Skip to content

Data Processing Agreement (DPA)

Last updated: 02 October 2026 · Version 2.0

This is a translation of the Portuguese original. Where the two differ, the Portuguese version prevails.

This Data Processing Agreement (the “DPA”) forms part of the Terms of Use and Service and of any contract between 6PS MEDIA GROUP LTDA (“6PS” or “the Processor”), CNPJ 12.829.681/0001-84, and its clients (“the Client” or “the Controller”). It applies whenever 6PS processes personal data on the Client’s behalf in delivering any technology Service: development, hosting, operation, integration, automation, artificial intelligence, digital communication, support or others.

1. Definitions

The terms “personal data”, “sensitive personal data”, “data subject”, “processing”, “controller”, “processor”, “sub-processor”, “security incident” and “ANPD” carry the meaning given by Law 13.709/2018 (the LGPD) and the ANPD’s rules. Where other data protection laws apply, such as the GDPR, the equivalent terms are read in line with those laws.

2. Roles of the parties

2.1. The Client is the Controller and defines the purposes and the essential means of the processing. 6PS is the Processor and processes the data solely on the Client’s behalf.

2.2. The Client warrants that it holds a valid legal basis for the processing, that it has given data subjects the information the law requires, and that its instructions comply with the law.

2.3. Where 6PS processes data for its own purposes, for example billing, security and the client relationship, it acts as a controller, under the Privacy Policy.

3. Scope of the processing

Item Description
Subject matter Delivery of the contracted Services
Duration The term of the contract, plus the return or deletion period
Nature Collection, storage, organisation, processing, transmission, integration between systems, analysis and deletion, according to the Service
Categories of data subjects Clients, end users, leads, staff, partners and other people whose data the Client enters or processes in the Services
Categories of data Identification, contact, content of communications, account and access data, technical and usage data, and others the Client defines
Sensitive data Only where the Specific Terms provide for it, with additional safeguards

Details specific to each Service may be set out in the Specific Terms or in the contract.

4. Obligations of 6PS

6PS undertakes to:

  1. process the data only under the Client’s documented instructions, whether in the contract, this DPA, the Service’s settings or written communications, and to say so if it considers an instruction unlawful;
  2. not use the data for its own purposes, not sell it, and not use it to train general purpose artificial intelligence models without the Client’s express authorisation;
  3. ensure that the people authorised to process the data are bound by a duty of confidentiality;
  4. apply the security measures in section 6;
  5. assist the Client, so far as is reasonable, in answering data subject requests, in impact assessments, and in requests from the ANPD;
  6. report security incidents under section 7;
  7. return or delete the data at the end of the contract, under section 9;
  8. make available the information needed to demonstrate compliance with this DPA.

5. Sub-processors

5.1. The Client gives general authorisation for the engagement of sub-processors needed to deliver the Services, in the following categories: cloud infrastructure and hosting; storage and backup; databases; email and communication; monitoring and observability; support; payment processing; artificial intelligence; and third party platforms integrated at the Client’s choice.

5.2. 6PS keeps a current list of sub-processors, available to the Client on request to dpo@6ps.group, and will give reasonable notice of adding or replacing a relevant sub-processor. The Client may object on reasoned grounds; if no solution is found, it may terminate the affected Service.

5.3. 6PS will impose on sub-processors data protection obligations equivalent to those in this DPA, and remains answerable to the Client for their performance, to the extent the law allows.

5.4. Third party platforms chosen by the Client, for example where the Client decides to integrate the Service with a messaging platform, social network, CRM, ERP or payment provider of its choosing, on its own account, process the data under their own terms, in a direct relationship with the Client, and are not sub-processors of 6PS.

6. Security measures

6PS maintains technical and administrative measures appropriate to the risk, including:

  • encryption of data in transit and, where applicable, at rest;
  • least privilege access control, strong authentication and periodic access review;
  • segregation of environments and of data between clients;
  • logging and monitoring of events and access;
  • backups and recovery procedures;
  • vulnerability and patch management;
  • management of suppliers and sub-processors;
  • training and confidentiality undertakings from the team.

7. Security incidents

7.1. 6PS will notify the Client without undue delay and, wherever possible, within 48 (forty-eight) hours of becoming aware of a security incident affecting data processed on the Client’s behalf.

7.2. The notice will contain, so far as it is available: a description of the incident, the nature and categories of data and data subjects affected, the likely consequences, the measures taken, and a contact point.

7.3. It falls to the Client, as Controller, to assess and make the notifications to the ANPD and to data subjects, with reasonable support from 6PS.

8. International transfers

Where the processing involves transferring data outside Brazil, for example through cloud providers or third party platforms with servers abroad, the transfer will follow article 33 of the LGPD and the ANPD’s rules, through standard contractual clauses, adequate safeguards or another applicable legal ground.

9. Termination, return and deletion

At the end of the Service, 6PS will, as the Client instructs, return the data in a structured and commonly used format or delete it within 30 (thirty) days, unless the contract sets a different period, and save for retention required by law or needed to exercise its rights, during which the data stays protected by this DPA. Backup copies are deleted on the regular rotation cycle.

10. Audit

The Client may request information and documentation evidencing compliance with this DPA. On-site audits, or audits by an independent third party, may be carried out on 30 (thirty) days’ notice, at most once a year, except in the event of an incident or a requirement from an authority, during business hours, under confidentiality and at the Client’s expense.

11. Liability

Each party is liable for the damage it causes in breach of data protection law or of this DPA, under articles 42 to 45 of the LGPD. The limitations of liability in the Terms of Use and Service, or in the contract, apply to the fullest extent the law permits.

12. Precedence and term

This DPA is in force for as long as 6PS processes personal data on the Client’s behalf. On matters of data protection it prevails over the Terms of Use and Service; a DPA signed individually between the parties prevails over this public version.

13. Contact

Data Protection Officer: José Wilker T. de Araujo · dpo@6ps.group 6PS MEDIA GROUP LTDA · CNPJ 12.829.681/0001-84 Rua Bananeiras, 361, Sala 101, Caixa Postal 279, Manaíra, João Pessoa/PB, CEP 58038-170, Brazil

Legal

6PS MEDIA GROUP LTDA — CNPJ 12.829.681/0001-84
Rua Bananeiras, 361, Sala 101, Caixa Postal 279, Manaíra, João Pessoa/PB, CEP 58038-170