Skip to main content

Data processing addendum.

This Addendum applies when you process personal data of third parties (your followers, leads, reviewers) through Viuz. It supplements our Terms of Service.

Effective 2026-09-01

When this Addendum applies

This Addendum applies whenever you use Viuz to process personal data about people other than yourself: the teammates and reviewers you invite, the public profiles you ask us to analyse, the people who interact with the posts you publish where you turn on a feature that reads those interactions, and anyone who appears in the media you upload or import. It supplements the Terms of Service and forms part of them for as long as you use those features.

Roles

For that data you are the controller (controlador under LGPD, controller under GDPR) and Zeit Capital LTDA is the processor (operador, processor) acting on your behalf. For the data we need to run our own business, such as your account, your billing record and product analytics, we are the controller ourselves; that processing is governed by our Privacy Policy and not by this Addendum.

Subject matter, nature, purpose and duration

We process the personal data described below to generate, render, schedule, publish and measure social media content on your instruction, and for nothing else. Processing lasts while your account is open, plus the retention windows set out in the Privacy Policy.

Categories of data and of data subjects

Teammates, clients and reviewers you invite: name, email address, role and their activity in your workspace. People whose public profiles you ask us to analyse: their public handle, their public posts and the public metrics those posts show. People who interact publicly with what you publish, where you enable a feature that reads those interactions: their public handle and the content of the interaction. Anyone visible or identifiable in the images and video you upload or import.

Our instructions

We process this data only on your documented instructions, which are these Terms, this Addendum, the Privacy Policy, and the actions you take in the product. We will tell you if an instruction appears to breach LGPD or GDPR. We do not sell personal data, we do not use it for advertising, we do not use it to train models of our own, and we do not process it for any purpose of our own beyond running and securing the service.

Confidentiality

Everyone we let near this data, employees and contractors alike, is bound by confidentiality, and access is limited to the people who need it to operate or support the service.

Security measures

Data is encrypted in transit with TLS and at rest by our hosting providers. Publishing tokens are encrypted by the application on top of that. Database access runs under least-privilege roles. Images are scanned for malware and stripped of EXIF metadata, including GPS coordinates, before they are stored. Publishing actions are recorded. Access to production systems is limited to the people who operate them, and we review these measures as the service changes.

Sub-processors

You authorise the sub-processors we use to run the service, each given only what it needs: Supabase (database and authentication), Railway (API, background workers and queue), Cloudflare (web delivery and media storage), Google (content generation with Gemini, and the Drive import if you use it), Perplexity (news and research features), Apify (reading the public profiles you ask us to analyse), Stripe (payments), Mixpanel (product analytics), Sentry (error reports) and Crisp (support chat). We announce a new sub-processor at least 30 days before it starts, you may object in writing on reasonable data protection grounds, and if we cannot accommodate the objection you may terminate the affected subscription.

Google user data

Files you bring in through the Google Drive import, on either of the two ways described in the Privacy Policy, are handled under the Google API Services User Data Policy, including its Limited Use requirements. On the default picker path the access token stays in your browser, we hold nothing for it, and we cannot open a file you did not choose there. If you connect a Google Drive account instead, we hold an encrypted refresh token for that connection until you disconnect it from the Connections tab, delete the brand, or delete your account; disconnecting it and deleting your account revoke the grant at Google before the encrypted token row is deleted, while deleting the brand deletes that row alone, without revoking anything at Google, so the grant stays live until you revoke it yourself at Google's own page or delete your account. A connected account reads file names, folder structure and thumbnails when you browse, and the bytes of the file you choose to import, never more. We never transfer that data except as needed to provide the feature or as the law requires, we never use it for advertising, and we never use it to develop or train generalised artificial intelligence or machine learning models. The Privacy Policy describes both ways of importing, and what each one reads and stores, in full.

International transfers

Viuz is operated from Brazil and most of the sub-processors above are in the United States or the European Union, so personal data is transferred internationally. Transfers rely on the mechanisms LGPD and GDPR allow: contractual clauses with each provider and adequacy decisions where one exists.

Assisting you

You remain responsible for answering the requests of the people whose data you process. Most of what you need is in the dashboard: content is editable and exportable, and deleting a brand deletes its data. For anything else, write to privacy@viuz.ai and we will help within a reasonable time. We also assist, in proportion to what we know, with your security obligations, your breach notifications and any impact assessment you have to run.

Personal data breach

If we confirm a breach affecting personal data you control, we notify you without undue delay and in any event within 72 hours where feasible, with the facts known at that time, the likely consequences, the measures taken, and a contact for follow-up. Notifying the ANPD, a supervisory authority or the affected people stays your decision as controller, and we give you what you need to make it.

Audit

On request we give you the information needed to show that we meet this Addendum. You may audit that once every twelve months, with 30 days written notice, at your own cost, under confidentiality, at a time that does not disrupt the service. Where a report or certification from a sub-processor answers the question, that report is what we provide.

Return and deletion

Deleting a brand deletes its posts, its media and its scheduled publications. When your account ends, we delete or return the personal data you control within 30 days, except where a law requires us to keep it. Backups age out on their own schedule and are not restored to serve a deleted account.

Precedence and changes

Where this Addendum and the Terms of Service disagree about the processing of personal data you control, this Addendum prevails. Material changes to it are announced by email or in-product at least 30 days before they take effect.

Contact

Data protection contact (encarregado under LGPD): dpo@viuz.ai. Privacy and data requests: privacy@viuz.ai. Zeit Capital LTDA, CNPJ 52.988.658/0001-57, Brasília, DF, Brazil.


Back to home