1. Identification of the Controller
Nuvia AI LTDA., registered under CNPJ 54.435.325/0001-26, with registered office at Av. Paulista 509, suite 1513, 15th floor, São Paulo/SP, ZIP 01311-910, Brazil, is the controller of personal data processed in connection with the provision of its services, pursuant to Brazil’s General Personal Data Protection Law (Law No. 13.709/2018, LGPD).
Where processing involves data subjects located in the European Union or the United Kingdom, the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the UK GDPR also apply.
2. Scope and Covered Services
This policy applies to the processing of personal data carried out by Nuvia across all of its products and channels, including:
- SaaS Platform (app.nuvia.ai): AI agents for sales and customer engagement via WhatsApp and LinkedIn;
- Institutional website (nuvia.ai): lead capture and commercial contact;
- Chrome Extension, Nuvia Company Insights: generation of company summaries from public domains;
- Third-party system integrations: HubSpot, Google Calendar, ZapSign, Advbox, Amigo, and RD Station.
3. Personal Data Processed
3.1 B2B Customer Data (platform users)
- Full name, corporate email, job title, and company;
- Phone number (for WhatsApp communications);
- Access credentials (password stored with bcrypt hash, never in plain text);
- Usage logs, IP address, device type, and browser;
- History of interactions with AI agents.
3.2 Lead Data (processed on behalf of customers)
Nuvia acts as a processor when its customers use the platform to prospect and engage leads. Data processed in this context include:
- Name, email, phone number, and job title of business contacts (B2B data);
- Conversation history via WhatsApp and LinkedIn;
- Sales opportunity qualification information.
Nuvia does not use these data to train its own AI models. Processing occurs solely for the provision of the contracted service.
3.3 Institutional Website Data
- Name, email, and phone number submitted through contact and demo scheduling forms;
- IP address, device identifier, and browser (user agent);
- Cookie and campaign tracking identifiers, including origin parameters (UTM) and advertising and analytics platform identifiers;
- Pages visited, traffic source, and form interactions.
3.4 Chrome Extension, Nuvia Company Insights
The extension collects only the domain of the active tab to query public company data and generate automatic summaries. No personal user data (name, email, password, or browsing history) is collected, stored, or transmitted.
3.5 Professional Data Obtained from Third Parties and Public Sources
Nuvia obtains professional contact data from public sources and licensed specialized providers for the purpose of composing and enriching B2B commercial contact databases made available to its customers. With respect to these data, Nuvia acts as a controller.
The categories of data processed in this context include:
- Name, corporate email, job title, and company of professional contacts;
- Public corporate registration data of legal entities obtained from official sources.
The legal basis for this processing is legitimate interest (Article 7, IX of the LGPD), in the context of professional communication between businesses. No sensitive personal data are processed in this context.
The data subject may, at any time, request information about the origin of their data, object to the processing, or request erasure through the channel indicated in Section 14.
4. Legal Bases
All personal data processing carried out by Nuvia has a specific legal basis under Article 7 of the LGPD. Where the GDPR or UK GDPR applies, the equivalent bases are indicated in parentheses:
- Performance of a contract (Article 7, V of the LGPD / Article 6(1)(b) of the GDPR): Account creation, authentication, delivery of contracted services, and technical support.
- Legitimate interest (Article 7, IX of the LGPD / Article 6(1)(f) of the GDPR): Security logs, fraud prevention, continuous service improvement, operational communications, and the obtaining and enrichment of professional B2B contact data from public sources and licensed providers (Section 3.5).
- Consent (Article 7, I of the LGPD / Article 6(1)(a) of the GDPR): Marketing, newsletters, and promotional communications. Consent may be withdrawn at any time.
- Compliance with a legal obligation (Article 7, II of the LGPD / Article 6(1)(c) of the GDPR): Responding to requests from competent authorities, the ANPD, EU/UK data protection authorities, and tax obligations.
5. Purposes of Processing
- Provision and maintenance of contracted services;
- User authentication and access control (RBAC);
- Operational communications (notifications, alerts, support);
- Performance analysis and continuous platform improvement;
- Fraud prevention and security monitoring;
- Compliance with legal and regulatory obligations;
- Marketing and commercial prospecting (based on consent);
- Composition and enrichment of B2B commercial contact databases made available to customers (Section 3.5).
6. Data Retention and Disposal
Nuvia retains personal data for the shortest period necessary to fulfill the purposes described in this policy or applicable legal obligations.
| Category | Retention Period |
|---|---|
| B2B customer data | Export made available within 15 days after contract termination upon formal written request; permanent deletion within 30 days after termination or after confirmation of complete export, whichever occurs later. |
| Lead data (platform) | According to customer configuration; deletion within 30 days after contract termination. |
| Institutional website lead data | Retained while an active commercial relationship or legitimate interest exists; reviewed annually. |
| Security and audit logs | Minimum of 1 year, in accordance with internal information security requirements. |
| Browsing data (website) | According to provider policies (Google Analytics: 14 months; Meta Pixel: 180 days). |
| Chrome Extension | Not retained; real-time processing without persistence. |
| Data subject to litigation | For the period determined by legal counsel as necessary. |
Personal data are deleted or de-identified when they are no longer necessary for the purposes that justified their processing. Deletion covers all systems in which the data subject’s data are recorded, including CRM systems and support tools, and is carried out through a manual process by the Engineering Team, with a record kept for audit purposes.
7. Data Sharing
Nuvia shares personal data only with third-party providers and partners strictly necessary for the provision of contracted services, always under appropriate data protection agreements (DPAs). Categories of third parties with whom data may be shared include:
- Cloud infrastructure providers (hosting, databases, and file storage);
- Providers of artificial intelligence models used for natural language processing;
- Communication channel platforms (messaging and professional social networks);
- CRM and calendar tools integrated by the customer;
- Monitoring providers for secure platform operation;
- Licensed specialized providers of B2B professional contact data, in the context of the processing described in Section 3.5;
- Business partners and affiliates, based on the data subject’s consent or another specific legal basis.
Nuvia does not sell personal data to third parties. Lead data processed on behalf of customers are used exclusively for the provision of the contracted service and are not shared with other customers or for Nuvia’s own marketing purposes.
Professional data obtained from third parties and public sources (Section 3.5) may be made available to Nuvia’s customers within the scope of contracted services, under the controller role described in that section.
8. International Data Transfers
Personal data processed by Nuvia are stored and processed in the United States of America, due to the location of the primary infrastructure and of certain contracted providers.
Nuvia adopts the following safeguards for international transfers, in accordance with Article 33 of the LGPD and, where applicable, Chapter V of the GDPR:
- Execution of Standard Contractual Clauses (SCCs) of the European Commission with international providers;
- For data originating in the United Kingdom, adoption of the UK Addendum to the SCCs or the International Data Transfer Agreement (IDTA), as applicable;
- Data Processing Agreements (DPAs) with all providers that process data on behalf of Nuvia;
- Verification that destinations adopt a level of protection compatible with the LGPD and, where applicable, the GDPR and UK GDPR.
9. Data Security
Nuvia implements technical and organizational controls to protect personal data against unauthorized access, loss, or improper disclosure, including:
- TLS in transit on all platform endpoints;
- AES-256 encryption at rest for databases and file storage;
- bcrypt hashing (salt 10) for password storage;
- Role-based access control (RBAC) with multi-tenant isolation by company;
- Structured access logs with method, URL, status, and IP for audit purposes;
- Rate limiting on all APIs;
- Input validation with Zod at all system boundaries;
- An active Information Security Program, with periodic reviews and continuous improvement of controls.
10. Data Subject Rights
Under Article 18 of the LGPD, data subjects have the following rights, exercisable at any time:
- Confirmation and Access (Article 18, I and II): Confirm the existence of processing and obtain a copy of the data processed.
- Correction (Article 18, III): Request the update or correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion (Article 18, IV): Request the anonymization, blocking, or deletion of unnecessary data or data processed in noncompliance with the LGPD.
- Portability (Article 18, V): Request the portability of data to another service or product provider.
- Erasure (Article 18, VI): Request the erasure of data processed on the basis of consent.
- Information about sharing (Article 18, VII): Obtain information about entities with which Nuvia shares data.
- Withdrawal of consent (Article 18, IX): Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Objection (Article 18, §2º): Object to processing based on legal grounds other than consent, in cases of noncompliance with the LGPD.
- Review of automated decisions (Article 20 of the LGPD): Request review of decisions made solely on the basis of automated processing of personal data that affect their interests, including commercial qualification decisions. Data subjects in the European Union and the United Kingdom have the equivalent right under Article 22 of the GDPR.
Data subjects located in the European Union and the United Kingdom have equivalent rights under Articles 15 to 22 of the GDPR, including the right to lodge a complaint with the competent data protection authority.
To exercise any of these rights, contact Nuvia’s Data Protection Officer (DPO) at dpo@nuvia.ai. Identification of the data subject and a description of the right to be exercised are required. The response period is up to 15 calendar days from receipt of the request, extendable with justification.
11. Cookies and Tracking Technologies
The nuvia.ai website uses cookies and similar technologies for operation, analytics, and marketing. The cookies used include:
- Essential / Session: Necessary for authentication and basic platform functionality. Cannot be disabled.
- Analytics: Collection of browsing data to improve the website. May be disabled in browser settings.
- Marketing: Tracking for advertising campaigns. Require consent and may be withdrawn.
- Functionality: Store language and login preferences to improve the experience.
The data subject may configure their browser to refuse cookies or to be notified when a cookie is sent. Disabling essential cookies may affect platform functionality.
12. Security Incidents
In the event of a security incident that may pose a risk or relevant harm to data subjects, Nuvia will follow its Incident Response Plan and take the following measures:
- Immediate containment and impact assessment;
- Notification to Brazil’s National Data Protection Authority (ANPD) within the period established by Article 48 of the LGPD;
- Communication to affected data subjects, where applicable, in clear and accessible language;
- Recording of the incident and of the measures taken for audit purposes.
Where the incident involves data subjects in the European Union or the United Kingdom, Nuvia will also observe the notification timelines and obligations under the GDPR and UK GDPR, as applicable.
13. Effectiveness and Updates
This policy takes effect on August 18, 2026 and supersedes prior versions. Nuvia will review this policy at least annually or whenever there are material changes to data processing practices.
Substantial changes will be communicated by email to registered data subjects and published on the website with an indication of the update date.
14. Contact and Data Protection Officer (DPO)
For questions, rights requests, incident reports, or any matter related to Nuvia’s processing of personal data:
| Data Protection Officer (DPO) | Antero Silva |
| DPO email | dpo@nuvia.ai |
| Support email | support@nuvia.ai |
| Postal address | Av. Paulista 509, suite 1513, 15th floor, São Paulo/SP, ZIP 01311-910, Brazil |