How Belo AI collects, uses, and protects personal information, including cookies, retention, safeguards, and privacy rights.
Status: DRAFT — counsel review required (not operative until counsel-approved publish)
Why: how we handle personal data (LGPD primary; other regimes where applicable).
When users see it: public page; linked from the trust page and Terms.
URL: 1
Translations: pt-BR · EN · es-ES · fr-FR (same path; app locale)
Source: 2026-07-21 reconciliation with lawyer commercial briefing · consolidates legacy privacy pages
Last updated: 2026-07-21
Counsel gate: qualified lawyer approval remains the final legal gate before operative publication.
This Privacy & Data Notice (“Notice”) explains how Belo Inteligência Artificial Ltda (“Belo AI,” “we,” “us”) collects, uses, shares, retains, and protects information when you use our websites, applications, APIs, and related services (the “Services” — AI-assisted data analysis that produces defensible, traceable analytical work products, as described in the Terms of Service §1).
Related documents:
Encarregado: Paulino Rodrigues de Oliveira Neto — contact belo@belo.ai (subject: “Privacy” or “Encarregado”). See §1.1.
Belo AI is provided by Belo Inteligência Artificial Ltda, CNPJ 55.692.612/0001-84, Rua da Consolação, 2302, Consolação, São Paulo/SP – CEP 01302-001, Brazil.
There is no United States (Delaware or other) legal entity operating the Services. Older copy stating that Belo AI “operates from the United States” or naming “Belo AI, Inc.” is incorrect and is withdrawn. Active commercial focus is Brazil; translated UI does not mean active sale in other markets.
Depending on context:
Under LGPD Art. 41, the controller must indicate an encarregado and, under Art. 41 §1, publicly disclose the encarregado’s identity and contact information (preferably on the controller’s website). Belo AI designates:
The encarregado’s activities include those in LGPD Art. 41 §2: accepting data-subject complaints and communications, providing clarifications, adopting measures, receiving ANPD communications, and guiding personnel on data-protection practices. Messages to the contact above are treated as communications to the named encarregado.
If Belo AI later designates a different natural person (or relies on an ANPD-recognized exemption from indication under complementary rules such as ANPD Resolution CD/ANPD nº 2/2022 for qualifying small processing agents, if counsel confirms applicability), the identity and contact published on this page will be updated without requiring re-acceptance of the Terms.
We do not purchase personal data from data brokers. We may receive:
We do not intentionally request sensitive/special-category personal data (LGPD Art. 5, II). Because the Services accept arbitrary analytical inputs, you or your organization may still submit such data in prompts or files. Do so only with a lawful basis and required safeguards. Enterprise customers remain responsible for lawful instructions under the DPA. If sensitive data is submitted, we process it only as needed to provide the requested feature and under applicable law.
We use information for the following purposes. Legal bases under LGPD Art. 7 are typical anchors and may vary by flow:
We do not sell personal information and do not share personal information for cross-context behavioral advertising.
Content you submit (including prompts, files, and team content) is processed to provide functionality such as retrieval, analysis, charting, and AI-assisted responses. For enterprise processing under a DPA, Customer Personal Data is processed only on documented instructions.
Belo AI does not train or fine-tune foundation models on Customer Content. Belo AI is a deployer of third-party models. Model providers used under enterprise API configurations are bound not to train on customer inputs under their applicable enterprise terms. AI model providers used are those identified on the Subprocessor List.
Prompts and relevant context may be sent to model providers solely to generate outputs for your request. Providers process data under their terms and the Subprocessor List.
The Services generate analytical outputs that may assist human decisions. You remain responsible for human review of high-impact decisions. Data subjects may have rights to review automated decisions under LGPD Art. 20 and analogous laws where applicable.
Unless a written enterprise agreement says otherwise, Belo AI may use de-identified, aggregated, or transformed service signals to operate, secure, and improve the Services — for example:
This carve-out does not authorize training models on your prompts, files, or workspace content.
BYOC note: License heartbeat telemetry for customer-cloud deployments is described in the Corporate/BYOC Addendum §6 and in §13 of this Notice. Heartbeats are designed as aggregate / deployment metadata (no prompts, files, row data, or schemas). Belo AI processes heartbeat metadata as independent controller for licensing, security, billing disputes, and legal compliance (LGPD Art. 7, V and/or IX and/or II as applicable). Where a field relates to an identifiable natural person in context, it is treated as personal data with the rights in §11; aggregate counts that cannot reasonably identify a person are not treated as personal data. International transfers of such fields follow §10.2 and Addendum §6.5.5 (not DPA Annex C).
We share information only as needed with categories of providers that perform functions essential to the Services. Infrastructure is provided by cloud providers (current: Google Cloud; the Subprocessor List identifies current providers and pre-authorized permitted alternatives, such as Amazon Web Services). Typical categories:
The detailed, versioned list of specific Subprocessors that process personal data on our behalf — with vendors, purposes, locations, and transfer mechanisms — is on the Subprocessor List. For enterprise customers, notice and objection rights for Subprocessor changes are as stated in the DPA and on the List (including pre-authorized switches among listed permitted alternatives and advance List updates for new Subprocessors).
We may also share information:
We use essential cookies and similar technologies for authentication, session management, security, and core functionality. These are required for the Services to function and cannot be disabled via an in-app toggle.
We may store preferences (for example, display theme) in browser storage such as localStorage or sessionStorage.
We use essential cookies and Google Analytics 4 (GA4), loaded only after the user’s consent via a first-party consent banner, with Consent Mode v2, and without Google advertising / Google ad signals. We do not use third-party advertising cookies to read or monetize chat content.
Messages sent to AI assistants run in a dedicated product context for providing the feature. We do not use advertising networks to monetize chat content.
You can adjust browser settings to remove or block cookies; doing so may break authentication or other core features. Analytics preferences can be managed through the consent banner on the website.
We retain personal information only as long as necessary for the purposes in this Notice, unless a longer period is required or permitted by law (including tax, accounting, security, and dispute purposes).
Typical categories (illustrative; enterprise DPA may set different defaults):
Upon account closure or verified deletion request, we delete or anonymize personal data in the ordinary course, subject to legal retention. Organization-level export and deletion tooling exist; the per-user individual export/deletion flow is under development. Enterprise customers may use available export/delete tooling and DPA processes.
Proportionate to size and risk, Belo AI maintains administrative, technical, and organizational safeguards, including:
No system is 100% secure. Belo AI is not currently certified under SOC 2 or ISO 27001; this Notice does not claim formal certifications. Current security and compliance information is on the Trust page2 (belo.ai/trust).
Personal data may be processed in Brazil, the United States, and other locations where Belo AI and its Subprocessors operate (see Subprocessor List). Default hosted compute may use the current cloud provider’s default region (e.g., GCP us-central1) unless otherwise configured. Enterprise residency commitments exist only if expressly contracted.
International transfers of personal data under this Notice rely on one or more of the following LGPD Art. 33 bases, as applicable to the flow:
Where Art. 33, II, b applies, Belo AI relies on the official standard contractual clauses adopted by ANPD Resolution CD/ANPD nº 19/2024, as published by ANPD/DOU, incorporated by reference:
The official public text of those clauses controls; no unauthorized alteration is made. Supplementary measures (encryption in transit/at rest, access control, least-data routing to model providers) apply as described in §9 and the DPA Annex B.
Where GDPR/UK GDPR apply to a specific customer relationship, EU SCCs / UK Addendum apply only if the optional DPA module is selected in an Order Form or transfer addendum.
Subject to legal limits, you may request confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, withdrawal of consent (where processing is based on consent), and review of automated decisions (Art. 20).
Organization-level export and deletion tooling are available; the per-user individual export/deletion flow is under development. Requests may also be sent to belo@belo.ai (see §11.4).
Where GDPR / UK GDPR applies, you may have rights of access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority.
Where the GDPR applies, Belo AI will maintain an EU representative under art. 27; identity and contact will be published here.
Where U.S. state privacy laws apply to our processing (Belo AI's international checkout is available to U.S. users; U.S. state privacy rights apply as statutory thresholds are met), you may have rights to know/access, correct, delete, obtain a copy, and opt out of certain processing. We will honor applicable requests from residents of states whose laws apply to us, including California (CPRA) and other states as they become applicable. We do not sell personal information and do not share personal information for cross-context behavioral advertising as those terms are defined under CPRA.
Email belo@belo.ai with sufficient detail to verify your identity and locate the data. We may need additional verification. Authorized agents may submit requests where law allows, subject to proof of authorization.
Enterprise end-users should typically contact their organization first; Belo AI will assist the customer under the DPA.
The Services are not intended for children under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided data, contact us for deletion.
If your organization runs Belo AI in its own cloud under a Corporate/BYOC Addendum (Supported Cloud Environment as defined in the Order Form; current: Google Cloud Platform — GCP only; permitted alternatives when offered, per the Addendum and Subprocessor List):
We may update this Notice from time to time. The updated version will be posted with a revised effective date. Material changes will be notified reasonably (website, in-product, and/or email). Where re-acceptance of Terms is required, the legal-acceptance version gate applies.
Belo Inteligência Artificial Ltda
CNPJ: 55.692.612/0001-84
Rua da Consolação, 2302, Consolação, São Paulo/SP – CEP 01302-001 – Brazil
Encarregado (LGPD Art. 41): Paulino Rodrigues de Oliveira Neto — belo@belo.ai (subject: “Encarregado” or “Privacy”). See §1.1.
For enterprise DPA / transfer questions: belo@belo.ai (subject: “Privacy / DPA”).
Belo AI



Jun 16



