For companies The card For you FAQ Blog
Book a demo
Atualizações da Startup

Ecomilhas Data Processing Agreement (DPA)

Jul 31, 2026 · 3 min read
Ecomilhas Data Processing Agreement (DPA)

Version 1.0 — effective 4 July 2026.

This Data Processing Agreement ("DPA") supplements the main agreement ("Agreement") between ECOMILHAS TECNOLOGIA LTDA (CNPJ 46.740.714/0001-37 — "ECOMILHAS") and the corporate client ("Client") that subscribes to the ESG goal-based variable-compensation program and other corporate services (the "Services"). It applies whenever ECOMILHAS processes personal data on behalf of the Client, in accordance with the LGPD, GDPR, UK GDPR, APPI, CCPA/CPRA and other applicable data protection laws.

In case of conflict on data protection, this DPA prevails over the Agreement.

1. Roles of the parties

For Client employee data processed within the Services, the Client is the Controller and ECOMILHAS acts as Processor, following the Client's documented instructions. Where ECOMILHAS determines its own purposes and means (e.g., fraud prevention, legal compliance, generating carbon credits from trips), it acts as an independent Controller under the Privacy Policy.

2. Subject matter, nature and purpose

3. Categories of data subjects and data (Annex I)

4. ECOMILHAS obligations (Processor)

ECOMILHAS will: (a) process data only on the Client's documented instructions and the law; (b) ensure confidentiality of authorised persons; (c) implement the security measures in Annex II; (d) assist the Client, as far as possible, with data-subject requests, impact assessments and consultations with authorities; (e) notify the Client of security incidents without undue delay after becoming aware; (f) on termination, delete or return the data, save mandatory retention; (g) make available information to demonstrate compliance and allow audits under Section 8.

5. Client obligations (Controller)

The Client warrants that it has a legal basis for the processing and for providing the data to ECOMILHAS, that its instructions are lawful, that it has informed its employees as required by law, and that it has obtained any required consents (including for background geolocation, where applicable).

6. Sub-processors

The Client authorises ECOMILHAS to engage sub-processors (e.g., cloud providers, payment/Mastercard processors, PIX, analytics and communications) under contracts with protection obligations equivalent to this DPA. ECOMILHAS keeps a list of sub-processors available on request and will inform of material changes with reasonable notice, allowing the Client to raise a reasoned objection.

7. International transfers

International transfers will occur only with an adequate safeguard: adequacy, EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA) or another basis authorised by the ANPD/competent authorities. The applicable SCCs/IDTA are deemed incorporated into this DPA where required.

8. Audit

With reasonable prior notice, at most once a year (except on authority order or after an incident), the Client may audit ECOMILHAS' compliance, preferably via reports, certifications or questionnaires, preserving confidentiality and operational continuity.

9. Security incidents

ECOMILHAS will assist the Client in notifying authorities and data subjects where required. For GDPR/UK GDPR processing, assistance takes into account the 72-hour notification deadline to the competent authority.

10. Liability

Each party's liability follows the limits of the Agreement. To the maximum extent permitted by law, liability for indirect damages and lost profits is excluded. The parties will cooperate to allocate liability in proportion to fault.

11. Term and termination

This DPA lasts as long as processing on the Client's behalf continues. On termination of the Agreement, ECOMILHAS will delete or return the data within 60 days, save mandatory retention.


Annex II — Technical and organisational security measures

Encryption in transit (TLS) and at rest; least-privilege access control and strong authentication; environment segregation; logging and monitoring; backups and continuity planning; vulnerability management and testing; vendor assessment and contracts; staff training and confidentiality; incident response procedures; pseudonymisation/minimisation where applicable.

This document is a template and must be legally validated and signed by the parties before taking effect.

Related documents: Privacy Policy · General Terms of Use · Cookie Policy.

Want this at your company?

Decarbonization with auditable primary data and engagement employees actually enjoy.

Book a demo →

Keep reading

Atualizações da Startup

Ecomilhas Cookie Policy

Atualizações da Startup

Ecomilhas on the road to B Corp certification

Atualizações da Startup

Ecomilhas at the Smart City Expo - Barcelona