Personal Data Processing Agreement (DPA)

                                                                                                                                 Personal Data Processing Agreement (DPA) – GOEVO Platform (SaaS)

This Personal Data Processing Agreement (“DPA”) establishes the rules applicable to the processing of personal data carried out within the scope of the GOEVO Platform, in accordance with Law No. 13.709/2018 (General Data Protection Law – LGPD), and is an integral part of the Service Provision Agreement – Software as a Service (SaaS) and the Contract Terms.      by reference.     

Information regarding the identification of personal data collected, legal bases, purposes, and the exercise of data subjects' rights is available in the Platform's Privacy Notice, which can be found electronically at [website address]. https://goevoscm.com.br/aviso-de-privacidade/ , an integral part of this DPA for all legal purposes.

  1. PROCESSING AND PROTECTION OF PERSONAL DATA

1.1.      The Parties are aware of and declare that they will faithfully comply with Law No. 13.709/2018 (General Data Protection Law), in accordance with its definitions and concepts, themselves, their partners, administrators, employees and agents, as well as require its compliance by third parties contracted by them.

1.2. In accordance with the activities established in this Instrument, GOEVO will have access to personal data of third parties related to the CONTRACTING PARTY's business. In these cases, GOEVO is the operator that processes personal data on behalf of the CONTRACTING PARTY, which controls this processing, following its instructions.

1.2.1. With regard to the CLIENT's data, and only with regard to this data, the CONTRACTOR is the data controller, processing it solely for the purpose of providing its services and fulfilling its legal obligations.

1.3. Thus, the Parties undertake to respect and act in accordance with the duties imposed on each of the data processing agents under Law No. 13.709/2018, being solely responsible for their actions, with the innocent Party having the right of recourse in cases of non-compliance and penalties, including judicial penalties and those applied by the National Data Protection Agency.

1.4. Once GOEVO has access to personal data, it undertakes to process it only for the specific purpose of fulfilling the service that is the subject of this Contract, and is prohibited from processing data that is incompatible with the controller's guidelines. 

1.5. The Parties agree to keep the data provided in a secure environment, observing the Information Security Guidance Guide published by the ANPD (Brazilian National Data Protection Authority) and the scale of the processing, through technical measures compatible with the use of best practices.

1.6. If GOEVO receives a request to exercise rights from data subjects, it must forward the request to the CONTRACTING PARTY within 2 (two) business days, starting from the date of receipt of the request, and the CONTRACTING PARTY will be responsible for directly responding to the data subject.

1.7. In the event of incidents, such as interceptions, sharing or leaks of personal data, the Party that verifies the incident has the duty to notify the other Party, in writing and within a maximum period of 2 (two) consecutive days, counted from the date of knowledge of the incident, so that all necessary security measures can be taken.

1.7.1. The Party that becomes aware of the incident must inform the other Party as soon as possible of at least the following information: (i) date and time of the incident; (ii) date and time of becoming aware of the incident; (iii) description of the incident, including the root cause, if identifiable; (iv) technical and security measures used to protect personal data, adopted before and after the incident, respecting trade and industrial secrets; (v) measures that have been or will be adopted to reverse or mitigate the effects of the incident on data subjects; (vi) the total number of data subjects whose data are processed in the processing activities affected by the incident, when identifiable, or an estimated number.

1.7.2. If requested, GOEVO shall assist the CONTRACTING PARTY in proving the regularity of the data processing operations carried out under this Contract, by producing reports and presenting the necessary records.

1.8. GOEVO may not share or use any data that is not essential to the service or that does not comply with these rules, without the express authorization of the CONTRACTING PARTY. 

1.9. GOEVO may contract independent and indispensable sub-operators to operationalize the service contracted by the CLIENT. These sub-operators may have access to the personal data of third parties related to the CLIENT's business only to enable the part of the GOEVO solution provided by them and following the same rules set forth herein. 

1.9.1. The CLIENT may request a report describing which sub-operators are used by GOEVO to provide the service contracted under this instrument. This report must be provided by GOEVO within 2 (two) business days of the request.

  1. DATA RETENTION AND DELETION

2.1. Personal data will be kept for the duration of the Contract.

2.2. After the termination of the Contract, GOEVO will delete or anonymize personal data, according to the instructions of the CONTRACTING PARTY and in compliance with applicable legal obligations, except for data whose maintenance is mandatory by law or regulation, data necessary for the regular exercise of rights in judicial, administrative or arbitration proceedings, such as access logs, which will be kept confidential in a controlled and secure environment, in accordance with Law No. 12.965/2014 and with the legal basis of art. 7, II, of Law No. 13.709/18, as well as backups and technical records for the period necessary for the security and integrity of the Platform.

  1. LIMITATION OF LIABILITY

3.1. GOEVO's responsibility regarding the processing of personal data will be subject to the limitations of liability stipulated in the SaaS Agreement and will not be extended by this DPA.

  1. EFFECTIVE DATE

4.1. This DPA will remain in effect as long as personal data is processed under this Agreement.

GOEVO – Technology applied to governance, with responsibility and transparency.