Skip to main content
EvoCODE IA® LogoEvoCODE IA® Logo
AGENTE NOCBY EVOCODE IA®
← Back to Home
Back to legal center
Terms of ServiceAcceptable Use PolicyPrivacy PolicyCookie PolicyData Processing Agreement (DPA)SubprocessorsLegal Notice

Version 2.3
Last updated: September 24, 2026

Privacy Policy — EvoCODE IA®

Last updated: September 24, 2026 · Version 2.3

This Privacy Policy ("Policy") explains how EvoCODE IA® Ltda ("EvoCODE", "we", "us") processes personal data in the context of our products and services — Kairo, TraceLog, and AgenteNOC — and of our websites, including https://evocode.ia.br, kairo.evocode.ia.br, and agentenoc.evocode.ia.br.

It forms part of our legal document hub, alongside the Terms of Service, the Acceptable Use Policy (AUP), the Cookie Policy, and the Data Processing Agreement (DPA). In the event of a conflict, the order of precedence is: DPA > Terms of Service > AUP > documentation.

We wrote this Policy in plain language. If anything is unclear, contact our Data Protection Officer (DPO): dpo@evocode.ia.br.


Table of contents

  1. Who we are and our roles in data processing
  2. What data we collect, by product
  3. Purposes and legal bases (table)
  4. Cookies and similar technologies
  5. With whom we share data (subprocessors)
  6. International transfers
  7. How long we keep data (retention)
  8. Information security
  9. Your rights and how to exercise them
  10. Automated decision-making and artificial intelligence
  11. Children and adolescents
  12. Data Protection Officer (DPO)
  13. Regional sections
  14. Updates to this Policy

1. Who we are and our roles in data processing

1.1. Who we are

EvoCODE IA® Ltda, enrolled with the CNPJ (Brazilian corporate taxpayer registry) under No. 63.623.332/0001-42, with its registered office at Praça Nossa Senhora do Rosário, 44, Sala 02 — Centro, Piracaia/SP — CEP 12970-000 — Brasil, Brazil, is a Brazilian software company that develops and operates:

Product What it is Where it runs
Kairo Multi-tenant scheduling SaaS platform, with WhatsApp-based customer service and artificial intelligence agents kairo.evocode.ia.br
TraceLog Network observability SaaS platform: monitoring of routes, latency, packet loss, and SLA tracelog (evocode.ia.br)
AgenteNOC AI agents for NOCs/ISPs, operating via WhatsApp, Telegram, and Discord (network monitoring and diagnostics), with an administrative panel agentenoc.evocode.ia.br + panel

1.2. Controller or processor? Understand the two roles

Data protection legislation distinguishes two roles, and we perform both, depending on the data:

a) EvoCODE as CONTROLLER. We are the controller — that is, the one who decides the purposes and means of the processing — when the data is processed by our own decision and for our own purposes. This is the case for:

  • account data of our customers ("tenants") and their users: registration, authentication, profile, preferences;
  • billing and payment data;
  • security logs and application access records;
  • platform usage telemetry (for operation, improvement, and statistics);
  • data of visitors to our websites and of marketing, support, and sales contacts.

b) EvoCODE as PROCESSOR (processor / service provider). We are the processor — the one who processes data on behalf of and under the instructions of another company — with respect to the personal data that our customers process through the platforms. In these cases, the controller is our customer (tenant), and the processing is governed by the DPA entered into with them. Examples:

  • data of Kairo invitees (people who book appointments with a company that uses Kairo);
  • content of conversations on WhatsApp, Telegram, and Discord held with AI agents configured by customers (Kairo and AgenteNOC);
  • personal data possibly present in the TraceLog network logs and telemetry subscribed to by a customer.

1.3. If your data was processed on behalf of one of our customers, contact them first

Important instruction for data subjects: if you booked an appointment with a company that uses Kairo, chatted with an AI agent operated by one of our customers (via WhatsApp, Telegram, or Discord), or are an end customer of a provider that uses TraceLog or AgenteNOC, the party that decides about your data is that company (the controller) — and it is to them that you should first direct yourself to exercise your rights (access, rectification, erasure, etc.).

We, as processor:

  • will forward to the competent controller, without undue delay, any data subject request that we improperly receive;
  • will assist the controller in handling the requests, in accordance with the DPA;
  • will only act directly on such data upon the controller's documented instruction or under a legal obligation.

Pursuant to Article 42, paragraph 1, of the LGPD (Lei Geral de Proteção de Dados — Brazilian General Data Protection Law, Law No. 13,709/2018), the processor is jointly and severally liable only when it fails to comply with the law or with the controller's lawful instructions.

If you cannot identify which company is the controller of your data, write to dpo@evocode.ia.br and we will help direct your request.


2. What data we collect, by product

We collect only the data necessary for the purposes described in this Policy. Below, the categories by product and by source.

2.1. Data common to all products (EvoCODE as controller)

  • Registration and account: name, e-mail, phone, company, job title, access credentials (password stored as a hash), language, and interface preferences.
  • Billing: billing data, subscribed plan, payment history, and tax documents. Payment card data is processed directly by the payment processor (Stripe) — we do not store the full card number.
  • Access and security records: IP address, date and time of access, session identifiers, user agent, and authentication events (pursuant to Article 15 of the Marco Civil da Internet — the Brazilian Internet Civil Framework, Law No. 12,965/2014). In AgenteNOC, these records are detailed in Section 2.4.
  • Usage and diagnostic telemetry: application usage events, error and performance logs.
  • Communications: messages exchanged with support (sac@evocode.ia.br, official WhatsApp +55 51 2191-0021), sales, and official channels.
  • Acceptance record: version of the Terms accepted and the date and time of acceptance at the time of registration.

2.2. Kairo

As controller (tenant data): account, tenant users, billing (Stripe), platform settings, logs.

As processor (on behalf of the controller tenant):

  • Invitee data: name, e-mail, phone, responses to booking forms, and the invitee's time zone;
  • WhatsApp conversations with AI agents: content of the messages exchanged between the invitee/end customer and the tenant's agent (via WhatsApp/Meta), including audio where applicable;
  • Calendar and meeting integrations: event and availability data synchronized via Google Calendar, Microsoft Outlook/Teams, and Zoom, upon OAuth authorization granted by the tenant or its users;
  • Booking data: date, time, event type, status, and history.

2.3. TraceLog

As controller: customer account and billing; IP address of visitors to the website/platform, with approximate IP-based geolocation; access and security logs.

As processor (on behalf of the controller tenant):

  • Network telemetry: monitored IP addresses, routes, latency and packet loss measurements, SLA indicators. The retention of this telemetry varies according to the subscribed plan: 7, 30, 180, or 365 days (see Section 7).

Note: network telemetry data refers primarily to infrastructure, but may contain personal data (e.g., IPs attributable to natural persons). We handle all telemetry with the same safeguards applicable to personal data.

2.4. AgenteNOC

As controller: customer accounts and panel users, billing, logs, data on access to training content in the panel (videos via VdoCipher).

In AgenteNOC, access records for the panel and the APIs are recorded with the IP address, the date and time in UTC, a pseudonymized session identifier, the user agent, authentication events, and the user or token that originated the access (see Section 7 for the retention periods).

As processor (on behalf of the controller tenant):

  • Content of conversations held with the AI agents via WhatsApp, Telegram, the panel's internal chat, and the mobile app: the user's message, the agent's response, sender identifiers (e.g., phone number, platform user ID), and, when sent by voice, the voice note, recorded in interaction logs;
  • Content of conversations held with the AI agents via Discord: the user's message (text only) and the agent's response, recorded in interaction logs;
  • Voice notes sent by the user to the agent via WhatsApp, Telegram, the panel's internal chat, and the mobile app are transcribed by an artificial intelligence provider (subprocessor already listed in Section 5.2); the audio file is temporary and is discarded after transcription, with periodic purging of leftover files; the transcribed text becomes part of the conversation history, with the same retention as Section 7; voice interactions are billed at a different rate;
  • Voice note generated by the agent (voice reply), when the Customer enables this feature: the text of the reply is sent to an artificial intelligence provider (a subprocessor already listed in Section 5.2, in the same category that performs transcription) to be synthesized into audio, and the reply reaches the user in voice and in text, never in voice alone. We do not keep a second copy of the spoken text: of the synthesis we record only technical and cost metrics — character count, audio duration, and estimated cost — never the content of the speech, which continues to exist only once in the conversation record, with the retention of Section 7. The generated audio file is delivered on the channel and stored together with the other media of the agent's messages. Every voice note is marked as AI-generated (Section 10). These synthesis metrics are processed by us as controller, on the legal basis of our legitimate interest in cost control and abuse prevention (Section 3);
  • Participants in groups in which the agent operates (member identifiers and metadata);
  • Network device credentials registered by the customer for monitoring and diagnostics — stored encrypted;
  • Technical network monitoring and diagnostic data generated during use.

2.5. Data we do NOT collect

  • We do not deliberately collect sensitive personal data (health, biometrics, religion, sexual orientation, etc.) for our own purposes. If a customer or end user enters this type of data in conversations or forms, it will be treated as customer content, under the controller's responsibility, with the safeguards of the DPA.
  • We do not collect data from children and adolescents (see Section 11).
  • We do not buy data lists nor sell personal data (see Section 5).

3. Purposes and legal bases

The table below maps each purpose to its legal basis under the LGPD (Art. 7) and, for data subjects in the European Economic Area/United Kingdom, under the GDPR/UK GDPR (Art. 6). Where we act as processor, the legal basis is determined by the controller (our customer); the bases below apply to the processing in which we are the controller.

Purpose Data involved LGPD legal basis (Art. 7) GDPR legal basis (Art. 6)
Creating and administering accounts, authenticating users, and providing the subscribed services Registration, credentials, settings Performance of a contract (item V) Art. 6(1)(b) — contract
Billing, collection, and default management Billing data, payment history Performance of a contract (V); credit protection (X) for collection Art. 6(1)(b); Art. 6(1)(f) — legitimate interest
Complying with legal and regulatory obligations (access records — Marco Civil Art. 15; tax and accounting obligations) Application access records, tax documents Legal obligation (II) Art. 6(1)(c) — legal obligation
Security, fraud and abuse prevention, anti-fraud monitoring IP, logs, authentication events, telemetry Legitimate interest (IX), with a Legitimate Interest Assessment (LIA) Art. 6(1)(f) — legitimate interest
Product improvement, error correction, and internal statistics (first-party analytics) Usage telemetry, error logs Legitimate interest (IX), with LIA Art. 6(1)(f) — legitimate interest
Support and customer service (customer service desk, official WhatsApp, e-mail) Communications and account data Performance of a contract (V) Art. 6(1)(b)
Marketing communications and news; non-essential cookies Contacts, cookie identifiers Consent (I) Art. 6(1)(a) — consent
Defense in legal proceedings and regular exercise of rights Contractual records, logs, acceptance record Regular exercise of rights (VI) Art. 6(1)(f)
Incident notification and responses to authorities Data involved in the incident Legal obligation (II); legitimate interest (IX) Art. 6(1)(c); Art. 6(1)(f)

Where the basis is consent, you may withdraw it at any time (see Section 9), without affecting the lawfulness of the processing carried out before the withdrawal. Where the basis is legitimate interest, you may object to the processing, and we keep documented Legitimate Interest Assessments (LIA).


4. Cookies and similar technologies

We use cookies and local storage for authentication and session (e.g., kairo_session, tracelog_session, XSRF-TOKEN), interface and language preferences, anti-bot security (Cloudflare Turnstile, on TraceLog) and — only with your consent — analytics and marketing (e.g., Google Tag Manager, on TraceLog, when active).

Non-essential scripts are only loaded after your consent, which may be given, refused, and withdrawn at any time via the consent banner and the "Cookie/privacy preferences" link in the footer of each product.

The complete and actual cookie tables, by product, with name, purpose, duration, and category, are set out in the Cookie Policy, available in the /legal hub of each product.


5. With whom we share data (subprocessors)

5.1. No-sale statement

We do not sell personal data. Nor do we share personal data with third parties for cross-context behavioral advertising. We share data only in the circumstances described below.

5.2. Subprocessors and service providers

We use providers (subprocessors, where we act as processor) strictly to enable the services, under contracts with data protection obligations. Categories, by product:

Common / infrastructure:

  • Own hosting and cloud providers (application infrastructure);
  • Cloud file storage providers;
  • Transactional e-mail sending providers;
  • Slack and Telegram (operational notifications);
  • Stripe (payment processing and billing).

Kairo:

  • Artificial intelligence model providers, including those configurable by the tenant — natural language processing for the agents, transcription, voice, and research in external sources;
  • Google OAuth (Google Calendar), Microsoft OAuth (Outlook/Teams), Zoom (calendar and meeting integrations);
  • Google Fonts (typography; exposes the IP address to Google on loading).

TraceLog:

  • Cloudflare (Turnstile — anti-bot protection at login);
  • IP geolocation database provider (approximate IP-based geolocation);
  • Artificial intelligence model providers (AI features);
  • Google Tag Manager (analytics/marketing, only with consent).

AgenteNOC:

  • Error and performance monitoring provider (including traces) of the platform services, including those that run the agents' tools;
  • Artificial intelligence model providers — natural language processing for the agents, transcription, voice, and research in external sources;
  • AI observability platform — debugging and improvement of the quality of service (conversation content, instructions, and assistant responses; USA);
  • VdoCipher (DRM video player, in the courses panel).

The public and up-to-date list of subprocessors, with country of processing and function, is maintained in the /legal hub and referenced in the DPA; the identity of each subprocessor is provided upon request to our Data Protection Officer (DPO), at dpo@evocode.ia.br, after verification of the requester (the Customer's account administrator or a data subject whose identity has been verified). Customers with an executed DPA are notified in advance of the addition of new subprocessors and may object, in accordance with the DPA.

5.3. Third-party channels

The messaging channels chosen by the Customer are not EvoCODE subprocessors:

  • WhatsApp (Meta Platforms) — a channel chosen by the Customer. The connection is made through integration software operated by EvoCODE, with no contractual relationship with Meta; Meta is not a subprocessor of EvoCODE and processes data under its own terms, as an independent controller. Use of this integration may be subject to restrictions imposed by Meta itself.
  • Telegram and Discord — channels chosen by the Customer and connected through bots registered by the Customer itself; each platform processes data under its own terms, as an independent controller.

5.4. Other sharing circumstances

  • Public authorities: where required by law or by court order and, where the law so permits, upon request from a competent authority, to the extent necessary;
  • Corporate transactions: in the event of a merger, acquisition, or reorganization, with continuity of the guarantees of this Policy;
  • Defense of rights: with legal and accounting advisors, under confidentiality;
  • With the controller: where we act as processor, the data is accessible to the controller customer by definition.

Application access records. The access records described in Section 7 are disclosed to third parties only upon court order (Marco Civil da Internet, Art. 15, paragraph 3, in conjunction with Art. 10, paragraph 1). Data subjects themselves may obtain, upon request, the access records that relate to them, in the exercise of the rights under Art. 18 of the LGPD, through the channels indicated in this Policy. A precautionary request from a police or administrative authority, or from the Public Prosecutor's Office, requires only that the records be preserved, including for a period longer than the statutory one (Art. 15, paragraph 2): it does not authorize disclosure, which remains subject to a judicial decision. Registration data showing personal qualification, parentage, and address follow their own rule and may be requested, as provided by law, by administrative authorities with legal competence to do so (Art. 10, paragraph 3).


6. International transfers

Some of our subprocessors process data outside Brazil (for example, the United States and the European Union). When we transfer personal data internationally, we adopt mechanisms recognized by the applicable legislation:

  • Brazil → abroad: we use the ANPD standard contractual clauses (SCCs), pursuant to Resolution CD/ANPD No. 19/2024, mandatory for new flows since 08/23/2025, and the other safeguards of Article 33 of the LGPD;
  • EEA/United Kingdom → abroad: we use the EU Standard Contractual Clauses (SCCs, Decision 2021/914) and, for the United Kingdom, the UK Addendum/IDTA, incorporated into the DPA where applicable;
  • Where the subprocessor in the USA is certified under the EU–U.S. Data Privacy Framework (DPF) (and the UK and Swiss extensions), that certification also supports the transfer from the EEA/UK/Switzerland.

The countries of processing of each subprocessor are listed in the public list of subprocessors. In addition, we apply technical measures (encryption in transit and at rest, minimization) to transferred data.


7. How long we keep data (retention)

We keep personal data only for as long as necessary for the purposes of this Policy, applying the following criteria: (i) term of the contract; (ii) statutory retention periods; (iii) limitation periods for the defense of rights; (iv) settings of the subscribed plan, where applicable.

Specific periods:

Category Period Basis
Application access records (access logs) 6 months Marco Civil da Internet, Art. 15 (legal obligation); a longer period only by court order or a precautionary request from an authority (Art. 15, paragraphs 1 and 2)
AgenteNOC access records (IP address, date and time in UTC, pseudonymized session, user agent, authentication events) 6 months, deleted within 7 days after the end of that period Marco Civil da Internet, Art. 15 (legal obligation)
Inventory of disclosures of AgenteNOC access records (reference, purpose, person responsible, and filters applied, which may include the user identifier and the IP address) 5 years from the record Brazilian Decree No. 8,771/2016, Art. 13, II (legal obligation); period aligned with the limitation period (regular exercise of rights)
Requests for extended retention of AgenteNOC access records (reference, purpose, period, and filters applied, which may include the user identifier and the IP address) While the request is in force and 5 years after it is closed or expires Marco Civil da Internet, Art. 15, paragraph 2 (legal obligation); period aligned with the limitation period (regular exercise of rights)
AgenteNOC technical application logs (errors and diagnostics) 30 days Legitimate interest (security and error correction)
Audio of a voice note generated by the AgenteNOC agent (synthesized file) and technical and cost metrics of the synthesis (character count, duration, and estimated cost — without the spoken text) 30 days (configurable by us), purged together by an automatic maintenance routine — independent from the retention of the conversation content, which follows a different criterion (duration of the account, no age-based purge) Legitimate interest (cost control and abuse prevention) and data minimization
Application usage events (usage telemetry and first-party analytics) 12 months, deleted at the end of that period Legitimate interest (product analysis and improvement)
TraceLog network telemetry According to the plan: 7, 30, 180, or 365 days Contractual setting defined by the controller customer
Tax and accounting records 5 years Tax legislation
Security incident records 5 years Resolution CD/ANPD No. 15/2024
Account data and customer content after termination of the contract Export available for 30 to 60 days after termination; then secure deletion Terms of Service and DPA (subject to legal retention)
Record of acceptance of the Terms (version and date) Applicable limitation period Regular exercise of rights
Consent-based marketing data Until withdrawal of consent LGPD Art. 7, I

In AgenteNOC, backups containing this data are replaced on a cycle of no more than 30 days.

At the end of the periods, the data is securely deleted or irreversibly anonymized. Where we act as processor, return and deletion follow the controller's instructions and the DPA.


8. Information security

We adopt technical and organizational measures capable of protecting personal data against unauthorized access, destruction, loss, alteration, and improper disclosure, including:

  • encryption in transit (TLS) and at rest; network device credentials stored encrypted (AgenteNOC); integration secrets stored with encryption;
  • passwords protected by hashing; role-based access control and the least privilege principle; support for strengthened authentication;
  • logical isolation between tenants (multi-tenant architecture with context segregation);
  • logging and monitoring of security events; anti-bot and anti-abuse protection;
  • vulnerability management and updates; segregated environments;
  • privacy governance, including Legitimate Interest Assessments (LIA) and Data Protection Impact Reports (RIPD) for higher-risk processing, such as the use of AI and large-scale messaging.

Security incidents: we maintain an incident response process. In the event of an incident with relevant risk or damage to data subjects, we will notify the ANPD and the affected data subjects within 3 business days, pursuant to Resolution CD/ANPD No. 15/2024, and we will keep a record of the incident for 5 years. Where we act as processor, we notify the controller customer within 48 hours of becoming aware, in accordance with the DPA.

No system is absolutely secure; for this reason, we ask that you also protect your credentials, which are personal and non-transferable, and notify us immediately (dpo@evocode.ia.br or sac@evocode.ia.br) in case of suspected compromise.


9. Your rights and how to exercise them

9.1. Data subject rights (LGPD, Art. 18)

You may, at any time and upon request, obtain:

  1. Confirmation of the existence of processing;
  2. Access to the data;
  3. Rectification of incomplete, inaccurate, or outdated data;
  4. Anonymization, blocking, or deletion of unnecessary or excessive data or data processed in non-compliance;
  5. Portability of the data to another provider, subject to ANPD regulations;
  6. Deletion of data processed on the basis of consent (subject to the statutory retention exceptions);
  7. Information about the entities with which we share your data;
  8. Information about the possibility of not providing consent and the consequences of refusal;
  9. Withdrawal of consent;
  10. Objection to processing carried out on other legal bases, in the event of non-compliance with the LGPD;
  11. Review of automated decisions (see Section 10).

9.2. How to exercise them

  • Channel: send your request to dpo@evocode.ia.br, indicating the product to which it refers (Kairo, TraceLog, or AgenteNOC) and the right you wish to exercise. Logged-in users may also manage various data directly in the account settings.
  • Identity verification: for your protection, we may request additional information to confirm that the request comes from the data subject themselves or from a legally appointed representative.
  • Deadlines: for confirmation of processing and access, we respond immediately in simplified format or, by means of a complete declaration, within 15 days of the request (LGPD, Art. 19). For the other rights, we respond without undue delay and will inform you if any specific statutory deadline applies.
  • Free of charge: the exercise of rights is free of charge.
  • If we cannot comply: we will state the factual or legal reasons preventing compliance (for example, a legal retention obligation), and you may petition the ANPD.

9.3. Data processed on behalf of a customer (redirection)

As explained in Section 1.3, if your data is processed by us on behalf of a customer (e.g., you are an invitee of a Kairo booking or chatted with a customer's AI agent), direct your request first to that customer, who is the controller. If the request reaches us, we will forward it to the controller and assist them in handling it, in accordance with the DPA. We will not directly handle requests concerning customers' data without the controller's instruction, except under a legal obligation.


10. Automated decision-making and artificial intelligence

Our products use artificial intelligence — in particular conversational agents in Kairo and AgenteNOC. Our commitments:

  • Transparency: every interaction with AI is identified as such. The agents introduce themselves as virtual assistants, and the customer (tenant) cannot disable this identification. Generated synthetic content — such as voice notes produced by text-to-speech — is marked as AI-generated in three layers, none of which the tenant can disable: the first voice note of each conversation opens with a spoken sentence stating that the voice is generated by artificial intelligence and is not that of a real person; every voice note travels with a written text carrying the same information; and the same information is kept in the caption displayed in the panel. These commitments also satisfy Article 50 of the European AI Regulation (EU AI Act), applicable as of 08/02/2026.
  • No training with customer data (default): we do not use customer data or conversation content to train AI models, by default. Irreversibly aggregated and anonymized data may be used to improve the services.
  • No warranty of accuracy: AI-generated responses may contain inaccuracies and do not replace human verification in relevant decisions; see the Terms of Service.
  • Review of automated decisions (LGPD, Art. 20): if any decision made solely on the basis of automated processing affects your interests, you have the right to request review and to receive clear information about the criteria used, through the channel dpo@evocode.ia.br. We do not employ exclusively automated decisions that produce significant legal effects on data subjects without adequate safeguards.
  • Governance: we maintain an impact assessment (RIPD) for the processing activities involving AI and large-scale messaging.

Where the AI agents are configured and operated by one of our customers, the customer is the controller of the content of those interactions, and the transparency obligations towards end users are shared in accordance with the Terms and the DPA.


11. Children and adolescents

Our products and websites are not directed at persons under 18 years of age, and we do not knowingly collect personal data from children and adolescents. Registration requires legal capacity to contract. If we become aware that we have collected data from a person under 18 without the legally required basis (LGPD, Art. 14), we will delete that data. If you believe this has occurred, contact dpo@evocode.ia.br.


12. Data Protection Officer (DPO)

Pursuant to Article 41 of the LGPD and Resolution CD/ANPD No. 18/2024, we have formally designated as Data Protection Officer (DPO):

Elizandro Pacheco de Almeida E-mail: dpo@evocode.ia.br

The DPO is the communication channel between EvoCODE, data subjects, and the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados — ANPD). Write to him to exercise rights, ask questions about this Policy, or report privacy concerns.


13. Regional sections

This Policy applies globally. The subsections below provide additional information required by local legislation and prevail, for data subjects in the respective region, over conflicting general provisions.

13.1. Brazil (LGPD)

The processing of personal data by EvoCODE is governed by Law No. 13,709/2018 (LGPD) and by the regulations of the ANPD — Autoridade Nacional de Proteção de Dados (Brazilian National Data Protection Authority), including Resolutions CD/ANPD No. 15/2024 (incidents), No. 18/2024 (data protection officer), and No. 19/2024 (international transfers). Your rights are described in Section 9.

In addition to the internal channels (dpo@evocode.ia.br), you have the right to petition the ANPD (https://www.gov.br/anpd) against EvoCODE, pursuant to Article 18, paragraph 1, of the LGPD, and to resort to consumer protection bodies, where applicable.

13.2. European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR / FADP)

If you are in the EEA, the United Kingdom, or Switzerland, the following provisions additionally apply:

  • Legal bases: we process your data on the basis of Article 6 of the GDPR/UK GDPR, as per the table in Section 3 — performance of a contract (6(1)(b)), legal obligation (6(1)(c)), legitimate interests (6(1)(f)), and consent (6(1)(a)).
  • Your rights: access, rectification, erasure ("right to be forgotten"), restriction of processing, objection (including to direct marketing, at any time), and portability in a structured, commonly used, and machine-readable format. Where the processing is based on consent, you may withdraw it at any time.
  • Response time: we will respond within 1 month, extendable by a further 2 months in complex cases, with justified prior notice.
  • Complaint to the authority: you have the right to lodge a complaint with the data protection authority of your country of residence, work, or of the place of the alleged infringement — for example, the ICO in the United Kingdom or the local supervisory authority in the EEA — without prejudice to other remedies.
  • Representative (Art. 27 GDPR/UK GDPR): where the appointment of a representative in the EU or the United Kingdom is required by reason of the scope of our activities, they will be appointed and identified in this section, with their contact details.
  • Transfers: data transfers from the EEA/UK/Switzerland are supported by the EU SCCs 2021/914, the UK Addendum/IDTA and, where applicable, by the importer's certification under the Data Privacy Framework (see Section 6).

13.3. United States — US State Privacy Rights

If you reside in a US state with a comprehensive privacy law in force (including, among others, California, Virginia, Colorado, Connecticut, Utah, Texas, and Oregon), the following apply, subject to the law of your state:

  • Rights: to confirm the processing and access your data; to correct inaccuracies; to delete personal data; to obtain a portable copy; and to opt out of (i) the "sale" of personal data, (ii) targeted advertising ("sharing" for cross-context behavioral advertising), and (iii) profiling with legal or similarly significant effects.
  • We do not sell or share: we do not sell personal data nor "share" it for cross-context behavioral advertising, within the meaning of those laws. Even so, you may register your opt-out preference.
  • Global Privacy Control (GPC): we honor universal preference signals, such as the GPC, as a valid exercise of opt-out in the browser in which it is active.
  • Non-discrimination: you will not be discriminated against for exercising your rights.
  • Appeal: if we deny your request, you may appeal by replying to our decision or writing to dpo@evocode.ia.br with the subject "Privacy Appeal". We will respond to the appeal within the period required by the law of your state and, in the event of a further denial, we will inform you how to contact the Attorney General or the competent authority of your state.
  • Authorized agent: requests may be made by an authorized agent, upon proof of the authorization.
  • Service provider: where we process data on behalf of business customers, we act as a service provider/processor within the meaning of those laws (including the CCPA/CPRA), in accordance with the clauses of the DPA.

13.4. Canada (PIPEDA and Québec — Law 25)

For data subjects in Canada, we process personal data in compliance with PIPEDA (Personal Information Protection and Electronic Documents Act) and, for Québec residents, with Law 25 (Act to modernize legislative provisions as regards the protection of personal information):

  • We obtain valid consent for the purposes described in this Policy and use the data only for purposes that a reasonable person would consider appropriate;
  • You may access and correct your data and withdraw consent, subject to legal and contractual restrictions, by writing to dpo@evocode.ia.br;
  • Québec: non-essential cookies and technologies operate on an opt-in basis; the person in charge of the protection of personal information is Elizandro Pacheco de Almeida — dpo@evocode.ia.br, whose title and contact details are published in this Policy; you may direct complaints to the Commission d'accès à l'information du Québec, and, at the federal level, to the Office of the Privacy Commissioner of Canada;
  • We inform you that the data may be processed outside Canada (see Section 6), with adequate contractual safeguards.

13.5. Latin America

  • Argentina (Ley 25.326 — Argentine Personal Data Protection Law): you have rights of access, rectification, updating, and deletion of your data, exercisable free of charge at intervals of no less than 6 months (access), through the channel dpo@evocode.ia.br. The Agencia de Acceso a la Información Pública (AAIP) is the supervisory authority, before which you may lodge complaints.
  • Mexico (LFPDPPP — Mexican Federal Law on the Protection of Personal Data Held by Private Parties): data subjects in Mexico may exercise the ARCO rights — Access, Rectification, Cancellation, and Opposition — as well as withdraw consent and limit the use or disclosure of the data, through the channel dpo@evocode.ia.br. This document serves as the aviso de privacidad (privacy notice) for the processing described herein.
  • Chile (Ley 21.719 — new Chilean Data Protection Law): the new Chilean data protection law, effective as of 12/01/2026 and with extraterritorial reach, guarantees rights of access, rectification, deletion, objection, portability, and blocking. We will handle requests from data subjects in Chile through the same channels and will fully comply with the new regime and with the Agencia de Protección de Datos Personales as of its entry into force.
  • Colombia (Ley 1581/2012 — Colombian Data Protection Law): data subjects in Colombia may know, update, and rectify their data, request proof of the authorization, be informed about the use, revoke the authorization and request deletion, and lodge complaints with the Superintendencia de Industria y Comercio (SIC). Channel: dpo@evocode.ia.br.

14. Updates to this Policy

This Policy is versioned and dated — the current version and the version history are available in the /legal hub. We may update it to reflect legal, regulatory, technical, or business changes.

  • Material changes (e.g., new purposes, new sharing categories, change of roles) will be notified with reasonable advance notice, by e-mail and/or a prominent notice in the applications, before they take effect.
  • Non-material changes (e.g., editorial adjustments) may be published directly, with an update of the date and version at the top of this document.
  • Where the law so requires, we will request new consent. Continued use of the services after a new version takes effect indicates awareness of the update, without prejudice to rights that depend on consent.

We recommend revisiting this page periodically. Questions? dpo@evocode.ia.br.


Company identification

EvoCODE IA® Ltda CNPJ: 63.623.332/0001-42 Praça Nossa Senhora do Rosário, 44, Sala 02 — Centro, Piracaia/SP — CEP 12970-000 — Brasil, Brazil Website: https://evocode.ia.br General/legal e-mail: contato@evocode.ia.br Support / Customer service: sac@evocode.ia.br · Official WhatsApp: +55 51 2191-0021 (https://wa.me/555121910021) Data Protection Officer (DPO): Elizandro Pacheco de Almeida — dpo@evocode.ia.br

Privacy Policy — Version 2.3 — Last updated: September 24, 2026.

EvoCODE IA® LogoEvoCODE IA® Logo
AgenteNOCby EvoCODE IA®

SaaS for Management and
Network Troubleshooting

LegalTermsPrivacyCookie PolicyLegal noticeFrequently asked questionsAgenteNOC
Contact

© 2026 AgenteNOC — Inteligência na gestão de redes · Desenvolvido por EvoCODE IA® · CNPJ 63.623.332/0001-42 · Todos os direitos reservados