
The Belo AI Data Processing Agreement covering processing instructions, security measures, subprocessors, transfers, retention, and audit rights.
Status: DRAFT — counsel review required (not operative until counsel-approved publish)
Why: processor terms (LGPD primary; GDPR/UK modular schedule) for hosted SaaS.
When users see it: public page /page/legal-dpa; Trust Center link.
URL: 1
Translations: pt-BR · EN · es-ES · fr-FR (same path; app locale)
Source: 2026-07-21 reconciliation with lawyer commercial briefing
Counsel gate: qualified lawyer approval remains the final legal gate before operative publication.
This DPA forms part of the agreement between Customer and Belo for the Services (Terms of Service + Order Form / Enterprise Agreement, as applicable) (the “Agreement”). The Services are Belo’s AI-assisted data analysis platform that produces defensible, traceable analytical work products (Terms §1).
Order of precedence (aligned across the package): signed Order Form > Corporate/BYOC Addendum (if any) > this DPA (for Personal Data processing) > product-specific terms > Terms of Service (including Schedule A).
Capitalized terms not defined here have the meaning in the Agreement.
2.1 Customer is Controller (Controlador). Belo is Operator/Processor (Operador) for Personal Data processed on Customer’s documented instructions in providing the Services.
2.2 Belo processes Personal Data only:
(a) to provide and support the Services;
(b) on Customer’s documented instructions (including configuration of the Services and this DPA); and
(c) as required by applicable law (in which case Belo informs Customer unless legally prohibited).
2.3 Subject matter, duration, nature, purpose, categories of data, and data subjects are described in Annex A.
2.4 Customer is responsible for the lawfulness of its instructions and for providing all notices and obtaining all rights/consents required for Belo to process Personal Data.
2.5 Hosted SaaS vs BYOC. This DPA applies only to hosted SaaS processing where Customer Content / Personal Data is processed in Belo-operated environments (cloud-class infrastructure providers as set out in the Subprocessor List; currently Google Cloud; pre-authorized permitted alternatives such as AWS, via List update). For BYOC deployments (GCP only):
(a) Customer Content remains in Customer’s cloud under the Corporate/BYOC Addendum and is not re-characterized as hosted processor data under this DPA; and
(b) License heartbeat metadata is processed by Belo as independent controller under Corporate/BYOC Addendum §6.5 (not as operator/processor under this DPA). International transfers of any heartbeat personal data follow Addendum §6.5.5 and the Privacy & Data Notice — not the Customer→Belo operator role map in Annex C of this DPA.
Customer instructs Belo to process Personal Data solely to provide the Services as described in the Agreement and Annex A. Belo shall promptly inform Customer if, in Belo’s opinion, an instruction violates applicable Data Protection Laws (without obligation to provide legal advice).
Belo ensures that persons authorized to process Personal Data are bound by confidentiality obligations and informed of relevant data-protection requirements.
Belo implements and maintains technical and organizational measures appropriate to the risk, described in Annex B, including encryption in transit and at rest for primary systems, access control, logging, vulnerability management, backups, and incident response.
This DPA does not represent that Belo holds SOC 2, ISO 27001, or similar certifications. Audit evidence is provided as available under §11.
6.1 General authorization. Customer authorizes Belo to engage the Subprocessors identified in the then-current Subprocessor List published by Belo — including, from the outset, providers identified as current or as permitted alternatives for each function (hosting, storage, inference, translation, search, etc.). Switching between pre-authorized equivalent-class providers (e.g., Google Cloud → AWS) takes effect via List update without prior notice, provided the processing role, safeguards, and transfer mechanism remain equivalent.
6.2 Belo will bind each Subprocessor to data-protection obligations substantially no less protective than this DPA.
6.3 Notice of new Subprocessors. The addition of a new Subprocessor — i.e., one not listed as a current provider or as a permitted alternative — is communicated by updating the Subprocessor List at least fifteen (15) days before use. Customers who wish to receive update alerts may subscribe to the notifications indicated on the List; the published update constitutes notice for all purposes of this DPA.
6.4 Objection. If a paid Customer reasonably objects to a new Subprocessor on data-protection grounds within the §6.3 period, the parties will discuss in good faith. If unresolved before the change takes effect, Customer may terminate the affected Services as its sole remedy (fees prepaid for unused periods handled per the Agreement / mandatory law).
6.5 Emergency replacements for security or legal reasons may occur with shorter notice; Belo will notify as soon as practicable.
Belo will provide reasonable assistance to Customer in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection, and automated-decision review under LGPD Art. 20 where applicable), taking into account the nature of Processing and information available to Belo.
Where feasible, Org-level export and deletion tooling may help Customer fulfill requests programmatically. Customer remains primarily responsible for responding to requests from its end users.
8.1 Belo will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Data processed under this DPA. Belo’s internal incident-response process is being institutionalized.
8.2 Brazil / LGPD support window. To support Customer’s controller obligations under ANPD Resolution CD/ANPD nº 15/2024 (controller notification to ANPD within three (3) business days of awareness for incidents involving relevant risk/harm), Belo will notify Customer without undue delay and will use commercially reasonable efforts to notify within three (3) business days of Belo’s awareness of a qualifying Security Incident — and earlier where practicable — so Customer can meet its own deadlines. This clause is a processor support commitment to Customer and does not transfer controller duties to Belo.
8.3 Notification will include available details about the nature of the incident, categories/approximate volume of data subjects and records (if known), likely consequences, and measures taken or proposed.
8.4 Where GDPR applies, notification will also be made without undue delay and, at the latest, within 72 hours after Belo’s awareness of GDPR-relevant incidents, unless a different contractual window is expressly set in the Order Form.
8.5 Belo will reasonably cooperate with Customer’s investigation and remediation.
Customer acknowledges that Personal Data may be processed in countries where Belo and Subprocessors operate (see Subprocessor List — cloud-class infrastructure providers: currently Google Cloud; pre-authorized permitted alternatives such as AWS, via List update). Belo will ensure a lawful transfer mechanism under applicable Data Protection Laws, per the modular schedule below.
This module always applies to international transfers of Personal Data subject to the LGPD that require standard contractual clauses under Art. 33, II, b. It is not optional and does not depend on Order Form selection.
The parties incorporate by reference the official standard contractual clauses adopted by ANPD Resolution CD/ANPD nº 19/2024, as published by ANPD in the Diário Oficial da União / official ANPD publication, without unauthorized alteration.
Role mapping (default for this DPA — hosted SaaS only):
Out of scope of this table / Annex C: BYOC license heartbeats (Belo as independent controller). See Corporate/BYOC Addendum §6.5.5 and Privacy & Data Notice §10.2 (controller→controller or Art. 33, IX path as applicable).
Annex C records the incorporation and completion details for the hosted role map above. The official ANPD text prevails over any summary. Supplementary measures include encryption in transit and at rest for primary systems, access control, and least-data routing to model providers for inference (Annex B).
Where a hosted transfer is instead (or also) necessary under Art. 33, IX because it is necessary to meet Art. 7, II, V, or VI (the only Art. 7 hypotheses Art. 33, IX incorporates), that basis applies in parallel to the extent permitted by law. Art. 7, IX (legitimate interest) is a processing basis and does not, by itself, open Art. 33, IX for international transfers.
This module applies when GDPR and/or UK GDPR apply to Personal Data processed under this DPA (legal trigger — Art. 3 and equivalents — not mere commercial selection by Customer). Documentary completion of the module (filling SCC / IDTA annexes) is effected via Order Form or transfer addendum, without the absence of a completed form suspending applicable legal obligations.
When the module applies:
(a) EU: the European Commission Standard Contractual Clauses (Module Two: Controller → Processor, and Module Three: Processor → Processor where applicable) are incorporated by reference and completed with the details in Annex A/B and the Subprocessor List;
(b) UK: the UK International Data Transfer Addendum (or IDTA) is incorporated as required by UK law.
Completion details: Annex D.
Transfers subject to Swiss data-protection law will use the EU SCCs with Swiss-required modifications where applicable. This module is reserved for documentary activation when Swiss processing volume or risk warrants it; legal application, if any, does not depend on commercial reservation.
Belo retains Personal Data only as long as needed to provide the Services or as required by law. Upon termination of the Services or written request, Belo will delete or return Personal Data within a reasonable period, generally up to thirty (30) days, upon written request; deletion confirmation provided upon request — unless law requires continued retention (including backups until expiry of backup cycles).
Customer may audit Belo’s Processing activities related to this DPA with at least thirty (30) days’ prior written notice, no more than once per year (unless a Security Incident or regulatory requirement justifies an additional audit), during business hours, subject to confidentiality and reasonable security constraints.
Belo may satisfy audit requests by providing available third-party reports, questionnaires, and documentation. No certification is promised by this clause.
Belo will not use Customer Personal Data or Customer Content to train or fine-tune foundation models. Model providers are engaged under terms that restrict training on customer inputs for the enterprise API configurations Belo uses. De-identified/aggregated telemetry for product improvement remains as described in the Privacy & Data Notice and Terms, and does not include training on Customer Content.
Liability under this DPA is subject to the limitations and exclusions in the Agreement, except where mandatory Data Protection Laws prohibit limitation. This DPA lasts for the term of the Services and survives as needed for post-termination deletion and confidentiality.
This DPA is governed by the governing law of the Agreement (Brazilian law for standard Terms), without prejudice to mandatory Data Protection Laws and any arbitration/court terms in the Agreement.
This DPA is accepted electronically as part of the Terms of Service (incorporation by reference) or, for enterprise customers, via execution of an Order Form that references it. No standalone signature is required.
STATUS: OPERATIVE BY INCORPORATION BY REFERENCE — HOSTED CUSTOMER PERSONAL DATA ONLY.
Official source pointer: ANPD Resolution CD/ANPD nº 19/2024 (standard contractual clauses for international transfers), DOU publication.
Complete when GDPR and/or UK GDPR apply to Personal Data processed (see §9.3); documentary execution via Order Form or transfer addendum:




Belo AI



Jun 16