Data Processing Agreement (DPA) — Anna · imanna.ai
This Data Processing Agreement ("DPA") forms part of the services agreement between the parties and governs the processing of personal data carried out by INFINITESUM on behalf of the Client, under Law No. 13.709/2018 (Brazilian LGPD).
0. When this DPA applies and how it is accepted
This DPA applies whenever the Client uses the Service to process third parties' personal data, in particular when activating:
- the Customer Assistant Module — Anna processes the Client's end customers' data;
- the Scheduling Module — Anna processes contacts and invitees designated by the Client;
- Anna Web, where the Client's project files contain third parties' personal data.
Acceptance of this DPA is required when activating the corresponding Module, with a record of date, time, and version.
1. Parties
CONTROLLER (Client): [company name], company registration [no.], with its office at [address].
PROCESSOR: INFINITESUM LTDA, CNPJ 65.498.658/0001-10, at Av. Conselheiro Aguiar, 4200, Loja 0007,
Edf. Vitrine, Boa Viagem, Recife/PE, Brazil.
Processor's DPO: Lucas Wanderley de Arruda — channel support@imanna.ai
2. Definitions
"Personal data," "data subject," "processing," "controller," "processor," "data protection officer," "incident," and "ANPD" have the meaning given by the LGPD. "Instructions" are the Controller's documented directions, including the settings it defines within the Service.
3. Subject matter and roles
The Controller determines the purposes and essential means; the Processor processes personal data solely according to the Controller's Instructions and this DPA, except where required by law. The subject matter, nature, purpose, duration, and categories are described in Annex I.
Outside this DPA's scope, INFINITESUM acts as controller of the Client's own account, billing, usage, and access-log data, as described in the Privacy Policy.
4. Processor obligations (Art. 39, LGPD)
- Process data only per documented Instructions and agreed purposes.
- Ensure confidentiality, including by staff and contractors, under confidentiality commitments.
- Adopt the security measures in Annex II, appropriate to the risk.
- Assist the Controller with data-subject requests and compliance with Articles 18, 48, and 49.
- Keep a record of processing operations performed on the Controller's behalf.
- Not use the data for its own purposes other than providing the Service.
- Not use the Controller's data to train, improve, or personalize generalized AI models.
5. Controller obligations
The Controller represents and warrants that it:
- has a legal basis for the processing it instructs, including for third-party data it provides (contacts, invitees, end customers);
- informs its data subjects as required, including — when activating the Customer Assistant — that support is provided by artificial intelligence, with a path to human support;
- complies with the policies of any messaging platform it connects, including the prior opt-in required by the WhatsApp Business policy;
- does not instruct the processing of sensitive personal data or data of children and adolescents through the Service, which is not intended for those purposes.
6. Sub-processors
The Controller authorizes the Processor to engage sub-processors. The Processor imposes on them obligations equivalent to this DPA and remains responsible to the Controller for their performance.
Sub-processors as of this publication:
| sub-processor | purpose | location |
|---|---|---|
| Anthropic | AI model provider | abroad |
| OpenAI | AI model provider | abroad |
| authentication and, when enabled, calendar | abroad | |
| Meta | when enabled, messaging and advertising | abroad |
| Tripo | 3D generation, on the user's own account (BYOK) | abroad |
| infrastructure and cloud providers | hosting, storage, and logs | abroad and/or Brazil |
| payment institutions and gateways | transaction processing | abroad and/or Brazil |
| support tools | customer service to the Controller | abroad and/or Brazil |
This list is kept up to date in this DPA. Material changes will be communicated with reasonable advance notice, allowing a reasoned objection.
7. International transfers
Some sub-processors are located abroad. Transfers comply with Article 33 of the LGPD, with appropriate safeguards such as specific contractual clauses. The Controller acknowledges and authorizes such transfers, which are necessary to provide the Service.
8. Security incidents
The Processor will notify the Controller without undue delay after becoming aware of any incident involving data processed on its behalf, providing reasonably available information so the Controller can meet its duties toward the ANPD and data subjects (Art. 48, LGPD).
9. Data-subject rights
The Processor will forward to the Controller, without delay, any data-subject requests it receives, and will provide reasonable technical assistance to respond within the legal timeframe. The Service provides export and deletion functions that address most such requests.
10. Audit
The Processor will make available reasonable information to demonstrate compliance and will allow audits, with prior notice, at reasonable frequency, subject to confidentiality and security, which may be satisfied through reports or certifications.
11. Termination, return, and deletion
Upon termination, the Processor will, per the Controller's instruction, return or delete the personal data processed on its behalf, except for a legal retention obligation, in which case it will maintain confidentiality.
Note — Anna Web: project files are stored on the Processor's cloud. The Controller must export them before termination, as deletion is permanent. Grace period: 7 days after termination.
12. Liability
Follows Articles 42 to 45 of the LGPD. The Processor is jointly liable only in the legal cases where it fails to comply with statutory obligations or does not follow the Controller's lawful Instructions.
13. Term
This DPA remains in force for as long as the Processor processes personal data on the Controller's behalf and, as to data protection, prevails over conflicting provisions of the main agreement.
14. Annex I — Description of processing
| item | description |
|---|---|
| Subject matter | Processing necessary to provide the Anna Service to the Controller, in the Modules it activates. |
| Nature and purpose | Collection, storage, use, response generation, and sharing with sub-processors, per Instructions. |
| Categories of data subjects | (a) users and representatives designated by the Controller; (b) end customers interacting with the Customer Assistant; (c) contacts and invitees designated by the Controller in the Scheduling Module; (d) data subjects whose data appears in Anna Web project files. |
| Categories of data | Account, credentials, usage/billing data, access logs; customer-support conversation content and end customers' contact details; calendar events (titles, times, attendees) and invitees' contact details; project file content in Anna Web. No sensitive data. |
| Duration | For the term of the main agreement, plus legal retention periods. |
15. Annex II — Security measures
- Encryption of data in transit and at rest.
- Least-privilege access control, with access to Controller data restricted to what is strictly necessary to operate, support, or investigate an incident.
- Two-factor authentication available for all accounts, with activation recommended, and applied to the Processor's administrative access under its internal security policy.
- Operation logging and monitoring.
- Backups and an incident response plan, tested at least annually.
- Confidentiality commitments from staff and sub-processors.
16. Signatures
Recife/PE, Brazil, ____ / ____ / ______.
________________________________________ CONTROLLER (Client) — [company name] · registration [no.]
________________________________________ PROCESSOR — INFINITESUM LTDA · CNPJ 65.498.658/0001-10
Where acceptance occurs electronically upon Module activation, the record of date, time, version, and user identification replaces the physical signature, under the Brazilian Internet Framework Act.