Data Processing Agreement
Version 1.0 · effective July 27, 2026
This agreement (the "DPA") forms part of the ValorBrain subscription contract and describes how we process personal data on the customer's behalf under Brazil's Law 13.709/2018 (LGPD). It applies automatically to every paid account; if your legal team needs a signed copy, write to [email protected] and we return it signed within two business days.
1. Roles
The customer is the controller: they decide which documents to index, who has access, and why. Valor Digital is the processor: we handle the data only to run the service, following the customer's instructions as expressed through the product and this agreement. We do not use customer data for our own purposes.
2. Subject matter and duration
Processing exists to index, retrieve and answer over the content the customer sends, and lasts as long as the subscription is active. Once it ends, section 9 applies.
3. Data processed
- Account: name, email, role, and the access record (who searched, who opened which document, when).
- Content:whatever the customer indexes — documents, messages, meetings, email and whatever comes from the connectors they authorize. It may contain third parties' personal data, and the customer defines the legal basis for that.
- Billing: invoicing data, handled by the payment processor.
We neither ask for nor recommend indexing sensitive personal data (LGPD art. 5, II) or children's data. Anyone who needs that should run ValorBrain in their own environment, and talk to us first.
4. Security
The technical measures in force are described under Security. The main ones: per-account isolation enforced by the database (PostgreSQL Row-Level Security), TLS in transit, bcrypt password hashing, API tokens stored as hashes, and a per-user access record. We do not make changes that lower the described level of protection without prior notice.
5. Subprocessors
The list lives at Subprocessors, with what each one receives and where it sits. The customer authorizes the listed subprocessors. Before adding a new one that touches customer content we give 30 days'notice to the account's admin contact; if the addition is unacceptable, the customer may terminate without penalty within that window, with a pro-rata refund of amounts already paid.
6. International transfer
Documents, vectors and the database sit on our infrastructure in Brazil. Answer generation is the exception:it uses a cloud language model outside the country, and each answer sends the question and the retrieved passages. Searching sends nothing; only a generated answer does. The transfer relies on LGPD art. 33, II (contractual clauses with the supplier) and is avoidable: the Empresa plan offers deployment inside the customer's environment as an option and Enterprise includes it, in which case no step leaves the customer's perimeter.
7. Data subject rights
The customer answers data subjects and we provide the tooling: content export via API, correction and deletion per document or per collection, and the access record in the interface. When a data subject contacts us directly, we forward to the customer within 5 business days instead of answering on their behalf. Formal assistance requested by the customer is delivered within 15 days.
8. Incidents
We notify the account's admin contact within 48 hoursof confirming a security incident that may pose relevant risk or harm, stating what is known, what is not yet known, and what has already been done. Notifying the ANPD and data subjects is the controller's duty; we supply the technical facts, written postmortem included.
9. Return and deletion
After the subscription ends the customer may export content for 30 days. Deletion then runs within 30 days of the request or of the end of that window, and reaches backups on the next rotation — backup retention is 14 days, so no copy survives beyond 44 days. Records required by law (tax, accounting) are kept for the statutory period, separate from content.
10. Audit
We answer security questionnaires and grant access to technical documentation under an NDA. We hold no SOC 2, ISO 27001 or HIPAA certification, and we promise no date for them: we would rather be checkable than certified on paper. Enterprise customers may commission an independent audit, at their cost and in an agreed window.
11. Governing law
This DPA is governed by Brazilian law. Venue is the district of Valor Digital's head office unless the subscription contract states otherwise.
12. Contact
Data Protection Officer: Gustavo Iucksh Santos · [email protected]

