सरकारी और कानून प्रवर्तन अनुरोध

    प्रारंभिक संस्करण, कानूनी समीक्षा में

    संस्करण 0.9.0

    यह दस्तावेज़ अभी हिंदी में अनुवादित नहीं है। इसे अंग्रेज़ी में दिखाया गया है; अनुवाद उपलब्ध होने तक अंग्रेज़ी पाठ ही बाध्यकारी है।

    Table of contents

    1. Scope and principles
    2. Who we are and where data is held
    3. What we require from Brazilian authorities
    4. Requests from outside Brazil
    5. Emergencies and reports we make on our own initiative
    6. Notice to customers and users
    7. Data minimization and challenges
    8. Data we hold for business customers
    9. Transparency
    10. How authorities should contact us

    1. Scope and principles

    1.1 What this document covers. It describes how L. M. PEREZ MONTANA (trade name SonhoLab), CNPJ 61.620.014/0001-00, handles requests from governments, courts, police, prosecutors and other public authorities. These requests may ask us to:

    • disclose data about users of our Services;
    • preserve data;
    • remove content.

    Terms used here have the meaning given in the Terms of Service.

    1.2 Principles.

    • (a) Legality. We disclose data only when the law requires it, following due legal process, or in the emergency cases in Section 5.
    • (b) Specificity. Requests must identify specific accounts or content and specific time periods. We do not give bulk or indiscriminate access.
    • (c) Minimization. We disclose the least data needed to comply.
    • (d) Transparency. We tell affected people when we lawfully can, and we publish aggregated figures.
    • (e) No backdoors. We do not build backdoors into our Services. We do not give any authority direct or real-time access to our systems. We do not weaken our encryption for anyone.

    1.3 What this document does not cover.

    2. Who we are and where data is held

    2.1 Establishment. SonhoLab is a Brazilian Empresário Individual with its registered address at Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil. It has no establishment, subsidiary or employees in any other country.

    2.2 Where data is held.

    • Our primary hosting is provided by Hetzner Online GmbH in data centers in Helsinki, Finland (EU), with Hetzner's automated server backups in Finland.
    • Our encrypted off-site backup copy is stored on equipment operated by SonhoLab in Brazil.
    • Our subprocessors process certain data in other countries, as listed in Subprocessors and International Transfers.

    2.3 What data we may have. The data we can disclose depends on the Service and on our retention periods. Categories we may hold include:

    • (a) registration data: name, email, phone, organization name and tax ID;
    • (b) access logs: IP address, date, time and time zone of access. We keep them for 6 months, as required by art. 15 of the Brazilian Internet Civil Framework (Marco Civil da Internet), and up to 12 months for security investigations;
    • (c) billing records;
    • (d) content: Customer Data, User Content and messages.

    After the periods in our Data Retention Schedule, data is deleted and we cannot produce it. Payment card numbers are held by our payment processor, not by us.

    2.4 Brazilian law applies. Brazilian law governs our handling of data collected in Brazil or relating to users in Brazil (Marco Civil arts. 10 and 11). We comply with valid orders of Brazilian courts and with requests that Brazilian law allows.

    3. What we require from Brazilian authorities

    3.1 Registration data. Authorities that the law empowers to request registration data may ask for data about a user's personal qualification, parentage and address without a court order (Marco Civil art. 10, §3, and the specific law that grants the power). The request must:

    • come from an authority with that legal power, on official letterhead or through an official channel;
    • cite the legal basis for the power;
    • identify the specific user or account.

    3.2 Access logs. We disclose access logs only under a court order (Marco Civil arts. 10, §1, and 22). The order must identify:

    • the specific account or content;
    • the time period;
    • the reasons, as art. 22 requires.

    3.3 Content of communications and stored content. We disclose the content of private communications, and other stored content, only under a court order that expressly covers that content (Marco Civil arts. 7, II and III, and 10, §2).

    3.4 Preservation. Police authorities, administrative authorities and the Public Prosecutor's Office may ask us to preserve specific access logs, including beyond the 6-month period (Marco Civil art. 15, §2).

    • We preserve the specified records and keep them confidential.
    • The authority must file for a court order to access them within the period set by law (Marco Civil art. 13, §§3 and 4, applied by art. 15, §2). If it does not, the preservation lapses and the records are deleted on our normal schedule.

    3.5 Content removal. We comply with court orders to remove specific content. We also act on extrajudicial notices, as explained in the Copyright and Content Removal Policy. The order or notice must identify the content unambiguously, for example by exact URL.

    3.6 Data protection authority. We cooperate with the Agência Nacional de Proteção de Dados (ANPD) under the LGPD and its regulations. This includes responding to requests about our processing and notifying security incidents.

    3.7 Legal basis for our disclosures. When we disclose personal data to comply with Brazilian legal process, we do so to comply with a legal or regulatory obligation (LGPD art. 7, II, and, for sensitive data, art. 11, II, a).

    4. Requests from outside Brazil

    4.1 General rule. Foreign authorities should direct requests for user data through the channels of international cooperation that Brazil recognizes. These are:

    • mutual legal assistance treaties (MLATs) and other international agreements;
    • letters rogatory, which require an exequatur from the Superior Court of Justice (STJ);
    • other procedures that Brazilian law recognizes.

    When a request reaches us through these channels as a Brazilian order, Section 3 applies.

    4.2 United States.

    • We have no establishment in the United States.
    • US authorities should use the Treaty on Mutual Legal Assistance in Criminal Matters between Brazil and the United States (promulgated in Brazil by Decreto 3.810/2001), letters rogatory, or another process that is recognized and enforceable in Brazil.
    • We do not treat a US subpoena, court order or warrant served directly on us as binding by itself. We review each one with counsel. Where it is not binding, we explain the proper channel to the requesting authority.

    4.3 European Union.

    • Authorities of EU member states may use mutual legal assistance between their state and Brazil, including under the Council of Europe Convention on Cybercrime (Budapest Convention), to which Brazil is a party.
    • EU e-Evidence Regulation. Regulation (EU) 2023/1543 on European Production and Preservation Orders applies from 18 August 2026. It covers service providers that offer certain services in the Union. SonhoLab applies it only if, and to the extent that, it covers our Services. It could apply, for example, to Services that let users in the EU communicate or store data and that have a substantial connection to the EU. If it applies:

      • we will designate a legal representative in the EU under Directive (EU) 2023/1544;
      • we will handle European Production Orders and European Preservation Orders through that representative;
      • we will follow the procedures, deadlines and grounds for refusal that the Regulation provides.
    • GDPR, art. 48. For personal data of people in the EU, a judgment or decision of a court or authority of a third country that requires us to transfer or disclose the data is recognized only if it is based on an international agreement, such as an MLAT, in force between that country and the EU or a member state.
    • Our hosting provider. Requests addressed to Hetzner in Finland are governed by Finnish and EU law and by Hetzner's own policies.

    4.4 Other countries. Authorities of other countries should use mutual legal assistance or letters rogatory as described in Section 4.1.

    4.5 Emergencies are the exception. Section 5 applies to foreign authorities in genuine emergencies.

    5. Emergencies and reports we make on our own initiative

    5.1 Emergency disclosure. We may disclose limited data to an authority without the process described above if we believe in good faith that:

    • there is an imminent risk of death or serious physical injury to a person; and
    • disclosure without delay is necessary to prevent it.

    We do so on the basis of protection of life (LGPD art. 7, VII, and art. 11, II, e; GDPR art. 6(1)(d) where it applies).

    5.2 What an emergency request must contain. An emergency request must:

    • (a) come from an identifiable official of a public authority, whom we can verify through official channels;
    • (b) describe the nature of the emergency and why it is imminent;
    • (c) specify the data needed and how it will help prevent the harm.

    We disclose only what is necessary to address the emergency. We ask the authority to follow up with the appropriate legal process.

    5.3 Reports we make on our own initiative.

    • (a) If we become aware of information that gives rise to a suspicion of a criminal offense involving a threat to someone's life or safety, we inform the competent authorities. For suspected offenses in the EU, we do so under art. 18 of the Digital Services Act.
    • (b) We report child sexual abuse material to the competent authorities, as described in the Acceptable Use Policy, Section 3.
    • (c) We notify security incidents to data protection authorities as the law requires. See Security and Incident Response.

    5.4 Records. We record every emergency disclosure and every report we make on our own initiative. The record includes the legal basis, the data disclosed and the recipient.

    6. Notice to customers and users

    6.1 We tell you first. Before we disclose data in response to a request, we notify the affected user. If the data belongs to an Organization, we also notify the Organization Owner. We give them a copy or summary of the request, so they have the opportunity to seek legal protection.

    6.2 When we do not tell you first. We do not give prior notice when:

    • (a) the law, or a court order, forbids it. For example, when a judge orders secrecy;
    • (b) notice would create a risk of death or serious physical injury to anyone;
    • (c) notice would compromise an emergency response under Section 5;
    • (d) the case involves child sexual abuse material or the exploitation of children;
    • (e) the account has been compromised, and notice would alert the person who compromised it rather than the account holder.

    6.3 Delayed notice. When we could not notify in advance, we notify as soon as the prohibition ends or the risk passes, where the law allows it.

    6.4 Content removal. When we remove content following an order or request of an authority, we give the affected user a statement of reasons, unless the law or the order forbids it. See the Copyright and Content Removal Policy, Section 13.

    7. Data minimization and challenges

    7.1 Narrow reading. We read each request narrowly. We disclose only the data expressly covered by the request, for the specified accounts and time period.

    7.2 Checks we make. Before responding we verify:

    • (a) that the request is authentic and comes from a competent authority. We confirm this through official channels where needed;
    • (b) that it has a valid legal basis and the form the law requires (for example, a court order where Section 3 requires one);
    • (c) that it identifies specific accounts or content and a specific time period;
    • (d) that it is proportionate to its stated purpose.

    7.3 Challenges. If a request is:

    • unclear, we ask the authority to clarify or narrow it;
    • overbroad, we ask the authority to narrow it;
    • lacking a valid legal basis or the required form, we refuse it;
    • unlawful in other respects, we challenge it through the available legal remedies.

    We do not disclose data while a lawful challenge is pending, unless the law or a court requires us to.

    7.4 Security of disclosures. We deliver data through a secure channel agreed with the authority. We log what we delivered, to whom and when.

    7.5 Costs. Where the law allows it, we may ask for reimbursement of reasonable costs of complying with requests that require significant work.

    8. Data we hold for business customers

    8.1 The customer is the controller. Many Organizations use our Systems to store data about their own students, patients, clients, workers and debtors. For that Customer Data the Organization is the controller and SonhoLab acts as its processor. The Organization is usually in the best position to respond to an authority. It knows the context and holds the legal duties toward the people concerned.

    8.2 We refer the authority to the customer first. When we receive a request for Customer Data, we first refer the authority to the Organization, unless:

    • the law or a court order requires us to respond directly;
    • the Organization itself is the subject of the investigation; or
    • an emergency under Section 5 applies.

    8.3 Notice to the customer. Section 6 applies. We notify the Organization unless one of the exceptions applies. The Data Processing Addendum (DPA) sets out our commitments to Organizations on this point.

    8.4 Sensitive sectors. For health data (the Health Data Addendum (Clínicas)) and for student data (the Children and Student Data Addendum (Verita)), we also take into account the professional secrecy and education-record protections that apply to the customer.

    9. Transparency

    9.1 Annual report. We publish an annual transparency report on sonholab.com. The first report will be published in March 2028 and will cover 2027. It includes, as aggregated figures:

    • (a) the number of requests for user data received, by country and by type (registration data, logs, content, preservation, emergency);
    • (b) the number of requests in which we disclosed some data, none, or which we challenged;
    • (c) the number of accounts affected;
    • (d) the number of content removal orders and notices, and our response times, together with the figures from the Copyright and Content Removal Policy, Section 16.

    9.2 Limits. The report contains no personal data. It may group small numbers into ranges where the law requires it, or to avoid identifying a specific investigation.

    10. How authorities should contact us

    10.1 Channel. Send requests to contacto@sonholab.com with the subject "Law enforcement request". Formal documents may also be delivered to Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil. This channel also serves as our single point of contact for authorities under art. 11 of the Digital Services Act.

    10.2 Language. Accepted languages for requests: English, Portuguese and Spanish.

    10.3 What to include.

    • (a) the name of the authority, and the name, position and official contact details of the requesting official;
    • (b) the legal basis and, where required, a copy of the court order;
    • (c) the specific accounts, identifiers or content concerned (for example, account email, slug, exact URL or phone number of an AI agent);
    • (d) the specific data requested and the time period;
    • (e) the deadline, and whether the request is subject to secrecy;
    • (f) for emergencies, the information in Section 5.2.

    10.4 Not for other matters. This channel is only for public authorities. Private parties who need data for legal proceedings should obtain a court order. Other messages sent to this channel will not receive a reply through it.

    10.5 Changes. We may update this document. Each version is published at sonholab.com/{lang}/legal with its date.


    Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.

    प्रारंभिक संस्करण, कानूनी समीक्षा में

    संस्करण 0.9.0

    इस पाठ का SHA-256 फ़िंगरप्रिंट: 756df590092a1745240551ac24e9e036fe4d38959998b13173de4f2941a5184b

    कानूनी केंद्र पर वापस जाएँ