Data Processing Agreement (DPA)
Last updated: June 30, 2026
Preamble
This Data Processing Agreement (“DPA”) supplements and forms part of the Terms of Use (the “Agreement”) between the Customer and MUPI SYSTEMS LTDA. (CNPJ 26.882.608/0001-80), owner of the eAgenda platform, and governs the processing of personal data carried out by the Provider on behalf of the Customer in the provision of the service. It was prepared in compliance with the Brazilian General Data Protection Law (Law 13,709/2018 — LGPD) and, where applicable to the Customer, with Regulation (EU) 2016/679 (GDPR). Capitalised terms not defined here have the meaning given to them in the Agreement.
1. Definitions
1.1. “DATA PROTECTION LAW”: the LGPD and, where applicable to the Customer, the GDPR, the UK GDPR and other applicable data protection laws.
1.2. “PERSONAL DATA”, “DATA SUBJECT”, “PROCESSING”, “SECURITY INCIDENT” and “AUTHORITY” have the meaning given in the DATA PROTECTION LAW.
1.3. “CONTROLLER”: the Customer, who determines the purposes and means of the PROCESSING of PERSONAL DATA entered into the ACCOUNT.
1.4. “PROCESSOR”: the Provider, who processes PERSONAL DATA on behalf of and in accordance with the instructions of the CONTROLLER.
1.5. “SUB-PROCESSOR”: a third party engaged by the Provider to process PERSONAL DATA in the provision of the service.
2. Subject Matter and Roles
2.1. This DPA governs the PROCESSING of PERSONAL DATA carried out by the Provider, as PROCESSOR, on behalf of the Customer, as CONTROLLER, in the performance of the Agreement, and forms an integral part of it for all purposes.
2.2. The Customer is responsible for having a valid legal basis for the PROCESSING and for complying with its duties as CONTROLLER; the Provider processes PERSONAL DATA solely to provide the service, as described in Annex I.
2.3. In the event of any conflict between the Agreement and this DPA regarding the PROCESSING of PERSONAL DATA, this DPA prevails.
3. Processing Instructions
3.1. The Provider shall process PERSONAL DATA only on the documented instructions of the Customer, as set out in this DPA, in the Agreement and in the functionality and settings of the PLATFORM, unless required otherwise by law, in which case the Provider shall inform the Customer beforehand, unless legally prohibited.
3.2. The Provider shall inform the Customer if, in its opinion, an instruction infringes the DATA PROTECTION LAW.
4. Confidentiality
4.1. The Provider ensures that persons authorised to process PERSONAL DATA are bound by an obligation of confidentiality and receive adequate training.
5. Security
5.1. The Provider implements the technical and organisational measures described in Annex II to protect PERSONAL DATA against unauthorised access and against destruction, loss, alteration, communication or dissemination, taking into account the state of the art, the costs and the risks involved.
6. Sub-processors
6.1. The Customer gives general authorisation for the engagement of the SUB-PROCESSORS listed in Annex III, which are necessary for the provision of the service.
6.2. The Provider shall inform the Customer, with reasonable prior notice, of the addition or replacement of any SUB-PROCESSOR, and the Customer may object on reasonable data protection grounds; if the objection is not resolved, the Customer may terminate the affected service.
6.3. The Provider binds each SUB-PROCESSOR to data protection obligations equivalent to those in this DPA and remains responsible for the acts of its SUB-PROCESSORS.
7. Assistance to the Controller
7.1. The Provider shall assist the Customer, to the extent reasonable and taking into account the nature of the PROCESSING: (a) in responding to DATA SUBJECT requests (access, rectification, erasure, portability and other rights), including through the functionality of the PLATFORM; (b) in complying with its obligations regarding security, incident notification, data protection impact assessments and prior consultation with the AUTHORITY.
7.2. If the Provider receives a DATA SUBJECT request directly, it shall forward it to the Customer and shall not respond on its own, unless instructed to do so.
8. Security Incidents
8.1. The Provider shall notify the Customer, by email, without undue delay and within 24 (twenty-four) hours of becoming aware, of any SECURITY INCIDENT involving PERSONAL DATA processed on the PLATFORM, with the information available so that the Customer can comply with its duties to notify the AUTHORITY and the DATA SUBJECTS.
8.2. Notification of an INCIDENT does not constitute an acknowledgement of fault or liability by the Provider.
9. International Transfers
9.1. PERSONAL DATA may be processed in data centres in Brazil or abroad, in particular in the United States and the European Union, subject to the international transfer requirements of the DATA PROTECTION LAW.
9.2. Where the Customer is subject to the GDPR or the UK GDPR and there is a transfer to a country without an adequacy decision, the European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914, controller-to-processor module) and, where applicable, the UK International Data Transfer Addendum issued by the ICO shall apply, as made available by the Provider as part of this Agreement.
10. Audit
10.1. The Provider shall make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, preferably through third-party certifications and reports (for example, ISO/IEC 27001), without compromising the security and confidentiality of other customers.
11. Termination
11.1. Upon termination of the Agreement, the Provider shall, in accordance with the Customer’s instructions and without prejudice to the export provided for in the Agreement, delete or return the PERSONAL DATA, subject to backup retention periods and to any retention required by legal or regulatory obligation.
Annex I — Description of the Processing
- Nature and purpose: provision of the scheduling service and related features (registration, calendar, history, notifications, reports).
- Operations: collection, recording, organisation, storage, use, disclosure, transmission and erasure.
- Categories of data subjects: END USERS (the Customer’s clients who make bookings) and the Customer’s AUTHORISED USERS.
- Categories of data: identification and contact (name, email, phone); booking data (date, time, service, professional, unit); history and interactions; technical data (IP, device). Any sensitive data entered by the Customer is the Customer’s responsibility as CONTROLLER.
- Duration: for the term of the Agreement, plus the retention periods provided for therein.
Annex II — Security Measures
- TLS 1.2 or higher encryption for data in transit.
- Passwords protected by key-derivation functions (bcrypt/Argon2).
- Storage in ISO/IEC 27001 certified data centres.
- Role-based access control and least-privilege principle.
- Access logging and audit trails.
- Staff confidentiality and training.
- Backup and disaster recovery routines.
Annex III — Sub-processors
- Cloud providers (Amazon Web Services, DigitalOcean, Microsoft Azure and/or Google Cloud): hosting, compute and storage — Brazil, USA or European Union, depending on the configured region.
- Postmark: email notifications — USA.
- Twilio: SMS notifications — USA.
- Meta Platforms: WhatsApp notifications — USA / European Union.
- Asaas, Mercado Pago and/or Stripe: payment processing — Brazil and USA/European Union. These providers may act as independent controllers of payment data, in which case such processing is governed by their own privacy policies.