Português (Brasil): Aditivo de Tratamento de Dados
This Data Processing Addendum ("DPA") forms part of the agreement governing the use of the Tevlio Services (the “Agreement”) between the Customer identified in the Agreement ("Customer") and:
- Legal name: Tevlio Tecnologia da Informação Ltda.
- CNPJ: 68.407.558/0001-20
- Address: R. Doutor Arlindo Luz, 540, Sala 01, Centro, Ourinhos, SP, CEP 19.900-011, Brazil
- Encarregado and contact: Pedro Lucca Soares Cruzeiro · privacy@tevlio.com
This DPA applies when Tevlio Processes Customer Personal Data as an Operator, Processor, Service Provider, or equivalent role. The LGPD is its primary reference. Other mandatory laws apply only when they legally cover the relevant Processing.
The Portuguese (Brazil) version is the original version and controls if it conflicts with this English translation. If there is a conflict, the following order applies: (1) mandatory law; (2) standard clauses or another mandatory transfer mechanism applicable to the transfer; (3) this DPA; and (4) the rest of the Agreement. A transfer clause controls only the Processing and transfer it covers.
1. Definitions
“ANPD” means Brazil’s Agência Nacional de Proteção de Dados (National Data Protection Agency).
“CCPA” means the California Consumer Privacy Act, as amended and regulated.
“Controller” means the person that determines the purposes and essential elements of Processing, including an equivalent role under Applicable Data Protection Law.
“Customer Personal Data” means personal data contained in Customer Content that Tevlio Processes on Customer’s behalf. It does not include data for which Tevlio independently determines the purposes and means, as described in the Privacy Policy.
“Personal Data Incident” means a confirmed security breach that causes accidental, unlawful, or unauthorized destruction, loss, alteration, disclosure of, or access to Customer Personal Data Processed by Tevlio or a Subprocessor.
“FADP” means the Swiss Federal Act on Data Protection.
“GDPR” means Regulation (EU) 2016/679, and “UK GDPR” means the GDPR as incorporated into and amended by UK law.
“Applicable Data Protection Law” means mandatory privacy, data-protection, security, or incident-notification law applicable to the Processing covered by the Agreement, including the LGPD and, where legally applicable, the GDPR, UK GDPR, FADP, and CCPA.
“LGPD” means Brazil’s Lei Geral de Proteção de Dados Pessoais, Law No. 13,709/2018.
“Operator” or “Processor” means the person that Processes personal data on behalf of a Controller, including an equivalent role under Applicable Data Protection Law.
“Services” means Tevlio Mail, Tevlio Cloud, Tevlio Helpdesk, and other Tevlio services identified in the applicable order.
“Subprocessor” means a third party engaged by Tevlio to Process Customer Personal Data on its behalf. It does not include a vendor that receives no Customer Personal Data or an independent Controller.
“Data Subject” means the identified or identifiable natural person to whom Customer Personal Data relates.
“Process” or “Processing” has the meaning given by Applicable Data Protection Law and includes collecting, accessing, recording, organizing, storing, using, transmitting, restricting, deleting, or destroying personal data.
“Data Protection Authority” means the ANPD or another authority competent for the relevant Processing.
“EU SCCs” means the European Commission standard contractual clauses adopted by Implementing Decision (EU) 2021/914, as amended or replaced.
“UK Addendum” means the International Data Transfer Addendum issued by the Information Commissioner’s Office for use with the EU SCCs, as amended or replaced.
2. Roles and scope
Customer acts as Controller or Processor of Customer Personal Data. Tevlio acts as Operator or Processor. If Customer is a Processor, it confirms that its instructions, its engagement of Tevlio, and its use of Subprocessors have been authorized by the responsible Controller.
Customer may enter into this DPA on behalf of affiliates authorized to use the Services if it has authority to do so. Customer remains the primary contact and responsible for instructions unless the law requires otherwise.
Customer’s documented instructions include the Agreement, Service settings, and lawful requests sent through agreed channels. The subject matter, duration, nature, purposes, data categories, and Data Subjects are described in Schedule 1.
3. Customer obligations
Customer will:
- comply with Applicable Data Protection Law when using the Services and Processing Customer Personal Data;
- provide required notices and have a valid legal basis;
- use consent only when it is the applicable legal basis;
- give lawful, documented instructions consistent with the Agreement;
- limit data to what is adequate, relevant, and necessary;
- properly configure users, access, retention, integrations, and security features; and
- respond to Data Subjects and Data Protection Authorities as Controller, with the assistance described in this DPA.
Customer is responsible for the lawfulness, accuracy, and source of Customer Personal Data, except to the extent Tevlio itself caused a violation.
4. Tevlio obligations
Tevlio will:
- Process Customer Personal Data only to provide, protect, support, and maintain the Services, according to Customer’s documented instructions or as required by mandatory law;
- inform Customer without delay if Tevlio reasonably believes an instruction violates Applicable Data Protection Law, unless legally prohibited;
- suspend the affected instruction when necessary to prevent unlawful Processing while the parties seek an appropriate alternative;
- limit access to persons subject to confidentiality obligations and with a legitimate operational need;
- maintain the records and information required for its role;
- not sell Customer Personal Data or share it for cross-context behavioral advertising; and
- inform Customer without undue delay if Tevlio determines that it cannot comply with a material obligation under this DPA.
If mandatory law requires Processing beyond Customer’s instructions, Tevlio will inform Customer before the Processing unless legally prohibited.
5. Data Subject rights and assistance
If Tevlio receives a Data Subject request concerning Customer Personal Data, it may forward the request to Customer or direct the Data Subject to contact Customer. Tevlio will respond directly only when authorized by Customer or required by law.
Taking into account the nature of the Processing and the information available, Tevlio will provide reasonable assistance with:
- requests for access, confirmation, correction, deletion, anonymization, blocking, portability, objection, consent withdrawal, and review of automated decisions;
- required privacy and international-transfer information;
- legally required impact assessments and prior consultations;
- investigations and lawful requests from Data Protection Authorities; and
- Customer’s compliance documentation.
Ordinary assistance available through the Services and support is included in the fees. Disproportionate custom work may be charged after Tevlio provides an estimate, unless charging is legally prohibited.
6. Subprocessors
Customer gives general authorization for Tevlio to engage the Subprocessors identified in the Vendors and Subprocessors List for the Services indicated there.
Before a Subprocessor Processes Customer Personal Data, Tevlio will enter into a written agreement containing purpose, confidentiality, security, incident, deletion, assistance, audit, and international-transfer obligations appropriate to the Processing. Tevlio remains responsible for the Subprocessor’s performance to the extent required by law and applicable transfer clauses.
Tevlio will notify the Account Owner by email or through the agreed method at least 15 days before a new Subprocessor begins Processing Customer Personal Data. If an urgent replacement is necessary for security, availability, or compliance, Tevlio may give notice as soon as reasonably possible and will explain the shorter period.
Customer may object on substantiated data-protection grounds within 10 business days after notice. The parties will seek a commercially reasonable alternative. If no alternative is available within 30 days, either party may terminate only the affected Service, and Tevlio will refund prepaid amounts for the unused period. Mandatory rights are not limited.
7. Security
Tevlio will maintain technical and organizational measures proportionate to risk to protect Customer Personal Data against unauthorized or unlawful Processing and accidental or unlawful destruction, loss, alteration, disclosure, or access. The minimum categories are in Schedule 2 , and current general practices are described in the Security Overview .
The measures may change as technology and risk evolve without an unjustified material reduction in overall protection during an active paid engagement. Customer is responsible for using available controls, managing users, protecting credentials and devices, and keeping its own exports or copies when recommended by Service documentation.
8. Audits and compliance information
Upon reasonable written request, Tevlio will provide information necessary to demonstrate compliance with this DPA, such as security documentation, completed questionnaires, and summaries of then-available assessments or certifications.
If that information is reasonably insufficient, Customer may conduct one audit in each 12-month period, subject to:
- at least 30 days’ notice;
- a scope, date, duration, and qualified independent auditor agreed by the parties;
- protection of confidentiality, privacy, security, and operational continuity;
- no access to another customer’s data or Tevlio trade secrets unrelated to compliance; and
- Customer paying its costs and Tevlio’s reasonable costs for extraordinary assistance.
The frequency and notice limits do not apply when a Data Protection Authority requires an audit, a Personal Data Incident justifies additional verification, or the law prohibits the limitation. A recent independent assessment may replace an on-site audit when legally sufficient.
9. Personal Data Incidents
Tevlio will notify Customer without undue delay after becoming aware of a Personal Data Incident affecting Customer’s data. The notice is not an admission of fault or liability.
As information becomes available, Tevlio will provide what Customer needs for its legal obligations, including:
- the known nature and approximate scope;
- affected data and Data Subject categories, when known;
- possible consequences that can reasonably be assessed;
- containment, mitigation, and remediation measures; and
- a contact for follow-up.
Tevlio will take reasonable steps to contain, investigate, remediate, and document the incident and will provide relevant updates. Tevlio will not notify Data Subjects or a Data Protection Authority on Customer’s behalf unless instructed by Customer, directly required by law, or responding to an emergency recognized by law.
10. Government and compulsory requests
When legally permitted, Tevlio will promptly notify Customer of a government or other compulsory request for Customer Personal Data. Tevlio will verify its legal validity, disclose only the data legally required, and use reasonable lawful measures to limit or challenge an excessive request when grounds exist.
If notice is prohibited, Tevlio will seek authorization to notify when legally and reasonably possible and will document the request as required by law and applicable transfer clauses.
11. Return and deletion
During the engagement and, if requested before access ends, upon termination, Customer may choose to receive Customer Personal Data through available export features or request its deletion. Unless a mandatory requirement provides otherwise, Customer must complete the export before access ends.
After termination or a valid deletion instruction, and after completing any requested return, Tevlio will delete Customer Personal Data from active systems within 60 days. Recovery copies are isolated from ordinary use and overwritten or deleted on a cycle generally not exceeding an additional 60 days.
Tevlio may retain data only for the period required by mandatory law. Use will be restricted to the legal purpose, and the data will remain protected by this DPA. Upon request, Tevlio will provide reasonable confirmation of deletion.
12. International transfers
12.1 Transfers from Brazil
When Tevlio transfers personal data from Brazil to a Subprocessor or another importer, it will adopt and maintain a valid mechanism under Article 33 of the LGPD and ANPD regulations. When contractual clauses are the applicable mechanism, the complete and unmodified ANPD standard contractual clauses approved by Resolution CD/ANPD No. 19/2024 will form part of the agreement executed with the importer.
Tevlio will maintain a completed record of the parties, transfer description, roles, responsibilities, onward transfers, and required security measures. This public DPA does not replace the instrument that must be executed between the exporter and importer. Transparency information is published in the Privacy Policy . Upon a valid request, Tevlio will provide the applicable clauses free of charge within the legal period, subject to the protection of commercial and industrial secrets.
12.2 Transfers from the European Economic Area
For a restricted transfer governed by the GDPR from a Customer in the European Economic Area to Tevlio in Brazil, the EU SCCs are incorporated as follows:
- Module 2 applies when Customer is Controller and Tevlio is Processor;
- Module 3 applies when Customer is Processor and Tevlio is Subprocessor;
- Clause 7, the docking clause, is included;
- Clause 9 uses Option 2, general authorization, with the notice period in Section 6;
- the optional language in Clause 11 is not included;
- in Clause 17, Option 1, the parties select Irish law;
- in Clause 18, the parties select the courts of Ireland;
- Annexes I and II are completed by Schedules 1 and 2 of this DPA;
- Annex III is completed by Schedule 3 and the records identified there; and
- the competent authority is determined by Clause 13 based on the exporter’s circumstances.
The selection of Irish law and courts applies only to the EU SCCs; commercial disputes under the Agreement remain subject to the Agreement. The parties will conduct the assessments required by Clause 14 and adopt supplementary safeguards when reasonably necessary.
12.3 United Kingdom and Switzerland
For a restricted transfer governed by UK law, the UK Addendum is incorporated into the EU SCCs. Its tables are completed using the parties and Schedules 1 through 3 of this DPA, and either party may terminate it in the circumstances permitted by its mandatory text. The parties will conduct the required risk assessment and adopt required supplementary measures.
For a transfer governed by the Swiss FADP, the EU SCCs apply with the adaptations required by the Swiss authority, including references to the FADP, the competent authority, and Data Subject rights in Switzerland.
12.4 Other transfers
For another restricted transfer, the parties will adopt the valid mechanism required by the applicable jurisdiction. Each mechanism applies only within its legal scope.
13. Additional terms for other laws
When the GDPR or UK GDPR applies, Sections 2 through 12 and the Schedules of this DPA constitute the instructions and mandatory terms of the Controller-Processor agreement, including confidentiality, security, Subprocessors, assistance, deletion, audit, and transfers.
When the CCPA applies to Customer Personal Data, Tevlio will act as a service provider or contractor for the business purposes described in Schedule 1. Tevlio will:
- comply with applicable CCPA obligations and provide the same level of privacy protection required of Customer for that data;
- not sell or share that data;
- not retain, use, or disclose it outside the purposes of the Agreement, the direct business relationship, or the permissions of the CCPA;
- not combine it with data received from another person or collected through Tevlio’s own interaction, unless legally permitted;
- require compatible restrictions from Subprocessors; and
- notify Customer if it can no longer comply with these obligations.
Customer may take reasonable and proportionate steps to verify compliance and require unauthorized use to be stopped and remediated, within the limits of the CCPA and this DPA.
14. Liability
The valid liability provisions of the Agreement apply between the parties to this DPA. They do not limit Data Subject rights, direct liability to a Data Subject or Data Protection Authority, or liability that law or standard clauses prohibit limiting.
Liability between the parties will be allocated according to each party’s contribution to the event, without prejudicing third-party rights.
15. Term and acceptance
This DPA begins when Customer accepts or signs the Agreement and continues while Tevlio Processes Customer Personal Data. Confidentiality, deletion, audit records, transfers, and liability that cannot be excluded survive for as long as necessary.
Customer accepts this DPA through Tevlio’s recorded electronic acceptance process. A separately signed copy may be requested from the Tevlio Encarregado .
Schedule 1 — Processing and transfer details
A. Parties
Customer / data exporter
- Name and qualification: the Customer identified in the Agreement.
- Address and contact: the legal or billing contact registered in the Account or signed order.
- Role: Controller or Processor when Processing data for another Controller.
- Signature and date: the recorded electronic acceptance or signature of the Agreement.
Tevlio / data importer
- Name: Tevlio Tecnologia da Informação Ltda.
- CNPJ: 68.407.558/0001-20
- Address: R. Doutor Arlindo Luz, 540, Sala 01, Centro, Ourinhos, SP, CEP 19.900-011, Brazil
- Encarregado and contact: Pedro Lucca Soares Cruzeiro · privacy@tevlio.com
- Role: Operator, Processor, or Subprocessor.
- Signature and date: the recorded electronic acceptance or signature of the Agreement.
B. Description of Processing
Subject matter: Processing necessary to provide, protect, maintain, and support Tevlio Mail, Tevlio Cloud, Tevlio Helpdesk, or another Service identified in the order.
Duration: the Agreement term plus the deletion periods in Section 11, except for mandatory legal retention.
Nature of operations: receipt, collection, transmission, organization, hosting, storage, retrieval, consultation, display, support access, security analysis, recovery copying, export, restriction, and deletion.
Purposes:
- Tevlio Mail: transmitting, receiving, storing, organizing, searching, protecting, and managing email and mailbox data.
- Tevlio Cloud: hosting, storing, delivering, resolving, protecting, and managing files, domains, DNS, cloud configurations, and related infrastructure.
- Tevlio Helpdesk: receiving, organizing, routing, storing, searching, and responding to tickets and related communications.
- All Services: authentication, billing support, diagnostics, abuse prevention, security, recovery copies, and Customer-requested integrations.
Categories of Data Subjects: Customer personnel and authorized users; Customer’s customers and prospective customers; correspondents, senders, recipients, support requesters, contacts, and users of domains, websites, or applications; vendors and business contacts; and other persons whose data Customer lawfully submits.
Categories of personal data: names and contact details; Account identifiers and roles; authentication and access records; IP, device, domain, DNS, routing, delivery, and diagnostic data; messages, files, attachments, tickets, headers, metadata, settings, support communications, and Customer-defined fields.
Sensitive data: the Services do not require sensitive data as a standard feature, but Customer Content may contain it. Customer must assess necessity and lawfulness, and the Schedule 2 safeguards will apply with additional agreed restrictions when a known risk requires them.
Children and adolescents: Accounts and authorized-user access are restricted to people who are at least 18 years old. Customer must not permit minors to access or use the Services. Customer Content may contain minors’ data only under Customer’s lawful instructions, without the minor accessing the Service, and in compliance with necessity, best-interest, and security requirements.
Frequency: continuous or intermittent depending on use of the Services.
Onward transfers: only to Subprocessors necessary for the Service, as described in the Vendors and Subprocessors List , and subject to Sections 6 and 12.
C. Competent authority
The competent authority is determined by Applicable Data Protection Law. For the LGPD, it is the ANPD. For the EU SCCs, it is determined by Clause 13 based on the exporter’s circumstances. For exclusively UK or Swiss transfers, it is the corresponding competent authority.
Schedule 2 — Technical and organizational measures
Tevlio applies the following categories of measures based on the Service, data, and risk. They do not guarantee that every threat or interruption will be prevented.
Governance and people
- Assigned responsibilities for security, privacy, incidents, and access management.
- Confidentiality obligations for persons authorized to access Customer Personal Data.
- Access, change, incident, and retention procedures proportionate to risk.
Identity and access
- Individual administrative accounts or keys and least-privilege access based on role.
- Multi-factor authentication for privileged access where technically supported, with compensating controls where necessary.
- Protected administrative channels, access revocation, and records appropriate to risk.
Data and network protection
- Encryption in transit using current protocols compatible with the Service.
- Protection of stored data through application encryption, storage-provider encryption, or both, depending on architecture.
- Memory-hard one-way hashing for passwords managed directly by Tevlio.
- Logical separation between Accounts, authorization controls, firewalls, rate limits, and abuse protections.
- Restricted access to credentials, keys, and secrets, with replacement or rotation when risk requires it.
Development and changes
- Version control and review or testing of changes based on risk.
- Dependency and vulnerability monitoring with risk-based prioritization.
- Restricted use of Customer Personal Data in development and testing.
- Controlled deployment and rollback for material changes.
Logs and incidents
- Logging, monitoring, and alerts proportionate to system risk.
- Procedures for incident triage, containment, investigation, remediation, and documentation.
- Retention of relevant evidence and records according to law and documented periods.
Availability and recovery
- Redundancy, integrity monitoring, recovery copies, or replication according to the Service.
- Protection of copies against unauthorized ordinary access.
- Restoration and recovery procedures proportionate to risk.
Vendors and physical security
- Risk-based assessment before a Subprocessor Processes Customer Personal Data.
- Written privacy, confidentiality, security, incident, deletion, and transfer obligations.
- Physical security operated by applicable data-center and infrastructure providers.
Data lifecycle
- Customer access and deletion controls where compatible with the Service.
- Retention and deletion according to instructions, documented periods, and legal obligations.
- Restriction of retained data to the purpose requiring its retention.
Additional risk
When Tevlio knows that Processing involves sensitive data, minors’ data, large-scale monitoring, or another high risk, the parties will assess additional purpose limitations, access controls, logs, encryption, separation, or contractual controls. A feature directed to minors or likely to be accessed by them will require a prior assessment and the measures required by applicable law, including Brazil’s Digital Statute for Children and Adolescents.
Schedule 3 — Authorized Subprocessors
Current Subprocessors, their purposes, data categories, applicable Services, and Processing locations are listed in the Vendors and Subprocessors List . The list is incorporated into this DPA and updated under Section 6. When Module 3 of the EU SCCs applies, each Subprocessor’s registered address and privacy contact will be included in the SCC record maintained by Tevlio and provided to Customer upon request.