Data protection

Privacy through responsibility, context, and control.

CometAI applies Brazilian Law No. 13,709/2018 according to its role in each operation and uses controls designed to limit access, retention, and exposure of personal data.

Version July 19, 2026Brazilian LGPD

Processing roles

The customer generally determines the purposes and means of interactions with its contacts and acts as controller. CometAI acts as processor/operator in those flows. For account, security, billing, and its own legal duties, CometAI may act as an independent controller.

Purpose and minimization

We process data needed for authentication, service delivery, integrations, support, fraud prevention, audits, and legal compliance. Customers must avoid unnecessary sensitive data and configure retention and consent for their purposes.

Data subject rights

Requests for confirmation, access, correction, portability, information, objection, consent withdrawal, or deletion are routed to the responsible party after secure identity verification and subject to lawful retention requirements.

Security and incidents

We use access controls, applicable encryption, hashing, tenant segregation, audits, and session management. Relevant incidents are assessed and reported to the controller; notices to ANPD and data subjects follow applicable responsibilities and deadlines.

AI and human review

Automated responses must be configured and supervised by customers. The platform must not be used for high-impact solely automated decisions without legal basis, transparency, appropriate controls, and a path to human review.

Providers and transfers

Infrastructure, communication, payment, and AI providers may process data to deliver enabled services, subject to applicable contracts and safeguards. The exact providers depend on customer-selected features.

Exercise your rights

Describe your request without including passwords, tokens, QR codes, recovery codes, or MFA codes. Identity confirmation may be required to protect the data subject.