DATA PROTECTION POLICY
MULTIAGENTS
Updated: January 2026
1. PURPOSE
This Data Protection Policy aims to establish guidelines and responsibilities for personal data processing within the scope of the Multiagents platform activities, in compliance with Law No. 13,709/2018 (Brazilian General Data Protection Law - LGPD).
2. SCOPE
Applies to all employees, service providers, partners, suppliers, clients, and third parties who process personal data through the Multiagents platform, regardless of the medium (physical or digital), covering the entire personal data processing chain.
3. APPLICABLE PRINCIPLES
Personal data processing by Multiagents shall observe the following principles established by LGPD:
3.1. Purpose
Data will be processed for legitimate, specific, explicit, and informed purposes, without the possibility of subsequent processing in a manner incompatible with these purposes.
3.2. Adequacy
Compatibility of processing with the purposes informed to the data subject, according to the processing context.
3.3. Necessity
Limitation of processing to the minimum necessary for achieving its purposes, with scope of relevant, proportional, and non-excessive data.
3.4. Free access
Guarantee to data subjects of facilitated and free consultation about the form and duration of processing, as well as the entirety of their personal data.
3.5. Data quality
Guarantee to data subjects of accuracy, clarity, relevance, and updating of data, according to the need and for fulfilling the purpose of its processing.
3.6. Transparency
Guarantee to data subjects of clear, precise, and easily accessible information about processing and the respective processing agents.
3.7. Security
Use of technical and administrative measures capable of protecting personal data from unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination.
3.8. Prevention
Adoption of measures to prevent the occurrence of damages due to personal data processing.
3.9. Non-discrimination
Impossibility of processing for unlawful or abusive discriminatory purposes.
3.10. Accountability and demonstration
Demonstration by the processing agent of the adoption of effective measures capable of proving compliance with personal data protection rules and the effectiveness of these measures.
4. DATA SUBJECT RIGHTS
Multiagents guarantees data subjects all rights provided in Article 18 of LGPD, including:
- Confirmation of processing of personal data;
- Access to personal data being processed;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data;
- Data portability to another service or product provider, upon express request;
- Deletion of personal data processed with the data subject's consent;
- Information about data sharing with public and private entities;
- Information about the possibility of not providing consent and the consequences of refusal;
- Consent revocation, under the terms of LGPD.
4.1. Channel for exercising rights
To exercise any of the above rights, the data subject may contact us via email: contact@multiagents.inc
Requests will be answered within 15 business days, according to deadlines established by ANPD.
5. LEGAL BASES FOR PROCESSING
Personal data processing operations carried out by Multiagents are based on the following legal bases provided in Article 7 of LGPD:
- Consent of the data subject;
- Compliance with legal or regulatory obligation by the controller;
- Contract execution or preliminary procedures related to a contract to which the data subject is a party;
- Regular exercise of rights in judicial, administrative, or arbitration proceedings;
- Protection of life or physical safety of the data subject or third party;
- Health protection, exclusively, in procedures performed by health professionals, health services, or health authorities;
- Legitimate interest of the controller or third party;
- Credit protection, under current legislation.
6. SECURITY AND GOVERNANCE
Multiagents adopts rigorous technical and administrative measures to protect personal data from unauthorized access, destruction, loss, alteration, communication, or any form of inadequate or unlawful processing.
6.1. Implemented security measures:
- Access control based on individual credentials, multi-factor authentication, and permission profiles;
- Data encryption in transit (TLS 1.3) and at rest (AES-256);
- Secure storage in certified cloud infrastructure with international certifications (ISO 27001, SOC 2);
- Continuous monitoring of systems and access logs for detection of suspicious activities;
- Firewall and DDoS protection to prevent intrusions and cyberattacks;
- Automatic backup with configurable retention and periodic recovery tests;
- Periodic training of employees on information security and data protection best practices;
- Internal policies for data classification, incident management, and breach response;
- Regular audits of security and compliance conducted by independent third parties;
- Environment segregation (production, staging, and development) with specific controls.
6.2. Third-party credential management
When Multiagents accesses third-party systems on behalf of the client (via API, OAuth2, or custom MCPs), all credentials are:
- Stored encrypted with securely managed keys;
- Isolated by tenant (client), without sharing between environments;
- Auditable, with logs of all operations performed;
- Revocable at any time by the data subject or client.
7. DATA SHARING
Multiagents may share personal data in the following cases:
7.1. With contracted processors
Service providers who process data on behalf of Multiagents (e.g., cloud infrastructure providers, monitoring tools, authentication services), always under:
- Contractual confidentiality and data protection clauses;
- Guarantee of LGPD compliance;
- Limitation of processing to authorized purposes.
7.2. With public authorities
When required by law, court order, request from competent authority, or to comply with legal or regulatory obligation.
7.3. In judicial, administrative, or arbitration proceedings
For regular exercise of rights or defense in proceedings.
7.4. With the data subject's consent
Upon express authorization for specific purposes.
7.5. With third parties integrated via platform
When the client configures integrations with CRMs, communication tools, or proprietary systems via API/MCP, sharing occurs under the client's responsibility, who acts as controller of that data.
8. RETENTION AND DISPOSAL
8.1. Retention period
Personal data will be stored only for the time necessary to fulfill its purposes, respecting:
- Contractual term during the service period;
- Legal or regulatory deadline, when applicable (e.g., tax, labor obligations);
- Deadline for exercising rights in judicial or administrative proceedings;
- Data subject consent, when applicable.
8.2. Secure deletion
After the retention period ends, data will be:
- Anonymized irreversibly, when possible; or
- Securely deleted, using techniques that prevent recovery (logical deletion followed by overwriting).
8.3. Portability and deletion on demand
The data subject may request:
- Portability of data in structured and interoperable format;
- Early deletion, except when there is a legal retention obligation.
9. BREACHES AND INCIDENTS
9.1. Incident management
Multiagents maintains a Security Incident Response Plan, which includes:
- Detection and containment of the breach immediately;
- Investigation to determine the cause, affected data, and impact;
- Notification to the National Data Protection Authority (ANPD), when applicable;
- Communication to affected data subjects, within a reasonable timeframe, when there is relevant risk or damage;
- Corrective measures to prevent recurrence;
- Detailed record of the incident and actions taken.
9.2. Notification deadlines
- To ANPD: within a reasonable timeframe, as determined by the authority (generally up to 2 business days);
- To data subjects: immediately after confirming the incident, when there is relevant risk.
10. INTERNATIONAL DATA TRANSFER
Multiagents does not perform international transfer of personal data, except when essential for:
- Contract execution or legal obligation;
- Use of cloud infrastructure services with data centers outside Brazil, always with:
- Standard Contractual Clauses (SCCs);
- Guarantee of adequate level of protection, according to LGPD;
- Express consent of the data subject, when applicable.
Currently, Multiagents' main infrastructure operates on servers located in Brazil.
11. DATA PROTECTION OFFICER (DPO)
Multiagents designates a Data Protection Officer (DPO), responsible for:
- Accepting complaints and communications from data subjects;
- Providing clarifications about data processing;
- Receiving communications from ANPD and taking appropriate measures;
- Guiding employees and contractors on data protection practices.
DPO Contact:
- Email: contact@multiagents.inc
- Support channel: available on the platform
12. UPDATES TO THIS POLICY
This Data Protection Policy may be updated at any time to reflect:
- Legislative or regulatory changes;
- Operational changes to the platform;
- Security and privacy best practices.
12.1. Change notification
When there are relevant changes, Multiagents will notify users through:
- Email registered on the platform;
- Notice on the platform interface;
- Publication on the official website.
Continued use of the platform after notification implies acceptance of the new conditions.