GET TO KNOW OUR DPA
DATA PROCESSING AGREEMENT (DPA) BETWEEN STARIAN AND ITS CUSTOMERS
STARIAN S/A, a legal entity governed by private law, headquartered at Av. Luiz Boiteux Piazza, no. 1302, Lote 89, Cachoeira Bom Jesus, Florianópolis/SC (State of Santa Catarina), CEP (Postal Code) 88056-000, CNPJ (National Registry of Legal Entities) no. 15.087.394/0001-34, hereinafter referred to as the “Contracted Party”, establishes this Data Processing Agreement (“DPA”) to regulate the conditions applicable to the processing of its customers’ personal data in the context of the use of the Checklist Fácil system.
By contracting any of the products and/or services offered by the Contracted Party, the Contracting Party expressly agrees to the terms established herein.
WHEREAS:
(A) The Contracted Party, as set out in the Master Agreement and its amendments, provides services or grants software licensing to the Contracting Party;
(B) During the provision of services or use of licensed software, the Contracted Party may process personal data of users and end customers of the Contracting Party. In order to ensure compliance with current legislation, the Parties resolve to formalize, in this document, the terms and conditions applicable to such processing.
(C) In compliance with Brazilian legislation, in particular Law No. 13,709/2018 (General Personal Data Protection Law – LGPD), the Contracted Party formalizes this personal data protection document in order to ensure legitimacy and security in the processing of personal data carried out by virtue of the contractual instruments established with the Contracting Parties of its systems. In complying with the purposes of this Agreement, the Contracted Party will perform, in the interest and under the guidance of the Contracting Party, actions classified as processing of personal data in light of Brazilian legislation, in particular Law No. 13,709/2018 (LGPD), observing, when applicable and in a supplementary manner, the legislation in force on data protection in the Contracting Party’s country. Processing operations will be subject to the provisions of this Data Processing Agreement.
DEFINITIONS FOR THE PURPOSE OF INTERPRETING THIS DOCUMENT:
(i) “ANPD”: refers to the public administration body responsible for overseeing, implementing and monitoring compliance with the General Data Protection Law – LGPD and other data protection laws in Brazil;
(ii) “Master Agreement”: refers to the formal agreement signed between the Contracting Party and the Contracted Party, which establishes the general terms and conditions of the commercial relationship between the Parties. This term encompasses the expressions “Agreement” and “Master Agreement” and should be understood as a separate document from this DPA;
(iii) “LGPD”: General Data Protection Law (Law No. 13,709/2018);
(iv) “Personal Data”: information relating to identified or identifiable individuals (“Personal Data”);
(v) “Contracted Party”: refers to the party that provides services to the Contracting Party, assuming the obligations and responsibilities established in the Master Agreement and in this DPA;
(vi) “Contracting Party”: refers to the party that contracts the Contracted Party’s products and/or services, being responsible for complying with the obligations established in the Master Agreement and in this DPA;
(vii) “Controller”: refers to the Contracting Company, responsible for making the main decisions regarding the Processing of Personal Data, including defining the purpose, the nature of the data processed and the duration of the processing. It is the Controller’s responsibility to provide clear instructions to STARIAN S/A (“Operator”), ensuring that the processing is carried out in accordance with its guidelines and applicable legislation. The Controller maintains control over the elements essential for fulfilling the purpose of the processing (“Controller”);
(viii) “Operator”: STARIAN S/A, which carries out the processing of personal data on behalf of the Controller (“Operator”), following its instructions. In performing this function, the Operator may define non-essential operational and technical aspects of the processing, such as the implementation of technical security measures;
(ix) “Data Subject”: refers to the individual to whom the personal data being processed relates. The Data Subject has rights guaranteed by the General Data Protection Law (LGPD), including access, correction, deletion and other forms of control over how their data is collected, used and stored during processing;
(x) “Processing”: any operation performed with personal data, such as those relating to the production, collection, reception, classification, access, use, reproduction, transmission, distribution, processing, storage, archiving, elimination, evaluation or control of information, communication, modification, transfer, diffusion or extraction;
(xi) “Parties”: refers to the Contracting Party, which contracts the services of the Contracted Party, being responsible for complying with the obligations established in the Master Agreement, and to the Contracted Party, which provides services to the Contracting Party, assuming the obligations and responsibilities established in the Master Agreement. The Parties are responsible for complying with the provisions agreed in this document, ensuring compliance with the legislation applicable to the Processing of Personal Data;
(xii) “Platform”: refers to a technological environment that integrates different components, including, but not limited to, SaaS (Software as a Service) systems, software, applications and other digital solutions. The Platform may include features such as data storage, user interfaces, APIs (Application Programming Interfaces) and other tools that enable process optimization and user experience improvement;
(xiii) “Data Subject”: refers to the individual to whom the Personal Data being processed refers.
1. PROCESSING OF PERSONAL DATA
1.1. The Parties declare that they are aware of and comply with current legislation regarding the protection of Personal Data, especially the General Law on the Protection of Personal Data (“LGPD”) and the Internet Civil Rights Framework, observing, when applicable and in a supplementary manner, the legislation in force on data protection in the LICENSEE’s country, within the scope of their respective responsibilities.
1.2. The Controller is responsible for ensuring the existence of a valid legal basis for the processing and for obtaining the necessary consents, when required, in addition to providing adequate information to the Data Subjects. The Operator undertakes to process Personal Data in accordance with the Controller’s instructions, within legal limits.
1.3. The Operator will not receive instructions directly from the Data Subjects, except with express authorization from the Controller and/or legal determination.
1.4. The Personal Data processed by the Operator will be collected, stored and used under the instructions of the Controller, exclusively for the following purposes:
- Fulfillment of contractual obligations established between the Parties;
- Compliance with legal and regulatory obligations of the Controller and/or the Operator, when applicable;
- Exercise of rights in judicial or administrative proceedings;
- Improvement and enhancement of the services and products of the Operator and its partners, as well as for the preparation of statistics and general studies. In these situations, Personal Data will be processed in a way that guarantees confidentiality, preferably in an anonymized manner, whenever possible, and without identifying or specifying the Personal Data Subject.
1.5. The Controller expressly authorizes the Operator to carry out international transfers of Personal Data for the sole and exclusive purpose of fulfilling the purposes set out in the Master Agreement, prohibiting other purposes.
2. OPERATOR’S OBLIGATIONS RELATED TO THE PROTECTION OF PERSONAL DATA
2.1. With regard to the protection of Personal Data, the Operator undertakes to:
- Process Personal Data only to the extent necessary to comply with the subject matter of the Agreement, under the terms of the Master Agreement and amendments signed with the Controller, within the limits of the Agreement;
- Not use Personal Data for any purpose other than that necessary for compliance with the subject matter of the Agreement, under the terms established with the Contracting Party and within the limits of the Agreement;
- Promptly inform the Controller, unless prohibited by law, about any communications or requests from the ANPD or other appropriate authorities involving the Personal Data processed;
- Provide, upon written request from the Controller and at least 48 (forty-eight) business hours in advance, reasonable support, within the scope of its attributions, for impact assessments and consultations with the ANPD;
- Apply, throughout the Processing of Personal Data, appropriate technical and organizational measures to protect data, especially against unauthorized access, leaks, undue changes, accidental or unlawful destruction, among other risks that characterize a “Personal Data Violation”;
- Make available to the Controller, upon request:
- the extraction of the Personal Data processed; and/or
- the deletion of such data, both in cases of termination of the Master Agreement and at the express request of the Controller, provided that the deadlines agreed between the Parties are respected.
2.3. The Operator undertakes to provide the documents and/or information that it has available at the time and that are necessary to demonstrate compliance with legal and contractual obligations.
It is important to highlight that:
- Documents that are not essential for this purpose or that involve confidential, strategic, secret, product or intellectual property information of the Operator or third parties will not be shared;
- Provision will only be required if the documents are technically accessible and are within the scope of the Operator’s responsibilities as established in the LGPD.
2.4. If the Operator identifies that its Platform is being used improperly, whether for illegal or illicit purposes, in breach of data protection legislation or even contrary to morality, by the Controller or any employee thereof, the Operator must report the incident. Upon notification from the Operator, the Controller must immediately cease any improper use of the Platform.
3. VIOLATION OF PERSONAL DATA
3.1. The Operator must notify the Controller within 72 (seventy-two) hours, counted from the moment the fact becomes known, about any incident that may represent a risk or relevant damage to the Data Subjects, allowing the Controller to adopt measures and, if applicable, notify the ANPD as provided for in Article 48 of the LGPD.
3.2. The Incident Notification must:
- describe the nature of the incident;
- describe the likely consequences of the incident;
- describe the measures taken or proposed by the Operator in response to the incident; and
- provide the contact details of the person responsible for processing the Operator’s Personal Data.
3.3. The information related to the reported incident, as set out in the items above, may be supplemented and/or updated later, as new information emerges or it becomes necessary to clarify points that are still under investigation at the time of the initial submission.
3.4. Incidents without relevant impact must be documented internally by the Operator, with records of the measures adopted and containment plans implemented.
3.5. The Operator will be responsible for any duly proven losses to the Controller or its end customers, provided that they are caused exclusively by actions or omissions of the Operator or its Subcontractors.
3.6. If there is a dispute involving the Processing of Personal Data, either Party may request that the dispute be reported to the other, in accordance with Article 125, II, of the CPC, whenever it understands that responsibility lies with the opposing Party or a third party.
4. SUBCONTRACTING
4.1. The Controller authorizes the Operator to subcontract services strictly necessary for compliance with the Agreement, provided that the subcontractors:
- act within the defined purposes; and
- fully comply with the obligations set forth in this Agreement.
4.2. The Operator will be solely responsible for its selection and for their performance under this Agreement, and is obliged to ensure that subcontractors comply with the provisions of the LGPD. Such obligation must be included in the written agreements that the Operator enters into with subcontractors.
5. SHARING PERSONAL DATA
5.1. The Controller’s Personal Data may be shared by the Operator with third parties in the following cases:
- Business succession, as in cases of merger, acquisition or incorporation, subject to prior communication by the Operator;
- Contracting data processing services with third parties (sub-operators), such as cloud hosting, system restoration, Information Technology consultancy, response to incidents or legal and/or administrative demands, as well as with technological platforms and tools, including solutions based on artificial intelligence, used to enable customer service, optimize the provision of services or implement operational improvements;
- Sharing with companies in the same economic group of the Operator, aiming at the integration, administration or support of operations, as long as the originally intended purposes and applicable legal requirements are respected.
6. AUDIT AND INSPECTION
6.1. The Operator undertakes to provide the Controller with the information and documents necessary to demonstrate compliance with this Agreement, provided that they are related to its duties under the LGPD and that it is legally or contractually obliged to make them available. Confidential information, such as trade secrets, business strategies or intellectual property, will not be shared unless there is an express contractual or legal obligation to do so.
6.2. The Controller may request the Operator to carry out a remote audit to verify compliance with the obligations set forth in this Agreement. Monitoring will be carried out by an employee appointed by the Operator, and any costs incurred by this activity will be borne exclusively by the Controller.
The audit must meet the following conditions:
- have the sole and exclusive purpose of attesting to compliance with obligations relating to the protection and privacy of Personal Data;
- not result in access to information protected by commercial confidentiality or intellectual property rights of the Operator or third parties;
- be technically feasible and reasonable, without compromising the security and integrity of the Operator’s systems or impacting its operations;
- the Controller must formalize the request at least 30 (thirty) days in advance, specifying the scope, purpose and subject matter of the audit;
- consider the Operator’s responsibilities under the LGPD, ensuring that only relevant information compatible with its obligations is audited.
7. RIGHTS OF THE DATA SUBJECT
7.1. The Controller will be responsible for informing Data Subjects about their rights and ensuring support, including access, rectification, deletion, limitation, portability or elimination of data.
7.2. The Operator will provide reasonable cooperation and assistance, when necessary, to support the Controller in responding to Data Subjects’ requests. This includes:
- informing the Controller about any request received directly from Data Subjects;
- supporting the Controller with the information and measures necessary to fulfill the request in the exercise of the rights provided for in Brazilian legislation, in particular Law No. 13,709/2018 (General Personal Data Protection Law – LGPD), observing, when applicable and in a supplementary manner, the legislation in force on data protection in the LICENSEE’s country.
7.3. If the assistance mentioned above requires significant resources from the Operator, such as time, technology, personnel or technical adaptations, the provision of support shall be negotiated in advance between the Parties, considering the efforts involved.
8. DELETING PERSONAL DATA
8.1. After termination of the Agreement, the Operator may retain Personal Data only if necessary for legal obligations, audits or protection of rights. After this period, the data will be permanently deleted.
8.2. If immediate deletion of data is not technically possible, for example in backups, the Operator undertakes to make such data inaccessible and delete it as soon as technically feasible.
9. EXCLUSION AND LIMITATION OF LIABILITY
9.1. The Operator shall not be liable for damages or violations arising from instructions provided by the Controller if such instructions are in breach of applicable legislation, including the LGPD, provided that the Processing has been carried out in good faith, within the contractual limits and in accordance with the express guidelines of the Controller.
9.2. The Operator’s liability is limited to direct losses proven to have been caused by its actions, omissions or those of its subcontractors, as provided for by law, and shall not exceed the total value of the Agreement. There will be no liability for lost profits or indirect damages, except in cases of intent or gross negligence.
9.3. The Operator does not guarantee that harmful events will not occur. Given the possibility of failures or bad faith on the part of its own users, or even malicious actions by third parties, the Controller acknowledges that the Operator’s civil and administrative liability is limited exclusively to damages arising from security incidents caused by the Operator’s own negligent or deliberate conduct or that of its staff.
10. MISCELLANEOUS
10.1. The Controller is and will continue to be the owner of the data processed, as well as being responsible for any third-party data, including Personal Data, that it enters into the software/platform owned by the Operator.
10.2. The Controller may not transfer to the Operator responsibility for failures related to the Processing of data under its responsibility.
10.3. The terms and conditions of the DPA form part of all licensing and service agreements executed and to be executed between the Controller and the Operator for all purposes, and the provisions contained herein prevail over any conflicting provisions on data and Processing provided for in the Master Agreement.
11. CONTACT PERSONS, QUESTIONS AND REQUESTS
11.1. Questions or requests related to the Processing of Personal Data should be directed to Starian’s Data Officer via email: protecaodedados@starian.com.
11.2. Communications regarding the occurrence of a security incident must be classified as confidential, using resources to ensure that the recipient actually receives them.
11.3. The jurisdiction of the judicial district of Florianópolis is elected for the processing and analysis of any type of controversy, conflict or litigation associated with the facts governed by this instrument.
UPDATED ON: 6/12/2026