NeoTrip
/Privacy

Privacy Policy

Last updated: May 2026

1. Introduction

NEOTRIP TECNOLOGIA LTDA. ("NeoTrip", "we" or "our"), registered under CNPJ/ME No. 64.622.390/0001-14, committed to transparency and the protection of privacy, presents its Privacy Policy ("Policy"), in strict compliance with Brazilian Federal Law No. 13,709/2018 (General Personal Data Protection Law – "LGPD"), the Brazilian Internet Civil Rights Framework (Law No. 12,965/2014), Decree No. 8,771/2016, and the guidelines of the National Data Protection Authority (ANPD).

This Policy describes, in a clear and accessible manner, what personal data we collect, how we process it, with whom we share it, how long we store it, and what your rights are as a data subject.

2. Definitions (Art. 5 of the LGPD)

  • Personal Data: information relating to an identified or identifiable natural person.
  • Sensitive Personal Data: data concerning racial or ethnic origin, religious belief, political opinion, trade union membership, health or sex life data, genetic or biometric data.
  • Data Subject: the natural person to whom the personal data refers.
  • Controller: the party responsible for decisions regarding the processing of personal data.
  • Processor: the party that processes data on behalf of the controller.
  • Data Protection Officer (DPO): the person appointed by the controller to act as a communication channel with data subjects and the ANPD.
  • Processing: any operation carried out with personal data.

3. NeoTrip's Roles in Data Processing

Depending on the context, NeoTrip acts in different roles:

3.1. As CONTROLLER, when:

  • collecting data from visitors to our corporate website;
  • managing commercial leads;
  • hiring and managing employees and suppliers;
  • operating a direct relationship with end users (B2C, when applicable — e.g., a travel planning application).

3.2. As PROCESSOR, when processing personal data of guests and end users on behalf of its hotel clients (controllers), in accordance with contractual instructions and the applicable Data Processing Agreement (DPA).

    4. Data We Collect

    4.1. Data provided directly by You:

    • Full name;
    • Corporate and/or personal email;
    • Phone number;
    • Company/hotel and job title;
    • Content of messages sent via forms, chats, or emails.

    4.2. Data collected automatically:

    • IP address and approximate geolocation data;
    • Browser type and version, operating system, device;
    • Pages visited, time spent, clicks, scroll;
    • Cookie, pixel, and similar technology identifiers;
    • Access and activity logs.

    4.3. Data processed in the Platform's operation (B2B – as Processor). When NeoTrip operates for hotel clients, it may process guest data, including:

    • Name, email, phone, language;
    • Conversation history with AI agents (website/WhatsApp);
    • Stated preferences (room type, dates, number of guests);
    • Transactional data related to pre-bookings and reservations;
    • Data strictly necessary for processing, without collecting credit card information directly by NeoTrip, except when expressly contracted and with the adoption of PCI-DSS standards through an accredited payment gateway.

    4.4. Sensitive Data: NeoTrip does not intentionally collect sensitive data. Should the User voluntarily provide such data in conversational interactions (e.g., dietary restrictions for religious/health reasons), processing will occur solely for the purpose of fulfilling the stated request, based on applicable legal bases (Art. 11 of the LGPD).

    4.5. Children and Adolescents' Data: where processing occurs, the best interests of the child and adolescent will be observed (Art. 14 of the LGPD), with specific, prominent consent from at least one parent or legal guardian.

    5. Purposes and Legal Bases for Processing (Art. 7 and 11 of the LGPD)

    PurposeLegal Basis
    Responding to contact requests and commercial proposalsPreliminary procedures for entering into a contract (Art. 7, V)
    Executing contracted servicesPerformance of a contract (Art. 7, V)
    Fulfilling legal and regulatory obligations (tax, labor)Compliance with a legal obligation (Art. 7, II)
    Direct marketing, newsletters, contentLegitimate interest / Consent (Art. 7, IX and I)
    Usage analysis, product improvement, metricsLegitimate interest (Art. 7, IX)
    Training and improving NeoTrip's internal modelsLegitimate interest, with prior anonymization or pseudonymization
    Fraud prevention and securityLegitimate interest (Art. 7, IX) and credit protection (Art. 7, X)
    Responding to authority requestsCompliance with legal obligation and exercise of legal rights (Art. 7, II and VI)

    5.1. NeoTrip does not use identifiable personal data of end guests to train generalist AI models without the express instruction of the controller hotel client.

    6. Data Sharing

    NeoTrip does not sell personal data. Sharing occurs only with:

    • Cloud infrastructure providers (e.g., AWS, Google Cloud), located in Brazil or abroad;
    • Language model providers (Anthropic – Claude, Google – Gemini, OpenAI – ChatGPT), solely for processing conversational interactions, under contracts that prohibit the use of data for the providers' own training, wherever technically feasible;
    • WhatsApp Business BSP partners (e.g., 360dialog, Meta), to enable WhatsApp integration;
    • Hotel clients, in the case of end guest data, in accordance with the contracted purpose;
    • Service providers (legal, accounting, anti-fraud, email marketing), under contractual confidentiality and security obligations;
    • Public authorities, upon a duly grounded legal request;
    • Acquirers or successors, in the event of corporate restructuring, merger, acquisition, or asset sale, while maintaining the original processing purpose.

    7. International Data Transfer

    7.1. NeoTrip's operations may involve the international transfer of personal data to countries where our technology providers are based (notably the United States and the European Union).

    7.2. Such transfers comply with Art. 33 of the LGPD, through:

    • adoption of standard contractual clauses;
    • ensuring a level of protection compatible with the LGPD;
    • performance of a contract with the data subject or preliminary procedures;
    • compliance with specific legally provided grounds.

    8. Retention and Deletion

    8.1. Personal data will be retained for as long as necessary to fulfill its purposes, subject to the following minimum periods:

    • Access logs: 6 (six) months (Art. 15 of the Internet Civil Rights Framework);
    • Registration and contractual data: during the term of the contract and for up to 5 (five) years after its termination (civil statute of limitations – Art. 206, §5, I, Civil Code);
    • Tax data: 5 (five) years (Art. 173, Tax Code);
    • Employment data: up to 5 (five) years after termination.

    8.2. After the applicable periods, data will be securely deleted or anonymized, except as provided in Art. 16 of the LGPD.

    9. Data Subject Rights (Art. 18 of the LGPD)

    You may, at any time, request:

    • confirmation of the existence of processing;
    • access to your data;
    • correction of incomplete, inaccurate, or outdated data;
    • anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data;
    • data portability;
    • deletion of data processed with your consent;
    • information about data sharing;
    • information about the possibility of withholding consent;
    • revocation of consent;
    • review of automated decisions that affect your interests (Art. 20 of the LGPD).

    9.1. To exercise your rights, contact the Data Protection Officer at dpo@neotrip.ai. We will respond to your request within the legal period of up to 15 (fifteen) days.

    9.2. For requests relating to data processed on behalf of hotel clients (as processor), we will redirect the request to the respective controller, notifying them of your request.

    10. Automated Decisions and AI

    10.1. NeoTrip uses artificial intelligence to suggest accommodations, answer questions, guide users through the booking process, and personalize interactions.

    10.2. Such processes do not replace relevant human decisions affecting data subject rights. The user may, at any time, request human assistance and review of any automated decision that affects them, pursuant to Art. 20 of the LGPD.

    11. Information Security

    NeoTrip adopts technical and organizational measures consistent with the state of the art, including:

    • encryption in transit (TLS 1.2+) and at rest;
    • access control with least privilege;
    • multi-factor authentication for administrative access;
    • continuous monitoring, backups, and business continuity plans;
    • periodic vulnerability testing and penetration tests;
    • employee training;
    • incident response policy with notification to the ANPD and data subjects, where applicable (Art. 48 of the LGPD).

    12. Cookies

    12.1. The Site uses essential, analytical, performance, and marketing cookies. Users may at any time manage their preferences through the consent banner or their browser settings.

    12.2. Disabling essential cookies may impair the proper functioning of the Site.

    13. Marketing and Relationship Communications

    13.1. NeoTrip may use your contact data to send marketing, relationship, and commercial nurturing communications, including:

    • promotion of NeoTrip Platform products, services, modules, and features;
    • newsletters, educational content, industry reports, and rich materials on hospitality, technology, and AI;
    • invitations to events, webinars, workshops, and demonstrations;
    • satisfaction surveys, NPS, and market studies;
    • promotions, special commercial conditions, and offers aligned with the recipient's profile;
    • institutional communications (product updates, news, success stories).

    13.2. Applicable legal bases. Marketing communications will follow the appropriate legal basis according to context:

    • Legitimate interest (Art. 7, IX of the LGPD), in B2B relationships with active clients, qualified leads, and professionals who have expressed interest in NeoTrip content, subject to a balancing test and respect for the data subject's legitimate expectations;
    • Consent (Art. 7, I of the LGPD), free, informed, unambiguous, and granular, whenever the audience is B2C, the communication is outside a professional context, or when required by specific legislation.

    13.3. Clear identification of communications. All communications of an advertising or promotional nature will be clearly, prominently, and unambiguously identified as such, in compliance with Art. 36 of the Brazilian Consumer Protection Code, avoiding any form of covert, disguised, or misleading advertising.

    13.4. Right to unsubscribe (opt-out). In all marketing communications sent, NeoTrip will provide:

    • a functional, free, easy-to-access, and visible unsubscribe link, placed prominently;
    • a simple mechanism requiring no more than one reasonable step to complete;
    • a maximum period of 5 (five) business days to effectively remove the recipient from the marketing communications list, counted from the receipt of the request;
    • confirmation of unsubscription, where technically feasible.

    13.5. Effects of unsubscribing. Exercising the opt-out for marketing communications does not affect:

    • the sending of transactional and operational communications essential to the performance of an ongoing contract (invoices, service alerts, security notifications, incident-related communications, contractual updates);
    • the sending of communications required by law or a competent authority;
    • other data processing carried out on a different legal basis.

    13.6. Preference granularity. Wherever technically feasible, NeoTrip will offer a preference center allowing data subjects to choose which categories of communication they wish to receive (e.g., educational content only, product news only, events only), ensuring granular control over their communications.

    13.7. Third-party marketing. NeoTrip does not sell, rent, assign, or share contact data with third parties for their own marketing purposes, except for the use of service providers (email marketing tools, CRM, automation) who act exclusively as processors, under contractual confidentiality and security obligations, without the right to independently use the data.

    13.8. Multi-channel communications. The provisions of this section apply to communications sent by email, SMS, WhatsApp, phone, push notifications, and other channels, subject to:

    • the specific rules of the WhatsApp Business Policy regarding qualified opt-in;
    • Meta's policies (WhatsApp Business Messaging Policy);
    • any applicable sector-specific regulations.

    13.9. Specific channel for marketing complaints. Requests, questions, or complaints regarding the receipt of marketing communications may be directed to the Data Protection Officer (dpo@neotrip.ai) or the specific privacy channel (privacidade@neotrip.ai). NeoTrip will make its best efforts to respond within no more than 15 (fifteen) days, pursuant to Art. 19 of the LGPD.

    14. Data Protection Officer (DPO)

    NeoTrip Tecnologia LTDACNPJ: 64.622.390/0001-14Email: dpo@neotrip.aiAvenida Brigadeiro Faria Lima, 1,912, 12th floorSão Paulo – SP, Brazil

    15. Amendments and Final Provisions

    This Policy may be updated periodically; the current version is always the one available at https://www.neotrip.ai/privacidade. In case of conflict, Brazilian law prevails, and the courts of the City of São Paulo/SP are elected as the competent forum.