
The Belo AI Data Processing Agreement covering processing instructions, security measures, subprocessors, transfers, retention, and audit rights.
Effective date: 2026-07-26
This DPA forms part of the Agreement between Customer and Belo for the Services and applies only to Customer Personal Data processed by Belo as processor/operator, without prejudice to the provisions of the Privacy & Data Notice. In case of conflict, the Order Form prevails; then, the Corporate/BYOC Addendum as to its subject matter; this DPA as to data protection; and, finally, the Terms.
In case of conflict: Order Form > Corporate/BYOC Addendum (if applicable) > this DPA > Terms of Service.
Capitalized terms not defined here have the meaning given in the Agreement.
2.1 Customer is the Controller. Belo is the Processor / Operator for Personal Data processed on Customer's documented instructions in providing the Services.
2.2 Belo processes Personal Data only:
(a) to provide and support the Services; (b) on Customer's documented instructions (including the Services configuration and this DPA); and (c) as required by applicable law (in which case Belo informs Customer unless legally prohibited).
2.3 The subject matter, duration, nature, purpose, categories of data, and data subjects are described in Annex A.
2.4 Customer is responsible for the lawfulness of its instructions and for providing all notices and obtaining all rights/consents required for Belo to process Personal Data.
2.5 Hosted SaaS and BYOC. This DPA applies to Belo's processing of Customer Personal Data, regardless of whether the data is in a Belo-hosted environment or in BYOC, whenever Belo actually accesses, receives, records, or processes that data on Customer's behalf. In BYOC, Customer Content remains, by default, in Customer's environment and is not processed by Belo; license heartbeats are processed by Belo as an independent controller. Exceptional access for support, logs, diagnostics, snapshots, or data shared with Belo is subject to this DPA to the extent it constitutes processing as a processor.
(a) Customer Content remains in Customer's cloud under the Corporate/BYOC Addendum and is not processed as processor data under this DPA; and (b) license-heartbeat metadata is processed by Belo as an independent controller under clause 6.5 of the Corporate/BYOC Addendum (and not as a processor under this DPA); international transfers of any heartbeat Personal Data follow clause 6.5.5 of that Addendum and the Privacy & Data Notice — and not the processor role map in Annex C of this DPA.
Customer instructs Belo to process Personal Data exclusively to provide the Services as described in the Agreement and Annex A. Belo will promptly inform Customer if, in Belo's opinion, an instruction violates applicable Data Protection Laws (without an obligation to provide legal advice).
Belo ensures that persons authorized to process Personal Data are bound by confidentiality obligations and informed of the relevant data-protection requirements.
Belo will implement and maintain technical and organizational measures appropriate to the risk and consistent with Annex B. Belo may update measures to keep pace with technical developments, provided that it does not materially reduce the overall level of protection during the contracted term. No reference to a practice, roadmap, or control not yet implemented constitutes a certification, absolute warranty, or commitment to a result, unless expressly assumed in an Order Form.
Belo implements and maintains technical and organizational measures appropriate to the risk, described in Annex B, including encryption in transit and at rest for primary systems, access control, logging, vulnerability management, backups, and incident response.
This DPA does not represent that Belo holds SOC 2, ISO 27001, or similar certifications. Audit evidence is provided as available under §11.
6.1 General authorization. Customer grants general authorization for the Subprocessors identified in the Subprocessor List, including the listed alternatives for the same function. Belo may use any listed provider for that function and may switch among those listed alternatives without additional notice. Adding a Subprocessor that is not already identified on the List, or a material replacement that is not a listed alternative for that function, requires notice under §6.3. Belo remains responsible for Subprocessors' compliance with this DPA to the extent required by applicable law.
6.2 Belo will bind each Subprocessor to data-protection obligations that are substantially no less protective than this DPA.
6.3 Notice. Belo will notify Customer of the addition of a Subprocessor that is not already identified on the List, or a material replacement that is not a listed alternative for that function, at least fifteen (15) days in advance, by updating the List and, for subscribed customers, by electronic alert. The notice will identify the function and main processing location where available. Editorial or corporate changes, and switches among listed alternatives for the same function, without a material change in risk do not require a new notice period.
6.4 Objection. Customer may object during the notice period on reasonable and documented data-protection grounds. The parties will seek a good-faith solution, including a commercially reasonable alternative configuration. If there is no solution, Customer may terminate only the affected component as a contractual remedy, without prejudice to non-waivable rights. The objection may not be used to prevent a replacement required for security or legal compliance.
6.5 Emergency replacements for security or legal reasons may occur with a shorter notice period; Belo will notify Customer as soon as practicable.
Belo will provide reasonable assistance to Customer in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection, and review of automated decisions under LGPD Article 20 where applicable), taking into account the nature of the Processing and the information available to Belo.
Where feasible, Org-level export and deletion tools may help Customer fulfill requests programmatically. Customer remains primarily responsible for responding to requests from its end users.
8.1 Belo will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data and, where reasonably possible, will seek to issue an initial notice within 24 hours of confirmation. Notification may be phased and does not depend on completion of the investigation.
8.2 Belo will provide, as available: the nature of the Incident, approximate categories of data and data subjects, likely consequences, measures taken or proposed, and a contact point. Customer is responsible for determining and making communications to the ANPD, data subjects, or authorities, except for Belo's direct legal obligations. Belo will provide reasonable cooperation and will not make a public communication on Customer's behalf without authorization, except where legally required.
8.3 Customer will promptly notify Belo of compromised credentials, insecure configurations, unlawful instructions, or incidents under its control that may affect the Services. Extraordinary assistance costs arising from Customer's act may be charged subject to prior agreement, except where the incident is attributable to Belo.
8.4 Notification will include available details about the nature of the incident, the categories/approximate volume of data subjects and records (if known), likely consequences, and measures taken or proposed.
8.5 Where the GDPR applies, notification will be made without undue delay and, at the latest, within 72 hours after Belo becomes aware of GDPR-relevant incidents, unless a different contractual window is expressly provided in the Order Form.
8.6 Belo will reasonably cooperate with Customer's investigation and remediation.
Customer acknowledges that Personal Data may be processed in countries where Belo and Subprocessors operate. The Subprocessor List is the authoritative, current statement of the cloud-infrastructure providers identified for hosting, including listed alternatives for the same function. Belo will ensure a lawful transfer mechanism under applicable Data Protection Laws, in accordance with the modular schedule below.
Where there is an international transfer subject to the LGPD, the parties will use a valid mechanism provided for in Article 33, including an adequacy decision or the standard contractual clauses of ANPD Resolution CD/ANPD No. 19/2024. When standard contractual clauses are used, their fields and annexes will be completed with information from this DPA, the Order Form, and the Subprocessor List, without changing the mandatory text.
This module applies whenever there is an international transfer of Personal Data subject to the LGPD that requires standard contractual clauses under Article 33, II, b. It is not optional and does not depend on selection in the Order Form.
The parties incorporate by reference the official standard contractual clauses adopted by ANPD Resolution CD/ANPD No. 19/2024, as published by the ANPD/DOU, without unauthorized alteration.
Role map (default for this DPA — hosted SaaS only):
Outside the scope of this table / Annex C: BYOC license heartbeats (Belo as independent controller). See Corporate/BYOC Addendum §6.5.5 and the Privacy & Data Notice.
Annex C records the incorporation. The official ANPD text prevails over any summary. Supplementary measures include encryption in transit and at rest, access control, and routing minimum data to model providers (Annex B).
Where a hosted transfer is also necessary under Article 33, IX because it is necessary to meet Article 7, II, V, or VI (the only Article 7 grounds that Article 33, IX incorporates), that basis applies in parallel to the extent permitted. Article 7, IX (legitimate interest) is a processing basis and does not, by itself, open Article 33, IX for international transfer.
Where the GDPR or UK GDPR applies and the transfer requires a safeguard, the European Commission SCCs, the appropriate modules, and the UK Addendum or IDTA, as applicable, apply. The parties will cooperate with transfer impact assessments and reasonable supplementary measures. Incorporation does not replace completion of mandatory selections and annexes where necessary.
This module applies when the GDPR and/or UK GDPR applies to Personal Data processed under this DPA (a legal trigger — Article 3 and equivalents — and not a mere commercial option of Customer). Documentary completion of the module (completion of SCC / IDTA annexes) takes place through the Order Form or a transfer addendum, without the absence of a completed form suspending applicable legal obligations.
When the module applies:
(a) EU: the European Commission Standard Contractual Clauses (Module Two: Controller → Processor, and Module Three: Processor → Processor where applicable) are incorporated by reference and completed with the details in Annexes A/B and the Subprocessor List; (b) United Kingdom: the UK International Data Transfer Addendum (or IDTA) is incorporated as required by United Kingdom law.
Completion details: Annex D.
Transfers subject to Swiss data-protection law will use the EU SCCs with the modifications required by Switzerland, where applicable. This module is reserved for documentary activation when Swiss processing volume or risk warrants it; legal application, if any, does not depend on the commercial reservation.
Belo will retain Customer Personal Data only for the period necessary for provision, documented instructions, and legal obligations. After termination or a valid request, it will delete or return active data within thirty (30) days, except for a different period in the Order Form, a reasonable technical impediment, or legal retention. Backup copies will be protected, will not return to ordinary use, and will be deleted according to the applicable cycle. Belo may retain minimal evidence for security, billing, and defense of rights.
Customer may audit compliance with this DPA once per year, on 30 days' notice, during business hours and without undue interference. Belo may satisfy the request primarily through available reports, questionnaires, policies, and independent evidence. An on-site or direct technical audit depends on demonstrated need, agreed scope, confidentiality, protection of other customers, and reimbursement of reasonable costs, except for a proven material breach attributable to Belo.
Belo may satisfy audit requests by providing available third-party reports, questionnaires, and documentation. No certification is promised by this clause.
Belo will not use Customer Personal Data or Customer Content to train or fine-tune foundation models. Model providers are engaged under terms that restrict training on customer inputs for the enterprise API configurations Belo uses. De-identified/aggregated telemetry for product improvement remains as described in the Privacy & Data Notice and the Terms and does not include training on Customer Content.
The parties' liability under this DPA forms part of, and does not expand, the limitations, exclusions, and remedies of the Agreement, except to the extent mandatory law prohibits limitation. No provision limits liability to data subjects or authorities where legally non-waivable, without prejudice to the parties' right of recourse according to fault, causation, and assumed obligations.
This DPA is governed by the governing law of the Agreement (Brazilian law for the standard Terms), without prejudice to mandatory Data Protection Laws and any arbitration/forum terms in the Agreement.
This DPA may be accepted by signature, an Order Form, or electronic acceptance that incorporates it and identifies its version. For enterprise customers, Belo will maintain reasonable evidence of incorporation. If law or standard contractual clauses require signature or additional completion, the parties will cooperate to complete the documentation.
This Annex is operationalized by incorporation by reference and applies exclusively to Customer Personal Data processed in Belo-hosted environments.
The official standard contractual clauses of ANPD Resolution CD/ANPD No. 19/2024 will be applied when necessary and integrated with selections and annexes completed from this DPA, the Order Form, and the Subprocessor List. The official text prevails and may not be modified except in fields expressly permitted.
Upon written request, the parties will exchange a PDF copy of the official clauses or complete module tables required by the official text with the details in Annexes A/B and the Subprocessor List.
Default role map for this Annex: Customer = controller/exporter where applicable; Belo = processor/operator-importer of hosted Personal Data; Subprocessors = onward importers under written terms.
BYOC heartbeats are excluded from this Annex. Heartbeat transfers (if any field is Personal Data and leaves Brazil) are governed by Corporate/BYOC Addendum §6.5.5 (Belo as independent controller; controller-to-controller SCCs and/or Article 33, IX as applicable), and not by this processor role map.
No party may invoke an altered private rewrite of the official SCC text; the official public instrument controls.
Official source: ANPD Resolution CD/ANPD No. 19/2024 (standard contractual clauses for international transfers).
Complete when the GDPR and/or UK GDPR applies to Personal Data processed (see §9.3); documentary execution takes place through the Order Form or an addendum:



Belo AI



Jun 16