Table of contents
- Scope and parties
- Definitions
- Roles of the parties
- Customer instructions
- Customer responsibilities
- Confidentiality
- Security
- Subprocessors
- Assistance with data subject rights
- Assistance with impact assessments and authorities
- Personal Data Breach notification
- Return and deletion
- Audits and information
- International transfers
- US state law terms (CCPA/CPRA and other states)
- Artificial intelligence features
- Government and law enforcement requests
- Switching and exit (EU Data Act)
- Liability
- Term, changes and order of precedence
- Governing law and disputes
- Annex I — Description of processing, per System
- Annex II — Technical and organizational measures
- Annex III — Subprocessors
- Annex IV — Transfer mechanisms
1. Scope and parties
1.1 Parties. This DPA is between the Customer and L. M. PEREZ MONTANA, trade name SonhoLab, a Brazilian Empresário Individual (ME), CNPJ 61.620.014/0001-00, Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil ("SonhoLab", "we"). Privacy contact and Encarregado (DPO): contacto@sonholab.com.
1.2 When it applies. This DPA applies whenever SonhoLab processes Customer Personal Data to provide a System. It forms part of the Terms of Service. The Customer accepts it electronically when it accepts the Terms of Service or signs an order. No separate signature is needed. A signed copy is available on request.
1.3 What it does not cover. This DPA does not cover data for which SonhoLab is the controller. That includes account and organization data, billing, support, marketing, the website sonholab.com, the free tools and consumer apps such as Hades, PDF Free and the games. The Privacy Policy covers that data.
1.4 Representatives. SonhoLab is appointing a representative in the European Union (Ireland) under GDPR Art. 27. Until the appointment is published, the Customer, data subjects and supervisory authorities can contact contacto@sonholab.com. SonhoLab has no UK representative under UK GDPR Art. 27, because it does not currently direct its services to the United Kingdom. If it starts to do so, it will appoint one and notify the Customer.
2. Definitions
Capitalized terms not defined here have the meaning given in the Terms of Service. Terms such as "personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meaning given in the Data Protection Laws. Where a law uses different words for the same idea, the words below include them. "Controller" includes "controlador" (LGPD) and "business" (CCPA). "Processor" includes "operador" (LGPD), "service provider" and "contractor" (CCPA) and "processor" under other US state laws.
- Authorized User: a person the Customer lets use a System under its account.
- Customer Personal Data: personal data that the Customer or its Authorized Users load into a System, or that a System collects or generates on the Customer's behalf, and that SonhoLab processes as processor. Annex I describes it per System.
- Data Protection Laws: all privacy and data protection laws that apply to the processing of Customer Personal Data under this DPA. These include, as applicable: Regulation (EU) 2016/679 (GDPR); the GDPR as it forms part of UK law and the UK Data Protection Act 2018 (UK GDPR); Brazil's Lei 13.709/2018 (LGPD) and the regulations of the Agência Nacional de Proteção de Dados (ANPD); the California Consumer Privacy Act as amended by the CPRA and its regulations (CCPA); and the comprehensive privacy laws of other US states (US State Laws).
- Personal Data Breach: a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. It includes a "security incident" under the LGPD and a "breach of the security of the system" under US state breach laws.
- Subprocessor: a third party that SonhoLab engages to process Customer Personal Data. Hetzner, which hosts the Systems, is a Subprocessor.
- System: a SonhoLab product the Customer uses under the Terms of Service, such as Inventory, Verita or Clinics. Annex I lists them.
- Transfer Clauses: the EU Standard Contractual Clauses, the UK Addendum and the ANPD standard clauses, as described in Section 14 and Annex IV.
3. Roles of the parties
3.1 Customer as controller. The Customer is the controller of Customer Personal Data. It decides the purposes and means of processing. SonhoLab is its processor.
3.2 Customer as processor. If the Customer processes Customer Personal Data on behalf of another controller, the Customer is a processor and SonhoLab is its subprocessor. The Customer is then the single point of contact for that controller. The Customer confirms that its instructions are authorized by that controller.
3.3 SonhoLab as controller of its own data. SonhoLab is the controller of: account and login data of Authorized Users; billing data; support conversations; and the security and access logs it must keep by law (for example, Brazil's Marco Civil da Internet, Art. 15). The Privacy Policy governs that data.
3.4 No own purposes. SonhoLab does not process Customer Personal Data for its own purposes. If SonhoLab ever determined the purposes and means of processing Customer Personal Data in breach of this DPA, it would be treated as a controller for that processing (GDPR Art. 28(10); LGPD Art. 42 §1, I).
4. Customer instructions
4.1 Documented instructions. SonhoLab processes Customer Personal Data only on the Customer's documented instructions. The Customer's complete instructions at the date of acceptance are:
- (a) the Terms of Service, this DPA and any product addendum that applies to the System;
- (b) the Customer's configuration and use of the System, including which features it turns on (for example, AI features or a WhatsApp channel);
- (c) actions taken by Authorized Users in the System; and
- (d) other written instructions the Customer gives through support channels, if they are consistent with the Terms of Service.
4.2 New instructions. Instructions outside the scope of the Terms of Service need SonhoLab's written agreement. SonhoLab may charge for them if they require work beyond the standard System.
4.3 Unlawful instructions. SonhoLab will tell the Customer promptly if, in its opinion, an instruction infringes the Data Protection Laws (GDPR Art. 28(3), final paragraph; LGPD Art. 39). SonhoLab may suspend that instruction until the Customer confirms or changes it. SonhoLab does not give legal advice to the Customer.
4.4 Legal requirements. If a law requires SonhoLab to process Customer Personal Data other than as instructed, SonhoLab will tell the Customer first, unless that law forbids it.
5. Customer responsibilities
5.1 The Customer is responsible for:
- (a) having a lawful basis for the processing and for engaging SonhoLab;
- (b) giving data subjects the notices that the law requires, including notice of AI use and of the Subprocessors that apply to the features it turns on;
- (c) obtaining any consent or authorization the law requires. This is especially important for health data, children's and students' data, biometric data, images, government identity documents and precise location;
- (d) making sure the data it loads is accurate, relevant and limited to what is necessary;
- (e) configuring access within its organization, including which Authorized Users can see each record;
- (f) keeping its own Authorized Users' credentials secure;
- (g) meeting its own registration, record-keeping and notification duties toward supervisory authorities and data subjects; and
- (h) answering data subject requests, with SonhoLab's help under Section 9.
5.2 Product addenda. Some Systems carry additional duties for the Customer. See the Children and Student Data Addendum (Verita), the Health Data Addendum (Clínicas), the AI Agents and Messaging Addendum, the Location and Mobility Addendum (Speed, Passayum), the Debt Collection Addendum (CobraDia), the Real Estate CRM and Valuation Addendum, the Workforce, Farm and Site Monitoring Addendum, the Developer and API Terms (Brain SaaS, LLM gateway) and the Procurement Intelligence Addendum (Bidstream).
6. Confidentiality
6.1 SonhoLab gives access to Customer Personal Data only to named personnel who need it to provide, secure or support the System.
6.2 Everyone with access is bound by a written duty of confidentiality or a statutory duty of secrecy (GDPR Art. 28(3)(b); LGPD Art. 47). The duty continues after their engagement ends.
6.3 SonhoLab personnel do not open the content of Customer Personal Data except: to provide support the Customer asked for; to investigate a security incident or abuse; or where the law requires it.
7. Security
7.1 SonhoLab maintains the technical and organizational measures in Annex II. They are designed to protect Customer Personal Data against Personal Data Breaches, taking into account the state of the art, costs, and the nature, scope, context and purposes of the processing (GDPR Art. 32; LGPD Art. 46).
7.2 SonhoLab may update the measures. Updates will not materially reduce the overall level of protection.
7.3 SonhoLab holds no security certifications (for example, no SOC 2 and no ISO 27001). The Customer has assessed the measures in Annex II and considers them appropriate for the Customer Personal Data it loads.
8. Subprocessors
8.1 General authorization. The Customer gives SonhoLab a general written authorization to engage Subprocessors (GDPR Art. 28(2)). The current list is in Subprocessors and International Transfers (Annex III). It shows each Subprocessor's purpose, location, the Systems that use it and the transfer mechanism.
8.2 Flow-down. SonhoLab engages each Subprocessor under a written contract that imposes data protection obligations no less protective than this DPA, as far as they apply to the Subprocessor's service (GDPR Art. 28(4)).
8.3 Responsibility. SonhoLab remains responsible to the Customer for the performance of each Subprocessor's obligations.
8.4 Notice of changes. SonhoLab will give at least 30 days' notice before it adds or replaces a Subprocessor. It does this by:
- (a) updating Subprocessors and International Transfers, with the date of the change; and
- (b) emailing the account owner email of the Customer's organization and every person subscribed to change notices.
8.5 Objection. The Customer may object in writing to contacto@sonholab.com within those 30 days, on reasonable data protection grounds. The parties will then discuss it in good faith. SonhoLab may offer, for example, to keep the Customer's data away from that Subprocessor or to switch off the feature that uses it.
8.6 Remedy. If SonhoLab cannot offer a reasonable alternative within 30 days of the objection, the Customer may terminate the affected System without penalty. Before termination takes effect it may export its data. SonhoLab will refund any prepaid fees for the period after termination for that System. This is the Customer's sole remedy for an objection.
8.7 Emergency replacement. If SonhoLab must replace a Subprocessor urgently for security or continuity reasons, it may do so with shorter notice. It will give notice as soon as possible, and Sections 8.5 and 8.6 still apply.
8.8 Optional features. Some Subprocessors are used only when the Customer turns on a feature (for example, AI features, a WhatsApp channel or a payment method). Turning on the feature is an instruction to use the Subprocessors listed for it. AI features run only on an AI provider the Customer connects with its own key, and that provider is not a Subprocessor (Section 16.3).
9. Assistance with data subject rights
9.1 Tools. Each System gives the Customer tools to access, correct, export and delete Customer Personal Data. Export is available on every plan, including Free.
9.2 Requests sent to SonhoLab. If SonhoLab receives a request from a data subject about Customer Personal Data, it will forward the request to the Customer without undue delay. It will not answer the request itself, unless the Customer authorizes it or the law requires it. SonhoLab may tell the data subject that it has forwarded the request.
9.3 Help. Taking into account the nature of the processing, SonhoLab will help the Customer answer requests to exercise rights under the Data Protection Laws (GDPR Arts. 12-22; LGPD Art. 18; CCPA). This includes rights of access, correction, deletion, portability, restriction, objection and opt-out. SonhoLab provides this help through the System's tools and, where the tools are not enough, by reasonable manual help. Its target is to let the Customer meet its own legal deadlines (for example, 15 days under LGPD Art. 19, one month under the GDPR, 45 days under US State Laws).
10. Assistance with impact assessments and authorities
10.1 SonhoLab will give the Customer the information reasonably available to it that the Customer needs to carry out:
- (a) a data protection impact assessment (GDPR Art. 35);
- (b) a relatório de impacto à proteção de dados pessoais (RIPD, LGPD Art. 38);
- (c) a data protection assessment or risk assessment under US State Laws; and
- (d) a prior consultation with a supervisory authority (GDPR Art. 36).
10.2 SonhoLab first meets this duty with this DPA, its annexes, Subprocessors and International Transfers, and Security and Incident Response. It will also answer reasonable written questions.
10.3 SonhoLab will cooperate with the ANPD, the competent EU or UK supervisory authority, or a US state regulator where the law requires it.
10.4 Extensive assistance beyond this may be charged at reasonable cost, where the law allows. SonhoLab will not charge for assistance needed because of its own breach of this DPA.
11. Personal Data Breach notification
11.1 Timing. SonhoLab will notify the Customer of a Personal Data Breach without undue delay. Its target is 48 hours and the maximum is 72 hours after SonhoLab confirms the breach. This is shorter than the Customer's own deadlines, which are 3 business days to the ANPD under Res. CD/ANPD 15/2024 and 72 hours to an EU or UK supervisory authority.
11.2 Channel. SonhoLab will send the notice to the account owner email of the Customer's organization. Where possible, it will also send it to any security contact the Customer has registered.
11.3 Content. The notice will include, as far as the information is known:
- (a) the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- (b) when the breach happened and when SonhoLab became aware of it;
- (c) the likely consequences;
- (d) the measures SonhoLab has taken or proposes to take, including measures to reduce possible harm;
- (e) whether the data was protected in a way that makes it unintelligible to others, such as encryption; and
- (f) a contact person for more information.
Where SonhoLab does not yet have all the information, it will provide it in phases without further undue delay.
11.4 Cooperation. SonhoLab will cooperate with the Customer's investigation and give reasonable help so the Customer can meet its notification duties. The Customer decides whether to notify authorities and data subjects about Customer Personal Data. SonhoLab will not notify them on the Customer's behalf unless the Customer asks it to or the law requires it.
11.5 No admission. A notice under this Section is not an admission of fault or liability.
11.6 Register. SonhoLab records every Personal Data Breach, whether or not notified, in its incident register. It keeps the register for 5 years. See Security and Incident Response.
12. Return and deletion
12.1 Export at any time. The Customer can export Customer Personal Data through the System at any time during the term, in a structured, commonly used, machine-readable format.
12.2 After the end. When a System ends for the Customer, SonhoLab keeps Customer Personal Data available for export for 30 days. After that, SonhoLab deletes it from active systems. This does not apply where a product addendum or the Data Retention Schedule sets a different period. For example, student data in Verita is deleted within 60 days after the contract ends, unless the school asks for export first.
12.3 Backups. Deleted data disappears from backups as the backups expire. Database backups are kept up to 14 days on the server and up to 14 days in the off-site copy, so deletion from all backups is complete within 30 days. Until then, backups are used only to restore service after an incident; the off-site copy is kept encrypted. SonhoLab does not restore deleted Customer Personal Data into active use, except to recover from an incident.
12.4 Free plan inactivity. Free plan organizations inactive for 90 days are purged after 2 prior notices, as described in the Data Retention Schedule.
12.5 Legal retention. SonhoLab may keep Customer Personal Data after deletion only where a law requires it. It will then protect that data, process it only for that legal purpose, and tell the Customer which data it keeps and why, unless the law forbids that.
12.6 Certification. On written request, SonhoLab will confirm the deletion in writing.
13. Audits and information
13.1 Documentation first. SonhoLab will make available all information necessary to show compliance with this DPA. It does this first through this DPA and its annexes, Security and Incident Response, Subprocessors and International Transfers, and written answers to the Customer's reasonable questions.
13.2 Questionnaires. The Customer may send one security or privacy questionnaire per year. SonhoLab will answer it within a reasonable time. It will also answer additional questionnaires after a Personal Data Breach or when a supervisory authority asks the Customer.
13.3 On-site audits. If the information above is not enough to show compliance, or a supervisory authority requires it, the Customer may carry out an audit, or have an independent auditor bound by confidentiality carry it out. The following conditions apply:
- (a) the Customer gives at least 30 days' written notice with a proposed scope;
- (b) the audit takes place during business hours, at most once a year, and does not unreasonably disrupt the Systems;
- (c) the audit does not give access to other customers' data or compromise their security;
- (d) the Customer bears the cost, including SonhoLab's reasonable time, unless the audit reveals a material breach of this DPA by SonhoLab; and
- (e) the Customer shares the audit report with SonhoLab.
The once-a-year limit does not apply after a Personal Data Breach or when a supervisory authority requires an audit.
13.4 Transfer Clauses. Nothing in this Section limits the audit rights in the EU Standard Contractual Clauses (Clause 8.9) or in the ANPD standard clauses. These audit terms are the way the parties agree to exercise those rights.
14. International transfers
14.1 Locations. Customer Personal Data is hosted by Hetzner Online GmbH in Helsinki, Finland (EU), with Hetzner's automated server backups in Finland. An off-site backup copy, encrypted before it leaves the server, is stored on equipment operated by SonhoLab in Brazil. SonhoLab personnel may access the data from Brazil. Some Subprocessors are in the United States or in other countries, as shown in Subprocessors and International Transfers. The Customer authorizes these transfers. SonhoLab will not transfer Customer Personal Data to any other country without the safeguards in this Section.
14.2 Brazil and the EU. Brazil and the EU recognize each other as adequate:
- Commission Implementing Decision (EU) 2026/179 covers transfers from the EEA to SonhoLab in Brazil (GDPR Art. 45).
- Res. CD/ANPD 32/2026 covers transfers from Brazil to the EU, including Hetzner in Finland (LGPD Art. 33, I).
The EU Standard Contractual Clauses in Annex IV apply to EEA-to-Brazil transfers only as a fallback. They apply if the adequacy decision is suspended, repealed or declared invalid, or if it does not cover a specific transfer.
14.3 UK. The UK has not recognized Brazil as adequate. Transfers from the UK to SonhoLab are made under the UK Addendum in Annex IV.
14.4 Onward transfers to Subprocessors. For Subprocessors outside the EEA, the UK and Brazil's adequate countries, SonhoLab uses:
- (a) the EU Standard Contractual Clauses (Module 3, processor to processor), and the EU-US Data Privacy Framework where the Subprocessor is certified;
- (b) the UK Addendum or the UK International Data Transfer Agreement for UK data; and
- (c) the ANPD standard clauses (Res. CD/ANPD 19/2024, Annex II), used in full and without changes, for transfers subject to the LGPD.
SonhoLab carries out transfer impact assessments where the EU Standard Contractual Clauses require them (Clause 14).
14.5 Other countries. If the Customer's law requires a specific transfer instrument (for example, in Chile, Peru, Colombia or Mexico), SonhoLab will cooperate in good faith to sign it. See Latin America Supplement.
14.6 Copies. SonhoLab will send the full text of the transfer clauses it uses within 15 days of a request (Res. CD/ANPD 19/2024, Art. 17). It may remove commercial terms that are not relevant.
15. US state law terms (CCPA/CPRA and other states)
15.1 Role and business purposes. For Customer Personal Data subject to the CCPA or US State Laws, SonhoLab is a service provider or contractor (CCPA) and a processor (US State Laws). The Customer discloses Customer Personal Data to SonhoLab only for these limited and specified business purposes: providing, securing, maintaining and supporting the Systems the Customer uses, as described in the Terms of Service and Annex I (the "Business Purposes").
15.2 Restrictions. SonhoLab will not:
- (a) sell or share Customer Personal Data, as those terms are defined in the CCPA, including sharing for cross-context behavioral advertising;
- (b) retain, use or disclose Customer Personal Data for any purpose other than the Business Purposes, including any commercial purpose, or as the CCPA otherwise permits a service provider or contractor;
- (c) retain, use or disclose Customer Personal Data outside the direct business relationship between SonhoLab and the Customer; or
- (d) combine Customer Personal Data with personal data it receives from or on behalf of another person, or collects from its own interactions with a consumer, except as the CCPA regulations allow (for example, to detect security incidents or protect against fraud).
15.3 Compliance. SonhoLab will comply with the obligations that apply to it under the CCPA and US State Laws. It will provide the same level of privacy protection they require of the Customer.
15.4 Notice if SonhoLab cannot comply. SonhoLab will notify the Customer promptly if it determines that it can no longer meet its obligations under the CCPA or US State Laws.
15.5 Right to take reasonable steps. The Customer may take reasonable and appropriate steps to ensure that SonhoLab uses Customer Personal Data consistently with the Customer's obligations, using the audit and information rights in Section 13.
15.6 Right to stop unauthorized use. On notice, the Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data. This includes requiring SonhoLab to stop the processing concerned, delete the data or suspend the affected feature.
15.7 Consumer requests. SonhoLab will help the Customer answer consumer requests as described in Section 9.
15.8 Subcontractors. SonhoLab will notify the Customer of each Subprocessor it engages (Section 8). It will bind each one by a written contract with obligations at least as protective as those in this Section.
15.9 Certification. SonhoLab certifies that it understands the restrictions in this Section and will comply with them.
15.10 Other US state processor duties. For US State Laws, the following Sections also satisfy the processor contract requirements: Section 4 (instructions), Section 6 (confidentiality of personnel), Section 12 (deletion or return), Section 13 (information and assessments), Section 8 (subprocessors with notice and a right to object), and Sections 10 and 11 (help with assessments, security and breach notification).
15.11 Health and students. SonhoLab is not a HIPAA business associate unless the parties sign a separate business associate agreement. SonhoLab does not offer one by default. For US schools, the Children and Student Data Addendum (Verita) applies in addition to this DPA. It is compatible with the Student Data Privacy Consortium National Data Privacy Agreement and the FERPA school-official exception (34 CFR §99.31(a)(1)(i)(B)), and it includes a New York Parents' Bill of Rights exhibit.
16. Artificial intelligence features
16.1 No training. SonhoLab does not use Customer Personal Data to train, fine-tune or improve AI models, whether its own or anyone else's.
16.2 No SonhoLab AI account. SonhoLab does not use its own AI provider accounts to process Customer Personal Data. No AI provider is a SonhoLab Subprocessor.
16.3 Customer's own AI provider (bring your own key). Every AI feature of every System runs on the Customer's own AI provider account. This includes the AI agent products (Jesse and Digital Team OS), the LLM gateway, Brain SaaS and the AI features of the other Systems. The AI features of a System stay off until the Customer adds its key. In every case:
- (a) AI features exist only on paid plans; the Free plan has none. The Customer chooses the provider and model, contracts with it directly and enters its own API key in the System's settings. SonhoLab never supplies an AI key;
- (b) the AI provider is the Customer's own vendor under the Customer's own contract, not a SonhoLab Subprocessor, and Section 8 does not apply to it;
- (c) adding the key is the Customer's instruction to send to that provider the data that the Customer's configuration sends;
- (d) the Customer is responsible for that provider's terms, its data processing agreement, transfer safeguards and training settings, and pays the provider's usage charges directly. SonhoLab is not responsible for the provider's charges, availability, outages, outputs or policy changes; and
- (e) SonhoLab stores the key outside source code, with access restricted to SonhoLab personnel, uses it only for the Customer's own features, deletes it when the Customer asks, and processes everything else under this DPA.
Subprocessors and International Transfers, Section 5, explains this.
16.4 Only when turned on. AI processing happens only through the features the Customer turns on. In Clinics, the optional AI assistant (scheduling support, reminders and in-app help) runs on the clinic's own key and processes patient data only if the clinic enables it, informs patients and obtains their consent where the law requires it. The clinic can disable it at any time, and the assistant makes no diagnosis or clinical decision. The AI Transparency Notice explains the features.
16.5 Customer duties. Where the Customer deploys an AI feature toward its own customers or users (for example, a WhatsApp assistant), the Customer is responsible for the notices and disclosures the law requires of it as deployer. The AI Agents and Messaging Addendum sets out the built-in AI disclosure and human handoff.
17. Government and law enforcement requests
17.1 If a public authority asks SonhoLab for Customer Personal Data, SonhoLab will redirect the authority to the Customer where possible. It will notify the Customer promptly, unless the law forbids it. It will disclose only what is legally required.
17.2 Government and Law Enforcement Requests explains the process. For transfers under the EU Standard Contractual Clauses, Clause 15 also applies.
18. Switching and exit (EU Data Act)
18.1 This Section applies where Regulation (EU) 2023/2854 (the Data Act), Chapter VI, applies to the Customer's use of a System.
18.2 Notice. The Customer may switch to another provider, or move its data to its own infrastructure, by giving at most 2 months' notice. SonhoLab will then give reasonable help during a transition period of up to 30 days, or longer where the Data Act allows it.
18.3 Data. The Customer can export all Customer Personal Data and other exportable data it loaded into the System through the System's export tools. SonhoLab will describe the exportable data categories and formats on request.
18.4 Charges. Standard export through the System's tools is always free. SonhoLab does not charge switching or data egress charges, as the Terms of Service (Section 19.6) state.
18.5 Deletion. After the switch, Section 12 applies.
19. Liability
19.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. For business customers, the cap is the fees paid in the 12 months before the claim.
19.2 This does not apply where a law forbids limiting liability. In particular, nothing in this DPA limits:
- (a) either party's liability to data subjects under GDPR Art. 82, UK GDPR Art. 82, LGPD Arts. 42 to 45 or Clause 12 of the EU Standard Contractual Clauses; or
- (b) any fine a supervisory authority imposes directly on a party.
19.3 The Customer is responsible for claims by data subjects or authorities that arise from its unlawful instructions or from data it loaded without a lawful basis.
19.4 Nothing in the Terms of Service excludes or limits rights that cannot be excluded or limited under the law that applies to the Customer or to data subjects.
20. Term, changes and order of precedence
20.1 Term. This DPA applies for as long as SonhoLab processes Customer Personal Data, including during the return and deletion period in Section 12.
20.2 Changes. SonhoLab may update this DPA to reflect changes in law, in the Systems or in Subprocessors. Material changes that reduce the Customer's protection take effect only after 30 days' notice. The Customer may terminate the affected System during that period. Changes that a law or supervisory authority requires may take effect sooner. Each version is dated and archived.
20.3 Order of precedence. If documents conflict, this order applies:
- the Transfer Clauses in Annex IV, for the transfers they cover;
- a product addendum listed in Section 5.2, where it gives data subjects more protection for that System;
- this DPA;
- the Terms of Service; and
- any other document.
21. Governing law and disputes
21.1 This DPA is governed by the law of Brazil. The courts of Fortaleza/CE, Brazil, have jurisdiction, as set out in the Terms of Service for business customers.
21.2 The Transfer Clauses are governed by the law and courts they designate in Annex IV. Nothing in this Section limits a data subject's right to complain to a supervisory authority or to bring a claim where the Data Protection Laws allow.
Annex I — Description of processing, per System
I.1 Common to all Systems
| Item | Description |
|---|---|
| Parties | Data exporter / controller: the Customer (its details are in its account). Data importer / processor: SonhoLab (Section 1.1). |
| Nature of processing | Hosting, storage, organization, retrieval, display, transmission, backup, export and deletion. Also, where the Customer turns on a feature: messaging, notifications, geocoding, payments or AI processing. AI features exist only on paid plans and run only on the Customer's own AI key entered in the System's settings (Section 16.3); the Free plan has no AI features. |
| Purpose | To provide, secure, maintain and support the System for the Customer, according to its instructions (Section 4). |
| Authorized Users (all Systems) | Name, email, phone, role, login and activity records, IP address and device data in access logs. |
| Frequency | Continuous, for the term. |
| Duration and retention | The term of the Terms of Service, plus the periods in Section 12, unless the System's row below or the Data Retention Schedule says otherwise. |
| Location | Hetzner, Helsinki, Finland (EU), including Hetzner's automated server backups. Encrypted off-site backup copy on equipment operated by SonhoLab in Brazil. Remote access from Brazil. Subprocessor locations as in Annex III. |
"Special categories" below means special categories under GDPR Art. 9, sensitive data under LGPD Art. 11, and sensitive personal information under the CCPA and US State Laws. It also flags children's data.
I.2 Per System
| System | Data subjects | Categories of personal data | Special categories / sensitive data | Purposes | Duration |
|---|---|---|---|---|---|
Inventory (inventario) | Authorized Users; the Customer's own customers (business contacts) | Authorized Users: name, email, password (stored only as a hash), role, activity in the audit trail. Customer contacts: name and email. Operational records: products, stock entries, production, packages with dispatch method, tracking number and free-text notes. No suppliers, addresses or invoices; no file uploads | None expected. Free-text notes are not intended for sensitive data | Inventory, production and dispatch management; subscription payments through Stripe | Term + Section 12 |
| Verita (school management) | Students (minors), parents and guardians, teachers and staff, persons authorized to pick up students | Identification, enrollment records, grades, attendance, tuition and fees, messages between school and families, school health records, photo of authorized pick-up persons, guardian signatures, enrollment documents, app push tokens | Children's data; health data; images of persons | School administration and communication with families, only as instructed by the school. No advertising, no profiling, no sale. See the Children and Student Data Addendum (Verita) | Term; deleted within 60 days after contract end unless the school asks for export; backups within 30 days |
Clinics (clinicas) | Patients (possibly minors) and their representatives; clinic staff | Identification, contact, medical history, treatments and doses, nutrition plans, before-and-after photos, appointments, consent forms and signatures, payments (Culqi where the clinic uses it), patient portal messages; WhatsApp messages if the clinic enables messaging; conversations with the AI assistant if the clinic enables it | Health data; images; possibly children's data | Clinical records, scheduling, patient portal, billing; (only if the clinic enables messaging) patient messages through the official WhatsApp Business Platform; and (only if the clinic enables it, with patient notice and consent where required) an optional AI assistant for scheduling support, reminders and in-app help, running on the clinic's own AI key (Section 16.3). The assistant makes no diagnosis or clinical decision; clinic staff remain responsible. See the Health Data Addendum (Clínicas) | As instructed by the clinic. The clinic is responsible for legal minimums (e.g., Brazil Lei 13.787/2018: 20 years) |
Farm (granja) | Farm owner and Authorized Users; workers; buyers; producers named in animal transit documents | Names, contact, roles, animal transit guides (GTA), sales and purchase records; where the farm uses these features, worker photos and location; app push tokens; assistant conversation history | None expected; worker images and location are sensitive in context. See the Workforce, Farm and Site Monitoring Addendum | Farm operations, traceability, sales, workforce coordination; AI assistant where turned on | Term + Section 12 |
| Bidstream (procurement) | Authorized Users; the Customer's own contacts it records | Business profile, saved searches, monitors and alerts, notes, contact details the Customer adds | None expected | Procurement search, alerts and bid preparation for the Customer. Public tender data compiled by SonhoLab is SonhoLab's own content, not Customer Personal Data (see the Procurement Intelligence Addendum) | Term + Section 12 |
| Brain SaaS (memory API for AI agents) | Developers and Authorized Users; any person whose data the Customer's agents store | Whatever the Customer's agents store (free text, events, memories), embeddings of that text, API key metadata, access logs | Not intended. If the Customer stores them, the Customer is responsible for the lawful basis | Storage and retrieval of memory for the Customer's AI agents, including semantic search. See the Developer and API Terms | Until the Customer deletes it, or term + Section 12 |
| CobraDia (daily collections) | Lender's Authorized Users (administrators, collectors); debtors | Debtor name, phone, government ID number and ID document photo, photo, address, geolocation (latitude and longitude), loans, payments, delinquency status | Government identity documents; precise geolocation; financial data | Loan and collection management for the lender; geocoding of addresses through OpenStreetMap Nominatim; payments through Stripe. See the Debt Collection Addendum (CobraDia) | As instructed by the lender; by default deleted 90 days after the debt is settled |
| Real Estate CRM | Leads, property owners, buyers and tenants; Authorized Users | Name, phone, budget, areas of interest, lead score, WhatsApp conversations, property documents, payment proofs, electronic signatures, valuations, appointments | Government identity numbers may appear in property documents | Lead management, messaging, property and document management, automated valuation and lead scoring as decision support. See the Real Estate CRM and Valuation Addendum | Term + Section 12; WhatsApp conversations 12 months rolling unless the Customer sets shorter |
| Restaurant System | Diners and customers; Authorized Users | Name, phone, delivery address, orders, notes, payment status | Not intended; free-text notes may reveal health information (for example, allergies) | Order taking, delivery and restaurant management | Term + Section 12 |
| Passayum (marketplace and delivery) | Buyers, merchants, couriers; Authorized Users | Name, contact, addresses, orders, payment status; couriers' identity verification and location during deliveries | Precise geolocation; couriers' government identity documents | Marketplace, order and delivery management. See the Location and Mobility Addendum (Speed, Passayum) | Term + Section 12 |
Ticketing (boleteria) | Ticket buyers and attendees; event organizer's Authorized Users | Name, email, phone, tickets purchased, payment status, check-in records | None expected | Ticket sales, access control and attendee communication for the organizer | Term + Section 12 |
| Speed (ride-hailing) | Riders, drivers; operator's Authorized Users | Name, contact, trip history, pick-up and drop-off points, real-time location during trips, driver documents and vehicle data, wallet balances, emergency button events | Precise geolocation; drivers' government identity documents | Ride dispatch, trip management, payments to drivers, safety features. See the Location and Mobility Addendum (Speed, Passayum) | Term + Section 12 |
| PDF Free | Authorized Users | Account data only, where an account is used. Documents processed on the device are not received by SonhoLab. | None | Document tools | Term + Section 12 |
| Jesse and Digital Team OS (AI WhatsApp assistants for businesses) | The business's customers and prospects who message it; the business owner and staff | Phone number, WhatsApp profile name, messages, voice notes and their transcripts, images and payment receipts (read by OCR), appointments, notes the assistant keeps about the conversation, web search queries the assistant runs | Not intended. If the business is in a health sector, health data only through the official WhatsApp Business Platform | Answering the business's customers as an AI assistant that says it is one at the start, scheduling, lead capture, handing off to a human on request. AI models run on the business's own AI provider account and key (Section 16.3); that provider is the business's vendor, not a SonhoLab Subprocessor. See the AI Agents and Messaging Addendum | Conversations 12 months rolling unless the business sets shorter; other data term + Section 12 |
| LLM gateway (llm-proxy, for API customers) | Any person whose data appears in the Customer's prompts; the Customer's developers | Prompts and model outputs in transit; usage records (tenant, model, token counts, timestamps); API key metadata | Whatever the Customer sends. The Customer decides | Routing the Customer's requests, with the Customer's own key, to the model provider it selects and returning the result. That provider is the Customer's vendor (Section 16.3). See the Developer and API Terms | As set out in the Developer and API Terms and the Order for this service |
Annex II — Technical and organizational measures
These are the measures SonhoLab maintains for Customer Personal Data. Items marked "rolled out per System" are not yet in place in every System. SonhoLab will tell a Customer the current status for its System on request.
| # | Area | Measure |
|---|---|---|
| 1 | Encryption in transit | All connections to the Systems use TLS. |
| 2 | Encryption of backups | Hetzner makes automated server backups in Finland. The off-site backup copy is encrypted on the server before it leaves it, and is stored on equipment operated by SonhoLab in Brazil (covered by the mutual adequacy between Brazil and the EU). |
| 3 | Access control for personnel | Access to production systems and Customer Personal Data is limited to named SonhoLab personnel who need it. Access to production servers requires personal SSH keys; password login is disabled. Administrative web panels use single-use sign-in links sent to named SonhoLab email addresses. |
| 4 | Separation between customers | Each organization's data is logically isolated. Every database query is scoped by organization ID. Database row-level security: rolled out per System; current status on request. |
| 5 | Abuse protection | Rate limiting protects the Systems against password guessing and other abuse. |
| 6 | Logging | Access logs are kept for 6 months, and up to 12 months for security investigations. They are stored confidentially. |
| 7 | Secrets management | Passwords, API keys and other secrets are kept outside source code. |
| 8 | Incident response | A documented incident response process covers Personal Data Breaches and malware. It includes containment, assessment and the notification timelines in Section 11. See Security and Incident Response. |
| 9 | Backups | Database backups are kept up to 14 days on the server and up to 14 days in the encrypted off-site copy, then expire. |
| 10 | Confidentiality | Personnel are bound by confidentiality (Section 6). |
| 11 | Subprocessor management | Subprocessors are bound by written data protection terms (Section 8). No SonhoLab AI account processes Customer Personal Data; AI features run only on the Customer's own key (Section 16.3). |
| 12 | Data subject rights | The Systems include export and deletion tools (Section 9). |
| 13 | Review | SonhoLab reviews these measures at least once a year and after any significant incident. |
| 14 | Certifications | None. SonhoLab does not hold SOC 2, ISO 27001 or any other security certification. |
Annex III — Subprocessors
The list of Subprocessors, with their purpose, location, the Systems that use them and the transfer mechanism for each, is in Subprocessors and International Transfers (04-subprocessors.md). It is incorporated into this DPA by reference. Changes follow Section 8.
Annex IV — Transfer mechanisms
IV.1 EU Standard Contractual Clauses
Incorporation. The standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 (the "EU SCCs") are incorporated by reference. They apply to transfers of Customer Personal Data subject to the GDPR:
- from the Customer to SonhoLab, but only where the Brazil adequacy decision does not cover the transfer (Section 14.2); and
- from SonhoLab to Subprocessors outside the EEA not covered by an adequacy decision.
Modules.
- Module 2 (controller to processor) applies where the Customer is a controller.
- Module 3 (processor to processor) applies where the Customer is a processor, and between SonhoLab and its Subprocessors.
- Options selected.
| Clause | Selection |
|---|---|
| Clause 7 (docking clause) | Included. Other entities may accede with the agreement of the parties. |
| Clause 9(a) (subprocessors) | Option 2: general written authorization. SonhoLab gives at least 30 days' notice of intended changes, as in Section 8. |
| Clause 11(a) (redress) | The optional independent dispute resolution language is not included. |
| Clause 13 (supervision) | The competent supervisory authority is set as Clause 13(a) requires. (i) If the Customer is established in the EU, it is the authority of the Customer's Member State. (ii) If the Customer is not established in the EU but has appointed an Art. 27 representative, it is the authority of the Member State where that representative is established. (iii) If the Customer is not required to appoint a representative, it is the authority of the Member State where the relevant data subjects are. For transfers where SonhoLab is the exporter, it is the authority of the Member State where SonhoLab's EU representative is established, which will be Ireland. Until that appointment is published, it is the authority of the Member State where the relevant data subjects are. |
| Clause 17 (governing law) | Option 1: the law of Ireland. |
| Clause 18 (forum) | The courts of Ireland. |
Annexes to the EU SCCs.
- Annex I.A (list of parties): the Customer and SonhoLab, with the details in the Customer's account and Section 1.1.
- Annex I.B (description of the transfer): Annex I of this DPA.
- Annex I.C (competent supervisory authority): as in Clause 13 above.
- Annex II (technical and organizational measures): Annex II of this DPA.
- Annex III (subprocessors): Subprocessors and International Transfers.
- Interpretation. Sections 13 (audits), 8 (subprocessors), 12 (deletion) and 11 (breach) of this DPA describe how the parties exercise the corresponding rights under the EU SCCs. They do not change the EU SCCs. If they conflict, the EU SCCs prevail.
IV.2 UK Addendum
- Incorporation. The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (the "UK Addendum"), issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018, is incorporated by reference. It applies to transfers of Customer Personal Data subject to the UK GDPR.
Tables.
- Table 1 (parties): as in Annex IV.1, item 4.
- Table 2 (selected SCCs, modules and clauses): the EU SCCs, with the modules and options in Annex IV.1.
- Table 3 (appendix information): Annexes I, II and III of this DPA.
- Table 4 (ending the Addendum when the approved Addendum changes): the Importer may end it.
- If the UK issues a replacement for the UK Addendum, the parties will use the replacement. SonhoLab may instead use the UK International Data Transfer Agreement with its Subprocessors.
IV.3 ANPD standard contractual clauses (Brazil)
- Incorporation. The standard contractual clauses in Annex II to Resolução CD/ANPD nº 19/2024 (the "ANPD Clauses") apply to international transfers of Customer Personal Data subject to the LGPD to countries the ANPD has not recognized as adequate. This includes transfers from SonhoLab to Subprocessors in the United States.
- No changes. The ANPD Clauses are adopted in full and without alteration, as Res. CD/ANPD 19/2024, Art. 16 requires. They are attached below verbatim, in Portuguese. No summary or translation in this DPA replaces them.
- Complementary clauses. Any complementary clause appears only in the place the ANPD model reserves for it. It must not contradict the ANPD Clauses or reduce the protection they give.
- Options and designations. The party designations are: the Customer as controller; SonhoLab as operator; each Subprocessor as sub-operator. Where the ANPD model offers options, the options that match this DPA apply.
- Transparency. SonhoLab publishes a Portuguese-language page on its international transfers (Res. CD/ANPD 19/2024, Art. 17). It is part of Subprocessors and International Transfers. SonhoLab sends the full text of the clauses within 15 days of a request.
Attached text:
The ANPD standard contractual clauses (Annex II of Resolução CD/ANPD nº 19/2024) are incorporated into this DPA by reference. We provide a copy on request within 15 days; write to contacto@sonholab.com.
IV.4 Other jurisdictions
Where the law of another country requires a specific instrument, Section 14.5 applies.
Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.