Data Processing Agreement (DPA)
Last updated: October 8, 2026 · version 1.3
Sets out how Keypoint, as processor, handles the personal data of the visitors and buyers of the Customer’s websites, for which the Customer is the controller.
1. Parties, roles and scope
This Agreement supplements the Terms of Service and applies between the Customer (the store, agency or other person who subscribes to Lens), as CONTROLLER, and KEYPOINT SOLUÇÕES EM TECNOLOGIA LTDA, CNPJ registration in progress, Goiânia/GO, Brazil (“Keypoint”), as PROCESSOR, under the Brazilian LGPD (Law 13,709/2018) and, where applicable, the GDPR (Regulation (EU) 2016/679).
It applies to the personal data of visitors and buyers of the Customer’s websites and checkouts that is processed by Lens. For the Customer’s own data (registration, billing), Keypoint is the controller, as described in the Privacy Policy.
2. Subject matter, nature and purpose of the processing
- Subject matter: provision of the Keypoint Lens service the Customer has purchased.
- Nature and purpose: collecting, storing, organizing, analyzing and displaying to the Customer browsing data (recorded sessions, clicks, scroll, errors, performance), orders and sales received by webhook from the Customer’s checkout, Meta Ads data and, when connected, WhatsApp Business data, and generating AI analyses of sessions.
- Categories of data subjects: visitors and buyers of the Customer’s websites.
- Categories of data: visit and session identifiers, IP address, device and browser data, pages and interactions, and order and buyer data sent by the Customer (for example name, e-mail, phone), depending on the Customer’s configuration.
- Duration: for the term of the contract and the archiving period described in section 10.
3. Controller’s instructions
Keypoint will process the data only on the Customer’s documented instructions, which are the Terms of Service, this DPA and the settings the Customer makes in the dashboard. If an instruction would violate the law, Keypoint will tell the Customer. Keypoint will not use this data for its own purposes, nor sell it or share it for advertising.
The Customer is responsible for having a lawful basis, informing data subjects and, where needed, obtaining consent before activating the recorder.
4. Confidentiality
Keypoint ensures that the people authorized to process the data are bound by a duty of confidentiality and have access only to what their duties require. Support access to the Customer’s account (“Enter as customer”) always notifies the Customer, is read-only and shows buyers’ personal data masked.
5. Security measures
- Field masking in the browser, before sending: password, card, CPF and other ID documents, and any input masked by default.
- Encryption in transit (TLS) for all communications.
- Role-based access control and two-factor authentication available.
- Meta and payment gateway tokens kept on the server only.
- Logs of access and relevant operations.
- Edge protection against abuse and denial-of-service attacks, and anti-bot verification.
- Continuous assessment and improvement of the measures, proportionate to the risk.
6. Subprocessors
The Customer gives general authorization for the subprocessors listed on the “Subprocessors” page. Keypoint imposes on them data protection obligations equivalent to those in this Agreement and remains liable to the Customer for their performance.
We will give 30 days’ notice, by e-mail or in the app, before adding or replacing a subprocessor. Within that period the Customer may object in writing, with reasons, at [email protected]; if no reasonable solution is found, the Customer may terminate the contract without penalty, keeping access until the end of the period already paid.
7. International data transfers
Keypoint’s servers are in the European Union (France). Some subprocessors process data in the United States, Iceland or other countries. Transfers comply with article 33 of the LGPD and, for data subject to the GDPR, with the European Commission’s Standard Contractual Clauses (SCCs) or another valid transfer mechanism, together with supplementary measures where necessary.
8. Data subject requests
If a data subject contacts Keypoint, we will forward the request to the Customer without undue delay, unless the law requires us to reply directly. We will help the Customer respond to requests for access, export, correction and deletion, through dashboard tools or by request to [email protected]. To locate a person’s data we use the e-mail, phone number or visit ID provided by the Customer.
9. Security incidents
Keypoint will notify the Customer without undue delay after becoming aware of a personal data breach affecting data processed on its behalf, with a target of 48 hours. The notification will include, as far as possible: the nature of the incident, the categories and approximate volume of data and data subjects affected, likely consequences, and measures taken or proposed. The Customer decides on notifying data subjects and the ANPD (or the competent supervisory authority), with our support.
10. Retention and deletion
Sessions and other data are kept for the retention period of the Customer’s plan (7, 30, 90 or 180 days). After cancellation or closure of the account, data is archived for 30 days and then permanently deleted, with a notice 1 day before. The Customer can export it before then. Any backup copies are removed in their normal rotation cycle. We keep data only where the law requires.
11. Audits and documentation
On request, Keypoint will provide the documentation reasonably necessary to demonstrate compliance with this Agreement (for example a description of security measures and the current list of subprocessors). On-site or technical audits require prior agreement on scope, date and confidentiality, and any extra costs are borne by the Customer.
12. Liability and final provisions
The parties’ liability under this Agreement follows the limits of the Terms of Service, without prejudice to any joint liability the law imposes towards data subjects. In case of conflict on data protection matters, this Agreement prevails. It remains in force while Keypoint processes data on the Customer’s behalf. DPO contact: [email protected].