LGPD Commitment
Free translation provided for convenience. The Portuguese version is the binding one and prevails in case of divergence.
Last updated: August 2026
1. The LGPD
The Brazilian General Data Protection Law (Law No. 13,709/2018), in force since 18 September 2020, establishes principles, rules and limits for the processing of personal data, protecting the fundamental rights of freedom and privacy.
2. Privacy by architecture at FCX
FCX is an agentic commercial intelligence platform: ATTO, its AI, runs the Guided Analysis (the Up-sell and Cross-sell, Persona, Opportunities and Leads engines) to prioritize opportunities and guide the commercial approach. The commitment to the LGPD is structural, not a mere consent form:
(i) No sensitive data. The analysis does not use sensitive data (art. 5, II, of the LGPD). Compliance is achieved by architecture.
(ii) Privacy by design. Solutions are conceived, from the outset, with data protection as a premise.
(iii) Overprivacy methodology. When there is little data available, ATTO automatically lowers the confidence of the analysis, formulates a hypothesis or requests validation, rather than inferring on fragile ground. The unavailability of a source does not authorize the platform to presume missing data.
(iv) Auditable recommendations. The platform separates evidence, inference and hypothesis; every recommendation can be reconstructed from the evidence it used.
(v) Purpose and necessity. Processing is lawful, transparent and limited to the purpose of providing the service; data is protected and deleted or anonymized once it is no longer necessary.
(vi) Processing chain. A compliance process is applied to suppliers and partners involved in the flow, to guarantee security and privacy end to end.
3. Principles observed
Good faith, purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, accountability and the duty to give account.
4. Data sources and authorized connectors
ATTO works from the Authorized Connectors enabled by the client company itself (CRM, e-mail, calendar, messaging, proposals, uploaded documents) and from permitted public sources about companies, products, markets and territories. The client company is responsible for holding a legal basis and authorization to enable each connector, and FCX records the scope and origin of every access performed.
Making a professional contact available requires, cumulatively: a permitted source, associated evidence, a documented legal basis, a legitimate commercial purpose, a proportionality assessment and a channel for objection or opt-out. In the absence of any of these requirements, the contact is discarded.
As part of the regular operation of the platform, FCX does not use: purchased external personal dossiers, inference of sensitive personal data, scraping of authentication-protected content, contact extraction without a legal basis, or identifiable reuse of data across distinct accounts. Data, states and memories are isolated by account or organization.
5. Security infrastructure
FCX adopts modern security measures to guarantee the integrity and protection of data, including encryption in transit (TLS/SSL) for traffic passing through its servers, access control and monitoring.
6. Automated decisions, human review and audit trail
ATTO's recommendations are produced automatically and constitute decision support — the commercial decision remains with the person who makes it. The data subject or the user may request human review of an automated recommendation or block that produces a material effect, through FCX's service channels; the analysis considers the available evidence and the rules applied, and the outcome is recorded.
FCX maintains an Audit Trail sufficient to reconstruct each analysis: the evidence and sources used, the rules and controls applied, the results, the gaps and the blocks. Records are versioned and are not overwritten by later updates.
7. Data subject rights and other policies
This statement is part of FCX's set of legal documents. To understand how FCX processes, shares, protects, stores and deletes data, see the other legal pages (Terms and conditions, Privacy policy, Cookies and Licence of Use). Data subjects may exercise their rights (confirmation, access, correction, anonymization, portability, deletion and information about sharing) through the channels below.
8. Data Protection Officer (DPO)
Officer responsible for handling requests from personal data subjects.
DPO: Eduardo Lehrbach — dpo@fcxsolutions.com.br.
9. Information and questions
For more information about FCX's commitment to the LGPD or about the Privacy Policy, write to suporte@fcxsolutions.com.br.