable of meeting the scope, quality standards, and performance expectations required by Orbis Strato and its clients.
To further protect confidential and proprietary information, all approved subconsultants, vendors, and business partners may be required to execute confidentiality agreements as part of the onboarding and contractual process. A sample of Orbis Strato's Non-Disclosure Agreement (NDA) is referenced as Appendix 2 to this Policy; see section 9.
Confidentiality — Team Obligations
The sensitive and confidential nature of Orbis Strato's operations requires all team members to uphold the highest standards of integrity, professionalism, and commitment to the interests of the organizations, clients, and stakeholders with whom we work.
Given our engagement with international organizations, diplomatic entities, and high-profile private clients, all staff members have a particular responsibility to avoid situations, actions, or relationships that may compromise operational integrity, create conflicts of interest, or adversely affect the reputation of Orbis Strato or its stakeholders.
Accordingly, all members of Orbis Strato's team shall:
- Perform their duties exclusively in the best interests of the client, stakeholder, and project objectives, acting under the authority and direction of their designated supervisors and in accordance with company policies;
- Respect the international and independent nature of their professional activities, maintaining impartiality and refraining from accepting instructions, influence, or interference from governments, institutions, or third parties external to the projects managed by Orbis Strato, except where formally authorized or contractually established;
- Refrain from accepting any remuneration, personal benefit, favor, or gift of significant value in connection with their role, duties, or services provided on behalf of Orbis Strato or its stakeholders;
- Conduct themselves at all times in a manner consistent with the professional standards and reputation of a company operating in international, diplomatic, and institutional environments;
- Avoid any activity, public statement, or personal business interest that may create actual, potential, or perceived conflicts of interest, or that may negatively affect their independence, impartiality, or professional judgment;
- Exercise the highest degree of discretion regarding all confidential, sensitive, or proprietary matters related to clients, stakeholders, and projects, both during and after the termination of their relationship with Orbis Strato;
- Refrain from the direct or indirect unauthorized disclosure, use, or dissemination of any information obtained through their professional duties.
All intellectual property, technical documents, records, methodologies, reports, and work products developed by team members in the course of their official duties shall remain the exclusive property of Orbis Strato.
Confidentiality — Human Resources
### Entering Employment
Orbis Strato's recruitment policy is designed to attract and retain professionals of the highest caliber, aligned with the technical, operational, and ethical requirements of each role. Our employment terms and conditions are structured to respond not only to the needs of our stakeholders, but also to the well-being, professional development, and long-term commitment of our team members.
In support of this objective, Orbis Strato places paramount importance on securing the highest standards of efficiency, integrity, and technical competence throughout the recruitment and appointment process.
Within this framework, we are equally committed to fostering a diverse and multicultural workforce, recognizing that broad professional perspectives and international backgrounds strengthen our ability to serve diplomatic, institutional, and private clients with excellence.
### Organization and Personnel Management
Following recruitment, the effective administration of information, records, and operational processes requires that all staff activities be conducted under clearly defined standards, policies, and professional responsibilities.
At the same time, Orbis Strato recognizes that the dynamic nature of its operations demands flexibility and continuous adaptation to evolving business, regulatory, and client requirements.
To ensure operational efficiency, information security, and compliance with internal policies, Orbis Strato shall:
- Organize, assign, and transfer staff as necessary to meet operational demands, while preserving the principles of security, confidentiality, and transparency in the handling of stakeholder information and data;
- Establish procedures for the periodic review of staff performance in order to optimize expertise allocation, assess service quality, recognize professional achievements, and ensure compliance with data protection standards;
- Implement training and professional development programs aimed at strengthening technical competencies, improving operational standards, and maintaining staff awareness of evolving policies related to confidentiality, information security, and data governance;
- Define appropriate conditions, protocols, and operational limits for business travel and external assignments, ensuring that all staff members remain fully compliant with this Information Access & Confidentiality Policy during domestic and international missions.
Data Management
### Managing Data Confidentiality
Orbis Strato's data confidentiality framework is designed to protect information against any form of accidental, unlawful, or unauthorized access, disclosure, alteration, or loss.
The company places particular emphasis on safeguarding the privacy, integrity, and controlled use of information, ensuring that access, sharing, and processing are strictly governed by defined authorization levels and legitimate operational needs.
Information is classified according to its sensitivity and potential impact. Data with low confidentiality requirements may be designated as internal or public, while information classified as high confidentiality must be strictly protected due to its potential to cause operational, legal, financial, or reputational harm if improperly disclosed.
High-confidentiality information includes, but is not limited to, sensitive project data, client information, contractual documentation, technical designs, and any proprietary or restricted materials.
When handling data confidentiality, the following principles shall always be considered:
- The authorized recipients and conditions under which data may be disclosed;
- Applicable legal, regulatory, and contractual obligations requiring confidentiality;
- Specific restrictions governing the use, processing, or dissemination of information;
- The inherent sensitivity of the data and the potential impact of unauthorized disclosure;
- The strategic or operational value of the information to unauthorized parties.
All personnel are required to apply these principles consistently to ensure the protection of Orbis Strato's information assets, as well as those of its clients, partners, and stakeholders.
### Encryption of Sensitive Information
Encryption is a fundamental security mechanism used to protect data by converting it into an unreadable format that can only be accessed by authorized individuals possessing the appropriate credentials, such as passwords or cryptographic keys.
All sensitive information should be encrypted when stored or transmitted, including but not limited to digital files, communications, and backups. The use of password protection, encryption tools, and secure transmission channels is mandatory for classified or confidential data, ensuring protection against unauthorized access or misuse.
### Data Access Management
Effective control of confidentiality depends on strict governance of data access rights. Access to information must be granted exclusively on a need-to-know basis and strictly aligned with defined roles and responsibilities.
All users must authenticate their access through secure credentials, including strong password policies and, where applicable, multi-factor authentication (MFA).
Access permissions shall be regularly reviewed to ensure they remain appropriate to current roles and responsibilities. Any access that is no longer required must be promptly revoked to minimize exposure and reduce security risks.
### Physical Security of Devices and Documents
Information security extends beyond digital systems and includes the physical protection of devices, storage media, and printed documents.
All employees and stakeholders must ensure that laptops, mobile devices, storage equipment, and hard-copy documents containing sensitive or confidential information are adequately secured against theft, loss, or unauthorized access.
Sensitive materials must never be left unattended in public or unsecured environments. When not in use, physical documents and devices should be stored in secure locations with controlled access, in accordance with internal security procedures.
### Secure Disposal of Data, Devices, and Physical Records
When information is no longer required for operational, legal, or contractual purposes, it must be disposed of in a secure and controlled manner.
Sensitive and confidential data must be permanently and securely erased to ensure it cannot be recovered, reconstructed, or misused. This applies to all digital storage media, including servers, computers, external drives, and backup systems.
Devices that have stored or processed sensitive information must be properly sanitized or physically destroyed, in accordance with applicable security standards, to eliminate any risk of residual data recovery.
Physical documents containing sensitive or confidential information must be securely destroyed through approved shredding or equivalent methods. Disposal of such materials in general waste or recycling streams is strictly prohibited.
### Data Acquisition and Usage Control
The collection of personal, sensitive, or confidential data shall always be guided by the principles of necessity, proportionality, and purpose limitation.
Orbis Strato requires that only data strictly necessary for defined operational, contractual, or legal purposes be collected and processed. The acquisition of sensitive information must be carefully evaluated and justified prior to collection.
The reduction of data exposure is a key principle of confidentiality management. Wherever possible, the volume of sensitive data collected should be minimized to reduce risk.
In addition, all use of sensitive information must be strictly limited to authorized purposes and handled in accordance with applicable internal policies, contractual obligations, and legal requirements.
### Device and System Security Management
Device security is a critical component of information protection, as endpoints often represent a primary source of exposure risk.
All systems and devices used to access or store company or client information must be secured through appropriate cybersecurity controls, including:
- Deployment of updated antivirus and endpoint protection solutions;
- Regular application of security patches and system updates;
- Controlled installation of authorized applications only (application whitelisting where applicable);
- Use of strong authentication mechanisms, including secure passwords and multi-factor authentication;
- Automatic locking and suspension of inactive sessions;
- Activation of firewall protections and network security controls;
- Use of full-disk encryption on devices containing sensitive or confidential data.
These measures are mandatory to ensure the confidentiality, integrity, and availability of all information processed within Orbis Strato's operational environment.
Appendices
This Policy has two appendices, both of them execution forms rather than web content:
- Appendix 1 — Security Information Compliance Term. Signed by individuals authorized to access information belonging to, or under the responsibility of, Orbis Strato Engenharia LTDA. - Appendix 2 — Non-Disclosure Agreement (NDA). Executed in connection with a specific scope of services and project.
Neither appendix is distributed from this website. The applicable forms are provided directly during onboarding, and a copy may be requested for review through our contact page.