Pipefy is recognized by Gartner® for its no-code agent builder capabilities

Learn more

Last updated: August 10, 2026

Annex I – DATA PROTECTION (DPA)

This Annex I governs Data Protection within the Pipefy Solution, defining the obligations and responsibilities of the parties involved regarding the privacy and security of processed information, and detailing the practices and security measures adopted by Pipefy to ensure the integrity, confidentiality, and availability of data, in accordance with applicable laws and regulations. The provisions of this Annex supplement the Terms of Use and apply to all Customers whenever personal or sensitive data is processed within the Pipefy Solution.

1. Pipefy will act as processor of personal data, processing information in accordance with the documented and specific instructions provided by the Customer, the data controller. Pipefy is a controller only with respect to the personal data used to create the platform user, such as the customer’s name and email, for which the legal basis is performance of a contract, for the purpose of accessing the platform to use the product. Pipefy has no authority to determine the purposes or means of processing other personal data processed by the Parties.

      1.1. For purposes of this Annex, the following definitions apply:
      a) Configuration Data: Information automatically generated or collected by the platform or system, related to the configuration, customization, and parameterization of the contracted product or service. This data may be accessed by Pipefy solely for purposes of technical support, continuous improvement of the platform, and understanding product usage, always in accordance with applicable data protection and privacy rules.
      b) Data Entered in Cards: Data entered directly by the Customer or its representatives, including, but not limited to, personal or corporate information, strategic or sensitive content related to use of the platform. This data is owned and processed exclusively by the Customer. Pipefy’s access to Data Entered in Cards is expressly limited and will occur only when necessary for technical support or specific consulting requested by the Customer; with the Customer’s prior, express, and specific authorization detailing the purpose and scope of access; or in compliance with a legal or regulatory obligation, upon notice to the Customer.

      1.2 The Customer is responsible for ensuring that data entered in Cards complies with applicable law and for maintaining adequate security measures within its internal environment to prevent unauthorized access.

      1.3 As Controller of Personal Data, the Customer is responsible for responding to data subjects’ requests to exercise their rights, and Pipefy, as Processor, will assist, whenever necessary and requested by the Customer, in responding to data subject requests, such as requests for access to Personal Data, correction of incomplete, inaccurate, or outdated Personal Data, blocking or deletion of unnecessary or excessive Personal Data, portability of Personal Data, and other rights provided for under applicable law, the granting of which will be at the Customer’s sole discretion.

      2. Pipefy is solely responsible for all costs incurred in responding to data subject requests where Pipefy is considered the Controller, and the Customer is solely responsible for responding to data subject requests where the Customer is considered the Controller, including the costs incurred in doing so.

        3. Commitments of the Parties. The Parties undertake and warrant that, each within the scope of its activities:
        A. Both Parties comply with all laws, rules, and regulations applicable to the Personal Data processed in connection with the performance of their obligations, including, but not limited to, Law No. 13,709/18 (Brazilian General Data Protection Law — “LGPD”) where data subjects reside in Brazil, and/or Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR) where data subjects reside in the European Union, and/or the California Consumer Privacy Act (CCPA) where data subjects reside in California, USA.
        B. Pipefy uses the personal data received in connection with this relationship solely for the purpose agreed between the Parties, and may not, under any circumstances, use such Personal Data for a different purpose, under penalty of immediate termination and full assumption of any damages caused to the other Party and/or third parties.
        C. Pipefy does not store or share personal data with third parties, except with the other Party’s prior express authorization, i.e., as required to comply with these Terms and this Annex.
        D. Both Parties treat all non-public Personal Data as confidential, even if this legal relationship is terminated, regardless of the reason for its termination.
        E. The duration of Processing must respect the contractual purpose, as well as the provisions of applicable law.
        F. Pipefy adopts appropriate mechanisms for the processing of Personal Data in accordance with legal requirements, in order to avoid loss, destruction, theft, damage, alteration, manipulation, or interception and/or accidental disclosure.
        G. Both Parties will limit access to Personal Data arising from these Terms only to employees, agents, and/or representatives who need it to carry out the relevant task/activity, with each Party being responsible for the acts of its employees, agents, and/or representatives.
        H. It is the Customer’s sole responsibility, as controller, to ensure that all personal data included in or processed on the Pipefy platform has a valid legal basis for processing. This includes, but is not limited to, obtaining data subjects’ consent, where applicable, or complying with another legal basis set forth in Article 7 of the LGPD.
        I. The Customer will be fully responsible for any breach of the LGPD arising from its failure to ensure a legal basis for the processing of personal data, including, but not limited to, any administrative sanctions or compensation for damages to third parties.

        3.1. The Parties acknowledge that the Pipefy Solution was developed to meet general privacy and data protection requirements, as applicable. The Customer represents that it is aware that the Pipefy Solution was not specifically designed, architected, or certified for the processing of sensitive personal data (as defined in the LGPD, GDPR, or equivalent laws) or highly regulated financial data (such as banking data or payment card credentials subject to PCI-DSS). The Customer is responsible for assessing the Solution’s suitability for the specific legal and regulatory requirements of its industry. Pipefy does not warrant compliance with any industry-specific standards that may apply to the Customer, and the Customer is solely responsible for ensuring that its use of the Solution complies with such standards.

        4. Vulnerability Management. The Parties undertake to manage vulnerabilities in their tools used to process personal data, performing periodic testing to identify and promptly remediate any vulnerabilities identified.

        5. Purpose of Storage. Pipefy undertakes to store Personal Data only for the periods necessary to: (i) achieve the purpose of processing Personal Data under these Terms; (ii) process payments; (iii) prevent or address technical issues; (iv) when possible, in anonymized form, to improve and enhance the Pipefy Solution; (v) as expressly authorized by the Customer, including cases of sharing Customer Data with Non-Pipefy Applications; and (vi) comply with legal and/or regulatory requirements.

        6. Log Retention. Pipefy will record “logs” of changes to and processing of personal data for which it is controller, retaining in such records the minimum elements needed to determine the activity, who performed it, and when, as required by law, with the Customer being responsible for managing data changes for which Pipefy acts solely as processor.

        7. Retention and Deletion of Personal Data. For as long as the Terms between the parties remain in effect, Customer data will be stored in Pipefy’s database on servers located in the United States, even if such data has been deleted through the application or through a set of routines and programming standards for accessing a web-based software application or platform (“API”). In the event of contract termination, regardless of cause, Pipefy reserves the right to delete the Customer’s Personal Data in accordance with the Customer’s written instructions, or, at the latest, within 180 (one hundred eighty) days, permanently, following termination of these Terms.

        8. Sub-processing. Pipefy may engage specialized third parties to carry out Personal Data processing activities on its behalf, as sub-processors (“Sub-Processors”), the updated list of which will be available on a specific page maintained by Pipefy (https://www.pipefy.com/pt-br/subprocessadores).

          8.1. General Authorization. The Customer grants Pipefy general and prior authorization to engage and replace Sub-Processors, provided the procedures set forth in this Clause are observed.

          8.2. Commitment to Prior Notice. Pipefy undertakes to actively notify the Customer prior to the addition of any Sub-Processor.

          8.3. Content of the Notice. The notice must contain, as applicable: (i) identification of the new Sub-Processor; (ii) a general description of the services or processing activities to be performed; (iii) the country or region where the Personal Data will be processed, when relevant; and (iv) the expected start date for use of the Sub-Processor.

          8.4. Communication Channel. The notice provided for in this Clause may be sent by electronic communication to the email address registered by the Customer as Account Administrator (Admin or Super Admin) and/or by a prominent notice on the Pipefy platform. It is the Customer’s responsibility to keep its contact information up to date and to monitor communications sent through the referenced channels.

          8.5. Objection Period and Criteria. The Customer may submit a formal, substantiated written objection within 15 (fifteen) calendar days from the date the notice was sent. The objection must be sent to [email protected] and based exclusively on legitimate, objective, and reasonably demonstrable grounds related to: (i) the proposed Sub-Processor’s non-compliance with applicable data protection law; (ii) relevant and documented information security risks; or (iii) the Sub-Processor’s inability to meet the legal or contractual requirements applicable to the processing of Personal Data.

          8.6. Handling of Objections. Upon receipt of an objection under Clause 8.5, the Parties will use reasonable efforts to discuss in good faith a solution that allows continuity of the services in compliance with applicable law. While the objection is under review, Pipefy may suspend use of the proposed Sub-Processor with respect to the Customer’s Personal Data, when operationally feasible.

          8.7. Absence of Resolution. If the Parties fail to reach a reasonable solution within 30 (thirty) calendar days of receipt of the objection, Pipefy may, at its discretion: (i) discontinue use of the proposed Sub-Processor with respect to the Customer’s Personal Data; (ii) adopt an alternative measure that eliminates the cause of the objection; or (iii) adopt any other measure reasonably necessary to address the Customer’s objection and maintain compliance with applicable law.

          8.8. Tacit Acceptance. The absence of an objection by the Customer within the period set forth in Clause 8.5 will be deemed acceptance of the addition or replacement of the Sub-Processor for all purposes under this Agreement.

          8.9. Responsibility for Sub-Processors. Pipefy is obligated to ensure that Sub-Processors commit to guaranteeing a level of security equal to or higher than that described in this Section before transferring any Personal Data or authorizing any sub-processing. Pipefy will be fully and jointly liable for any non-compliance, breach, irregularity, or unlawful act committed by its Sub-Processors.

          9. International Data Transfer. Pipefy adopts the standard contractual clauses for international data transfer, prepared and approved by the National Data Protection Authority (“ANPD”), as set out in Appendix 1, which ensure adequate safeguards for compliance with the principles, data subject rights, and data protection regime provided for in the LGPD.

          10. Grounds for Disclosure. Pipefy will not disclose Personal Data to third parties, at any time, except in the following cases: (i) with the Customer’s prior written authorization; (ii) in accordance with the sub-processing rules described above; (iii) as required by applicable data protection law, provided Pipefy uses reasonable efforts to share only the minimum amount of Personal Data necessary for a specific purpose, with the Customer being notified in advance, as set forth in these Terms.

          11. Requests from Authorities. If Pipefy is the recipient of any judicial order and/or official request or communication requiring the provision or disclosure of personal information, unless expressly prohibited by law, regulation, or judicial or administrative order, it must notify the Customer, within a maximum of 36 business hours, of the occurrence, providing an opportunity, in a timely manner, to take legal measures to prevent or mitigate the effects of the disclosure of the Personal Data related to or covered by such request.

          12. Third-Party Application. If the Customer installs, activates, and/or otherwise uses a Non-Pipefy Application together with the Pipefy Solution, the Customer is aware and agrees that the provider of such Non-Pipefy Application may access Customer Data, including Personal Data, as necessary for integration of such Non-Pipefy Application with the Pipefy Solution and/or in accordance with the activities of that Non-Pipefy Application. In this context, Pipefy is not responsible for any incident, disclosure, modification, or deletion of Customer Data and Personal Data resulting from access by a Non-Pipefy Application.

          13. Pipefy’s Obligations. Pipefy warrants and guarantees:
          A. confidentiality and integrity of information shared by the Customer;
          B. non-violation of privacy and protection of Personal Data in its relationship with Customers, suppliers, researchers, consumers, and employees;
          C. adoption of technical and administrative information security measures to prevent misuse and unauthorized use of Personal Data;
          D. immediate and adequate response to all Customer requests regarding the Processing of Personal Data, as well as consideration of guidance from the National Data Protection Agency regarding the Processing of transferred Personal Data;
          E. maintenance of written records of activities relating to compliance with applicable data privacy law;
          F. restriction of access to Personal Data by defining authorized and responsible individuals for Processing, and ensuring and accounting for the trustworthiness of its employees, agents, and representatives who will have access to Personal Data, taking into account the nature of such Personal Data;
          G. maintenance of a detailed inventory of access to Personal Data and connection and application-access logs, containing the time, duration, identity of the employee or person responsible for the access, and the file accessed, including when such access is made to comply with legal obligations or determinations by a competent authority;
          H. that the processing of Personal Data — i.e., any operation or set of operations performed on the Personal Data of its Customers, suppliers, and employees, including, but not limited to, obtaining, recording, storing, altering, analyzing, using, transmitting, combining, blocking, deleting, or destroying — is fully consistent with data subjects’ rights and will be carried out in accordance with the established purpose;
          I. protection of the Personal Data of its Customers, suppliers, and employees, guaranteeing them, subject to legal limits, the right to be informed of any processing of their data, as well as to access their own data, among other rights provided for under applicable law;
          J. recording of activities involving international transfer of Personal Data, indicating the destination country/organization and adopting the safeguards necessary for the transfer to be carried out in accordance with applicable law and guidance from the competent authority;
          K. responding to information requests made by the Customer within up to 36 business hours, justifying any delays; and
          L. cooperating in responding to requests from the Customer’s data subjects (the Customer’s customers), using appropriate technical and organizational measures, in accordance with the Customer’s instructions;
          M. making available evidence of its active certifications (such as ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, and ISO/IEC 42001) and independent audit reports (such as the SOC 2 Type II report), which will be provided subject to strict confidentiality, upon formal written request, and subject to a minimum interval of 1 (one) year. On-site audits or additional questionnaires will be subject to feasibility review, operational costs, and specific confidentiality agreements.

          14. Contingency Plan. Pipefy undertakes to establish contingency mechanisms to prevent data leaks, and to test and keep such mechanisms up to date, undertaking to present its Contingency Plan to the Customer upon request to respond to authority requests or in the event of legal claims.

          15. Incident Notice. If, at any time, there is an actual, suspected, or potential threat to the security of Personal Data, or suspicion of loss, destruction, deletion, damage, corruption, misuse, or unauthorized disclosure of Personal Data to an unauthorized third party, the Party that becomes aware of the incident must notify the other Party within a maximum of 48 (forty-eight) hours of becoming aware of the incident, and the notice must contain full and complete details of the breach, including:
          A. date and time of the incident;
          B. date and time the affected Party became aware of the breach;
          C. the types of data affected by the incident;
          D. the data subjects affected by the incident;
          E. the nature and facts of the breach, including the data subject, where possible;
          F. contact details of the person responsible for data protection or the representative appointed to handle the data breach at the company, responsible for providing additional information about the incident;
          G. the likely and/or potential consequences of the incident; and
          H. the measures taken or proposed by Pipefy or the person responsible for the protection of Personal Data to remedy the breach and mitigate any adverse effects, and the implementation dates for such measures (action plan).

          16. Incident Handling. In the event of a Security Incident involving Personal Data processed by Pipefy on the Customer’s behalf, Pipefy will use commercially reasonable efforts to promptly take appropriate measures to contain, mitigate, and remedy the effects of the incident, and, when technically feasible, to recover or restore the affected Personal Data. Pipefy will also provide reasonable assistance to the Customer, to the extent required by applicable law and considering the nature of the processing and the information available to Pipefy, to enable the Customer to respond to requests or investigations by competent authorities directly related to the incident and the Personal Data processed on the Customer’s behalf, without prejudice to Pipefy’s own legal obligations.

          17. Resilience. Backups are stored in the USA, where Pipefy’s entire multi-tenant infrastructure is hosted. In addition:
          a. Full database backups are performed once every 24 (twenty-four) hours, with continuous archiving of transaction logs, allowing point-in-time recovery for any moment within the retention period.
          b. Each database backup is retained for at least 7 (seven) days in the same region.
          c. The application source code is managed on GitLab SaaS (GitLab.com). The backup, retention, and recovery policy for the Git repositories follows GitLab.com’s official policy, which includes multi-region geographic redundancy and retention of up to 90 (ninety) days.
          d. Records: retained for up to 5 years. These logs cannot be restored. The Customer may open a ticket with Pipefy, which can help provide audit-log details of such backups.
          e. Any changes made on the Web (such as field deletions) can be safely restored via a support ticket within up to 180 (one hundred eighty) days of the occurrence.

            Contact information. Pipefy’s support for matters related to privacy and personal data protection will be directed to our Data Protection Officer, Cainã Gomez, through the Data Subject Request Form or via the email address [email protected] for matters not related to the exercise of data subject rights.


            APPENDIX 1 — INTERNATIONAL TRANSFER OF PERSONAL DATA

            This Appendix sets out the conditions under which Pipefy, Inc. (“Pipefy,” “Exporter,” or the “Processor”) undertakes to carry out, on behalf of the Customer (“Customer,” “Importer,” or the “Controller”), International Data Transfer operations in accordance with the provisions of National Legislation and the National Data Protection Authority (“ANPD”) set out below.

            Section I — General Information

            CLAUSE 1. Identification of the Parties

            1.1. By this contractual instrument, the Exporter and the Importer (hereinafter, the Parties), identified below, agree to adopt the standard contractual clauses (hereinafter, the Clauses) approved by the National Data Protection Authority (ANPD), to govern the International Data Transfer described in Clause 2, in accordance with the provisions of National Legislation.

            Name:

            Qualification:

            Main address:

            Email address:

            Contact for the Account Holder:

            () Exporter/Controller () Exporter/Operator

            Nome: Pipefy, Inc.

            Main address: City of San Francisco, California, at 548 Market Street, PMB 96462, United States of America.

            Email address: [email protected]

            Contact for the Data Subject: [email protected]

            ( ) Importer/Controller (x) Importer/Operator

            CLAUSE 2. Purpose

            2.1. These Clauses apply to International Data Transfers from the Exporter to the Importer, as described below.

            Description of the international data transfer:

            Main purposes of the transfer: Use of the Pipefy Solution, a cloud-based tool that allows the Client to automate and manage different types of processes through data manipulation, according to the Platform’s terms of use.

            Data storage period: 180 days after contract termination.

            Other information: Data processing will occur as regulated in the Pipefy Solution Terms of Use, its Annex I — Data Protection (“DPA”) and in the Pipefy Privacy Policy, available at https://www.pipefy.com/pt-br/politica-de-privacidade, which are integral and indispensable parts of this Annex.

            CLAUSE 3. Subsequent Transfers

            3.1. The Importer may not carry out a Subsequent Transfer of the Personal Data subject to the International Data Transfer governed by these Clauses, except as provided in item 18.3.

            CLAUSE 4. Responsibilities of the Parties

            4.1. Without prejudice to the duty of mutual assistance and the Parties’ general obligations, the Party Designated below, as Controller, will be responsible for compliance with the following obligations under these Clauses: a) responsible for publishing the document referred to in Clause 14: (x) Exporter ( ) Importer; b) responsible for responding to data subject requests under CLAUSE 15: (x) Exporter ( ) Importer; c) responsible for providing security-incident notice under Clause 16: (x) Exporter ( ) Importer.

            4.2. For purposes of these Clauses, if it is subsequently found that the Party Designated under item 4.1 acts as Processor, the Controller will remain responsible for: a) compliance with the obligations set forth in Clauses 14, 15, and 16 and other provisions established in National Legislation, especially in the event of omission or non-compliance by the Designated Party; b) responding to ANPD determinations; and c) guaranteeing data subjects’ rights and remedying damages caused, subject to Clause 17.

            Section II — Mandatory Clauses

            CLAUSE 5. Purpose.

            5.1. These Clauses serve as a mechanism to enable the secure international flow of personal data, establishing minimum guarantees and valid conditions for carrying out an International Data Transfer, and aim to ensure adequate safeguards for compliance with the principles, data subject rights, and data protection regime provided for in National Legislation.

            CLAUSE 6. Definitions.

            6.1. For purposes of these Clauses, the definitions in Article 5 of Law No. 13,709 of August 14, 2018, and Article 3 of the International Personal Data Transfer Regulation will apply, without prejudice to other regulatory acts issued by the ANPD. The Parties further agree to the following terms and their meanings:
            a) Processing Agents: the controller and the processor;
            b) ANPD: National Data Protection Authority;
            c) Clauses: the standard contractual clauses approved by the ANPD, comprising Sections I, II, and III;
            d) Related Agreement: a contractual instrument entered into between the Parties or at least between one of them and a third party, including a Third-Party Controller, sharing a common purpose, link, or dependency relationship with the agreement governing the International Data Transfer;
            e) Controller: the Party or third party (“Third-Party Controller”) responsible for decisions regarding the processing of Personal Data;
            f) Personal Data: information related to an identified or identifiable natural person;
            g) Sensitive Personal Data: personal data concerning racial or ethnic origin, religious belief, political opinion, union or religious, philosophical, or political organization membership, data concerning health or sex life, genetic or biometric data, when linked to a natural person;
            h) Deletion: exclusion of data or a set of data stored in a database, regardless of the procedure employed;
            i) Exporter: processing agent, located within the national territory or in a foreign country, that transfers personal data to an Importer;
            j) Importer: processing agent, located in a foreign country or that is an international organization, that receives personal data transferred by the Exporter;
            k) National Legislation: the set of Brazilian constitutional, statutory, and regulatory provisions on personal data protection, including Law No. 13,709 of August 14, 2018, the International Data Transfer Regulation, and other regulatory acts issued by the ANPD;
            l) Arbitration Law: Law No. 9,307 of September 23, 1996;
            m) Security Measures: technical and administrative measures adopted to protect personal data from unauthorized access and from accidental or unlawful destruction, loss, alteration, communication, or dissemination;
            n) Research Body: a direct or indirect public administration body or entity, or a nonprofit private legal entity duly established under Brazilian law, headquartered and domiciled in the country, whose institutional mission or corporate or statutory purpose includes basic or applied historical, scientific, technological, or statistical research;
            o) Processor: the Party or third party, including a Subcontractor, that processes Personal Data on behalf of the Controller;
            p) Designated Party: the party to the agreement designated, under Clause 4 (“Option A”), to fulfill, as Controller, specific obligations relating to transparency, data subject rights, and security incident notification;
            q) Parties: Exporter and Importer;
            r) Access Request: a request for mandatory compliance, by force of law, regulation, or determination by a public authority, to grant access to the Personal Data subject to the International Data Transfer governed by these Clauses;
            s) Subcontractor: a processing agent engaged by the Importer, with no relationship with the Exporter, to carry out Personal Data processing following an International Data Transfer;
            t) Third-Party Controller: the Controller of Personal Data that provides written instructions for carrying out, on its behalf, the International Data Transfer between Processors governed by these Clauses, under Clause 4 (“Option B”);
            u) Data Subject: the natural person to whom the Personal Data subject to the International Data Transfer governed by these Clauses relates;
            v) Transfer: the type of processing by which a processing agent transmits, shares, or provides access to Personal Data to another processing agent;
            w) International Data Transfer: transfer of Personal Data to a foreign country or to an international organization of which the country is a member; and
            x) Subsequent Transfer: an International Data Transfer originating from an Importer and directed to a third party, including a Subcontractor, provided it does not constitute an Access Request.

            CLAUSE 7. Applicable Law and ANPD Oversight.

            7.1. The International Data Transfer subject to these Clauses is subject to National Legislation and ANPD oversight, including the power to apply preventive measures and administrative sanctions to either Party, as applicable, and to limit, suspend, or prohibit international transfers arising from these Clauses or a Related Agreement.

            CLAUSE 8. Interpretation.

            8.1. Any application of these Clauses must occur in accordance with the following terms: a) these Clauses must always be interpreted in the manner most favorable to the Data Subject and in accordance with the provisions of National Legislation; b) in case of doubt as to the meaning of terms in these Clauses, the meaning most consistent with National Legislation applies; c) no item of these Clauses, including a Related Agreement and the provisions of Section IV, may be interpreted so as to limit or exclude either Party’s liability with respect to obligations set forth in National Legislation; and d) the provisions of Sections I and II prevail in the event of a conflict of interpretation with additional Clauses and other provisions set forth in Sections III and IV of this instrument or in Related Agreements.

            CLAUSE 9. Possibility of Accession by Third Parties.

            9.1. By mutual agreement between the Parties, a processing agent may accede to these Clauses as an Exporter or Importer, by completing and signing a written document, which will form part of this instrument.

            9.2. The acceding party will have the same rights and obligations as the original Parties, according to the position assumed as Exporter or Importer and in accordance with the corresponding category of processing agent.

            CLAUSE 10. General Obligations of the Parties.

            10.1. The Parties undertake to adopt, and when necessary, demonstrate the adoption of, effective measures capable of evidencing observance and compliance with these Clauses and National Legislation, including the effectiveness of such measures, and, in particular, to:
            a) use Personal Data only for the specific purposes described in Clause 2, without further processing incompatible with those purposes, subject in any case to the limitations, guarantees, and safeguards provided for in these Clauses;
            b) ensure that the processing is compatible with the purposes disclosed to the Data Subject, according to the context of the processing;
            c) limit processing to the minimum necessary to achieve its purposes, with a scope of data that is relevant, proportional, and not excessive in relation to the purposes of Personal Data processing;
            d) guarantee Data Subjects, subject to Clause 4:
            (d.1) clear, precise, and easily accessible information about the processing carried out and the respective processing agents, subject to trade and industrial secrets;
            (d.2) easy and free consultation regarding the manner and duration of the processing, as well as the entirety of their Personal Data; and
            (d.3) the accuracy, clarity, relevance, and updating of Personal Data, in accordance with the need for and purpose of its processing;
            e) adopt security measures appropriate to and compatible with the risks involved in the International Data Transfer governed by these Clauses;
            f) not process Personal Data for unlawful discriminatory or abusive purposes;
            g) ensure that any person acting under its authority, including subcontractors or any agent collaborating with it, whether free of charge or for consideration, processes data only in accordance with its instructions and these Clauses; and
            h) maintain records of Personal Data processing operations subject to the International Data Transfer governed by these Clauses, and present the relevant documentation to the ANPD upon request.

            CLAUSE 11. Sensitive Personal Data.

            11.1. If the International Data Transfer involves Sensitive Personal Data, the Parties will apply additional safeguards, including specific security measures proportional to the risks of the processing activity, the specific nature of the data, and the interests, rights, and guarantees to be protected, as described in Section III.

            CLAUSE 12. Personal Data of Children and Adolescents.

            12.1. If the International Data Transfer involves Personal Data of children and adolescents, the Parties will apply additional safeguards, including measures ensuring that processing is carried out in their best interest, in accordance with National Legislation and relevant international law instruments.

            CLAUSE 13. Lawful Use of Data.

            13.1. The Exporter warrants that the Personal Data was collected, processed, and transferred to the Importer in accordance with National Legislation.

            CLAUSE 14. Transparency.

            14.1. The Designated Party will publish, on its website, a document containing easily accessible information written in simple, clear, and precise language about the International Data Transfer, including, at minimum, information on:
            a) the manner, duration, and specific purpose of the international transfer;
            b) the destination country of the transferred data;
            c) identification and contact details of the Designated Party;
            d) shared use of data by the Parties and its purpose;
            e) the responsibilities of the agents that will carry out the processing;
            f) Data Subjects’ rights and the means to exercise them, including an easily accessible channel for requests and the right to petition against the Controller before the ANPD; and
            g) Subsequent Transfers, including recipients and the purpose of the transfer.

            14.2. The document referred to in item 14.1 may be made available on a specific page or integrated, prominently and accessibly, into the Privacy Policy or equivalent document.

            14.3. Upon request, the Parties must provide the Data Subject, free of charge, a copy of these Clauses, subject to trade and industrial secrets.

            14.4. All information made available to data subjects under these Clauses must be written in Portuguese.

            CLAUSE 15. Data Subject Rights.

            15.1. The Data Subject has the right to obtain from the Designated Party, with respect to the Personal Data subject to the International Data Transfer governed by these Clauses, at any time and upon request, in accordance with National Legislation:
            a) confirmation of the existence of processing;
            b) access to the data;
            c) correction of incomplete, inaccurate, or outdated data;
            d) anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in violation of these Clauses or National Legislation;
            e) portability of data to another service or product provider, upon express request, in accordance with ANPD regulations, subject to trade and industrial secrets;
            f) deletion of Personal Data processed with the Data Subject’s consent, except in the circumstances set out in Clause 20;
            g) information on public and private entities with which the Parties have shared data;
            h) information on the possibility of not providing consent and the consequences of refusal;
            i) revocation of consent through a free and simplified procedure, without affecting processing carried out prior to the request for deletion;
            j) review of decisions made solely on the basis of automated processing of personal data that affect the Data Subject’s interests, including decisions intended to define their personal, professional, consumer, or credit profile or aspects of their personality; and
            k) information regarding the criteria and procedures used for automated decision-making, subject to trade and industrial secrets.

            15.2. The Data Subject may object to processing carried out on the basis of an exemption from consent, in the event of non-compliance with these Clauses or National Legislation.

            15.3. The deadline for responding to requests under this Clause and item 14.3 is 15 (fifteen) days from the date of the Data Subject’s request, except where a different deadline is established by specific ANPD regulation.

            15.4. If the Data Subject’s request is directed to the Party not designated as responsible for the obligations under this Clause or item 14.3, that Party must:
            a) inform the Data Subject of the service channel made available by the Designated Party; or
            b) forward the request to the Designated Party as soon as possible, to enable a response within the deadline set out in item 15.3.

            15.5. The Parties must immediately inform the Processing Agents with which they have shared data of any correction, deletion, anonymization, or blocking of data, so that they can perform the same procedure, except where such communication is demonstrably impossible or involves disproportionate effort.

            15.6. The Parties must provide mutual assistance in order to respond to Data Subjects’ requests.

            CLAUSE 16. Security Incident Notification.

            16.1. The Designated Party must notify the ANPD and Data Subjects, within 3 (three) business days, of the occurrence of a security incident that may pose a relevant risk or damage to Data Subjects, as provided for in National Legislation.

            16.2. The Importer must maintain a record of security incidents in accordance with National Legislation.

            CLAUSE 17. Liability and Compensation for Damages.

            17.1. A Party that, in the course of Personal Data processing activity, causes property or moral damage, individual or collective, in violation of these Clauses and National Legislation, is obligated to remedy it.

            17.2. The Data Subject may seek compensation for damage caused by either Party as a result of a violation of these Clauses.

            17.3. The defense of Data Subjects’ interests and rights may be pursued in court, individually or collectively, in accordance with applicable law on individual and collective remedies.

            17.4. A Party acting as Processor is jointly liable for damage caused by the processing when it fails to comply with these Clauses or fails to follow the Controller’s lawful instructions, except as provided in item 17.6.

            17.5. Controllers directly involved in processing that resulted in damage to the Data Subject are jointly liable for such damage, except as provided in item 17.6.

            17.6. Neither Party will be held liable if it is proven that:
            a) it did not carry out the Personal Data processing attributed to it;
            b) although it carried out the Personal Data processing attributed to it, there was no violation of these Clauses or National Legislation; or
            c) the damage resulted from the Data Subject’s own exclusive fault or that of a third party who is not a recipient of a Subsequent Transfer or subcontracted by the Parties.

            17.7. Under National Legislation, the judge may shift the burden of proof in favor of the Data Subject where, in the judge’s assessment, the allegation is plausible, there is insufficient means to produce evidence, or producing evidence would be excessively burdensome for the Data Subject.

            17.8. Actions for compensation for collective damages under this Clause may be brought collectively in court, in accordance with applicable law.

            17.9. A Party that compensates the Data Subject for damage has a right of recourse against other responsible parties, in proportion to their participation in the harmful event.

            CLAUSE 18. Safeguards for Subsequent Transfer.

            18.1. The Importer may only carry out Subsequent Transfers of Personal Data subject to the International Data Transfer governed by these Clauses if expressly authorized, in accordance with the circumstances and conditions described in Clause 3.

            18.2. In any case, the Importer:
            a) must ensure that the purpose of the Subsequent Transfer is compatible with the specific purposes described in Clause 2;
            b) must ensure, by way of a written contractual instrument, that the safeguards provided for in these Clauses will be observed by the third-party recipient of the Subsequent Transfer; and
            c) for purposes of these Clauses, and with respect to the Personal Data transferred, will be considered responsible for any irregularities committed by the third-party recipient of the Subsequent Transfer.

            18.3. The Subsequent Transfer may also be carried out based on another valid International Data Transfer mechanism provided for in National Legislation, regardless of the authorization referred to in Clause 3.

            CLAUSE 19. Notification of Access Requests.

            19.1. The Importer will notify the Exporter and the Data Subject of any Access Request related to the Personal Data subject to the International Data Transfer governed by these Clauses, except where notification is prohibited by the law of the country where the data is processed.

            19.2. The Importer will take appropriate legal measures, including legal action, to protect Data Subjects’ rights whenever there is adequate legal grounds to challenge the legality of the Access Request and, if applicable, the prohibition on providing the notice referred to in item 19.1.

            19.3. To respond to requests from the ANPD and the Exporter, the Importer must maintain a record of Access Requests, including date, requester, purpose of the request, type of data requested, number of requests received, and legal measures adopted.

            CLAUSE 20. Termination of Processing and Deletion of Data.

            20.1. The Parties must delete the Personal Data subject to the International Data Transfer governed by these Clauses upon termination of processing, within the scope and technical limits of their activities, retention being authorized only for the following purposes:
            a) compliance with a legal or regulatory obligation by the Controller;
            b) study by a Research Body, ensuring, whenever possible, anonymization of Personal Data;
            c) transfer to a third party, provided the requirements set out in these Clauses and National Legislation are met; and
            d) exclusive use by the Controller, with third-party access prohibited, and provided the data is anonymized.

            20.2. For purposes of this Clause, processing is deemed to have terminated when:
            a) the purpose set out in these Clauses has been achieved;
            b) the Personal Data is no longer necessary or relevant to achieving the specific purpose set out in these Clauses;
            c) the processing period has ended;
            d) a Data Subject’s request has been fulfilled; and
            e) determined by the ANPD, where there has been a violation of these Clauses or National Legislation.

            CLAUSE 21. Data Processing Security.

            21.1. The Parties must adopt security measures that ensure protection of the Personal Data subject to the International Data Transfer governed by these Clauses, even after its termination.

            21.2. The Parties will set out, in Section III, the Security Measures adopted, taking into account the nature of the information processed, the specific characteristics and purpose of the processing, the current state of technology, and the risks to Data Subjects’ rights, particularly in the case of sensitive personal data and data of children and adolescents.

            21.3. The Parties must make the necessary efforts to adopt periodic assessment and review measures aimed at maintaining a level of security appropriate to the characteristics of the data processing.

            CLAUSE 22. Law of the Data Recipient Country.

            22.1. The Importer represents that it has not identified laws or administrative practices of the recipient country of the Personal Data that would prevent it from complying with the obligations assumed under these Clauses.

            22.2. In the event of any regulatory change that alters this situation, the Importer will immediately notify the Exporter for assessment of the contract’s continuity.

            CLAUSE 23. Non-Compliance with the Clauses by the Importer.

            23.1. In the event of a violation of the safeguards and guarantees provided for in these Clauses, or the Importer’s inability to comply with them, the Exporter must be immediately notified, except as provided in item 19.1.

            23.2. Upon receipt of the notice referred to in item 23.1, or upon verification of the Importer’s non-compliance with these Clauses, the Exporter will take appropriate measures to ensure protection of Data Subjects’ rights and compliance of the International Data Transfer with National Legislation and these Clauses, and may, as applicable:
            a) suspend the International Data Transfer;
            b) request the return of the Personal Data, its transfer to a third party, or its deletion; and
            c) terminate the contract.

            CLAUSE 24. Choice of Forum and Jurisdiction.

            24.1. Brazilian law applies to these Clauses, and any dispute between the Parties arising from these Clauses will be resolved before the competent courts of Brazil, subject, as applicable, to any forum elected by the Parties in Section IV.

            24.2. Data Subjects may bring legal actions against the Exporter or the Importer, at their choice, before the competent courts in Brazil, including those located at their place of residence.

            24.3. By mutual agreement, the Parties may resort to arbitration to resolve disputes arising from these Clauses, provided it is conducted in Brazil and in accordance with the provisions of the Arbitration Law.

            Section III — Security Measures.

            (i) Governance and supervision of internal processes: All Information Security, Privacy and Data Protection measures can be viewed in detail at:https://www.pipefy.com/pt-br/seguranca/

            (ii) technical and administrative security measures, including measures to ensure the security of operations performed, such as the collection, transmission and storage of data: All Information Security, Privacy and Data Protection measures can be viewed in detail at:https://www.pipefy.com/pt-br/seguranca/ 
            Book a Demo Book a Demo