PRIVACY AND DATA PROTECTION POLICY

Last updated: 21 July 2026

We, at DECO PLATAFORMA DIGITAL LTDA. ("deco" or "Platform"), a private legal entity with limited liability headquartered at Rua Visconde de Inhaúma, No. 134, Suite 2001, Centro, Rio de Janeiro, RJ, ZIP Code 20.091-901, registered with the CNPJ/ME under No. 47.563.279/0001-85, are committed to protecting the privacy and security of the information you provide when using the Platform, in accordance with applicable data-protection law.

deco operates as part of a corporate group. Depending on your location and how you contract the Services, the entity responsible for your personal data may be DECO PLATAFORMA DIGITAL LTDA. (Brazil) or deco.cx LLC (Delaware, United States) for customers domiciled outside Brazil. References to "deco," "we," "us," and "our" refer to the applicable entity.

This Policy explains how we handle the personal data you provide when accessing and registering on our Platform. This Policy is an integral part of our Terms and Conditions of Use.

We do not aim to collect, or in any way request, personal data from individuals under the age of 18, as the Platform is intended for use by adults. If we become aware that we have collected personal data from an individual under 18, we will delete it.

If we make significant changes to this Policy, we will notify you. We also recommend that you review this page periodically, as this Policy may be updated to reflect improvements to our Services or changes in law.

If, after reading this Policy, you still have questions, contact us at privacy@decocms.com.

We do not recommend browsing or registering on our Platform if you do not agree with the terms of this Privacy Policy, as in certain cases the processing of your personal data is necessary regardless of your consent.

1. A BRIEF SUMMARY

We recommend reading this Policy in full. However, we highlight some essential points:

  • Two roles. For the personal data of visitors to our website and of the people who register and manage accounts on the hosted Platform, deco acts as controller. For the personal data that a Customer processes through the Managed Service (for example, data about the Customer's own end users or website visitors), the Customer is the controller and deco acts as operator/processor, processing such data only per the Customer's instructions and the contracted purposes.

  • Self-hosting. deco's software is open source. When you run it as a self-hosted deployment — on your own infrastructure, with your own keys and data — deco does not collect or process the data you handle in that instance, unless you separately engage our Managed Service or support.

  • How we collect. We collect your personal data (i) directly from you, when you access our website and register or contact us; and (ii) automatically, when you navigate our website and use the hosted Platform.

  • How we use it. Your personal data is used for the purposes for which it was collected, as described in Section 4, and may be shared with third parties (subprocessors) to provide our Services, comply with legal obligations, or as authorized by law.

  • AI processing. The Platform includes AI features and autonomous Agents. We use third-party AI model providers to deliver these features, on a transient basis. We do not use Customer Content or your personal data to train third-party or public foundation models, and we do not sell your personal data.

  • Google data. When you connect a Google account to the Platform, specific rules on the access, use, sharing, protection, retention, and deletion of your Google user data apply, as described in Section 7.

  • Your rights. To exercise your rights or ask how we handle your personal data, contact us at privacy@decocms.com.

2. DEFINITIONS

For the purposes of this Policy:

deco: DECO PLATAFORMA DIGITAL LTDA., CNPJ/ME No. 47.563.279/0001-85, and, where designated in a specific contract as the contracting party, deco.cx LLC (Delaware).

Authorized User or Customer: the individual or legal entity that adopts deco's software or contracts the Services, and is responsible for managing the Users it designates.

User(s): the registered person(s) who use the Platform under the responsibility of the Authorized User, who may be the same as the Authorized User.

Party / Parties: deco, the Authorized User, and/or the User, individually or collectively.

Registration / Account: the location where the User's information is stored and through which the User accesses the hosted Platform.

Platform: deco's software and services made available to the Authorized User, however branded or packaged from time to time (currently including deco's open-source workspace and control plane, its CMS, and its apps), together with any related modules and the hosted instance available at studio.decocms.com.

Services: the operation and professional services deco provides to the Authorized User (such as auditing, implementation, sustaining and evolution, and optimization of digital experiences), as detailed in the applicable order form or contract.

Agent: an autonomous or semi-autonomous software agent made available through the Platform that performs tasks and may take actions on the Customer's behalf according to the Customer's configuration and instructions.

Self-Hosted Deployment: a deployment in which the Authorized User runs deco's open-source software on its own infrastructure, with its own keys and data. Managed Service: a deployment in which deco hosts and/or operates the software and Services on the Customer's behalf.

Customer Content: the content, data, code, configurations, applications, and other materials that the Authorized User or its Users submit to, create within, or generate through the Platform.

LGPD: Brazilian Federal Law No. 13.709/2018 (General Data Protection Law).

ANPD: the Brazilian National Data Protection Authority, responsible for enforcing the LGPD.

Controller: the party responsible for decisions regarding the processing of personal data, especially its purposes and means.

Operator (Processor): the natural or legal person who processes personal data on behalf of the controller.

Data Subject (Holder): the natural person to whom the processed personal data relates.

Data Protection Officer (DPO / Encarregado): the person designated to act as a communication channel between the controller, data subjects, and the ANPD.

Personal Data: any information related to an identified or identifiable natural person, such as name, tax identification number (e.g., CPF or RNE, where applicable), address, phone, email, IP address, and location.

Sensitive Personal Data: personal data about racial or ethnic origin, religious belief, political opinion, union or organization membership, health or sex life, or genetic or biometric data, when linked to a natural person.

Incident: any accidental or unlawful access, acquisition, use, modification, disclosure, loss, or destruction involving personal data.

Processing: any operation carried out with personal data, such as collection, recording, organization, storage, adaptation, retrieval, use, disclosure, transfer, dissemination, comparison, restriction, deletion, or destruction.

Google User Data: any data or information obtained by deco through Google APIs as a result of the Authorized User or a User connecting a Google account to the Platform, as described in Section 7.

Other terms not defined here have the meaning given in a specific clause, in the LGPD, or in the Terms of Use.

3. HOW WE COLLECT YOUR PERSONAL DATA

We may collect your personal data in the following ways:

Electronic identifiers (cookies and similar technologies). Cookies are files that can be temporarily stored on your device. We use cookies to facilitate your navigation, adapt it to your interests, and understand how our website and Services are used. You can configure your device to refuse cookies; in that case, you may not be able to access all parts of the Platform, as some cookies are essential for its proper functioning. We also use similar tracking technologies (such as web beacons and analytics scripts) to understand which pages and content you access. We rely on our legitimate interest (art. 7, IX, LGPD) in understanding and improving how our website and Services are used to justify this processing. Unlike cookies, web beacons cannot be individually disabled through the Platform, but you may limit their effect through your browser's general privacy settings and extensions.

Registration or contact data. You may provide personal data directly when registering, contracting the Services, or contacting us. In this case, we use the data specifically for the purpose for which it was collected — for example, to respond to a request for information, or to enable your access to and use of the contracted Services.

Where possible, we offer reasonable options regarding the collection and use of your information. For example, you can: (i) decline to provide personal data that is not necessary for the provision of the Services or for compliance with legal or contractual obligations; (ii) set your browser preferences and use tools to block cookies; (iii) opt out of marketing communications; (iv) cancel your subscription; and/or (v) submit a request to exercise your rights at privacy@decocms.com.

We cannot guarantee the adequate operation of the Platform or delivery of the Services if you provide incorrect information or choose not to provide certain personal data.

4. WHAT PERSONAL DATA IS COLLECTED AND FOR WHAT PURPOSE

deco is an AI-service company. It publishes open-source software — currently a private AI workspace and control plane where agents work, a CMS, and apps — and offers a service that operates its Customers' digital experiences (sites, apps, and storefronts) with senior engineers, AI agents, and proprietary software. The software can be self-hosted by the Customer or operated by deco as a Managed Service.

The nature, manner, and purpose of the processing vary according to the context in which the personal data was collected. In general, to view and contract our Services you access and register on our website (https://decocms.com) or on the hosted Platform (https://studio.decocms.com), and we may request personal data such as your name, email, tax identification number (e.g., CPF or RNE, where applicable for billing or legal compliance), phone, and address, for identification, contact, contracting, and billing.

We may also collect usage, device, and log data automatically (such as IP address, browser and device information, and interactions with the hosted Platform) to operate, secure, and improve the Services and to meter usage.

Customer Content processed on behalf of Customers. When a Customer uses the Managed Service, Customer Content may include personal data of the Customer's own end users or website visitors. deco processes that data as operator/processor, only per the Customer's instructions and the contracted purposes, and does not use it for its own independent purposes. In a Self-Hosted Deployment, deco does not process that data.

We may also process your personal data where reasonably necessary or legally required (i) for reasons of public interest; (ii) to respond to requests from public authorities; (iii) to meet reporting or record-keeping requirements; or (iv) for the regular exercise of rights in legal proceedings.

5. LEGAL BASES FOR PROCESSING

We process your personal data based on one or more of the following legal bases set forth in art. 7 of the LGPD, depending on the purpose and context of each processing activity described in this Policy:

  • Execution of a contract or preliminary procedures related to a contract to which you are a party (art. 7, V) — for example, to register you on the Platform and provide the contracted Services.

  • Consent (art. 7, I) — for example, when you connect a Google account to the Platform (as described in Section 7) or when you opt in to receive marketing communications.

  • Compliance with a legal or regulatory obligation (art. 7, II) — for example, to comply with tax, accounting, or record-keeping requirements.

  • Legitimate interest (art. 7, IX) — for example, to use cookies and similar technologies to understand and improve how our website and Services are used, and to prevent fraud and keep our Platform secure, always safeguarding your fundamental rights and freedoms.

  • Regular exercise of rights in judicial, administrative, or arbitration proceedings, and protection of credit, where applicable (art. 7, VI and XI).

6. AI FEATURES AND AUTONOMOUS AGENTS

The Platform includes AI features and Agents that process data to perform tasks on the Customer's behalf (such as diagnostics, content generation, optimization, and monitoring).

  • Models and providers. The Platform can route requests to multiple AI runtimes and model providers (which may include, among others, Anthropic, OpenAI, Google/Gemini, OpenRouter, and Ollama). In a Self-Hosted Deployment, the Customer uses its own keys and provider accounts. In the Managed Service, inputs and relevant context may be transmitted to and processed by these providers on a transient basis solely to provide the Services.

  • No training on your data. We do not use Customer Content or your personal data to train third-party or public foundation models, and we do not sell your personal data.

  • Improvement of our Services. We may use aggregated, de-identified, or anonymized data derived from use of the Platform to operate, secure, and improve the Services.

  • Human oversight. Where the Platform provides human-in-the-loop review or approval controls, the Customer is responsible for configuring and using them; the Customer remains responsible for the actions Agents take under its configuration.

7. GOOGLE USER DATA (GOOGLE API SERVICES)

When you connect a Google account to deco, we access certain Google user data through Google APIs, strictly to provide the features you request. This section applies in addition to the rest of this Policy, and prevails over it in case of conflict regarding Google user data specifically.

Data we access. With your authorization via Google OAuth, and only using the read-only scope `analytics.readonly`, we access your Google Analytics 4 data: the list of Analytics accounts and properties you can access, and the report data you request (metrics and dimensions such as page paths, views, sessions, conversions, and realtime active users). We do not access or modify any other Google data.

How we use it. Solely to perform the actions you request inside deco — listing your properties and running the Analytics reports you ask for — and to display the results to you. Data is processed transiently to answer your request. We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalized AI/ML models.

How we share it. We do not sell Google user data and do not share it with data brokers or advertisers. We share it only with infrastructure sub-processors strictly as needed to operate the feature, under confidentiality obligations, and with Google to make the API requests you authorize.

How we protect it. OAuth tokens are stored encrypted per connection; data is transmitted over TLS and protected by access controls.

Retention and deletion. We do not store the Google Analytics report data itself beyond what is necessary to generate and display the results you requested; such data is processed transiently, within the same session, and is not retained in our databases afterward. We retain OAuth tokens only while your connection is active. You can revoke deco's access at any time from your Google Account permissions (myaccount.google.com/permissions) or by disconnecting the integration in the Platform, which invalidates the stored token. You may request deletion by contacting privacy@decocms.com.

Limited Use. deco's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. WHO WE SHARE YOUR PERSONAL DATA WITH

To provide our Services, we share personal data with third parties (subprocessors) that support our operations and that are contractually bound to protect it. We may disclose your personal data to:

  • Infrastructure, hosting, and content-delivery providers (e.g., Cloudflare; and, for resilience and specific workloads, other cloud providers such as AWS and Google Cloud), to host and serve the hosted Platform;

  • AI model providers (e.g., Anthropic, OpenAI, Google/Gemini, OpenRouter), to deliver AI features on a transient basis, as described in Section 6;

  • Authentication providers (e.g., Google, GitHub), to enable secure login;

  • Payment and financial institutions (e.g., Stripe), to process payments;

  • Operational and business-tool providers (e.g., CRM, analytics, communication, and email tools) that we contract to support our business;

  • A potential buyer or successor in the case of a merger, acquisition, restructuring, reorganization, or sale or transfer of deco's assets;

  • Competent government or judicial authorities, to comply with a court order, law, legal process, or administrative proceeding; and

  • Other parties with your consent, or as otherwise disclosed at the time of collection.

We reserve the right to share personal data where necessary to comply with a legal obligation, to enforce our Terms of Use, or to protect the rights of our team and customers.

When we share personal data with the entities above, we limit the sharing to what is necessary and require them to commit to a level of protection consistent with this Policy, including not using the data for any purpose other than providing services on our behalf or complying with legal requirements. To learn more about how our subprocessors handle personal data, contact us at privacy@decocms.com.

9. INTERNATIONAL DATA TRANSFERS

deco operates globally and uses providers located in Brazil, the United States, and other countries — for example, edge/CDN and cloud infrastructure, AI model providers, and payment providers (including Google LLC and other infrastructure and payment providers). Your personal data, including the Google user data described in Section 7, may therefore be transferred to and processed outside your country of residence, including in the United States. Such transfers are carried out in compliance with the safeguards required by art. 33 of the LGPD — including standard contractual clauses, privacy policies, and certifications adopted by these providers — to ensure a level of personal-data protection compatible with Brazilian law.

10. EXERCISING YOUR RIGHTS

You may contact us to exercise the rights guaranteed by applicable law, such as confirmation of the existence of processing; access to your personal data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data or data processed in non-compliance with the law; portability; information about with whom we share your data; review of decisions taken solely on the basis of automated processing; and withdrawal of consent.

We may be unable to accept a request to change your personal data if, for example, doing so would violate a law or render other information incorrect. If you request deletion, we may retain a copy where required by law or where we have a legal basis to do so.

To exercise your rights, contact us at privacy@decocms.com. You may also file a complaint with the National Data Protection Authority (ANPD). If you are an end user whose data is processed by a Customer through the Platform, please direct your request to that Customer (the controller); we will support the Customer as operator/processor as required.

11. DATA SECURITY

We maintain procedural, technical, and physical safeguards designed to protect personal data against loss, misuse, and unauthorized access, disclosure, alteration, or destruction — including encryption in transit (TLS) and encrypted storage of connection tokens. However, no transmission of data over the internet is completely secure, and we cannot guarantee the absolute security of personal data transmitted to the Platform. We ask for your cooperation in maintaining a secure environment. If you identify or become aware of anything that compromises information security, contact us at privacy@decocms.com.

In the event of a security incident that may create relevant risk or harm to data subjects, we will act in accordance with applicable law, including notifying the competent authority and affected data subjects where required.

12. HOW LONG WE STORE YOUR DATA

Your personal data is stored only for the time necessary to fulfill the purposes for which it was collected, unless a longer period is required or permitted — for example, to comply with legal, regulatory, or contractual obligations, or to safeguard deco's rights. For personal data processed as operator on behalf of a Customer, data is retained for the duration of the Services and returned to or deleted for the Customer when no longer needed, per the applicable contract, subject to legal retention requirements. Google user data is subject to the specific retention and deletion rules described in Section 7, which prevail over this Section in case of conflict.

13. HOW TO CONTACT US

For questions or requests about how we process your personal data, contact us at privacy@decocms.com. For the purposes of the LGPD, our Data Protection Officer (Encarregado) can also be reached through this same email address.

14. APPLICABLE LAW

This Policy is governed by Brazilian law, in particular the LGPD (Federal Law No. 13.709/2018). For personal data controlled by the US Entity, additional or different data-protection laws may apply, as set out in the applicable contract. Any dispute arising from the use or interpretation of the Platform will be resolved in accordance with the governing-law and jurisdiction provisions of the applicable Terms of Use or contract.

Where a specific contract between deco and the Customer contains data-protection terms (e.g., a Data Processing Agreement), those terms prevail over this Policy in case of conflict, with respect to the matters they specifically address.

15. UPDATES

This Privacy Policy is subject to periodic changes to keep it current with our processing activities and with applicable data-protection law. We reserve the right to revise it at any time, whether for the use of new technologies or whenever we deem necessary. The updated Policy will be published on our website, and we recommend checking it periodically.