Versão 1.0, 2026-10-05. Modelo para anexar ao contrato com cada Cliente; a versão inglesa é a de referência para Clientes internacionais.
Data Processing Agreement (Acordo de tratamento de dados)
Este modelo de acordo está disponível em inglês, para anexar ao contrato com cada Cliente. A tradução portuguesa ainda não está disponível.
Between the Customer (controller) and MANEIRA ASTUTA - DESENVOLVIMENTO, OTIMIZAÇÃO, GOVERNANÇA E EDUCAÇÃO, UNIPESSOAL LDA, NIPC 515710202, Av. Padre Luís Pinto Carneiro, n.º 234, 4585-172 Gandra PRD (Paredes), Portugal, operating HumanAI (Processor). This agreement implements article 28 of the GDPR and forms part of the service contract.
1. Subject and duration
The Processor processes personal data on the Customer's behalf only to provide the HumanAI service described in the contract, for as long as the contract lasts and for the return or deletion period in clause 10.
2. Instructions
The Processor processes personal data only on the Customer's documented instructions, which are the contract, this agreement and the Customer's configuration of the platform (projects, members, enabled AI providers, recording settings). If Union or Member State law requires the Processor to process the data otherwise, it informs the Customer before processing, unless that law prohibits it. If an instruction appears to infringe data protection law, the Processor says so without delay.
3. Confidentiality
Everyone authorised to process the data is bound by confidentiality.
4. Security
The Processor applies the measures in Annex 2 and keeps them appropriate to the risk (GDPR art. 32).
5. Subprocessors
The Customer gives general authorisation for the subprocessors in Annex 3. The Processor gives at least 30 days' written notice of any intended addition or replacement; the Customer may object on reasonable data protection grounds within that period, and if the parties cannot agree the Customer may terminate the affected service. The Processor imposes on each subprocessor obligations equivalent to this agreement and remains liable for them.
AI model providers are used only when the Customer enables them for its projects, and the platform blocks providers the Customer has not enabled. Where the Customer contracts a provider directly, or its Users bring their own provider accounts, and the Customer instructs the Processor to use it, that provider is not the Processor's subprocessor, and the Customer is responsible for having a suitable contract with it (a business or API plan with a data processing agreement and no training on Customer data). Where the Processor supplies the provider account to deliver the service, the provider is the Processor's subprocessor and is listed in Annex 3.
6. International transfers
Personal data is transferred outside the EEA only with a safeguard under Chapter V of the GDPR (adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or the Commission's standard contractual clauses, Module 3 where the Processor engages a subprocessor, with a transfer impact assessment). Transfers to countries without adequacy and without such a safeguard are not made with the Customer's personal data.
7. Assistance
The Processor helps the Customer, taking into account the nature of the processing, to answer data subject requests, carry out data protection impact assessments and prior consultations, and meet its security obligations.
8. Personal data breaches
The Processor notifies the Customer without undue delay, and in any case within 48 hours of becoming aware of a breach affecting the Customer's data, with the information in article 33(3) GDPR as it becomes available, and updates as it develops.
9. Audits
The Processor makes available the information needed to show compliance and allows audits by the Customer or an auditor it appoints, with at least 30 days' notice, during business hours, no more than once a year unless there has been a breach or a regulator requires it, and under confidentiality.
10. Return and deletion
At the end of the service the Customer may export its data for 30 days. All Customer personal data is deleted from active systems within 60 days of the end of the service, except where law requires retention. Data in backups is deleted when the backup expires, at the latest 6 months later, and until then is used only to recover from an incident; if a backup is restored, data already deleted is deleted again. On request, the Processor issues a certificate of deletion.
11. Customer obligations
The Customer, as controller: (a) has a lawful basis for the processing it instructs and gives data subjects the information required by articles 13 and 14 GDPR, including its staff and the participants in meetings its Users record; (b) ensures that recordings are made only with the participants' consent and that voice profiles are created only with the explicit consent of the person concerned and where the law allows it, in particular under employment law; (c) carries out a data protection impact assessment where required, with the Processor's assistance; (d) does not use recordings, transcripts or activity logs to monitor its workers beyond what the law allows; (e) enables only AI providers for which a valid transfer safeguard exists.
12. Liability and law
Liability follows the service contract and article 82 of the GDPR. This agreement is governed by Portuguese law. If this agreement and the service contract conflict on personal data, this agreement prevails.
Signatures
| Customer (controller) | Processor | |
|---|---|---|
| Entity | [Customer name, NIPC/VAT] | MANEIRA ASTUTA - DESENVOLVIMENTO, OTIMIZAÇÃO, GOVERNANÇA E EDUCAÇÃO, UNIPESSOAL LDA, NIPC 515710202 |
| Signed by | [Name, position, with authority to bind the Customer] | Ana Sofia Coelho dos Santos, Managing Partner (Gerente) |
| Date | ||
| Signature |
---
Annex 1. Description of the processing
| Item | Description |
|---|---|
| Data subjects | Customer staff and contractors using the platform; people mentioned in Customer content (colleagues, stakeholders); participants in meetings recorded by Users |
| Categories of data | Identification and contact data; role and project membership; work content (code, tickets, documents, messages); activity and audit logs; meeting audio, transcripts and summaries; where enabled with explicit consent, voice profiles (biometric data, GDPR art. 9) |
| Nature and purpose | Hosting, organising, retrieving, transmitting to enabled AI providers, transcribing, summarising and deleting, in order to provide the HumanAI service |
| Retention | As set in the contract and Customer configuration; defaults in the Privacy Policy |
Annex 2. Technical and organisational measures
- Isolated work environment per person; isolation between projects.
- Encrypted connections (TLS) to the portal and cockpit; private network between team devices.
- Individual accounts; second factor (TOTP) for sensitive platform operations; signed, HTTP-only portal session cookie.
- Personal access tokens kept in each person's vault, never shared or hard-coded; automatic scanning for pasted secrets.
- Least privilege for project members; platform administration access logged.
- Audit log of relevant actions; human approval for actions on production environments.
- Daily backups and continuous database archiving; encrypted (AES-256) off-site copies on a second company server in Portugal, kept up to 6 months (7 daily, 4 weekly, 6 monthly); automatic restore tests daily (sample), weekly (members' files) and monthly (full database point-in-time restore).
- Incident response procedure and vulnerability disclosure channel.
- Encryption at rest: off-site backups are encrypted; the portal database is encrypted at rest by its provider; server and workstation disks, including the platform database on the main server, do not yet use full-disk encryption (access restricted to administrators over a private network).
Annex 3. Authorised subprocessors
See the public page Subprocessors & Integrations in its version at signature date.