BdrGo is the new name of NextWho. References to the former brand in the current documents identify the same platform.
This Data Processing Agreement ("DPA") forms part of the agreement when incorporated by the Order. The parties' legal identification, the subject matter, the term and the particulars of the operation are set out in the Order and completed addenda.
1. Roles and subject matter
For data from leads, lists, campaigns, messages and integrations processed in accordance with documented instructions, the customer acts as controller and BdrGo as processor. Each party remains the controller of data it processes for its own purposes, such as account administration, security, billing, defense of rights and institutional relations.
The classification follows each party's actual decisions. If BdrGo begins determining the purpose and essential means of an operation, the parties will document the change and the corresponding responsibilities.
2. Customer instructions
The Order, settings, campaigns, API calls and authorized requests constitute the documented instructions. BdrGo will process data only to provide, protect and support the service. If an instruction appears to violate the law or mandatory policies, it may be suspended pending clarification.
The customer warrants that it has the authority, transparency and legal basis to collect, enter and enrich data and communicate with data subjects. BdrGo is not required to carry out an unlawful instruction or conceal the customer's identity.
3. Processing details
| Subject matter | Provision of the AI-powered lead generation, enrichment and multichannel prospecting platform. |
|---|---|
| Duration | The term of the agreement and the applicable retention, export and deletion period. |
| Operations | Authorized collection, receipt, validation, organization, enrichment, storage, analysis, generation, transmission, integration, export and deletion. |
| Data | Professional identification and contact details, company, job title, professional profiles, messages, responses, meetings, metadata, logs and customer-defined fields. |
| Data subjects | Users, administrators, leads, company representatives, customers and campaign recipients. |
| Sensitive data | Not part of the standard scope and must not be entered without written authorization, necessity and additional safeguards. |
4. BdrGo's obligations
- process data in accordance with documented instructions and limit access to authorized persons;
- maintain confidentiality commitments and technical and organizational controls proportionate to the risk;
- provide reasonable assistance with rights requests, incidents, assessments and customer obligations;
- maintain records and evidence of the operations under its responsibility;
- notify relevant changes of subprocessor when required by the Order;
- return, export, delete or anonymize data upon termination, subject to legal obligations.
5. Customer obligations
- define the purpose, legal basis, audience, message, frequency and qualification criteria;
- provide notices and obtain consent when necessary, including for WhatsApp;
- respond to data subjects and inform BdrGo of requests that depend on the platform;
- not instruct discriminatory, excessive or misleading processing, or processing incompatible with the data subject's expectations;
- manage users, credentials, integrations, exports and authorized recipients;
- notify BdrGo of any incident or misuse related to its accounts and data.
6. Subprocessors
The customer authorizes the use of subprocessors necessary for cloud services, storage, authentication, security, billing, email, messaging, AI, research, enrichment and integrations. BdrGo will require compatible protection and remain responsible for its obligations as processor.
The applicable list will be made available when entering into the agreement or upon request. If the Order provides for notification of a new subprocessor, the customer may raise an objection based on data protection grounds; the parties will seek a reasonable alternative, and if none is possible, only the affected feature may be terminated.
7. International transfers
International transfers will use a valid mechanism under the LGPD and ANPD regulations. When Brazilian standard contractual clauses are used, they will be incorporated without modification into the applicable instrument and completed with the transfer information.
8. Security
Measures may include logical separation of workspaces, least privilege, authentication, secrets protection, secure transmission, audit logs, backups, monitoring, vulnerability management and vendor controls. The specific level takes into account the nature, context, volume, risk and state of the art.
The customer acknowledges that integrations and settings under its control also affect security and must keep permissions, devices, domains, senders and credentials appropriately protected.
9. Incidents
BdrGo will notify the customer without undue delay after confirming a security incident involving data under its processing, providing, as available, the nature, affected categories, measures taken, risks and a contact point. Updates may be provided in stages without delaying the first useful notification.
The customer, as controller, decides on and carries out notifications to the ANPD and data subjects when required. BdrGo will provide reasonable cooperation and preserve evidence, without making statements on the customer's behalf unless authorized in writing or required by its own legal obligation.
10. Rights, audits and cooperation
BdrGo will provide features and reasonable assistance to locate, correct, export, block or delete data. Complex requests, on-site audits or activities outside the standard service may depend on a previously agreed scope, confidentiality, security, scheduling and costs.
Audits must avoid access to other customers' data and information that could compromise security. Existing reports, certifications, questionnaires and evidence will take precedence over invasive inspections.
11. Termination
After the service ends, the customer may export data during the indicated window. BdrGo will then delete or anonymize the content according to its technical cycle, except for retention required by law, litigation, security or a minimal suppression list. Retained data will be isolated, with limited access and no use for new purposes.
12. Liability and precedence
Each party is responsible for its decisions, obligations and violations. This DPA does not transfer responsibility for defining the customer's legal basis and message to the processor, nor does it eliminate BdrGo's liability for failure to follow legitimate instructions or its own legal duties. Contractual limits do not apply where prohibited by law.