Data protection
Privacy through responsibility, context, and control.
CometAI applies Brazilian Law No. 13,709/2018 according to its role in each operation and uses controls designed to limit access, retention, and exposure of personal data.
Version July 19, 2026Brazilian LGPD
Processing roles
The customer generally determines the purposes and means of interactions with its contacts and acts as controller. CometAI acts as processor/operator in those flows. For account, security, billing, and its own legal duties, CometAI may act as an independent controller.
Purpose and minimization
We process data needed for authentication, service delivery, integrations, support, fraud prevention, audits, and legal compliance. Customers must avoid unnecessary sensitive data and configure retention and consent for their purposes.
Data subject rights
Requests for confirmation, access, correction, portability, information, objection, consent withdrawal, or deletion are routed to the responsible party after secure identity verification and subject to lawful retention requirements.
Security and incidents
We use access controls, applicable encryption, hashing, tenant segregation, audits, and session management. Relevant incidents are assessed and reported to the controller; notices to ANPD and data subjects follow applicable responsibilities and deadlines.
AI and human review
Automated responses must be configured and supervised by customers. The platform must not be used for high-impact solely automated decisions without legal basis, transparency, appropriate controls, and a path to human review.
Providers and transfers
Infrastructure, communication, payment, and AI providers may process data to deliver enabled services, subject to applicable contracts and safeguards. The exact providers depend on customer-selected features.
Exercise your rights
Describe your request without including passwords, tokens, QR codes, recovery codes, or MFA codes. Identity confirmation may be required to protect the data subject.