TimelinesAI LGPD Compliance - Brazil
Last updated: January 29, 2026
1. Our Approach to LGPD Compliance
2. Roles and Responsibilities
• Customer acts as the Controller(Controlador) — decides how and why
personal data is processed
• TimelinesAI acts as the Operator(Operador) — processes data only according
to customer instructions
3. Data Processing Agreement
4. Security Measures
- Encryption: All connections use SSL/TLS encryption (A+ grade from
Qualys/SSL Labs). Data is encrypted in transit and at rest. - Access Controls:Role-based permissions limit data access to authorized team
members only. - Regular Backups: Automated daily backups ensure data availability and
recovery. - Security Testing: Mandatory code reviews and periodic security audits.
- Incident Response: Documented procedures for handling security incidents.
5. Data Infrastructure
- Servers are located in virtual private cloud (VPC) environments with restricted
security groups - Separate testing/development and production environments
Regular monitoring and security updates
6. Data Subject Rights
As a data operator, TimelinesAI supports customers (controllers) in fulfilling data subject rights under LGPD, including:
- Access — confirmation and access to personal data
- Rectification — correction of incomplete or inaccurate data
- Erasure — deletion of data when appropriate
- Portability — data export in structured format
- Objection — ability to object to processing
7. Third-Party Service Providers
TimelinesAI uses carefully selected third-party service providers (sub-processors) for
infrastructure, payment processing, and communication services. All sub-processors
are required to maintain appropriate security and data protection standards. We remain responsible for our sub processors’ compliance with data protection obligations.
8. Data Retention
We retain personal data only as long as necessary to provide our services or as required by law. When a customer account is closed, data is made available for export for 30 days, after which it may be deleted according to our data retention policy.
9. Privacy Policy
Our complete privacy practices, including how we collect, use, and protect personal information, are detailed in our
Privacy Policy at: timelines.ai/privacy
Contact Us
For questions about our data protection practices or to exercise data subject rights, please contact:
TimelinesAI Privacy Team
Email: privacy@timelines.ai
Website: timelines.ai