Privacy Policy — EvoCODE IA®
Last updated: September 1, 2026 · Version 2.1
This Privacy Policy ("Policy") explains how EvoCODE IA® Ltda ("EvoCODE", "we", "us") processes personal data in the context of our products and services — Kairo, TraceLog, and AgenteNOC — and of our websites, including https://evocode.ia.br, kairo.evocode.ia.br, and agentenoc.evocode.ia.br.
It forms part of our legal document hub, alongside the Terms of Service, the Acceptable Use Policy (AUP), the Cookie Policy, and the Data Processing Agreement (DPA). In the event of a conflict, the order of precedence is: DPA > Terms of Service > AUP > documentation.
We wrote this Policy in plain language. If anything is unclear, contact our Data Protection Officer (DPO): dpo@evocode.ia.br.
Table of contents
- Who we are and our roles in data processing
- What data we collect, by product
- Purposes and legal bases (table)
- Cookies and similar technologies
- With whom we share data (subprocessors)
- International transfers
- How long we keep data (retention)
- Information security
- Your rights and how to exercise them
- Automated decision-making and artificial intelligence
- Children and adolescents
- Data Protection Officer (DPO)
- Regional sections
- Updates to this Policy
1. Who we are and our roles in data processing
1.1. Who we are
EvoCODE IA® Ltda, enrolled with the CNPJ (Brazilian corporate taxpayer registry) under No. 63.623.332/0001-42, with its registered office at Praça Nossa Senhora do Rosário, 44, Sala 02 — Centro, Piracaia/SP — CEP 12970-000 — Brasil, Brazil, is a Brazilian software company that develops and operates:
| Product | What it is | Where it runs |
|---|---|---|
| Kairo | Multi-tenant scheduling SaaS platform, with WhatsApp-based customer service and artificial intelligence agents | kairo.evocode.ia.br |
| TraceLog | Network observability SaaS platform: monitoring of routes, latency, packet loss, and SLA | tracelog (evocode.ia.br) |
| AgenteNOC | AI agents for NOCs/ISPs, operating via WhatsApp, Telegram, and Discord (network monitoring and diagnostics), with an administrative panel | agentenoc.evocode.ia.br + panel |
1.2. Controller or processor? Understand the two roles
Data protection legislation distinguishes two roles, and we perform both, depending on the data:
a) EvoCODE as CONTROLLER. We are the controller — that is, the one who decides the purposes and means of the processing — when the data is processed by our own decision and for our own purposes. This is the case for:
- account data of our customers ("tenants") and their users: registration, authentication, profile, preferences;
- billing and payment data;
- security logs and application access records;
- platform usage telemetry (for operation, improvement, and statistics);
- data of visitors to our websites and of marketing, support, and sales contacts.
b) EvoCODE as PROCESSOR (processor / service provider). We are the processor — the one who processes data on behalf of and under the instructions of another company — with respect to the personal data that our customers process through the platforms. In these cases, the controller is our customer (tenant), and the processing is governed by the DPA entered into with them. Examples:
- data of Kairo invitees (people who book appointments with a company that uses Kairo);
- content of conversations on WhatsApp, Telegram, and Discord held with AI agents configured by customers (Kairo and AgenteNOC);
- personal data possibly present in the TraceLog network logs and telemetry subscribed to by a customer.
1.3. If your data was processed on behalf of one of our customers, contact them first
Important instruction for data subjects: if you booked an appointment with a company that uses Kairo, chatted with an AI agent operated by one of our customers (via WhatsApp, Telegram, or Discord), or are an end customer of a provider that uses TraceLog or AgenteNOC, the party that decides about your data is that company (the controller) — and it is to them that you should first direct yourself to exercise your rights (access, rectification, erasure, etc.).
We, as processor:
- will forward to the competent controller, without undue delay, any data subject request that we improperly receive;
- will assist the controller in handling the requests, in accordance with the DPA;
- will only act directly on such data upon the controller's documented instruction or under a legal obligation.
Pursuant to Article 42, paragraph 1, of the LGPD (Lei Geral de Proteção de Dados — Brazilian General Data Protection Law, Law No. 13,709/2018), the processor is jointly and severally liable only when it fails to comply with the law or with the controller's lawful instructions.
If you cannot identify which company is the controller of your data, write to dpo@evocode.ia.br and we will help direct your request.
2. What data we collect, by product
We collect only the data necessary for the purposes described in this Policy. Below, the categories by product and by source.
2.1. Data common to all products (EvoCODE as controller)
- Registration and account: name, e-mail, phone, company, job title, access credentials (password stored as a hash), language, and interface preferences.
- Billing: billing data, subscribed plan, payment history, and tax documents. Payment card data is processed directly by the payment processor (Stripe) — we do not store the full card number.
- Access and security records: IP address, date and time of access, session identifiers, user agent, authentication events (pursuant to Article 15 of the Marco Civil da Internet (Brazilian Internet Civil Framework, Law No. 12,965/2014)).
- Usage and diagnostic telemetry: application usage events, error and performance logs.
- Communications: messages exchanged with support (sac@evocode.ia.br, official WhatsApp +55 51 2191-0021), sales, and official channels.
- Acceptance record: version of the Terms accepted, date, IP, and user agent at the time of registration.
2.2. Kairo
As controller (tenant data): account, tenant users, billing (Stripe), platform settings, logs.
As processor (on behalf of the controller tenant):
- Invitee data: name, e-mail, phone, responses to booking forms, and the invitee's time zone;
- WhatsApp conversations with AI agents: content of the messages exchanged between the invitee/end customer and the tenant's agent (via Evolution API/Meta), including audio where applicable;
- Calendar and meeting integrations: event and availability data synchronized via Google Calendar, Microsoft Outlook/Teams, and Zoom, upon OAuth authorization granted by the tenant or its users;
- Booking data: date, time, event type, status, and history.
2.3. TraceLog
As controller: customer account and billing; IP address of visitors to the website/platform, with approximate IP-based geolocation (GeoIP, via MaxMind); access and security logs.
As processor (on behalf of the controller tenant):
- Network telemetry: monitored IP addresses, routes, latency and packet loss measurements, SLA indicators. Retention follows the subscribed plan — 7, 30, 90, or 365 days — subject to a minimum technical period of 40 days for raw measurements (latency and route history). This minimum exists because the monthly SLA report covers the immediately preceding closed calendar month and is available on all plans: without it, the prior month's report could not be issued. In practice, on plans with a window shorter than 40 days, raw measurements are deleted once they reach 40 days, and not before. Aggregated data (hourly rollups) is kept for up to twice the plan's window. See Section 7.
Note: network telemetry data refers primarily to infrastructure, but may contain personal data (e.g., IPs attributable to natural persons). We handle all telemetry with the same safeguards applicable to personal data.
2.4. AgenteNOC
As controller: customer accounts and panel users, billing, logs, data on access to training content in the panel (videos via VdoCipher).
As processor (on behalf of the controller tenant):
- Content of conversations held with the AI agents via WhatsApp, Telegram, and Discord: the user's message, the agent's response, sender identifiers (e.g., phone number, platform user ID), and audio, recorded in interaction logs (InteractionLog);
- Participants in groups in which the agent operates (member identifiers and metadata);
- Network device credentials registered by the customer for monitoring and diagnostics — stored encrypted;
- Technical network monitoring and diagnostic data generated during use.
2.5. Data we do NOT collect
- We do not deliberately collect sensitive personal data (health, biometrics, religion, sexual orientation, etc.) for our own purposes. If a customer or end user enters this type of data in conversations or forms, it will be treated as customer content, under the controller's responsibility, with the safeguards of the DPA.
- We do not collect data from children and adolescents (see Section 11).
- We do not buy data lists nor sell personal data (see Section 5).
3. Purposes and legal bases
The table below maps each purpose to its legal basis under the LGPD (Art. 7) and, for data subjects in the European Economic Area/United Kingdom, under the GDPR/UK GDPR (Art. 6). Where we act as processor, the legal basis is determined by the controller (our customer); the bases below apply to the processing in which we are the controller.
| Purpose | Data involved | LGPD legal basis (Art. 7) | GDPR legal basis (Art. 6) |
|---|---|---|---|
| Creating and administering accounts, authenticating users, and providing the subscribed services | Registration, credentials, settings | Performance of a contract (item V) | Art. 6(1)(b) — contract |
| Billing, collection, and default management | Billing data, payment history | Performance of a contract (V); credit protection (X) for collection | Art. 6(1)(b); Art. 6(1)(f) — legitimate interest |
| Complying with legal and regulatory obligations (access records — Marco Civil Art. 15; tax and accounting obligations) | Access logs, tax documents | Legal obligation (II) | Art. 6(1)(c) — legal obligation |
| Security, fraud and abuse prevention, anti-fraud monitoring | IP, logs, authentication events, telemetry | Legitimate interest (IX), with a Legitimate Interest Assessment (LIA) | Art. 6(1)(f) — legitimate interest |
| Product improvement, error correction, and internal statistics (first-party analytics) | Usage telemetry, error logs | Legitimate interest (IX), with LIA | Art. 6(1)(f) — legitimate interest |
| Support and customer service (customer service desk, official WhatsApp, e-mail) | Communications and account data | Performance of a contract (V) | Art. 6(1)(b) |
| Marketing communications and news; non-essential cookies | Contacts, cookie identifiers | Consent (I) | Art. 6(1)(a) — consent |
| Defense in legal proceedings and regular exercise of rights | Contractual records, logs, acceptance record | Regular exercise of rights (VI) | Art. 6(1)(f) |
| Incident notification and responses to authorities | Data involved in the incident | Legal obligation (II); legitimate interest (IX) | Art. 6(1)(c); Art. 6(1)(f) |
Where the basis is consent, you may withdraw it at any time (see Section 9), without affecting the lawfulness of the processing carried out before the withdrawal. Where the basis is legitimate interest, you may object to the processing, and we keep documented Legitimate Interest Assessments (LIA).
4. Cookies and similar technologies
We use cookies and local storage for authentication and session (e.g., kairo_session, tracelog_session, XSRF-TOKEN), interface and language preferences, anti-bot security (Cloudflare Turnstile, on TraceLog) and — only with your consent — analytics and marketing (e.g., Google Tag Manager, on TraceLog, when active).
Non-essential scripts are only loaded after your consent, which may be given, refused, and withdrawn at any time via the consent banner and the "Cookie/privacy preferences" link in the footer of each product.
The complete and actual cookie tables, by product, with name, purpose, duration, and category, are set out in the Cookie Policy, available in the /legal hub of each product.
5. With whom we share data (subprocessors)
5.1. No-sale statement
We do not sell personal data. Nor do we share personal data with third parties for cross-context behavioral advertising. We share data only in the circumstances described below.
5.2. Subprocessors and service providers
We use providers (subprocessors, where we act as processor) strictly to enable the services, under contracts with data protection obligations. Actual categories and examples, by product:
Common / infrastructure:
- Own hosting and cloud providers (application infrastructure);
- AWS S3 (file storage) and AWS SES (e-mail sending);
- Resend / Postmark / SMTP (transactional e-mail sending);
- Slack and Telegram (operational notifications);
- Stripe (payment processing and billing).
Kairo:
- OpenAI and AI providers configurable by the tenant (e.g., Google Gemini, Anthropic, Cohere) — natural language processing for the agents;
- Evolution API → Meta/WhatsApp (WhatsApp messaging channel);
- Google OAuth (Google Calendar), Microsoft OAuth (Outlook/Teams), Zoom (calendar and meeting integrations);
- Google Fonts (typography; exposes the IP address to Google on loading).
TraceLog:
- Cloudflare (Turnstile — anti-bot protection at login);
- MaxMind GeoIP2 (approximate IP-based geolocation);
- OpenAI (AI features); Evolution API → Meta/WhatsApp;
- Google Tag Manager (analytics/marketing, only with consent).
AgenteNOC:
- Sentry (error and performance monitoring, including traces);
- Evolution API → Meta/WhatsApp, Telegram, and Discord (messaging channels);
- VdoCipher (DRM video player, in the courses panel).
The public and up-to-date list of subprocessors, with country of processing and function, is maintained in the /legal hub and referenced in the DPA. Customers with an executed DPA are notified in advance of the addition of new subprocessors and may object, in accordance with the DPA.
5.3. Other sharing circumstances
- Public authorities: where required by law, court order, or request from a competent authority, to the extent necessary;
- Corporate transactions: in the event of a merger, acquisition, or reorganization, with continuity of the guarantees of this Policy;
- Defense of rights: with legal and accounting advisors, under confidentiality;
- With the controller: where we act as processor, the data is accessible to the controller customer by definition.
6. International transfers
Some of our subprocessors process data outside Brazil (for example, the United States and the European Union). When we transfer personal data internationally, we adopt mechanisms recognized by the applicable legislation:
- Brazil → abroad: we use the ANPD standard contractual clauses (SCCs), pursuant to Resolution CD/ANPD No. 19/2024, mandatory for new flows since 08/23/2025, and the other safeguards of Article 33 of the LGPD;
- EEA/United Kingdom → abroad: we use the EU Standard Contractual Clauses (SCCs, Decision 2021/914) and, for the United Kingdom, the UK Addendum/IDTA, incorporated into the DPA where applicable;
- Where the subprocessor in the USA is certified under the EU–U.S. Data Privacy Framework (DPF) (and the UK and Swiss extensions), that certification also supports the transfer from the EEA/UK/Switzerland.
The countries of processing of each subprocessor are listed in the public list of subprocessors. In addition, we apply technical measures (encryption in transit and at rest, minimization) to transferred data.
7. How long we keep data (retention)
We keep personal data only for as long as necessary for the purposes of this Policy, applying the following criteria: (i) term of the contract; (ii) statutory retention periods; (iii) limitation periods for the defense of rights; (iv) settings of the subscribed plan, where applicable.
Specific periods:
| Category | Period | Basis |
|---|---|---|
| Application access records (access logs) | 6 months | Marco Civil da Internet, Art. 15 (legal obligation) |
| TraceLog network telemetry — raw measurements (latency and route) | According to the plan: 7, 30, 90, or 365 days, with a 40-day technical minimum | Contractual setting defined by the controller customer, plus the period necessary to produce the monthly SLA report for the closed month |
| TraceLog network telemetry — aggregated data (hourly rollups) | Up to 2x the plan's window | Contractual setting: trend charts and historical comparisons |
| Network telemetry of accounts without an active plan | 60 days, counted from the collection of each data item | Same export window ensured under contract (Terms of Service, Section 9.5; DPA, Clause 11), also applicable to an account that never subscribed to a plan; performance of the contract and of steps prior to entering into it (LGPD, Art. 7, V) |
| Tax and accounting records | 5 years | Tax legislation |
| Security incident records | 5 years | Resolution CD/ANPD No. 15/2024 |
| Account data and customer content after termination of the contract, or in the absence of an active plan | Export available for 60 days; then secure deletion | Terms of Service, Section 9.5, and DPA, Clause 11 (subject to legal retention) |
| Record of acceptance of the Terms (version, date, IP, user agent) | Applicable limitation period | Regular exercise of rights |
| Consent-based marketing data | Until withdrawal of consent | LGPD Art. 7, I |
Purging is carried out by a periodic automated routine. Between two runs, data that has already exceeded the period may not yet have been deleted; the stated period is the deletion criterion, not an instantaneous cutoff.
At the end of the periods, the data is securely deleted or irreversibly anonymized. Where we act as processor, return and deletion follow the controller's instructions and the DPA.
8. Information security
We adopt technical and organizational measures capable of protecting personal data against unauthorized access, destruction, loss, alteration, and improper disclosure, including:
- encryption in transit (TLS) and at rest; network device credentials stored encrypted (AgenteNOC); integration secrets stored with encryption;
- passwords protected by hashing; role-based access control and the least privilege principle; support for strengthened authentication;
- logical isolation between tenants (multi-tenant architecture with context segregation);
- logging and monitoring of security events; anti-bot and anti-abuse protection;
- vulnerability management and updates; segregated environments;
- privacy governance, including Legitimate Interest Assessments (LIA) and Data Protection Impact Reports (RIPD) for higher-risk processing, such as the use of AI and large-scale messaging.
Security incidents: we maintain an incident response process. In the event of an incident with relevant risk or damage to data subjects, we will notify the ANPD and the affected data subjects within 3 business days, pursuant to Resolution CD/ANPD No. 15/2024, and we will keep a record of the incident for 5 years. Where we act as processor, we notify the controller customer within 48 hours of becoming aware, in accordance with the DPA.
No system is absolutely secure; for this reason, we ask that you also protect your credentials, which are personal and non-transferable, and notify us immediately (dpo@evocode.ia.br or sac@evocode.ia.br) in case of suspected compromise.
9. Your rights and how to exercise them
9.1. Data subject rights (LGPD, Art. 18)
You may, at any time and upon request, obtain:
- Confirmation of the existence of processing;
- Access to the data;
- Rectification of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary or excessive data or data processed in non-compliance;
- Portability of the data to another provider, subject to ANPD regulations;
- Deletion of data processed on the basis of consent (subject to the statutory retention exceptions);
- Information about the entities with which we share your data;
- Information about the possibility of not providing consent and the consequences of refusal;
- Withdrawal of consent;
- Objection to processing carried out on other legal bases, in the event of non-compliance with the LGPD;
- Review of automated decisions (see Section 10).
9.2. How to exercise them
- Channel: send your request to dpo@evocode.ia.br, indicating the product to which it refers (Kairo, TraceLog, or AgenteNOC) and the right you wish to exercise. Logged-in users may also manage various data directly in the account settings.
- Identity verification: for your protection, we may request additional information to confirm that the request comes from the data subject themselves or from a legally appointed representative.
- Deadlines: for confirmation of processing and access, we respond immediately in simplified format or, by means of a complete declaration, within 15 days of the request (LGPD, Art. 19). For the other rights, we respond without undue delay and will inform you if any specific statutory deadline applies.
- Free of charge: the exercise of rights is free of charge.
- If we cannot comply: we will state the factual or legal reasons preventing compliance (for example, a legal retention obligation), and you may petition the ANPD.
9.3. Data processed on behalf of a customer (redirection)
As explained in Section 1.3, if your data is processed by us on behalf of a customer (e.g., you are an invitee of a Kairo booking or chatted with a customer's AI agent), direct your request first to that customer, who is the controller. If the request reaches us, we will forward it to the controller and assist them in handling it, in accordance with the DPA. We will not directly handle requests concerning customers' data without the controller's instruction, except under a legal obligation.
10. Automated decision-making and artificial intelligence
Our products use artificial intelligence — in particular conversational agents in Kairo and AgenteNOC. Our commitments:
- Transparency: every interaction with AI is identified as such. The agents introduce themselves as virtual assistants, and the customer (tenant) cannot disable this identification. Generated synthetic content (such as text-to-speech audio/voice notes) is marked as AI-generated. These commitments also satisfy Article 50 of the European AI Regulation (EU AI Act), applicable as of 08/02/2026.
- No training with customer data (default): we do not use customer data or conversation content to train AI models, by default. Irreversibly aggregated and anonymized data may be used to improve the services.
- No warranty of accuracy: AI-generated responses may contain inaccuracies and do not replace human verification in relevant decisions; see the Terms of Service.
- Review of automated decisions (LGPD, Art. 20): if any decision made solely on the basis of automated processing affects your interests, you have the right to request review and to receive clear information about the criteria used, through the channel dpo@evocode.ia.br. We do not employ exclusively automated decisions that produce significant legal effects on data subjects without adequate safeguards.
- Governance: we maintain an impact assessment (RIPD) for the processing activities involving AI and large-scale messaging.
Where the AI agents are configured and operated by one of our customers, the customer is the controller of the content of those interactions, and the transparency obligations towards end users are shared in accordance with the Terms and the DPA.
11. Children and adolescents
Our products and websites are not directed at persons under 18 years of age, and we do not knowingly collect personal data from children and adolescents. Registration requires legal capacity to contract. If we become aware that we have collected data from a person under 18 without the legally required basis (LGPD, Art. 14), we will delete that data. If you believe this has occurred, contact dpo@evocode.ia.br.
12. Data Protection Officer (DPO)
Pursuant to Article 41 of the LGPD and Resolution CD/ANPD No. 18/2024, we have formally designated as Data Protection Officer (DPO):
Elizandro Pacheco de Almeida E-mail: dpo@evocode.ia.br
The DPO is the communication channel between EvoCODE, data subjects, and the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados — ANPD). Write to him to exercise rights, ask questions about this Policy, or report privacy concerns.
13. Regional sections
This Policy applies globally. The subsections below provide additional information required by local legislation and prevail, for data subjects in the respective region, over conflicting general provisions.
13.1. Brazil (LGPD)
The processing of personal data by EvoCODE is governed by Law No. 13,709/2018 (LGPD) and by the regulations of the ANPD — Autoridade Nacional de Proteção de Dados (Brazilian National Data Protection Authority), including Resolutions CD/ANPD No. 15/2024 (incidents), No. 18/2024 (data protection officer), and No. 19/2024 (international transfers). Your rights are described in Section 9.
In addition to the internal channels (dpo@evocode.ia.br), you have the right to petition the ANPD (https://www.gov.br/anpd) against EvoCODE, pursuant to Article 18, paragraph 1, of the LGPD, and to resort to consumer protection bodies, where applicable.
13.2. European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR / FADP)
If you are in the EEA, the United Kingdom, or Switzerland, the following provisions additionally apply:
- Legal bases: we process your data on the basis of Article 6 of the GDPR/UK GDPR, as per the table in Section 3 — performance of a contract (6(1)(b)), legal obligation (6(1)(c)), legitimate interests (6(1)(f)), and consent (6(1)(a)).
- Your rights: access, rectification, erasure ("right to be forgotten"), restriction of processing, objection (including to direct marketing, at any time), and portability in a structured, commonly used, and machine-readable format. Where the processing is based on consent, you may withdraw it at any time.
- Response time: we will respond within 1 month, extendable by a further 2 months in complex cases, with justified prior notice.
- Complaint to the authority: you have the right to lodge a complaint with the data protection authority of your country of residence, work, or of the place of the alleged infringement — for example, the ICO in the United Kingdom or the local supervisory authority in the EEA — without prejudice to other remedies.
- Representative (Art. 27 GDPR/UK GDPR): where the appointment of a representative in the EU or the United Kingdom is required by reason of the scope of our activities, they will be appointed and identified in this section, with their contact details.
- Transfers: data transfers from the EEA/UK/Switzerland are supported by the EU SCCs 2021/914, the UK Addendum/IDTA and, where applicable, by the importer's certification under the Data Privacy Framework (see Section 6).
13.3. United States — US State Privacy Rights
If you reside in a US state with a comprehensive privacy law in force (including, among others, California, Virginia, Colorado, Connecticut, Utah, Texas, and Oregon), the following apply, subject to the law of your state:
- Rights: to confirm the processing and access your data; to correct inaccuracies; to delete personal data; to obtain a portable copy; and to opt out of (i) the "sale" of personal data, (ii) targeted advertising ("sharing" for cross-context behavioral advertising), and (iii) profiling with legal or similarly significant effects.
- We do not sell or share: we do not sell personal data nor "share" it for cross-context behavioral advertising, within the meaning of those laws. Even so, you may register your opt-out preference.
- Global Privacy Control (GPC): we honor universal preference signals, such as the GPC, as a valid exercise of opt-out in the browser in which it is active.
- Non-discrimination: you will not be discriminated against for exercising your rights.
- Appeal: if we deny your request, you may appeal by replying to our decision or writing to dpo@evocode.ia.br with the subject "Privacy Appeal". We will respond to the appeal within the period required by the law of your state and, in the event of a further denial, we will inform you how to contact the Attorney General or the competent authority of your state.
- Authorized agent: requests may be made by an authorized agent, upon proof of the authorization.
- Service provider: where we process data on behalf of business customers, we act as a service provider/processor within the meaning of those laws (including the CCPA/CPRA), in accordance with the clauses of the DPA.
13.4. Canada (PIPEDA and Québec — Law 25)
For data subjects in Canada, we process personal data in compliance with PIPEDA (Personal Information Protection and Electronic Documents Act) and, for Québec residents, with Law 25 (Act to modernize legislative provisions as regards the protection of personal information):
- We obtain valid consent for the purposes described in this Policy and use the data only for purposes that a reasonable person would consider appropriate;
- You may access and correct your data and withdraw consent, subject to legal and contractual restrictions, by writing to dpo@evocode.ia.br;
- Québec: non-essential cookies and technologies operate on an opt-in basis; the person in charge of the protection of personal information is Elizandro Pacheco de Almeida — dpo@evocode.ia.br, whose title and contact details are published in this Policy; you may direct complaints to the Commission d'accès à l'information du Québec, and, at the federal level, to the Office of the Privacy Commissioner of Canada;
- We inform you that the data may be processed outside Canada (see Section 6), with adequate contractual safeguards.
13.5. Latin America
- Argentina (Ley 25.326 — Argentine Personal Data Protection Law): you have rights of access, rectification, updating, and deletion of your data, exercisable free of charge at intervals of no less than 6 months (access), through the channel dpo@evocode.ia.br. The Agencia de Acceso a la Información Pública (AAIP) is the supervisory authority, before which you may lodge complaints.
- Mexico (LFPDPPP — Mexican Federal Law on the Protection of Personal Data Held by Private Parties): data subjects in Mexico may exercise the ARCO rights — Access, Rectification, Cancellation, and Opposition — as well as withdraw consent and limit the use or disclosure of the data, through the channel dpo@evocode.ia.br. This document serves as the aviso de privacidad (privacy notice) for the processing described herein.
- Chile (Ley 21.719 — new Chilean Data Protection Law): the new Chilean data protection law, effective as of 12/01/2026 and with extraterritorial reach, guarantees rights of access, rectification, deletion, objection, portability, and blocking. We will handle requests from data subjects in Chile through the same channels and will fully comply with the new regime and with the Agencia de Protección de Datos Personales as of its entry into force.
- Colombia (Ley 1581/2012 — Colombian Data Protection Law): data subjects in Colombia may know, update, and rectify their data, request proof of the authorization, be informed about the use, revoke the authorization and request deletion, and lodge complaints with the Superintendencia de Industria y Comercio (SIC). Channel: dpo@evocode.ia.br.
14. Updates to this Policy
This Policy is versioned and dated — the current version and the version history are available in the /legal hub. We may update it to reflect legal, regulatory, technical, or business changes.
- Material changes (e.g., new purposes, new sharing categories, change of roles) will be notified with reasonable advance notice, by e-mail and/or a prominent notice in the applications, before they take effect.
- Non-material changes (e.g., editorial adjustments) may be published directly, with an update of the date and version at the top of this document.
- Where the law so requires, we will request new consent. Continued use of the services after a new version takes effect indicates awareness of the update, without prejudice to rights that depend on consent.
We recommend revisiting this page periodically. Questions? dpo@evocode.ia.br.
Version history
Below we record the material changes to this Policy. The current version and the other pieces of the legal corpus are published in the legal hub at https://evocode.ia.br/legal.
Version 2.1 — September 1, 2026
- TraceLog telemetry retention (Sections 2.3 and 7). The window for the TraceLog Pro plan changed from 180 (one hundred eighty) to 90 (ninety) days — plans are now 7, 30, 90, or 365 days. A minimum technical period of 40 (forty) days for raw measurements (latency and route history) was added, necessary to produce the monthly SLA report for the immediately preceding closed calendar month. The table in Section 7 now distinguishes raw measurements from aggregated data (hourly rollups, up to 2x the plan's window), states 60 (sixty) days for the telemetry of accounts without an active plan, counted from the collection of each data item, and clarifies that purging is carried out by a periodic automated routine — the stated period is the deletion criterion, not an instantaneous cutoff. The row for account data and customer content after termination, previously expressed as a range of "30 to 60 days," was fixed at 60 (sixty) days and now also covers an account without an active plan, including one that never subscribed to a plan.
- Removal of the Laravel Nightwatch subprocessor. The application telemetry and monitoring service is no longer used and was removed from the list of subprocessors in Section 5.2 and from the Public List of Subprocessors.
- Version history. This section was created, so that the record of changes now appears within the document itself, and not only in the legal hub.
Version 2.0 — July 22, 2026
- Original text of this document, published in the consolidation of EvoCODE IA®'s legal corpus (Terms of Service, Acceptable Use Policy, Privacy Policy, Cookie Policy, Data Processing Agreement, Public List of Subprocessors, and Legal Notice).
Company identification
EvoCODE IA® Ltda CNPJ: 63.623.332/0001-42 Praça Nossa Senhora do Rosário, 44, Sala 02 — Centro, Piracaia/SP — CEP 12970-000 — Brasil, Brazil Website: https://evocode.ia.br General/legal e-mail: contato@evocode.ia.br Support / Customer service: sac@evocode.ia.br · Official WhatsApp: +55 51 2191-0021 (https://wa.me/555121910021) Data Protection Officer (DPO): Elizandro Pacheco de Almeida — dpo@evocode.ia.br
Privacy Policy — Version 2.1 — Last updated: September 1, 2026.