Data Processing Agreement (DPA)
Last updated: September 1, 2026 · Version 2.1
This Data Processing Agreement ("DPA") is an integral and inseparable part of the Terms of Service of EvoCODE IA® Ltda and governs the processing of personal data that we, EvoCODE IA® Ltda, carry out on behalf of the Customer in the provision of the Kairo, TraceLog, and AgenteNOC products (collectively, the "Services"). By accepting the Terms of Service, the Customer automatically accedes to this DPA, with no separate signature required.
This DPA was drafted to simultaneously satisfy the LGPD (Lei Geral de Proteção de Dados — Brazilian General Data Protection Law, Law No. 13,709/2018) and the General Data Protection Regulation of the European Union (Regulation (EU) 2016/679 — "GDPR"), in particular its Article 28, as well as the GDPR as incorporated into United Kingdom law ("UK GDPR") and the service provider provisions of applicable US state legislation (including the CCPA/CPRA).
1. Definitions and roles
1.1. The terms "dados pessoais", "tratamento", "titular", "controlador", "operador", "encarregado", "incidente de segurança" and related terms have the meaning assigned to them by the LGPD; the terms "personal data", "processing", "data subject", "controller", "processor", "personal data breach" and related terms have the meaning assigned to them by the GDPR. Where this DPA uses a term from one regime, the equivalent term of the other regime is deemed equally covered.
1.2. Roles. For the personal data processed through the Services on the Customer's behalf and under its instructions ("Customer Data"):
- the Customer is the Controller (LGPD, Art. 5, VI) / Controller (GDPR, Art. 4(7)) — or, where the Customer itself acts as a processor for a third party, it acts as controller vis-à-vis us for the purposes of this DPA and warrants that it has the necessary authorization;
- EvoCODE IA® Ltda is the Processor (LGPD, Art. 5, VII) / Processor (GDPR, Art. 4(8)) and, for the purposes of California legislation, a service provider.
1.3. This DPA does not apply to the data of which EvoCODE is the controller — the Customer's account registration data, billing and payment data, platform security logs, aggregated usage telemetry, and website/marketing data — which are governed by our Privacy Policy.
1.4. "Subprocessor" means any third party engaged by us to process Customer Data in support of the provision of the Services.
1.5. "Data Protection Legislation" means all rules applicable to the processing of Customer Data, including the LGPD, ANPD regulations and resolutions (in particular Resolutions CD/ANPD No. 15/2024 and No. 19/2024), the GDPR, the UK GDPR, and applicable US state privacy laws.
2. Subject matter, duration, and nature of the processing
2.1. The subject matter of this DPA is the processing of Customer Data strictly necessary for the provision of the subscribed Services, as described in Annex I.
2.2. The duration of the processing coincides with the term of the Terms of Service, plus the return and deletion period provided for in Clause 11.
2.3. The nature and purpose of the processing are the technical operations of collection, storage, organization, consultation, use, transmission, and deletion of personal data inherent to the operation of each product, as per Annex I. We do not sell Customer Data, do not share it for cross-context behavioral advertising, and do not use it to train artificial intelligence models of our own or of third parties, except upon express and documented instruction of the Customer to the contrary.
3. Documented instructions
3.1. We will process Customer Data exclusively in accordance with the Customer's documented instructions, which comprise: (a) the Terms of Service and this DPA; (b) the configuration of the Services made by the Customer and its authorized users in the platform interfaces; and (c) additional written instructions, reasonable and compatible with the Services, transmitted through the official channels.
3.2. We may process Customer Data outside those instructions only where required by law or by order of a competent authority; in that case, we will inform the Customer before the processing, unless such communication is prohibited by law.
3.3. Duty to warn. If we consider that an instruction of the Customer violates the Data Protection Legislation, we will warn the Customer immediately and may suspend execution of the instruction until the matter is clarified, without this constituting a contractual breach on our part (LGPD, Arts. 39 and 42, paragraph 1; GDPR, Art. 28(3), last subparagraph).
3.4. The Customer warrants that the Customer Data was collected and is shared with us lawfully, on an adequate legal basis, and that the instructions it transmits to us comply with the Data Protection Legislation. The Customer is solely responsible for assessing the lawfulness of the purposes and legal bases of the processing it determines.
4. Confidentiality
4.1. We ensure that every person authorized to process Customer Data — employees, contractors, and administrators — is bound by an obligation of confidentiality, whether by contract or legal duty, which survives the end of the relationship.
4.2. Access to Customer Data is limited to what is strictly necessary for the provision of the Services (least privilege principle), as detailed in Annex II.
5. Security of processing
5.1. We implement and will maintain the technical and organizational measures described in Annex II, appropriate to the nature of the data processed and the risks involved (LGPD, Arts. 46 to 49; GDPR, Art. 32), including encryption, access control, logical isolation between tenants, audit logging, and backups.
5.2. We may update the measures in Annex II to keep pace with technological and threat developments, provided that the change does not materially reduce the overall level of security.
6. Subprocessors
6.1. General authorization. The Customer grants us general authorization to engage Subprocessors, in the manner of Article 28(2) of the GDPR and the good practices of the LGPD.
6.2. Public list. We maintain a Public List of Subprocessors, organized by product, with identification, purpose, data involved, location, and transfer safeguard, available in the legal hub at https://evocode.ia.br/legal. The list in force on the date of acceptance is deemed approved by the Customer.
6.3. Prior notification and objection. We will notify the Customer (by e-mail or notice on the platform) with at least 15 (fifteen) days' advance notice before adding or replacing a Subprocessor. The Customer may submit a reasoned objection on legitimate data protection grounds, through the channel dpo@evocode.ia.br, within that period. Upon receiving the objection, we will seek in good faith a reasonable alternative (for example, a configuration that avoids the new Subprocessor); if that is not possible, the Customer may terminate, without penalty, the portion of the Services that depends on the objected-to Subprocessor.
6.4. Flow-down of obligations. We will enter into a written contract with each Subprocessor imposing data protection obligations substantially equivalent to those of this DPA, including security, confidentiality, and purpose limitation. We remain fully liable to the Customer for the Subprocessors' compliance with the obligations we flow down to them.
6.5. The services contracted directly by the Customer and merely connected through the platform are not Subprocessors (for example, the Customer's own Google, Microsoft, Zoom, Stripe, or WABA account when the integration uses the Customer's credentials); in such cases, the relationship is governed by the terms between the Customer and the respective vendor.
7. International transfers
7.1. Some Subprocessors process data outside Brazil (see the Public List of Subprocessors). Every international transfer of Customer Data will comply with a valid transfer mechanism under the applicable Data Protection Legislation.
7.2. Flows originating in Brazil (LGPD). For transfers of personal data from Brazil abroad, we adopt the ANPD Standard Contractual Clauses, approved by Resolution CD/ANPD No. 19/2024, which are incorporated into this DPA by reference, without modification, with EvoCODE as exporter and the Subprocessor or foreign affiliate as importer, or another valid mechanism under Article 33 of the LGPD (such as an ANPD adequacy decision, where one exists). In the event of a conflict between this DPA and the ANPD standard clauses, the latter prevail with respect to the transfer they govern.
7.3. Flows subject to the GDPR/UK GDPR. Where the processing is subject to the GDPR and involves a transfer to a country without an adequacy decision, the Standard Contractual Clauses of the European Commission (Implementing Decision (EU) 2021/914) apply — module 2 (controller→processor) or module 3 (processor→subprocessor), as the case may be — incorporated by reference, with EvoCODE or the Subprocessor as importer. Where the UK GDPR applies, the UK International Data Transfer Addendum (or the IDTA) approved by the ICO is additionally incorporated. In the event of a conflict, the SCCs/Addendum prevail with respect to the transfer they govern.
7.4. We will assess, where required, the level of protection of the destination country and will adopt reasonable supplementary measures (encryption, pseudonymization, minimization) to ensure essentially equivalent protection.
8. Assistance to the Controller
8.1. Data subject rights. Taking into account the nature of the processing, we will provide reasonable assistance, through appropriate technical and organizational measures, so that the Customer can respond to data subject requests (LGPD, Art. 18; GDPR, Arts. 12 to 23), including the export, rectification, and deletion features available on the platform.
8.2. Redirection. If we directly receive a data subject request relating to Customer Data (for example, a Kairo invitee or an AgenteNOC conversation interlocutor), we will not respond on the merits: we will forward the request to the Customer without undue delay and direct the data subject to contact the Customer, unless we are under a contrary legal obligation.
8.3. DPIA and impact assessments. We will provide reasonable assistance to the Customer in the preparation of Personal Data Protection Impact Reports (RIPD, LGPD, Art. 38) and Data Protection Impact Assessments (GDPR, Arts. 35 and 36), as well as in prior consultations with the authority, providing the information about the processing that is in our possession.
8.4. Authorities. We will cooperate with the ANPD and, where applicable, with EEA/United Kingdom data protection authorities, and will provide reasonable assistance to the Customer in inspections or requests from those authorities relating to Customer Data.
8.5. Assistance that exceeds the standard features of the platform and demands disproportionate effort may be charged at reasonable rates, communicated in advance.
9. Security incidents
9.1. Notification to the Customer. Upon becoming aware of a security incident affecting Customer Data, we will notify the Customer without undue delay and, as a maximum target, within 48 (forty-eight) hours from the discovery of the incident, by e-mail to the account administrator and/or by notice on the platform.
9.2. Minimum content. The notification will contain, at a minimum and to the extent of the information available, the content required by Resolution CD/ANPD No. 15/2024: (a) a description of the nature and category of the incident; (b) the categories of data subjects and of personal data affected, with estimated volumes; (c) the technical and security measures adopted before and after the incident; (d) the risks and possible consequences for data subjects; (e) the mitigation and remediation measures adopted or proposed; (f) the relevant dates (occurrence, discovery, communication); and (g) the contact details of our Data Protection Officer. Information unavailable in the first notice will be supplemented in successive updates, in phases.
9.3. It is for the Customer, in its capacity as controller, to assess the risk and decide on the communication of the incident to the ANPD and to data subjects (regulatory deadline of 3 business days, where there is relevant risk or damage) or to the EEA/UK authorities (72 hours, GDPR, Art. 33). We will provide reasonable assistance in that assessment and communication, and we will not communicate the incident to authorities or data subjects on the Customer's behalf without its instruction, except under our own legal obligation.
9.4. We will keep an internal record of incidents involving personal data for a minimum period of 5 (five) years, and will adopt the applicable containment, eradication, and recovery measures. The notification of an incident does not constitute an admission of fault or liability.
10. Audits
10.1. We will make available to the Customer, upon request, the information reasonably necessary to demonstrate compliance with this DPA, primarily through available documentation, audit reports, attestations, and certifications (for example, summaries of security tests and descriptions of the measures in Annex II).
10.2. Where such information is demonstrably insufficient to meet a legal or regulatory requirement of the Customer, the Customer may conduct (directly or through an independent auditor that is not a competitor of ours, bound by confidentiality) an on-site or remote audit, provided that: (a) there will be a minimum prior notice of 30 (thirty) days; (b) the audit will take place no more than 1 (one) time per 12 (twelve)-month period, except following a relevant incident or a determination by an authority; (c) it will be conducted during business hours, with reasonable scope and duration agreed in advance, without access to other customers' data or to trade secrets; and (d) the costs will be borne by the Customer, including the reasonable time of our team beyond the first day of accompaniment.
10.3. We will remedy, within a reasonable period, material non-conformities with this DPA identified in an audit.
11. Return and deletion of data
11.1. Upon termination of the Terms of Service, for any reason, the Customer may export the Customer Data for 60 (sixty) days from termination, through the platform's export features or by request to support, in a structured and commonly used format. The same 60 (sixty)-day window applies to an account without an active Plan — including an account that never subscribed to a Plan, maintained only in registration or under evaluation —, in which case, since there is no termination from which to count the period, the window is calculated per data item, from its respective collection or generation, in accordance with the periods stated in Annex I-B. The Customer, in its capacity as controller, instructs EvoCODE to observe these windows and acknowledges that they form part of the documented processing instructions of this DPA.
11.2. After the period in item 11.1, we will delete the Customer Data from the production systems within a reasonable period and from backups in accordance with the normal backup rotation cycles, except where retention is required by law (for example, application access records for 6 months, pursuant to Article 15 of the Marco Civil da Internet (Brazilian Internet Civil Framework, Law No. 12,965/2014), and tax documents for the statutory periods). Data retained under a legal obligation remains protected by this DPA and will be processed only for the purpose of the retention.
11.3. We will certify the deletion in writing, upon the Customer's request.
12. Liability
12.1. Each party is liable for the damage it causes by reason of non-compliance with the Data Protection Legislation, in the manner of Articles 42 to 45 of the LGPD and Article 82 of the GDPR. In our capacity as processor, we are jointly and severally liable only where we fail to comply with the legal obligations specific to processors or where we have not followed the Customer's lawful instructions (LGPD, Art. 42, paragraph 1, I).
12.2. The total liability of each party under this DPA is subject to the liability cap provided in the Limitation of Liability clause of the Terms of Service (cap equivalent to the amounts paid in the 12 months preceding the event), except for willful misconduct or gross negligence and the cases in which the law prohibits limitation. Nothing in this DPA limits the right of recourse between the parties in proportion to their share in the damage (LGPD, Art. 42, paragraph 4).
12.3. The Customer shall indemnify EvoCODE for losses arising from processing that the Customer determines in violation of the Data Protection Legislation, including unlawful instructions maintained after the warning under Clause 3.3.
13. Precedence, term, and final provisions
13.1. This DPA remains in force for as long as the Terms of Service remain in force and, with respect to the deletion, confidentiality, and assistance obligations, until their full performance.
13.2. Precedence. In matters of personal data protection, this DPA prevails over the Terms of Service, the Acceptable Use Policy, and any other contractual document between the parties. The ANPD standard clauses and the SCCs/UK Addendum, where applicable, prevail over this DPA with respect to the transfers they govern (Clauses 7.2 and 7.3).
13.3. Amendments to this DPA follow the amendment procedure of the Terms of Service, with prior notification; amendments required by a change in the Data Protection Legislation may take effect immediately, with notice to the Customer.
13.4. The governing law and venue defined in the Terms of Service apply to this DPA, without prejudice to the mandatory provisions of the Data Protection Legislation applicable to the processing.
Annex I — Description of the processing (by product)
A. Kairo — multi-tenant scheduling with WhatsApp-based service and AI agents
| Element | Description |
|---|---|
| Categories of data subjects | Invitees of the Customer's bookings; interlocutors of WhatsApp conversations with the Customer's AI agents; end users authorized by the Customer. |
| Categories of data | Invitee data: name, e-mail, phone, responses to booking forms, time zone, language; content of WhatsApp conversations with AI agents (messages, agent responses, sender identifiers, audio/voice notes); event and availability data synchronized from calendars (Google, Microsoft) and meeting links (Zoom/Teams/Meet); communication metadata (dates, times, delivery status). |
| Sensitive data | Not requested by the platform; may appear incidentally in the free-form content of messages and forms, under the Customer's responsibility. |
| Operations | Collection via booking pages and messaging channels; storage; organization; consultation; use by AI agents to respond and schedule; transmission to messaging, calendar, video, and AI subprocessors; sending of transactional e-mails and messages; deletion. |
| Purpose | To operate the scheduling, notifications, and automated customer service configured by the Customer. |
B. TraceLog — network observability
| Element | Description |
|---|---|
| Categories of data subjects | Persons identifiable from the Customer's network telemetry (subscribers/users of monitored connections); visitors to the Customer's public status pages. |
| Categories of data | Network telemetry: IP addresses, routes (traceroute), latency, packet loss, SLA metrics; technical equipment identifiers; approximate geolocation derived from IP; technical logs. Telemetry retention according to the subscribed plan: 7, 30, 90, or 365 days, subject to a minimum technical period of 40 (forty) days for raw measurements (latency and route history), necessary to produce the monthly SLA report for the preceding closed calendar month. Aggregated data (hourly rollups): up to 2× the plan's window. Accounts without an active plan: 60 (sixty) days, aligned with the export window of Clause 11. The Customer, as controller, acknowledges and instructs that these periods form part of the documented processing instructions of this DPA. |
| Sensitive data | Not applicable by design. |
| Operations | Automatic collection by probes/collections configured by the Customer; storage with expiry per plan; aggregation; consultation in dashboards; alerts; deletion. |
| Purpose | Monitoring of the performance, availability, and SLA of the networks designated by the Customer. |
C. AgenteNOC — AI agents for NOCs/ISPs via WhatsApp/Telegram/Discord
| Element | Description |
|---|---|
| Categories of data subjects | Interlocutors of the Customer's agents (end customers, technicians, and staff of the Customer); participants in WhatsApp/Telegram/Discord groups monitored or served by the agents. |
| Categories of data | Conversation content (interaction records: user message, agent response, sender identifiers — phone number/username —, audio and transcripts); group participant data; technical network diagnostic data provided in the conversations; the Customer's network device credentials, stored encrypted; message metadata. |
| Sensitive data | Not requested; may appear incidentally in the free-form content of the conversations, under the Customer's responsibility. |
| Operations | Receiving and sending messages; storage of interaction records; use by AI models for diagnostics and response; transmission to messaging and AI subprocessors; error monitoring; deletion. |
| Purpose | Automated customer service, monitoring, and network diagnostics, as configured by the Customer. |
D. Provisions common to Annex I
- Duration: term of the Terms of Service + export/deletion period (Clause 11) and retention per plan/law.
- Subprocessors: as per the Public List of Subprocessors by product.
- Use of AI: the content submitted to AI providers is used exclusively to generate the requested response/functionality; it is not used to train models (Clause 2.3).
Annex II — Technical and organizational measures
- Encryption in transit: modern TLS on all external communications (application, APIs, webhooks, integrations).
- Encryption at rest: data stored on infrastructure with disk/volume encryption; encrypted backups.
- Encryption of credentials and secrets: integration credentials, OAuth tokens, API keys, and network device credentials stored with application-level encryption (fields with the
encryptedcast), with keys managed outside the database; infrastructure secrets kept in centralized secret management, outside the source code. - Multi-tenant isolation: single-database architecture with logical isolation per tenant: every tenant data model carries a tenant identifier and is accessed exclusively through an automatic scope bound to the authenticated tenant's context, preventing cross-tenant queries; automated tests cover the isolation.
- Access control: authentication with strong passwords and MFA support; role- and permission-based authorization (least privilege); segregation between production and development environments; restricted, individually attributed, and logged administrative access; periodic access reviews and immediate revocation upon offboarding.
- Audit logs: logging of relevant activities (authentication, administrative actions, changes to sensitive tenant data) with timestamp and author; access records kept in accordance with the Marco Civil da Internet; protection of the logs against alteration.
- Backups and continuity: automatic and periodic database backups, encrypted, with restoration tests; documented disaster recovery procedures.
- Application security: development lifecycle with code review, monitored dependencies, timely correction of vulnerabilities, CSRF protection, input validation, rate limiting, and error and performance monitoring.
- Network and infrastructure security: isolated containers, minimal port exposure, firewalls, system security updates, internal TLS where applicable.
- Minimization and retention: collection limited to what is necessary per feature; automatic expiry of telemetry per plan, subject to the minimum technical period stated in Annex I; deletion routines upon contract termination.
- Incident management: internal procedure for detection, containment, assessment, and notification (Clause 9); incident records kept for 5 years.
- Organization: designated and published Data Protection Officer; internal security and privacy policy; staff training and confidentiality undertakings; assessment of vendors/Subprocessors prior to engagement.
Version history
Below we record the material changes to this DPA. The current version and the other pieces of the legal corpus are published in the legal hub at https://evocode.ia.br/legal.
Version 2.1 — September 1, 2026
- TraceLog telemetry retention periods (Annex I-B and Annex II, item 10). The window for the TraceLog Pro plan changed from 180 (one hundred eighty) to 90 (ninety) days — plans are now 7, 30, 90, or 365 days. A minimum technical period of 40 (forty) days for raw measurements (latency and route history) was added, necessary to produce the monthly SLA report for the immediately preceding closed calendar month; aggregated data (hourly rollups), up to 2x the plan's window; accounts without an active plan, 60 (sixty) days. Annex I-B now states that these periods form part of the documented processing instructions of this DPA.
- Return and deletion (Clause 11.1). The export window for Customer Data was fixed at 60 (sixty) days and now expressly covers an account without an active Plan, including one that never subscribed to a Plan, in which case it is calculated per data item, from its respective collection or generation.
- Removal of the Laravel Nightwatch subprocessor. The service is no longer used and was removed from the corpus. The change does not modify the text of this DPA: it appears in the Privacy Policy (Section 5.2) and in the Public List of Subprocessors, referenced in Clause 6.
- Version history. This section was created, so that the record of changes now appears within the document itself, and not only in the legal hub.
Version 2.0 — July 22, 2026
- Original text of this document, published in the consolidation of EvoCODE IA®'s legal corpus (Terms of Service, Acceptable Use Policy, Privacy Policy, Cookie Policy, Data Processing Agreement, Public List of Subprocessors, and Legal Notice).
EvoCODE IA® Ltda — CNPJ 63.623.332/0001-42 Praça Nossa Senhora do Rosário, 44, Sala 02 — Centro, Piracaia/SP — CEP 12970-000 — Brasil, Brazil Website: https://evocode.ia.br · Legal contact: contato@evocode.ia.br · Support: sac@evocode.ia.br · WhatsApp: +55 51 2191-0021 Data Protection Officer (DPO): Elizandro Pacheco de Almeida — dpo@evocode.ia.br