DATA PROCESSING AGREEMENT (DPA) - Suppliers

Last Update: July 2026

This Data Processing Agreement is entered into by the Hotmart Group entity that is a party to the Contract (hereinafter "Hotmart") and the Provider (hereinafter "Contracted Party"), who will provide services or products to Hotmart.

This Data Processing Agreement (“Agreement”) applies to all Personal Data Processing activities carried out under the Contract entered into between the Parties and forms an integral part of the Contract for all legal purposes. All other provisions not affected by this Agreement shall remain in full force and effect.

DEFINITIONS

  1. 1. Definitions. For the purposes of this instrument, terms beginning with capital letters, regardless of whether they are plural or singular, shall be read and interpreted in accordance with the meaning attributed to them in the Contract or in Brazilian Federal Law No. 13.709/2018 (“Lei Geral de Proteção de Dados Pessoais” or “LGPD”), in Regulation (EU) 2016/679 (“GDPR”), in the California Consumer Privacy Act (“CPRA”), in the Mexican Ley Federal de Protección de Datos Personales en Posesión de Los Particulares and/or in Colombian Law No. 1581 of 2012, collectively referred to as “Applicable Data Protection Laws and Regulations”.
  2. 2. Application. The provisions set forth in Section 1 below apply in all cases, regardless of whether the Contracted Party acts, within the scope of the contractual relationship, as a Controller or as a Processor of Personal Data. The provisions of Section 2 apply exclusively when both Parties act as Independent Controllers. Finally, the provisions of Section 3 apply exclusively when the Contracted Party acts as a Processor of Personal Data.

SECTION 1 – GENERAL CONDITIONS FOR THE PROCESSING OF PERSONAL DATA

  1. 3. Compliance with legislation. The Contracted Party declares, through this Agreement, that it complies with all applicable Data Protection Laws and Regulations, without prejudice to other sectoral or general rules on the subject, as well as regulations and guidelines issued by competent authorities.
  2. 4. Serving the purpose. The Contracted Party undertakes to process any Personal Data eventually transmitted by Hotmart and/or accessed by virtue of the Contract solely for purposes necessary to fulfill its obligations or compatible with the contractual object.
  3. 5. Duties and obligations of the Contracted Party. The Contracted Party’s duties and obligations include:
    1. Contact Hotmart immediately if the Contracted Party has access, in the context of the execution of the Contract, to excessive Personal Data or Data not necessary for the execution of the Contract, and, if so, the Contracted Party must destroy such Personal Data; and
    2. Notify Hotmart immediately in case of any security-related changes, data protection and/or practices that may impact the obligations assumed by signing this Agreement.
  4. 6. Prohibitions. Within the context of the Contract, the Contracted Party is prohibited from:
    1. Copying, transferring, duplicating, or performing any action outside the scope of the contract aimed at creating a new database from the Personal Data transmitted by Hotmart and/or accessed by virtue of the Contract, unless authorized in writing by Hotmart;
    2. Using any type of tool, technology, reverse engineering, or any other method aimed at identifying the Data Subjects, in cases where Hotmart has shared Personal Data in a Pseudonymized manner (so that it is not possible to directly identify the Data Subjects without cross-referencing with other information or accessing an identification key); and
    3. Anonymize Personal Data transmitted by Hotmart within the context of the Contract and use them, in an anonymized form, for purposes other than those stipulated in the Contract and this Agreement.
  5. 7. Sensitive Personal Data. If the Contracted Party processes Sensitive Personal Data in the context of the Contract, the Contracted Party undertakes to process such information only to the extent strictly necessary to fulfill its contractual obligations and to adopt appropriate measures to maintain the integrity, confidentiality, and security of such information.
  6. 8. Lawful Sharing of Databases. If the scope of the Contract involves the assignment, access or sharing of databases containing Personal Data, the Contracted Party represents and warrants that such data was obtained lawfully, in accordance with applicable Data Protection Laws and Regulations.
  7. 9. Duty of confidentiality. The Contracted Party represents and guarantees that it will keep the Personal Data processed under this Contract confidential, ensuring control over who accesses it, who, in turn, must be subject to the duty of confidentiality and duly trained for the Processing of Personal Data.
  8. 10. Access restriction. The Contracted Party guarantees that it will adopt reasonable measures to ensure the reliability of any employee, representative and/or subcontractor who may have access to Personal Data related to the subject matter of the Contract, ensuring that access to such information is limited to those who actually need to access it, as strictly necessary for the purposes established in the Contract.
  9. 11. Security Measures. The Contracted Party declares and warrants that it adopts technical and administrative security measures capable of protecting the Personal Data processed under the Contract from unauthorized access and from unlawful or accidental situations of destruction, loss, alteration, theft, leakage or any other form of inappropriate or unlawful processing, and must comply, minimally, with the following security standards:
    1. Establishing strict control over access to data by defining the responsibilities of individuals who will have access to it, and granting exclusive access privileges to specific responsible parties;
    2. Establishing mechanisms for authenticating access to records, using, for example, two-factor authentication systems to ensure the individualization of the person responsible for processing the records;
    3. The creation of a detailed inventory of accesses regarding connection logs and application access logs, containing the time, duration, identity of the employee or person responsible for the access designated by the Contracted Party, and the file accessed, including when such access is made to comply with legal obligations or determinations by authorities; and
    4. Use of record management solutions using techniques that guarantee the inviolability of the data.
  10. 12. International Data Transfers. If the contract entails the International Transfer of Personal Data between Hotmart and the Contracted Party, the following conditions must be met:
    1. If the Contract is entered into between a Hotmart entity, based in the European Union, and a Contracted Party not established in an European Union Member-State:
      1. In the event that the destination country is covered by an Adequacy Decision issued by the European Commission, this mechanism will be used to enable the international transfer, if applicable. In its absence, The Standard Contractual Clauses (SCC) of the European Union, as set out in the Annex to European Commission Executive Decision 2021/914, shall be used. The Parties acknowledge that such Standard Contractual Clauses incorporate this Agreement for all legal purposes and may be updated in accordance with regulatory updates from competent authorities.
        1. If the Contract is entered between Independent Controllers, the SCC Module 1 must be adopted under the following conditions:
          1. The optional Docking Clause in Article 7 shall not apply.
          2. In Clause 11, the optional language/text does not apply.
          3. In Clause 17, Option 1 will be applied as stipulated in the Contract, or, in its absence or if the stipulation is a jurisdiction outside of the EU, the law of the Netherlands.
          4. In Clause 18(b), any disputes arising from this Agreement shall be resolved in the courts in the following order of preference: (i) as stipulated in the Contract; (ii) in the absence of a stipulation in the Contract, or if the stipulation is a jurisdiction outside of the EU, in the courts of Amsterdam, Netherlands.
          5. Annexes I.A, I.B and I.C of Module 1 of the Standard Contractual Clauses of the European Union is deemed completed with the information from Appendix I.
          6. Annex II to the Standard Contractual Clauses of the European Union is deemed completed in accordance with Appendix III.
        2. If the Contract is entered between Hotmart as a Controller and the Contracted Party as a Processor, Module 2 of the SCC must be adopted under the following conditions:
          1. The optional Docking Clause in Article 7 shall not apply.
          2. Option 2 - General Written Authorization of clause 9a will be applied, with a prior notification period of 15 (fifteen) days for changes to subprocessors.
          3. In Clause 11, the optional language/text does not apply.
          4. In Clause 17, Option 1 will be applied as stipulated in the Contract, or, if the stipulation is a jurisdiction outside of the EU, the law of the Netherlands.
          5. In Clause 18(b), any disputes arising from this Agreement shall be resolved in the courts in the following order of preference: (i) as stipulated in the Contract; (ii) in the absence of a stipulation in the Contract, or if the stipulation is a jurisdiction outside of the EU, in the courts of Amsterdam, Netherlands.
          6. Annexes I.A, I.B and I.C of Module 2 of the Standard Contractual Clauses of the European Union is deemed completed with the information from Appendix II.
          7. Annex II to the Standard Contractual Clauses of the European Union is deemed completed in accordance with Appendix III.
    2. If the Contract is entered into between a Hotmart entity based in Brazil and a Contracted Party based in another country, and the destination country is covered by an Adequacy Decision issued by the Agência Nacional de Proteção de Dados, this mechanism will be used to enable the international transfer, if applicable. In its absence, the Brazilian Standard Contractual Clauses approved through Resolution CD/ANPD No. 19/2024 shall be used. The Parties acknowledge that the Standard Contractual Clauses incorporate this Agreement for all legal purposes and may be updated in accordance with regulatory updates from competent authorities.
      1. The Brazilian Standard Contractual Clause is deemed completed in accordance with Appendix IV.
      2. Appendix III shall be considered as Section III of the Brazilian Standard Contractual Clauses.
  11. 13. International Transfers made by the Contracted Party. The Contracted Party will be solely responsible for ensuring that any International Transfer of Personal Data it may carry out comply with applicable legal requirements, being fully liable for any non-compliance, as well as for its effects and consequences before Hotmart.
  12. 14. Contracted Party's Liability. The Contracted Party shall be solely liable for the Personal Data Processing exclusively applicable to it, whether directly or indirectly, as well as for any direct or indirect damage arising from the unlawful Processing of Personal Data attributable to the Contracted Party, including security incidents, acts that exceed reasonable limits for the execution of the Contract's purpose, or activities that are inconsistent with the instructions provided by Hotmart, as applicable.
  13. 15. Impleadment of Parties. In case Hotmart is sued by any individual or legal entity, including public authorities or private entities, due to the Processing of Personal Data exclusively attributable to the Contracted Party, Hotmart may exercise its right to impleadment of parties, without prejudice to reimbursement of any judicial or extra-judicial expenses incurred by Hotmart, including administrative fines, court and procedural costs, attorney fees, and amounts awarded in court judgments.
  14. 16. Duty of assistance. Subject to any applicable technical and legal limitations, the Contracted Party undertakes to assist Hotmart in carrying out compliance actions that are necessary to comply with Data Protection Laws and Regulations, including, but not limited to, the provision of documents and information.

SECTION 2 – SPECIFIC CONDITIONS APPLICABLE TO THE PROCESSING OF PERSONAL DATA BY PARTIES UNDER A CONTROLLER-CONTROLLER REGIME

  1. 17. Data Subject and Third-Party Requests. Each Party shall be solely responsible for responding to requests from Data Subjects or third parties (including competent authorities) relating to Personal Data under its responsibility within the scope of the Contract. Notwithstanding the foregoing, the Parties undertake to provide mutual assistance, upon request and to the extent necessary, to enable the provision of adequate and timely responses, especially when the request involves Processing activities carried out by both Parties.
  2. 18. Security Incidents. In the event of a Security Incident involving Personal Data (“Incident”) directly related to the scope of the Contract and controlled exclusively by the other Party, the party that becomes aware of the situation shall, within a reasonable timeframe that allows for the timely fulfillment of the obligations established in the Applicable Data Protection Laws and Regulations, notify the other Party. In this event, a written notification must be sent to Hotmart exclusively via email to security@hotmart.com. Said notification must contain, at least, the following information without prejudice to any other information requested by the competent authority in its recommendations and regulations.
    1. Date and time of the incident;
    2. Date and time the Party became aware of the Incident;
    3. Description of the incident, including the root cause, if it can be identified;
    4. List of types of Personal Data affected by the Incident;
    5. List and number of affected Data Subjects, either concretely or potentially, specifying, where applicable, the number of children, adolescents or elderly people affected;
    6. Contact details of the Data Protection Officer (DPO) or another person from whom additional information about the incident can be obtained;
    7. Description of the technical and security measures implemented to protect personal data, adopted before and after the Incident;
    8. Description of the possible consequences of the Incident, identifying the potential impacts on the Data Subjects; and
    9. Indication of measures being taken to repair the damage and prevent future incidents, including, where possible, measures to mitigate and/or redress any potential consequences for Data Subjects.

SECTION 3 – SPECIFIC CONDITIONS APPLICABLE IF THE CONTRACTED PARTY ACTS AS A PROCESSOR

  1. 19. Limitation of Processing. In cases where the Contracted Party acts as a Processor, it undertakes to process the Personal Data listed in the Contract in accordance with the instructions set forth in this Agreement and/or provided separately by Hotmart.
  2. 20. Record of processing activities. The Contracted Party shall maintain a written record of the following information:
    1. Record of Personal Data Processing activities carried out under the Contract;
    2. A record of international transfers of personal data to third countries, including information about the destination country/organization and documentation proving the adoption of the necessary safeguards; and
    3. General description of the technical and organizational security measures adopted to ensure: (i) Pseudonymization and encryption of personal data, where applicable; (ii) confidentiality, availability, integrity and resilience of systems; (iii) the ability to restore availability and access to Personal Data quickly in the event of a physical or technical incident; and (iv) and the existence of a process for continuous verification of technical and organizational measures related to the security of Personal Data Processing.
  3. 21. Subcontracting. The Contracted Party may only involve third parties (suppliers and/or service providers), as subcontractors, in the Personal Data Processing activities related to the Contract if it enters into a written contract with each subcontractor. The content of such contracts shall include provisions that, at a minimum, guarantee an equivalent or higher level of protection for personal data than the provisions and obligations set forth in this Agreement.
  4. 22. Obligations with respect to third parties. The Contracted Party, with respect to third parties involved in the Processing of Personal Data, shall also:
    1. Preserve the integrity and accuracy of Personal Data controlled by Hotmart, and update, correct, or delete such data upon request by Hotmart;
    2. Verify, through due diligence or equivalent procedure, that each third party is able to guarantee a level of protection of Personal Data at least equivalent to that provided for in this Agreement and to provide evidence of this verification to Hotmart, at request;
    3. Assume before Hotmart full and exclusive responsibility for all actions and omissions committed by third parties involved in Personal Data Processing activities; and
    4. Present, when requested by Hotmart, a copy of the contracts signed between the Contracted Party and third parties, duly signed, safeguarding the confidentiality of confidential, commercial or competitively sensitive information.
  5. 23. Objection by Hotmart. Hotmart may, at its sole discretion and at any time, object to the participation of third parties in the Processing of Personal Data in connection with the Contract. In such case, the Contracted Party must refrain from initiating or, if in progress, immediately terminate any Personal Data Processing activity carried out by a third party not permitted by Hotmart, and shall adopt the necessary measures to ensure that the Personal Data processed by it is duly returned and deleted, in accordance with clause 33. The Contracted Party shall also, whenever necessary, indicate and engage another third party capable of performing the intended activities, in order to ensure the continuity and full execution of the Contract. The Contracted Party shall not, under any circumstances, claim prejudice or impossibility of contractual performance due to the exercise, by Hotmart, of the right to object provided herein.
  6. 24. International Data Transfer by the Contracted Party. The Contracted Party may only carry out International Transfers of Personal Data accessed and/or obtained in connection with the Contract under the following circumstances: (i) when necessary for the execution of the purposes set forth in the Contract or in another instrument executed between the Parties; (ii) upon express authorization granted by Hotmart; or (iii) when necessary to comply with obligations established under applicable legislation. In all such cases, the Contracted Party must ensure compliance with one of the criteria provided for in the Applicable Data Protection Laws and Regulations.
  7. 25. Receipt of Requests. If the Contracted Party receives a request from Data Subjects or third parties, including competent authorities, regarding Personal Data controlled by Hotmart and related to the scope of the Contract, the Contracted Party must transmit the request to Hotmart within 24 (twenty-four) hours of its receipt exclusively via email (privacy@hotmart.com).
  8. 26. Duty to abstain. The Contracted Party shall abstain from any interaction with the party responsible for the request referred to in clause 25, unless necessary to comply with a legal/regulatory obligation or an official request issued by a competent authority.
  9. 27. Collaboration. In any case, the Contracted Party agrees to assist Hotmart in carrying out actions that prove necessary to ensure that requests received are fulfilled.
  10. 28. Communication in case of a Security Incident. In the event of suspected or confirmed unauthorized access, improper disclosure, and/or accidental or intentional destruction, loss, alteration, communication, dissemination, or any form of improper processing of Personal Data related to the Contract, the Contracted Party undertakes to send written communication to Hotmart, exclusively via email (security@hotmart.com) within a maximum period of 24 (twenty-four) hours, unless a shorter legal period applies. Said communication must contain, at a minimum, the following information, without prejudice to other information requested by the competent authority in its recommendations and regulations.
    1. Date and time of the incident;
    2. Date and time the Contracted Party became aware of the Incident;
    3. Description of the incident, including the root cause, if it is possible to identify it;
    4. List of types of Personal Data affected by the Incident;
    5. List and number of affected Data Subjects, either concretely or potentially, specifying, where applicable, the number of children, adolescents or elderly people affected;
    6. Contact details of the Data Protection Officer (DPO) or another person from whom it is possible to obtain additional information about what happened;
    7. Description of the technical and security measures implemented to protect the personal data, adopted before and after the Incident;
    8. Description of the possible consequences of the Incident, identifying the potential impacts on the Data Subjects; and
    9. Indication of measures being taken to repair the damage and prevent further Incidents, including, where possible, measures to mitigate and/or repair any potential consequences for Data Subjects.
  11. 29. Subsequent submission of information. If the Contracted Party does not have all the information indicated in clause 28 above, it must submit it gradually, justifying the reason for not fully providing it, as well as specifying the deadline for providing the remaining information, ensuring the greatest possible speed.
  12. 30. Incident Investigation. The Contracted Party, at its own expense, will be responsible for investigating the causes of the Incident and taking the necessary measures to remedy its consequences, promptly informing Hotmart of all the actions taken.
  13. 31. Prohibition on the disclosure of information about the Incident. In the event of an incident involving Personal Data controlled by Hotmart, Hotmart will be solely responsible for assessing and determining the need to report the security incident to the competent authority and the Data Subjects involved. The Contracted Party, in turn, undertakes not to issue any statement about the Incident on behalf of Hotmart unless otherwise permitted in writing by Hotmart.
  14. 32. Deletion, alteration, or correction. Hotmart may request the Contracted Party, at any time, to correct, update, modify, or permanently delete the Personal Data Processed due to the relationship between the Parties, extending the actions taken to any copies.
  15. 33. Return and/or deletion of Personal Data. Upon termination of the Contract, the Contracted Party undertakes to return and/or delete, securely, permanently and without any additional cost, all Personal Data transmitted, obtained or accessed within the scope of the contractual relationship, including any copies (whether in digital or physical format), unless otherwise lawfully agreed between the Parties or if applicable legal and regulatory obligations require the storage of information for an additional period.
  16. 34. Proof of return or disposal. The Contracted Party shall provide, when requested by Hotmart, evidence proving the return/deletion of Personal Data, as described in clause 33 above, within 15 (fifteen) calendar days from the date of the request.
  17. 35. Conducting an audit. The Contracted Party declares to be aware and agrees that Hotmart has the right, at any time and at its sole discretion, during the term of the Contract and/or for the entire period in which the Contracted Party retains Personal Data transmitted by Hotmart, to audit the Contracted Party, remotely or on-site, being able to access environments, facilities and/or documents (respecting applicable legal and technical limits), in order to verify, among other elements, the measures adopted for the protection of Personal Data. The audit may only be carried out by employees of the Controller or a contracted third party.
  18. 36. Liability. Hotmart’s non-exercise of the right to conduct audits does not, under any circumstances, exempt the Contracted Party from its responsibilities for any breach of its obligations relating to the Processing of Personal Data.
  19. 37. Adoption of Measures. If at any time there’s evidence of the need for an adjustment to the processes, activities or infrastructure of the Contracted Party, it shall undertake to adopt the necessary measures within a maximum period of 30 (thirty) days, unless a shorter period is determined by the competent authorities, generating evidence of the corrective actions adopted.
  20. 38. Providing information. The Contracted Party shall make available to Hotmart, upon the latter’s request in advance, all information and documents necessary to demonstrate the Contracted Party’s compliance with the provisions of this Agreement, and shall permit and contribute to audits, including periodic checks and inspections carried out by Hotmart or by an auditor it sends, in relation to the processing of Personal Data transmitted and/or accessed under the Contract.
  21. 39. Termination of the Contract. If the Contracted Party fails to resolve the faults or nonconformities identified by Hotmart within the timeframe agreed upon by the Parties, Hotmart may terminate the Contract without incurring any fines and/or penalties.

FINAL PROVISIONS

  1. 40. Conflict between the Agreement and the Contract Provisions. In case of conflict or inconsistency between the provisions of the Contract and this Agreement, or any other document signed between the Parties, specifically with regard to the processing of Personal Data, the following documents shall prevail, in order of precedence:
    1. Standard Contractual Clauses;
    2. This Agreement;
    3. The Contract.
  2. 41. Amendment to the Agreement. This Agreement may be amended from time to time, by Hotmart in case any update is needed, or if a new law, regulation, or recommendation from competent authorities that demands the alteration of its provisions arises.
  3. 42. Validity. If any provision of this Agreement is deemed null, invalid, or unenforceable, the remaining provisions shall remain valid and in force.
  4. 43. Survival. This Agreement shall remain in effect if any Personal Data Processing activity related to the Contract persists after its termination.