Platform Terms of Use
Last updated: 2026-06-16 Effective date: June 16, 2026
Translation notice. This is a faithful translation of the binding Portuguese-language (pt-BR) version. The Portuguese version is the sole binding and enforceable version and prevails over this English translation on any divergence.
These Terms of Use (“Terms”) govern access to and use of the Platform and the Services made available by Sparsu, a platform conducted by Antônio Amaral Egydio Martins, a natural person domiciled in the city of São Paulo/SP, Brazil, currently in the process of incorporating a legal entity, hereinafter the “Company”, by the Client — a natural or legal person — and its Authorized Users. Until the incorporation of the legal entity is completed, the Company’s obligations are undertaken by the natural person identified above; once the company is incorporated, these Terms will be updated to reflect its corporate name and CNPJ enrollment number.
Language and prevalence. The Portuguese (pt-BR) version of these Terms is the sole binding version and prevails over any translation into English or any other language in the event of divergence. The translation is provided for convenience only.
1. Acceptance, object and incorporated documents
1.1. Object. These Terms constitute the agreement governing the Company’s provision to the Client — whether a natural or legal person — of the Platform and the chargeback data and dispute Services described in Section 3.
1.2. Acceptance. Acceptance of these Terms binds the Client — a natural or legal person — from first access to or first use of the Platform, on its own behalf and on behalf of its Authorized Users. By accessing or using the Platform, the Client represents that it has read, understood and fully accepted these Terms.
1.3. Incorporation of the Privacy Policy. The Company’s Privacy Policy, available at https://dispute.sparsu.com, forms part of these Terms by reference. Acceptance of these Terms constitutes acceptance of the Privacy Policy, which is the privacy notice required by art. 9 of Law No. 13,709/2018 (the “LGPD”).
1.4. Data Processing Agreement (DPA). The processing of personal data carried out by the Company on behalf of and under the documented instructions of the Client, in the operator scope, is governed by the Data Processing Agreement (DPA) entered into with each Client under art. 39 of the LGPD. Where the Client is a BCB-regulated institution, the DPA additionally carries the set of clauses required by art. 17 of Resolution BCB No. 85/2021 (and, for banking clients, of Resolution CMN No. 4,893/2021).
1.5. No financial clauses. These Terms establish no prices, fees, consideration or payment conditions. In this present version, the Services carry no charges; any commercial conditions, should they ever exist, will be the subject of a separate instrument agreed between the parties.
2. Definitions
For the purposes of these Terms, the following terms, when capitalized, have the meanings set out below. The binding terms in Portuguese are “operador” and “controlador”; the expressions “operator”/“processor” and “controller” are reserved for this translation.
2.1. Platform: the set of software, API, web interface and infrastructure provided by the Company for the ingestion, storage, representment-package building and management of chargebacks and disputes.
2.2. Services: the chargeback data and dispute features made available through the Platform — ingestion, representment-package building, dispute representment and response, and management of reason codes/ARNs and evidence files.
2.3. API: the HTTP/JSON interface through which the Client integrates with the Platform, which may also be accessed through a web interface.
2.4. Client (or Contracting Institution, where a legal entity): any person, natural or legal, who registers on the Platform and uses the Services and/or the APIs by accepting these Terms. A Client may be, among others, a payment institution, an acquirer/card-acceptance institution or a sub-acquirer — whether or not authorized by the Central Bank of Brazil (“BCB”) —, a merchant/establishment, or a natural person. Any person with access to the website may register. The Client is the controller of its cardholders’ data for dispute purposes. Where the Client is a BCB-regulated institution, the applicable regulatory pass-through clauses of these Terms and the DPA additionally apply.
2.5. Authorized Users: the Client’s employees or representatives authorized by it to access the Platform under the Client’s credentials, for whose acts the Client is responsible.
2.6. Data subject or Cardholder: the natural person to whom the processed personal data relates — the cardholder whose dispute the Client routes to the Platform, a third party to the Company and a consumer for the purposes of the Consumer Defense Code (“CDC”, Law No. 8,078/1990; STJ Súmula 297). The data subject is not a user of the Platform.
2.7. Operator: the Company, when it processes personal data on behalf of the Client-controller and under its documented instructions (LGPD art. 5, VII).
2.8. Controller: the Company, when, independently determining the purposes and means, it reuses Client-sourced Chargeback Data for its own purposes (LGPD art. 5, VI).
2.9. Data Processing Agreement (DPA): the instrument governing processing in the operator scope, under the documented instructions of the Client-controller (LGPD art. 39), and which, where the Client is a BCB-regulated institution, carries the set of clauses of art. 17 of Resolution BCB No. 85/2021; it does not authorize the Company’s own use (controller).
2.10. Chargeback Data: the dispute data processed on the Platform — network, truncated PAN (first 6 digits of the BIN + last 4 digits), ARN, reason code, amount, currency, merchant name, cardholder name, email and document fragment, device fingerprint, status, source feed and evidence metadata — without CVV/CVC, PIN, full magnetic track or full PAN.
2.11. Sensitive Authentication Data (SAD): the card verification value (CVV/CVC/CVV2/CVC2/CID/CAV2), the full magnetic track and the PIN/PIN block — data whose storage is prohibited to everyone except issuers; the Company is not an issuer and does not store such data, without exception, even if encrypted.
2.12. Sub-processor (Subcontratado/Suboperador): the third party engaged by the Company under flow-down obligations for part of the service (cloud, object storage, model hosting, evidence/email storage), recorded in the Company’s internal register.
2.13. Security Incident: an event affecting Client data, subject to notification to the Client and to the regime of Resolution CD/ANPD No. 15/2024.
2.14. Data Residency: the commitment that all storage and processing of Chargeback Data remains in Brazil, save for international transfers carried out under a mechanism of art. 33 of the LGPD.
2.15. Data Protection Officer (Encarregado): the person designated as the channel of communication between the Company, the data subjects and the National Data Protection Authority (“ANPD”), under art. 41 of the LGPD; also the contact for Security Incidents. To be appointed — write to comercial@sparsu.com.
3. Description of the Platform and Services
3.1. The Platform is a chargeback data and dispute API, provided as an HTTP/JSON interface plus a web interface, which delivers: (a) ingestion of chargeback/dispute records; (b) storage of such records; (c) representment-package building; (d) dispute representment and response; (e) management of reason codes, ARNs and evidence files.
3.2. Present reality. These Terms describe only the present reality of the Services. The Company undertakes no obligation, under these Terms, regarding features, products or data uses that are future and not yet existing.
4. Eligibility and Authorized Users
4.1. Eligibility. The Platform is open to self-serve registration: any person, natural or legal — including payment institutions, acquirers/card-acceptance institutions, sub-acquirers (whether or not authorized by the BCB), merchants/establishments and natural persons — may register and use it, together with their Authorized Users. Where the Client is a BCB-regulated institution, the regulatory pass-through provisions of these Terms additionally apply to it.
4.2. Responsibility for Authorized Users. The Client is responsible for the acts of its Authorized Users and for their compliance with these Terms.
4.3. Data subjects are third parties. Data subjects (cardholders) are third parties to the Company and are not users of the Platform; access to the Platform is restricted to the Client and its Authorized Users.
5. Account, API access and credential security
5.1. Duty of safekeeping. The Client and its Authorized Users must protect API keys and other access credentials, keep them confidential, observe the least-privilege principle in their assignment, and be responsible for all activity carried out under their credentials.
5.2. Credential compromise. The Client must notify the Company, without delay, of any loss, compromise or unauthorized use of credentials.
5.3. Company measures. The Company, on its side, enforces encryption in transit (TLS) and at rest, with documented key management, and per-Client logical segregation, with no data sharing between distinct Clients, as set out in Section 15 (Confidentiality).
6. Acceptable use and prohibitions
6.1. Prohibition on Sensitive Authentication Data (SAD). The Client is prohibited from submitting to the Platform any Sensitive Authentication Data — CVV/CVC, PIN, full magnetic track or full PAN. Such data is rejected at the API edge by construction (the Company uses strict object validation and an automated control that rejects sensitive authentication data at the boundary, rejecting any forbidden key and any value shaped like a full PAN).
6.2. Minimization of identifiers. The Client must not submit more cardholder identifiers than necessary for the dispute purpose; of the cardholder’s document, only the fragment of up to 8 characters is admitted, never the full document. The minimization duty (LGPD art. 6, III) rests on the Client as to the data it routes.
6.3. Further prohibitions. The Client and its Authorized Users are prohibited from: (a) bypassing the API contract; (b) reverse engineering, decompiling or disassembling the Platform; (c) using the Platform outside the documented dispute-management purpose; (d) co-mingling third-party data with their own.
6.4. Suspension and access restriction. Upon a detected breach of the acceptable-use obligations of this Section 6 — in particular the submission of Sensitive Authentication Data rejected at the API edge (Section 6.1) — or upon a security event, such as credential compromise (Section 5.2) or suspected unauthorized use, the Company may immediately suspend, throttle or restrict the Client’s and its Authorized Users’ access to the API and the Platform. Where practicable, the Company gives notice to the Client, and access is restored once the cause is cured. This power is exercised without prejudice to the termination rights under Section 19 and gives rise to no credit, rebate or consideration.
7. Client obligations and lawful-basis warranty
7.1. Lawful-basis warranty. The Client represents and warrants that it holds a valid legal basis (LGPD arts. 7 and, where applicable, 11) and gives lawful, documented instructions (LGPD art. 39) for the processing of the cardholder data it routes to the Company.
7.2. Controller in the operator scope; transparency. As to the dispute processing carried out in the operator scope, the Client is the controller and is responsible for discharging the transparency duty of art. 9 of the LGPD toward its own cardholders.
7.3. Accuracy and provenance. The Client represents and warrants the accuracy and provenance of the data it supplies, so as to support source-traceability as contemplated by art. 43, §1, of the CDC, where applicable.
8. Data protection — the two roles and DPA reference
8.1. TREATMENT ROLES. Roles are allocated per purpose, not per dataset.
8.2. (i) OPERATOR (LGPD art. 5, VII). The Company acts as OPERATOR when it processes Chargeback Data on behalf of and under the documented instructions of the Client, in the course of executing disputes and chargebacks, under the Data Processing Agreement (LGPD art. 39). In this case the Client is the CONTROLLER, determines the purposes, means and retention period and is responsible for the legal basis and the transparency duty (art. 9) toward its data subjects; the Company merely carries out those instructions. The legal basis is performance of a contract (art. 7, V) and/or the Client’s own bases (art. 7, X).
8.3. (ii) CONTROLLER (LGPD art. 5, VI). The Company acts as CONTROLLER when, independently determining the purposes and means, it reuses Client-sourced Chargeback Data for its own purposes — product analytics and benchmarking and the development, improvement and provision of its products and services, including analytical and predictive models for fraud prevention and dispute management. In this case the processing is governed by the Company’s Privacy Policy and by the Company’s own legal basis, with the data subject’s right to object assured (art. 18, §2). The Company adopts legitimate interest (art. 7, IX) as the basis for this purpose, supported by a documented balancing test (art. 10) and conditioned on the safeguards set out therein, in particular minimization and anonymization (art. 12).
8.4. No re-use of basis — non-erosion of the role split. The legal basis of one role is NEVER reused to justify the other: the Data Processing Agreement (operator) does not authorize the Company’s own use (controller), and the purpose limitation of the operator scope does not extinguish the separately-disclosed own-use right of the controller. Where the controller role applies, the Company acknowledges the solidary liability under art. 42 of the LGPD.
8.5. Regulatory flow-down clauses in the DPA. Where the Client is a BCB-regulated institution, the Data Processing Agreement referenced in Section 1.4 carries the flow-down clause set of art. 17 of Resolution BCB No. 85/2021 (and of Resolution CMN No. 4,893/2021 for banking clients), including data residency, segregation, BCB access, sub-processing notice and deletion on termination.
9. Data residency — Brazil
9.1. General rule. All storage and processing of the Client’s Chargeback Data remains in Brazil — the cloud region is pinned to Brazil and the development database resides in Brazil.
9.2. International transfer. Any cross-border sub-service is flagged to the Client before contracting. International transfers of personal data occur only under a mechanism of art. 33 of the LGPD: standard contractual clauses (Resolution CD/ANPD No. 19/2024) for destinations without an adequacy decision; and EU/EEA adequacy (Resolution CD/ANPD No. 32/2026) for in-scope destinations. The dates and article numbers of the said resolutions must be confirmed by legal counsel.
10. Sub-processors
10.1. General authorization. The Company may engage and replace Sub-processors (cloud, object storage, model hosting, evidence/email storage) under general authorization, recording each in an internal register. The conditions of every sub-processing are: (a) the Sub-processor’s access is limited to what is strictly necessary; (b) data-protection obligations flow down to the Sub-processor; (c) the Company remains liable to the Client for the Sub-processor’s conduct.
10.2. Disclosure on request. The identities of the Company’s Sub-processors are disclosed to the Client on request, under confidentiality.
11. Audit and regulator (BCB) access
11.1. Access to records. The Company permits the Client to access the contracts relating to the Client, the stored data, backups, processing information, logs and access codes. Where the Client is a BCB-regulated institution, the Company additionally permits, through the Client, the BCB to access those records, under art. 17, VII, of Resolution BCB No. 85/2021.
11.3. Access by judicial order. The disclosure to third parties of stored records, personal data or communications content occurs solely upon a judicial order, under the Brazilian Civil Rights Framework for the Internet (Marco Civil, Law No. 12,965/2014, arts. 7, II-III, and 10, §§1-2).
12. Security incident notification
12.1. Duty to notify. The Company notifies the affected Client of any Security Incident touching Client data within a timeframe compatible with the Client’s own reporting obligations — and, where the Client is a BCB-regulated institution, with its reporting window to the BCB — with defined crisis thresholds and a status-update cadence.
12.2. Data Protection Officer channel. The Data Protection Officer is the contact for Security Incidents, in accordance with the regime of Resolution CD/ANPD No. 15/2024 and art. 48 of the LGPD.
13. Continuity, interruption and resolution regime
13.1. Prior notice of interruption. The Company gives at least 30 (thirty) days’ prior notice before any planned interruption of the Services. A permanent discontinuation of the Services is not a planned interruption but a termination governed by Section 19 (export, deletion and deletion certificate).
13.2. Resolution regime. Where the Client is a BCB-regulated institution and enters a resolution regime, the Company cooperates with the administrator appointed by the BCB, ensuring full and unrestricted access.
13.3. Exit and portability. The Company maintains a documented export format and an off-boarding runbook so as to provide the Client with a business-continuity alternative.
14. Service availability
14.1. No availability warranty (SLA). The Platform is provided without any uptime or service-level (SLA) warranty. Any availability commitment, should it ever exist, will be the subject of a separate instrument agreed separately, without any credit, rebate or consideration arising from these Terms.
14.2. Maintenance windows. The Company may perform routine maintenance, using reasonable efforts to reduce the impact on the Services, subject, as to planned interruptions, to the prior notice in Section 13.1.
15. Confidentiality
15.1. Mutual duty of confidentiality. Each party protects the other party’s confidential information to which it has access by reason of these Terms, refraining from disclosing it to third parties and from using it for any purpose other than the performance of these Terms. Disclosure is restricted to those persons who need to know and only to the extent permitted by these Terms, the Data Processing Agreement or a mandatory rule of law, with the receiving party remaining responsible for such persons’ compliance with this duty.
15.2. Company measures over Client data. The Company protects the Client’s data and other confidential information by means of encryption in transit (TLS) and at rest, with documented key management, and per-Client logical isolation, with no cross-client co-mingling of data between distinct Clients.
15.3. Carve-out for disclosure by judicial order. The disclosure to third parties of stored records, personal data or communications content occurs solely upon a judicial order, under the Brazilian Civil Rights Framework for the Internet (Marco Civil, Law No. 12,965/2014, arts. 7, II-III, and 10, §§1-2), as provided in Section 11.3.
16. Intellectual property
16.1. Company ownership. The Company owns the Platform, the API, the software, the underlying models and all derived, aggregated and anonymized data products.
16.2. Client rights and license. The Client retains the rights in the Chargeback Data it submits and receives, and receives a limited, non-exclusive, non-transferable license to use the Platform for its dispute purposes.
16.3. Narrow data-use hook. Any reuse of Client-sourced data to develop or improve products is anchored to the legitimate-interest basis, to the anonymization boundary and to the right to object of art. 18, §2, of the LGPD — never to an intellectual-property license that overrides the data subject’s rights. These Terms grant no perpetual or unrestricted license over personal data.
16.4. Feedback license. The Client and its Authorized Users grant the Company a non-exclusive, irrevocable, royalty-free license to use suggestions, comments and reports (feedback) — such as bug reports and feature requests — to improve the Platform. This license reaches only non-personal feedback and is distinct from the reuse of personal data addressed in Section 16.3.
17. Warranties and disclaimers
17.1. Security warranty. The Company warrants that it provides the Platform with the security measures described in these Terms and in the Privacy Policy.
17.2. Nature of analytical outputs. The analytical and predictive outputs of the Platform (triage label / win-probability) are decision-support concerning the dispute, and not a decision about the cardholder. The Company does not guarantee any specific dispute outcome or recovery rate.
17.3. Provision “as is”. Save for the express warranties of these Terms, the Platform is provided “as is” (no estado em que se encontra). This disclaimer does not apply so as to constitute an abusive clause under art. 51 of the CDC.
18. Limitation of liability and indemnity
18.1. Allocation of liability. The parties allocate liability between themselves as set out in these Terms and in the Data Processing Agreement.
18.2. Indemnity by the Company. The Company indemnifies the Client for its own failures that expose the Client to regulatory or legal sanction — including, where the Client is a BCB-regulated institution, a BCB sanction — within the limits of these Terms.
18.3. Indemnity by the Client. The Client indemnifies the Company for losses arising from breach of (a) the lawful-basis warranty (Section 7.1) and the documented-instructions duty (LGPD art. 39); and (b) the acceptable-use prohibitions (Section 6), in particular the submission of Sensitive Authentication Data or of excessive identifiers.
18.4. Non-neutralization carve-out. No limitation of liability in these Terms neutralizes (a) the Company’s solidary liability, as controller, toward data subjects and Clients (LGPD art. 42); nor (b) where the Client is a BCB-regulated institution, the indemnity and step-in duties flowed down under the BCB rules.
18.5. No abusive clause. The limitations of this Section are construed so as not to constitute an abusive clause under art. 51 of the CDC.
19. Term, termination and deletion on termination
19.1. Term and termination. These Terms are effective from the effective date and may be terminated for cause or for convenience. Termination for convenience observes 30 days’ prior notice; termination for cause operates upon notification, subject to the cure period where applicable. The consequences of termination are the deletion provided for in Section 19.2 and the survival of the obligations of Section 19.3.
19.2. Deletion on termination. Upon termination, the Company exports the Client’s data; the Client confirms its integrity; the Company then deletes the raw operational store and the training set / derived features, issuing a deletion certificate.
19.3. Survival. The confidentiality obligations (Section 15) and the Company’s obligations in the controller scope survive termination.
20. Amendment of the Terms
20.1. Revision with prior notice. The Company may revise these Terms upon prior notice through https://dispute.sparsu.com or notification to the Client, stating the effective date of the new version. Continued use after such date implies agreement with the revised version. The notice is effective and prior; the Client bears no burden to check for changes on its own.
20.2. Sole forward-looking clause. This is the only forward-looking clause admitted in these Terms; no other provision addresses future and non-existing features, products or data uses.
21. Order of precedence
21.1. Where a signed instrument with the Client (a specific agreement or the Data Processing Agreement) conflicts with these Terms, the signed instrument prevails for that Client. This is the seam that keeps the operator scope (under the DPA) and the controller scope (for own use) coherent, including as to conflicts touching cardholder data.
22. General provisions
22.1. Compliance with law. The parties undertake to comply with the applicable law.
22.2. Notices. The notices provided for in these Terms are given in writing, to the addresses and electronic channels indicated by the parties, and are deemed received: (a) on delivery, if by physical means; or (b) on proven dispatch, if by electronic means. Each party is responsible for keeping its contact details up to date. This notice mechanism underpins Sections 12 (incident notification), 13 (interruption notice) and 20 (amendment of the Terms).
22.3. Assignment. Neither party may assign these Terms without the prior written consent of the other, save for assignment to a company of the same economic group upon notice.
22.4. Severability. The invalidity or unenforceability of any clause does not affect the others, which remain in full force.
22.5. Waiver. Tolerance of any breach does not constitute waiver, novation or amendment of the agreement.
22.6. Force majeure. Neither party is liable for non-performance arising from fortuitous event or force majeure.
22.7. No agency. These Terms create no partnership, mandate, agency or employment relationship between the parties.
22.8. Entire agreement. These Terms, the Privacy Policy and the Data Processing Agreement constitute the entire agreement between the parties as to their object.
23. Governing law and forum
23.1. Governing law. These Terms are governed by Brazilian law.
23.2. Forum. The parties elect the forum of the Judicial District (Comarca) of São Paulo, State of São Paulo, Brazil, corresponding to the Company’s domicile, to resolve disputes arising from these Terms. The election is made in writing, with express reference to these Terms and bearing pertinence with the domicile of one of the parties, in accordance with art. 63, §1, of the Code of Civil Procedure, as amended by Law No. 14,879/2024. The parties acknowledge the risk of an ex officio decline in the case of a random forum (foro aleatório); the exact wording of the said §1 and the satisfaction of the pertinence test must be confirmed by legal counsel.
23.3. Preservation of privacy rights. No clause of these Terms may imply a waiver of privacy rights or impose a forum that defeats them, in accordance with art. 8, sole paragraph, of the Marco Civil.
23.4. US-consumer-law rights addressed in the Privacy Policy. The governing law and forum of this Section 23 reach the operator (service-provider) relationship between the Company and the Client. They do not restrict the rights of US consumers (such as California residents under the California Consumer Privacy Act, as amended — “CCPA”). Those rights — including the right to know, to delete, to correct, to opt out of sale/sharing, and to have a Global Privacy Control (GPC) signal honored — are addressed in the Privacy Policy and are exercised directly before the Company in its capacity as a business (controller), independently of this Section.
24. AI/ML outputs — no guarantee of outcome
24.1. Decision-support, not a guarantee. The Platform’s analytical and predictive outputs — the dispute-triage label and the win-probability estimate — are decision-support concerning the dispute, generated by analytical and predictive (machine-learning) models. They are a statistical estimate, not a promise. The Company does not guarantee any specific dispute outcome, recovery, win rate or representment result, and a higher win-probability does not entitle the Client to any outcome.
24.2. Estimate, subject to error. A win-probability output is a model estimate computed from historical patterns; it may be wrong in any individual case and reflects no assessment of, and produces no legal effect or significant impact upon, the person of the cardholder (it concerns the dispute, consistent with Section 17.2 and the Privacy Policy). The Client remains responsible for its own decisions on whether and how to pursue any dispute.
24.3. No reliance warranty. Except for the express warranties of these Terms, the model outputs are provided as part of the Platform on an “as is” basis (Section 17.3); the Company gives no warranty that any output is accurate, complete or fit for a particular decision.
25. Data used to train the Company’s models (own-use license)
25.1. Transparent statement of the own-use right. Stated plainly and without burying it: the Company reuses Client-sourced Chargeback Data to train, develop and improve its own dispute-triage and win-probability models, as well as for product analysis and benchmarking. This is an independent-controller activity of the Company (Section 8.3), governed by the Privacy Policy and by the Company’s own legal basis — never by the Data Processing Agreement. The Company chooses to disclose this use expressly and up front, rather than leaving it implicit.
25.2. Scope of the license. To enable the use in Section 25.1, the Client grants the Company a non-exclusive, worldwide, royalty-free license to host, process and reuse the submitted Chargeback Data to train, validate and improve the Company’s dispute-triage and win-probability models and to create derived, aggregated and anonymized data products, which the Company owns (Section 16.1). This license is bounded — it does not extend to selling the Client’s raw data, and it is subject to the limits of Section 25.3.
25.3. Boundaries that protect the data subject. This license is not an intellectual-property license that overrides the cardholder’s rights (Section 16.3). It is anchored to, and limited by: (a) the Company’s legitimate-interest basis and its documented balancing test (LGPD arts. 7, IX, and 10); (b) the minimization and anonymization safeguards (LGPD arts. 6, III, and 12), with Sensitive Authentication Data and full PAN never stored (Sections 2.11 and 6.1); and (c) the cardholder’s right to object (LGPD art. 18, §2), on whose exercise the Company ceases the controller-role processing as to that data subject. No perpetual or unrestricted license over personal data is granted. On termination, the training set and derived features are deleted under Section 19.2.
25.4. Consistency across documents. This clause is consistent with, and is to be read together with, Section 16 (Intellectual property), Section 8 (the two roles), the Privacy Policy and the Data Processing Agreement — the DPA governing the operator scope carves out the Company’s own use, which lives exclusively under the controller scope described here.
26. Data-processing roles and the DPA — dual-hat (business/service-provider)
26.1. Two roles, two regimes. As detailed in Section 8, the Company wears two hats, allocated by purpose: it is an operator/processor (a CCPA “service provider”/“contractor”) when running disputes on the Client’s documented instructions, and an independent controller (a CCPA “business”) when reusing Client-sourced data for its own model-training and benchmarking purposes.
26.2. Service-provider certification in the DPA. For the operator/service-provider scope, the Company’s processing is governed by the Data Processing Agreement (DPA) — see /en/legal/dpa — entered into with each Client under LGPD art. 39, which — where the Client is a BCB-regulated institution — carries the BCB flow-down clauses (Section 8.5) and, for US-facing engagements, a CCPA service-provider/contractor certification: the Company certifies it does not sell or share the Client’s personal information and does not retain, use or disclose it outside the direct business purpose of the Services or as otherwise permitted by the CCPA. The DPA does not authorize the Company’s own (controller/business) use.
26.3. No erosion between roles. Consistent with Section 8.4, the legal basis or certification of one role is never reused to justify the other: the DPA (service-provider) does not license the own-use training, and the purpose limitation of the operator scope does not extinguish the separately-disclosed own-use right of the controller/business (Section 25).
27. Security and information-security program
27.1. Security commitments. The Company maintains the technical and organizational security measures described in these Terms (Sections 5, 11 and 15) and in the Privacy Policy. These include encryption in transit (TLS) and at rest with documented key management, role-based least-privilege access control, multi-factor authentication, audit logging and per-Client logical segregation.
27.2. Information-security program (GLBA). For US-facing engagements, the Company maintains a written information-security program consistent with the Gramm-Leach-Bliley Act (GLBA) Safeguards framework, appropriate to the sensitivity of the Chargeback Data and to the Company’s role, including where it serves regulated financial-institution Clients.
28. Language prevalence; effective date
28.1. Prevalence. The Portuguese (pt-BR) version of these Terms is binding and prevails over the English translation or any other language in the event of divergence.
28.2. Effective date. Last updated: 2026-06-16. Effective date: June 16, 2026.