Ваши права на конфиденциальность и как их осуществить

    Предварительная версия на юридической проверке

    Версия 0.9.0

    Этот документ еще не переведен на русский язык. Он показан на английском; до появления перевода обязательную силу имеет английский текст.

    Table of contents

    1. Scope
    2. Your rights by region
    3. How to make a request
    4. Identity verification
    5. Authorized agents and representatives
    6. Response times
    7. Fees
    8. When we cannot fully meet a request
    9. Requests about Customer Data (SonhoLab as processor)
    10. Appeals (United States)
    11. Complaints procedure (United Kingdom) and other complaint routes
    12. Requests about a deceased person
    13. Records we keep of requests

    1. Scope

    This document explains how anyone can use their privacy rights with L. M. PEREZ MONTANA ("SonhoLab", "we", "us"). It supports our Privacy Policy (02-privacy-policy.md). Terms such as "System", "Customer", "Customer Data" and "Organization Account" have the meanings given in the Privacy Policy.

    It applies to personal data we control, such as account, billing, support, marketing and consumer-app data. For Customer Data that we process on behalf of a Customer, section 9 applies.

    2. Your rights by region

    The rights below come from the law of your place of residence. Where more than one law applies, you get the benefit of each.

    2.1 Brazil (LGPD)

    Under the Lei Geral de Proteção de Dados (Lei 13.709/2018), art. 18, you may ask for:

    1. confirmation that we process your personal data;
    2. access to your data;
    3. correction of incomplete, inaccurate or outdated data;
    4. anonymization, blocking or deletion of data that is unnecessary, excessive or processed unlawfully;
    5. portability of your data to another provider, on express request;
    6. deletion of data processed with your consent, except where the law allows us to keep it (LGPD art. 16);
    7. information about the public and private entities we share your data with;
    8. information about the option not to give consent, and what happens if you refuse;
    9. revocation of consent (LGPD art. 8 §5).

    You may also:

    • object to processing based on a legal basis other than consent, if it does not comply with the LGPD (art. 18 §2);
    • ask for a review of decisions taken solely by automated processing that affect your interests, and for information about the criteria used (art. 20);
    • petition the Agência Nacional de Proteção de Dados (ANPD) (art. 18 §1).

    The Brazil Supplement (R-br-lgpd.md) has more detail.

    2.2 European Economic Area (GDPR)

    Under the General Data Protection Regulation (EU) 2016/679 you may:

    RightGDPR article
    Get access to your data and information about how we use itArt. 15
    Have inaccurate data corrected and incomplete data completedArt. 16
    Have your data erased in the cases the law setsArt. 17
    Restrict processing while a dispute is checked, or in other cases the law setsArt. 18
    Have us tell recipients about a correction, erasure or restrictionArt. 19
    Receive data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where feasibleArt. 20
    Object to processing based on legitimate interest, for reasons related to your situation; and object to direct marketing at any time, with no reason neededArt. 21
    Not be subject to a decision based solely on automated processing with legal or similarly significant effects, and get human intervention, express your view and contest itArt. 22
    Withdraw consent at any time, without affecting earlier processingArt. 7(3)
    Lodge a complaint with a supervisory authorityArt. 77

    The EEA and UK Supplement (R-eu-uk.md) has more detail.

    2.3 United Kingdom (UK GDPR and Data Protection Act 2018)

    You have the same rights as in section 2.2 under the UK GDPR. In addition, as amended by the Data (Use and Access) Act 2025:

    • for access requests, we carry out reasonable and proportionate searches. If we need you to clarify your request, the response time pauses until you reply;
    • for automated decisions, you have the safeguards in UK GDPR arts. 22A-22D: information about the decision, the chance to make representations, human intervention and the right to contest it;
    • you may use our data protection complaints procedure (section 11.1) before or instead of going to the Information Commissioner's Office (ICO).

    2.4 United States (state privacy laws)

    If you live in a state with a comprehensive privacy law (for example, California, Colorado, Connecticut, Virginia, Texas or Oregon), you may:

    1. know and access the personal information we collected about you, including categories, sources, purposes and recipients;
    2. delete personal information we collected from you;
    3. correct inaccurate personal information;
    4. port your data in a portable, readily usable format;
    5. opt out of the sale or sharing of personal information, targeted advertising, and profiling in furtherance of decisions with legal or similarly significant effects. We do not sell, share or use personal information for these purposes, and we honor Global Privacy Control;
    6. limit the use of sensitive personal information. We use it only for purposes the law permits without this request;
    7. where your state gives this right (for example, Oregon and Minnesota), get a list of the specific third parties to which we disclosed your personal information;
    8. appeal our decision on your request (section 10);
    9. not be discriminated against for using any of these rights. We will not deny you service, charge a different price or give a lower quality of service because you used your rights.

    The United States Supplement (R-us-states.md) has state-specific details, including rights over consumer health data and biometric data.

    2.5 Latin America

    The Latin America Supplement (R-latam.md) has details for each country. In short:

    CountryMain rightsAuthority
    ChileAccess, rectification, deletion (supresión) and objection under Ley 19.628. From 1 December 2026, Ley 21.719 adds portability, blocking and rights about automated decisionsAgencia de Protección de Datos Personales (from 1 December 2026)
    PeruInformation, access, rectification, cancellation and objection (Ley 29733 and its Regulation, DS 016-2024-JUS)Autoridad Nacional de Protección de Datos Personales (Ministry of Justice)
    MexicoAccess, rectification, cancellation and objection (ARCO rights) and revocation of consent (Ley Federal de Protección de Datos Personales en Posesión de los Particulares, 2025)Secretaría Anticorrupción y Buen Gobierno
    ColombiaKnow, update and correct your data; ask for proof of your authorization; be informed of use; revoke authorization and ask for deletion; complain (Ley 1581 de 2012)Superintendencia de Industria y Comercio (SIC)
    ArgentinaAccess, rectification, updating and deletion (Ley 25.326)Agencia de Acceso a la Información Pública (AAIP)

    For other countries, we honor the rights your local law gives you.

    3. How to make a request

    3.1 Channels

    • Email: write to contacto@sonholab.com with the subject "Privacy request."
    • Your account: use the tools in your Organization Account or consumer app:

      • Export your data. Export is always available on every plan, including Free;
      • update your profile details in your account settings.
    • Post: L. M. PEREZ MONTANA (SonhoLab), attention: Encarregado, Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil.
    • UK complaints: our electronic complaint form (section 11.1).

    You do not need an account to make a request. We do not require you to create one.

    3.2 What to include

    To help us answer quickly, tell us:

    • your name and the email or phone number you use with us;
    • the product or website involved;
    • which right you want to use, and what data it concerns;
    • where you live (so we apply the right law);
    • if you act for someone else, proof that you may do so (section 5).

    If your request is unclear, we will ask you to clarify it.

    3.3 How we reply

    We reply by email, unless you ask for another channel. We give copies of data in a common electronic format. For portability, we use a structured, machine-readable format: CSV for in-app reports; JSON for complete exports. We send files over an encrypted connection.

    4. Identity verification

    We must make sure we give data only to the right person. We verify identity in proportion to the risk of the request.

    • Logged-in requests. If you make the request from your account, your login is usually enough.
    • Email requests. We check that the request comes from the email address linked to the data, or we send a confirmation code to that address or phone.
    • Higher-risk requests. For access to specific pieces of data, deletion, or requests about sensitive data (for example, Hades voice data), we may ask you to confirm additional details we already hold, such as recent activity or billing details.
    • No unnecessary documents. We ask for an official identity document only if we cannot verify you any other way. If we do, we use it only to verify you and delete it once the request is closed.
    • No extra use. We use information given for verification only to verify you and to keep a record of the request.

    If we cannot verify your identity, we tell you, explain why, and, where possible, handle the parts of your request that do not need verification (for example, opting out of marketing).

    5. Authorized agents and representatives

    You may ask someone to make a request for you.

    • United States. An authorized agent may submit a request with your signed written permission. We may also ask you to verify your identity directly with us, or to confirm that you gave permission. We do not need this if the agent holds a valid power of attorney under state law.
    • Brazil. A representative may act for you with a power of attorney (procuração).
    • EEA, UK and other countries. A representative may act for you as your local law allows, with proof of authority.
    • Minors and people under guardianship. A parent or legal guardian may make requests for a child or a person they represent, with proof of that status. For students of a school that uses Verita, requests go through the school (section 9).

    We deal with the agent, but we send data only to you or to a verified agent. We may refuse an agent's request if the agent cannot prove its authority.

    6. Response times

    We answer as soon as we can, and no later than:

    RegionDeadlineExtension
    BrazilConfirmation of processing and access in simplified form right away where our tools allow it (for example, the account export), or a complete answer within 15 days of receipt (LGPD art. 19 II)None
    EEA and UK1 month from receipt (GDPR art. 12(3))Up to 2 more months for complex or numerous requests. We tell you within the first month and explain why
    United States45 days from receiptUp to 45 more days when reasonably necessary. We tell you within the first 45 days and explain why
    Latin AmericaThe period your local law setsAs your local law allows

    For US requests to know or delete, we confirm receipt within 10 business days where state law requires it. In the UK, the response time pauses while we wait for any clarification we asked you for. The clock starts once we receive the request. Where we need to verify identity, we act as soon as verification is complete, within the same deadline.

    7. Fees

    Using your rights is free. We do not charge for access, copies, correction, deletion, portability, objection or appeals.

    If a request is manifestly unfounded or excessive, for example, repeated identical requests with no reason, we may refuse it where the law allows. If we do, we explain why and tell you how to complain.

    8. When we cannot fully meet a request

    Sometimes the law allows or requires us to refuse all or part of a request. For example:

    • we must keep some data by law, such as tax records for 5 years or access logs for 6 months (Marco Civil da Internet art. 15);
    • we need the data to establish, exercise or defend legal claims;
    • giving the data would reveal personal data of other people or trade secrets;
    • we cannot verify your identity;
    • deleted data still exists in backups. It will disappear when the backups expire, within 30 days, and we will not restore it for any other use.

    When we refuse, we tell you which part we refused, why, and how to appeal or complain. When we delete data we must partly keep, we restrict it to the purpose that requires us to keep it.

    9. Requests about Customer Data (SonhoLab as processor)

    When a Customer (for example, a school, clinic, lender or business) uses a System, the Customer is the controller of the data in it. We act only on its instructions.

    If you send us a request about Customer Data:

    1. we tell you that we act as processor, and name the organization if we can identify it;
    2. we forward your request to the Customer within 2 business days, so it can meet its legal deadline;
    3. we help the Customer answer, for example by exporting, correcting or deleting data on its instructions, as set out in the Data Processing Addendum (DPA) (03-data-processing-addendum.md);
    4. we do not answer the substance of your request ourselves, unless the Customer instructs us to or the law requires it.

    We forward only what the Customer needs to handle your request. If you are a student, patient, debtor or end customer of a business, you will usually get the fastest answer by contacting that organization directly.

    10. Appeals (United States)

    If we refuse all or part of your request, you may appeal.

    • How: reply to our decision, or write to contacto@sonholab.com with the subject "Privacy appeal," within 60 days after our decision.
    • Who decides: the Encarregado (data protection officer) reviews the appeal and the original decision.
    • When: we decide within the period your state law sets.
    • Outcome: we tell you in writing what we decided and why.
    • If we deny the appeal, we tell you how to contact your state Attorney General to submit a complaint.

    11. Complaints procedure (United Kingdom) and other complaint routes

    11.1 UK data protection complaints procedure

    If you are in the UK, you may complain to us about how we use your personal data, as provided by section 164A of the Data Protection Act 2018.

    • How to complain: write to contacto@sonholab.com, with the subject "Privacy request".
    • Acknowledgement: we acknowledge your complaint within 30 days of receiving it.
    • Investigation: we investigate without undue delay and take appropriate steps to respond, including making enquiries.
    • Updates: we keep you informed of progress.
    • Outcome: we tell you the outcome without undue delay.
    • Your right to go to the ICO: you may also complain to the Information Commissioner's Office (ico.org.uk) at any time. The ICO usually expects you to raise the complaint with us first.

    11.2 Other complaint routes

    We would like the chance to fix any concern first. You may complain at any time to:

    Where you areAuthority
    BrazilAgência Nacional de Proteção de Dados (ANPD), www.gov.br/anpd
    EEAThe data protection authority where you live, work or where the issue happened. List at edpb.europa.eu. SonhoLab is appointing a representative in the European Union (Ireland); until the appointment is published, you can contact contacto@sonholab.com
    United KingdomInformation Commissioner's Office (ICO), ico.org.uk
    United StatesYour state Attorney General. In California, also the California Privacy Protection Agency
    Chile, Peru, Mexico, Colombia, ArgentinaThe authority listed in section 2.5

    Filing a complaint does not affect your other legal remedies.

    12. Requests about a deceased person

    • Brazil. The ANPD's position (Nota Técnica nº 3/2023/CGF/ANPD) is that the LGPD does not apply to the data of deceased persons. Their personality rights are protected by the Código Civil: under art. 12, sole paragraph, the spouse or any relative in the direct line or collateral up to the fourth degree may act; under art. 20, sole paragraph, the spouse, ascendants and descendants may protect the deceased person's image, voice and words.
    • EEA. The GDPR does not apply to deceased persons (Recital 27), but some countries give rights to heirs or to people the deceased designated, for example France (Loi Informatique et Libertés, art. 85), Italy (Codice privacy, art. 2-terdecies) and Spain (LOPDGDD, art. 3).
    • Everywhere. Data about living people that appears alongside a deceased person's data (for example, a relative's voice in a recording) is fully protected.

    12.2 How to make a request

    A spouse, parent, child, heir, estate representative, or other person with standing under the applicable law may ask us to access, correct or delete a deceased person's data, or to close their account. Please send to contacto@sonholab.com:

    • the deceased person's name and the email or account they used, if known;
    • proof of death, such as a death certificate;
    • proof of your standing, such as a document showing your relationship, a will, or a court or estate document;
    • what you want us to do.

    We handle the request under the law that applies and respect any wishes the deceased person left, where the law requires it. We may refuse where another person with equal standing objects, until the matter is resolved.

    12.3 Hades

    Hades lets users create memorials and, with the required consents, synthetic voices of deceased persons. Hades is not currently offered to the public; access is limited to invited testers. Family members and heirs may ask us to remove a memorial or a voice. We act on notices to take down a voice within 48 hours. Any voice can be revoked. When the voice owner (or, for a deceased person, a person with standing) revokes it, the voice is removed for everyone, the user who created it and all other users, and deleted from all our systems automatically. The Hades Addendum: Voice, Biometrics, Memorials and Companion AI (P-voice-biometric-deceased.md) explains the rules on standing, objections and takedown.

    13. Records we keep of requests

    We keep a record of each request, our verification steps and our response for 24 months, to show that we handled it correctly and to answer any complaint. We use these records only for that purpose. Where US state law requires it, we compile statistics about the requests we receive.


    Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.

    Предварительная версия на юридической проверке

    Версия 0.9.0

    Отпечаток SHA-256 этого текста: 4c8266ca208ee0be709489e319ca04e8724a1d1a95258e3e0379a4724f621734

    Вернуться в Правовой центр