Ecomilhas Data Processing Agreement (DPA)

Version 1.0 — effective 4 July 2026.
This Data Processing Agreement ("DPA") supplements the main agreement ("Agreement") between ECOMILHAS TECNOLOGIA LTDA (CNPJ 46.740.714/0001-37 — "ECOMILHAS") and the corporate client ("Client") that subscribes to the ESG goal-based variable-compensation program and other corporate services (the "Services"). It applies whenever ECOMILHAS processes personal data on behalf of the Client, in accordance with the LGPD, GDPR, UK GDPR, APPI, CCPA/CPRA and other applicable data protection laws.
In case of conflict on data protection, this DPA prevails over the Agreement.
1. Roles of the parties
For Client employee data processed within the Services, the Client is the Controller and ECOMILHAS acts as Processor, following the Client's documented instructions. Where ECOMILHAS determines its own purposes and means (e.g., fraud prevention, legal compliance, generating carbon credits from trips), it acts as an independent Controller under the Privacy Policy.
2. Subject matter, nature and purpose
- Subject matter: processing of personal data necessary to provide the Services.
- Nature: collection, recording, organisation, storage, use, sharing with sub-processors, deletion.
- Purpose: enabling ESG benefits, validating trips, calculating rewards and producing decarbonisation reports.
- Duration: the term of the Agreement, plus statutory retention periods.
3. Categories of data subjects and data (Annex I)
- Data subjects: employees and representatives designated by the Client.
- Data: identification (name, corporate email, internal ID), employment link, trip and mobility data, geolocation, ecomilhas and rewards. Not intended for sensitive data; the Client must not submit it.
4. ECOMILHAS obligations (Processor)
ECOMILHAS will: (a) process data only on the Client's documented instructions and the law; (b) ensure confidentiality of authorised persons; (c) implement the security measures in Annex II; (d) assist the Client, as far as possible, with data-subject requests, impact assessments and consultations with authorities; (e) notify the Client of security incidents without undue delay after becoming aware; (f) on termination, delete or return the data, save mandatory retention; (g) make available information to demonstrate compliance and allow audits under Section 8.
5. Client obligations (Controller)
The Client warrants that it has a legal basis for the processing and for providing the data to ECOMILHAS, that its instructions are lawful, that it has informed its employees as required by law, and that it has obtained any required consents (including for background geolocation, where applicable).
6. Sub-processors
The Client authorises ECOMILHAS to engage sub-processors (e.g., cloud providers, payment/Mastercard processors, PIX, analytics and communications) under contracts with protection obligations equivalent to this DPA. ECOMILHAS keeps a list of sub-processors available on request and will inform of material changes with reasonable notice, allowing the Client to raise a reasoned objection.
7. International transfers
International transfers will occur only with an adequate safeguard: adequacy, EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA) or another basis authorised by the ANPD/competent authorities. The applicable SCCs/IDTA are deemed incorporated into this DPA where required.
8. Audit
With reasonable prior notice, at most once a year (except on authority order or after an incident), the Client may audit ECOMILHAS' compliance, preferably via reports, certifications or questionnaires, preserving confidentiality and operational continuity.
9. Security incidents
ECOMILHAS will assist the Client in notifying authorities and data subjects where required. For GDPR/UK GDPR processing, assistance takes into account the 72-hour notification deadline to the competent authority.
10. Liability
Each party's liability follows the limits of the Agreement. To the maximum extent permitted by law, liability for indirect damages and lost profits is excluded. The parties will cooperate to allocate liability in proportion to fault.
11. Term and termination
This DPA lasts as long as processing on the Client's behalf continues. On termination of the Agreement, ECOMILHAS will delete or return the data within 60 days, save mandatory retention.
Annex II — Technical and organisational security measures
Encryption in transit (TLS) and at rest; least-privilege access control and strong authentication; environment segregation; logging and monitoring; backups and continuity planning; vulnerability management and testing; vendor assessment and contracts; staff training and confidentiality; incident response procedures; pseudonymisation/minimisation where applicable.
This document is a template and must be legally validated and signed by the parties before taking effect.
Related documents: Privacy Policy · General Terms of Use · Cookie Policy.
Want this at your company?
Decarbonization with auditable primary data and engagement employees actually enjoy.
Book a demo →