This Data Processing Agreement ("DPA") is entered into between INKOUST CONSULTORIA E AGENCIA DE MARKETING E TECNOLOGIA LTDA ("Processor") and you, the subscribing organization ("Controller"), and forms part of the Terms of Service. This DPA governs the processing of personal data in accordance with GDPR Article 28, LGPD Article 14, and equivalent provisions under applicable data protection laws.
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person, as defined under GDPR and LGPD.
- Processing: Any operation performed on personal data, including storage, analysis, and deletion.
- Data Subject: The individual whose personal data is being processed.
- Sub-processor: A third party engaged by the Processor to process personal data.
2. Subject Matter and Duration
This DPA applies to all processing of personal data by HX OS on behalf of the Controller in connection with the provision of the CORA strategic intelligence platform. The DPA remains in force for the duration of the Terms of Service and continues until all personal data has been deleted or returned per Section 9.
3. Nature and Purpose of Processing
HX OS processes personal data for the following purposes:
- Account management and authentication
- Delivery of AI-powered brand diagnosis and strategic recommendations
- Billing and subscription management
- Platform security and audit logging
- Aggregated, anonymized benchmark intelligence generation (no PII included)
4. Types of Personal Data Processed
- User account data: name, email address, organization name
- Billing information (managed by Stripe; HX OS does not store raw payment card data)
- Usage metadata: session data, feature interactions, diagnostic events
- Strategic input data: brand descriptions, positioning narratives, market data (may contain personal data if input by Controller)
5. Processor Obligations
The Processor (HX OS) agrees to:
- Process personal data only on documented instructions from the Controller
- Ensure personnel authorized to process personal data are bound by confidentiality
- Implement appropriate technical and organizational security measures (Article 32 GDPR)
- Respect conditions for engaging sub-processors (Section 7)
- Assist the Controller in responding to Data Subject requests
- Assist the Controller with security obligations, breach notifications, DPIAs, and prior consultations
- Delete or return personal data upon termination (Section 9)
- Provide all information necessary to demonstrate compliance with this DPA
6. Controller Obligations
The Controller agrees to:
- Ensure there is a lawful basis for all personal data processing instructions
- Provide accurate and complete data to HX OS
- Maintain appropriate privacy notices for Data Subjects
- Not instruct HX OS to process personal data in a way that violates applicable law
7. Sub-processors
The Processor may engage sub-processors to perform specific processing activities. Current approved sub-processors:
| Sub-processor | Location | Processing activity |
|---|
| Stripe, Inc. | USA / EU | Payment processing and billing |
| Base44 (infrastructure) | USA / EU | Cloud hosting, database storage |
| Google Cloud / Analytics | USA / EU | Infrastructure and anonymized analytics |
The Processor will notify the Controller of any intended changes to sub-processors with at least 30 days' notice, allowing the Controller to object.
8. International Transfers
Where personal data is transferred to countries outside the EEA or Brazil without an adequacy decision, the Processor will ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission and/or ANPD-compliant mechanisms.
9. Data Return and Deletion
Upon termination of the Terms of Service or upon written request from the Controller:
- The Processor will delete all personal data within 30 days
- The Processor will provide written confirmation of deletion upon request
- Data required by law (billing records, audit logs) will be retained for the legally mandated period and then deleted
10. Security Measures
The Processor implements the following technical and organizational measures (TOMs):
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for data at rest
- Multi-tenant data isolation (each organization's data is logically separated)
- Role-based access control (RBAC) with audit logging
- Regular vulnerability assessments
- Incident response procedures with 72-hour notification capability
- Employee confidentiality training and agreements
11. Data Breach Notification
In the event of a personal data breach, the Processor will notify the Controller without undue delay and within 72 hours of becoming aware of the breach, providing sufficient information for the Controller to meet its own notification obligations under GDPR Article 33 and LGPD Article 48.
12. Data Subject Rights
The Processor will assist the Controller in fulfilling obligations to respond to Data Subject rights requests (access, correction, deletion, portability, restriction, objection) within the timeframes required by applicable law. Submit requests to privacy@coracodex.xyz.
13. Governing Law
This DPA is governed by the law of the Federative Republic of Brazil, with GDPR standards applied for EU/EEA data subjects.
14. Contact
Data Controller / DPA Contact
INKOUST CONSULTORIA E AGENCIA DE MARKETING E TECNOLOGIA LTDA
CNPJ: 29.702.964/0001-63
Email:
privacy@coracodex.xyz