YouTube Comment Moderation Service
Data Processing Agreement
Prepared in accordance with the Brazilian General Data Protection Law (Lei no 13.709/2018 — LGPD), the Marco Civil da Internet (Lei no 12.965/2014), and the Digital Statute of Children and Adolescents (Lei no 15.211/2025 — ECA Digital).
Between the Customer identified on the signature page (Controller) and the operator of the Moderaty service identified on the signature page (Processor)
1. Purpose and Scope
1.1 This Data Processing Agreement (DPA) governs the processing of personal data by the Processor on behalf of the Controller in connection with Moderaty, a YouTube comment moderation service that retrieves comments from the Controller's YouTube channel(s) via the YouTube Data API, classifies them (including automated detection of hate speech and related abusive content), and executes moderation actions (such as holding, hiding, or removing comments) in accordance with the Controller's configuration of the Service.
1.2 This DPA applies to personal data of third-party comment authors contained in or associated with comments processed through the Service (Comment Data). The processing of the Controller's own account, contact, and billing data — for which the Processor acts as controller — is governed by the Moderaty Terms of Service and Privacy Policy, not by this DPA.
1.3 The Parties acknowledge that the processing described in this DPA is carried out in Brazilian territory and is therefore subject to the LGPD pursuant to its Article 3, item I, regardless of the location of the Controller or of the data subjects.
2. Definitions
Capitalized terms not defined here have the meanings given in Article 5 of the LGPD, including: personal data; sensitive personal data; data subject; controller (controlador); operator/processor (operador); processing; anonymized data; and national authority (ANPD). In addition:
- (a) Comment Data: personal data contained in YouTube comments retrieved from the Controller's channel(s), including comment text, author display name or username, author channel identifier, and associated metadata.
- (b) Moderation Outcome Data: the minimal records the Processor retains after a moderation action, limited to the comment identifier reference, the comment text (truncated to 500 characters), the classification verdict, the action taken, and the timestamp. Moderation Outcome Data excludes author identifiers and author profile data.
- (c) ECA Digital: Law no 15.211/2025 (Digital Statute of Children and Adolescents), in force since March 2026.
- (d) Marco Civil: Law no 12.965/2014 (Brazilian Civil Rights Framework for the Internet), as interpreted by the Brazilian Supreme Court (STF) in its 2025 rulings on platform duties of care.
- (e) ANPD SCCs: the standard contractual clauses for international data transfers approved by ANPD Resolution CD/ANPD no 19/2024, mandatory for qualifying transfers since 23 August 2025.
3. Roles of the Parties
3.1 The Controller is the controller of the Comment Data. The Processor is the operator (processor) and processes Comment Data solely on the Controller's documented instructions.
3.2 The Controller's documented instructions consist of: (a) this DPA; (b) the moderation rules, filters, thresholds, and actions the Controller configures in the Service; and (c) any written instruction issued through the Service or by e-mail. The Processor shall not process Comment Data for its own purposes.
3.3 If the Processor believes an instruction violates the LGPD or other applicable data protection law, it shall promptly inform the Controller and may suspend execution of the specific instruction until clarified.
4. Subject Matter, Duration, Nature and Purpose of Processing
4.1 The subject matter, duration, nature and purpose of the processing, the categories of data subjects and of personal data, and the retention rules are described in Annex I, which forms an integral part of this DPA.
4.2 The processing duration matches the term of the Controller's subscription to the Service, subject to the deletion obligations in Section 17.
5. Controller Obligations and Lawful Basis
5.1 The Controller warrants that it has a valid lawful basis under Article 7 of the LGPD for the processing of Comment Data and, to the extent Comment Data contains sensitive personal data within the meaning of Article 5, item II (for example, comment content revealing racial or ethnic origin, religious conviction, or political opinion), a valid basis under Article 11 of the LGPD.
5.2 The Parties note that legitimate interest (Article 7, item IX) is not an available basis for sensitive personal data under Article 11. The Parties anticipate that the relevant bases for sensitive data in this context will typically be: (a) compliance with a legal or regulatory obligation (Article 11, item II), including duties of care concerning gravely illicit content — such as hate speech and racism — as established by the Marco Civil and STF precedent; and/or (b) protection of the life or physical safety of the data subject or of a third party (Article 11, item VII).
5.3 The Controller is responsible for its own privacy notices to data subjects where required, for the lawfulness of its configuration choices in the Service, and for responding to data subject requests concerning Comment Data.
5.4 The Controller represents that it is at least 18 years of age, that the Service is a professional tool directed exclusively at adults, and that it is not a service likely or foreseeably accessed by children or adolescents within the meaning of the ECA Digital.
6. Processor Obligations
The Processor shall:
- (a) process Comment Data only on documented instructions, as set out in Section 3.2;
- (b) ensure that persons authorized to process Comment Data are bound by confidentiality;
- (c) implement and maintain the technical and organizational measures in Annex II;
- (d) engage sub-processors only as permitted by Section 10;
- (e) assist the Controller, taking into account the nature of the processing, in responding to data subject requests (Section 13) and in meeting its obligations regarding security, incident notification, and data protection impact assessments (RIPD);
- (f) make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA (Section 16); and
- (g) delete Comment Data as required by Sections 7 and 17.
7. Data Minimization and Author-Identifier Non-Retention
7.1 The Processor minimizes retained Comment Data: comments are retrieved, classified, and acted upon; comment text (truncated to 500 characters) is stored solely as part of Moderation Outcome Data, and author identifiers (display name, author channel identifier) are not persistently stored by the Service.
7.2 Author identifiers are processed transiently, in memory only, strictly for the duration required to classify the comment and execute the configured moderation action, and are discarded immediately thereafter.
7.3 Beyond the comment text stored within Moderation Outcome Data, the Processor shall not reconstruct, reassemble, or maintain archives of comment bodies or author profiles.
7.4 The Parties acknowledge that pseudonymized identifiers (such as hashed usernames) remain personal data under the LGPD. The Processor shall not retain author identifiers taken from Comment Data, pseudonymized or otherwise, and never for profiling or enrichment. Channel identifiers entered by the Controller in user rules are Controller configuration, not retained Comment Data.
7.5 The Processor shall not use Comment Data or Moderation Outcome Data to train, fine-tune, or improve machine-learning models, whether its own or third-party models.
8. Sensitive Personal Data
8.1 The Parties acknowledge that Comment Data may incidentally contain sensitive personal data, including hate speech content that itself references race, ethnicity, religion, political opinion, health, or sexual orientation of data subjects or third parties.
8.2 The Processor's classification targets the abusive character of the content, not the personal traits of the author. The Processor shall not extract, profile, categorize, score, or enrich sensitive attributes of any data subject.
8.3 The lawful basis for the processing of sensitive personal data flows down from the Controller pursuant to Section 5, and the Processor acts on the Controller's instructions in that regard.
9. Data of Children and Adolescents
9.1 The Parties acknowledge that Comment Data may include personal data authored by, or relating to, children or adolescents, and that the Processor cannot identify the age of comment authors and does not attempt to do so. Age assurance on the YouTube platform is the responsibility of the platform provider, not of the Parties.
9.2 Because age identification of comment authors is technically infeasible, the Processor treats all Comment Data to the highest protection standard, consistent with the best-interest principle of Article 14 of the LGPD and with the ECA Digital.
9.3 Accordingly, and without limiting Sections 7 and 8, the Processor shall not: (a) build or maintain profiles of comment authors; (b) perform author-level behavioral analysis or scoring (classification is content-level only); (c) use Comment Data for advertising or commercial profiling; or (d) use Comment Data for model training, as set out in Clause 7.5.
9.4 The Processor documents this design posture in its data protection impact assessment (RIPD) as the measure that satisfies the best-interest principle given the impossibility of age identification.
10. Sub-processors
10.1 The Controller grants general authorization for the sub-processors listed in Annex III. The Processor shall inform the Controller at least 15 days in advance of any intended addition or replacement of a sub-processor, and the Controller may object on reasonable data protection grounds within 10 days of notice.
10.2 The Processor shall impose on each sub-processor data protection obligations no less protective than those in this DPA and remains fully liable to the Controller for the sub-processor's performance.
10.3 YouTube / Google LLC acts as the source platform and, in respect of comment publication and moderation execution, as an independent platform operator under its own terms; the Parties' obligations regarding the YouTube API are limited to lawful retrieval and execution of moderation actions on the Controller's channel.
11. International Data Transfers
11.1 The Parties acknowledge that Comment Data transits infrastructure located outside Brazil, including YouTube/Google systems and the sub-processors identified in Annex III.
11.2 Any international transfer of personal data under this DPA shall rely on a valid mechanism under Article 33 of the LGPD. Where the transfer mechanism is standard contractual clauses, the Parties incorporate the ANPD SCCs (Resolution CD/ANPD no 19/2024) as set out in Annex IV. Standard contractual clauses of other jurisdictions (including EU SCCs) shall not be used as a substitute for the ANPD SCCs.
11.3 The Processor shall maintain in Annex III a current record of the transfer mechanism relied upon for each sub-processor — including, for Turso, the specific edge-replica regions enabled at any time — and shall update it upon any change. The Processor shall not enable database replicas in regions not recorded in Annex III.
12. Security Measures
12.1 The Processor shall implement and maintain the technical and organizational measures described in Annex II, including encryption in transit, least-privilege access control, credential and API-key management, and environment isolation.
12.2 The Processor shall regularly test, assess, and evaluate the effectiveness of those measures and shall adjust them to address material changes in risk.
13. Data Subject Requests
13.1 Taking into account the data-minimization measures of Section 7 (which limit the personal data the Processor holds), the Processor shall provide reasonable assistance so the Controller can respond to data subject requests within the LGPD deadlines, including the 15-day confirmation/access deadline of Article 19.
13.2 If the Processor receives a request directly from a comment author, it shall forward it to the Controller within 5 business days and shall not respond on the Controller's behalf unless instructed.
14. Personal Data Incident Notification
14.1 The Processor shall notify the Controller without undue delay after becoming aware of a personal data incident affecting Comment Data or Moderation Outcome Data, providing the information reasonably available to enable the Controller to assess its own notification duties.
14.2 The Parties acknowledge that under ANPD Resolution CD/ANPD no 15/2024 a controller must notify the ANPD and affected data subjects within 3 business days of becoming aware of an incident that may entail relevant risk or harm. The Processor shall cooperate in good faith so the Controller can meet that deadline.
15. Statutory Log Retention (Marco Civil da Internet)
15.1 Notwithstanding Section 7, the Processor retains connection records and records of access to applications for the statutory period of 6 months under Articles 13 and 15 of the Marco Civil; these logs and the Moderation Outcome Data described in Section 7 are the only records the Processor retains.
15.2 Such logs are stored separately from operational data, kept under secrecy as required by law, used solely for legal compliance, and automatically and permanently deleted at the end of the statutory retention period.
16. Audits and Compliance Documentation
16.1 The Processor shall make available, upon reasonable request, documentation demonstrating compliance with this DPA, including a summary of its RIPD, its security policies, and records of processing relevant to the Service.
16.2 Audits shall be conducted primarily through documentation and written questionnaires. On-site inspections are permitted at most once per year (or when required by the ANPD), with 30 days' notice, during business hours, at the Controller's reasonable cost, and subject to confidentiality.
17. Term, Termination and Deletion
17.1 This DPA takes effect on the date the Controller accepts the Moderaty Terms of Service or signs this DPA, whichever occurs first, and remains in force for the duration of the processing.
17.2 Upon termination of the Service, the Processor shall delete any remaining Comment Data within 30 days, except the statutory logs under Section 15, and shall certify the deletion upon the Controller's written request.
18. Liability
18.1 Each Party is liable for the damage it causes through processing in violation of the LGPD or of this DPA, consistent with Article 42 of the LGPD. The Processor is liable when it fails to comply with the obligations of an operator or disregards the Controller's lawful instructions.
18.2 Liability limits, if any, in the Moderaty Terms of Service apply to this DPA to the extent permitted by law and shall not limit liability for willful misconduct or for violations of the LGPD.
19. Governing Law, Language and Dispute Resolution
19.1 This DPA is governed by the laws of Brazil, including the LGPD, the Marco Civil, and the ECA Digital.
19.2 This DPA is executed in English. A Portuguese version shall be made available and, for processing involving data subjects located in Brazil, the Portuguese version prevails in case of divergence. The Parties shall keep both versions aligned.
19.3 Disputes shall be submitted to the courts of the judicial district of the Processor's registered seat in Brazil, unless the Parties agree in writing to arbitration seated in Brazil under the rules of a recognized arbitral institution.
20. Final Provisions
20.1 In case of conflict between this DPA and the Moderaty Terms of Service, this DPA prevails on matters of personal data protection.
20.2 Amendments must be in writing. If any provision is held invalid, the remainder stays in force and the Parties shall replace the invalid provision with a valid one closest to its intent.
20.3 Notices under this DPA shall be sent to the e-mail addresses stated on the signature page and are deemed received on the next business day.
Signature Page
IN WITNESS WHEREOF, the Parties execute this Data Processing Agreement as of the date of the last signature below.
| CONTROLLER (Customer) | PROCESSOR (Moderaty operator) |
|---|---|
| Name / Company: ______________________________ | Name / Company: ______________________________ |
| CNPJ / Tax ID (if any): _______________________ | CNPJ: ______________________________________ |
| E-mail for notices: __________________________ | E-mail for notices: __________________________ |
| Signature: __________________________________ | Signature: __________________________________ |
| Name: _______________________________________ | Name: _______________________________________ |
| Title: ______________________________________ | Title: ______________________________________ |
| Date: _______________________________________ | Date: _______________________________________ |
Under Brazilian law this DPA may be executed electronically; acceptance of the Terms of Service incorporating this DPA also constitutes execution (Clause 17.1).
Annex I — Details of the Processing
| Item | Description |
|---|---|
| Subject matter | Automated moderation of YouTube comments on the Controller's channel(s), including hate-speech classification and execution of moderation actions via the YouTube Data API. |
| Duration | Term of the Controller's subscription to the Service, plus the 30-day deletion window of Clause 17.2. |
| Nature and purpose | Retrieval of comments; automated content-level classification (hate speech / abusive content); execution of the Controller-configured moderation action (hold, hide, remove, report); immediate discard of author identifiers after classification and action; retention of Moderation Outcome Data (including truncated comment text). |
| Categories of data subjects | Authors of comments on the Controller's YouTube channel(s). Comment authors are not age-identifiable and may include children or adolescents; all Comment Data is treated to the highest protection standard (Section 9). |
| Categories of personal data | Comment text; author display name / username; author channel identifier; comment identifier; timestamps. Author identifiers are processed transiently and never stored (Section 7). |
| Sensitive personal data | Comment content may incidentally reveal racial or ethnic origin, religious conviction, political opinion, health data, or data concerning sex life or sexual orientation, typically within hate speech itself. No extraction, profiling, or enrichment of sensitive attributes (Section 8). |
| Retention and deletion | Author identifiers: discarded immediately after classification and action. Moderation Outcome Data (including comment text truncated to 500 characters): retained for the subscription term, deleted within 30 days of termination. Statutory connection/application-access logs: 6 months (Marco Civil, Arts. 13 and 15), segregated, then auto-deleted. |
| Processing location | Processing operations are managed from Brazil; comment data transits YouTube/Google infrastructure and the sub-processors in Annex III (see Section 11 and Annex IV). |
Annex II — Technical and Organizational Measures
| Domain | Measure |
|---|---|
| Transmission security | Encryption in transit (TLS 1.2 or higher) for all connections to the YouTube Data API, sub-processors, and end-user sessions. |
| Access control | Least-privilege access to production systems; unique credentials; multi-factor authentication for administrative access; periodic access reviews. |
| Credential management | API keys, OAuth tokens, and secrets stored in a managed secrets store; never in source code or logs; rotation on personnel change or suspicion of compromise. |
| Data isolation | No use of production Comment Data in development or test environments; ephemeral processing buffers isolated per job. |
| Minimization by design | No persistent storage of comment author identifiers (Section 7); Moderation Outcome Data schema enforced at the application layer. |
| Logging and monitoring | Security event logging; alerting on anomalous access; statutory Marco Civil logs segregated, access-restricted, and auto-deleted after 6 months. |
| Incident response | Documented incident response plan aligned with the 3-business-day ANPD notification duty (Section 14); post-incident review. |
| Vendor management | Sub-processor due diligence and contractual flow-down (Section 10); annual review of Annex III. |
| Governance | Named data protection officer (encarregado) with publicly disclosed contact; RIPD maintained for the Service; records of processing activities kept current. |
Annex III — Authorized Sub-processors
| Sub-processor | Function | Location | Transfer mechanism (Art. 33 LGPD) |
|---|---|---|---|
| Google LLC (YouTube Data API) | Source platform: comment retrieval and moderation action execution | United States | ANPD SCCs (Annex IV), to the extent applicable to the API relationship |
| Netlify, Inc. | Application hosting and delivery (website, application, and serverless functions) | United States | ANPD SCCs (Annex IV) |
| OpenAI, LLC | Transient comment classification only; no retention; no training | United States | ANPD SCCs (Annex IV) |
| Turso (ChiselStrike, Inc.) | Database hosting for account data and Moderation Outcome Data | United States (primary); edge replicas: none currently enabled — a region may be enabled only after being recorded in this Annex III | ANPD SCCs (Annex IV) |
| [E-mail delivery provider] | Transactional e-mail (notices, receipts, security alerts) | [Region] | ANPD SCCs (Annex IV) if outside Brazil |
Additions or replacements follow the notice-and-objection procedure of Clause 10.1. Billing processors (currently Stripe, Inc. — United States) process the Controller's billing data on the Processor's behalf, for which the Processor is the controller (see the Privacy Policy); they receive no Comment Data and are outside the scope of this DPA.
Annex IV — International Transfer Mechanism (ANPD Standard Contractual Clauses)
IV.1 For each international transfer of personal data under this DPA that relies on standard contractual clauses, the Parties incorporate by reference the standard contractual clauses approved by ANPD Resolution CD/ANPD no 19/2024 (ANPD SCCs), which apply in full and prevail over any conflicting term of this DPA in respect of the transfer.
IV.2 For transfers to sub-processors, the Processor acts as data exporter and the sub-processor as data importer, with the ANPD SCCs executed between them; the Processor shall provide the Controller copies upon request.
IV.3 Where a transfer relies on another Article 33 mechanism (for example, an ANPD adequacy decision), Annex III records that mechanism, and this Annex IV applies only to transfers recorded as relying on the ANPD SCCs.
IV.4 The Parties acknowledge that standard contractual clauses of other jurisdictions (including EU SCCs) do not satisfy Article 33 of the LGPD and shall not be used as a substitute for the ANPD SCCs.