Data Processing Agreement
Last updated 10 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement governing the use of RenewBud between the customer or organisation that owns or controls the relevant RenewBud workspace ("Controller") and MM Sistemas e Informática, CNPJ 42.188.885/0001-44, Avenida Delfim Moreira, 840, Loja 02, Várzea, Teresópolis - RJ, CEP 25953-236, Brazil ("Processor", "RenewBud", "we", "us" or "our").
This DPA applies where RenewBud processes personal data on behalf of the Controller in connection with the RenewBud service.
1. Roles of the Parties
The Controller determines the purposes and means of processing personal data entered into its RenewBud workspace. RenewBud processes that personal data on behalf of the Controller and in accordance with the Controller's documented instructions.
Each party will comply with the data protection laws applicable to it, including, where applicable, the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and Brazil's Lei Geral de Proteção de Dados Pessoais ("LGPD").
2. Subject Matter and Duration
RenewBud processes personal data on behalf of the Controller for the purpose of providing, securing, supporting and maintaining the RenewBud service.
Processing will continue for the duration of the Controller's use of RenewBud and for any limited period afterwards during which data is retained in accordance with this DPA, the RenewBud Privacy Policy or applicable law.
3. Nature and Purpose of Processing
Processing may include collecting, recording, organising, storing, retrieving, displaying, transmitting, updating, backing up and deleting personal data contained within the Controller's RenewBud workspace.
The purpose of the processing is to provide functionality for managing subscriptions, contracts, licences, suppliers, renewal dates, cancellation deadlines, responsible persons, reminders, recurring costs and related business information.
4. Categories of Data Subjects
Personal data processed through RenewBud may relate to:
- the Controller's employees;
- team members and workspace users;
- contract owners;
- supplier and vendor contacts;
- contractors;
- professional advisers; and
- other business contacts entered into the Service by the Controller.
5. Types of Personal Data
Personal data processed through RenewBud may include:
- names;
- business email addresses;
- job titles;
- departments;
- organisational roles;
- supplier or vendor information;
- responsibility for subscriptions, contracts or renewals;
- workspace activity and audit information; and
- personal data contained in notes, comments or other information submitted by the Controller or its authorised users.
The Controller should not intentionally use RenewBud to process special category personal data, criminal offence data or other highly sensitive personal data unless such processing has been expressly agreed with RenewBud and is lawful.
6. Controller Responsibilities
The Controller is responsible for ensuring that:
- personal data submitted to RenewBud has been collected and is processed lawfully;
- appropriate privacy information has been provided to data subjects where required;
- it has an appropriate lawful basis for the processing;
- its instructions to RenewBud comply with applicable data protection law;
- only personal data reasonably necessary for its use of RenewBud is entered into the Service; and
- access to its RenewBud workspace is provided only to authorised users.
7. Documented Instructions
RenewBud will process personal data only on documented instructions from the Controller, including as necessary to provide the Service under the applicable agreement.
The Controller's configuration and use of RenewBud, actions performed through the Service and instructions submitted to RenewBud support may constitute documented instructions.
If RenewBud is required by applicable law to process personal data other than on the Controller's instructions, RenewBud will inform the Controller before carrying out that processing unless applicable law prohibits such notification.
If RenewBud reasonably believes that an instruction infringes applicable data protection law, RenewBud will inform the Controller without undue delay and may suspend the affected processing until the matter is resolved.
8. Confidentiality
RenewBud will ensure that persons authorised to process personal data on its behalf are subject to appropriate confidentiality obligations.
Access to personal data will be limited to persons who reasonably require access for the operation, security, maintenance or support of the Service.
9. Security
RenewBud will implement and maintain appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Security measures will be appropriate to the nature of the processing, the information processed, the available technology and the risks presented by the processing.
These measures may include, where applicable to the relevant RenewBud implementation:
- secure authentication mechanisms;
- password hashing;
- encrypted communications using HTTPS/TLS;
- access controls and user permissions;
- audit logging;
- secure hosting and database controls;
- backup and recovery procedures;
- security monitoring;
- software security updates; and
- additional authentication controls where available.
10. Sub-processors
The Controller provides general authorisation for RenewBud to engage sub-processors where reasonably necessary to provide the Service.
RenewBud will require sub-processors that process personal data on its behalf to enter into contractual obligations providing an appropriate level of data protection consistent with RenewBud's obligations under this DPA, to the extent applicable to the services provided by that sub-processor.
RenewBud remains responsible for the performance of its data protection obligations where required by applicable law.
RenewBud will make information about material sub-processors available to customers and, where required, provide reasonable notice of material changes to sub-processors.
Where applicable law gives the Controller a right to object to a new sub-processor, the Controller may raise a reasonable data protection objection within the period specified in the relevant notice.
11. International Data Transfers
Personal data processed through RenewBud may be transferred to or processed in countries outside the country in which the Controller or data subject is located.
Where an international transfer requires safeguards under applicable data protection law, RenewBud will use an appropriate lawful transfer mechanism.
Where the UK GDPR applies, such mechanisms may include applicable adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved Standard Contractual Clauses or another legally recognised transfer mechanism.
Where the LGPD applies, international transfers will be handled in accordance with the LGPD and applicable regulations issued by the Autoridade Nacional de Proteção de Dados (ANPD).
12. Data Subject Requests
Taking into account the nature of the processing, RenewBud will provide reasonable assistance to the Controller, through appropriate technical and organisational measures where possible, to enable the Controller to respond to requests from data subjects exercising rights under applicable data protection law.
If RenewBud receives a request directly from a data subject concerning personal data for which the Controller is responsible, RenewBud may direct the data subject to the Controller unless RenewBud is legally required to respond directly.
13. Assistance With Compliance
Taking into account the nature of the processing and the information available to RenewBud, RenewBud will provide reasonable assistance to the Controller with its applicable obligations relating to:
- security of processing;
- personal data breaches;
- data protection impact assessments;
- consultation with supervisory authorities where required; and
- data subject rights.
14. Personal Data Breaches
RenewBud will notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed by RenewBud on the Controller's behalf.
Where information is reasonably available, RenewBud will provide information necessary to assist the Controller in assessing and complying with its breach notification obligations.
RenewBud may provide information in phases where complete information is not immediately available.
Notification of a personal data breach does not constitute an admission of fault or liability by RenewBud.
15. Deletion or Return of Personal Data
Following termination of the Controller's RenewBud account or the end of the relevant processing services, RenewBud will, at the Controller's choice where reasonably and technically available, delete or return personal data processed on the Controller's behalf, unless applicable law requires retention.
Personal data may remain temporarily within backups or disaster recovery systems until deleted through normal backup rotation, provided that such data remains protected and is not used for other purposes.
The Controller is responsible for exporting any Customer Data it wishes to retain before its account or workspace is permanently deleted.
16. Audit and Compliance Information
RenewBud will make available information reasonably necessary to demonstrate compliance with its processor obligations under applicable data protection law and this DPA.
Where reasonably necessary and where other available compliance information is insufficient, RenewBud will permit an appropriate audit or inspection relating to processing carried out on behalf of the Controller, subject to reasonable notice, confidentiality requirements, security restrictions and measures designed to avoid unreasonable disruption to RenewBud or other customers.
The parties will seek to use existing security documentation, certifications, reports or written responses before requiring an on-site audit where those materials reasonably demonstrate compliance.
17. Records and Regulatory Cooperation
RenewBud will maintain records relating to processing activities where required by applicable law.
RenewBud will cooperate with competent data protection authorities to the extent required by applicable law in relation to personal data processed under this DPA.
18. Liability
Liability arising under this DPA is subject to the applicable liability provisions contained in the RenewBud Terms and Conditions, except to the extent that such limitation is prohibited by applicable law.
19. Order of Precedence
If there is a conflict between this DPA and the RenewBud Terms and Conditions concerning the processing of personal data on behalf of the Controller, this DPA will take precedence in relation to that processing.
20. Termination
This DPA will remain in effect for as long as RenewBud processes personal data on behalf of the Controller.
Obligations that by their nature must continue after termination, including confidentiality, data protection, deletion and applicable audit obligations, will continue for as long as RenewBud retains the relevant personal data.
21. Contact
Questions regarding this DPA or requests concerning data processing may be sent to:
MM Sistemas e Informática
CNPJ: 42.188.885/0001-44
Avenida Delfim Moreira, 840, Loja 02
Várzea, Teresópolis - RJ
CEP 25953-236
Brazil
Website: renewbud.com
Privacy contact: renewal@renewbud.com
Business customers requiring an executed copy of this DPA may contact RenewBud using the contact details above.