Legal

Data Processing Addendum

Standard controller-to-processor terms governing the personal data you upload to Publiq about your contacts. Accepted by using the service — no signature required.

Version 2026-09-08In effect since: All legal documentsLer em português
On this page

This Data Processing Addendum (the "DPA") forms part of the Terms of Service between [LEGAL ENTITY NAME] ("Processor", "we") and the customer that uses the Publiq platform ("Controller", "you").

It applies automatically. By using the service you accept these terms, and they bind us without a separate signed contract. If your procurement process requires a countersigned copy, ask us and we will provide one.

It governs only the personal data we process on your behalf: the data of your contacts, your leads, the people who message your channels and the recipients of your emails. It does not govern your own account data, for which we are the controller and for which the Privacy Policy applies.

1. Subject matter, duration, nature and purpose

Subject matter: the processing of personal data necessary to provide the Publiq platform — transactional and marketing email, conversation automation on third-party messaging channels, lead capture, segmentation and reporting.

Duration: from the moment you first upload or capture personal data through the platform until the deletion or return of that data as described in the "Return and deletion" section. This DPA survives termination of the Terms for as long as we hold any of your personal data.

ElementDescription
Nature of processingCollection, recording, organisation, storage, retrieval, use, transmission, disclosure to the platforms you connect, restriction, erasure and anonymisation.
PurposeSolely to provide, secure and support the service, on your documented instructions.
Categories of data subjectYour contacts and leads; the people who message the channels you connect; recipients of email you send; subscribers to your web push notifications; visitors who submit your forms or use your website chat.
Categories of personal dataIdentification and contact data (name, email, phone), platform identifiers (WhatsApp number, Instagram-scoped id, Messenger page-scoped id, Telegram chat id, TikTok open id, website chat session id), public profile fields (username, display name, profile picture), consent and subscription status, the content of messages and conversations, email metadata (sender, recipients, subject, merge variables, delivery status and events), send and cost logs, suppression records, push endpoints and browser user agent, and any custom attributes you choose to define.
Special categoriesThe platform is not designed for, and must not be used to process, sensitive personal data under LGPD article 5, II or GDPR article 9 — including health, biometric, racial or ethnic origin, religious, political or trade-union data, or data concerning sex life. If you place such data in a custom attribute or a message, you do so on your own responsibility and must implement any additional safeguards the law requires.

2. Roles of the parties

You are the controller (controlador) of the personal data covered by this DPA. You determine its purposes and means, you decide who is contacted and on what legal basis, and you are responsible for the lawfulness of the collection and for the information given to data subjects.

We are the processor (operador). We process that data only to provide the service to you, and never for our own purposes. If we ever determine the purposes or means of processing for our own account, we become a controller for that processing and it falls under the Privacy Policy instead.

The platforms you connect — Meta, TikTok, Telegram, Google and others — act as independent controllers of the data they hold about their own users. This DPA does not make them our subprocessors in that capacity.

3. Documented instructions

We process personal data only on your documented instructions. Your instructions are: the Terms of Service, this DPA, the configuration you set in the application, and the API calls your systems make. Nothing else instructs us.

We may process outside those instructions only where required by law binding on us. In that case, we will inform you of the requirement before processing, unless the law prohibits that notice on important grounds of public interest.

If we consider an instruction to infringe data protection law, we will tell you and may suspend that specific processing until it is resolved.

4. Confidentiality of personnel

We ensure that every person authorised to process your personal data is bound by a duty of confidentiality — contractual or statutory — that survives the end of their engagement with us.

Access is granted on a need-to-know basis. Staff access to a customer account for support is time-boxed, issues no long-lived credential, and is recorded in a separate platform audit trail that names the staff member, the target account and the time.

5. Security measures

We implement appropriate technical and organisational measures under LGPD article 46 and GDPR article 32. The current measures include, and the Security section of the Privacy Policy describes in full:

  • Encryption of every stored third-party credential and secret with AES-256-GCM, and encryption of data in transit with TLS.
  • Password hashing with argon2id; storage of API keys, session tokens and one-time tokens as SHA-256 hashes only; optional two-factor authentication with an encrypted secret.
  • Tenant isolation enforced in the data access layer, which refuses to execute a query that was never scoped to an organisation.
  • Signature verification on every inbound webhook from a platform provider, and HMAC signing of every outbound webhook.
  • Rate limiting per IP and per identity on authentication and public endpoints, CAPTCHA on signup, duplicate-account detection, and protection against requests to internal network addresses.
  • Redaction of credentials and secrets in application logs, which expire after 30 days.
  • An audit trail of actions taken in each organisation.

We may update these measures as technology evolves, provided the level of protection is not reduced. We do not hold an ISO 27001 certification, a SOC 2 report or a PCI DSS attestation, and we make no such representation.

6. Subprocessors

You give general written authorisation for us to engage subprocessors. The current list, with the purpose and the data categories for each, is published on our Subprocessors page and forms part of this DPA.

We impose on each subprocessor, by written contract, data protection obligations no less protective than those in this DPA. We remain fully liable to you for the performance of each subprocessor's obligations.

Before a new subprocessor begins processing your data, we will update the Subprocessors page and give at least 30 days' notice by email to the account address. You may object on reasonable, data-protection-related grounds within those 30 days, at [DPO EMAIL]. We will work with you in good faith to find an alternative; if none is reasonably available, you may terminate the affected part of the service without penalty, with a pro-rata refund for the unused period.

7. Assistance with data subject rights

The platform gives you the tools to answer a data subject request yourself, without waiting for us. On a contact's page in the application, the "Privacy (GDPR/LGPD)" panel offers "Export data", which downloads that contact's record, and "Request deletion", which anonymises the contact, redacts the recipient address, the subject and the variables interpolated into the message body from the related email records, and adds the original address to the suppression list so it can never be re-imported or contacted again. Erasure on request removes exactly the same fields that the retention sweep removes when a term expires — the product has one definition of "redacted", not two.

Where a request cannot be satisfied with those tools, we will assist you by appropriate technical and organisational measures, at your reasonable request, taking into account the nature of the processing. We answer such requests from you without undue delay and in any case within 10 business days.

If a data subject contacts us directly about data we process on your behalf, we will not respond on the merits. We will tell them to contact you, and forward the request to you promptly with enough detail for you to identify the record.

We will also assist you, taking into account the information available to us, with your obligations on security of processing, notification of incidents, data protection impact assessments and prior consultation with a supervisory authority.

8. Security incident notification

We will notify you without undue delay, and in any event within 48 hours of confirming a personal data breach affecting personal data we process on your behalf. The same deadline is stated in the Privacy Policy and is the one our internal incident response runbook is built to meet — the three state one deadline, not three.

The notice will describe, to the extent known at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it and to mitigate its effects, and a contact point for further information. Where we cannot provide all of that at once, we will provide it in phases as the investigation advances, without further undue delay.

The 48 hours run from confirmation, not from the first suspicion. We would rather tell you about a confirmed incident quickly than send you a rumour, and the notice will say plainly what is still unknown.

Notifying a supervisory authority — the ANPD, or a data protection authority in the European Union — and communicating with the affected data subjects is your responsibility as controller, within the deadline the applicable law sets for you. That deadline is yours, not ours, and this DPA does not shorten or extend it. We will provide the information and the cooperation you reasonably need in order to meet it.

Our notice will go to the account email address on file. Keep it current. You may report a suspected incident to us at [SECURITY CONTACT EMAIL].

9. Audit and demonstration of compliance

We will make available to you the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate.

  • In the first instance, we satisfy this obligation by answering a reasonable security questionnaire and by providing the documentation we maintain.
  • An on-site or remote inspection may take place at most once in any twelve-month period, on at least 30 days' written notice, during business hours, without unreasonably disrupting our operations, and subject to confidentiality. A further audit may take place after a confirmed security incident affecting your data or where a supervisory authority requires it.
  • The auditor must not be a competitor of ours, and you bear the cost of the audit unless it reveals a material breach of this DPA by us.
  • An audit may not extend to the data of another customer, or to any part of our systems where it would compromise the security or confidentiality of other customers.

10. Return and deletion at the end

At any time during your subscription you may export your data from the application and through the API. Do this before you terminate.

On termination, and at your choice, we will delete or return the personal data we process on your behalf. Unless you ask for return within 30 days of termination, we will proceed to deletion. The Data Deletion page sets out the deletion procedure and the deadlines that apply.

We may retain personal data to the extent, and for as long as, we are required to by law binding on us — for example tax and accounting records — and we will retain the audit trail and the suppression list, because deleting an audit trail defeats its purpose and deleting a suppression record would allow an address that opted out to be contacted again. Anything retained on those grounds remains protected by this DPA and is not processed for any other purpose.

11. International transfers

You authorise the transfer of personal data to the subprocessors listed on our Subprocessors page, several of which are outside Brazil and outside the European Economic Area, to the extent necessary to provide the service.

Each such transfer is covered by an appropriate safeguard: standard contractual clauses of the kind approved by the ANPD under LGPD article 33, or, where the GDPR applies, the European Commission's Standard Contractual Clauses under GDPR article 46; or an adequacy decision covering the destination country. We will provide a copy of the safeguard applicable to a specific transfer on request.

Where you instruct us to send data to a platform, a webhook endpoint or a spreadsheet outside those countries, that transfer is made on your instruction and under your responsibility as controller.

12. General

  • Precedence: where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails.
  • Liability: each party's liability under this DPA is subject to the limitation of liability in the Terms of Service, to the extent permitted by law.
  • Changes: we may update this DPA to reflect a change in the law, in a regulator's guidance or in the service, provided the level of protection is not reduced, on at least 30 days' notice.
  • Governing law: as stated in the Terms of Service.

Questions about this DPA, or a request for a countersigned copy: [DPO EMAIL]. Processor: [LEGAL ENTITY NAME], [CNPJ], [REGISTERED ADDRESS].

This document is a template generated from how the product actually works. It is not legal advice and must be reviewed by a qualified lawyer before it is relied on with real customers.

Data Processing Addendum — Publiq