Lunaum produto da Helsen Ia Tecnologia LTDA

Version 1.4 · In force since 2026-08-02 Publication address: https://lunahia.com.br/en/dpa Portuguese version: https://lunahia.com.br/dpa Principal instrument: Helsen Platform Terms of Use, published at https://lunahia.com.br/en/terms

Language notice. This is a courtesy translation. The original and legally prevailing text is the Portuguese version, kept in section-for-section parity with this one. Should any divergence in meaning arise between the two texts, the Portuguese version prevails.

Document status. This text has been in force since 2026-08-02, the date it was published at this address, and it binds Helsen to what is written here. External legal review by a lawyer has not been carried out as of that date: it is an open, tracked item, and it ceased to be a condition of entry into force on 2026-08-02. Any adjustment the review may require enters as a new dated version in the version history at the end of this document — no change happens without leaving a trace.

Nature of this annex. This document is Annex I to the Terms of Use, forms an integral part of them for all purposes, and is accepted in the same act of registration, without individual negotiation (clause 3.1 of the Terms). It may be updated independently of the principal instrument, as set out in clause 3.3 of the Terms.

The capitalised terms used in this annex — Helsen, Customer, End Business, End User, Meta Platform and Helsen Software — carry the meaning given to them by clause 1 of the Terms of Use. This annex creates no parallel vocabulary: where it needs a concept, it uses the concept already defined.


1. Parties, roles and scope

Identification of the parties. Helsen is HELSEN IA TECNOLOGIA LTDA, a Brazilian limited liability company (sociedade empresária limitada) enrolled with the Brazilian corporate taxpayer registry (CNPJ/MF) under no. 57.589.381/0001-03, with its registered office at Rua Argélia, no. 425, Anexo 01, Petrovale 2ª Seção, Ibirité/MG, ZIP code 32417-087, Brazil, trading under the business name Helsen Ia. The Customer is the legal entity identified in the registration referred to in clause 3 of the Terms of Use, by the data it itself provides in that act. This identification is the same as in clause 1.1 of the Terms of Use, and this annex creates no parallel identification: where it says "Helsen", it means the legal entity above; where it says "the Customer", it means the legal entity that accepted the Terms upon registration.

1.1. Subject matter. This annex governs the processing of personal data that Helsen carries out on behalf of the Customer in providing the Helsen Software, and allocates between the parties the obligations of Brazilian Law No. 13,709/2018 (LGPD).

1.2. The full chain, declared. The processing governed by this annex is one link in a chain of five positions. Declaring the chain in full is what allows each party to know what it owes — and to whom.

LinkWho it isRole in the processing of message content
End UserThe natural person who exchanges messages with a company over WhatsAppData subject
End BusinessThe company that owns the WhatsApp Business Account and decides to speak to the End UserController — decides the purpose and the means of the service interaction
CustomerThe software company that integrates the channel into its own productProcessor for the End Business, and controller of its own commercial relationship with it
HelsenThe messaging infrastructure engaged by the CustomerProcessor, in the capacity of subprocessor. It decides neither the purpose nor the means of the processing of content
MetaThe operator of the WhatsApp Business PlatformProcessor of Company Content, under its own global processor terms

1.3. Helsen decides neither purpose nor means. Helsen does not define why messages are exchanged, with whom, when, or what content is sent. It performs transport, persistence for the declared period and event delivery, under instruction. That is the factual reason supporting the legal qualification in the row above — it is not a label chosen for contractual convenience.

1.4. Where Helsen is a controller, not a processor. For Helsen's own data — Customer registration, API access credentials, access records, subscription and billing data — Helsen is a controller, on the basis of performance of this contract, compliance with legal and regulatory obligations, and the legitimate interest of securing the operation. That data belongs to companies and their representatives, not to the End User of the conversation. Its processing is governed by the privacy policy, not by this annex.

1.5. Negative scope. This annex does not govern the relationship between the End Business and Meta, which is direct, has its own instrument and does not depend on Helsen; nor the relationship between the Customer and the End Business, which is the subject of section 10 below.


2. Documented instructions

2.1. Helsen processes personal data exclusively in accordance with: (a) the Terms of Use; (b) this annex; (c) the published privacy policy; and (d) the Customer's lawful instructions transmitted through the means set out in section 2.3. That set constitutes the controller's documented instructions for the purposes of article 39 of the LGPD.

2.2. Helsen does not process the data for its own purposes, does not sell it, does not disclose it to third parties outside section 6, and does not use it to train, tune or evaluate any artificial intelligence or machine learning model, whether its own or a third party's.

2.3. How an instruction is given. A Customer instruction is expressed through: the configuration the Customer makes in the console or through the public API; the request it issues; and written communication to Helsen's contact channel. Verbal instructions are not binding.

2.4. Duty to warn. If an instruction from the Customer appears to Helsen to infringe the LGPD or another applicable data protection rule, Helsen informs the Customer in writing and may suspend compliance with that specific instruction pending clarification. The warning does not constitute legal advice and does not transfer to Helsen the controller's responsibility for the lawfulness of the purpose.

2.5. Order of a competent authority. Helsen may process data outside the Customer's instructions where required by law or by order of a competent authority. In that case it informs the Customer beforehand, unless the rule or order itself prohibits such notice.


3. Categories of data and of data subjects

3.1. The categories of personal data processed, the data subjects to whom they relate, the purpose of each item and its retention period are declared, item by item, in the privacy policy published at https://lunahia.com.br/en/privacy, sections 2 to 4.

3.2. Why by reference and not by copy. Reproducing the policy's table here would create two independent texts about the same fact, which diverge on the first adjustment made to only one of them. The document describing what is processed is the policy; this annex describes under what title the processing takes place. The policy forms an integral part of this annex by reference.

3.3. In summary, without replacing the reference. The processing covers message content and its media attachments, WhatsApp Business account and phone number identifiers, business-scoped user identifiers, the End User's phone number and profile name, and the delivery metadata of each message. The data subjects are the End Users and the natural persons who represent the Customer and the End Businesses.

3.4. Sensitive data and data of children and adolescents. The Helsen Software is not intended for the processing of sensitive personal data or of data relating to children and adolescents, and offers no specific functionality for them. If the content of a message contains such data, it results from the conversation the controller conducts, and the legal basis and the corresponding safeguards are the controller's responsibility.


4. Duration, deletion and return

4.1. Duration. The processing governed by this annex lasts for as long as the engagement of the Helsen Software lasts and extends, for each item of data, to the end of the retention period applicable to it.

4.2. Periods, by reference. The retention periods are declared in the privacy policy, section 6, and originate in Helsen's technical retention table, which binds each published period to the parameter actually configured in the infrastructure. There is no "policy" period and a separate "system" period. This annex repeats no figure: the figure lives in one place only, and that is where it changes.

4.3. Deletion at the end of the period. Once the period for each class of data expires, deletion is carried out by an automatic routine, independently of any request by the Customer and of any human decision.

4.4. End of the contract. Upon termination, the Customer's access to the Helsen Software is cut off on the termination date. The data then existing follows the retention periods already running and is deleted at the end of each of them, with no further act. Upon request made within 30 (thirty) days of termination, Helsen makes available an export of the data existing at that moment, in a structured and commonly used format. Once that period has elapsed, there is no recovery.

4.5. No archiving service. Helsen provides no archiving and no backup service for messages, and does not offer extended retention as a feature. Retention periods exist out of operational and legal necessity, not as a promise of long-term custody. It is for the Customer and the End Business to extract and preserve, on their own account, whatever they need beyond the declared periods. The same absence is declared by Meta with respect to Company Content — see section 6.4.

4.6. Operational backups. Backups that exist for continuity of operations follow their own expiry cycle and constitute neither archiving nor an extension of the retention period of any class of data.


5. Security and confidentiality

5.1. Technical measures. Helsen adopts, as a minimum: encryption of data in transit over a secure channel; encryption of data at rest, including of the Meta Platform access credentials, which are stored encrypted under a key managed in a dedicated service; logical isolation between Customers enforced in the database itself; access control by individual identity, with least privilege and a second factor; cryptographic signing of the events delivered to the Customer; and API access logging, retained for the period declared in the policy.

5.2. Organisational measures. Access to personal data restricted to those with a demonstrated functional need; periodic review of authorisations; and an incident response process with a designated owner.

5.3. Confidentiality of personnel. Every person who, in Helsen's service, has access to personal data processed on behalf of the Customer is bound by a written confidentiality obligation that survives the end of the engagement.

5.4. Level of detail. This annex describes the measures in general terms and by category, deliberately. Publishing topology, versions, internal addresses or configuration parameters would turn a document of assurance into a map for an attacker. Detail is made available in the form and within the limits of section 9.


6. Subprocessors

6.1. General authorisation. The Customer authorises Helsen to engage subprocessors for the provision of the Helsen Software, subject to the conditions of this section.

6.2. Flow-down obligation. Helsen maintains with each subprocessor a written instrument imposing obligations no less protective than those of this annex, and remains fully liable to the Customer for the acts of its subprocessors.

6.3. Current nominal list.

SubprocessorPurposeWhere the data sits
Amazon Web ServicesApplication compute, managed database, ingestion and event delivery queues, and management of encryption keysUnited States, as set out in section 7
CloudflareStorage and delivery of the media files exchanged in messagesOutside Brazil, as set out in section 7
VercelHosting and delivery of the web console interfaceOutside Brazil, as set out in section 7

The table declares who, for what and in which country — which is what the controller needs in order to comply with articles 33 and 39 of the LGPD. It declares no internal region, address, account identifier, resource name or credential of any provider: that would add nothing for the controller and would add attack surface for anyone looking for one.

6.4. Meta's position is different, and does not fit in the table above. Meta is not a subprocessor engaged by Helsen. It is the processor of Company Content in the direct relationship between the End Business and Meta itself, under the Meta Global Processor Terms, by force of what the WhatsApp Business Platform Cloud API Terms establish — verbatim, in the text captured and hash-verified by Helsen: "To the extent that Meta acts as a Processor of Company Personal Data, the parties shall comply with the Meta Global Processor Terms." The same terms declare that, once use of the Cloud API ceases, Meta deletes any remaining Company Content within 90 days, and that "Meta does not provide an archiving service or any backup functionality". Helsen does not control those periods and makes no statement about them beyond what Meta's own text asserts.

6.5. Prior notice and right to object. The addition of a new subprocessor or the replacement of an existing one is communicated to the Customer with at least 30 (thirty) days' notice, at the contact address on record and on this page. The Customer may object on reasoned grounds, in writing, within the notice period. Absent a solution accommodating the objection, the Customer may terminate the contract without penalty up to the effective date of the change.

6.6. An emergency replacement, prompted by severe unavailability or by a security incident at the subprocessor, may take effect immediately, with communication on the same date and the right to object preserved after the fact.


7. International transfers

7.1. The fact. The message data processed by Helsen — including message content stored in the database — is processed outside Brazil, at the subprocessors named in section 6.3 and in the countries declared there. Application compute, the managed database, the queues and the management of encryption keys run on Amazon Web Services infrastructure located in the United States. In this version there is no processing of message content on infrastructure located in Brazilian territory.

7.2. The transfer instrument: what exists today, and what does not.

This item was rewritten on 2026-08-02, and the previous version is recorded in the version history at the end. It stated that the transfers relied on articles 33, IX, and 39 of the LGPD. That statement was incorrect: item IX of article 33 is the ground of specific and highlighted consent of the data subject — which Helsen does not have and could not obtain, since it does not communicate with the data subject — and article 39 concerns the processor's duty to follow instructions and is not a ground for international transfer at all. The invocation has been withdrawn, and no other provision has been put in its place. Choosing the adequate ground is an act that requires a qualified lawyer, and the external legal review remains open and tracked. Replacing a wrong ground with another one chosen without legal advice would swap a known defect for an unknown one.

What this annex states in this item is therefore fact, not legal ground:

(a) What exists. Helsen maintains with each subprocessor named in section 6.3 the data processing agreement offered by that subprocessor, with data protection obligations, security commitments and use restricted to the provision of the contracted service.

(b) What those agreements are. The data protection instruments of Amazon Web Services, Cloudflare and Vercel rely on the European Union Standard Contractual Clauses. Those are not the Brazilian Standard Contractual Clauses, whose content the Brazilian National Data Protection Authority set out in Resolution CD/ANPD no. 19 of 23 August 2024, in an annex whose adoption is mandatory and unalterable in its essential parts. A European clause does not satisfy the Brazilian requirement by equivalence.

(c) What Helsen does not claim. Helsen does not claim that the instruments described in (a) satisfy Resolution CD/ANPD no. 19/2024, and does not claim to hold, as of this version, an adequate international transfer instrument under the LGPD. The adequate instrument is being determined, and that determination depends on the external legal review above. Helsen would rather declare the gap than declare a ground it does not have.

(d) The state of facts as of this version. There is no contracted Customer, no connected End Business and no production message traffic: no third-party data subject's message content was being transferred when this text was written. This does not cure item (b) or item (c), and it is recorded here because it is the difference between prospective exposure and processing under way without an instrument — and because omitting it would hide from the Customer the very fact it needs in order to assess its own risk.

(e) What changes once the instrument is defined. The definition enters as a new dated version of this annex, communicated as set out in clause 11.3, and no change happens without leaving a trace in the version history at the end.

7.3. Helsen keeps the list in section 6.3 current as a snapshot of what is in force. A change in the geography of processing follows the notice and objection procedure of section 6.5.

7.4. Out of scope. The traffic of messages across the Meta Platform itself and the location of the repositories hosted by Meta — among them the contact repository described in section 4 of the privacy policy — are not controlled by Helsen, arise from the direct relationship between the End Business and Meta, and are not the subject of this annex.


8. Assistance to the controller

8.1. Data subject requests. Helsen provides the Customer with the technical assistance necessary to satisfy the rights set out in article 18 of the LGPD, to the extent that the data is under Helsen's control and the request cannot be satisfied by the Customer itself using the functions of the Helsen Software.

8.2. Forwarding. A data subject request received directly by Helsen concerning processing carried out on behalf of the Customer is forwarded to the Customer — Helsen does not decide on it, because it is not the controller of that processing. The public procedure is at https://lunahia.com.br/en/data-deletion.

8.3. Response times. Helsen responds to a Customer request for assistance within 10 (ten) calendar days of receipt, a period sized to fit within the 15 (fifteen) days that article 19, II, of the LGPD allows the controller.

8.4. Security incident. Upon becoming aware of a security incident that may entail relevant risk or harm to data subjects, Helsen notifies the Customer within 48 (forty-eight) hours of becoming aware of the incident, not of concluding its investigation. The incident notice describes the nature of the event, the categories and estimated volume of data and data subjects affected, the technical measures already taken and those recommended, and is updated as the investigation progresses. The initial notice is not conditioned on the investigation being complete: notifying late is how a notification arrives after the harm.

8.5. Notification to the authority and to data subjects. Notification to the Brazilian National Data Protection Authority and to data subjects is the controller's decision and obligation. Helsen supplies the technical information available to it to inform that notification.

8.6. Impact assessment. Helsen supplies the technical information available to it for the preparation of a personal data protection impact report, where the Customer or the authority requires one.


9. Audit

9.1. Ordinary form. Helsen responds to a request for evidence of compliance by means of a security questionnaire answered in writing and the provision of such documentation as it holds, within 30 (thirty) days of receipt.

9.2. Frequency. One audit per year, unless a relevant security incident or an order of a competent authority justifies another outside the cycle.

9.3. On-site or third-party audit. Permitted where the route in item 9.1 proves insufficient for the stated purpose, on 30 (thirty) days' notice, during business hours, without interrupting operations, and with the auditor bound by a confidentiality obligation equivalent to that of section 5.3. The auditor may not be a competitor of Helsen.

9.4. Limits. The audit does not extend to: data of other Customers; Helsen's trade secrets; credentials, keys and configuration parameters whose exposure would create fresh risk; or direct access to the production environment. An audit that required opening those surfaces would increase the very risk it exists to measure.

9.5. Costs. Costs are borne by the requesting Customer, unless the audit establishes a relevant breach of this annex by Helsen.


10. The Customer's obligation at the end of the chain

10.1. The obligation. The Customer undertakes to maintain, with each End Business whose data travels through the Helsen Software, an equivalent instrument to this annex, qualifying it as processor for that controller and authorising the subcontracting of Helsen as subprocessor.

10.2. Why this is a clause and not a recommendation. Without that equivalent instrument at the end of the chain, the chain breaks at its most important link: Helsen comes to process the message content of a data subject who is not its own, on behalf of someone who has not demonstrated title to authorise it. In that scenario Helsen can no longer qualify as a processor and begins to look like a controller without a legal basis of its own — which is precisely the exposure this annex exists to avoid.

10.3. Breach. The absence of the equivalent instrument is a breach of this annex and of the Terms of Use, and authorises suspension of access under clause 11.1 of the Terms.

10.4. Customer representation and liability. The Customer represents that it holds valid title to authorise the processing it instructs, that the End Businesses have obtained the necessary rights from the data subjects, and that the information provided to data subjects covers the chain described in section 1.2. The Customer is liable to Helsen for damages arising from the falsity of that representation.

10.5. Evidence. Helsen may request from the Customer, once a year or upon concrete indication of breach, a written statement that the equivalent instruments are in force. Helsen does not request copies of the Customer's contracts with its own clients.


11. Term, updates and prevailing text

11.1. Term. This annex takes effect upon acceptance of the Terms of Use at registration and lasts for the duration of the engagement, with those obligations that by their nature survive it — confidentiality, deletion and assistance regarding facts occurring during the term — continuing after termination.

11.2. Single acceptance. Acceptance is single, made at registration, by affirmative act of the Customer, covers this annex in full and is not subject to individual negotiation (clause 3.1 of the Terms).

11.3. Independent updates. This annex may be updated independently of the Terms of Use. Any change is communicated with at least 30 (thirty) days' notice before its effective date, at the contact address on record and on this page. A change that lowers the level of protection entitles the Customer to terminate without penalty up to the effective date. Correction of a material error, drafting adjustments with no effect on obligations, and adaptation to a requirement of a competent authority may take effect immediately, with communication on the same date.

11.4. Conflict between documents. In the event of conflict between this annex and the Terms of Use on matters of personal data protection, this annex prevails. On all other matters, the Terms of Use prevail.

11.5. Language. The Portuguese text is the original and legally prevailing version. Any translation, including this English version published at https://lunahia.com.br/en/dpa, is for information only. In the event of divergence in meaning, the Portuguese version prevails.

11.6. Law and forum. Brazilian law and the forum elected in clause 13 of the Terms of Use apply to this annex.


Provenance of quotations

Every contractual quotation in this document comes from Meta's own contractual text, captured and hash-verified by Helsen, and not from memory.

Section of this annexSource
6.4 — Meta as processor of Company ContentWhatsApp Business Platform Cloud API Terms, §4.5 and Exhibit A (Data Processing Terms)
6.4 — deletion within 90 days and absence of archivingWhatsApp Business Platform Cloud API Terms, §4.5
1.2 — chain of rolesHelsen's privacy policy, section 5, published at https://lunahia.com.br/en/privacy
4.2 — periods by referenceHelsen's technical retention table and section 6 of the privacy policy
7.2 (b) — the AWS, Cloudflare and Vercel agreements rest on the European clausesData protection agreements offered by the subprocessors themselves. These three texts have not yet been captured with a hash by Helsen, and their capture is recorded as a pending item of the contract monitoring cycle. Until captured, the statement does not carry the same degree of authority as the clauses quoted verbatim above
7.2 (b) — mandatory content of the Brazilian Standard Contractual ClausesResolution CD/ANPD No. 19 of 23 August 2024. Not yet captured with a hash, for the same reason and with the same pending item

Version history

VersionDateWhat changedStatus
1.02026-07-29Initial drafting of Annex I, with the chain of roles declared, subprocessors named, periods by reference and the Customer's obligation at the end of the chainSuperseded
1.12026-08-02Identification of the legal entity at the start of section 1, in parity with clause 1.1 of the Terms of Use and without creating a parallel identification. The numbering of existing clauses did not changeSuperseded
1.22026-08-02Publication at this address and rewrite of the document status note: the text is now in force as of the publication date, and external legal review is now recorded as an open, tracked item rather than a condition of entry into force. No clause was changed in this version — the change is one of status and publication, not of contentSuperseded
1.32026-08-02Section 7 — international transfers. Item 7.2 read, verbatim: "The transfers rely on articles 33, IX, and 39 of the LGPD — performance of a contract to which the indirect data subject is a party through the controller — and on contractual data protection clauses entered into with each subprocessor, with obligations equivalent to those of this annex." The statement was wrong on two counts: article 33, IX is the ground of specific and highlighted consent of the data subject, not performance of a contract (which is VI, and requires the data subject to be a party); and article 39 is not a ground for international transfer. The invocation was withdrawn, and no other provision was put in its place — choosing the ground is an act for a qualified lawyer, and the external review remains pending. In its place came a statement of fact: where the data is processed, what instrument Helsen has today, that this instrument rests on the European clauses and not on the Brazilian Standard Contractual Clauses of Resolution CD/ANPD No. 19/2024, and that the adequate instrument is being determined. Item 7.1 now names the AWS location. The provenance table gained two rows marking what has not yet been captured with a hash. No other clause of this annex was changed, and no role qualification was touchedSuperseded
1.42026-08-02Separation between the published text and the internal drafting support. The working version control and the method notes leave the page and remain in the source; the provenance table now identifies each origin by the name of the third-party contract, not by the file in which Helsen stores it. References to the Terms of Use, the privacy policy, the data deletion page and the Portuguese version are now made by public clickable address. No clause, obligation, period, role or subprocessor was changed in this version — the five-link chain of section 1.2, the named list of section 6.3 and all of item 7.2 remain identicalIn force

Helsen's legal documents are published in Portuguese and in English. The Portuguese version is the legally prevailing one; the English version is a courtesy translation.