Skip to main content
AutoAgency
X-Ray
Legal · Authorities

Government requests

In force since July 19, 2026

1. Why this policy exists

This page describes what AutoAgency does when a law enforcement, judicial, administrative or regulatory authority — Brazilian or foreign — requests personal data or content. It applies to every such request and has been in force since July 19, 2026, under the responsibility of UnboundSales (AutoAgency), in Brazil.

Context that sets the scope: AutoAgency is a B2B platform. The data we handle belongs, for the most part, to our customers and to their customers. In most cases we are processors, not the data owners — and that changes who should answer the request.

2. Legitimacy — we do not act on informal requests

We only act on requests that arrive through an official channel and in writing, identifying the authority, the case or investigation, the legal basis and the exact scope of the data.

  • We do not act on verbal requests, phone calls, messaging apps, personal email, or requests from someone claiming to be an authority without proof. Such contact is answered with directions to the official channel — and it is recorded.
  • A request from a foreign authority is only honored when it arrives through the applicable legal cooperation channels. An authority outside Brazil has no standalone power to compel data we process in Brazil.

Before any disclosure, we verify that the authority has jurisdiction over that request and that the order in fact reaches the data being asked for.

3. Minimization — we disclose the minimum, never the database

We disclose only the data specifically described in the order, for the people and the time period it delimits. We refuse, and challenge where necessary:

  • generic requests, with no person or time scope (“all data”, “all users”, “everything you have”);
  • requests for direct, continuous or automated access to our systems;
  • requests reaching data of third parties unrelated to the investigation.

When a request targets data belonging to a customer of ours, the rule is to direct the authority to that customer, who is the controller of that data — unless the order is expressly addressed to us and does not allow that redirection. And we do not create data that does not exist: we build no new report, correlation or analysis to satisfy a request.

4. Challenge — we push back on what is excessive

With legal support, we seek clarification or file an objection against any request that is excessive, generic, disproportionate, without a clear legal basis, or outside the jurisdiction of the requesting authority.

  • We notify the affected individual and/or customer whenever possible, so they can mount their own defense.
  • We withhold notice only when secrecy is imposed by law or by court order — and in that case we revisit notification as soon as the secrecy lapses.
  • Secrecy about the existence of a request is honored only when expressly imposed, and for as long as it is imposed. We do not presume secrecy.

5. Recordkeeping — every request is documented

Every request received is recorded, whether honored or not, with:

  • date received and channel of entry;
  • requesting authority and case or investigation;
  • legal basis invoked and scope requested;
  • decision taken (fully honored, partially honored, challenged, refused, redirected to the customer) and its rationale;
  • exactly what data was disclosed, when and to whom;
  • whether the individual or customer was notified, or the grounds for secrecy.

Records are retained for at least 5 years, and they are the input for any transparency report we may publish.

6. How a request reaches us

Official channel: contato@autoagencia.io, addressed to UnboundSales — AutoAgency.

Whoever receives it does not decide alone: every request is escalated to legal responsibility before any answer or disclosure. No member of the team, and no automated system, discloses data to an authority without that step.

7. Processors involved

Part of the infrastructure is operated by third parties, which may receive requests directly and answer under their own policies: Cloudflare, Inc. (edge and execution), Supabase, Inc. (database) and Clerk, Inc. (authentication) — all operating in the US and Brazil.

8. Review

This policy is reviewed at least once a year, or sooner if there is a relevant legal or infrastructure change.