Back
PTESEN

Data Processing Agreement

Last updated: June 3, 2026 (Version 1.0)

1. Parties

This Data Processing Agreement ("DPA") is entered into between:

Data Processor: ReveLumi (operated by Gyaco Educação e Treinamento Ltda., CNPJ 17.798.899/0001-32), a Brazilian company providing AI-powered qualitative research services, headquartered in São Paulo, Brazil.

Data Controller: The organization identified in the Order Form or service agreement referencing this DPA ("Controller"), whose personal data is processed by ReveLumi in the course of providing its services.

This DPA forms part of and is incorporated into the Terms of Use and/or service agreement between the parties (the "Agreement").

2. Definitions

For the purposes of this DPA:

"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection law, including Brazil's Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018).

"Processing" means any operation performed on Personal Data, including collection, recording, storage, use, transmission, or deletion.

"Data Subject" means the natural person whose Personal Data is processed — in the context of ReveLumi's services, typically respondents invited by the Controller to participate in research conversations.

"Sub-processor" means any third party engaged by ReveLumi to process Personal Data on behalf of the Controller.

"Research Session" means a conversational interview conducted via WhatsApp or other supported channel, orchestrated by ReveLumi's AI platform on behalf of the Controller.

3. Scope and Purpose of Processing

ReveLumi processes Personal Data solely to provide its qualitative research services as described in the Agreement. The processing activities covered by this DPA include:

• Conducting automated conversational Research Sessions with Data Subjects via WhatsApp or other supported channels.

• Transcribing, analyzing, and summarizing responses to generate research insights for the Controller.

• Managing contact lists and session invitations provided by the Controller.

• Storing session recordings, transcripts, and derived insights in ReveLumi's platform.

ReveLumi will not process Personal Data for any purpose other than those specified in the Agreement and this DPA, unless required by applicable law.

4. Categories of Personal Data Processed

Depending on the research conducted, ReveLumi may process the following categories of Personal Data:

• Contact information: name, phone number, email address (as provided by the Controller for session invitations).

• Conversational data: text messages, audio recordings, and transcripts generated during Research Sessions.

• Usage metadata: session timestamps, message delivery status, and platform interaction logs.

ReveLumi does not intentionally collect special categories of sensitive Personal Data (e.g., health, biometric, or financial data). The Controller is responsible for ensuring that research scripts do not solicit such data unless a separate written agreement has been executed.

5. Obligations of ReveLumi as Processor

ReveLumi agrees to:

• Process Personal Data only on documented instructions from the Controller, as set forth in the Agreement and this DPA.

• Ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.

• Implement and maintain appropriate technical and organizational security measures to protect Personal Data against unauthorized access, loss, or disclosure.

• Notify the Controller without undue delay, and in any event within 72 hours, upon becoming aware of a Personal Data breach affecting data processed under this DPA.

• Assist the Controller in fulfilling its obligations to respond to Data Subject rights requests (access, correction, deletion, portability) to the extent technically feasible.

• At the Controller's choice, delete or return all Personal Data upon termination of the Agreement, and delete existing copies unless applicable law requires otherwise.

• Make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations set forth in this DPA.

6. Obligations of the Controller

The Controller agrees to:

• Ensure it has a valid legal basis under the LGPD and any other applicable law for providing Personal Data to ReveLumi and for the processing activities described in this DPA.

• Obtain any necessary consents from Data Subjects prior to sharing their contact information with ReveLumi.

• Provide accurate and lawful instructions to ReveLumi regarding the scope of processing.

• Inform ReveLumi promptly if any instruction given would result in a violation of applicable data protection law.

7. Sub-processors

The Controller grants ReveLumi general authorization to engage the sub-processors listed below. ReveLumi will inform the Controller of any intended additions or replacements with reasonable advance notice, providing the Controller an opportunity to object.

All sub-processors are bound by data processing agreements that impose data protection obligations no less protective than those set forth in this DPA.

Sub-processorPurposeLocation
Supabase (PostgreSQL + Storage)Primary data storageUS-West-2 (Oregon, USA)
Amazon Web Services (AWS)Processing infrastructureUS-West-2 (Oregon, USA)
Google (Gemini AI + Speech-to-Text)AI inference and audio transcriptionUSA / Google Cloud us-central1
Meta / WhatsApp Cloud APIConversational interface for research sessionsUSA
LangfuseLLM observability and loggingUSA
AmplitudeProduct analyticsUSA
StripeBilling and subscription managementUSA
SalvyDedicated WhatsApp numbers (when applicable)Brazil / USA
Google OAuthUser authentication for the platformUSA

8. International Data Transfers

Personal Data processed under this DPA may be transferred to and stored in the United States of America, where ReveLumi's primary infrastructure and sub-processors are located. ReveLumi will ensure that such transfers are carried out in accordance with applicable data protection law, including the international transfer provisions of the LGPD (Articles 33–36).

Where required by applicable law, ReveLumi will implement appropriate safeguards for international data transfers, such as standard contractual clauses or equivalent mechanisms.

9. Data Retention and Deletion

ReveLumi retains Personal Data processed under this DPA for the duration of the active service agreement with the Controller, plus a period of up to 12 (twelve) months following termination, to allow for audit and dispute resolution purposes. After this period, Personal Data will be securely deleted or anonymized.

The Controller may request deletion of specific Personal Data at any time by contacting privacy@revelumi.com. ReveLumi will fulfill such requests within 30 (thirty) days, except where retention is required by applicable law.

10. Data Subject Rights

To the extent that ReveLumi receives a request directly from a Data Subject concerning their Personal Data, ReveLumi will promptly (and in any event within 5 business days) forward such request to the Controller. ReveLumi will not respond to Data Subject requests on behalf of the Controller without the Controller's prior written authorization, except as required by law.

11. Security Measures

ReveLumi maintains technical and organizational measures appropriate to the risk of the processing, including:

• Encryption of data in transit (TLS 1.2 or higher) and at rest.

• Access controls and authentication mechanisms restricting access to Personal Data to authorized personnel only.

• Regular security assessments of its infrastructure and sub-processors.

• Incident response procedures to detect, contain, and report Personal Data breaches.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Agreement. To the extent permitted by applicable law, ReveLumi's aggregate liability to the Controller under this DPA shall not exceed the total fees paid by the Controller to ReveLumi in the 12 months preceding the event giving rise to the claim.

13. Governing Law and Jurisdiction

This DPA shall be governed by the laws of the Federative Republic of Brazil. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of the city of São Paulo, State of São Paulo, Brazil.

14. Data Protection Contact

For any questions, requests, or notices related to data protection under this DPA, the Controller may contact ReveLumi at:

Email: privacy@revelumi.com

Website: https://revelumi.com