A summary for our users
This summary highlights the essential points of our Privacy Policy. The full document below details our practices and constitutes the legal agreement.
- We are the Controller of your account data — name, email, billing.
- We are the Processor of the content you input: you (or your company) are the Controller.
- We have no control over the legality or nature of your content.
- Account data: identification, contact and billing, to administer your account, provide support and process payments.
- Usage data: access logs, device type, to ensure security, monitor performance and improve our services.
- Your content is not used to train our general-purpose AI models.
- Processing is secure and transient, solely to provide the service you hired.
- Our contracts with AI providers (such as OpenAI) also prohibit training on your data.
- We never sell your personal data; we share only with essential partners under strict contractual obligations.
- You can access, correct and request deletion of your personal data — most of it in your account settings.
- End-to-end encryption (TLS and AES-256), strict access control and continuous monitoring.
Nama Inteligência Artificial Ltda. ("Nama", "we", "us" or "our") develops Artificial Intelligence solutions designed to broaden access to information and support decisions in corporate environments. This Privacy Policy explains how we collect, use, store, share, and protect personal data related to our products and services, in compliance with the General Data Protection Law (Law No. 13.709/2018 — "LGPD") and other applicable laws. This Policy is an integral part of Nama's Terms of Service and, where applicable, the Master Services Agreement (MSA) and its Annexes. In case of conflict, the contractual terms signed between the parties shall prevail. It must be read together with its Appendices, which are an integral part of this document.
01To whom this policy applies
This policy applies to all individuals who interact directly with Nama's products and services, such as visitors to our sites, users of our platforms, and representatives of our corporate clients. When we act as a Data Processor for our corporate clients, the processing of data entered by them into our platform is governed by the Privacy Policy and terms of our client (the Data Controller).
02Our role in data processing: controller and processor
To ensure full transparency, it is essential to distinguish the two roles Nama plays:
When Nama is the CONTROLLER: We act as the Controller of the data we collect directly from you to manage your account, process payments, and communicate. This includes your registration and platform usage data. We have full responsibility for the protection and legal use of this data, as described in this Policy.
When Nama is the PROCESSOR: When you use our services to process your own documents and data, your business is the Controller and Nama acts as the Processor. Our responsibility, in this case, is technical and security-related: we process your content strictly following your instructions and protect it with robust security measures. We have no control over the legality or nature of the content you send, which is your responsibility as the Controller.
03How we collect your personal data
We collect your personal data in the following ways:
- Provided directly by you: when registering, filling out forms, interacting with our products, requesting support, or sending resumes;
- Collected automatically: through cookies, access logs, use of our APIs or systems, and other tracking means;
- Received from third parties: such as partners, corporate clients (data controllers), suppliers, and platforms integrated with Nama.
04What personal data we collect
a) Account and Usage Data (Controlled by Nama)
- Identification and contact data (full name, email, phone, position).
- Login and authentication data.
- Technical interaction data (IP address, browser type, device, access logs).
- Billing and payment data.
b) Client Content (Processed by Nama as a Processor)
- Any files, documents, texts, or other data that you or your organization send, connect, or input into our platform to be processed by our AI services. Responsibility for the legality and content of this data lies exclusively with the Client (Controller).
05For what purposes we use your data
Our commitment to the privacy of your content: Nama does NOT use the content you input into the platform (your documents, questions, texts) to train our AI models in a general way, to benefit other clients, or for any other purpose than providing the service you hired. Our contracts with third-party AI providers (such as OpenAI) also contractually prohibit the use of this data for training their models.
The processing of your content is done securely and transiently, with the sole purpose of generating responses according to your instructions.
We process personal data for the following purposes:
- Allow access and operation of the Nama platform and services;
- Provide technical support and customer service;
- Comply with legal and regulatory obligations;
- Perform institutional and marketing communications (based on appropriate legal grounds);
- Ensure information security and prevent fraud;
- Improve features and user experience;
- Process payments and billing;
- Analyze data for performance improvement and new product development;
- Conduct audits and respond to public bodies when required by law;
- Execute contracts signed with clients and partners.
06Legal bases for data processing
The processing activities carried out by Nama are supported by the following legal bases, as applicable:
- Execution of a contract or preliminary procedures;
- Compliance with legal or regulatory obligation;
- Legitimate interest of Nama or third parties, safeguarding the rights of the data subject;
- Consent of the data subject, when required;
- Regular exercise of rights in judicial, administrative, or arbitration proceedings;
- Protection of life and physical integrity of the data subject or third parties.
07Sharing of personal data
Your personal data may be shared with:
- We make the data available to our corporate clients, to the extent that they are the Controllers of the Content entered on the platform by their own users;
- Sub-processors who provide services to Nama (e.g., cloud providers, third-party technical support, monitoring, information security);
- Public authorities, upon legal or judicial determination;
- Legal, accounting advisors, and independent auditors;
- In cases of merger, acquisition, or corporate restructuring.
All third parties are contractually obliged to adopt security and compliance measures compatible with the LGPD.
08Rights of data subjects
You have the following rights under the LGPD:
- Confirmation of the existence of the processing;
- Access to personal data;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary data or data processed in non-compliance;
- Data portability;
- Information about data sharing;
- Revocation of consent;
- Opposition to processing based on legitimate interest;
- Petition before the ANPD.
Requests can be made by email at legal@nama.ai. For your security, we may request proof of identity.
09Information security
Nama adopts technical and administrative measures capable of protecting personal data against unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination. Among the measures are:
- Encryption of data in transit (TLS) and at rest (AES-256);
- Control of access and granular authentication by role (RBAC);
- Logging and auditing of events;
- Monitoring and periodic vulnerability testing;
- Segregation of development, testing, and production environments;
- Incident response plan.
10Data retention and deletion
Personal data is stored for the time necessary to fulfill the purposes described in this policy or as required by legal, contractual, or regulatory obligations.
- Account data: retained while the account is active and for up to 180 days after closure to facilitate eventual reactivation, after which it is anonymized.
- User content: retained while the account is active. After closure, deleted within 30 days from production systems. Residual copies may remain in encrypted and isolated backups, deleted according to our rotation cycle.
- Billing data: retained as required by legal and fiscal requirements (up to 5 years or more, depending on jurisdiction).
11International data transfer
Nama uses infrastructure with servers located in different countries, especially in the United States. All transfers are carried out in accordance with applicable data protection legislation and use mechanisms such as Standard Contractual Clauses (SCCs), in addition to verifying partners' adherence to recognized adequacy frameworks, such as the Data Privacy Framework (DPF).
12Automated decisions
Nama does not use your data to make exclusively automated decisions that produce legal or similarly relevant effects on you. Our AI models operate as tools to support human decision-making, always with user or human operator supervision.
13Cookies and similar technologies
We may use cookies and similar tools to:
- Remember browsing preferences;
- Improve user experience on our site;
- Perform statistical analysis of usage;
- Display personalized content.
You can manage your cookie preferences directly in your browser or on our consent banner. For more information, please consult our Cookie Policy: https://nama.ai/cookies
14Changes to this policy
This Policy may be altered at any time to reflect changes in our practices or legal requirements. When significantly altered, the new version will be released with prominence in our channels and we will update the revision date. We recommend that you consult this page periodically.
Nama Inteligência Artificial Ltda.
CNPJ: 51.804.866/0001-96
Address: Rua Afonso de Freitas, 58, Paraíso, São Paulo/SP — CEP 04006-050
Contact email: legal@nama.ai
AAppendix A — Details on data processing and third-party services
To operate and improve the Nama platform, we rely on the support of technological partners (sub-processors) who are leaders in their fields. We maintain a high standard of security and privacy with all our partners and share only the data strictly necessary for each purpose. Below, we detail the main categories of services, the partners involved, and the main types of data processed.
1. Infrastructure, hosting, and AI processing
This is the backbone of our platform, ensuring performance, security, and the ability to process our AI solutions at scale.
| Partner | Main purpose | Examples of data processed | Privacy policy |
|---|---|---|---|
| Google Cloud (Google LLC) | Main cloud provider, data storage, AI processing (Vertex AI, Kubernetes Engine), and networking. | User Content (for processing), Usage Data, IP Address. | Google Policy |
| Amazon Web Services (AWS) | Specific hosting and data backup components (e.g., S3). | User Content (for backup), Usage Data. | AWS Policy |
| OpenAI API (OpenAI, L.L.C.) | Access to advanced language models for text generation as part of our RAG service. | User Content (only relevant context sent via prompt). | OpenAI Policy |
| Vercel (Vercel Inc.) | Hosting and distribution of front-end components of our site and application for optimized performance. | Usage Data. | Vercel Policy |
| Cloudflare (Cloudflare, Inc.) | Traffic optimization and network security (CDN, WAF). | Usage Data, IP Address, Trackers. | Cloudflare Policy |
2. Authentication and integrations
These services simplify platform access and allow connection with your data sources.
| Partner | Main purpose | Examples of data processed | Privacy policy |
|---|---|---|---|
| Google OAuth (Google LLC) | Authentication for registration and login using a Google account. | Google profile data (Name, Email, User ID). | Google Policy |
| Microsoft OAuth (Microsoft Corp.) | Authentication for registration and login using a Microsoft account. | Microsoft profile data (Name, Email, User ID). | Microsoft Policy |
| Account Access (Google Drive, OneDrive, Dropbox) | Allows you to connect your accounts to index files. | Authentication tokens and access to the files you authorize. | — |
3. Payment processing
Manages our subscriptions and processes payments securely.
| Partner | Main purpose | Examples of data processed | Privacy policy |
|---|---|---|---|
| Stripe (Stripe Inc) | Exclusive processor for credit card transactions and recurring subscription management. | Name, Email, Payment Information, Billing Address. | Stripe Policy |
4. Communication and contact management
Tools that help us communicate with you effectively.
| Partner | Main purpose | Examples of data processed | Privacy policy |
|---|---|---|---|
| ActiveCampaign, Inc. | Marketing automation, newsletter sending, and contact management. | Name, Email, Phone Number, Usage Data. | ActiveCampaign Policy |
| Postmark (Wildbit LLC) | Service for sending transactional emails (e.g., account confirmation, password reset). | Name, Email. | Postmark Policy |
5. Performance analysis and monitoring
We use these tools to understand how users interact with the platform and to ensure its stability and performance.
| Partner | Main purpose | Examples of data processed | Privacy policy |
|---|---|---|---|
| Google Analytics | Analysis of traffic and user behavior on our site and platform. | Cookies, Usage Data, Device ID. | Google Policy |
| New Relic (New Relic Inc.) | Real-time monitoring of technical performance and health of our infrastructure. | Usage Data, application performance data. | New Relic Policy |
6. Advertising (optional)
We may use these services to display ads about Nama on other platforms.
| Partner | Main purpose | Examples of data processed | Privacy policy |
|---|---|---|---|
| Google Ads, Meta Ads (Facebook/Instagram), LinkedIn Ads | Conversion tracking and remarketing to display relevant ads. | Cookies, Usage Data, Trackers. | — |
You can manage your advertising preferences directly in these platforms' settings or through our cookie management tool.
BAppendix B — Your privacy rights and how to exercise them
Nama recognizes and is committed to facilitating the exercise of your privacy rights, regardless of your location. You can exercise most of these rights directly in your account settings on the Nama App. For additional requests or questions, please contact our team at legal@nama.ai.
1. Your fundamental privacy rights
These are the rights we guarantee to all our users globally, in accordance with the principles of the most stringent privacy laws:
- Right of Access and Information — You have the right to know if we are processing your personal information and to request a copy of this data. You also have the right to be informed about how and why your data is used, with whom it is shared, and for how long it is retained.
- Right of Correction (Rectification) — You have the right to request the correction of any inaccurate or incomplete personal information we maintain about you.
- Right to Erasure ("Right to be Forgotten") — You have the right to request the deletion of your personal information. We will comply with this request, except in cases where we are legally required to retain the data (for example, for tax, security purposes, or to comply with legal obligations).
- Right to Withdraw Consent — When the processing of your data is based on your consent, you have the right to withdraw it at any time. Withdrawal of consent will not affect the legality of processing carried out before its withdrawal.
- Right to Object to Processing — You have the right to object to the processing of your personal information in certain circumstances, such as for direct marketing purposes.
- Right to Data Portability — You have the right to receive the personal information you have provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit it to another controller, where technically feasible.
2. Regional specificities
In addition to the fundamental rights above, specific laws may grant additional rights:
| Region | Applicable legislation | Additional rights and considerations |
|---|---|---|
| Brazil | LGPD (General Data Protection Law) | In addition to fundamental rights, the LGPD guarantees you the right to review automated decisions that affect your interests and the right to file a complaint directly with the National Data Protection Authority (ANPD). You also have the right to be informed about the possibility of not providing consent and the consequences of such refusal. |
| European Economic Area (EEA) and UK | GDPR (General Data Protection Regulation) | The GDPR emphasizes the right to restriction of processing, allowing you to request the limitation of the use of your data under certain conditions. You also have the right to file a complaint with your local data protection authority (DPA). |
| United States | CCPA/CPRA (California) and other state laws | Residents of applicable states have the right to opt out of the "sale" or "sharing" of their personal information for behavioral advertising purposes. They also have the right to limit the use and disclosure of sensitive personal information. Nama does not sell your personal information. |
How and when we will respond to your request
After verifying your identity, we will respond to your request without undue delay and within the timeframes stipulated by applicable legislation (usually 15 to 45 days, depending on your location and the complexity of the request). If we need more time, we will inform you of the reason and the extended deadline.
We do not charge fees for processing your request, unless it is considered manifestly unfounded or excessive, as permitted by law.
If you are not satisfied with our response, you have the right to contact the competent data protection authority in your jurisdiction.
Data-protection questions?
Our Data Protection Officer and security team can walk you through a DPA, subprocessor list or a data-residency setup.
SSO · RBAC · audit trail · LGPD-ready