Table of contents
- About this Policy
- Controller or processor: what this Policy does not cover
- What we collect, where it comes from, why we use it, and our legal bases
- Sensitive data
- Children and students
- AI processing and automated decisions
- Who receives personal data
- International transfers
- Security
- How long we keep data
- Your rights
- United States: state privacy disclosures
- Cookies and similar technologies
- Marketing communications and how to opt out
- Consumer apps, free tools and product addenda
- Changes to this Policy
- Contact us, representatives and supervisory authorities
1. About this Policy
1.1 Who we are
SonhoLab is the trade name of L. M. PEREZ MONTANA, a Brazilian sole proprietorship (Empresário Individual, Microempresa), CNPJ 61.620.014/0001-00, with its registered address at Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil.
- General contact: contacto@sonholab.com
- Phone: +55 85 99412-2292
- Website: https://sonholab.com
In this Policy, "SonhoLab", "we", "us" and "our" mean L. M. PEREZ MONTANA.
1.2 Data protection officer (Encarregado)
Our data protection officer (Encarregado pelo tratamento de dados pessoais under LGPD art. 41) is Leandro Manuel Pérez Montañana. You can reach the Encarregado at contacto@sonholab.com. The Encarregado handles requests from individuals and from data protection authorities, and communicates in Portuguese as Brazilian law requires.
1.3 Representatives in the EU and the UK
We are established in Brazil. For people in the European Economic Area (EEA), we are appointing a representative under GDPR art. 27:
- EU representative: SonhoLab is appointing a representative in the European Union (Ireland). Until the appointment is published, EU residents can contact contacto@sonholab.com.
- UK representative: none. We do not currently direct our services to the United Kingdom, so we have not appointed a representative under UK GDPR art. 27. If we start to do so, we will appoint one and list it here. People in the UK keep all their rights under the UK GDPR.
Once the appointment is published, you and any supervisory authority may contact our EU representative about any issue related to our processing of personal data. Appointing a representative does not change our own responsibility.
1.4 Scope and how this Policy fits with our other documents
This Policy is part of the SonhoLab Legal Center. It works in layers:
- Master documents apply to everyone. They include this Policy, the Terms of Service (01-terms-of-service.md), the Data Processing Addendum (DPA) (03-data-processing-addendum.md), Subprocessors and International Transfers (04-subprocessors.md), the Cookie Policy (05-cookie-policy.md), the AI Transparency Notice (07-ai-transparency.md), Security and Incident Response (08-security-and-incidents.md), Your Privacy Rights and How to Exercise Them (09-data-rights-requests.md) and the Data Retention Schedule (10-retention-schedule.md).
- Regional supplements add rules for your region: Brazil Supplement (R-br-lgpd.md), EEA and UK Supplement (R-eu-uk.md), United States Supplement (R-us-states.md) and Latin America Supplement (R-latam.md).
- Product addenda add rules for specific products, such as Hades, Verita, Clinics or our games. Section 15 lists them. Product-specific addenda apply only to products offered under them and are published on the Legal Center when the product is offered.
If a product addendum or regional supplement gives you more protection than this Policy, the more protective text applies.
Language. English is the master text. We publish translations in Portuguese (Brazil), Spanish, French, German, Hindi, Indonesian and Russian. For users in Brazil, the Portuguese (pt-BR) text is binding to the extent Brazilian law requires. Where the law of your country requires its local-language version to prevail, that version prevails.
1.5 Terms we use
- Personal data means any information about an identified or identifiable living person. In US state law this is often called "personal information."
- System means any SonhoLab software product, such as Inventory, Verita, Clinics, Farm, Bidstream, Brain SaaS, CobraDia, Real Estate CRM, Restaurant System, Passayum, Ticketing, Speed, PDF Free, Jesse or Digital Team OS.
- Customer means a business, school, clinic or other organization that uses a System under our Terms of Service.
- Customer Data means the personal data a Customer, or the Customer's users, load into a System or collect through it.
- Organization Account means the account a Customer creates through our central registration. One Organization Account can access every System the organization selects.
- User means a person who logs in to an Organization Account or to one of our consumer apps.
2. Controller or processor: what this Policy does not cover
2.1 When SonhoLab is the controller
We are the controller (in Brazil, controlador; in US state law, the "business" or "controller") when we decide why and how personal data is used. This covers:
- our websites, including sonholab.com and our product landing pages;
- central registration at
sonholab.com/{lang}/registroand the control panel at control.sonholab.com; - the login details and profile of every User of an Organization Account;
- plans, billing and payments;
- our support desk (Sofia) and our website chat assistant (Tifa);
- our own sales and support assistant on WhatsApp, which is a channel of our support desk (Sofia);
- marketing, newsletters and waitlists;
- our free web tools;
- our consumer apps: PDF Free, SonhoLab Poker, Casa Embrujada (Roblox), the Job Portal and ComexCalc, and Hades (not currently offered to the public; access is limited to invited testers);
- security, fraud prevention and legal compliance for all of the above.
This Policy covers this data.
2.2 When SonhoLab is the processor
When a Customer uses a System, the Customer decides what data to load and why. For that Customer Data, the Customer is the controller and SonhoLab is the processor (in Brazil, operador; in US state law, the "service provider" or "processor").
Examples of Customer Data:
- students, guardians and grades in Verita (the school is the controller);
- patients and health records in Clinics (the clinic is the controller);
- debtors in CobraDia (the lender is the controller);
- the end customers who chat with a business through Jesse or Digital Team OS (the business is the controller);
- products, customer contacts and dispatch records in Inventory, and products, suppliers and contacts in Real Estate CRM or Restaurant System;
- drivers, riders, buyers and sellers in Speed or Passayum;
- workers and site records in Farm.
This Policy does not cover Customer Data. For Customer Data:
- the Customer's own privacy notice tells you how your data is used;
- our Data Processing Addendum (DPA) (03-data-processing-addendum.md) sets our duties to the Customer;
- Subprocessors and International Transfers (04-subprocessors.md) lists the providers that help us run the Systems.
We process Customer Data only on the Customer's documented instructions. We do not use Customer Data for our own purposes. We do not sell it. We do not use it to train AI models.
2.3 Mixed situations
A single person can deal with us in both roles. For example, if you are a teacher who logs in to Verita:
- your login email, password and access history are handled by SonhoLab as controller under this Policy (section 3.2.4);
- the grades and messages you enter are Customer Data controlled by your school.
We also keep limited service data about how each Organization Account uses a System (for example, the number of active people and the storage used) to apply plan limits and plan capacity. We handle that as controller under this Policy. It does not include the content of Customer Data.
2.4 If you are a student, patient, debtor or end customer of one of our Customers
Please send your privacy request to the organization that holds your data. If you send it to us instead, we will tell you that we act as processor, forward your request to that organization, and help it answer. Your Privacy Rights and How to Exercise Them (09-data-rights-requests.md) explains this process.
3. What we collect, where it comes from, why we use it, and our legal bases
3.1 How to read this section
Each table below describes one processing activity. For each one, we list:
- Data: the categories of personal data;
- Source: where we get it;
- Purposes: why we use it;
- Legal basis: the Brazilian basis (LGPD art. 7, or art. 11 for sensitive data) and the EEA/UK basis (GDPR art. 6, or art. 9 for special-category data);
- US categories: the matching category under California law, for US state notice-at-collection purposes (section 12 explains them);
- Retention: how long we keep it. The Data Retention Schedule (10-retention-schedule.md) has the full rules.
We collect only what we need for each purpose. We do not use data for a new purpose that is incompatible with the original one without telling you first and, where the law requires it, asking for your consent.
3.2 Processing activities
3.2.1 Visiting our websites
| Data | IP address, date and time, requested page, referring page, browser and device type, language, error codes |
| Source | Your browser, automatically |
| Purposes | Deliver the page; keep the site secure; prevent abuse and attacks; diagnose errors; meet our legal duty to keep access logs |
| Legal basis | Brazil: legal obligation (LGPD art. 7 II; Marco Civil da Internet art. 15) and legitimate interest (art. 7 IX). EEA/UK: legitimate interest in security and service delivery (GDPR art. 6(1)(f)) |
| US categories | Identifiers; internet or other electronic network activity |
| Retention | 6 months; up to 12 months when needed for a security investigation |
3.2.2 Website analytics (only with your consent)
| Data | Pages viewed, time on page, clicks on key buttons, approximate location derived from IP (country or city), device and browser type, a random analytics identifier stored in a cookie |
| Source | Your browser, through Google Analytics 4, only after you accept analytics cookies |
| Purposes | Understand which pages and languages are useful; improve content and navigation |
| Legal basis | Brazil: consent (LGPD art. 7 I). EEA/UK: consent (GDPR art. 6(1)(a); ePrivacy Directive art. 5(3); UK PECR reg. 6) |
| US categories | Identifiers (online identifier); internet or other electronic network activity; geolocation (approximate only) |
| Retention | Cookie lifetimes and analytics retention are listed in the Cookie Policy (05-cookie-policy.md). Google Analytics 4 keeps event data for 2 months. |
Google Signals is off. Ad-personalization signals are off. We do not link analytics to advertising products. Analytics does not load until you accept it, and you can withdraw consent at any time through the "Cookie settings" link on every page.
3.2.3 Website chat and our AI assistants
We run an AI chat assistant on our websites (Tifa) and an AI sales and support assistant on WhatsApp, which is a channel of our support desk (Sofia). Both say at the start of the conversation that they are AI assistants of SonhoLab. You can ask for a human at any time.
| Data | Your messages and the assistant's replies; any contact details you choose to give (name, email, phone, company, country); what you are interested in (product, budget range, timing); for WhatsApp, your WhatsApp number and profile name, and voice notes you send |
| Source | You |
| Purposes | Answer your questions; route you to a person; follow up on a request for a quote, demo or access; improve the answers the assistant gives |
| Legal basis | Brazil: steps prior to a contract at your request (LGPD art. 7 V) and legitimate interest in answering inquiries (art. 7 IX). EEA/UK: steps prior to a contract (GDPR art. 6(1)(b)) and legitimate interest (art. 6(1)(f)) |
| US categories | Identifiers; commercial information (products of interest); audio information (voice notes); professional information (company, role) |
| Retention | Chats that become a support request follow the support-ticket period (24 months after closure). Contact details you give for follow-up follow the marketing-lead period (until you unsubscribe or 24 months without interaction). WhatsApp conversations: 12 months rolling. Website chat transcripts that do not become a ticket or a lead: 12 months. |
Chat messages and voice notes are processed by OpenAI, through SonhoLab's own API account, under a contract that bars it from training on your data. Please do not share sensitive data in the chat. Section 6 and the AI Transparency Notice (07-ai-transparency.md) give more detail.
3.2.4 Central registration and Organization Accounts
| Data | For the organization: name, country, phone, preferred language, the Systems selected, plan, the URL path or custom domain used. For each person: name, email, phone (optional), role in the organization, password (stored only as a one-way hash), login links sent by email, sign-up date, last access, IP address at sign-up, campaign source (UTM tags) if you arrived from a campaign |
| Source | You. If a colleague invited you, your organization's administrator gave us your name and email |
| Purposes | Create and run the Organization Account; let you log in to every System your organization selected; provision Free plans automatically; enable paid plans after order and payment; send account notices (including inactivity and deletion notices); keep the account secure; enforce plan limits; keep internal operational records of sign-ups (organization slug, Systems selected, country, campaign source) |
| Legal basis | Brazil: performance of a contract (LGPD art. 7 V); legitimate interest for security and fraud prevention (art. 7 IX). EEA/UK: performance of a contract (GDPR art. 6(1)(b)); legitimate interest for security (art. 6(1)(f)) |
| US categories | Identifiers; customer records; commercial information; internet or other electronic network activity; professional information; sensitive personal information (account login credentials) |
| Retention | Life of the account plus 30 days after cancellation, then deleted. Free plans with no activity are deleted after 90 days of inactivity, after 2 prior notices |
Required data. We need a name, an email and a password to create an account. Without them we cannot create or secure it. Phone and marketing preferences are optional.
3.2.5 Legal acceptance and consent records
| Data | Which document you accepted or which consent you gave (for example, the Terms of Service, this Policy, the DPA, marketing consent, cookie choices); its version and digital fingerprint; date and time; the account or browser that accepted; IP address |
| Source | You, when you accept or choose |
| Purposes | Prove what was agreed and when; honor your choices; defend legal claims |
| Legal basis | Brazil: legal obligation and accountability (LGPD arts. 7 II and 8 §2) and the exercise of rights in legal proceedings (art. 7 VI). EEA/UK: legal accountability (GDPR arts. 5(2) and 7(1)) and legitimate interest in defending claims (art. 6(1)(f)) |
| US categories | Identifiers; internet or other electronic network activity |
| Retention | 5 years after the relationship ends |
3.2.6 Plans, billing and payments
| Data | Name and email of the billing contact; organization name and address; the account holder's identity document number and the organization's tax identifier (for example, CPF or CNPJ in Brazil), collected only when the Organization upgrades to a paid plan and used only to identify the contracting party and issue invoices — never requested for Free plans; plan, price, currency, invoices, payment date, payment status, the last digits and brand of your card, and payment references |
| Source | You; our payment provider (Stripe) |
| Purposes | Charge for paid plans; issue invoices; reconcile payments; handle refunds and chargebacks; keep tax and accounting records; prevent payment fraud |
| Legal basis | Brazil: performance of a contract (LGPD art. 7 V); legal obligation under Brazilian tax law (art. 7 II); credit protection where relevant (art. 7 X). EEA/UK: performance of a contract (GDPR art. 6(1)(b)); legitimate interest in complying with Brazilian tax law (art. 6(1)(f)), because GDPR art. 6(1)(c) covers only EU or member-state law |
| US categories | Identifiers; customer records (including partial payment card data); commercial information; sensitive personal information (government identifier, only for paid plans) |
| Retention | 5 years (Brazilian tax law), or longer if the law requires |
We do not store full card numbers. Stripe collects and stores your payment card details. In some countries a local payment method may be offered at checkout. Stripe and card networks may also process your data as independent controllers for their own fraud and compliance duties.
3.2.7 Support desk
Our support desk (Sofia, at soporte.sonholab.com) handles tickets from Customers and Users.
| Data | Name, email and organization of the person asking; the ticket text, comments, attachments and screenshots; the System involved; ticket history and status |
| Source | You; your organization's administrator |
| Purposes | Answer and fix the issue; classify and route tickets; suggest replies; measure response times |
| Legal basis | Brazil: performance of a contract (LGPD art. 7 V); legitimate interest in improving support (art. 7 IX). EEA/UK: performance of a contract (GDPR art. 6(1)(b)); legitimate interest (art. 6(1)(f)) |
| US categories | Identifiers; customer records; professional information; audio or visual information (screenshots) |
| Retention | 24 months after the ticket is closed |
Our support desk uses AI (OpenAI) to classify tickets, read screenshots and draft replies. A person oversees the support process, and you can always ask for a human to handle your ticket. Screenshots may show Customer Data. Please crop or blur anything we do not need. Any Customer Data that reaches support is still handled under the DPA.
3.2.8 Service, security and legal notices
| Data | Name, email, phone, language, account and plan status |
| Source | Your account |
| Purposes | Send messages you need to use the service: login links, receipts, plan changes, inactivity and deletion warnings, security alerts, incident notices, changes to our legal documents |
| Legal basis | Brazil: performance of a contract and legal obligation (LGPD art. 7 V and II). EEA/UK: performance of a contract (GDPR art. 6(1)(b)); legitimate interest (art. 6(1)(f)) |
| US categories | Identifiers; customer records |
| Retention | Life of the account plus 30 days after cancellation |
You cannot opt out of these messages while you have an account, because they are part of the service. They do not contain advertising.
3.2.9 Marketing, newsletters and waitlists
| Data | Name, email, phone or WhatsApp number (if you give it), company, country, language, the products you asked about, your consent and its date. We do not track whether you open our emails. We count clicks on links only in aggregate, not per person |
| Source | You, when you join a waitlist, subscribe, request a demo or tick a marketing box |
| Purposes | Tell you when a product you asked about opens; send news and offers about SonhoLab products; invite you to demos |
| Legal basis | Brazil: consent (LGPD art. 7 I), or legitimate interest for existing business customers about similar products (art. 7 IX), with an opt-out in every message. EEA/UK: consent (GDPR art. 6(1)(a); ePrivacy Directive art. 13; UK PECR reg. 22), or the "soft opt-in" for existing customers where the law allows it |
| US categories | Identifiers; commercial information; professional information |
| Retention | Until you unsubscribe, or 24 months without interaction |
Section 14 explains how to opt out.
3.2.10 Free web tools
We offer free tools on sonholab.com (for example, PDF, image, QR and metadata tools).
| Data | For tools marked "processed in your browser": the file never leaves your device and we receive nothing from it. For tools marked "uploaded for processing": the file you upload and the result, for the time needed to process it. For all tools: an anonymous usage count (tool name and date, with no identifier) |
| Source | You |
| Purposes | Run the tool you asked for; count how often each tool is used |
| Legal basis | Brazil: performance of a contract at your request (LGPD art. 7 V). EEA/UK: performance of a contract (GDPR art. 6(1)(b)) |
| US categories | None for local tools. For uploaded files: whatever the file contains |
| Retention | Uploaded files are deleted within 1 hour after processing. Anonymous counts are kept as statistics |
Where a tool page shows a label, it tells you which of the two applies. If a tool page does not show a label, treat it as "uploaded for processing." Free Tools and Content Services Terms (P-content-tools.md) has the details.
3.2.11 Security, fraud prevention and legal compliance
| Data | Logs, account identifiers, IP addresses, device and browser data, failed login attempts, rate-limit events, reports of abuse, and records of our decisions |
| Source | Automatically; other users; our providers; authorities |
| Purposes | Protect accounts, Systems and people; detect and stop fraud, spam, attacks and misuse; investigate incidents; enforce our Terms of Service and Acceptable Use Policy (06-acceptable-use-policy.md); respond to lawful requests (see Government and Law Enforcement Requests, 12-law-enforcement.md); establish, exercise or defend legal claims |
| Legal basis | Brazil: legal obligation (LGPD art. 7 II); exercise of rights in proceedings (art. 7 VI); legitimate interest (art. 7 IX); fraud prevention and security (art. 11 II g, where sensitive data is involved). EEA/UK: legal obligation where EU or UK law applies (GDPR art. 6(1)(c)); legitimate interest (art. 6(1)(f)); in the UK, the recognized legitimate interests for security and crime prevention where they apply |
| US categories | Identifiers; internet or other electronic network activity |
| Retention | Access logs: 6 months, up to 12 months for investigations. Incident register: 5 years. Other records: as long as needed for the investigation or claim, then per the Data Retention Schedule |
3.2.12 Public procurement records (Bidstream)
Bidstream compiles public tender and contract-award records. Those records sometimes include the names, business emails or phone numbers of contact persons at buyers or suppliers.
| Data | Name, job title, organization, business contact details, as published in the tender record |
| Source | Public procurement portals and official gazettes (publicly available sources) |
| Purposes | Let Bidstream users find and analyze public tenders |
| Legal basis | Brazil: legitimate interest, for data made manifestly public (LGPD art. 7 IX and §§3-4). EEA/UK: legitimate interest (GDPR art. 6(1)(f)) |
| US categories | Identifiers; professional information |
| Retention | 24 months after the notice closes, which covers the award period |
You may object at any time, and we will remove your details unless we have compelling grounds. Procurement Intelligence Addendum (P-procurement.md) has the details.
3.2.13 Consumer apps
Our consumer apps are summarized in section 15. Each has its own addendum with a full description.
3.3 Legitimate interests we rely on
Where we rely on legitimate interest, we have balanced our interest against your rights and expectations. Our interests are:
- keeping our Systems and accounts secure and available;
- preventing fraud, spam and abuse;
- answering inquiries and supporting our Customers;
- improving our websites and support using data we already hold;
- telling existing business customers about similar products, with an easy opt-out;
- making public procurement data searchable (Bidstream);
- establishing, exercising and defending legal claims.
You may ask us for a summary of our balancing test for any activity.
3.4 Data we get from others
Most data comes from you. We also receive data from:
- your organization's administrator, who can invite you to an Organization Account;
- Stripe, about the status of your payments;
- app stores (Google Play, Apple App Store), about purchases and app installs, as independent controllers;
- Roblox, for Casa Embrujada, about your Roblox user ID;
- public sources, for Bidstream records (section 3.2.12).
4. Sensitive data
Some laws give extra protection to certain types of data. They include health, biometric, genetic, racial or ethnic origin, religious, political, sex life and sexual orientation data (LGPD art. 5 II and art. 11; GDPR art. 9). US state laws also treat account login credentials, government identifiers, precise geolocation and the data of known children as sensitive.
As controller, we do not seek sensitive data on our websites, in registration, billing, support or marketing. The exceptions are:
| Where | What | Basis |
|---|---|---|
| Account login | Email and password (hashed) | Needed to provide the service (a permitted purpose under US law) |
| Billing | Identity document number and tax identifier, only for paid plans | Performance of contract; legal obligation (invoicing) |
| Hades | Voice samples and voice models (biometric data); information that may reveal health or emotional state; data about deceased persons given by the user | Explicit, separate consent of the voice owner (LGPD art. 11 I; GDPR art. 9(2)(a)); protection of life for the crisis protocol (LGPD art. 11 II e; GDPR art. 9(2)(c)) |
If you include sensitive data in a chat, a support ticket or a free-text field, we use it only to answer you. We do not use sensitive data to infer characteristics about you, to profile you or for advertising.
Customer Data may include sensitive data, such as health records in Clinics or children's data in Verita. The Customer decides that under its own legal basis. The product addenda set extra safeguards: Health Data Addendum (P-health.md), Children and Student Data Addendum (P-children-education.md), Location and Mobility Addendum (P-location-mobility.md) and Debt Collection Addendum (P-debt-collection.md).
5. Children and students
Our accounts are for adults. You must be 18 or older to create an Organization Account or an account in any of our consumer apps. Hades and SonhoLab Poker are strictly 18+.
Children and students use our Systems only through an organization. A school or similar organization may give students and guardians access to a System, such as Verita. In that case:
- the school is the controller and decides what data is used;
- families and students cannot register themselves;
- the school obtains any parental consent or authorization the law requires (COPPA school authorization in the US; LGPD art. 14 in Brazil; GDPR art. 8 in the EEA; ECA Digital, Lei 15.211/2025, including linking accounts of users under 16 to a guardian);
- we use student data only to provide the service: no advertising, no profiling, no sale, no AI training.
The Children and Student Data Addendum (Verita) (P-children-education.md) has the full rules, including the US student-data terms and the New York Parents' Bill of Rights.
COPPA statement. Our websites, consumer apps and free tools are not directed to children under 13. We do not knowingly collect personal data from children under 13, except through a school acting under the COPPA school-authorization practice for an educational purpose. If we learn that we collected personal data from a child under 13 without proper authorization, we will delete it. If you believe this happened, write to contacto@sonholab.com.
Other minors. Our free tools and some content pages are open to anyone, but they need no account. Where a tool processes files in your browser, we receive nothing. We do not use advertising or profiling technologies on services directed to children or students. Casa Embrujada runs on Roblox under Roblox's rules and age settings, and we keep only Roblox user IDs and game progress (see Games and Virtual Items Terms, P-social-games.md).
6. AI processing and automated decisions
6.1 Where we use AI as controller
| Feature | What the AI does | Provider | Where |
|---|---|---|---|
| Website chat (Tifa) | Answers questions; collects details for follow-up | OpenAI | US |
| WhatsApp sales and support assistant | Answers questions; turns voice notes into text | OpenAI; Meta (WhatsApp channel) | US / Ireland |
| Support desk (Sofia) | Classifies tickets; reads screenshots; drafts replies, under human oversight | OpenAI | US |
These are the only activities for which SonhoLab uses its own AI account with personal data covered by this Policy. Hades is not currently offered to the public; its AI providers are described in the Hades Addendum and the AI Transparency Notice.
AI features inside a System that process Customer Data are covered by the DPA and the AI Transparency Notice, not by this section. They run on the Customer's own AI provider key, never on SonhoLab's account.
6.2 Our AI commitments
- We tell you when you are talking to an AI, at the start of the conversation.
- You can ask for a human in our chat, WhatsApp assistant and support desk.
- Our AI provider is contractually barred from training its models on the data we send it. We use OpenAI through a SonhoLab API account, only for the website chat and the support desk.
- We do not train AI models on Customer Data. We also do not use the personal data described in this Policy to train AI models.
- Synthetic audio is labeled as AI-generated (Hades).
- AI output can be wrong. Do not rely on it for medical, legal, financial or other professional advice.
The AI Transparency Notice (07-ai-transparency.md) lists every AI feature, its models and its limits.
6.3 Automated decisions
We do not make decisions with legal or similarly significant effects about you based solely on automated processing without human review.
We do use some automated processing, for example:
- security controls such as rate limits on repeated login attempts;
- Free-plan inactivity cleanup, which deletes an unused Free plan after 90 days, only after 2 notices that let you keep it;
- AI ticket classification in support, which only routes tickets and does not decide the outcome.
You can ask for a human to review any automated decision that affects you, give your point of view, and contest it (LGPD art. 20; GDPR art. 22; UK GDPR arts. 22A-22D). Where a product uses automated scoring or estimates (for example, valuations in the Real Estate CRM), its addendum explains the logic and the human-review path.
7. Who receives personal data
We do not sell personal data. We share it only with the recipients below, and only as needed.
Subprocessors and service providers. They process data on our behalf, under written contracts with confidentiality, security and no-training terms. The complete, current list is in Subprocessors and International Transfers (04-subprocessors.md). For the activities in this Policy, the main ones are:
Provider Purpose Location Hetzner Online GmbH Hosting, storage, backups Finland (EU) Stripe, Inc. / Stripe Payments Europe Ltd. Payments and subscriptions US / Ireland OpenAI, L.L.C. (SonhoLab API account) AI for the website chat and the support desk only US Meta Platforms (WhatsApp Business Platform) WhatsApp channel for our assistant US / Ireland Google LLC (Google Analytics 4) Website analytics, only with consent US Our email runs on our own mail server on the same Hetzner infrastructure in Finland.
- Independent controllers. Some companies receive data to provide their own service to you under their own privacy terms: Google Play and the Apple App Store (app purchases), Roblox Corporation (Casa Embrujada), payment card networks, and your own WhatsApp provider.
- Your organization. If you are a User of an Organization Account, its administrators can see your name, email, role and access history within that account.
- Professional advisers. Accountants, lawyers and auditors, under a duty of confidentiality, when needed.
- Authorities. Courts, regulators and law enforcement, when the law or a valid order requires it. Government and Law Enforcement Requests (12-law-enforcement.md) explains how we review and respond.
- A successor business. If SonhoLab's business is transferred, merged or reorganized, personal data may pass to the successor, which must honor this Policy. We will give you any notice the law requires.
We give Customers 30 days' notice before adding or replacing a subprocessor that processes Customer Data, as set out in the DPA.
8. International transfers
Where your data is stored. Our Systems and websites are hosted by Hetzner Online GmbH in Helsinki, Finland (EU), with Hetzner's automated server backups in Finland. An off-site backup copy is encrypted before it leaves the server and is stored on equipment operated by SonhoLab in Brazil.
Access from Brazil. SonhoLab is based in Brazil, and our personnel access the servers from Brazil. Hades, which is not offered to the public, has its own locations and providers, described in its Addendum.
Transfers to service providers. Some providers are in the United States (section 7).
We protect each transfer as follows:
| Transfer | Safeguard |
|---|---|
| EEA → Brazil (SonhoLab, including the encrypted off-site backup copy) | EU adequacy decision for Brazil, Commission Implementing Decision (EU) 2026/179 (GDPR art. 45) |
| Brazil → EEA (Hetzner, Finland) | ANPD adequacy recognition of the EU, Resolução CD/ANPD nº 32/2026 (LGPD art. 33 I) |
| EEA → United States | EU Standard Contractual Clauses 2021 (Commission Decision (EU) 2021/914), Module 2 or 3; plus the EU-US Data Privacy Framework where the provider is certified (GDPR arts. 45-46) |
| UK → Brazil or United States | UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; plus the UK Extension to the EU-US Data Privacy Framework where the provider is certified |
| Brazil → United States | ANPD standard contractual clauses, adopted in full and without changes (Resolução CD/ANPD nº 19/2024, LGPD art. 33 II b) |
| Other countries | The safeguards the local law requires, as set out in the Latin America Supplement (R-latam.md) |
Copies of the clauses. You can ask for a copy of the safeguards that apply to your data at contacto@sonholab.com. We send the text within 15 days. We may remove commercial terms that are not about data protection.
Portuguese transfer page. As required by Resolução CD/ANPD nº 19/2024 art. 17, we publish a page in Portuguese that describes our international transfers: the Portuguese version of Subprocessors and International Transfers (04-subprocessors.md), in our Legal Center.
Subprocessors and International Transfers (04-subprocessors.md) shows the country and safeguard for each provider.
9. Security
We protect personal data with technical and organizational measures suited to the risk. They include:
- encryption in transit (TLS) for our websites, Systems and apps;
- encryption of off-site backups before they leave the server;
- restricted access: only named SonhoLab personnel can access production systems. Access to production servers requires personal SSH keys; password login is disabled. Administrative web panels use single-use sign-in links sent to named SonhoLab email addresses;
- separation between organizations: every query to a System is scoped to the organization that owns the data. Database row-level security is being rolled out product by product;
- rate limiting on sign-in, sign-up, password reset and other public endpoints;
- access logs kept for 6 months;
- secrets kept outside source code;
- incident response procedures, including response to malware;
- an annual review of these measures.
We hold no security certifications (such as SOC 2 or ISO 27001). No system is completely secure, and we do not promise that it is.
If an incident affects your data, we will notify you and the competent authorities as the law requires. For data we control, we notify the ANPD and affected people within 3 business days (Resolução CD/ANPD nº 15/2024), EEA and UK authorities within 72 hours where required, and US residents within the periods set by state law. For Customer Data, we notify the Customer without undue delay, with a target of 48 hours and at most 72 hours after we confirm the incident. We keep a register of incidents for 5 years.
Security and Incident Response (08-security-and-incidents.md) has the details.
10. How long we keep data
We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires. Then we delete or anonymize it. Main periods:
| Data | Retention |
|---|---|
| Account & organization data | life of account + 30 days after cancellation, then deleted |
| Free plan inactive | purged after 90 days of inactivity, with 2 prior notices |
| Access/application logs | 6 months (Marco Civil art. 15), up to 12 months for security investigations |
| Billing, invoices, tax | 5 years (Brazil tax law) or longer if required |
| Consent and legal-acceptance records | 5 years after the relationship ends |
| Privacy requests & responses | 24 months |
| Marketing leads / waitlist | until unsubscribe or 24 months without interaction |
| Support tickets | 24 months after closure |
Backups. Database backups are kept up to 14 days on the server and up to 14 days in the encrypted off-site copy. Data you delete disappears from backups as they expire, within 30 days at most.
The Data Retention Schedule (10-retention-schedule.md) covers every category, including Hades, Customer Data, legal holds and anonymization.
11. Your rights
Depending on where you live, you have rights over your personal data. In summary:
| Region | Main rights | Our response time |
|---|---|---|
| Brazil (LGPD art. 18) | Confirmation that we process your data; access; correction; anonymization, blocking or deletion of unnecessary or unlawful data; portability; deletion of data processed with consent; information about who we share with; information about refusing consent; revoking consent; objection; review of automated decisions (art. 20); petition to the ANPD | 15 days for a complete answer (LGPD art. 19 II) |
| EEA and UK (GDPR arts. 15-22) | Access; rectification; erasure; restriction; portability; objection (including to direct marketing at any time); not being subject to solely automated decisions with significant effects; withdrawing consent; complaint to a supervisory authority | 1 month, extendable by 2 months for complex requests |
| United States (state privacy laws) | Know and access; delete; correct; portability; opt out of sale, sharing, targeted advertising and significant profiling; limit use of sensitive data; appeal a refusal; no discrimination for using your rights | 45 days, extendable by 45 days |
| Latin America | Access, rectification, cancellation and objection (ARCO) and the other rights of your local law | As your local law requires |
How to use them.
- Use the tools in your account. Export is always available on every plan.
- Or write to contacto@sonholab.com, saying what you want.
Exercising your rights is free. We may need to verify your identity. You may use an authorized agent where the law allows it. If we refuse a request, we explain why and how to appeal or complain.
Your Privacy Rights and How to Exercise Them (09-data-rights-requests.md) gives the full process, including identity checks, agents, appeals, the UK complaints procedure, requests about deceased persons, and requests about Customer Data.
Withdrawing consent. Where we rely on consent, you can withdraw it at any time, as easily as you gave it. Withdrawal does not affect processing that happened before.
12. United States: state privacy disclosures
This section applies to residents of US states with comprehensive privacy laws, including California (CCPA as amended by the CPRA), Colorado, Connecticut, Virginia, Texas, Oregon and the other states listed in the United States Supplement (R-us-states.md). We apply these commitments to all US residents, whether or not a particular state law applies to us.
12.1 Notice at collection: categories of personal information
In the last 12 months we have collected the following categories. We collect them from the sources and for the purposes described in section 3. Retention is set out in section 10 and the Data Retention Schedule.
| Category (Cal. Civ. Code §1798.140) | Examples | Disclosed for a business purpose to | Sold or shared? |
|---|---|---|---|
| Identifiers | Name, email, phone, IP address, account ID, online identifiers | Hosting, payment, AI, messaging and analytics providers | No |
| Customer records (Cal. Civ. Code §1798.80(e)) | Name, address, phone, partial card data, tax ID | Hosting and payment providers | No |
| Protected classifications | Age confirmation; for Hades, date of birth, gender and nationality if you provide them | Hosting provider | No |
| Commercial information | Plans, purchases, products of interest | Hosting and payment providers | No |
| Internet or other electronic network activity | Logs, pages viewed (with consent), interactions with our Systems | Hosting and analytics providers | No |
| Geolocation data | Approximate location from IP address only | Analytics provider (with consent) | No |
| Audio, electronic or visual information | Voice notes, screenshots; for Hades, voice recordings | Hosting and AI providers | No |
| Professional information | Company, role | Hosting and AI providers | No |
| Sensitive personal information | Account login credentials; identity document / tax ID (paid plans only); for Hades, voiceprints (biometric) | Hosting and AI providers, as described in section 4 | No |
We do not create inferences to build profiles about you.
12.2 Sensitive personal information
We use sensitive personal information only for purposes the law permits without an opt-out (for example, to provide the service you asked for, to secure accounts, and to prevent fraud; CCPA regulations §7027(m)). We do not use it to infer characteristics about you. For this reason we do not offer a "Limit the Use of My Sensitive Personal Information" link. Where a state law requires your opt-in consent before we process sensitive data (for example, biometric data in Hades), we ask for it first.
12.3 We do not sell or share
We do not sell personal information and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We do not sell or share the personal information of consumers under 16. We do not use personal information for targeted advertising.
12.4 Global Privacy Control and Do Not Track
We honor the Global Privacy Control (GPC) signal. When your browser sends it, we treat it as a request to opt out of any sale, sharing or targeted advertising for that browser, and we do not load marketing technologies.
Browsers also offer a "Do Not Track" setting. Because we do not track you across other companies' websites, and because we already honor GPC, Do Not Track does not change what we do.
12.5 Your US rights, appeals and agents
You may ask to know, access, delete, correct and port your personal information, and to opt out as described above. Where your state gives it, you may also ask for a list of the specific third parties we disclosed your data to. If we refuse your request, you may appeal, and if we deny the appeal, you may contact your state Attorney General. You may use an authorized agent. We will not discriminate against you for using your rights. Section 11 and Your Privacy Rights and How to Exercise Them (09-data-rights-requests.md) explain how.
12.6 Other US disclosures
- Financial incentives. We do not offer financial incentives in exchange for personal information.
- De-identified data. Where we de-identify data, we keep it in de-identified form and do not attempt to re-identify it, except to test our de-identification as the law allows.
- California "Shine the Light." We do not disclose personal information to third parties for their own direct marketing.
- Consumer health data. Some state laws, such as Washington's My Health My Data Act, protect consumer health data. Section 11 of the United States Supplement (R-us-states.md) is our consumer health data privacy policy, for Hades and other products that may process such data.
13. Cookies and similar technologies
We use:
- strictly necessary cookies and local storage, always, to run our websites and Systems (for example, to keep you logged in and to remember your cookie choice);
- preference cookies to remember settings such as language, where you allow them;
- analytics cookies (Google Analytics 4) only after you opt in, with Google Signals off;
- no marketing cookies, unless we add them in the future and you opt in.
Our banner offers "Accept all" and "Reject all" with equal prominence on the first screen, plus granular settings. You can change your choice at any time through the "Cookie settings" link on every page.
The Cookie Policy (05-cookie-policy.md) lists every cookie, its purpose and duration, and explains GPC and local storage in our apps.
14. Marketing communications and how to opt out
We send marketing only as described in section 3.2.9.
- Email. Every marketing email has an unsubscribe link. One click stops marketing email.
- WhatsApp and SMS. Reply "STOP" (or the opt-out word shown in the message) to stop. We do not send automated marketing messages to US phone numbers without prior express written consent.
- Any channel. Write to contacto@sonholab.com, or change your preferences in your account.
We stop within 10 business days at most, and in practice immediately. After you opt out, we keep only what we need to make sure we do not contact you again. You will still receive service and security messages while you have an account.
15. Consumer apps, free tools and product addenda
We are the controller for the consumer apps below. Each addendum explains the data in full.
| App or service | What it does, in short | Main data | Addendum |
|---|---|---|---|
| Hades (not currently offered to the public; invited testers only) | Memorials and companion AI, including voice features | Account data (email, name, date of birth, nationality, gender, photo, device ID); information the user provides about a deceased person; conversations; voice samples and voice models, only with the voice owner's explicit, separate consent, and revocable at any time; signals used for the crisis protocol | Hades Addendum: Voice, Biometrics, Memorials and Companion AI (P-voice-biometric-deceased.md) |
| SonhoLab Poker | Social poker with virtual chips that have no cash value | Email, display name, password hash, age confirmation (18+), chip balance, purchases, hand history | Games and Virtual Items Terms (P-social-games.md) |
| Casa Embrujada (Roblox) | Game experience on Roblox | Roblox user ID and username, game progress, public leaderboards, purchases made in Robux through Roblox | Games and Virtual Items Terms (P-social-games.md) |
| PDF Free | PDF scanner and tools for Android | Processed on your device. No account, no ads. Google Play services may download the scanner module | Free Tools and Content Services Terms (P-content-tools.md) |
| Free web tools | Browser tools on sonholab.com | See section 3.2.10 | Free Tools and Content Services Terms (P-content-tools.md) |
| ComexCalc (imports.sonholab.com) | Import-cost calculator | Calculations run in your browser; server access logs only | Free Tools and Content Services Terms (P-content-tools.md) |
| Job Portal (empleo.sonholab.com) | Job listings and applications | Account data, CVs and applications you submit | Recruiting and Job Portal Addendum (P-recruiting.md) |
Hades in brief. Hades is not currently offered to the public. Access is limited to invited testers, and these rules apply to them and to any future general release. Hades is only for adults. It tells you it is an AI at the start of every session and every 3 hours. It follows a published crisis protocol: if a conversation shows a risk of self-harm, it stops the roleplay and points to crisis lines. It does not simulate public figures, politicians or candidates. A voice can be cloned only with the explicit, separate consent of the voice owner. For a deceased person, the uploader must declare that they are a spouse, parent, child or heir, and that no one with equal standing objects. Any voice can be revoked. When the voice owner revokes it, it is removed for everyone, the user who created it and all other users, and deleted from all our systems automatically. The shared voice library is opt-in only and is not available to users in the United States. It is available to EEA users only where the voice owner gave explicit consent. Generated audio is labeled as AI-generated. We act on notices to take down a voice within 48 hours.
Product addenda for Systems. For our B2B Systems, the Customer is the controller of Customer Data (section 2.2). The following addenda set the extra rules we follow as processor: Children and Student Data Addendum (P-children-education.md), Health Data Addendum (P-health.md), AI Agents and Messaging Addendum (P-ai-agents-messaging.md), Location and Mobility Addendum (P-location-mobility.md), Debt Collection Addendum (P-debt-collection.md), Real Estate CRM and Valuation Addendum (P-real-estate-valuation.md), Workforce, Farm and Site Monitoring Addendum (P-workforce-farm.md), Developer and API Terms (P-developer-api.md) and Procurement Intelligence Addendum (P-procurement.md).
16. Changes to this Policy
We may update this Policy when our services, providers or the law change. Each change creates a new version with a date and a digital fingerprint, and past versions stay available in the Legal Center.
- For material changes, we notify account holders by email and show a notice on our websites at least 30 days before the change takes effect.
- If a change means we want to use your data for a new purpose that needs consent, we ask for your consent first. We do not apply such changes retroactively to data we already hold.
- Minor changes (for example, clearer wording or updated contact details) take effect when published.
17. Contact us, representatives and supervisory authorities
Privacy questions and requests Encarregado (data protection officer): Leandro Manuel Pérez Montañana Email: contacto@sonholab.com
Postal address L. M. PEREZ MONTANA (SonhoLab), Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil
EU representative: SonhoLab is appointing a representative in the European Union (Ireland). Until the appointment is published, EU residents can contact contacto@sonholab.com. UK representative: none; we do not currently direct our services to the United Kingdom (see section 1.3).
Complaints. We would like the chance to fix any concern first. You may also complain to a supervisory authority at any time:
| Where you are | Authority |
|---|---|
| Brazil | Agência Nacional de Proteção de Dados (ANPD), www.gov.br/anpd |
| EEA | The data protection authority of the member state where you live, work or where the issue happened. The European Data Protection Board lists them at edpb.europa.eu |
| United Kingdom | Information Commissioner's Office (ICO), ico.org.uk. You may first use our data protection complaints procedure, described in Your Privacy Rights and How to Exercise Them (09-data-rights-requests.md) |
| United States | Your state Attorney General. In California, also the California Privacy Protection Agency |
| Latin America | Your national authority, listed in the Latin America Supplement (R-latam.md) |
Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.