This Agreement forms part of the Contract between the Customer, as controller, and UDISOFTBOX CONSULTORIA E TECNOLOGIA LTDA, CNPJ 40.737.902/0001-20, as processor (“INGESTIA”), whenever Customer Data contains personal data.
1. Definitions and precedence
1.1. The definitions of Law No. 13,709/2018, the Brazilian General Data Protection Law (“LGPD”), apply. “Customer Personal Data” means the personal data processed by INGESTIA on behalf of the Customer.
1.2. In the event of a conflict concerning data protection, this DPA prevails; mandatory standard contractual clauses for international transfer will prevail as to the matters they regulate.
2. Subject matter, duration and instructions
2.1. INGESTIA will process data to provide ingestion, storage, transformation, SQL and text-to-SQL querying, dashboards, APIs, support, security, backup, usage-based billing and deletion.
2.2. The processing will last for as long as the Contract is in force and during the technical period for return and deletion.
2.3. The Contract, the Platform configuration, authorized support tickets and this DPA constitute documented instructions. Additional instructions that require development, entail costs or change risks will be subject to agreement.
2.4. If an instruction appears to violate the law, INGESTIA will inform the Customer and may suspend its execution until clarified, unless prohibited by law.
3. Processing details
Data subjects: customers, employees, suppliers, partners and other individuals whose data the Customer connects to the Platform.
Data: identifiers, contact details, professional, commercial and financial data and other fields defined by the Customer; encrypted technical credentials; schemas, queries and logs.
Operations: collection via connection, receipt, storage, organization, transformation, querying, controlled transmission, provision, backup and deletion.
Special data: the entry of sensitive data, data of children or adolescents, biometrics, health data or data subject to regulated confidentiality is not presumed to be authorized. Its processing requires prior assessment and agreement.
4. INGESTIA's obligations
INGESTIA shall:
- process data only in accordance with documented instructions and applicable law;
- ensure that authorized persons are bound by a confidentiality commitment;
- restrict access on a least-privilege basis and keep a record of administrative actions;
- adopt the technical and administrative measures described in Annex I;
- report data subject requests received directly, without responding to them on behalf of the Customer, unless authorized or legally required;
- support, to a reasonable extent, data subject rights, impact assessments, consultations with the ANPD (Brazilian National Data Protection Authority) and demonstration of compliance;
- report any order from an authority requiring access, where permitted; and
- make available the information necessary to demonstrate compliance with this DPA.
5. Customer's obligations
The Customer shall:
- ensure the legal basis, transparency, minimization, accuracy and legitimacy of the instructions;
- configure users, permissions, retention and exports;
- not provide prohibited or excessive data;
- respond to data subjects and make regulatory communications as controller; and
- assess whether the Platform and its configurations are appropriate to the risks of the processing.
6. Security
6.1. INGESTIA will maintain measures proportionate to the nature of the service and may update them without materially reducing the overall level of protection.
6.2. The Customer acknowledges the shared responsibility model: Platform controls do not replace the security of the Customer's sources, devices, users, keys and configurations.
7. Incidents
7.1. INGESTIA will notify the Customer without undue delay and, whenever feasible, within 24 hours after confirming a security incident involving Customer Personal Data.
7.2. The notification will include, as available: nature; categories and estimated volume; affected data subjects; containment measures; risks; point of contact and updates. Information may be provided in stages, and doing so will not constitute an admission of liability.
7.3. INGESTIA will support the investigation and communications. The Customer decides on notification to the ANPD and to data subjects, taking into account the current regulatory deadline of three business days when there is relevant risk or damage.
8. Sub-processors
8.1. The Customer grants general authorization for the subprocessors on the current public list.
8.2. INGESTIA will impose data protection obligations compatible with this DPA and will remain responsible for its obligations to the Customer, within legal and contractual limits.
8.3. A new material subprocessor will be announced at least 15 days in advance. The Customer may object on documented data protection grounds. The parties will seek a reasonable alternative; if that is not feasible, the Customer may terminate only the affected service, without any future penalty.
9. International transfer
9.1. Business data stored in BigQuery/GCS and processed in Cloud Run remain, under the current configuration, in the São Paulo region. Metadata, account, configuration, e-mail, authentication and AI schemas/queries may be processed in the United States.
9.2. The parties will adopt a mechanism permitted by Article 33 of the LGPD and by Resolution CD/ANPD No. 19/2024, including, where applicable, ANPD standard contractual clauses incorporated without incompatible changes.
9.3. INGESTIA will maintain information on the country, purpose and data accessed by each subprocessor.
10. Audit
10.1. Upon reasonable request, INGESTIA will provide policies, questionnaire responses, reports or available evidence, while protecting trade secrets, security and other customers' data.
10.2. On-site or technical audits will take place at most once a year, except in the event of an incident or a requirement from an authority, with 30 days' notice, during business hours, by an independent auditor bound by confidentiality and at the Customer's expense. Tests that affect production will not be permitted without a specific agreement.
11. Return and deletion
11.1. During the term and for 30 (thirty) days after termination, the Customer may export data via API, REST, OData or CSV, according to the contracted features.
11.2. Thereafter, INGESTIA will delete the active data within 30 (thirty) days. Backup copies will be isolated, will not return to ordinary use and will be deleted in the applicable cycle, unless a legal obligation applies.
11.3. INGESTIA may provide a statement of deletion upon request.
12. Liability and term
12.1. Each party's liability will follow the LGPD, its share in the damage and the valid limits of the Contract, without excluding data subjects' rights or the powers of the ANPD.
12.2. Confidentiality, audit, cooperation and deletion survive for as long as data remains under processing.
ANNEX I — SECURITY MEASURES
- TLS in transit;
- source credentials encrypted at rest with AES-256-GCM, with the key in a server-only variable;
- secrets not displayed in the interface or recorded in logs;
- dedicated datasets per tenant, scoped IAM and blocking of queries outside the authorized prefix;
- cache segregated per tenant;
- restricted super-admin access and audited actions;
- support for TLS, SSH and allowlists on connections;
- BigQuery time-travel for seven days, versioned GCS landing and PostgreSQL backups by Neon;
- monitoring, alerts, execution trails and health checks; and
- review of controls whenever there is a material change in architecture.