Purpose and relationship with the contractual instruments
1.1.This Data Processing Agreement ("DPA") governs the processing of personal data carried out by FXO Serviços em Informática Ltda. ("FXO" or "Processor") on behalf of the customer ("Controller"), within the scope of the Wi-Fi.now platform, in accordance with Law No. 13,709/2018 ("LGPD"). It applies both to customers bound by a bilateral agreement (as its Exhibit II) and to those bound by adherence to the Platform Terms of Use, which incorporate it by reference.
1.2.Reciprocal linkage. This DPA and the main instrument (agreement or Platform Terms of Use) are mutually conditioned: acceptance of one implies acceptance of the other, and termination of one implies termination of the other, except for obligations that, by their nature, survive. In matters of personal data protection, this DPA prevails over the main instrument.
1.3.This DPA does not apply to personal data that FXO processes as a controller (registration and financial data, and panel usage data of the Controller's representatives), which are governed by the Privacy Policy.
Roles and documented instructions
2.1.In the processing of End Users' personal data through the platform, the Controller determines the purposes and means of processing (LGPD, art. 5, VI), and FXO acts exclusively as Processor (art. 5, VII), processing the data on behalf of the Controller and in accordance with its documented instructions.
2.2.The Controller's documented instructions consist of: (i) the main instrument and this DPA, including Appendix 1; (ii) the settings configured by the Controller in the administrative panel (enabled authentication methods, collected fields, portal customization); and (iii) subsequent written instructions, provided they are lawful, technically feasible, and compatible with the platform's scope.
2.3.FXO will inform the Controller, without undue delay, if it understands that an instruction violates the LGPD or another applicable rule, and may suspend execution of the specific instruction until written confirmation from the Controller, who will assume the corresponding responsibility.
2.4.Absolute prohibitions. FXO is prohibited from: (i) processing End Users' personal data for its own purposes, including advertising, database enrichment, creation of behavioral profiles, or commercialization of data, under any circumstances; (ii) correlating Session Records with browsing data: browsing records, when they exist, reside exclusively on the Controller's infrastructure and do not pass through FXO's systems; and (iii) retaining data beyond the periods set out in Section 9.
2.5.FXO may use aggregated data that has been irreversibly anonymized, not susceptible to re-identification, for statistical purposes and platform improvement; once anonymized, such data ceases to constitute personal data for purposes of the LGPD.
Scope of processing
3.1.The scope of processing (categories of data subjects, categories of data, purposes, nature, and duration) is described in Appendix 1, which exhaustively delimits the authorized processing. Any processing outside Appendix 1 requires a written amendment.
3.2.Controller representations. The Controller represents and warrants that: (i) it has a valid legal basis for the processing of End Users' data (LGPD, art. 7); (ii) it makes available to End Users, on the portal and in its physical premises, the information required by arts. 9 and 18 of the LGPD; and (iii) its instructions comply with applicable law. FXO is not liable for the absence or invalidity of the legal basis defined by the Controller.
3.3.Sensitive and regulated data. The Controller is prohibited from configuring the captive portal to collect sensitive personal data (LGPD, art. 5, II), data of children and adolescents, or data subject to specific regulatory regimes, except upon prior written notice to FXO and a specific amendment. Collection in violation of this provision is at the Controller's sole risk and authorizes immediate suspension of the feature involved.
3.3.1.Incidental authentication of adolescents on the captive portal, resulting from the technical impossibility of age verification in the available authentication methods, does not constitute a breach of item 3.3 by FXO. It is the Controller's responsibility to observe LGPD art. 14 and the best interests of the minor when defining the portal's texts, notices, and settings whenever its audience may include adolescents.
Personnel confidentiality
4.1.FXO ensures that access to personal data processed on behalf of the Controller is restricted to professionals with a functional need for access, bound by a contractual or statutory confidentiality obligation, and trained in personal data protection.
Security of processing
5.1.FXO will adopt the technical and administrative measures described in Appendix 2, suitable to protect personal data against unauthorized access and against accidental or unlawful destruction, loss, alteration, communication, or dissemination (LGPD, arts. 46 to 49), taking into account the state of the art and the nature of the data processed.
5.2.FXO may update the measures in Appendix 2, provided that the resulting level of protection is not reduced.
Subprocessors
6.1.The Controller generally authorizes the engagement of subprocessors by FXO for the operation of the platform (cloud infrastructure, sending of tokens via SMS and WhatsApp, and related services).
6.2.FXO will notify the Controller, with at least 30 (thirty) days' notice, of the inclusion or replacement of a subprocessor with access to End Users' personal data. The Controller may object, in writing and with justification, within 15 (fifteen) days of the notice. If the objection persists without a reasonable alternative, the Controller may terminate the relationship with respect to the affected environments, without penalty, as the exclusive remedy, except for damages arising from willful misconduct or gross negligence by FXO or its subprocessors.
6.3.Chain liability. FXO will contractually impose on each subprocessor data protection obligations equivalent to those of this DPA and will remain fully liable, to the Controller, for the acts and omissions of its subprocessors as if they were its own.
6.4.OAuth identity providers (Google, LinkedIn, Microsoft) and the End User's telephone carriers are not FXO subprocessors: they act as autonomous processing agents, under their own terms, in the direct relationship they maintain with the End User and/or with the Controller, holder of the OAuth credentials.
International transfers
7.1.Processing will preferably be carried out on infrastructure located in Brazil. Should the operation of the platform involve a subprocessor that stores or accesses data outside national territory, FXO will ensure that the transfer complies with the regime set out in arts. 33 et seq. of the LGPD and the ANPD regulations in force at the time, including, where applicable, standard contractual clauses recognized by it.
Assistance to the Controller
8.1. Data subject rights
8.1.1.It is the Controller's responsibility to respond to data subject requests (LGPD, art. 18). Requests from End Users received directly by FXO will be forwarded to the Controller within 5 (five) business days, without a substantive response to the data subject, unless otherwise instructed in writing or required by law.
8.1.2.FXO will make available to the Controller, through the panel or upon request, the functionalities and information reasonably necessary to handle requests for access, correction, deletion, portability, and information about the processing, limited to the data described in Appendix 1.
8.2. Other obligations
8.2.1.FXO will provide reasonable cooperation to the Controller in preparing data protection impact assessments (DPIA) and in responding to ANPD requests, insofar as they relate to the processing described in this DPA. Cooperation that exceeds ordinary use of the contracted plan may be charged according to FXO's then-current price table, communicated in advance. Cooperation indispensable for the Controller to meet a legal or regulatory deadline will not be conditioned on prior payment, without prejudice to the subsequent billing of amounts owed.
Retention and deletion
9.1.Session Records (accounting): retained for 12 (twelve) months from the end of each session, a period that meets, with a margin, the record-keeping duties of the Marco Civil da Internet (Brazilian Internet Civil Rights Framework), when applicable to the Controller, and supports the regular exercise of rights in judicial, administrative, or arbitration proceedings (LGPD, art. 7, VI). Upon expiry, FXO will carry out automatic, permanent, and irrecoverable purging.
9.2.Consent records and authentication identifiers: retained for the duration of the relationship and, after its termination, for the period necessary to comply with legal obligations and to exercise rights in proceedings, with use limited to those purposes.
9.3.Termination of the relationship: FXO will make available the export of data in a structured, commonly used format for 30 (thirty) days, after which it will delete the personal data processed on behalf of the Controller, except for retention required by law. Deletion will be certified in writing upon the Controller's request.
9.4.Backup copies: data in encrypted backups follow their own overwrite cycle, not exceeding 90 (ninety) days after deletion from the active database, remaining during that interval logically inaccessible for ordinary use and protected by the measures in Appendix 2.
Security incidents
10.1.Notification period. FXO will notify the Controller, without undue delay and within a period not exceeding 48 (forty-eight) hours from becoming aware, of any security incident that may cause relevant risk or harm to End Users, with the available information: nature of the incident, categories and estimated volume of data subjects and data affected, measures taken and recommended, and a point of contact.
10.2.The information will be progressively supplemented as the investigation proceeds, and the lack of details shall not justify delaying the initial notification.
10.3.It is the Controller's responsibility, in its capacity as controller of the End Users' data, to assess and carry out notifications to the ANPD and to data subjects within the deadlines set by the applicable regulations. The deadline in item 10.1 was set to preserve the Controller's margin to meet its regulatory deadline. FXO will provide the cooperation necessary for such notifications.
10.4.FXO will notify the ANPD directly only for incidents relating to data of which it is the controller. Neither party will admit liability, on behalf of the other, to data subjects or authorities.
Audit
11.1.FXO will make available annually, upon request, documentation demonstrating compliance with this DPA (description of security measures, attestations, certifications, or independent assessment reports, where they exist).
11.2.If the documentation is not reasonably sufficient, the Controller may conduct, directly or through an independent auditor bound by confidentiality, 1 (one) audit per 12 (twelve)-month period, upon 30 (thirty) days' prior notice, on business days and during business hours, limited to the processing covered by this DPA, without access to data of other FXO customers, trade secrets, or systems outside the scope, and at the Controller's expense.
11.3.An additional audit will be permitted following a relevant security incident or by determination of a competent authority.
Liability
12.1.The parties' liability for breaches of this DPA is subject to the limitation of liability and indemnification regime of the main instrument, except for willful misconduct, gross negligence, and cases where such limitation is prohibited by public policy rules. In the absence of a limitation regime in the main instrument, the statutory regime applies. No provision of this DPA limits or excludes the parties' liability to data subjects or authorities under the LGPD.
12.2.The party that compensates for damage caused by the other will have a right of recourse, in proportion to each agent's participation in the harmful event (LGPD, art. 42, § 4).
Term
13.1.This DPA remains in force for as long as FXO processes personal data on behalf of the Controller, with the obligations of Sections 4, 7, 9, 10, and 12 and item 6.3 surviving termination for as long as FXO retains, under any title, personal data processed on behalf of the Controller, including in backup copies. This DPA may be made available in other languages as a courtesy; in the event of any discrepancy, the Portuguese-language version prevails.
A1Appendix 1. Description of processing
| Element | Description |
|---|---|
| Categories of data subjects | End Users: natural persons who authenticate on the captive portal to access the Controller's Wi-Fi network (visitors, customers, staff). |
| Token authentication data | Phone number provided; token sent and validated; consent record (text, version, date, time). |
| OAuth authentication data | Basic data returned by the provider chosen by the End User (account identifier, name, and email, as per the configured scope); consent record. The platform does not receive or store passwords. |
| Session Records (accounting) | Identification of the authenticated user, assigned IP address, MAC address, start and end times, duration of stay, status, periodic updates (default interval of 15 minutes). |
| Data expressly NOT processed | Browsing history, sites visited, URLs, applications used, content of communications, continuous geolocation, sensitive data (LGPD, art. 5, II). Browsing records, when they exist, reside exclusively on the Controller's firewall. |
| Purposes | (i) authenticate End Users; (ii) record session accounting; (iii) record consents in an auditable manner; (iv) comply with applicable legal record-keeping duties. No other purpose. |
| Nature of processing | Collection, recording, storage, retrieval, export to the Controller, and deletion, by automated means. |
| Duration | For the duration of the relationship, subject to the retention periods set out in Section 9. |
A2Appendix 2. Technical and administrative security measures
| Domain | Measures |
|---|---|
| Encryption | Traffic encrypted in transit (TLS) between device, portal, and platform; communication with the firewall supported by a dedicated certificate; data encrypted at rest; encrypted backups. |
| Access control | Logical access on a need-to-know basis (least privilege); strengthened authentication for administrative access; periodic access reviews; logging of administrative access to data. |
| Segregation | Logical isolation by environment/tenant (UNIQID); segregation between production and development; data from different customers do not share an access context. |
| Secure operation | Vulnerability and update management; server hardening; availability and security event monitoring; source restriction for RADIUS communication (previously authorized public IPs). |
| Continuity | Periodic encrypted backups; tested restoration procedures; backup overwrite cycle not exceeding 90 days after deletion from the active database. |
| People and processes | Confidentiality obligations; periodic privacy and security training; internal incident response procedure with defined roles; designated DPO ([email protected]). |
| Disposal | Automated purging at the end of the periods set out in Section 9, with permanent and irrecoverable deletion from the active database. |