Table of contents
- About this notice
- Where we use AI
- Who provides the AI
- No training on your data
- Telling you when you interact with AI
- Labeling AI-generated content
- Limitations and accuracy
- Human oversight and your right to a human review
- Automated decisions with significant effects
- Prohibited uses of AI
- How to report an AI problem
- Changes to this notice
- Contact
1. About this notice
1.1 This AI Transparency Notice applies to all products and services ("Systems") provided by L. M. PEREZ MONTANA, trade name SonhoLab, CNPJ 61.620.014/0001-00, Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil ("SonhoLab", "we", "us").
1.2 This notice supplements the Terms of Service (01-terms-of-service.md), the Privacy Policy (02-privacy-policy.md) and the Data Processing Addendum (DPA) (03-data-processing-addendum.md). If this notice conflicts with the DPA on how we process Customer Data, the DPA prevails.
1.3 Some products have their own addendum with more detailed AI rules:
- Hades: Hades Addendum: Voice, Biometrics, Memorials and Companion AI (
P-voice-biometric-deceased.md). - Jesse, Digital Team OS and other messaging agents: AI Agents and Messaging Addendum (
P-ai-agents-messaging.md). - Brain SaaS and the LLM gateway: Developer and API Terms (Brain SaaS, LLM gateway) (
P-developer-api.md). - Clinics: Health Data Addendum (Clínicas) (
P-health.md). - Real Estate CRM: Real Estate CRM and Valuation Addendum (
P-real-estate-valuation.md). - Job Portal: Recruiting and Job Portal Addendum (
P-recruiting.md).
1.4 Defined terms. "AI System" means a machine-based system that generates outputs such as text, audio, images, predictions or recommendations from the inputs it receives. "Customer" means an organization that uses a System under a paid or free plan. "Customer Data" means personal data and other content that a Customer, or its users, load into a System. "Output" means content an AI System produces. "Customer's AI Provider" means the AI provider that a Customer chooses, contracts with and connects to a System with its own API key.
2. Where we use AI
2.1 The table below lists the AI functions in our Systems. A System not listed here does not use AI. Examples: Inventory, Verita and the ComexCalc import calculator do not use AI today. In every System, AI features exist only on paid plans and run on the Customer's AI Provider (section 3.2).
| System | What the AI does | Who provides the AI | Who is the controller of the data |
|---|---|---|---|
| Jesse and Digital Team OS | Answer a business's customers on WhatsApp; read payment receipts and images; transcribe voice notes; search the web to answer questions; notify the business of leads | The Customer's AI Provider | The business (SonhoLab is processor for the agent platform) |
| Clinics | Optional assistant for scheduling support, appointment reminders and in-app help, for staff and patients. It may process patient data. It never diagnoses or makes clinical decisions (see P-health.md) | The clinic's AI Provider, only if the clinic enables it | The clinic |
| Farm | Assistant that answers questions about farm data (see P-workforce-farm.md) | The Customer's AI Provider | The Customer |
| Bidstream | Summaries of public notices and match scores (see P-procurement.md) | The Customer's AI Provider | SonhoLab for public notices; the Customer for its own profile and searches |
| Brain SaaS | Creates embeddings (numeric representations of text) for search | The Customer's AI Provider | The Customer |
| LLM gateway | Routes a Customer's requests to AI providers | The Customer's AI Provider | The Customer |
| Real Estate CRM | Assistant and valuation-support functions, where available in the release the Customer uses | The Customer's AI Provider | The Customer |
| Job Portal | None. The Job Portal does not use AI to rank or match candidates. Any future AI feature would need new terms first (see P-recruiting.md) | — | — |
| Tifa (chat on sonholab.com and product sites) | Answers visitor questions about SonhoLab and captures contact requests | SonhoLab's own account (OpenAI) | SonhoLab |
| Sofia (support desk, including SonhoLab's WhatsApp sales and support assistant) | Classifies and summarizes support tickets and suggests answers, including from screenshots you attach; transcribes voice notes | SonhoLab's own account (OpenAI) | SonhoLab for accounts; the Customer for its own tickets |
| Hades (not currently offered to the public; invited testers only) | Conversation that simulates a deceased loved one; voice synthesis and voice cloning; embeddings for memory; speech-to-text; safety checks on conversations | SonhoLab's own accounts and equipment (section 3.3) | SonhoLab |
2.2 AI is optional and paid-plan only. The Free plan of every System has no AI features. On paid plans, AI features stay off until the Customer enters its own AI key in the System's settings, and the Customer can remove the key at any time. SonhoLab does not add AI features to a System without updating this notice first.
3. Who provides the AI
3.1 Two models.
- (a) The Customer's own key ("bring your own key") for every System. Every AI feature of every System and agent product runs on the Customer's AI Provider (section 3.2). SonhoLab's own AI accounts are never used for Customers.
- (b) SonhoLab's own accounts for SonhoLab's own activities. SonhoLab uses the OpenAI API (OpenAI, L.L.C.) only for its website chat (Tifa) and support desk (Sofia), where SonhoLab is the controller. Hades is the only product that uses SonhoLab's own AI accounts (section 3.3).
3.2 The Customer's AI Provider.
- (a) The Customer chooses the provider and model (usually OpenAI), contracts with it directly and enters its own API key in the System's settings. SonhoLab never supplies an AI key to any Customer.
- (b) That provider processes the data under the Customer's own contract. It is the Customer's vendor, not a SonhoLab subprocessor.
- (c) The Customer is responsible for that provider's terms, data processing agreement, international-transfer safeguards, and retention and training settings. The provider bills the Customer directly. SonhoLab is not responsible for the provider's charges, availability, outages, outputs or policy changes.
- (d) SonhoLab is the processor only for the System itself: hosting, storage, the WhatsApp channel where used, and sending to the provider the data that the Customer's configuration sends.
- (e) We store the key outside source code, with access restricted to SonhoLab personnel, use it only for that Customer's own features, and delete it when the Customer asks or removes it.
- (f) Web search for the AI agents (Tavily / Brave Software) is listed as a SonhoLab subprocessor in Subprocessors and International Transfers.
Details are in Subprocessors and International Transfers (04-subprocessors.md), section 5, the AI Agents and Messaging Addendum (P-ai-agents-messaging.md), section 12, and the Developer and API Terms (P-developer-api.md).
3.3 SonhoLab's own accounts. Only the providers below process personal data for AI functions on SonhoLab's own accounts.
| Provider | What it does | Location | Used for |
|---|---|---|---|
| OpenAI, L.L.C. (API account held by SonhoLab) | Language models, speech-to-text | United States | Tifa and Sofia; Hades |
| Google LLC, Gemini API (paid tier) | Vision and OCR, language models | United States | Hades only |
| Groq, Inc. (paid tier) | Speech-to-text, language models | United States | Hades only |
| Models run on equipment operated by SonhoLab | Voice synthesis, voice cloning, local language models, embeddings | Brazil | Hades only |
Hades is not currently offered to the public; access is limited to invited testers. Its equipment in Brazil connects to our servers in Finland over an encrypted private network (Tailscale). Tailscale Inc. sees connection metadata only, not content. See P-voice-biometric-deceased.md, section 14.
3.4 Where the rest of your data lives. Our primary hosting is Hetzner Online GmbH, in Helsinki, Finland (EU). AI providers receive only what is needed for the specific request. See 04-subprocessors.md for transfer safeguards (EU Standard Contractual Clauses, the EU-US Data Privacy Framework where certified, the UK Addendum, and ANPD standard clauses under Resolution 19/2024).
3.5 Changes. We give notice of new subprocessors as described in the DPA and in 04-subprocessors.md. Business Customers can object as the DPA provides. A Customer can change its own AI Provider at any time by changing its key.
4. No training on your data
4.1 Providers. For Customer Data, the Customer's contract and account settings with its own AI Provider decide whether that provider may use the data for training. We recommend settings that bar training. For SonhoLab's own accounts (Tifa, Sofia and Hades), our contracts with OpenAI (API), Google (paid Gemini API) and Groq (paid tier) bar them from using the data to train or improve their models.
4.2 SonhoLab. SonhoLab does not train, fine-tune or otherwise improve AI models using Customer Data. For data we hold as processor, doing so would also breach our role under GDPR article 28(10) and LGPD article 39. We will not change this for data we already hold without your prior, affirmative consent.
4.3 No sale. We do not sell personal data. We do not share it for cross-context behavioral advertising.
4.4 Operational retention by providers. Providers may keep inputs and outputs for a limited time to operate the service and detect abuse, under their API terms. For the Customer's AI Provider, the Customer's own settings apply.
5. Telling you when you interact with AI
5.1 At the start. When a person interacts with an AI System that we provide, we tell them it is AI at the latest at the first interaction, in clear words, unless that is obvious from the context. This follows the EU AI Act (Regulation (EU) 2024/1689) article 50(1) and (5), which apply from 2 August 2026.
5.2 Messaging agents. Our WhatsApp agents open each new conversation with a line such as "I'm an AI assistant of <business>." A business using our agents may not remove or hide that line. See P-ai-agents-messaging.md.
5.3 When you ask. If you ask whether you are talking to a human or to AI, the AI System will say it is AI. This follows the Utah Artificial Intelligence Policy Act (Utah Code § 13-2-12), which also requires proactive disclosure in higher-risk interactions such as health or financial matters. We disclose proactively in all cases anyway.
5.4 Bots that sell. Our agents do not pretend to be human to encourage a purchase or to influence a vote (California Business and Professions Code § 17941).
5.5 Companion AI (Hades). Hades tells users that they are talking to AI, not to a human and not to the real person, at the start of each session and again at least every 3 hours of continued use. This follows California SB 243 (Business and Professions Code § 22601 and following) and New York General Business Law article 47. See P-voice-biometric-deceased.md, section 5.
5.6 Emotion recognition. We do not offer AI that recognizes emotions from biometric data (such as voice or face) in any System offered to the public. Hades, which is not currently offered to the public, is designed to run automated safety checks on the text of conversations only to trigger its crisis protocol (see P-voice-biometric-deceased.md, section 6). We never use emotion recognition in a workplace or educational setting (EU AI Act article 5(1)(f)).
6. Labeling AI-generated content
6.1 Audio and images. Audio and images generated by our AI Systems are labeled as AI-generated. For Hades, each synthetic voice playback carries a visible or audible notice that the voice is an AI-generated imitation.
6.2 Deepfakes. A synthetic voice or image that resembles a real person is a "deep fake" under EU AI Act article 50(4). We disclose it as artificial wherever we present it. You must keep that disclosure if you share the content outside our Systems (see section 10).
6.3 Machine-readable marking. Where required by law, we will also mark synthetic audio and images in a machine-readable way, so they can be detected as AI-generated (EU AI Act article 50(2)), before that obligation applies to the System concerned.
6.4 Text. AI-generated text in chats is identified by the disclosure in section 5. If a Customer publishes AI-generated text to inform the public on matters of public interest, the Customer must disclose it as AI-generated unless a person has reviewed and edited it and takes editorial responsibility (EU AI Act article 50(4)).
6.5 Elections. Our Systems may not be used to create synthetic content of political figures, parties or candidates. In Brazil, TSE Resolution 23.610/2019, article 9-B (as amended by Resolution 23.755/2026), requires labels on AI content in electoral material and bans deepfakes in electoral propaganda, including deepfakes of deceased persons.
7. Limitations and accuracy
7.1 AI Systems make mistakes. Outputs can be incomplete, out of date, biased or simply wrong, even when they sound confident. They can misread a receipt, mistranscribe a voice note, or misunderstand a question.
7.2 Not professional advice. AI output from our Systems is not medical, psychological, legal, financial, tax, real-estate appraisal or other professional advice. Hades is not therapy. Valuation estimates are not appraisals. Check important information with a qualified person.
7.3 Your responsibility. Review outputs before you rely on them, especially before you pay money, sign something, send a message to others, or make a decision about another person.
7.4 Business Customers. A Customer that uses AI outputs in its own operations is responsible for how it uses them, including checking outputs that it sends to its own customers or relies on for decisions.
7.5 SonhoLab's responsibility. We design our AI features with care, choose reputable providers, and fix problems when we learn about them. The limits on our liability are in the Terms of Service. Nothing in this notice excludes or limits rights that cannot be excluded or limited under the law that applies to you.
8. Human oversight and your right to a human review
8.1 People stay in charge. Named SonhoLab personnel oversee our AI Systems. They can review AI behavior, correct it, and turn features off.
8.2 Human handoff. In our messaging agents, you can ask to talk to a person at any time. The agent passes the conversation to the business or to SonhoLab, as applicable.
8.3 Review of any decision that matters. If an AI System was involved in a decision that affects you, such as a suspension of your account, a refused request, or a flagged payment, you can ask a person to review it. Write to contacto@sonholab.com with "Human review" in the subject. A person who was not involved in the original decision will look at it, consider what you tell us, and give you the outcome and the main reasons.
8.4 Content moderation. Where we restrict content or accounts, we give a statement of reasons and a way to contest the decision. This includes the notice-and-action rules in articles 16 and 17 of the EU Digital Services Act (Regulation (EU) 2022/2065). See Copyright and Content Removal Policy (11-copyright-dmca.md).
9. Automated decisions with significant effects
9.1 Our rule. SonhoLab does not make decisions about you that produce legal effects, or similarly significant effects, based solely on automated processing, including profiling. A person reviews any such decision before it takes effect.
9.2 The laws behind this rule.
- EU and EEA: GDPR article 22. You have the right not to be subject to such decisions, and the rights to human intervention, to express your view, and to contest the decision.
- United Kingdom: UK GDPR articles 22A to 22D, as introduced by the Data (Use and Access) Act 2025, with the same safeguards.
- Brazil: LGPD article 20. You can ask for review of decisions taken solely on automated processing that affect your interests, and for clear information on the criteria and procedures used.
- California: the CCPA regulations on automated decision-making technology (ADMT), in force since 1 January 2026. Because a person reviews significant decisions, our Systems do not use ADMT to replace human decision-making.
- Other US states: state privacy laws give a right to opt out of profiling in furtherance of decisions with legal or similarly significant effects. We do not carry out such profiling.
9.3 Customer decisions. Some Systems produce scores, rankings, prioritized lists or estimates that a Customer may use (for example, lead scoring, collection prioritization or property valuation estimates). These are decision support only. The Customer, as controller, must keep a person in the loop and must handle requests for review from its own data subjects. We help the Customer do so, as set out in the DPA.
9.4 High-risk areas. We do not offer AI functions that evaluate students' learning outcomes, filter job candidates, evaluate the creditworthiness of individuals, or evaluate workers' performance. If we plan to, we will update this notice first.
10. Prohibited uses of AI
10.1 You may not use our AI Systems, or their outputs, to do any of the following. This list adds to the Acceptable Use Policy (06-acceptable-use-policy.md).
Practices banned by EU AI Act article 5, on any service:
- (a) use subliminal, manipulative or deceptive techniques that distort a person's behavior and cause, or are likely to cause, significant harm;
- (b) exploit a person's vulnerabilities due to age, disability, or social or economic situation, including grief, in a way that causes or is likely to cause significant harm;
- (c) evaluate or classify people by their social behavior or personal traits to give them a "social score";
- (d) predict that a person will commit a crime based only on profiling or personality traits;
- (e) build or expand facial recognition databases by untargeted scraping of images;
- (f) infer emotions in a workplace or school, except for medical or safety reasons;
- (g) use biometric data to categorize people by race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation;
- (h) generate non-consensual intimate or sexual images, audio or video of a real person, or any child sexual abuse material. (The AI Act adds these two bans from 2 December 2026. We apply them now.)
Other prohibited uses:
- (i) clone or imitate the voice or likeness of a living person without that person's own consent, or of a deceased person outside the rules in
P-voice-biometric-deceased.md; - (j) create synthetic content of public figures, politicians, parties or candidates;
- (k) present AI output as human-made, or remove AI labels or machine-readable marks, to deceive others;
- (l) commit fraud, impersonation or scams, including voice-clone scams;
- (m) send spam, or automated marketing messages without the recipient's consent;
- (n) harass, threaten, shame or intimidate anyone, including debtors;
- (o) give medical diagnoses or treatment decisions without a qualified professional;
- (p) take decisions with legal or similarly significant effects about people without human review;
- (q) try to extract, reverse engineer or bypass the safety measures of an AI System;
- (r) share, publish or distribute nonconsensual intimate images, including AI-generated ones. The US TAKE IT DOWN Act (47 U.S.C. § 223a) requires removal of such content within 48 hours of a valid request.
10.2 We may suspend or end access to any AI feature that is used in breach of this section, as set out in the Terms of Service.
11. How to report an AI problem
11.1 What to report. Tell us if an AI System:
- gave a harmful, offensive or dangerous answer;
- did not say it was AI, or claimed to be human or a real person;
- produced a voice or image of you, or of someone you represent, without consent;
- produced sexual content involving a real person or any content involving a minor;
- was wrong in a way that affected you;
- made or supported a decision you want a person to review.
11.2 How to report.
- In the product, use the report option where available.
- By email: contacto@sonholab.com, subject "AI report". Include the System, the date and time, what happened, and a screenshot or link if you have one.
- For voice or likeness takedowns in Hades, follow
P-voice-biometric-deceased.md, section 13. We act on valid requests within 48 hours. - For intimate images, write "TAKE IT DOWN" in the subject. We remove valid requests within 48 hours.
11.3 What happens next. A person reads every report. We may pause the feature, remove content, correct the System, or contact the Customer that deployed it. We tell you the outcome. If we decide not to act, we tell you why and how you can contest the decision.
11.4 Other routes. You can also complain to a supervisory authority: in Brazil, the Agência Nacional de Proteção de Dados (ANPD); in the EU, your local data protection authority; in the UK, the Information Commissioner's Office (ICO); in the US, your state Attorney General. Details are in Your Privacy Rights and How to Exercise Them (09-data-rights-requests.md).
12. Changes to this notice
12.1 We update this notice when our AI use changes, for example when we add a provider or a new AI function. We give advance notice of material changes as described in the Terms of Service and in 04-subprocessors.md.
12.2 We will not start using your data, or Customer Data we already hold, for a new AI purpose, such as model training, without your prior, affirmative consent.
13. Contact
- SonhoLab: L. M. PEREZ MONTANA, CNPJ 61.620.014/0001-00, Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil.
- Data protection officer (Encarregado): contacto@sonholab.com.
- EU representative (GDPR article 27): SonhoLab is appointing a representative in the European Union (Ireland). Until the appointment is published, EU residents can contact contacto@sonholab.com.
- UK representative (UK GDPR article 27): none. We do not currently direct our services to the United Kingdom; if we start to do so, we will appoint one.
Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.