Atendimento 24/7
Resposta imediata a qualquer hora, sem escalar o time nem a fila noturna.
How Cortex collects, uses, shares and protects personal data, in compliance with the LGPD (Lei nº 13.709/2018, Brazil's General Data Protection Law).
This Policy explains, in plain language, how Cortex collects, uses, shares and protects personal data related to:
Cortex acts predominantly as a B2B provider of technology, automation and digital service via WebChat. In some situations it is a Controller (for example, marketing and relationship management) and, in others, a Processor for clients (handling data according to contractual instructions in integrations and support). When we act as a Processor, the Agreement and the DPA prevail as signed with the client.
How to identify Cortex's role in the processing of your data: (i) if you used the Cortex institutional website or WebChat directly, Cortex is the Controller; (ii) if you used the WebChat embedded in a B2B client's product or service, the client is the Controller and Cortex is the Processor. If in doubt, contact dpo@thecortex.digital and the request will be forwarded to the correct Controller within 5 business days.
The terms below have the meaning assigned by the Lei Geral de Proteção de Dados (Lei nº 13.709/2018, LGPD) and are used throughout this document:
Personal data, sensitive data, data subject, processing, Controller, Processor, Data Protection Officer (DPO), Autoridade Nacional de Proteção de Dados (ANPD, Brazil's Data Protection Authority), RIPD (Data Protection Impact Report), TIA, cookies and similar technologies, solely automated decision-making and profiling.
We collect the minimum necessary for each purpose, always in a transparent and proportionate manner.
Log retention: 6 to 12 months according to the Agreement and SLA.
Cortex does not intentionally collect sensitive data or data of minors through its institutional channels.
If, by client instruction, it becomes necessary to process sensitive data in a B2B context, the conditions will be set out in the applicable DPA.
We process data according to the legal bases of the LGPD (art. 7): consent, performance of a contract, legal/regulatory obligation, legitimate interest, credit protection and the regular exercise of rights.
Summary of purposes:
| Purpose | Description | Legal basis |
|---|---|---|
| Operation and security of the website and WebChat | Ensure operation, prevent fraud, maintain availability and respond to incidents. | Legitimate interest and legal obligation (technical records). |
| Service and commercial relationship | Respond to contacts, send proposals and schedule meetings. | Performance of a contract or preliminary procedures; legitimate interest. |
| Optional marketing and communication | Sending newsletters, invitations and materials upon opt in. | Consent (opt in) or legitimate interest with opt out. |
| Product improvement and analytics | Analyze usage metrics, performance and usability of the WebChat. | Legitimate interest; consent for analytical cookies. |
| B2B support and WebChat-only operation | Run Atena and Apolo services in WebChat as per contract. | Performance of a contract; DPA. |
The website and the WebChat use cookies and similar technologies to ensure performance and security.
The categories and purposes are described in the Cookie Policy.
Users can accept, reject or configure preferences via the banner and Preference Center.
Marketing events and campaign measurement linked to the website or the WebChat occur only with marketing consent when they involve non-essential cookies.
Data may be shared with third parties strictly necessary for operation:
Cortex does not sell personal data.
In the event of a merger, acquisition or reorganization, the processing will follow the safeguards of this Policy.
Some providers operate outside Brazil.
When analytics is consented to, Google Analytics (Google LLC) may process events on international infrastructure, including the United States. Google Analytics 4 does not store IP addresses, and the retention period configured on the landing page property is 14 months.
For these cases, Cortex adopts standard contractual clauses, performs a TIA (Transfer Impact Assessment) and applies encryption and strict access controls.
When we act as a Processor, the transfer details are set out in the client's DPA.
We adopt administrative, technical and physical controls to protect data and communications:
These controls are detailed in the Security White Paper (Annex V).
We keep data for as long as necessary for the purposes or for legal and contractual periods.
Afterward, we delete, anonymize or archive it with access restriction.
General guidelines:
Deletion requests will be honored when there is no retention obligation.
Data subjects may request:
How to exercise them: send an email to dpo@thecortex.digital with the subject “LGPD Data Subject Rights”.
Cortex may request identity validation.
Response time: up to 15 days (extendable in complex cases).
If the data is processed on behalf of a B2B client, the request will be forwarded to the corresponding Controller.
The data subject may also petition the ANPD.
Cortex may operate automated flows under the instruction of the B2B client (for example, KYC, withdrawal screening, ticket classification). When these flows result in a decision with relevant effects on the data subject, the right to review by a natural person is ensured upon formal request to the DPO (dpo@thecortex.digital) or to the Controller of the corresponding operation, pursuant to art. 20 of the LGPD.
On the Cortex institutional website and the public WebChat, no solely automated decisions are made that produce legal effects on visitors.
The website and the channels are not intended for children (up to 12 years old) or adolescents (up to 18 years old) without the specific consent of at least one parent or legal guardian, pursuant to art. 14 of the LGPD.
Should we identify data of minors without an adequate legal basis, we will carry out secure deletion and notify the B2B Controller client, where applicable.
The privacy program includes:
These controls are part of Annexes III, IV and V of the Agreement.
This Policy may be updated due to legal, technical or business changes.
The current version is always available on the website, with its update date.
Relevant changes may be communicated through a notice on the website.
This Policy is part of Annex IV, Public Policies of the Agreement; in case of conflict, the Agreement prevails.
The Atena and Apolo agents operate in a WebChat-only model, with sessions and messages processed in the WebChat as per the Agreement and DPA.
When Cortex acts as a Processor, the DPA and the other annexes apply.
| Activity | Data category | Purpose | Legal basis | Retention | Sharing | International transfer |
|---|---|---|---|---|---|---|
| Website and WebChat browsing | IP, user agent, session, essential cookies | Operation and security | Legitimate interest; legal obligation | 6 to 12 months | Cloud, security and monitoring | Possible, with clauses and encryption |
| Analytics (if consented) | Analytical identifiers | Measure audience and performance | Consent | According to tool | Analytics providers | Possible, with safeguards |
| Contact form | Name, email, phone, company, message | Respond to commercial requests | Performance of a contract or legitimate interest | Up to 24 months | CRM, email, support | Possible, with safeguards |
| WebChat sessions | Session IDs, origin, logs, conversation content | Service, KYC, support | Performance of a contract; DPA | Contractual term plus up to 12 months | Sub-processors (cloud, CDN, WebChat, LLM) | Possible, with DPA and TIA |
| B2B support | Technical contacts, logs, attachments | Diagnosis and resolution of incidents | Performance of a contract | During the contract | Technical tools | Possible, as per DPA |
| Operation as a Processor | Data defined by the client | Processing under instruction | Performance of a contract (client Controller) | As per DPA | Approved sub-processors | As per DPA/TIA |
A Atena atende o jogador no WebChat logado, responde a partir da base de conhecimento aprovada pelo operador e escala para o humano quando o caso exige julgamento.
Meu saque ainda não caiu.
Saque de R$ 500 aprovado às 14h32. O banco libera em até 2 horas.
Perfeito, obrigado!
O caso que pede julgamento chega pronto ao humano.
Resposta imediata a qualquer hora, sem escalar o time nem a fila noturna.
Cada resposta nasce da base de conhecimento aprovada pelo operador.
Jogo responsável e autoexclusão seguem a política que você define sob a Lei 14.790/2023. A Cortex aplica em toda conversa e registra que aplicou.
O caso sensível sobe para o humano com o contexto inteiro da conversa junto.
O jogador é atendido a qualquer hora no WebChat logado, com o mesmo tom e o mesmo critério — sem depender de quem está de plantão.
Seu limite de depósito está em R$ 300 por semana. Para reduzir, te passo agora para uma pessoa da equipe.
A Atena responde a partir da base aprovada do operador e consulta Deméter e Nêmesis antes de falar. Nada de improviso em saque, limite ou bônus.
Cada decisão vai para log WORM com hash encadeado e PII redigida, retido por cinco anos. Quando o regulador perguntar, a prova já está montada.
São seis os gatilhos que levam a conversa ao humano: jogo responsável, crise emocional, ameaça regulatória, falha de resolução, pedido explícito do jogador e limite sem resolução na conversa. O caso chega ao operador com o contexto inteiro, sem repetir pergunta.
Plugamos a Atena no WebChat e no backoffice que você já roda hoje.
As regras da casa viram comportamento: tom, limite, alçada e base de conhecimento.
Go-live acompanhado por 15 dias, com métrica de resolução e escalonamento à vista.
A esteira de implantação leva de 15 a 30 dias úteis, contados a partir da entrega dos seus acessos e integrações. O go-live tem 15 dias de hypercare acompanhado.
Não. A Atena responde ao volume repetitivo dentro da regra aprovada e leva ao humano os casos que pedem julgamento. O time entra com o contexto da conversa e a evidência já reunida: crise emocional, risco regulatório, exceção de contrato ou pedido do jogador.
Toda decisão vai para um log de escrita-só: o banco não aceita alterar nem apagar linha já gravada, cada registro carrega o hash do anterior, e adulterar um deles quebra a cadeia inteira — o que torna a alteração detectável, não impossível. A PII vai redigida, a retenção é de cinco anos e, ao fim dela, o dado é descartado como manda a LGPD. A trilha é exportável para auditoria.
Não. A Atena sobe sobre o WebChat e o backoffice que você já opera. A integração é por API e evento, sem trocar de stack.
A Atena aplica a política da Nêmesis: detecta sinal de risco na conversa, encaminha limite, pausa e autoexclusão, e aciona o CVV 188 em caso de crise. Base: Lei 14.790/2023 e normas da SPA/MF (Secretaria de Prêmios e Apostas do Ministério da Fazenda).
Por crédito — 1 crédito equivale a 1 resposta da Atena. Cada plano inclui mensalidade, setup igual à mensalidade e um pool mensal de créditos. O consumo acima do pool vira recarga.
Os agentes pausam, todos, inclusive os de compliance, até a recarga. Nenhuma conversa é cortada no meio: o que já começou termina, e o seu time humano continua atendendo pelo Backoffice, porque atendimento de pessoa não consome crédito. O consumo é medido por ciclo e por agente e fica consultável a qualquer momento. O operador recebe alertas automáticos quando o consumo alcança 80%, 95% e 100% do pool contratado. A obrigação legal de jogo responsável e de prevenção à lavagem de dinheiro segue sendo do operador, com ou sem crédito.