legal

Privacy Policy

Version:

3.0

LAST UPDATE:

This Privacy Policy reflects volis.ai's commitment to protecting the privacy and personal data of its users, clients, partners, candidates and visitors. It sets out, in clear terms, the rules for the collection, use, storage, sharing and protection of personal data, in accordance with the Brazilian General Data Protection Law (Law no. 13.709/2018 – LGPD) and the European Union General Data Protection Regulation (Regulation (EU) 2016/679 – GDPR).

1. Who we are

volis.ai operates through the following companies:

  • Volis Tecnologia Ltda., registered in Brazil under CNPJ 55.781.617/0001-83, with registered office at Rua Itapaiúna, 1800, apt. 251, Jardim Morumbi, 05705-901 São Paulo/SP, Brazil;

  • VOLIS AI TECNOLOGIA LDA, registered in Portugal under NIPC 518311244, with registered office at Rua das Sobreiras, 396, Lordelo do Ouro e Massarelos, 4150-713 Porto, Portugal.

For any matter concerning personal data protection, including the exercise of rights, please contact dpo@volis.ai.

2. When this Policy applies - and when it does not

2.1. This Policy applies to personal data processed by volis.ai as Controller: data of website visitors, business contacts, client and partner representatives, job candidates and administrative platform users.

2.2. Where volis.ai provides data and artificial intelligence services to corporate clients, it acts as Processor (LGPD: “Operadora”): it processes operational data exclusively on behalf of, under the documented instructions of and in the name of the client, who is the controller of that data. Such processing is governed by the services agreement and the Data Processing Agreement (DPA) executed with each client, not by this Policy. Data subjects whose data is processed in that context should contact, in the first instance, the responsible client company.

3. Data we collect

3.1. Data you provide directly

  • First and last name, email and message - when you fill in contact forms on the website; First and last name, email, phone number, job title and company - when you attend events or engage our services;

  • CV, professional and academic background and references - when you apply for a position;

  • Access credentials and configurations - when you use the platform as an authorised user of a client.

3.2. Data collected automatically

  • On the website (volis.ai): we use aggregated, cookieless visit statistics (see Section 4). Forms submitted through the website are processed by our hosting provider (Framer);

  • On the platform (authenticated users): IP address, access dates and times, session identifier, browser and device information, and usage logs - collected for authentication, information security, fraud prevention and auditing.

4. Cookies and measurement technologies

4.1. The volis.ai website does not use advertising, tracking or profiling cookies. For audience statistics we use Framer Analytics, a cookieless measurement tool: the IP address and browser information are processed only transiently and irreversibly (hashed with a daily-rotating key), and no persistent identifiers are stored on your device.

4.2. On the platform, strictly necessary cookies may be used for authentication and session security; these are essential to the service and do not require consent.

5. Purposes and legal bases

Purpose

Data

Legal basis (LGPD / GDPR)

Responding to business enquiries and proposals

Identification and professional contact details

Pre-contractual steps (Art. 7(V) LGPD; Art. 6(1)(b) GDPR)

Performing contracts with clients and partners

Identification, contact, billing data

Performance of contract (Art. 7(V) LGPD; Art. 6(1)(b) GDPR)

Authenticating users and securing the platform

Credentials, IP, access logs

Performance of contract and legitimate interest (information security)

Recruitment and selection

CV and application data

Pre-contractual steps; consent for extended retention

Institutional and marketing communications

Name and business email

Consent (opt-in), revocable at any time; legitimate interest for existing clients, with opt-out

Compliance with legal, tax and regulatory obligations

Contractual and billing data

Legal obligation (Art. 7(II) LGPD; Art. 6(1)(c) GDPR)

6. Data entered into the platform and artificial intelligence

6.1. Content, prompts and operational data entered into the platform by clients and their authorised users are processed exclusively to: (a) generate the requested outputs and perform the contracted features; (b) maintain the security and integrity of the system; and (c) monitor for misuse or abuse.

6.2. No-training commitment: client data is never used to train or improve third-party or general-purpose artificial intelligence models, nor is it cross-referenced or combined with other clients' data, under any circumstances. volis.ai does not sell, rent or trade personal data.

6.3. The client is responsible for ensuring that it has the legal basis and authorisations required to enter third-party personal data into the platform.

7. Data sharing and suppliers

7.1. Data may be shared only with:

  • Infrastructure and service providers acting as processors under data processing agreements (DPAs), including: Google Cloud Platform and Google Workspace (infrastructure and productivity), Cloudflare (network security and Zero Trust), Palantir Technologies (data and AI platform) and Framer (website hosting and forms);

  • volis.ai group entities (Brazil and Portugal), for internal administrative and operational purposes;

  • Judicial or administrative authorities, where there is a legal obligation or a valid order.

7.2. All suppliers are bound by contractual confidentiality and data protection clauses and are assessed prior to engagement.

8. International transfers

8.1. Operational data processed on behalf of European clients is hosted and processed on servers located within the European Economic Area (EEA).

8.2. Certain supporting services (such as website hosting and productivity tools) may involve international transfers, including to the United States and between Brazil and the European Union. In such cases, volis.ai adopts the safeguards provided for in the LGPD and the GDPR, including standard contractual clauses (SCCs), adequacy decisions/assessments and supplementary technical measures.

9. Data retention

  • Business contacts and contractual data: up to 5 years after the end of the contractual relationship (statutory limitation and tax periods);

  • Application data: up to 1 year after the end of the recruitment process, unless consent is given for longer retention or immediate deletion is requested;

  • Access logs and security telemetry: 6 months (minimum under Brazil's Marco Civil da Internet) to 12 months;

  • Clients' operational data: for the term of the contract, with return or deletion within 90 days after termination, unless a legal retention obligation applies.

Once processing is no longer necessary, data is securely deleted or anonymised.

10. Your rights

10.1. You may, at any time: confirm the existence of processing; request access to, rectification, anonymisation, blocking, erasure or portability of your data; obtain information about sharing; object to processing based on legitimate interest; and withdraw consent.

10.2. Requests should be sent to dpo@volis.ai and will be answered within the applicable statutory deadlines.

10.3. You also have the right to lodge a complaint with the competent authority: the Brazilian National Data Protection Authority (ANPD) or the Portuguese data protection authority (CNPD).

11. Minors

volis.ai's services are strictly business-to-business (B2B) and are not directed at individuals under the age of 16. We do not knowingly process minors' personal data; if accidental processing is identified, the data will be deleted immediately.

12. Information security

volis.ai adopts appropriate technical and organisational measures to protect personal data, including: a Zero Trust architecture with identity verification on every access, encryption in transit and at rest, role-based access control with least privilege and multi-factor authentication, continuous monitoring, audit trails and a documented incident response procedure. Internal access is restricted to authorised staff bound by confidentiality obligations. volis.ai never requests passwords by email and never sends executable files.

13. Updates to this Policy

This Policy may be updated to reflect legal, technological or operational changes. The current version, with its date, will always be available on this page. Material changes will be communicated through official channels.

14. Governing law and jurisdiction

  • Relationships with Volis Tecnologia Ltda.: Brazilian law; courts of the Judicial District of São Paulo/SP, Brazil;

  • Relationships with VOLIS AI TECNOLOGIA LDA: Portuguese law; courts of the Judicial District of Porto, Portugal.