Pular para o conteúdo

Este documento é publicado apenas em inglês e espanhol, porque um texto contratual não se traduz sem advogado. A versão em inglês aparece abaixo.

Business Services Agreement

Version 0.0.1 · effective 26 August 2026

All documents

0 · The essentials in ten lines

  • This agreement governs the relationship between Datta and your company. Each person's own account is still governed by the Terms of Service.
  • Your organization's data is yours. People's data belongs to those people, and it reaches your company only with each subject's authorization.
  • Paying more does not widen a permission. No plan hands you a datum its subject did not authorize, and a revocation takes effect even if your account is fully paid up.
  • The commercial terms live in the order form: scope, volumes, prices, term, and any service metrics that are agreed.
  • We do not commit to an availability percentage today. What we do commit to is in the section «Availability, maintenance and incidents», with concrete deadlines.
  • We hold no SOC 2 or ISO 27001 certification today. The real security measures, with their gaps declared, are in the data processing agreement.
  • Suspending your account for non payment does not delete your data and does not cut any person's right to read, export or revoke.
  • You can leave. Termination opens a transition period to export, and your people's personal vaults remain theirs.
  • We do not use your company name or logo as a customer without your written authorization.
  • This agreement exists in English and Spanish; on conflict the English version controls.

1 · Parties, acceptance and the order form

1.1 The Datta service is provided by DATTTA LLC, a Delaware limited liability company (United States), file 10563369, formed on 26 March 2026, trading as «Datta», with its address at 1201 N Orange St, Ste 7665, Wilmington, DE 19801-1186, United States («Datta», «we»). «You» is the contracting company: the legal entity identified in the account or in the order form, together with the group companies the order form includes.

1.2 Whoever accepts this agreement represents that they can bind the company. If they cannot, they must not accept it. Acceptance is recorded with its date.

1.3 The order form is the document, signed or accepted in the product, that sets the package, the scope, the included volumes, the prices, the currency, the term and, where agreed, the service metrics and support response times. Without an order form, your company uses Datta under this agreement and under whatever the product enables on its self serve plan, with no committed volumes and no committed metrics.

1.4 Order of precedence. Where two documents say different things about the same subject, this is the order:

  1. The order form, on what it expressly regulates.
  2. The data processing agreement, on everything that is processing of personal data.
  3. This agreement.
  4. The Terms of Service and the policies they link to.

1.5 The Terms of Service still govern every person's own account, including your people's. This agreement takes away no right those terms give a person, and no order form can do so either.

1.6 If your company imposes its own master agreement, that master agreement prevails on what it expressly regulates and this agreement governs everything else. General purchasing conditions arriving inside a purchase order do not modify this agreement unless we sign them separately.

2 · What you are contracting

2.1 Datta provides your company, to the extent the order form contracts it:

  • Organization vault: the company as a verified subject, with its legal identity, governance and compliance data, under the same verification ladder as people.
  • Identity verification at volume: checking against the document itself and, where the document allows it, against its chip, for the people your company invites to verify.
  • Access by subject authorization: requesting, receiving and renewing people's data, always through scoped, time bound and revocable grants issued by each subject.
  • Interfaces: the Datta API and the MCP server, for your systems and for the agents your company authorizes.
  • Record and evidence: a chained audit trail of who asked for what, what was granted and what was read.

2.2 Annex A states which components are live today and which are under construction. An order form cannot contract as available something Annex A declares under construction, unless it sets the date by which it must be available and what happens if it is not.

2.3 What is not for sale. Datta does not sell people's data, neither yours nor anyone else's. The consent rail is not a product you buy: it is the architecture everything passes through. Your company pays for its own context and verification infrastructure, never for access to personal data.

3 · Whose data is whose

This is the clause that governs all the others. A business agreement that does not separate these three piles ends up promising the customer something that is not the customer's.

3.1 Your organization's data. Everything your company loads about itself is yours. Datta acquires no right over it beyond the minimum technical licence needed to run the service: to store it sealed, transmit it encrypted, index it blindly and show it to whoever your company authorizes. That licence ends when you delete the content or when this agreement ends, subject to the strict exceptions in the retention policy.

3.2 People's data. Personal data your company processes through Datta belongs to the subject. Your company is the controller and Datta its processor, under the data processing agreement. That agreement forms part of this one and is accepted with it.

3.3 The limit no plan moves. Your company reaches exactly what each subject authorized, for the scope and the time they authorized. Not the most expensive package, not an order form, not a privileged integration widens a grant. If a subject revokes, access dies immediately even if your company is fully paid up and the contract is still in force. No fee buys an exception to this.

3.4 Service records. Datta keeps your organization's audit trail and access records for the integrity of the chain, and makes them available to your company to review and export. They carry no identifiers in the clear.

3.5 Never. Datta does not use your company's data or people's data for its own purposes, nor for commercial analytics, nor for advertising, nor to train artificial intelligence models, its own or anyone else's.

4 · Your organization: seats, people and agents

4.1 A seat is access to the organization vault for a person your company designates. Your company manages joiners and leavers, and answers for what its members do inside the organization vault.

4.2 A member's personal account is not yours. When a person creates their Datta account, even through a flow run by your company, that personal vault is theirs: their data, their history, their right to export and to leave. Your company cannot read it, cannot administer it and cannot claim it when the employment or commercial relationship ends. Removing a seat removes access to the organization vault, and nothing else.

4.3 Sponsored plans. If your company sponsors its members' personal plans, the sponsorship ends when the seat or the agreement ends. The person keeps their vault, its content and its history, on the free plan or on whichever plan they choose to buy themselves.

4.4 Your company's agents. The artificial intelligence agents your company authorizes act for your company: what they do with the data you showed them is your company's responsibility towards Datta and towards third parties, exactly as if your staff had done it. Agent grants are scoped, carry no wildcards, have a maximum life, and reading never implies writing. Datta may limit, suspend or revoke an agent's access for abuse, security or anomalous patterns, without touching the rest of your account.

4.5 Credentials. Your company safeguards its credentials, keys and tokens. What happens under them is attributable to your company unless it tells us of a compromise as soon as it detects one.

5 · Use of the service, technical limits and interface changes

5.1 Technical limits. The service applies rate and volume limits per account. The ones that apply to your company are those of the contracted package, and they live in product configuration so they can be adjusted without interrupting the service. A limit is announced before it applies and, when it is reached, the message names the exact ceiling. Nothing is cut silently.

5.2 What a ceiling never blocks. Hitting any limit never prevents reading, exporting, porting or deleting your own data, nor revoking a grant. That holds for your company and it holds for every person.

5.3 Interface changes. A breaking change to the API or to the MCP server is announced at least 90 days in advance to your account's technical contact, and the previous version keeps answering throughout that period. The only exception is a change security forces us to make sooner; in that case it applies immediately and we explain why.

5.4 Repeated writes. Write operations require an idempotency key. An integration that does not send one may duplicate data, and that duplication is your company's responsibility.

5.5 Prohibited use. Your company may not: upload address books or contact databases it does not own or that were bought or scraped; use the network to build prospecting lists or send unsolicited messages; try to infer third party data by brute forcing the counting channels; resell or export third party data obtained from the service; or circumvent technical limits.

5.6 Security testing. Probing or attacking the service to test it requires prior written authorization, with an agreed scope and window. To report a vulnerability found without looking for it, the channel is datta.global/contact and no prior permission is needed.

6 · Availability, maintenance and incidents

6.1 What we do not commit to today. Datta does not commit to an availability percentage today. Committing to a number requires measuring it and publishing how it is measured, and that instrument does not exist yet. An order form may commit an availability level only when it also defines how it is measured, over what period, and with what consequence if it is missed.

6.2 Planned maintenance. Maintenance we expect to interrupt the service is announced at least 5 business days ahead to your account's technical contact, with the estimated window. Emergency maintenance is announced as soon as it is decided, and always explained afterwards.

6.3 Service incidents. While a material outage lasts we keep your account contact informed, and when it closes we send a summary of what happened, what caused it and what changed so it does not repeat.

6.4 Security incidents. A security breach affecting your company's data is notified without undue delay and no later than 48 hours from confirmation, on the terms and with the information set out in the data processing agreement.

6.5 Reduction of measures. If a security measure is going to change in a way that lowers the level of protection, we give 30 days' notice. The same applies to adding or changing a sub processor, with a right to reasoned objection, per the living list at datta.global/legal/subprocessors.

7 · Support and escalation

7.1 Contacts. Each party designates an account contact and a technical contact, and tells the other when they change. Notices under this agreement are treated as delivered when they reach those contacts.

7.2 Channel. The support channel is the form at datta.global/contact, in English or Spanish. Every request is acknowledged within 2 business days.

7.3 Severities and resolution times. Severity levels, target response and resolution times, and out of hours coverage, where agreed, are set by the order form. Without an order form there are no committed resolution times.

7.4 Escalation. If a matter is not moving, your company's account contact may escalate it to the person who owns the relationship at Datta, and from there to management. Escalation is requested through the same channel and answered in writing.

7.5 What support does not do. Datta support does not access the contents of personal vaults, and cannot hand your company a datum its subject did not grant it. A request to that effect is answered by saying exactly this.

8 · Prices, invoicing and payment

8.1 Prices. Prices are those of the order form. Unless it says otherwise, the currency is United States dollars.

8.2 How we charge today. Datta invoices and collects by bank transfer. There is no payment processor today: no cards are charged and no card data is held for anyone. Payment terms are 30 days from the invoice date, unless the order form sets another period.

8.3 Variable consumption. While per organization consumption metering is not available (Annex A), the order form sets a fixed price per period and no variable consumption is invoiced. Once metering is available, the invoice itemizes the period's counts; if your company's own record differs, we review it and correct what needs correcting. You have 30 days from the invoice to dispute a count.

8.4 Taxes. Prices are exclusive of taxes. Each party bears those its law imposes on it. If your company's law requires withholding on the payment, the amount is grossed up so that Datta receives what it would have received without the withholding, and your company provides the withholding certificate.

8.5 Late payment. An overdue invoice accrues the maximum interest the applicable law allows. If non payment continues more than 15 days after the notice of default, Datta may suspend the service.

8.6 What a suspension for non payment never does. It does not delete your company's data, it does not close your people's personal accounts, and it does not cut any person's right to read, export, revoke or delete what is theirs. Suspension affects the contracted service, never a subject's rights.

8.7 Price changes. Prices for a committed term do not change during that term. A price change takes effect from the next renewal and is announced at least 60 days in advance.

9 · Data protection

9.1 The data processing agreement is incorporated into this one and governs the processing of personal data: documented instructions, confidentiality, security measures, sub processors, assistance with subject rights, breach notification, deletion and return, audits, international transfers, and the modules for each applicable regime.

9.2 Cascading deletion. If a subject exercises reciprocal deletion or revokes a grant, Datta executes it in its systems and your company undertakes to honour the same deletion or revocation in its internal systems fed from Datta, within a maximum of 15 days, save for a legal retention obligation, which it will document. The acknowledgement is recorded as evidence, without the deleted datum.

9.3 Anti circumvention. Your company does not re acquire a deleted datum by other means to circumvent the deletion, nor rebuild it from derived copies.

9.4 Third party notice. When your company uploads data about people who do not use Datta, it delivers the notice its law requires. The template is in the corresponding annex of the data processing agreement, and the public version lives at the notice to non users.

9.5 Identity verification. A verification result says that, at that moment, the person passed the checks described in the biometric policy. It does not say they are solvent, trustworthy or legitimate in their intentions, and it does not replace your company's regulatory obligations. Decisions your company takes relying on a verification are its own.

10 · Security, certifications and customer verification

10.1 Measures. The technical and organizational measures are described in the security annex of the data processing agreement, written as they are today and with the gaps declared alongside their plan. An aspirational security annex is a lawsuit waiting for a date, so nothing in there is a measure that is not already operating.

10.2 Certifications. Datta holds no SOC 2 or ISO 27001 certification today. Any claim to the contrary, wherever it comes from, is false.

10.3 Questionnaires. Datta answers one security questionnaire from your company per year, and additionally after a material incident, with whatever documentation and reports it holds.

10.4 Audit. The audit right, its frequency, its notice period and its limits are those of the data processing agreement. They are not duplicated here so that they cannot diverge.

10.5 Hosting. Data is hosted only in Canada, the United States or Europe, per the privacy policy. The order form may narrow that choice, within the available regions.

11 · Confidentiality

11.1 Each party protects the other's confidential information with at least the same care it applies to its own, uses it only to perform this agreement, and shares it only with those who need to know and are bound by an equivalent duty.

11.2 Information is not confidential if it was already public through no fault of the recipient, if the recipient already held it without a duty of confidence, if it comes from a third party entitled to disclose it, or if the recipient developed it independently without using what it received.

11.3 If an authority or a law compels disclosure of confidential information, the recipient gives the other party prior notice unless legally barred, and discloses only what is required.

11.4 The duty lasts while this agreement is in force and for 3 years afterwards. Personal data is not governed by that period: it is governed by the data processing agreement and the retention policy, and the duty to protect it does not expire.

12 · Intellectual property, feedback and trademarks

12.1 The service, its software, its data models and its documentation belong to Datta. This agreement transfers no ownership: it grants the right to use the service while it is in force and paid for.

12.2 Your company's data belongs to your company. People's data belongs to those people. Nothing in this section changes the section «Whose data is whose».

12.3 Feedback. If your company suggests an improvement, we may use it with no time limit and no consideration. That permission covers the idea, never your data or people's data.

12.4 Trademarks. Neither party uses the other's trademark, name or logo without written authorization. We do not publish your company's name or logo as a customer, not on the site, not in sales materials, not to investors, without your written authorization, and you may withdraw it at any time, effective for the next material we publish.

13 · Warranties and limits of liability

13.1 What Datta warrants. That it provides the service with the professional care of the industry, and that it holds the rights needed to provide it.

13.2 What it does not. Beyond the above, and to the maximum extent the applicable law allows, the service is provided «as is» and the implied warranties of merchantability, fitness for a purpose and non infringement are excluded. Features marked beta may change or be withdrawn, and are provided without warranty.

13.3 Excluded damages. Neither party is liable for indirect or consequential damages, lost profits, lost opportunity or reputational harm.

13.4 General cap. Each party's total aggregate liability for all claims arising in the same twelve month period is limited to the greater of USD 100 and what your company paid Datta in the twelve months before the event giving rise to the claim.

13.5 Enhanced cap. For breach of the confidentiality obligations and of the data protection obligations, the cap is twice the amount in the previous section.

13.6 What is not capped. None of this limits liability for wilful misconduct or gross negligence, for harm to life or personal integrity, for your company's payment obligations, or for the indemnities in the next section. Nor does it limit any right a mandatory law declares non waivable.

14 · Indemnities

14.1 By your company. Your company holds Datta, its directors, employees and suppliers harmless from third party claims, damages and reasonable costs, including legal fees, arising from: (a) data uploaded in violation of third party rights or applicable law; (b) unlawful processing instructions or instructions without your own legal basis; (c) use of the service in breach of this agreement, including the prohibitions in the section «Use of the service, technical limits and interface changes»; (d) breach of the cascading deletion obligation; (e) the acts of the agents your company authorized; and (f) claims by subjects whose data your company processed outside the authorized purpose.

14.2 By Datta. Datta holds your company harmless from a third party claim alleging that the service, used in accordance with this agreement, infringes that third party's intellectual property. It does not cover a claim arising from using the service outside this agreement, from combining it with products or data Datta did not supply, or from the data your company uploaded. If such a claim materializes, Datta may modify the service, obtain the necessary licence, or terminate the affected part and refund the unused prepaid portion.

14.3 By Datta, for wilful misconduct or gross negligence. Datta holds your company harmless for breaches of the data processing agreement caused by Datta's wilful misconduct or gross negligence.

14.4 Procedure. The party receiving the claim gives prompt notice, lets the other party control the defence with reasonably acceptable counsel, cooperates reasonably, and does not settle without the other party's consent, which will not be unreasonably withheld.

15 · Term, renewal and termination

15.1 Term. The initial term and renewal are those of the order form. If it says nothing, the agreement runs month to month and renews unless either party says otherwise.

15.2 Termination for convenience. Either party may terminate on 30 days' notice. If your company terminates before the end of a committed term, prepaid amounts are not refunded unless the order form says so. If Datta terminates for convenience, it refunds the unused prepaid portion.

15.3 Termination for breach. Either party may terminate if the other materially breaches and does not cure within 30 days of written notice.

15.4 Immediate termination. Either party may terminate immediately if the other enters insolvency or liquidation. Datta may terminate immediately if your company becomes subject to applicable sanctions, or if its use of the service puts third parties, people's data or the integrity of the service at risk.

15.5 Suspension. Datta may suspend the service, in whole or in part, for non payment under the payment section, for an active security threat, or under a legal order. Suspension is proportionate, is announced in advance except in an emergency, and is lifted when the cause ends. No suspension deletes data.

15.6 Survival. The following survive termination: the sections «Whose data is whose», «Confidentiality», «Intellectual property, feedback and trademarks», «Warranties and limits of liability», «Indemnities», «Exit: export, transition and deletion» and «Governing law and disputes», together with accrued payment obligations.

16 · Exit: export, transition and deletion

16.1 Transition period. On termination, your company has 30 days of read and export access, unless termination was caused by an active security threat or a legal order. The order form may extend that period.

16.2 What is delivered. Your organization's data, in a machine readable format. With the honesty this corpus demands of itself: today the automated export covers identity, profile and address book, and the rest of the vault is delivered within the transition period as a structured extraction, at the request of your account contact. Full vault export is under construction (Annex A).

16.3 What is not delivered. Data living in other people's personal vaults, which was never your company's, and audit records belonging to third parties. What your company received under a grant while it was live, it received; terminating the agreement creates no new right over it, and the cascading deletion obligations continue to apply.

16.4 Deletion. Once the transition period ends, your company chooses return or deletion, and deletion follows the real cycle in the retention policy. Datta provides confirmation of deletion on request. The exception is whatever the law requires us to keep, which is isolated and blocked.

16.5 People keep what is theirs. Terminating this agreement closes no personal account, deletes no personal vault and transfers the contents of none to your company. Each person's portability is a right, not a feature of their employer's plan.

17 · Non solicitation

While this agreement is in force and for 12 months afterwards, neither party will actively solicit for employment a person employed by the other with whom it had direct contact because of this agreement. A public job posting does not count as solicitation, nor does hiring someone who applies on their own initiative without having been approached.

18 · Changes to this agreement

18.1 Material changes to this agreement are announced at least 30 days ahead to your account contact. If your company does not agree, it may terminate without penalty before they take effect.

18.2 A change does not apply to a term already committed in an order form until its next renewal, unless the law requires it to apply sooner.

18.3 The version history of this document lives at datta.global/legal.

19 · Governing law and disputes

19.1 This agreement is governed by the laws of the State of Delaware, United States, without regard to its conflict of laws rules, and disputes are submitted to the courts located in Delaware.

19.2 There is no mandatory arbitration and no waiver of class actions.

19.3 Before any formal action, the parties escalate the matter to a decision maker on each side and negotiate in good faith for 30 days. That period does not prevent either party from seeking urgent interim relief.

20 · Miscellaneous

20.1 Assignment. Your company may not assign this agreement without our consent, which will not be unreasonably withheld. Datta may assign it to an affiliate or a successor, with notice.

20.2 Subcontracting. Datta may rely on sub processors per the data processing agreement, and answers for them as for its own acts.

20.3 Force majeure. Neither party is liable for a failure caused by an event beyond its reasonable control, while it lasts and provided it is communicated and mitigated. Accrued payment obligations are not suspended.

20.4 Sanctions and export control. Neither party may use the service in violation of the sanctions and export control rules that apply to it.

20.5 Independent parties. This agreement creates no partnership, agency, joint venture or employment relationship between the parties.

20.6 Notices. Notices are delivered to the designated contacts. Notices from Datta to your company are treated as delivered on the business day after they are sent.

20.7 Severability and no waiver. If a clause is invalid, the rest remains in force. Not exercising a right does not waive it.

20.8 Entire agreement. This agreement, the order form, the data processing agreement, the Terms of Service and the policies they link to are the entire agreement between the parties on its subject matter, and supersede any prior understanding.

20.9 Languages. The English and Spanish versions are parallel originals. On conflict the English version controls.

Annex A · What is live today and what is under construction

This annex exists so that no order form promises what the product does not do yet. It is updated with each version of this document.

Live today

ComponentStatus
Organization vault with an owner and the company's own dataLive
Organization verification ladderLive in the data model; the assisted verification flow is under construction
Identity verification against the document and its chipLive
Scoped, time bound, revocable grants with a full historyLive
Agent access through the MCP server, with revocation re read on every operationLive
Cryptographically chained audit trail, with the actor identifiedLive
Daily encrypted backup with an offsite copy at another provider in another countryLive
In product rights for every person: sessions, devices, access history, deactivate, delete and exportLive

Under construction

ComponentWhat is missing
Seats for organization membersOnly the owner exists today
Role based context for the organization's agentsThe role context compiler is not finished
Per organization consumption meteringWithout it, variable consumption cannot be invoiced
Variable consumption invoicingDepends on the metering above
Hosted onboarding of your users on a Datta domainBuilt, not yet enabled
Full vault exportThe automated export covers identity, profile and address book
Availability measurement and publicationWithout it, no percentage is committed
Security certificationsNone today

Annex B · Definitions

TermWhat it means
Order formThe document that sets package, scope, volumes, prices, currency, term and, where agreed, service metrics and support times
Organization vaultThe sealed space where your company keeps its own data as a verified subject
Personal vaultA person's sealed space, which belongs to them and not to your company
SeatThe access of a person designated by your company to the organization vault
GrantThe explicit authorization, scoped and time bound and revocable, issued by a subject
SubjectThe person a piece of personal data belongs to
AgentAn artificial intelligence system authorized to read or write in a vault, within a grant
InterfacesThe Datta API and the MCP server
Cascading deletionYour company's obligation to repeat in its own systems the deletion or revocation a subject exercised
QueryA billable read operation by an agent or a system of your company against the service

Version 0.0.1 · Last updated: 26 August 2026 · Controller: DATTTA LLC (trading as «Datta») · Contact: datta.global/contact

Back to home

DATTA / Seus dados. Seus termos.

Converse com a Datta

Estamos explorando: Seus dados. Seus termos..