How we handle your personal data
This policy describes, in clear language, how MyDatAgent collects, uses, stores, and protects your personal data, in compliance with the General Data Protection Law (Law 13.709/2018) and international privacy best practices.
1. Who we are · data controller
MyDatAgent, hereinafter "MDA", is a Brazilian company based in São Paulo (CNPJ 00.000.000/0001-00). We act as a controller of personal data collected on our website and as an operator of data that customers entrust to us for processing via our platform.
2. What data we collect
We collect only what's necessary to deliver our services. The categories are:
| Category | Purpose | Legal basis (LGPD) |
|---|---|---|
| Registration · name, corporate email, job title, company, WhatsApp | Responding to requests · scheduling meetings · technical materials | Consent (art. 7, I) |
| Navigation · IP, device, pages viewed, reading time | Product analysis · site improvement · fraud prevention | Legitimate interest (art. 7, IX) |
| Functional cookies · session, preferences | Site functionality · personalization | Consent |
| Communication · message history with our team | Support · relationship history | Contract performance (art. 7, V) |
We don't collect sensitive data (health, biometrics, religion, etc.) through the public website. For customers in production, sensitive data may be processed per specific contract (DPA).
3. How we use your data
- Respond to your contact and schedule demos or technical conversations;
- Send relevant technical content (whitepapers, blog posts, product updates) — you can unsubscribe anytime;
- Improve the site and product through aggregated usage analysis (without individual identification);
- Prevent fraud and ensure the security of our infrastructure;
- Comply with legal obligations (tax, regulatory, judicial).
We never sell your data. We never use your registration data to train public AI models. We practice what we preach.
4. Who we share with
We share data only with strictly necessary operators:
- HubSpot · CRM and marketing — with DPA and ANPD standard clauses;
- AWS Brazil (sa-east-1) · hosting our infrastructure;
- Google Workspace · corporate email and calendar;
- Payment providers · only for active customers with contracts.
All operators sign a data processing agreement (DPA) and are bound by the same security and privacy standards we follow.
5. International transfer
Our product infrastructure operates entirely in a Brazilian datacenter (AWS sa-east-1). Some operational tools (HubSpot, Google Workspace) may process data in the United States under contractual guarantees (ANPD/EU Standard Clauses). For use of our production AI platform, we guarantee by contract (DPA) that no customer data crosses borders.
6. Your rights as a data subject
Per article 18 of LGPD, you have the right to:
- Confirm whether your data is being processed;
- Access the data we hold about you;
- Correct incomplete, inaccurate, or outdated data;
- Anonymize, block, or delete unnecessary or non-compliant data;
- Port your data to another provider;
- Delete data processed with your consent;
- Obtain information on who we share your data with;
- Revoke consent at any time;
- Request review of automated decisions that affect you.
To exercise any right, contact the DPO: dpo@mydatagent.ai — response within 15 business days.
7. How long we keep your data
- Lead registration — up to 3 years after last contact (then anonymized);
- Active customer — during contract + 5 years for tax compliance;
- Navigation logs — 6 months;
- Marketing communications — until you unsubscribe.
8. How we protect your data
We implement technical and organizational measures aligned with international best practices:
- Encryption in transit (TLS 1.3) and at rest (AES-256);
- Access based on least privilege principle (RBAC) with mandatory Single Sign-On;
- Automatic PII masking (Microsoft Presidio) in any flow touching AI;
- Auditable and immutable logs of all sensitive operations;
- Certifications SOC 2 Type I & II and ISO/IEC 27001.
In case of a security incident, we notify ANPD and affected data subjects within 72 hours, per LGPD article 48.
9. Changes to this Policy
We may update this policy to reflect regulatory or operational changes. Material changes will be communicated at least 30 days in advance via email and/or prominent notice on the site. The current version published on this page is always the one in effect, with the date and version number at the top.
Questions, requests, or exercising your rights
Data Protection Officer (DPO): Fernando Outa
Email: dpo@mydatagent.ai · response within 15 business days per LGPD article 19.