
The Belo AI Data Processing Agreement covering processing instructions, security measures, subprocessors, transfers, retention, and audit rights.
Status: DRAFT — shown on the production site
Why: processor terms (LGPD/GDPR) for hosted SaaS.
When users see it: public page /page/legal-dpa; Trust Center link.
URL: 1
Translations: pt-BR · EN · es-ES · fr-FR (same path; app locale)
Source: rascunho 2026-07-11
This DPA forms part of the agreement between Customer and Belo for the Services (Terms of Service + Order Form / Enterprise Agreement, as applicable) (the “Agreement”).
If there is a conflict: Order Form > this DPA > Terms of Service.
Capitalized terms not defined here have the meaning in the Agreement.
2.1 Customer is Controller (Controlador). Belo is Operator/Processor (Operador) for Personal Data processed on Customer’s documented instructions in providing the Services.
2.2 Belo processes Personal Data only:
(a) to provide and support the Services;
(b) on Customer’s documented instructions (including configuration of the Services and this DPA); and
(c) as required by applicable law (in which case Belo informs Customer unless legally prohibited).
2.3 Subject matter, duration, nature, purpose, categories of data, and data subjects are described in Annex A.
2.4 Customer is responsible for the lawfulness of its instructions and for providing all notices and obtaining all rights/consents required for Belo to process Personal Data.
2.5 Hosted SaaS vs BYOC. This DPA applies to hosted SaaS processing where Customer Content / Personal Data is processed in Belo-operated environments. For BYOC deployments, Customer Content generally remains in Customer’s cloud; processing of any residual Personal Data (if any) in license heartbeats is addressed in the Corporate/BYOC Addendum and remains [OPEN — COUNSEL] as to personal-data classification of specific fields. Do not treat this DPA as asserting that Belo is (or is not) a processor of BYOC heartbeat fields until counsel resolves that question.
Customer instructs Belo to process Personal Data solely to provide the Services as described in the Agreement and Annex A. Belo shall promptly inform Customer if, in Belo’s opinion, an instruction violates applicable Data Protection Laws (without obligation to provide legal advice).
Belo ensures that persons authorized to process Personal Data are bound by confidentiality obligations and informed of relevant data-protection requirements.
Belo implements and maintains technical and organizational measures appropriate to the risk, described in Annex B, including encryption in transit and at rest for primary systems, access control, logging, vulnerability management, backups, and incident response.
This DPA does not represent that Belo holds SOC 2, ISO 27001, or similar certifications. Audit evidence is provided as available under §11.
6.1 Customer authorizes Belo to engage Sub-Processors listed in the then-current Subprocessor List published by Belo.
6.2 Belo will bind each Sub-Processor to data-protection obligations substantially no less protective than this DPA.
6.3 Notice. Belo will provide paid Customers at least thirty (30) days’ advance notice before adding or replacing a material Sub-Processor (email and/or update to the Subprocessor List with subscription option).
6.4 Objection. If Customer reasonably objects to a new Sub-Processor on data-protection grounds within the notice period, the parties will discuss in good faith. If unresolved before the change takes effect, Customer may terminate the affected Services as its sole remedy (fees prepaid for unused periods handled per the Agreement / mandatory law).
6.5 Emergency replacements for security or legal reasons may occur with shorter notice; Belo will notify as soon as practicable.
Belo will provide reasonable assistance to Customer in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection, and automated-decision review under LGPD Art. 20 where applicable), taking into account the nature of Processing and information available to Belo.
Where feasible, Org-level export and deletion tooling may help Customer fulfill requests programmatically. Customer remains primarily responsible for responding to requests from its end users.
8.1 Belo will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Data processed under this DPA.
8.2 Brazil / LGPD support window. To support Customer’s controller obligations under ANPD Resolution CD/ANPD nº 15/2024 (controller notification to ANPD within three (3) business days of awareness for incidents with relevant risk/damage), Belo will use commercially reasonable efforts to notify Customer within three (3) business days of Belo’s awareness of a qualifying Security Incident — and earlier where practicable — so Customer can meet its own deadlines.
Note for counsel: The statutory 3-business-day clock runs on the controller. This clause is a processor support commitment to Customer, not a reassignment of controller duties to Belo.
8.3 Notification will include available details about the nature of the incident, categories/approximate volume of data subjects and records (if known), likely consequences, and measures taken or proposed.
8.4 Where GDPR applies, notification will also be made without undue delay and, where the Agreement so requires, within any shorter contractual window (e.g., 24–72 hours) if expressly stated in the Order Form. Default draft: without undue delay and no later than 72 hours after Belo’s awareness for GDPR-relevant incidents, unless a different period is agreed.
8.5 Belo will reasonably cooperate with Customer’s investigation and remediation.
Customer acknowledges that Personal Data may be processed in countries where Belo and Sub-Processors operate (see Subprocessor List). Belo will ensure a lawful transfer mechanism under applicable Data Protection Laws.
For international transfers of Personal Data subject to the LGPD that require standard contractual clauses, the parties intend to rely on the official standard contractual clauses adopted by ANPD Resolution CD/ANPD nº 19/2024.
[OPEN — COUNSEL — ATTACHMENT MECHANICS]
Placeholder Annex C: “Official ANPD Resolution CD/ANPD nº 19/2024 Standard Contractual Clauses — [PDF to be attached / official citation to be inserted by counsel before external use].”
Until Annex C is attached or validly incorporated, this §9.2 is non-operative for transfers that depend on those SCCs.
If Customer Personal Data is subject to GDPR and/or UK GDPR and the parties select this module in the Order Form or a transfer addendum:
(a) EU: the European Commission Standard Contractual Clauses (Module Two: Controller → Processor, and Module Three: Processor → Processor where applicable) are incorporated by reference and completed with the details in Annex A/B and the Subprocessor List;
(b) UK: the UK International Data Transfer Addendum (or IDTA) is incorporated as required by UK law;
(c) Swiss transfers use the EU SCCs with Swiss-required modifications where applicable.
If this optional module is not selected, EU/UK SCCs are not automatically in force solely by this draft.
Belo retains Personal Data only as long as needed to provide the Services or as required by law. Upon termination of the Services or written request, Belo will delete or return Personal Data within thirty (30) days and, upon request, certify deletion, unless law requires continued retention (including backups until expiry of backup cycles).
Customer may audit Belo’s Processing activities related to this DPA with at least thirty (30) days’ prior written notice, no more than once per year (unless a Security Incident or regulatory requirement justifies an additional audit), during business hours, subject to confidentiality and reasonable security constraints.
Belo may satisfy audit requests by providing available third-party reports, questionnaires, and documentation. No certification is promised by this clause.
Belo will not use Customer Personal Data or Customer Content to train or fine-tune foundation models. Model providers are engaged under terms that restrict training on customer inputs for the enterprise API configurations Belo uses. De-identified/aggregated telemetry for product improvement remains as described in the Privacy & Data Notice and Terms, and does not include training on Customer Content.
Liability under this DPA is subject to the limitations and exclusions in the Agreement, except where mandatory Data Protection Laws prohibit limitation. This DPA lasts for the term of the Services and survives as needed for post-termination deletion and confidentiality.
This DPA is governed by the governing law of the Agreement (Brazilian law for standard Terms), without prejudice to mandatory Data Protection Laws and any arbitration/court terms in the Agreement.
STATUS: PLACEHOLDER — COUNSEL TO ATTACH OFFICIAL TEXT OR CONFIRM INCORPORATION-BY-REFERENCE MECHANICS.
Official source: ANPD Resolution CD/ANPD nº 19/2024 (standard contractual clauses for international transfers).
Complete only when the optional EU/UK module is selected:
Apr 4
Mar 31
Mar 31
Belo AI



Jun 16
Jun 24