Data Processing Agreement (DPA)
Last updated: July 27, 2026
The legally binding version of these terms is the one written in Portuguese (Brazil). This translation is a courtesy.
This Data Processing Agreement (“DPA”) forms part of the Terms of Use and governs exclusively the scenario in which Conversa Labs LTDA, registered under CNPJ (Brazilian corporate taxpayer registry) 67.791.399/0001-47 (“Conversa Labs”, “processor”), processes personal data on behalf of and under the instructions of the subscriber (“controller”) — namely, when our team accesses an account by reason of the human assistance add-on.
Outside that scenario the roles are different and are described in the Privacy Policy: we are controllers of the subscriber’s own data, and the subscriber is controller of their customers’ data. This DPA does not change those roles.
1. Definitions
The definitions of the Brazilian General Data Protection Law (Lei nº 13.709/2018 — LGPD) apply. “Personal data”, “data subject”, “processing”, “controller”, “processor”, “data protection officer”, and “security incident” have the meaning given in Article 5. “Account” has the meaning given in the Terms of Use.
2. Subject matter, nature, and purpose of the processing
The subject matter is the provision of the human assistance service on an account named by the controller. The nature of the processing is technical access for reading and, where necessary to the requested solution, for configuration within that account.
The purpose is strict: to investigate and resolve the support request opened by the controller. We do not carry out processing for our own purposes, we do not build profiles, we do not train models with such data, and we do not use it for marketing, product analytics, or any other end.
3. Duration
Processing occurs during, and only during, each recorded access session, and for as long as the assistance add-on remains in force over that account. If the add-on is cancelled, the authorization ceases and the access ceases.
4. Types of data and categories of data subjects
It is the controller who determines what exists inside their account. When accessing it, we may come into incidental contact with: the registration and contact data of the controller’s customers (name, phone, email), conversation content, attachments, service data (labels, notes, history), and operational settings. The categories of data subjects are the controller’s customers, contacts, and staff.
We do not request and have no need for sensitive personal data (Article 5, II) or for data of children and adolescents. If the controller keeps such data in the account, responsibility for the legal basis and for the applicable safeguards remains theirs.
5. Controller’s instructions and specific authorization
We act strictly under the instructions of the controller (Article 39 of the LGPD). Instructions are formalized at two levels:
- Prior authorization per account: acceptance of the Account Access Authorization Term, bound to the identifier of that specific account. The authorization given for one account does not extend to any other.
- The support request that originates each access: every session is opened from an identifiable request by the controller, whose reference is recorded in the audit trail.
If we understand that an instruction from the controller violates the LGPD, we will inform the controller and will not carry it out until it is remedied.
6. Record of processing operations (Article 37)
We keep an immutable, append-only record of each access, containing: identification of the professional who accessed it, the start and end date and time, the account identifier, the support request reference, and the reason. The record cannot be edited or deleted once created — the restriction is enforced in the database, not merely in the application.
The controller may consult this trail at any time in the subscriber area and request a copy, including to support a response to a data subject or to an authority.
7. Confidentiality and authorized personnel
Access is limited to the professionals who need it to handle the support request, all of whom are bound by a confidentiality obligation that survives the end of their engagement. We do not use shared credentials: each professional has their own identity, and it is that identity which appears in the trail — a record that does not identify a person is not a record.
8. Security
We adopt technical and administrative measures commensurate with the risk, among them: encrypted transport (TLS), individual authentication, least- privilege access control, environment segregation, audit logging, and periodic credential review. No measure entirely eliminates risk, and we do not promise absolute security.
9. Subprocessors
The controller grants general authorization for the use of the subprocessors necessary to operate the service, listed by name in the Privacy Policy. We will give at least 30 (thirty) days’ prior notice of the addition or replacement of any subprocessor that processes personal data on behalf of the controller; should there be a reasoned objection, the controller may terminate the add-on at no cost.
We are answerable to the controller for the acts of the subprocessors we engage, on the same terms as this agreement.
10. International transfer
Where processing takes place outside Brazil by a subprocessor, it will occur under the grounds of Article 33 of the LGPD and subject to adequate contractual guarantees. The up-to-date list and the location of each subprocessor are set out in the Privacy Policy.
11. Data subject rights
Responding to data subjects is an obligation of the controller, who holds the relationship with them. If we receive a data subject request directly regarding data existing inside an account, we will not answer it on our own initiative: we will forward it to the controller without delay and provide reasonable technical assistance so that they can respond within the legal deadline.
12. Security incidents
We will notify the controller, without undue delay and within 48 (forty-eight) hours of becoming aware, of any security incident that may give rise to relevant risk or harm to data subjects and that involves data processed by us on their behalf. The notice will state the nature of the incident, the data affected, the measures taken, and the recommendations. Notification to the national authority and to the data subjects, pursuant to Article 48, is the controller’s responsibility, with our support.
13. Return and deletion
We do not retain copies of account content. Once the add-on or the contract ends, the controller keeps their data in their own installation and may export it as set out in the Terms of Use. The access trail records are retained for the period necessary to comply with our own legal accountability obligations (Article 37), even if the add-on has been cancelled — deleting them would destroy the evidence that protects both parties.
14. Audit and demonstration of compliance
Upon request and within 30 (thirty) days, we make available to the controller the information necessary to demonstrate compliance with this agreement, including the full access trail relating to their accounts. On-site audits may be agreed on a case-by-case basis, with reasonable prior notice, during business hours, and without compromising third-party confidentiality.
15. Liability
Each party is answerable for the obligations the LGPD assigns to it by reason of its role. This agreement does not transfer to the controller the responsibilities the law imposes on us as processors, nor does it transfer to us those the law imposes on the controller. The liability regime of Articles 42 to 45 of the LGPD applies as appropriate.
16. Data protection officer and contact
Contact for the data protection officer (DPO): contato@conversalabs.com.br. Requests relating to this agreement must be sent through that channel.
17. Term and precedence
This DPA remains in force for as long as an assistance add-on is active over any account of the controller. In the event of a conflict between this agreement and the Terms of Use as regards the processing of personal data on behalf of the controller, this agreement prevails.