1. Purpose 1. This Data Protection Agreement ("DPA") is an integral part of the Service Agreement (“Contract”), both updated periodically, or any other applicable agreement between E-goi, Lda (hereinafter “E-goi”) and the “Client” who purchases Services from E-goi, collectively referred to as “Parties.” 2. All terms not defined in this Data Processing Agreement will have the meanings established in the Glossary of the Contract. For clarity, all references to the “Contract” will include this Data Processing Agreement (when applicable), as defined herein. 3. E-goi adheres to international data privacy protocols and will make every effort and resource available to ensure that personal and institutional data of individuals interacting with E-goi, whether directly (as system users) or indirectly (as recipients), is used appropriately and responsibly, and in full compliance with Regulation (EU) 2016/679 of the European Parliament and the Council, of April 27, 2016. 2. Definitions 1. The following definitions, within the scope of this agreement, have the reach attributed to them by the clauses set forth in this section: a. "Affiliate" means an entity that directly or indirectly controls, is controlled by, or is under common Control with an entity. b. "Contract" refers to E-goi's Terms of Use (at https://bo.egoiapp.com/legal/egoi-terms) or any other written or digital contract governing the provision of the Service to the Client, as these terms or contracts may be updated periodically. c. "Control" means ownership, voting power or similar interest representing 50% (fifty percent) or more of the then-outstanding interests of the subject entity. The term "Controlled" should be interpreted accordingly. d. “Personal data,” information relating to an identified or identifiable natural person (“data subject”); a natural person is considered identifiable if they can be identified, directly or indirectly. e. "Client Data" refers to personal data that E-goi processes on behalf of the Client via the Service, as more specifically described in this Data Processing Agreement. f. “Processing,” an operation or a set of operations performed on personal data or on sets of personal data, whether or not by automated means; g. “Data Controller” or “Controller” refers to the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data; h. “Data Processor” or “Processor” refers to a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller; i. “Consent” of the data subject refers to a freely given, specific, informed, and unambiguous indication of the data subject's wishes, by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them; j. “Personal data breach” refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed; k. "Data Protection Laws" refers to all applicable data protection laws and regulations relating to the processing of any portion of the Client Data under the Contract, including, where applicable, European Data Protection Laws (including the GDPR) and Non-European Data Protection Laws (including the LGPD). 2. Definitions not present in the Contract and used in this Addendum have the meaning given by Regulation (EU) 2016/679. 3. Roles and Responsibilities of the Parties 1. The Parties acknowledge and agree that, in the context of processing Client Data, E-goi acts as a Processor on behalf of the Client (whether the Client is the Data Controller or another Processor), unless otherwise stipulated in the Contract or any applicable Addendum. 4. Processing Details 1. The processing of personal data by E-goi (Processor) under the terms of the Contract and this DPA will be limited to and conducted in strict compliance with the terms of the following clauses: a. Subject of processing: provision of services, subject of the Contract. b. Duration of processing: personal data will be processed for the period corresponding to the duration of the services provided under the Contract, plus the time necessary for exercising all rights and fulfilling the obligations arising therefrom. c. Nature of processing: all processing operations inherent to the exercise of rights and fulfillment of obligations that are the subject of the Contract, and management of the respective contractual relationship. d. Categories of Data Subjects: Contacts (i.e., Client's subscribers and other individuals about whom the Client has provided information or who have interacted with the Client via the Service). e. Categories of Personal Data: The Client may upload, submit or otherwise provide certain personal data to the Service, the scope of which is typically determined and controlled by the Client at its sole discretion and may include, but is not limited to, the following types of personal data: Identification and contact data (e.g., name, date of birth, gender, general, occupation or other demographic information, address, title, contact information, including email address); personal interests or preferences (including purchase history, marketing preferences, and publicly available social media profile information); IT Information (e.g., IP addresses, usage data, cookie data, online browsing data, location data, browser data); financial information (e.g., credit card data, account data, payment information). 2. E-goi will never sell, lend, or transfer personal data, contact lists, or any other user or recipient data to third parties, except in compliance with a court request/order. 3. The content of the user's contact lists and their messages may be analyzed by E-goi for maintenance purposes, troubleshooting, or in the event of suspected violation of the contract terms or E-goi policies by the user. 4. E-goi will not modify or edit the content of messages or contact lists that comply with E-goi's Electronic Distribution Policy without the prior and explicit consent of the user who created those messages and contact lists. This does not include situations that are merely database corrections, incorrect addresses, and similar instances, where E-goi does not require any consent. 5. Processing Instructions 1. E-goi (Subprocessor) should only process personal data following documented instructions from the Client, unless required to do so by Union or Member State law applicable to E-goi. In such cases, E-goi must inform the Client of that legal requirement before processing, unless the law prohibits this for important public interest reasons. The Client can provide further instructions throughout the duration of personal data processing. These instructions should always be documented. 2. The Parties agree that the Agreement, including this Data Processing Agreement, along with the Client's configuration or use of any settings, variables, or options in the Service (as the Client may modify from time to time) constitute the Client's complete and final instructions to E-goi regarding the processing of Client Data. 3. E-goi stores registration data and statistical information concerning recipients listed in the user's contact list. 6. Client Compliance 1. The Client represents and warrants that: a. It is in compliance and will continue to comply with all applicable laws, including Data Protection Laws, concerning the processing of Client Data and processing instructions provided to E-goi. b. It is responsible for the legality of processing and data subjects' rights. c. It has obtained and will continue to obtain all necessary consents and rights according to Data Protection Laws to process Client Data for the purposes described in the Agreement. 2. The Client will be solely responsible for the accuracy, quality, and legality of Client Data and the means by which Client Data was acquired. 3. Without prejudice to the generality of the foregoing, the Client agrees that it will be responsible for complying with all applicable laws (including Data Protection Laws) applicable to Campaigns (as defined in the Agreement) or other content created, sent, or managed through the Service, including related to obtaining consents (when necessary) to send communications. 7. Legality of Client Instructions 1. The Client will ensure that E-goi's processing of Client Data in accordance with the Client's instructions will not cause E-goi to breach any applicable laws, regulations or rules, including, without limitation, Data Protection Laws. 2. E-goi will immediately notify the Client in writing, unless prohibited from doing so under European Data Protection Laws, if E-goi becomes aware or believes that any of the Client's data processing instructions violate European Data Protection Laws. 3. When the Client acts as a Subprocessor on behalf of a third-party Data Controller (or another intermediary of the final Data Controller), the Client warrants that its processing instructions, as outlined in the Agreement and this Data Processing Agreement, including its authorizations for E-goi to appoint Subprocessors pursuant to this Data Processing Agreement, have been authorized by the respective Data Controller. 4. The Client will act as the sole point of contact for E-goi, and E-goi will not need to interact directly with (nor provide notifications to or procure authorizations from) third-party Data Controllers except through regular provision of the Service as outlined in the Agreement. The Client will be responsible for forwarding any notifications received under this Data Processing Agreement to the relevant Data Controller, when applicable. 8. Confidentiality 1. E-goi will ensure that individuals authorized by E-goi to process Client Data (including its team, agents, and subcontractors) are under the appropriate (contractual or legal) obligations of confidentiality. 9. Security of Processing 1. E-goi implements robust technical and organizational measures to ensure the security of personal data, providing a level of protection appropriate to the risk associated with data processing. These measures include, but are not limited to, safeguarding data against a security breach that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access (personal data breach). Additionally, E-goi adopts advanced Information Security practices, aligned with internationally recognized standards and best practices, to mitigate risks related to confidentiality, integrity, and availability of personal data. For more details on E-goi's approach to Information Security, including specific measures and applicable policies, refer to the Information Security Document. This document details E-goi's practices and commitments to protect personal data processed within its services. 2. E-goi will only grant access to personal data being processed to its personnel members strictly as necessary for the execution, management, and monitoring of the contract. 3. The Client agrees that, except as stipulated in this Data Processing Agreement, the Client is responsible for the secure use of the Service, including protecting their account authentication credentials, securing the Client Data when in transit to and from the Service, and implementing appropriate secure encryption or backup measures for Client Data uploaded to the Service. 10. International Transfers 1. E-goi's data storage and processing servers are located in Portugal, within the European Economic Area (EEA). We don't store data outside the EEA. Consequently, the Client's and their Contacts' information will not be transferred or processed outside the EEA by E-goi, and it will always be handled securely and in compliance with this Data Processing Agreement and applicable data protection laws. 2. However, E-goi may use subcontractors to provide certain services, as detailed later in this Agreement. These subcontractors may process data in countries outside the EEA. In cases where it's necessary to transfer personal data outside the EEA, E-goi is committed to ensuring all safeguards required by applicable data protection laws are implemented, including but not limited to those specified in Articles 44 to 47 of the GDPR. 3. E-goi will continuously monitor the compliance of these international transfers with the requirements of European Data Protection Laws (including the GDPR) and Non-European Data Protection Laws (including the LGPD) and other applicable regulations, ensuring that the Client's data is always protected with the highest level of security and privacy. 11. Use of Subcontractors 1. The E-goi platform is designed to control all data flows, ensuring a "privacy by design" model, including technical and organizational measures that minimize risks and ensure compliance with Data Protection Laws. Client data is not transferred outside the systems controlled by E-goi, except in specific cases where it is strictly necessary to use Subcontractors. 2. The Client agrees that E-goi may hire Subcontractors to process Personal Data provided by the Client on their behalf, according to documented instructions from the Client, E-goi, and Data Protection Laws. The Subcontractors hired by E-goi are subject to contractual obligations of confidentiality and data protection that are at least as strict as the obligations established in this Data Processing Agreement. 3. E-goi will notify the Client via RSS about any changes to this document, including the inclusion of new Subcontractors, as soon as possible before or after authorizing such new Subcontractors to process Personal Data. The Client will have the opportunity, in case of a justified objection due to a violation of Data Protection Laws, to terminate the Contract within thirty (30) days following that notification. 4. The current set of Subcontractors hired by E-goi and authorized by the Client to carry out the processing of personal data as well as for other purposes without processing personal data is as follows: Entity(ies) Category Relevant Services / Activities / Purpose Details of Processed Data Country of Registration Countries of Processing Communication, Connectivity and Messaging Operators (e.g.: Telecommunications Operators, Messaging Services Google, Apple, Meta) Message Transport Transport of messages via SMS, Voice, Push / Webpush and WhatsApp Broadcasting Does not process or directly access personal data. The content of the messages may contain personal data, depending on the use made by the Data Controller. Various Global IP Telecom Hosting and Datacenter Network Housing services for our Datacenter equipment No direct access to data by the Sub-processor. Portugal Portugal BunnyCDN Network and Security Content Delivery Network (CDN); WAF and DDoS Protection Does not process or directly access relevant personal data. Cached content is distributed to optimize performance and security. Slovenia Various (global CDN network) Fullstory User Session Analysis and Monitoring User Session Analysis and Monitoring Provides session replay and analytics services to monitor platform usability. May collect anonymized user interactions. USA USA OVHcloud Hosting Hosting of SMTP servers used for the processing and sending of emails Processing of SMTP emails for delivery purposes. Metadata is processed (sender/recipient addresses, date/time stamps), but not stored. This is a transit process, and emails are not stored on OVHcloud servers. France France Albato Integration and Automation (SaaS) “No-code” platform for automation of flows between applications (embedded and standard) Enables the automation of flows between applications, and may process data according to the use case defined by the Client. Germany Germany 12. Assistance to the Data Controller 1. E-goi must assist the Client in fulfilling their obligations to respond to requests to exercise data subject rights, considering the nature of the processing. In fulfilling its obligations, E-goi must comply with the Client's instructions. 2. As part of the Service, E-goi provides the Client with various self-service features that the Client can use to retrieve, correct, delete, or restrict the use of the Client's Data, assisting them in relation to their obligations (or their third-party Data Controller's) to respond to data subject requests through the Client's account at no additional cost. 3. Furthermore, given the nature of the processing, E-goi will provide any additional assistance necessary to the Client to the extent possible so that the Client (or their third-party Data Controller) can fulfill their data protection obligations in relation to data subjects' rights under Data Protection Laws. 4. If such a request is made directly to E-goi, E-goi will not respond to this communication directly, except as appropriate (for instance, to direct the data subject to contact the Client) or as determined by law, without the Client's prior authorization. If E-goi is obliged to fulfill such a request, E-goi, when the Client is identified or identifiable from the request, will immediately notify the Client and provide a copy of the request, unless E-goi is legally prohibited from doing so. 5. Besides E-goi's obligation to assist the Client under the above terms, E-goi assists the Client to ensure compliance with the obligations set out in Articles 32 to 36 of the GDPR, considering the nature of the processing and the information available to E-goi. 13. Notification of Personal Data Breach 1. In the event of a personal data breach concerning data processed by E-goi, E-goi must notify the Client without undue delay after becoming aware of the breach and in accordance with the Agreement. This notification must at least include the following elements: a. A description of the nature of the breach (including, if possible, the categories and approximate number of data subjects affected and records concerned); b. Contact details for a point where more information regarding the personal data breach can be obtained; c. The likely consequences of the breach and the measures taken or proposed to address it, including mitigating any potential negative effects. 2. If it's not possible to provide all this information at the same time, the initial notification must contain the available information, and further information should be provided subsequently without undue delay as it becomes available. 3. E-goi’s notification or response to a Security Incident under this clause should not be regarded as an acknowledgment of fault or responsibility by E-goi in relation to the Security Incident. 4. It is the Client's responsibility to notify the data subject, legal authorities, and/or other entities as applicable under the law. 14. Deletion or Return of Data upon Termination 1. Upon termination or expiration of the Agreement, E-goi will delete or return to the Client (at the Client's discretion) all Client Data (including copies) in its possession or control, except where E-goi is legally required to retain all or some of the Client Data, or Client Data that has been archived in backup systems, which E-goi will securely isolate, protect from further processing, and eventually delete in accordance with E-goi's deletion policies, unless otherwise required by law. 2. The parties agree that the certification of deletion of the Client Data will be provided by E-goi to the Client only upon written request from the Client. 15. Security Audit Reports and Rights 1. E-goi will make all information necessary to demonstrate compliance with this Data Processing Agreement available to the Client and will facilitate and contribute to audits, including inspections by the Client or another auditor mandated by the Client to evaluate compliance with this Data Processing Agreement. 2. The Client reserves the right to conduct audits at E-goi's premises, directly or through a representative, with ten business days' notice, during normal business hours, to verify compliance with the obligations of the present Agreement and gather elements likely to introduce improvements in the activities developed by both Parties. 3. The audits referred to above will be accompanied by one or more E-goi employees/collaborators, focusing solely on compliance with the Agreement, ensuring necessary measures to prevent incidents that might compromise the security, privacy, and industrial property of Third Parties. 4. If non-compliance with the Agreement's obligations is found as a result of an audit, the Second Party shall notify E-goi in writing to rectify the non-compliance within the period specified in the Agreement, under the risk of exercising the right of termination. 5. The Client acknowledges and agrees to exercise its audit rights under this Data Processing Agreement and all audit rights granted by Data Protection Laws. Clients can submit requests by filling out a contact form (at https://www.e-goi.com/pt/contactos/). 16. Specific Jurisdiction Terms 1. If E-goi processes Client Data originating from and protected by Data Protection Laws in one of the jurisdictions listed in Annex A, the terms specified in Annex A concerning the applicable jurisdiction(s) (“Specific Jurisdiction Terms”) apply in addition to the terms of this Data Processing Agreement. 2. In case of conflict or ambiguity between the Specific Jurisdiction Terms and other terms of this Data Processing Agreement, the applicable Specific Jurisdiction Terms will prevail, but only to the extent of their applicability to E-goi. 17. Limitation of Liability 1. The liability of each Party and all its Affiliates assumed collectively in the aggregate arising from this Data Processing Agreement shall be subject to the exclusions and limitations of liability established in the Contract. 18. Actions Against E-goi 1. All actions against E-goi under this Data Processing Agreement or related thereto shall be brought exclusively by the Customer entity that is a party to the Contract. 19. Data Protection Rights 1. Under no circumstances will either party limit its own liability concerning the data protection rights of any individual under this Data Processing Agreement or otherwise. 20. Duration of the Data Processing Agreement 1. This Data Processing Agreement will remain in effect as long as E-goi performs Data Processing operations on behalf of the Customer or until the Contract is terminated (and all Customer Data has been returned or deleted). 21. Replacement of Previous Contracts 1. The parties agree that this Data Processing Agreement shall replace any existing data processing agreements or similar documents that the parties may have previously entered into regarding the Service. 22. Document Precedence 1. In case of conflict or inconsistency between this Data Processing Agreement and the E-goi Terms of Use, the provisions of the following documents (in order of precedence) shall prevail: (i) Data Processing Agreement; (ii) Contract; (iii) E-goi Terms of Use. 23. Continuity of the Contract 1. Except for changes made by this Data Processing Agreement, the Contract remains unchanged and in full force and effect. 24. Third-Party Rights 1. Persons not part of this Data Processing Agreement or their respective successors and authorized assigns shall have no right to enforce any of the terms of this Data Processing Agreement. 25. Applicable Law and Jurisdiction 1. This Data Processing Agreement shall be governed and interpreted in accordance with the legal and jurisdictional provisions in force in the Contract, unless otherwise determined by applicable Data Protection Laws. 26. Questions and Contact 1. If the Customer has any questions or concerns regarding this Data Processing Agreement or E-goi's privacy practices, they can contact E-goi through the following means: a. Contact form: https://www.e-goi.com/contacts/ b. Email: dpo@e-goi.com c. Mailing address: E-goi, Av. Menéres, 840 4450-190 Matosinhos Portugal 2. E-goi is committed to responding to all requests and concerns presented by the Customer in accordance with applicable data protection laws, ensuring a prompt and appropriate response to the issues raised. Annex A – Jurisdiction-Specific Terms Brazil Section I - General Information 1. Identification of the Parties 1.1. By this contractual instrument, the Exporter and Importer (hereinafter, Parties), as identified below, agree to adopt the contractual standard clauses (hereinafter Clauses) approved by the National Data Protection Authority (ANPD), to govern the International Data Transfer described in Clause 2, in accordance with the provisions of the National Legislation. Name: The Customer, as specified in the Contract or in the E-goi Account data. Qualification: Controller Main address: The Customer, as specified in the Contract or in the billing data in the E-goi Account. Email address: The Customer, as specified in the Contract or in the billing data in the E-goi Account. Contact for the Holder: The Customer, as specified in the Contract or in the E-goi Account data. Other information: (X) Exporter/Controller) ( ) Exporter/Operator) Name: E-goi, Lda Qualification: Operator Main address: As specified in the Contract Email address: As specified in the Contract Contact for the Holder: As specified in the Contract Other information: ( ) Importer/Controller (X) Importer/Operator 2. Object 2.1. These Clauses apply to the International Data Transfers from the Exporter to the Importer, as described below. Description of the international data transfer: As specified in the Contract. Main purposes of the transfer: As specified in the Contract. Categories of personal data transferred: As specified in the Contract. Data retention period: As specified in the Contract. Other information: Not applicable 3. Subsequent Transfers 3.1. The Importer may conduct Subsequent Transfers of the Personal Data subject to the International Data Transfer governed by these Clauses under the circumstances and conditions described below and provided that the provisions of Clause 18 are observed. Main purposes of the transfer: As specified in the Contract. Categories of personal data transferred: As specified in the Contract. Data retention period: As specified in the Contract. Other information: Not applicable 4. Responsibilities of the Parties 4.1. Without prejudice to the duty of mutual assistance and the general obligations of the Parties, the Designated Party below, as the Controller, shall be responsible for fulfilling the following obligations set out in these Clauses: a) Responsible for publishing the document provided for in Clause 14; (X) Exporter ( ) Importer b) Responsible for handling the requests of holders referred to in CLAUSE 15: (X) Exporter ( ) Importer c) Responsible for notifying the security incident provided for in Clause 16: (X) Exporter ( ) Importer 4.2. For the purposes of these Clauses, if it is later found that the Designated Party as per item 4.1. acts as an Operator, the Controller will remain responsible: a) for fulfilling the obligations set forth in Clauses 14, 15, and 16 as well as other provisions established in the National Legislation, especially in case of omission or non-compliance with obligations by the Designated Party; b) for complying with ANPD's determinations; and c) for ensuring the rights of the Holders and compensating for any damages caused, as provided in Clause 17. Section II - Mandatory Clauses 5. Purpose 5.1. These Clauses serve as a mechanism to enable the secure international flow of personal data, establishing minimum guarantees and valid conditions for carrying out an International Data Transfer and ensuring the adoption of appropriate safeguards to comply with the principles, rights of the Holder, and data protection regime provided in the National Legislation. 6. Definitions 6.1. For the purposes of these Clauses, the definitions of Article 5 of Law No. 13,709, of August 14, 2018, and Article 3 of the International Personal Data Transfer Regulation will be considered, without prejudice to other normative acts issued by the ANPD. The Parties also agree to consider the terms and their respective meanings, as follows: a) Processing agents: the controller and the operator; b) ANPD: National Data Protection Authority; c) Clauses: the standard contractual clauses approved by the ANPD, which include Sections I, II, and III; d) Related Contract: contractual instrument signed between the Parties or, at least, between one of them and a third party, including a Third-Party Controller, which has a common purpose, linkage or dependency relationship with the contract that governs the International Data Transfer; e) Controller: Party or third party ("Third-Party Controller") responsible for decisions regarding the processing of Personal Data; f) Personal Data: information relating to an identified or identifiable natural person; g) Sensitive Personal Data: personal data concerning racial or ethnic origin, religious belief, political opinion, membership in a union or religious, philosophical or political organization, data related to health or sexual life, genetic or biometric data, when linked to a natural person; h) Deletion: exclusion of a data set stored in a database, regardless of the procedure employed; i) Exporter: processing agent located in the national territory or foreign country that transfers personal data to Importer; j) Importer: processing agent located in a foreign country or as an international organization that receives personal data transferred by the Exporter; k) National Legislation: set of Brazilian constitutional, legal, and regulatory provisions regarding the protection of Personal Data, including Law No. 13,709, of August 14, 2018, the International Data Transfer Regulation, and other normative acts issued by the ANPD; l) Arbitration Law: Law No. 9,307, of September 23, 1996; m) Security Measures: technical and administrative measures adopted to protect personal data from unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or diffusion; n) Research Body: direct or indirect public administration body or private non-profit legal entity legally constituted under Brazilian laws, with headquarters and forum in the country, which includes in its institutional mission or social or statutory objective the basic or applied research of historical, scientific, technological or statistical character; o) Operator: Party or third party, including a Subcontractor, processing Personal Data on behalf of the Controller; p) Designated Party: Contract Party designated, under Clause 4 ("Option A"), to fulfill specific obligations regarding transparency, Holder's rights, and security incident communication as Controller; q) Parties: Exporter and Importer; r) Access Request: mandatory service request, by law, regulation, or public authority determination, to grant access to Personal Data subject to the International Data Transfer governed by these Clauses; s) Subcontractor: processing agent contracted by the Importer, without link to the Exporter, to carry out Personal Data processing after an International Data Transfer; t) Third-Party Controller: Controller of Personal Data providing written instructions for conducting, on their behalf, the International Data Transfer between Operators governed by these Clauses, as per Clause 4 ("Option B"); u) Holder: natural person referred to in the Personal Data subject to the International Data Transfer governed by these Clauses; v) Transfer: processing modality through which a processing agent transfers, shares or provides access to Personal Data to another processing agent; w) International Data Transfer: transfer of Personal Data to a foreign country or international organization of which the country is a member; and x) Subsequent Transfer: International Data Transfer, originated from an Importer, and destined to a third party, including a Subcontractor, provided it does not configure an Access Request. 7. Applicable Law and ANPD Supervision 7.1. The International Data Transfer subject to these Clauses is subject to the National Legislation and the supervision of the ANPD, including the power to apply preventive measures and administrative sanctions to both Parties, as applicable, as well as to limit, suspend or prohibit international transfers resulting from these Clauses or a Related Contract. 8. Interpretation 8.1. Any application of these Clauses must occur according to the following terms: a) these Clauses should always be interpreted in the manner most favorable to the Holder and in accordance with the provisions of the National Legislation; b) in case of doubt regarding the meaning of terms of these Clauses, the interpretation most aligned with the National Legislation applies; c) no item of these Clauses, including here a Related Contract and the provisions of Section IV, may be interpreted with the aim of limiting or excluding the liability of any Party related to obligations provided in the National Legislation; and d) the provisions of Sections I and II prevail in case of conflict of interpretation with additional Clauses and other provisions set out in Sections III and IV of this instrument or Related Contracts. 9. Possibility of Third-Party Adherence 9.1. By mutual agreement of the Parties, a processing agent may adhere to these Clauses as an Exporter or Importer, by completing and signing a written document that will integrate this instrument. 9.2. The adhering party shall have the same rights and obligations as the original Parties, according to the position assumed as Exporter or Importer, and the corresponding processing agent category. 10. General Obligations of the Parties 10.1. The Parties undertake to adopt and, when necessary, demonstrate the adoption of effective measures capable of proving compliance with the provisions of these Clauses and the National Legislation and, including the effectiveness of these measures, in particular: a) use Personal Data only for the specific purposes described in Clause 2, without potential for further processing in a manner incompatible with these purposes, observed, in any case, the limitations, guarantees, and safeguards provided in these Clauses; b) ensure treatment compatibility with the purposes informed to the Holder, according to the treatment context; c) limit treatment to the minimum necessary to achieve its purposes, with a scope of relevant, proportional, and non-excessive data regarding the Personal Data treatment purposes; d) guarantee to Holders, observed the provision in Clause 4. (d.1.) clear, precise, and easily accessible information about the treatment and respective processing agents, observed commercial and industrial secrets; (d.2.) facilitated and free consultation on how and duration of treatment, as well as on the full extent of their Personal Data; and (d.3.) the correctness, clarity, relevance, and updating of Personal Data, according to the necessity and to fulfill its treatment's purpose; e) adopt appropriate security measures compatible with the risks involved in the International Data Transfer governed by these Clauses; f) not conduct Personal Data treatment for illicit or abusive discriminatory purposes; g) ensure that any person acting under its authority, including subcontractors or anyone collaborating with it, gratuitously or against payment, treats data only in compliance with its instructions and with the provisions set out in these Clauses; and h) maintain record of Personal Data treatment operations subject to the International Data Transfer governed by these Clauses, and present the pertinent documentation to the ANPD, when requested. 11. Sensitive Personal Data 11.1. If the International Data Transfer involves sensitive Personal Data, the Parties will apply additional safeguards, including specific security measures proportional to the treatment activity risks, the specific nature of the data, and the interests, rights, and guarantees to be protected as described in Section III. 12. Personal Data of Children and Adolescents 12.1. If the International Data Transfer involves Personal Data of children and adolescents, the Parties will apply additional safeguards, including measures ensuring the treatment is conducted in their best interest, under the National Legislation and relevant international law instruments. 13. Legal Use of Data 13.1. The Exporter guarantees that the Personal Data has been collected, processed, and transferred to the Importer in accordance with the National Legislation. 14. Transparency 14.1. The Designated Party will publish on its webpage document easily accessible drafted in simple, clear, and precise language about the International Data Transfer, including at least information on: a) the form, duration, and specific purpose of the international transfer; b) the data destination country's identification; c) the Designated Party's identification and contact information; d) data shared use by the Parties and its purpose; e) responsibilities of agents who will perform the treatment; f) the Holder's rights and the ways to exercise them, including an easily accessible channel for handling requests and the right to challenge the Controller before the ANPD; and g) Subsequent Transfers, including related to recipients and transfer purposes. 14.2. The document referred to in item 14.1. can be made available on a specific page or integrated, prominently and easily accessible, with the Privacy Policy or equivalent document. 14.3. Upon request, the Parties must make a free copy of these Clauses available to the Holder, observed commercial and industrial secrets. 14.4. All information made available to the holders, under these Clauses, must be drafted in Portuguese. 15. Holder's Rights 15.1. The Holder has the right to obtain from the Designated Party, with regard to the Personal Data subject to the International Data Transfer governed by these Clauses, at any time, and upon request, pursuant to the National Legislation: a) confirmation of the treatment's existence; b) access to the data; c) correction of incomplete, inaccurate, or outdated data; d) anonymization, blocking, or elimination of unnecessary, excessive, or data processed non-compliance with these Clauses and provided in the National Legislation; e) data portability to another service or product provider, upon express request, according to the ANPD regulation, observed commercial and industrial secrets; f) elimination of Personal Data processed with the Holder's consent, except in cases provided for in Clause 20; g) information of public and private entities with which the Parties have conducted shared data use; h) information about the possibility of not giving consent and the consequences of refusal; i) revocation of consent by free and facilitated procedure, ratified the processing carried out prior to the elimination request; j) review of decisions made solely based on automated data processing affecting their interests, including those intended to define their personal, professional, consumption, and credit profile, or aspects of their personality; and k) information about criteria and procedures used for automated decision, observed commercial and industrial secrets. 15.2. The holder can object to processing conducted based on one of the consent waiver circumstances, in case of non-compliance with these Clauses or the National Legislation. 15.3. The period for handling requests provided in this Clause and item 14.3. is 15 (fifteen) days from the date of the holder's request, except when a different period is established in specific ANPD regulation. 15.4. If the Holder's request is directed to a Party not designated as responsible for the obligations set out in this Clause or in item 14.3., the Party must: a) inform the Holder of the service channel provided by the Designated Party; or b) forward the request to the Designated Party as soon as possible to enable a response within the period stipulated in item 15.2. 15.5. The Parties must immediately inform the Treatment Agents with whom they have conducted shared data use of the correction, elimination, anonymization, or blocking of data, to repeat the same procedure, except when this communication is demonstrably impossible or involves disproportionate effort. 15.6. The Parties must promote mutual assistance to meet Holders' requests. 16. Security Incident Communication 16.1. The Designated Party shall notify the ANPD and the Holders within 3 (three) business days of a security incident that may result in significant risk or harm to the Holders, observed the provisions in the National Legislation. 16.2. The Importer must maintain a registry of security incidents under the National Legislation. 17. Liability and Damage Compensation 17.1. The Party that results in patrimonial, moral, individual, or collective damage, due to the exercise of the Personal Data processing activity, violating these Clauses and the National Legislation, is obligated to compensate it. 17.2. The Holder may seek compensation for damage caused by either of the Parties due to the violation of these Clauses. 17.3. The defense of the interests and rights of the Holders may be pursued in court, individually or collectively, as provided in the relevant legislation concerning individual and collective protection instruments. 17.4. The Party acting as an Operator is jointly liable for the damages caused by the treatment when it breaches these Clauses or fails to follow the Controller's lawful instructions, except as provided in item 17.6. 17.5. Controllers directly involved in the treatment from which damages to the Holder arise are jointly liable for these damages, except as provided in item 17.6. 17.6. No liability of the Parties shall arise if it is proven that: a) they did not perform the Personal Data processing attributed to them; b) even though they performed the Personal Data processing attributed to them, there was no violation of these Clauses or the National Legislation; or c) the damage results from the Holder's exclusive fault or from a third party that is not a recipient of a Subsequent Transfer or subcontracted by the Parties. 17.7. Under the National Legislation, the judge may reverse the burden of proof in favor of the Holder when the claim is deemed credible, there is indigence for proof production purposes, or when the proof production by the Holder is excessively onerous. 17.8. Collective damage compensation actions aimed at accountability under this Clause may be exercised in court collectively, as provided in the relevant legislation. 17.9. The Party that compensates the damage to the holder has the right of recourse against the other responsible parties, proportionally to their participation in the harmful event. 18. Safeguards for Subsequent Transfers 18.1. The Importer may only conduct Subsequent Transfers of Personal Data subject to the International Data Transfer governed by these Clauses if expressly authorized, under the circumstances and conditions described in Clause 3. 18.2. In any case, the Importer: a) must ensure the purpose of the Subsequent Transfer is compatible with the specific purposes described in Clause 2; b) must guarantee, by written contractual instrument, that the safeguards provided in these Clauses will be observed by the third-party recipient of the Subsequent Transfer; and c) for the purposes of these Clauses, and regarding the transferred Personal Data, shall be considered responsible for any irregularities committed by the third-party recipient of the Subsequent Transfer. 18.3. The Subsequent Transfer may also be conducted based on another valid mechanism for International Data Transfer foreseen in the National Legislation, regardless of the authorization provided for in Clause 3. 19. Notification of Access Request 19.1. The Importer will notify the Exporter and the Holder about Access Request related to the Personal Data subject to the International Data Transfer governed by these Clauses, except when notification is prohibited by the law of the data treatment country. 19.2. The Importer shall take the appropriate legal measures, including legal actions, to protect the Holders' rights whenever there is adequate legal basis to question the legality of the Access Request and, if applicable, the prohibition on making the notification referred to in item 19.1. 19.3. To meet ANPD and Exporter requests, the Importer must maintain a registry of Access Requests, including date, requester, request purpose, type of data requested, number of requests received, and legal measures taken. 20. Termination of Treatment and Data Deletion 20.1. The Parties must delete the Personal Data subject to the International Data Transfer governed by these Clauses after the treatment termination, within and under the technical limits of the activities, retaining only for the following purposes: a) compliance with a legal or regulatory obligation by the Controller; b) study by a Research Body, ensuring, whenever possible, the anonymization of Personal Data; c) transfer to a third party, provided the requirements in these Clauses and the National Legislation are respected; and d) the exclusive use of the Controller, prohibiting third-party access, and provided data is anonymized. 20.2. For the purposes of this Clause, treatment termination is considered when: a) the purpose provided in these Clauses is achieved; b) Personal Data is no longer necessary or relevant to achieve the specific purpose set forth in these Clauses; c) the treatment period is over; d) Holder's request is fulfilled; and e) ANPD determines when there is a violation of these Clauses or the National Legislation. 21. Data Treatment Security 21.1. The Parties must adopt security measures ensuring protection to Personal Data subject to the International Data Transfer governed by these Clauses, even after its termination. 21.2. The Parties will inform, in Section III, the Security Measures adopted, considering the nature of the processed information, specific characteristics and treatment purpose, current technological state, and risks to the Holders' rights, especially in the case of sensitive personal data and data of children and adolescents. 21.3. The Parties must make necessary efforts to adopt periodic evaluation and review measures to maintain an adequate security level corresponding to the data treatment's characteristics. 22. Legislation of the Data Recipient Country 22.1. The Importer declares that it has not identified laws or administrative practices of the Personal Data recipient country that prevent it from fulfilling the obligations assumed in these Clauses. 22.2. Upon normative changes that alter this situation, the Importer shall immediately notify the Exporter for contract continuation assessment. 23. Importer Clause Non-compliance 23.1. If there is a breach of the safeguards and guarantees provided in these Clauses or the Importer's inability to comply, the Exporter should be immediately notified, subject to the provision in item 19.1. 23.2. Upon receiving the notification referred to in item 23.1 or verifying non-compliance with these Clauses by the Importer, the Exporter shall take the pertinent measures to ensure Holders' rights protection and compliance of the International Data Transfer with the National Legislation and these Clauses, which may include: a) suspending the International Data Transfer; b) requesting the return of the Personal Data, its transfer to a third party, or its deletion; and c) terminating the contract. 24. Choice of Forum and Jurisdiction 24.1. These Clauses are governed by Brazilian law, and any disputes between the Parties arising from these Clauses will be resolved before the competent courts in Brazil, subject to the forum elected by the Parties in Section IV, if applicable. 24.2. Holders may file lawsuits against the Exporter or Importer, as they choose, before the competent courts in Brazil, including those located at their place of residence. 24.3. By mutual agreement, the Parties may resort to arbitration to resolve disputes arising from these Clauses, provided it is held in Brazil and in accordance with the provisions of the Arbitration Law.