Personal Data Processing Addendum (DPA) — Fabapp
Last updated: July 22, 2026
This Personal Data Processing Addendum ("Addendum" or "DPA") is incorporated into the Terms of Use and applies when FABAPP TECNOLOGIA S.A., CNPJ No. 04.013.941/0001-10 ("Fabapp" or "Processor") processes personal data of the End Users of the applications created by the client ("Client" or "Controller"), on the Client's behalf and instruction, pursuant to Lei nº 13.709/2018 (LGPD — Brazil's General Data Protection Law).
In the event of a conflict between this Addendum and the Terms of Use regarding the processing of personal data of the End Users, this Addendum prevails.
1. Roles of the parties
1.1. The Client is the Controller and Fabapp is the Processor of the Personal Data of the End Users processed through the Client's applications.
1.2. As regards the Client's own registration, account, billing, and usage data, Fabapp acts as Controller, in accordance with the Privacy Policy.
2. Subject matter and instructions
2.1. Fabapp will process the Personal Data of the End Users exclusively in accordance with the Client's documented instructions, materialized by the configuration and use of the Platform and by this Addendum, and for the purposes of providing, maintaining, protecting, and billing the Platform.
2.2. Fabapp will inform the Client if, in its assessment, an instruction violates the LGPD or another applicable rule.
2.3. Fabapp's own use. Regardless of the Controller–Processor relationship above, the Client acknowledges and authorizes that Fabapp process data in accordance with the Terms of Use and the Privacy Policy, including to improve the Platform and to develop and train AI models and technologies, in which case Fabapp acts as Controller with respect to that specific processing, adopting safeguards such as aggregation, pseudonymization, or anonymization.
3. Subject matter of the processing (Annex I)
- Nature and purpose: operation of the Client's application (storage, query, processing, and provision of data), authentication of End Users, AI content generation, and related functions.
- Duration: for as long as the contractual relationship is in effect, subject to legal retention.
- Types of data: those the Client decides to collect in its application (for example: identification, contact, credentials, content generated by the End User).
- Categories of data subjects: the End Users and other data subjects defined by the Client.
The Client is responsible for not entering sensitive personal data or data of children/adolescents without an adequate legal basis and without the required safeguards.
4. Security
Fabapp will adopt technical and organizational measures that are reasonable and compatible with the risk, including access control, logical segregation by project/application, encryption in transit and, where applicable, at rest, access logs, and incident response processes.
5. Confidentiality
Fabapp ensures that persons authorized to process the Personal Data are subject to a duty of confidentiality.
6. Sub-processors
6.1. The Client generally authorizes Fabapp to engage sub-processors for the provision of the Platform (for example, cloud hosting, AI providers, payment processing, communication, and security).
6.2. Fabapp will impose on sub-processors data protection obligations compatible with those of this Addendum and will remain responsible to the Client for the sub-processors' compliance.
6.3. The list of the main sub-processors may be obtained at privacy@fabapp.com. Material changes may be communicated by reasonable means, with the Client entitled to object for a legitimate reason related to data protection.
7. Rights of data subjects
7.1. Considering the nature of the processing, Fabapp makes available on the Platform features that assist the Client in responding to data subject requests.
7.2. Should Fabapp directly receive a request from an End User, it may forward it to the Client, who is responsible for responding to it as Controller.
8. Security incidents
Fabapp will notify the Client, without undue delay after becoming aware, of security incidents involving the Personal Data processed on the Client's behalf, with the information reasonably available so that the Client can comply with its obligations to notify the ANPD and the data subjects.
9. International transfer
Fabapp may process data outside Brazil, subject to the cases and safeguards of the LGPD (art. 33 to 36).
10. Deletion or return
Once the processing has ended, Fabapp will, at the Client's choice and in accordance with the Platform's features, delete or return the Personal Data, subject to the retention required by law. Export tools available on the Platform allow the Client to obtain its data before termination.
11. Audit and accountability
Upon reasonable request, with prior notice and under confidentiality, Fabapp will make available the information necessary to demonstrate compliance with this Addendum, preferably by means of existing documentation, reports, or certifications.
12. Liability
The liability of the parties observes the LGPD (art. 42 to 45) and the limits set out in the Terms of Use and, where applicable, in the Commercial Agreement.
13. Contact
Matters relating to this Addendum: privacy@fabapp.com (channel of the Encarregado/DPO — Data Protection Officer).