Privacy Policy | ACENA.AI

Privacy Policy

ACENA.AI Platform | Last updated: July 2025


1. Controller Identification

1.1. The ACENA.AI platform (“Platform”) is operated by VIVAMAIS MULTISSERVIÇOS LTDA, a company duly incorporated under the laws of the Federative Republic of Brazil, registered under CNPJ 61.944.506/0001-43, with its principal place of business in the city of São Paulo, State of São Paulo (“Controller,” “we,” “us,” or “our”).

1.2. Questions and requests relating to this Privacy Policy may be directed to our Data Protection contact at: info@acena.ai.

2. Scope and Applicability

2.1. This Privacy Policy describes how we collect, use, store, share, and protect personal data processed in connection with the ACENA.AI Platform, a Software-as-a-Service (SaaS) solution that enables clients (“Clients”) to deploy AI-powered conversational agents under their own brand (white-label deployment).

2.2. This Policy applies to: (a) Clients who subscribe to the Platform; (b) end users who interact with AI agents deployed by Clients; and (c) visitors to our websites and documentation portals.

2.3. Where Clients use the Platform to process personal data of their own customers, the Client acts as the independent controller of such data. Our role in relation to that data is limited to processing on behalf of the Client, as described in Section 7.

3. Definitions

3.1. For purposes of this Policy, the following terms shall have the meanings set forth below:

3.2. “Personal Data” means any information relating to an identified or identifiable natural person, as defined by applicable data protection legislation, including the Brazilian General Data Protection Law (Lei no. 13.709/2018, “LGPD”) and, where applicable, the European General Data Protection Regulation (EU 2016/679, “GDPR”).

3.3. “Processing” means any operation performed on Personal Data, whether automated or manual, including collection, recording, storage, use, transmission, and deletion.

3.4. “Client” means any legal or natural person who has entered into a subscription agreement for the Platform.

3.5. “End User” means any individual who interacts with a conversational agent deployed by a Client through the Platform.

3.6. “Third-Party LLM Provider” means any external large language model service provider selected and configured by the Client to power the conversational agents deployed on the Platform.

4. Categories of Personal Data Collected

4.1. We may collect and process the following categories of Personal Data depending on the context of interaction:

4.2. Client Account Data: name and surname of account holders and authorised administrators, business e-mail address, company name and tax identification number, billing address, and payment method metadata (no raw card numbers are stored by us).

4.3. Platform Usage Data: authentication tokens, IP addresses, browser type and version, operating system, session timestamps, feature interaction logs, and API request metadata.

4.4. Conversation Data: messages and inputs submitted by End Users to agents deployed by Clients. This data is transmitted to and processed by the Third-Party LLM Provider selected by the Client, subject to the privacy terms of that provider. We do not claim ownership of Conversation Data.

4.5. Configuration Data: agent settings, prompt templates, knowledge base content, and integration credentials uploaded or entered by Clients.

4.6. Support Data: communications submitted via support channels, including e-mail correspondence and any attachments voluntarily provided.

5. Purposes and Legal Bases for Processing

5.1. We process Personal Data only for lawful purposes, relying on one or more of the following legal bases under the LGPD and, where applicable, the GDPR:

5.2. Performance of Contract: to create and manage Client accounts, provide subscribed services, process payments, and send service-related communications (legal basis: execution of a contract, pursuant to Article 7, V of the LGPD).

5.3. Legitimate Interests: to monitor and improve the security, performance, and reliability of the Platform; to prevent fraud and abuse; and to compile aggregated, non-identifying analytics (legal basis: legitimate interests, pursuant to Article 7, IX of the LGPD, provided such interests do not override the data subject’s fundamental rights).

5.4. Legal Obligation: to comply with applicable tax, financial reporting, and regulatory requirements (legal basis: compliance with a legal obligation, pursuant to Article 7, II of the LGPD).

5.5. Consent: where we collect data for marketing communications, we rely on the data subject’s freely given, specific, and informed consent, which may be withdrawn at any time without detriment (legal basis: consent, pursuant to Article 7, I of the LGPD).

6. Clients as Independent Data Controllers

6.1. When a Client deploys an AI agent on the Platform, the Client is solely responsible for: (a) determining the purposes and means of processing Personal Data of End Users; (b) obtaining any consent or other lawful basis required by applicable law in relation to End User data; (c) complying with applicable data protection legislation in their jurisdiction; and (d) publishing their own privacy notices to End Users.

6.2. We provide technical infrastructure and contractual data processing terms that allow Clients to fulfill their obligations. The specific terms governing our role as a data processor on behalf of Clients are set out in the Data Processing Addendum available upon request.

7. Third-Party LLM Providers

7.1. The Platform is designed to integrate with Third-Party LLM Providers. The selection and configuration of any such provider is performed exclusively by the Client within the Platform settings.

7.2. When a Client selects a Third-Party LLM Provider, Conversation Data submitted by End Users will be transmitted to that provider in accordance with the Client’s configuration. We act solely as a technical intermediary for this transmission.

7.3. Clients are responsible for reviewing and accepting the terms of service and privacy policies of any Third-Party LLM Provider they configure. We do not represent or warrant the privacy practices of any Third-Party LLM Provider.

7.4. We do not use Conversation Data for training our own machine learning models unless explicitly agreed upon with the Client in writing.

8. Sharing of Personal Data

8.1. We do not sell Personal Data to third parties.

8.2. We may share Personal Data with the following categories of recipients solely to the extent necessary to fulfill the purposes described in Section 5:

8.3. Payment Processors: billing and payment services are provided by Stripe (for global transactions) and Mercado Pago (for transactions within Brazil). Payment data is processed in accordance with the respective processor’s privacy policy and applicable PCI-DSS standards.

8.4. Infrastructure Providers: cloud hosting, content delivery, and monitoring services may process Personal Data on our behalf under data processing agreements.

8.5. Professional Advisors: legal counsel, auditors, and accountants may access Personal Data under obligations of professional confidentiality.

8.6. Regulatory Authorities: we may disclose Personal Data to governmental authorities when required by applicable law or valid legal process.

9. International Data Transfers

9.1. Personal Data may be transferred to and processed in countries outside Brazil. Where such transfers occur, we implement appropriate safeguards, such as standard contractual clauses approved by applicable authorities, to ensure that the transferred data receives a level of protection equivalent to that afforded by Brazilian law.

9.2. Clients who select Third-Party LLM Providers located outside Brazil are responsible for ensuring that such transfers comply with applicable data protection laws in their respective jurisdictions.

10. Data Retention

10.1. We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law.

10.2. Account data is retained for the duration of the Client’s subscription and for a period of five (5) years following termination, unless a longer retention period is mandated by law.

10.3. Billing and transaction records are retained for the period required by Brazilian tax law, currently five (5) years.

10.4. Upon expiration of applicable retention periods, Personal Data will be securely deleted or anonymised.

11. Data Subject Rights

11.1. Depending on applicable law, individuals may have the right to: (a) confirm whether we process their Personal Data and obtain access to such data; (b) correct inaccurate or incomplete data; (c) request deletion of data processed without lawful basis; (d) obtain information about third parties with whom their data has been shared; (e) object to or request restriction of certain processing activities; (f) withdraw consent where processing is consent-based; and (g) lodge a complaint with the applicable supervisory authority, including the Autoridade Nacional de Proteção de Dados (ANPD) in Brazil.

11.2. Requests should be submitted to info@acena.ai. We will acknowledge requests within fifteen (15) business days and respond within the timeframes prescribed by applicable law.

11.3. End Users seeking to exercise rights regarding data processed by a Client’s agent should contact the Client directly, as the Client acts as the independent controller for such data.

12. Security Measures

12.1. We implement technical and organisational security measures appropriate to the nature and risk level of the data processed. These measures include, without limitation, encryption of data in transit and at rest, access controls based on the principle of least privilege, regular security assessments, and incident response procedures.

12.2. No security system is impenetrable. In the event of a data breach that poses a risk to the rights and freedoms of data subjects, we will notify affected parties and the relevant supervisory authority in accordance with applicable legal requirements.

13. Cookies and Tracking Technologies

13.1. Our web properties may use cookies and similar technologies for session management, security, analytics, and functionality purposes. Detailed information about our use of cookies is provided in our Cookie Notice, available on our website.

14. Amendments to This Policy

14.1. We reserve the right to amend this Privacy Policy at any time. We will notify Clients of material changes at least fifteen (15) days before they take effect, by e-mail to the registered account address or by notice within the Platform.

14.2. Continued use of the Platform after the effective date of any amendment constitutes acceptance of the updated Policy.

15. Governing Law and Jurisdiction

15.1. This Privacy Policy is governed by the laws of the Federative Republic of Brazil, with particular reference to Lei no. 13.709/2018 (LGPD) and other applicable legislation.

15.2. Any dispute arising out of or in connection with this Policy shall be submitted to the exclusive jurisdiction of the courts of the city of São Paulo, State of São Paulo, Brazil, to the exclusion of any other forum.

16. Contact

16.1. All privacy-related inquiries, requests, and notices should be directed to VIVAMAIS MULTISSERVIÇOS LTDA, by e-mail to info@acena.ai.