DATA PROTECTION POLICY
MULTIAGENTS

Updated: January 2026

1. PURPOSE

This Data Protection Policy aims to establish guidelines and responsibilities for personal data processing within the scope of the Multiagents platform activities, in compliance with Law No. 13,709/2018 (Brazilian General Data Protection Law - LGPD).

2. SCOPE

Applies to all employees, service providers, partners, suppliers, clients, and third parties who process personal data through the Multiagents platform, regardless of the medium (physical or digital), covering the entire personal data processing chain.

3. APPLICABLE PRINCIPLES

Personal data processing by Multiagents shall observe the following principles established by LGPD:

3.1. Purpose

Data will be processed for legitimate, specific, explicit, and informed purposes, without the possibility of subsequent processing in a manner incompatible with these purposes.

3.2. Adequacy

Compatibility of processing with the purposes informed to the data subject, according to the processing context.

3.3. Necessity

Limitation of processing to the minimum necessary for achieving its purposes, with scope of relevant, proportional, and non-excessive data.

3.4. Free access

Guarantee to data subjects of facilitated and free consultation about the form and duration of processing, as well as the entirety of their personal data.

3.5. Data quality

Guarantee to data subjects of accuracy, clarity, relevance, and updating of data, according to the need and for fulfilling the purpose of its processing.

3.6. Transparency

Guarantee to data subjects of clear, precise, and easily accessible information about processing and the respective processing agents.

3.7. Security

Use of technical and administrative measures capable of protecting personal data from unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination.

3.8. Prevention

Adoption of measures to prevent the occurrence of damages due to personal data processing.

3.9. Non-discrimination

Impossibility of processing for unlawful or abusive discriminatory purposes.

3.10. Accountability and demonstration

Demonstration by the processing agent of the adoption of effective measures capable of proving compliance with personal data protection rules and the effectiveness of these measures.

4. DATA SUBJECT RIGHTS

Multiagents guarantees data subjects all rights provided in Article 18 of LGPD, including:

  • Confirmation of processing of personal data;
  • Access to personal data being processed;
  • Correction of incomplete, inaccurate, or outdated data;
  • Anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data;
  • Data portability to another service or product provider, upon express request;
  • Deletion of personal data processed with the data subject's consent;
  • Information about data sharing with public and private entities;
  • Information about the possibility of not providing consent and the consequences of refusal;
  • Consent revocation, under the terms of LGPD.
4.1. Channel for exercising rights

To exercise any of the above rights, the data subject may contact us via email: contact@multiagents.inc

Requests will be answered within 15 business days, according to deadlines established by ANPD.

5. LEGAL BASES FOR PROCESSING

Personal data processing operations carried out by Multiagents are based on the following legal bases provided in Article 7 of LGPD:

  • Consent of the data subject;
  • Compliance with legal or regulatory obligation by the controller;
  • Contract execution or preliminary procedures related to a contract to which the data subject is a party;
  • Regular exercise of rights in judicial, administrative, or arbitration proceedings;
  • Protection of life or physical safety of the data subject or third party;
  • Health protection, exclusively, in procedures performed by health professionals, health services, or health authorities;
  • Legitimate interest of the controller or third party;
  • Credit protection, under current legislation.

6. SECURITY AND GOVERNANCE

Multiagents adopts rigorous technical and administrative measures to protect personal data from unauthorized access, destruction, loss, alteration, communication, or any form of inadequate or unlawful processing.

6.1. Implemented security measures:
  • Access control based on individual credentials, multi-factor authentication, and permission profiles;
  • Data encryption in transit (TLS 1.3) and at rest (AES-256);
  • Secure storage in certified cloud infrastructure with international certifications (ISO 27001, SOC 2);
  • Continuous monitoring of systems and access logs for detection of suspicious activities;
  • Firewall and DDoS protection to prevent intrusions and cyberattacks;
  • Automatic backup with configurable retention and periodic recovery tests;
  • Periodic training of employees on information security and data protection best practices;
  • Internal policies for data classification, incident management, and breach response;
  • Regular audits of security and compliance conducted by independent third parties;
  • Environment segregation (production, staging, and development) with specific controls.
6.2. Third-party credential management

When Multiagents accesses third-party systems on behalf of the client (via API, OAuth2, or custom MCPs), all credentials are:

  • Stored encrypted with securely managed keys;
  • Isolated by tenant (client), without sharing between environments;
  • Auditable, with logs of all operations performed;
  • Revocable at any time by the data subject or client.

7. DATA SHARING

Multiagents may share personal data in the following cases:

7.1. With contracted processors

Service providers who process data on behalf of Multiagents (e.g., cloud infrastructure providers, monitoring tools, authentication services), always under:

  • Contractual confidentiality and data protection clauses;
  • Guarantee of LGPD compliance;
  • Limitation of processing to authorized purposes.
7.2. With public authorities

When required by law, court order, request from competent authority, or to comply with legal or regulatory obligation.

7.3. In judicial, administrative, or arbitration proceedings

For regular exercise of rights or defense in proceedings.

7.4. With the data subject's consent

Upon express authorization for specific purposes.

7.5. With third parties integrated via platform

When the client configures integrations with CRMs, communication tools, or proprietary systems via API/MCP, sharing occurs under the client's responsibility, who acts as controller of that data.

8. RETENTION AND DISPOSAL

8.1. Retention period

Personal data will be stored only for the time necessary to fulfill its purposes, respecting:

  • Contractual term during the service period;
  • Legal or regulatory deadline, when applicable (e.g., tax, labor obligations);
  • Deadline for exercising rights in judicial or administrative proceedings;
  • Data subject consent, when applicable.
8.2. Secure deletion

After the retention period ends, data will be:

  • Anonymized irreversibly, when possible; or
  • Securely deleted, using techniques that prevent recovery (logical deletion followed by overwriting).
8.3. Portability and deletion on demand

The data subject may request:

  • Portability of data in structured and interoperable format;
  • Early deletion, except when there is a legal retention obligation.

9. BREACHES AND INCIDENTS

9.1. Incident management

Multiagents maintains a Security Incident Response Plan, which includes:

  • Detection and containment of the breach immediately;
  • Investigation to determine the cause, affected data, and impact;
  • Notification to the National Data Protection Authority (ANPD), when applicable;
  • Communication to affected data subjects, within a reasonable timeframe, when there is relevant risk or damage;
  • Corrective measures to prevent recurrence;
  • Detailed record of the incident and actions taken.
9.2. Notification deadlines
  • To ANPD: within a reasonable timeframe, as determined by the authority (generally up to 2 business days);
  • To data subjects: immediately after confirming the incident, when there is relevant risk.

10. INTERNATIONAL DATA TRANSFER

Multiagents does not perform international transfer of personal data, except when essential for:

  • Contract execution or legal obligation;
  • Use of cloud infrastructure services with data centers outside Brazil, always with:
    • Standard Contractual Clauses (SCCs);
    • Guarantee of adequate level of protection, according to LGPD;
    • Express consent of the data subject, when applicable.

Currently, Multiagents' main infrastructure operates on servers located in Brazil.

11. DATA PROTECTION OFFICER (DPO)

Multiagents designates a Data Protection Officer (DPO), responsible for:

  • Accepting complaints and communications from data subjects;
  • Providing clarifications about data processing;
  • Receiving communications from ANPD and taking appropriate measures;
  • Guiding employees and contractors on data protection practices.

DPO Contact:

  • Email: contact@multiagents.inc
  • Support channel: available on the platform

12. UPDATES TO THIS POLICY

This Data Protection Policy may be updated at any time to reflect:

  • Legislative or regulatory changes;
  • Operational changes to the platform;
  • Security and privacy best practices.
12.1. Change notification

When there are relevant changes, Multiagents will notify users through:

  • Email registered on the platform;
  • Notice on the platform interface;
  • Publication on the official website.

Continued use of the platform after notification implies acceptance of the new conditions.

13. CONTACT

For questions, requests, or exercise of rights related to data protection, please contact:

Email: contact@multiagents.inc
Website: https://www.multiagents.inc

Multiagents
Vertical AI Multi-Agent Platform
https://www.multiagents.inc

The most efficient way to build and operate vertical AI agents for Ecommerce, SaaS and scalable businesses.

© 2026 Multiagents. All rights reserved.