Data Processing Addendum (DPA)
Version: 1.2.0 · Last updated: 2026-07-28
This Data Processing Addendum (DPA) is an integral part of the Software Adhesion Contract between BRYCKS (MATHEUS GOBETTI SILVA DESENVOLVIMENTO DE SOFTWARES LTDA, CNPJ 64.691.700/0001-52) and the Tenant. It regulates the processing of personal data carried out by BRYCKS as Processor on behalf of the Tenant (Controller), in compliance with Brazilian LGPD (Law 13.709/2018), ANPD Resolution CD/ANPD No. 18/2024 (DPO) and ANPD Resolution CD/ANPD No. 19/2024 (International Transfer).
1. Purpose
The Processor will process personal data provided by the Controller solely to deliver the Moovyi platform services under the Adhesion Contract: hosting, indexing, transactional email, messaging service (WhatsApp Business and Instagram Direct), financing simulations, sales records and contract issuance, electronic signature, bank statement import and reconciliation, marketplace publishing, vehicle transfer records with RENAVE, measurement of the Controller's advertising campaigns, reporting and data subject requests.
2. Duration
Processing lasts for the term of the Adhesion Contract.
3. Data subjects and categories of data
- Subjects: Tenant staff with panel access and salespeople registered for commission purposes; leads and end-customers captured by the Tenant via website, forms and messaging channels; identifiable counterparties in bank statements imported by the Tenant.
- Data categories: name, email, phone, CPF (AES-256-GCM encrypted at rest), address, birth date, declared income, financing data, vehicle interest, IP and user agent, access logs.
- Messaging data (when the Controller activates the Meta integrations): WhatsApp number, Instagram profile name and handle, content of the messages exchanged and ad campaign identifiers (e.g. CTWA).
- Sale, contract and electronic signature data: buyer details, amounts, payment methods, contract content and signature evidence (date, time, IP, signer email).
- Controller financial data: bank branch and account number and transaction descriptions, which may contain an individual counterparty name — encrypted at rest, with account lookup by blind index (HMAC).
4. Processor obligations
- Process data only under lawful, documented Controller instructions.
- Adopt security measures compatible with LGPD art. 46 (encryption at rest for CPF, bank data and transaction descriptions, blind-index lookup, TLS in transit, RBAC, per-tenant isolation at the data layer, audit logs, segregated backups).
- Ensure confidentiality from staff and sub-processors.
- Assist the Controller with data subject requests, providing export, anonymization, deletion and retention-policy features in the panel.
5. Controller representations and warranties
The Controller represents and warrants that it holds an adequate legal basis and meets its transparency duties towards data subjects for all personal data it submits to the platform or instructs the Processor to handle, and is liable to the Processor and to third parties for instructions that breach the LGPD. This expressly covers:
- Contacting data subjects through the integrated messaging channels, including outbound campaigns and re-engagement of old contacts.
- Third-party data contained in bank statements the Controller imports into the Cash module, whose processing relies on the Controller's own tax, accounting and reconciliation duties.
- Buyer and signer data used to issue contracts and collect electronic signatures.
The Controller undertakes not to enter sensitive personal data (LGPD art. 5, II) into free-text fields nor to request it through the messaging channels, as the platform was not designed to process it.
6. Incident notification
The Processor will notify the Controller within 48 (forty-eight) hours of becoming aware of any incident likely to cause material risk to data subjects, including nature of affected data, affected subjects, technical measures taken and mitigation steps. The Controller is responsible for formal notices to ANPD and data subjects.
7. Sub-processors
The Controller authorizes the Processor to engage Stripe (card payments), Abacate Pay (recurring PIX), Supabase (database, auth and file storage, on AWS infrastructure), Resend, Vercel, Railway, Google (Maps and — subject to visitor consent on moovyi.com — Tag Manager, Analytics 4 and Ads), Microsoft Clarity (subject to visitor consent), ViaCEP, ReceitaWS, FIPE and API Brasil, plus the following optional sub-processors, engaged only when the Controller activates the integration: Meta Platforms (WhatsApp Business, Instagram Messaging, Conversions API), Autentique (electronic signature), SERPRO (RENAVE) and the marketplaces Mercado Livre, OLX, Webmotors and iCarros. Material changes to this list are communicated 30 days in advance and may be objected to in writing within that period.
8. International transfer
International transfers rely on the Standard Contractual Clauses approved by ANPD (Resolution CD/ANPD No. 19/2024) signed with each sub-processor. The ANPD SCCs prevail over conflicting provisions of this DPA.
9. Ad measurement (Meta Conversions API)
Activating the Conversions API is an express instruction of the Controller. Once active, the Processor sends the Controller's own conversion events (e.g. lead received, sale closed) to Meta containing data subject identifiers transmitted exclusively as cryptographic hashes, for the sole purpose of measuring the Controller's ad performance.
In that operation Meta processes data under its own terms and may qualify as an independent controller. The Controller must hold a legal basis and provide adequate transparency to data subjects regarding this sharing, and may disable the integration at any time in the admin panel.
10. Audit
The Controller may request reasonable security documentation with 15 days notice. On-site audits require prior agreement and may be replaced by recognized certifications (SOC 2, ISO 27001) when available.
11. Return or deletion at termination
The Tenant may request data export in a structured format within 30 days after contract termination, after which data will be deleted or anonymized. The Processor will not withhold data as leverage for payment defaults.
12. Processor's DPO
Matheus Gobetti Silva — email dpo@moovyi.com, phone +55 (16) 99635-4165.
13. Governing law and venue
Brazilian law; São Paulo/SP venue (per clause 19 of the Adhesion Contract).