BdrGo
PTENES
Legal center Privacy Terms Sign in
LGPD addendum

Data processing

Responsibilities between the customer as controller and BdrGo as processor for lists, campaigns, conversations and integrations.

Last updated: August 30, 2026 ← Back to the website

BdrGo is the new name of NextWho. References to the former brand in the current documents identify the same platform.

This Data Processing Agreement ("DPA") forms part of the agreement when incorporated by the Order. The parties' legal identification, the subject matter, the term and the particulars of the operation are set out in the Order and completed addenda.

1. Roles and subject matter

For data from leads, lists, campaigns, messages and integrations processed in accordance with documented instructions, the customer acts as controller and BdrGo as processor. Each party remains the controller of data it processes for its own purposes, such as account administration, security, billing, defense of rights and institutional relations.

The classification follows each party's actual decisions. If BdrGo begins determining the purpose and essential means of an operation, the parties will document the change and the corresponding responsibilities.

2. Customer instructions

The Order, settings, campaigns, API calls and authorized requests constitute the documented instructions. BdrGo will process data only to provide, protect and support the service. If an instruction appears to violate the law or mandatory policies, it may be suspended pending clarification.

The customer warrants that it has the authority, transparency and legal basis to collect, enter and enrich data and communicate with data subjects. BdrGo is not required to carry out an unlawful instruction or conceal the customer's identity.

3. Processing details

Subject matterProvision of the AI-powered lead generation, enrichment and multichannel prospecting platform.
DurationThe term of the agreement and the applicable retention, export and deletion period.
OperationsAuthorized collection, receipt, validation, organization, enrichment, storage, analysis, generation, transmission, integration, export and deletion.
DataProfessional identification and contact details, company, job title, professional profiles, messages, responses, meetings, metadata, logs and customer-defined fields.
Data subjectsUsers, administrators, leads, company representatives, customers and campaign recipients.
Sensitive dataNot part of the standard scope and must not be entered without written authorization, necessity and additional safeguards.

4. BdrGo's obligations

  • process data in accordance with documented instructions and limit access to authorized persons;
  • maintain confidentiality commitments and technical and organizational controls proportionate to the risk;
  • provide reasonable assistance with rights requests, incidents, assessments and customer obligations;
  • maintain records and evidence of the operations under its responsibility;
  • notify relevant changes of subprocessor when required by the Order;
  • return, export, delete or anonymize data upon termination, subject to legal obligations.

5. Customer obligations

  • define the purpose, legal basis, audience, message, frequency and qualification criteria;
  • provide notices and obtain consent when necessary, including for WhatsApp;
  • respond to data subjects and inform BdrGo of requests that depend on the platform;
  • not instruct discriminatory, excessive or misleading processing, or processing incompatible with the data subject's expectations;
  • manage users, credentials, integrations, exports and authorized recipients;
  • notify BdrGo of any incident or misuse related to its accounts and data.

6. Subprocessors

The customer authorizes the use of subprocessors necessary for cloud services, storage, authentication, security, billing, email, messaging, AI, research, enrichment and integrations. BdrGo will require compatible protection and remain responsible for its obligations as processor.

The applicable list will be made available when entering into the agreement or upon request. If the Order provides for notification of a new subprocessor, the customer may raise an objection based on data protection grounds; the parties will seek a reasonable alternative, and if none is possible, only the affected feature may be terminated.

7. International transfers

International transfers will use a valid mechanism under the LGPD and ANPD regulations. When Brazilian standard contractual clauses are used, they will be incorporated without modification into the applicable instrument and completed with the transfer information.

8. Security

Measures may include logical separation of workspaces, least privilege, authentication, secrets protection, secure transmission, audit logs, backups, monitoring, vulnerability management and vendor controls. The specific level takes into account the nature, context, volume, risk and state of the art.

The customer acknowledges that integrations and settings under its control also affect security and must keep permissions, devices, domains, senders and credentials appropriately protected.

9. Incidents

BdrGo will notify the customer without undue delay after confirming a security incident involving data under its processing, providing, as available, the nature, affected categories, measures taken, risks and a contact point. Updates may be provided in stages without delaying the first useful notification.

The customer, as controller, decides on and carries out notifications to the ANPD and data subjects when required. BdrGo will provide reasonable cooperation and preserve evidence, without making statements on the customer's behalf unless authorized in writing or required by its own legal obligation.

10. Rights, audits and cooperation

BdrGo will provide features and reasonable assistance to locate, correct, export, block or delete data. Complex requests, on-site audits or activities outside the standard service may depend on a previously agreed scope, confidentiality, security, scheduling and costs.

Audits must avoid access to other customers' data and information that could compromise security. Existing reports, certifications, questionnaires and evidence will take precedence over invasive inspections.

11. Termination

After the service ends, the customer may export data during the indicated window. BdrGo will then delete or anonymize the content according to its technical cycle, except for retention required by law, litigation, security or a minimal suppression list. Retained data will be isolated, with limited access and no use for new purposes.

12. Liability and precedence

Each party is responsible for its decisions, obligations and violations. This DPA does not transfer responsibility for defining the customer's legal basis and message to the processor, nor does it eliminate BdrGo's liability for failure to follow legitimate instructions or its own legal duties. Contractual limits do not apply where prohibited by law.

© 2026 BdrGo Data deletion · Cookies · Acceptable use · Commercial terms Questions: [email protected]