UpuaiUpuai

Data Processing Addendum (DPA)

Version:
2.0.0
In force since:
October 02, 2026
Supersedes:
1.0.0 (August 29, 2026)
Operated by:
GMB TECNOLOGIA LTDA — CNPJ 68.727.144/0001-88

This Data Processing Addendum (“DPA”) forms part of the Terms of Use and governs the processing of personal data that you, as Controller, submit to the Upuai Cloud platform, operated by GMB TECNOLOGIA LTDA, CNPJ 68.727.144/0001-88, as Processor, under Brazilian Law no. 13,709/2018 (LGPD).

This DPA binds the parties automatically upon acceptance of the Terms of Use, with no separate signature required. Customers who need an executed instrument, specific clauses or their own contractual template may request one at contato@upuai.com.br.

Language. This is a courtesy translation. The Portuguese version at upuai.com.br/dpa is the binding version; in case of divergence, it prevails.

1. Roles

When you use the Platform to host applications, databases, files and volumes containing third-party personal data — your customers, end users, staff or partners — you are the Controller and determine the purposes and means of processing; we are the Processor and process that data solely on your instructions.

This DPA does not apply to data for which we are Controller — account, billing, Platform usage — which is governed by the Privacy Policy.

2. Subject matter, nature and purpose

Subject matter. Provision of the compute, database, storage, networking and related services described in the Terms of Use.

Nature of operations. Collection by receipt, storage, structuring, replication, backup, transmission, access for requested support, and deletion.

Purpose. Solely to perform the contracted service. We do not use Controller Data for our own purposes, do not sell it, do not use it for advertising, and do not use it to train artificial intelligence models.

Duration. For the term of the contract, subject to section 10.

3. Categories of data and data subjects

The Controller determines what is sent to the Platform. We have no control over, and no advance visibility into, the categories actually processed.

Categories of data subjects typically involved: end users, customers, staff and commercial contacts of the Controller.

Categories of data typically involved: registration and contact data, account and authentication data, transactional and usage data, subject-generated content and access logs.

4. Controller obligations

You represent and warrant that: you have an adequate legal basis for each processing operation carried out through the Platform; you provide data subjects with the information required by the LGPD; you obtain and manage consent where that is the legal basis; and your instructions do not violate the LGPD or any other applicable rule.

You are responsible for the security configuration of your resources, including access control to your databases and buckets, management of your secrets, and definition of data retention within your applications.

5. Processor obligations

We undertake to:

Process only on instructions. Process Controller Data solely on your documented instructions, which comprise these Terms, this DPA, the configuration you define in the dashboard and API, and support requests you submit. If we consider an instruction to breach the LGPD, we will notify you and may suspend its execution.

Confidentiality. Ensure that persons authorized to process the data are bound by a duty of confidentiality, and limit access to what is strictly necessary.

Security. Implement the technical and administrative measures in Annex I.

Assistance. Assist you, so far as reasonable and taking into account the nature of the processing, in responding to data subject requests, preparing impact assessments, notifying incidents and responding to the ANPD.

Records. Maintain records of the processing operations carried out on our side, available on request.

6. Data subject requests

Requests from data subjects concerning data in your applications must be handled by you, the Controller — only you know the context and hold the means of access within your application.

If we receive a request directly from one of your data subjects, we will not respond on the merits: we will forward it to you without undue delay, unless the law requires a direct response.

The Platform gives you full administrative access to your databases, buckets and volumes, which allows you to locate, correct, export and delete a data subject’s data without depending on us. If you nonetheless need technical assistance, write to contato@upuai.com.br.

7. Subprocessors

You give general authorization for engagement of the subprocessors listed at /en-US/subprocessors.

Each subprocessor is contractually bound by data protection obligations no less protective than those in this DPA. We remain answerable to you for the acts of our subprocessors as if they were our own.

Additions and replacements are announced 30 days in advance, and the right of substantiated objection is described in section 7 of the subprocessors page.

8. Security incidents

We will notify you without undue delay and, in any event, within 48 hours of becoming aware of a security incident affecting Controller Data.

The notification will include, so far as known: the nature of the incident, the categories and approximate volume of data and data subjects involved, the likely consequences, the measures taken and mitigations, and a channel for further information. Information not immediately available is supplemented as the investigation progresses.

Notification to the ANPD and to data subjects, where applicable, is your responsibility as Controller. We will provide the information you need to do so within the statutory deadline.

9. International transfers

Controller Data — applications, databases, buckets and volumes — is stored and processed in Brazil, in a datacenter in Belo Horizonte/MG.

International transfers are limited to those described in section 6 of the Privacy Policy and to the foreign subprocessors listed, on the basis of article 33 of the LGPD and through contractual data protection clauses.

Execution logs sent for automated failure summaries may contain personal data if your application emits it to log output. This feature can be disabled in the project settings; if you process sensitive data or do not want this transfer, disable it.

10. Deletion and return

On termination of the contract, you may export Controller Data by the means described in section 7 of the Terms of Use, during the 15-day retention period following termination.

After that period, we delete Controller Data from production systems. Residual copies in backups are deleted at the end of their retention cycle and remain subject to this DPA for as long as they exist.

We retain data beyond those periods only where the law requires, and then only for the legal purpose justifying the retention.

11. Audit

Upon reasonable request, with 30 days’ prior notice and no more than once a year, we will make available the information necessary to demonstrate compliance with this DPA, including a description of security measures and the results of any security assessments we hold.

On-site audits or penetration testing against our infrastructure require prior agreement on scope, method, date and costs, and are subject to a confidentiality agreement and to preserving the security and privacy of other customers.

12. Liability

Liability under this DPA is subject to the limits in section 13 of the Terms of Use, save that those limits do not apply to damages arising from a breach of personal data protection attributable to Upuai, under section 13.4 of those Terms, nor to penalties imposed directly by the ANPD on either party for its own acts.

13. Term and precedence

This DPA remains in force for as long as we process Controller Data. In case of conflict between this DPA and the Terms of Use regarding the processing of personal data, this DPA prevails.


Annex I — Technical and administrative security measures

Access control. Passwordless authentication, by one-time code or external provider; role-based access control with least privilege; scoped API tokens stored as cryptographic digests; environment segregation.

Isolation. Each workspace runs in a dedicated namespace, with network policy restricting traffic between workspaces, per-workspace resource quotas, and hardened workload isolation via lightweight virtualization.

Encryption. TLS on all external traffic; secrets and integration credentials encrypted at rest with AES-256-GCM; external backups encrypted before leaving our infrastructure.

Supply chain. Vulnerability scanning of container images before publication; cryptographic signing of Platform images; our own private registry; dependencies and infrastructure components under periodic update.

Logging and monitoring. Audit records with actor, IP address, user agent and timestamp; monitoring of availability, resources and storage integrity, with alerting; log retention per section 9 of the Privacy Policy.

Continuity. Automatic backups of managed databases per Plan; encrypted external copy of the control database with tamper protection; documented recovery procedures, periodically tested.

People. Access to production infrastructure restricted to authorized personnel under a duty of confidentiality, with administrative access logged.

Incident management. Documented detection, containment, investigation and notification procedure, with the deadline in section 8 of this DPA.


GMB TECNOLOGIA LTDA — CNPJ 68.727.144/0001-88 — Belo Horizonte/MG, Brazil. Data Protection Officer: contato@upuai.com.br.