This Privacy Policy describes how Wabot CRM Pro, a platform operated by Web Infinite Marketing e Serviços Digitais Ltda, collects, uses, shares, protects and deletes personal data. It applies to the app.wabot.app.br website, the web application, our APIs, the messaging channel integrations and the artificial intelligence features of the platform.
This document follows Brazilian Law No. 13,709/2018 (Lei Geral de Proteção de Dados — LGPD) and observes the requirements of the platforms we integrate with, including Meta’s policies for the WhatsApp Business Platform and for Instagram.
1. Who is responsible for processing
| Legal entity | Web Infinite Marketing e Serviços Digitais Ltda |
| Company registration (CNPJ) | 43.517.824/0001-46 |
| Address | Venâncio Aires/RS, Brasil |
| Product | Wabot CRM Pro (app.wabot.app.br) |
| Data Protection Officer | contato@wabot.app.br |
| Privacy contact | contato@wabot.app.br |
2. Our two roles: controller and processor
This is the most important distinction in this document. Wabot CRM Pro is a B2B platform: our users are businesses that use the system to serve their own customers. As a result, we process data in two different capacities.
2.1. As a controller
We act as controller for the data of those who subscribe to and use the platform — the account holder, its administrators and its agents. We determine the purposes and means of processing this account, billing, support, security and usage data.
2.2. As a processor
We act as processor for the data of the end contacts and customers that each business manages inside the platform — contacts, conversations, messages, files, tags, service history and campaigns. That data belongs to our customer, who is its controller. We process it solely under the customer’s instructions and as needed to provide the service.
In practice: if you are a consumer who messaged a business on WhatsApp and you want to access or delete your messages, your request should first be addressed to that business, which controls the data. You may still write to us at contato@wabot.app.br and we will forward the request to the responsible customer and support the process on our side.
3. Data we process
3.1. Account and registration data (we are the controller)
- Full name, email address and mobile phone number in international format.
- Password, stored solely as a cryptographic hash — never in readable form.
- Subscription plan, usage limits, AI credits and subscription status.
- Email verification records and welcome communications.
- Additional users (agents) created by the account holder.
3.2. Technical, usage and security data
- Access and authentication records, IP address and browser or device information.
- Audit records of relevant actions performed within the system.
- Technical logs of errors, performance, processing queues and channel connection status.
- Credentials and sessions of the messaging channels connected by the customer, stored encrypted and used only to keep the channel operating.
- Anti-fraud signals collected on the login and sign-up screens to block bots.
3.3. Service data processed on behalf of the customer (we are the processor)
- Contacts: name, phone number, profile identifiers and custom fields.
- Conversation content: text messages, images, audio, video and documents exchanged between the business and its contacts, with timestamps and delivery status.
- Service organisation: tags, internal notes, agent assignment, sales pipeline stage and activity history.
- Product catalogue, bulk messaging campaigns, automations and schedules created by the customer.
3.4. Data received from Meta platforms
When a customer connects an official channel, we receive from Meta only what is required to operate the service: business account and connected number or profile identifiers, access tokens, the content of messages received and sent, the sender’s display name and identifier, and status events such as delivery, read receipts and send failures.
3.5. Data we do not collect
We do not request or collect, on our own initiative, sensitive data as defined in article 5, II of the LGPD — racial or ethnic origin, religious belief, political opinion, trade union membership, health data, sex life, genetic or biometric data. If a customer’s contact spontaneously sends such information within a conversation, it is stored as part of the message, under the responsibility of the controlling customer.
We also do not use advertising tools, remarketing, tracking pixels, heatmaps or third-party analytics in the product.
4. Where the data comes from
- Directly from you, at sign-up, while using the system and when contacting support.
- From your use of the platform, through automatically generated technical records.
- From Meta platforms, when the customer connects an official channel.
- From the messaging channels the customer connects to the platform.
- From imports and integrations the customer configures, such as contact spreadsheets, WooCommerce stores and billing systems.
5. Why we use the data and on what legal basis
| Purpose | Legal basis (LGPD) |
|---|---|
| Create and maintain the account, authenticate access and deliver the contracted service | Performance of a contract (art. 7, V) |
| Send and receive messages on the channels connected by the customer | Performance of a contract (art. 7, V) |
| Process contacts, conversations and campaigns on behalf of the customer | Instruction of the controlling customer (art. 39) |
| Run artificial intelligence agents when enabled by the customer | Performance of a contract (art. 7, V) |
| Send operational communications: email verification, channel disconnection alerts, plan expiry and service changes | Performance of a contract (art. 7, V) |
| Ensure security, prevent fraud and abuse, keep audit records | Legitimate interest (art. 7, IX) and legal obligation (art. 7, II) |
| Diagnose failures, measure performance and improve the platform | Legitimate interest (art. 7, IX) |
| Comply with legal and regulatory obligations and orders from competent authorities | Legal obligation (art. 7, II) and regular exercise of rights (art. 7, VI) |
| Send commercial communications about product news | Consent (art. 7, I), revocable at any time |
We do not sell personal data and we do not transfer it to third parties for advertising or commercial profiling.
6. WhatsApp and Instagram integrations
6.1. WhatsApp Business Platform (Meta official API)
When a customer connects the official API, Wabot CRM Pro acts as a service desk tool on top of the customer’s own business account. The permissions requested during connection are limited to what is necessary for the purposes below:
| What the access is for | What we do with it |
|---|---|
| WhatsApp Business account management | Identify the connected account and phone number, register the inbound webhook, and read or create the message templates used by the customer. |
| Sending and receiving messages | Receive messages addressed to the customer’s number and send the replies written by the support team or by the AI agent the customer configured. |
| Business account linkage | Associate the channel with the correct account during connection and keep the credential valid. |
We do not use this access to collect data unrelated to customer service, to build a contact database of our own, or for any advertising purpose.
6.2. Instagram
The Instagram integration is under development and is not yet available to customers. Once enabled, it will be used to reply to direct messages and comments received on the professional profile the customer connects, under the same treatment described in this policy for WhatsApp: we receive only the content of the messages or comments, the identifier and display name of the person interacting, and use them to display and answer the conversation inside the system. No Instagram data will be used for advertising, resale or database enrichment.
6.3. Compliance with Meta policies
The use of data obtained through Meta platforms complies with the applicable WhatsApp Business terms, Meta’s platform policies and the resulting data use rules. It is the customer’s responsibility to ensure a legitimate contact basis, respect messaging windows and content rules, and refrain from using the channels for unsolicited messages.
7. Artificial intelligence
When a customer enables an AI agent, the content required to generate the reply is sent to the language model provider — currently OpenAI. This may include the text of the ongoing conversation, the instructions configured by the customer, product catalogue data and, where the feature is enabled, the transcription of incoming audio messages.
- The feature is optional and remains off until the customer enables it.
- The customer can disable AI globally, per channel or per individual conversation.
- The customer may use their own provider API key, in which case processing takes place under their own account with that provider.
- AI-generated replies may contain inaccuracies; the customer is responsible for supervising usage and defining the agent’s operating limits.
We do not use customer conversation content to train artificial intelligence models of our own.
8. Who we share data with
We share data only with providers necessary to operate the service, strictly to the extent required, under confidentiality and security obligations:
| Provider | Function | Processing location |
|---|---|---|
| Supabase | Database, authentication and file storage | United States |
| Meta Platforms | WhatsApp Business Platform and, in the future, Instagram | United States and other countries |
| OpenAI | Language models, audio transcription and catalogue search | United States |
| Resend | Transactional email delivery | United States |
| Cloudflare | Bot protection on login and sign-up screens | Global network |
| Cloud infrastructure provider | Hosting of the application servers | Outside Brazil |
In addition, the customer may enable optional integrations such as WooCommerce stores or billing systems. In those cases the sharing results from the customer’s own configuration and is also governed by the integrated service’s policy.
We may also share data with public authorities where required by law, court order or the regular exercise of rights, and with legal and accounting advisers bound by confidentiality.
9. International data transfers
As shown in the table above, part of the processing takes place on servers located outside Brazil, mainly in the United States. These transfers are necessary for the performance of the contract entered into with the customer, under article 33, II, (d) of the LGPD, and are carried out with providers that adopt contractual clauses and security measures consistent with the level of protection required by Brazilian law.
10. Cookies and browser storage
Wabot CRM Pro does not use advertising, tracking or third-party analytics cookies. We use only what is strictly necessary for operation:
- Browser local storage: holds the session token and interface preferences such as light or dark theme. It is cleared on sign-out.
- Technical administrative session cookie: a protected cookie restricted to authentication routes, used only when an administrator accesses an account to provide support, so that the original session can be safely restored.
- Bot protection: the check on the login and sign-up screens may store temporary technical identifiers from that protection provider.
11. How long we keep data
| Category | Retention period |
|---|---|
| Account and registration data | For as long as the account exists and up to 5 years after closure, for defence in potential disputes and compliance with legal obligations |
| Contacts, conversations, messages and files | While the account is active or until the customer deletes them; after account closure, deleted as described in section 12 |
| Channel and integration credentials | Deleted when the channel is disconnected or the account is closed |
| Access and audit logs | Up to 6 months, in line with article 15 of the Brazilian Internet Civil Framework, or longer where required by law |
| Tax and billing records | For the periods required by applicable tax legislation |
12. Data deletion
When a channel is disconnected, that channel’s data — including credentials, sessions and associated files — is removed from our systems. When an account is closed, operational data is deleted or anonymised, except for what we must retain for the periods described above.
Detailed instructions for requesting removal, including what to include in the request and the response times, are available on the Data Deletion page. Requests may also be sent directly to contato@wabot.app.br.
13. Information security
- Traffic encrypted in transit via HTTPS/TLS.
- Passwords stored only as hashes; integration credentials and channel sessions stored encrypted.
- Logical isolation between accounts: each account can access only its own data.
- Role-based access control, token authentication with expiry, and audit logging of administrative actions.
- Availability monitoring, rate limiting and protection against abusive automation.
- Periodic database backups.
No internet-connected system is entirely immune to incidents. Should a security incident occur with relevant risk to data subjects, we will notify the affected customers and the Brazilian National Data Protection Authority under article 48 of the LGPD.
14. Your rights as a data subject
The LGPD grants you the right, at any time and free of charge, to:
- confirm whether we process data about you and access it;
- correct incomplete, inaccurate or outdated data;
- request anonymisation, blocking or deletion of unnecessary data or data processed in breach of the law;
- request portability to another provider;
- obtain information about who we share your data with;
- withdraw consent, where consent is the applicable legal basis;
- object to processing based on legitimate interest;
- lodge a complaint with the Brazilian National Data Protection Authority.
To exercise any of these rights, write to contato@wabot.app.br. We may request additional information to confirm your identity before fulfilling the request — this verification exists to protect you. We will respond within 15 days of receiving a complete request.
If your request concerns data processed by a business customer of the platform, section 2.2 applies: we will forward the request to the controlling business and support its handling.
15. Children and adolescents
The platform is intended for professional use and is not directed at people under 18. We do not create accounts for minors nor knowingly collect their data. If we become aware that a child’s or adolescent’s data has been entered without proper legal grounds, we will take appropriate steps to delete it.
16. Customer responsibilities
By using Wabot CRM Pro, the customer undertakes to:
- hold an adequate legal basis to process the data of the contacts it enters into the platform;
- keep its own privacy policy available to its contacts;
- not use the channels for unsolicited messages or in breach of Meta’s rules and applicable law;
- safeguard access credentials and its own team’s permission profiles;
- respond, as controller, to data subject requests concerning the data it manages.
17. Changes to this policy
This policy may be revised to reflect legal, regulatory, operational or product changes. The version in force is always the one published on this page, with the last updated date shown at the top. Material changes will be communicated to customers through the registered contact channels, with reasonable notice whenever possible.
Version in force: August 5, 2026.
18. Contact
Questions, requests and complaints regarding privacy and data protection should be addressed to our Data Protection Officer:
- Data Protection Officer: contato@wabot.app.br
- Email: contato@wabot.app.br
- Controller: Web Infinite Marketing e Serviços Digitais Ltda — CNPJ 43.517.824/0001-46
- Address: Venâncio Aires/RS, Brasil
This is a translation provided for convenience and for app review purposes. The authoritative version is the Portuguese one, available at app.wabot.app.br/politica-de-privacidade. In the event of any discrepancy, the Portuguese version prevails.