Roles
Where the customer determines the purposes and essential means of personal-data processing submitted to M2 Visibility, the customer acts as Controller and M2.IA as Processor. If the customer is itself a Processor, M2.IA may act as Subprocessor. M2.IA remains Controller for its own account, billing, security, legal-compliance and commercial data.
Subject matter and instructions
M2.IA processes Customer Personal Data only to provide, secure, maintain and support the contracted services under documented instructions, the agreement and applicable law. Processing continues for the term and any additional period required for return, deletion, lawful retention and defense of rights.
Data and data subjects
Data may include professional identity and contact information, technical identifiers, usage data, content submitted through prompts and integrations, audit evidence and other data legitimately submitted by the customer. Data subjects may include employees, contractors, customers, prospects and business partners.
Processor obligations
- Process data according to documented instructions and identify manifestly unlawful instructions where required.
- Restrict access to authorized persons bound by confidentiality.
- Maintain technical and organizational measures proportionate to risk.
- Provide reasonable assistance for data-subject requests and regulatory obligations.
- Maintain relevant processing and security evidence.
- Not sell Customer Personal Data or use it for purposes incompatible with the contracted service.
Customer obligations
The customer is responsible for legal grounds, transparency, legitimate instructions, data minimization, user management and appropriate feature configuration. Sensitive data or children’s data should not be submitted without documented necessity and controls appropriate to the risk.
Subprocessors
The customer provides general authorization for subprocessors required to provide the service, subject to protection obligations appropriate to the delegated activity. The current list is maintained at /en/legal/subprocessors.
International transfers
Where personal data subject to the LGPD is transferred internationally, the parties will use a legally valid mechanism, which may include ANPD-approved standard contractual clauses or another mechanism permitted by applicable law.
Security and incidents
M2.IA maintains risk-proportionate security controls including access management, logical segregation, secrets protection, logging, auditability, change governance and incident response. Confirmed incidents involving Customer Personal Data will be reported to the customer without undue delay with reasonably available information supporting assessment, containment and legally required notifications.
Data subject and authority requests
Requests concerning customer-controlled data may be redirected to the customer unless prohibited by law. M2.IA will provide reasonable technical assistance consistent with the nature of processing and available functionality.
Return and deletion
Following termination, the customer may request export through contracted features. M2.IA will delete or anonymize data after applicable operational periods, except where retention is required by law, security, fraud prevention, audit or defense of rights.
Audit and evidence
M2.IA may support due diligence through its Trust Center, technical documentation, control evidence and reasonable questionnaires. On-site audits and invasive testing require defined scope, confidentiality, security safeguards, notice and separate agreement.
Liability and precedence
Liability and financial caps follow the main agreement except for mandatory legal obligations. This DPA prevails over conflicting agreement provisions only with respect to processing covered by this DPA.
Legal and privacy contact
M2.IA Consultoria em Tecnologia da Informação, Brazilian CNPJ 62.138.251/0001-94, Brazil.
contato@m2ia.app