Skip to content

Legal & Trust · LEGAL-2.0

Privacy Policy

How M2.IA Consultoria em Tecnologia da Informação handles personal data relating to M2 Visibility, its websites, accounts, commercial contacts and platform operations.

Version 2.0 · Effective August 19, 2026 · M2.IA Consultoria em Tecnologia da Informação · Brazilian CNPJ 62.138.251/0001-94

This Policy describes processing performed by M2.IA. In corporate environments, the customer may act as controller for data submitted to M2 Visibility, while M2.IA acts as processor under the customer’s documented instructions. M2.IA may act as controller for account, billing, security, commercial relationship and legal-compliance data processed for its own purposes.
01

Who we are and scope

M2 Visibility is a SaaS AI Visibility platform operated by M2.IA Consultoria em Tecnologia da Informação, Brazilian CNPJ 62.138.251/0001-94. This Policy applies to visitors of m2ia.app and visibility.m2ia.app, registered users, customer and prospect representatives, commercial contacts and other individuals whose data is processed in connection with the services.

02

Categories of personal data

  • Identity and professional contact data, such as name, work email, company, role and phone number when provided.
  • Authentication, authorization and security data, including internal identifiers, roles, login events, audit trails and signals required to prevent abuse.
  • Usage and operational data, such as pages used, product events, measurement runs, configurations, plan limits and technical telemetry.
  • Customer content, including brands, domains, questions, prompts, configurations, responses and evidence required to provide the service.
  • Commercial and contractual data, including demo requests, plan and subscription information, billing contacts and support history.
  • Data obtained from customer-authorized integrations, limited to the configured scope and purpose of each integration.
03

Purposes and legal grounds

Data is processed to provide and administer the platform, authenticate users, measure consumption, execute contracted features, protect the service, answer requests, preserve audit evidence, comply with legal obligations, exercise rights, prevent fraud and manage commercial relationships.

Depending on the context, processing may rely on contract performance and pre-contract steps, legal obligations, exercise of legal rights, legitimate interests subject to necessity and balancing, and consent where required.

04

AI models and prompts

Some features send prompts and strictly necessary context to AI providers configured for the requested measurement or analysis. The actual provider set depends on tenant configuration and may include Base44-provided AI capabilities, OpenAI, Anthropic and Google, as well as optional providers enabled by the customer.

05

Sharing and subprocessors

M2.IA shares data only when needed to operate the service, follow customer instructions, comply with law, or protect rights and security. Providers that may process personal data on behalf of M2.IA are subject to controls proportionate to their function.

The current public register is available at Subprocessors.

06

International transfers

Infrastructure and AI providers may operate outside Brazil. Where an international transfer is subject to the Brazilian LGPD, M2.IA will rely on a legally permitted mechanism, which may include ANPD-approved standard contractual clauses, an adequacy decision or another lawful transfer mechanism applicable to the specific flow.

07

Retention and deletion

Personal data is retained for as long as required for the disclosed purposes, the contractual relationship, legal obligations, security, fraud prevention, audit and exercise of rights. Customer data is deleted or returned in accordance with the contract, applicable DPA and technical limitations, subject to lawful retention requirements.

08

Security

The platform uses access controls, tenant segregation, least-privilege principles, audit trails, credential protections, secrets management, scope validation and operational readiness controls. No measure eliminates all risk, and controls are reviewed as the architecture and processing risks evolve.

09

Security incidents

Incidents involving personal data are assessed based on nature, impact, affected individuals, containment and notification requirements. When M2.IA acts as processor, it will notify the customer controller without undue delay after becoming aware of a relevant incident. When acting as controller, it will follow applicable notification requirements to the ANPD and affected individuals.

10

Data subject rights

Subject to applicable law, individuals may request confirmation of processing, access, correction, anonymization, blocking or deletion of improper data, portability where regulated, information about sharing, withdrawal of consent and other legally established rights. Where a corporate customer controls the relevant data, M2.IA may redirect the request to that customer and provide contractual assistance.

11

Cookies and similar technologies

The websites and platform may use local storage, cookies or similar technologies required for authentication, security, preferences, sessions and product measurement. Non-essential technologies subject to consent will be handled through an appropriate choice mechanism.

12

Children and sensitive data

M2 Visibility is designed for professional and enterprise use and is not directed to children. Customers should not submit sensitive personal data or children’s data through prompts, integrations or datasets unless a valid legal basis, documented necessity and appropriate controls have been established.

13

Changes

This Policy may be updated to reflect legal, technical, contractual or operational changes. Material changes will be identified by a new effective date and communicated through an appropriate channel when required.

14

Contact

Legal and privacy contact

M2.IA Consultoria em Tecnologia da Informação, Brazilian CNPJ 62.138.251/0001-94, Brazil.

contato@m2ia.app