Legal document

Data Processing Agreement

This agreement governs the personal data processing Tablia carries out on behalf of the contracting store, under art. 39 of Brazilian Law 13,709/2018 (LGPD). It is the instrument that records the store's instructions — without it, the split of roles described in the Privacy Policy would have no contractual basis.

It applies automatically. This agreement forms part of the Terms of Use and takes effect on contracting, with no separate signature needed. A store that needs a signed copy — for internal policy or an audit requirement — can request one at the address in section 15.

Last updated: August 21, 2026

This is a translation. The binding version of this document is the Portuguese one, published at tablia.com.br. It carries the same version number — the version identifies the document, not the translation. Where the two diverge, the Portuguese text prevails.

1. Subject matter and framing

The parties to this agreement are Tablia Serviços Tecnológicos Ltda., company ID (CNPJ)53.734.413/0001-66 ("Tablia"), and the legal entity that contracts the Platform ("Store").

For the personal data of end customers who request a quote from a Store:

  • the Store is the Controller — it decides the purposes and the means of processing
  • Tablia is the Processor — it processes on the Store's behalf and according to its instructions

This agreement does not apply to data for which Tablia is the controller: site visitors, people who fill in the contact form, and Store Users (Owners and Salespeople). Those follow the Privacy Policy.

2. Definitions

The terms personal data, data subject, processing, controller, processor, data protection officer, deletion, anonymisation and security incident carry the meaning given to them by Brazilian Law 13,709/2018 (LGPD).

Platform, Store, Store User, End Customer, Inventory and Quote carry the meaning in section 2 of the Terms of Use.

Processed Data means the data described in Annex I.

3. The Controller’s documented instructions

Tablia processes the Processed Data only according to the Store's instructions. The following are the Store's documented instructions, for all purposes of LGPD art. 39:

  • this agreement, including its annexes
  • the Terms of Use and the signed commercial agreement
  • the settings the Store defines in the Platform — inventory, users, roles, PDF text, service channels
  • the actions Store Users take in the Platform
  • additional instructions sent in writing through the channels in section 15

If Tablia considers that an instruction breaches the LGPD or another applicable rule, it will notify the Store and may suspend that instruction until the matter is resolved.

Tablia does not use the Processed Data for its own purposes, does not sell it, does not pass it to third parties outside Annex II, and does not use it to train artificial intelligence models.

4. Tablia’s obligations as Processor

  • Process the Processed Data only as set out in section 3, for the time set in Annex I
  • Maintain confidentiality, as set out in section 6
  • Apply the security measures in section 7 and Annex III
  • Assist the Store in responding to data subjects, as set out in section 8
  • Report security incidents, as set out in section 9
  • Engage sub-processors only as set out in section 10
  • Assist the Store in preparing an impact assessment, when it needs one, providing the information within our sphere
  • Keep a record of the processing operations it carries out on the Store's behalf
  • Return or delete the Processed Data on termination, as set out in section 13
  • Keep a publicly named Data Protection Officer, as a channel for the Store and for data subjects

5. The Store’s obligations as Controller

The quality of the processing depends on decisions only the Store can take. These are its obligations:

  • Have a legal basis for the processing it instructs, and be able to demonstrate it
  • Inform its customers about the processing, including the use of Tablia as a processor, and keep its own privacy notice accessible
  • Obtain consent where that is the applicable legal basis, especially for marketing communication
  • Not send sensitive data, nor data of children or teenagers, to the Platform — it was not designed for that
  • Control its Users' access and revoke it when someone leaves the team
  • Respond to data subjects, as controller, calling on Tablia when needed
  • Instruct what happens to the data when the contract ends

6. Confidentiality

Tablia keeps the Processed Data confidential and restricts access to those who need it to run the service. Anyone with access is bound by a confidentiality obligation that survives the end of their engagement.

The obligation does not apply to information that becomes public through no fault of Tablia, nor to disclosure required by law or by a competent authority — in which case the Store will be notified beforehand, unless such notification is prohibited.

7. Security

Tablia applies technical and administrative measures suitable to protect the Processed Data, under LGPD arts. 46 to 49. The measures in force are in Annex III.

The measures may be updated to keep pace with technical developments, provided the level of protection is not reduced. Material changes are communicated to the Store.

8. Data subject rights

The data subject exercises their rights with the Store, which is the controller. Tablia does not respond directly to requests about the Processed Data without the Store's instruction.

If a data subject approaches Tablia, we will forward the request to the Store within 5 business days, telling the data subject that it has been forwarded.

When the Store needs our help to answer a request — access, correction, portability, deletion, anonymisation, information about sharing — Tablia will provide the necessary support within 10 business days of the request, a period compatible with what the LGPD imposes on the controller.

9. Security incidents

On becoming aware of a security incident involving the Processed Data, Tablia will notify the Store within 48 hours, reporting, to the extent known:

  • the nature of the incident and the data affected
  • the approximate number of data subjects involved
  • the technical and security measures already taken
  • the related risks and the recommended mitigation measures

The initial notification does not wait for the investigation to be complete. Further information is sent as it is established.

Notifying the Brazilian data protection authority and the data subjects is the Store's duty, as controller, under LGPD art. 48. Tablia supplies the information it needs to meet that duty.

10. Sub-processors

By accepting this agreement, the Store authorises the engagement of the sub-processors listed in Annex II.

Tablia imposes on each sub-processor, by contract, data protection obligations equivalent to those in this agreement, and is liable to the Store for their acts as if they were its own.

New sub-processors. Tablia will give at least 30 days' notice of any addition or replacement, updating Annex II and the date at the top of this page. A Store that objects on reasoned grounds within that period may terminate the contract at no cost, if the objection is not resolved.

The artificial intelligence market moves fast. Changing the model provider is the most likely reason for Annex II to change, and it follows the same procedure.

11. International transfers

Part of the processing takes place outside Brazil, as set out in Annex II. In particular, the content of the quote list — and the original file, when it is a PDF or an image — is sent to the artificial intelligence service to be read.

The transfers comply with LGPD art. 33, on the basis of necessity for performance of the contract and under contractual clauses signed with each sub-processor, binding them to protection standards compatible with Brazilian law.

The Store, as controller, is informed of these transfers by this agreement and must reflect them in its own privacy notice.

12. Audit and demonstrating compliance

On request, Tablia makes available to the Store the information needed to demonstrate compliance with this agreement — a description of the security measures, the list of sub-processors and the record of processing operations.

The Store may carry out one audit per year, with 30 days' notice, during business hours, itself or through an independent auditor bound by confidentiality. The audit must not compromise the security of other stores or expose third-party data, and its costs are borne by the Store — unless it finds a material breach.

An additional audit may be carried out after a security incident affecting the Store.

13. Return and deletion

Once the contract ends, and according to the Store’s instruction:

  • the Store may export the Inventory and the quote history in CSV, within 60 days of termination
  • after that period, Tablia deletes or anonymises the Processed Data, subject to the retention periods in Annex I
  • only data whose retention is required by a legal obligation, or needed for the regular exercise of rights, is kept — and only for that long

Deletion extends to the sub-processors in Annex II, under the contracts signed with them.

14. Liability

Each party is liable for breaching the obligations this agreement assigns to it. Tablia is liable under LGPD art. 42, §1 — including jointly and severally, where the law so provides.

The Store will indemnify Tablia for losses arising from an unlawful instruction, from the absence of a legal basis for the processing instructed, or from failing to inform its own data subjects.

The liability caps in section 16 of the Terms of Use apply to this agreement, save for what the law does not allow to be capped.

15. Term, precedence, changes and contact

This agreement is in force for as long as Tablia processes Processed Data, and survives the end of the contract as far as necessary — confidentiality, deletion and liability.

Precedence. On matters of data protection, this agreement prevails over the Terms of Use. Where a specific agreement is signed between Tablia and the Store, that one prevails over this.

Changes. Material changes are communicated 30 days in advance. A Store that does not agree may terminate at no cost up to the date they take effect.

Data Protection Officer: Carolina Porto · [email protected]

Tablia Serviços Tecnológicos Ltda. · Company ID (CNPJ) 53.734.413/0001-66 · Rua Professor Estevão Pinto, 555 — Serra, Belo Horizonte, MG, CEP 30.220-060

Annex I — Description of the processing

Nature and purpose

Collection, storage, automated processing, structuring, lookup and transmission of personal data, for the purpose of enabling customer service, product lookups, quote building, commercial communication and the features requested by the user themselves.

Categories of data subject

End customers — individuals or representatives of legal entities — who request a quote from a Store, through its public page or through the WhatsApp channel.

Types of data

Identification and contact
Name or company name, WhatsApp number, email, tax ID when given
Content of the request
List of products and quantities, and the original file sent — PDF, image, spreadsheet, document or text
Processing result
Items recognised, matching products, missing items, quote versions
Relationship
Preferred salesperson, deal status, message history when the WhatsApp channel is active
Technical records
Date and time of operations, unique quote identifier, access logs

The Platform does not request sensitive data within the meaning of LGPD art. 5, II. The file the customer sends may contain information beyond the product list — it is the Store's responsibility to tell its customers to send only what is necessary.

Duration and retention

  • Quotes, uploaded files and PDFs: 5 years from the last interaction
  • WhatsApp conversations: 5 years from the last interaction
  • Access and security logs: 6 months, under the Brazilian Internet Civil Framework

Periods aligned with section 9 of the Privacy Policy. The Store may instruct a shorter period in writing.

Annex II — Authorised sub-processors

Sub-processorActivityPlace of processing
Google — GeminiReading the list and ranking the resultsUnited States
Google CloudHosting and running the PlatformUnited States
CloudflareStorage of files and PDFsGlobal network
Amazon Web Services — SESSending transactional emailUnited States
Meta — WhatsApp BusinessMessage transport, when the channel is activeAs set out in the provider's policy

The artificial intelligence provider in use today is Google (Gemini). It may be replaced by OpenAI (ChatGPT), Anthropic (Claude) or xAI (Grok), following the procedure in section 10.

Annex III — Security measures

Transport
HTTPS across the whole service, with HSTS enabled and security headers applied
Authentication
Token in an httpOnly cookie, with request-forgery protection and automatic lockout after repeated failed attempts
Authorisation
Separation by role — Owner and Salesperson — and isolation between stores on every query
Availability
Request rate limits per origin to contain abusive use
Logging
Access and usage logs, kept for the periods in Annex I
Personnel
Access restricted to those who need it, under a confidentiality obligation

No measure removes risk entirely. This annex describes what is in force on the date at the top of this page and may evolve, without reducing the level of protection.