Courtesy translation. This document was translated from Portuguese for convenience. It describes obligations under Brazilian law, notably Law No. 13,709/2018 (LGPD), and is not a notice under the GDPR or any other foreign regime. In the event of any divergence, the Portuguese version prevails and is the only binding one: datago.com.br/politica-de-privacidade.html.
1. Who we are and who this Policy applies to
DATAGO TECNOLOGIA LTDA, a Brazilian limited liability company registered with the CNPJ/MF under No. 30.728.220/0001-05, with its head office at Rua Amado Almeida, 77, Floor 3, Glória, São Gabriel da Palha, Espírito Santo, CEP 29.780-000, and a branch at Rua Victorino Cardoso, 235, Sala 04, Andar 01, Jardim Camburi, Vitória, Espírito Santo, CEP 29.090-820, Brazil, hereinafter "Datago", "we" or "our", is the Controller responsible for this Privacy Policy.
Official contact: contato@datago.com.br · +55 (27) 99997-0276
This Policy explains how we collect, use, store, share, protect and erase personal data in the context of:
- our institutional website, blog and other digital channels;
- our commercial, contractual and support relationship;
- the services we provide, including but not limited to Salesforce CRM implementation and support, Tableau BI implementation, and the Nitzap, Data Mining, Xrep and Super Kanban applications;
- our participation in events, trade fairs and marketing activities;
- our interactions on social media profiles.
This Policy observes Brazilian Law No. 13,709/2018 (LGPD), Law No. 12,965/2014 (Brazilian Internet Civil Framework), Decree No. 8,771/2016, the resolutions and guidance of the Brazilian National Data Protection Authority (ANPD) and, on a subsidiary basis, the Consumer Protection Code (Law No. 8,078/1990).
Nothing in this Policy limits, in any way, the rights the law grants to the data subject.
1.1. Territorial application
Under art. 3 of the LGPD, this Policy applies to any processing operation carried out:
- in Brazilian territory;
- whose purpose is to offer or supply goods or services to individuals located in Brazil, or the processing of data of individuals located in Brazil;
- whose personal data was collected in Brazilian territory.
This applies regardless of the country where Datago, its suppliers or its servers are based.
2. Definitions
| Term | Meaning |
|---|---|
| Data subject | The natural person to whom the personal data relates. |
| Personal data | Information relating to an identified or identifiable natural person. |
| Sensitive personal data | Data on racial or ethnic origin, religious belief, political opinion, membership of a trade union or of a religious, philosophical or political organisation, data concerning health or sex life, genetic or biometric data. |
| Anonymised data | Data relating to a data subject who cannot be identified, considering the use of reasonable and available technical means. It is not considered personal data (art. 12 of the LGPD). |
| Processing | Any operation carried out with personal data: collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, erasure, evaluation, modification, communication, transfer, dissemination or extraction. |
| Controller | The natural or legal person responsible for decisions regarding the processing. |
| Processor | The natural or legal person who carries out the processing on behalf of the controller. |
| Sub-processor | A third party engaged by the processor to assist in carrying out the processing. |
| Data Protection Officer (DPO) | The person appointed to act as the channel of communication between the controller, the data subjects and the ANPD. |
| Client | The legal entity that has a contractual relationship with Datago. |
| End User | The natural person who interacts with a Client through Datago's solutions (for example, someone who converses with a company via Nitzap). |
3. Our two roles: Controller and Processor
This is the point that defines the scope of this Policy.
3.1. When Datago acts as Controller
When we decide the purposes and means of the processing. This is the case for the data of:
- visitors to our website, blog and digital channels;
- leads, prospects and commercial contacts, including those obtained from public sources and third parties;
- representatives and contacts of clients, suppliers and partners;
- participants in events and marketing activities;
- people who contact us through support, chatbot, email, telephone or WhatsApp;
- job applicants and employees (covered by a specific internal policy).
This Policy fully governs that processing.
3.2. When Datago acts as Processor
When we process personal data on behalf of and under the documented instructions of a Client, within that Client's technology environment. This is the case for data that passes through or resides:
- in the Client's Salesforce org, during implementation, support or maintenance projects;
- on the Nitzap platform, as regards the storage and transmission of WhatsApp conversations between the Client and its End Users, according to the contracted deployment model described in Section 3.3;
- in the Data Mining, Xrep and Super Kanban applications licensed to the Client.
In those cases, the Client is the Controller and defines the purposes and means of the processing. It falls to the Client to establish the applicable legal bases, to provide information to its data subjects and to respond to their requests.
Datago acts exclusively in accordance with the Client's documented instructions and under the terms of the Data Processing Addendum (DPA) signed with the Client, which governs security, confidentiality, sub-processors, audit, incidents and the return or erasure of data at the end of the contract.
If you are an End User of a company that uses our solutions, your request regarding personal data should be addressed first to that company. Even so, you may contact us through the channels in Section 16 and we will forward the request to the responsible Controller, at no cost.
3.3. Nitzap deployment models and their effect on data
Nitzap may be contracted under different deployment models, and the chosen model determines which personal data Datago actually processes. This is a material distinction: under one of the models, conversation content never passes through nor resides on Datago infrastructure.
| Model | Where conversations are kept | What Datago processes | Datago's role |
|---|---|---|---|
| Nitzap SaaS (Datago cloud) | On infrastructure managed by Datago | Storage and transmission of message content and metadata, WhatsApp identifiers and telephone numbers, with no access to content for its own purposes. Full processing only of licensed user data and activity logs | Processor as regards Client and End User data; Controller as regards licensing and billing data |
| Nitzap On-Premise (Client governance) | Exclusively on the Client's infrastructure and under the Client's governance. They neither pass through nor reside in a Datago environment | Only identification data of licensed users: user login, name, corporate email and platform connection status, for licence consumption control, activation, support and billing. No conversation, contact or service data is transmitted to Datago | Controller as regards licensing data; Processor only in occasional technical access (see 3.4) |
| Hybrid model | According to the architecture agreed in the contract | Defined case by case in the DPA | Defined case by case in the DPA |
Practical consequences of the On-Premise model:
- Datago does not store, does not routinely access and does not retain the content of conversations, attachments, contacts or service histories;
- defining retention periods, backup policies, encryption at rest and access controls over content is the Client's responsibility, as Controller and holder of the infrastructure;
- data subject requests relating to conversation content must be addressed exclusively to the Client, since Datago has no technical means to answer them;
- the geographic residence of conversation data is determined by the Client, not by Datago (see Section 9);
- in the event of a security incident on the Client's infrastructure, the obligation to notify the ANPD and the data subjects lies with the Client, as Controller.
3.4. Occasional technical access in environments under Client governance
Even in the On-Premise model, and also in Salesforce implementation and support projects, Datago professionals may need to access the Client's environment temporarily to diagnose faults, apply fixes or run updates.
Access, viewing and extraction of data constitute processing under art. 5, X, of the LGPD. For that reason, even in those cases Datago remains subject to the DPA, with the following safeguards:
- access upon prior, recorded authorisation from the Client, limited to what is necessary for the activity;
- named and traceable credentials, with no use of shared generic accounts;
- logging of the accesses made, auditable by the Client;
- a prohibition on copying, extracting or retaining data from the Client's environment beyond what is strictly necessary for diagnosis, with erasure at the end of the activity;
- a confidentiality obligation on all professionals involved.
3.5. Transparency note
Unlike some competing products, we do not make the blanket claim that we "do not store end user data".
In the SaaS model, messages, WhatsApp identifiers and telephone numbers are in fact stored and transmitted by our infrastructure. That follows from the architecture: without storage there is no service history, no search and no conversation continuity.
Saying otherwise would be false, and the LGPD is explicit in including storage in the definition of processing (art. 5, X). What we do state, and what appears in the contract, is something different and more precise:
- Datago does not access conversation content for any purpose of its own. We do not read, analyse, classify, mine or extract commercial value from End Users' messages;
- we do not use conversation content to train artificial intelligence models, whether our own or third parties';
- we do not share content with third parties beyond what is strictly necessary to deliver the service, notably Meta's own messaging infrastructure;
- we do not sell, assign or monetise conversation content in any form;
- technical access to content is exceptional, occurs only upon a ticket or recorded authorisation from the Client, is limited to what is necessary for diagnosis and is recorded in an auditable log, under Section 3.4;
- data is kept with logical segregation per org, encryption in transit, connection credentials and keys stored in encrypted form, profile-based access control and the retention periods set out in Section 10.
In short: in the SaaS model Datago is a technical custodian of the content, not a user of it.
In the On-Premise model, the statement that we do not retain conversation content is true and verifiable, because it follows from the architecture itself: the data never reaches our infrastructure. In that scenario, we process only the minimum licensing data described above.
4. Minimisation principle
We collect only the data necessary for each purpose. We do not request sensitive personal data (art. 11 of the LGPD) or data of children and adolescents (art. 14). Our services are intended for people over 18 years of age, in a professional and business context.
Should we identify sensitive data or data of a minor received without an adequate legal basis, it will be erased; see Sections 13 and 14.
5. Master table of processing activities
The table below consolidates, for each collection scenario: which data we process, for what purpose, on which legal basis, with whom we share it, for how long we keep it and what happens if the data is not provided (art. 9 of the LGPD).
| Scenario | Data processed | Purpose | Legal basis (LGPD) | Sharing | Retention | If not provided |
|---|---|---|---|---|---|---|
| Browsing the website and digital channels | IP, access logs (date/time with time zone), browser, OS, device, pages visited, traffic source (referrer/UTM), cookie identifiers | Operate and protect the site; measure audience; fix errors; improve content and products | Legal obligation (art. 7, II together with art. 15 of the Internet Civil Framework) for logs; Consent (art. 7, I) for analytics and marketing cookies; Legitimate interest (art. 7, IX) for security | Cloud provider; analytics and media tools, according to consent (see Section 8) | Logs: 6 months (legal minimum). Cookies: according to the individual period stated in the preferences panel | Some site features may not work; we will not be able to measure audience or personalise content |
| Contact, support, chatbot and forms | Name, email, telephone/WhatsApp, company, role, message content, attachments and evidence submitted | Respond to the request; open and handle tickets; provide support and maintenance; keep a service history | Preliminary procedures and performance of a contract (art. 7, V); Legitimate interest (art. 7, IX) for pre-contractual matters | Cloud provider; Salesforce (CRM/service); transactional email tool; Meta (when contact occurs via WhatsApp) | 5 years after closure of the ticket or of the contract | We will not be able to respond, open a ticket or provide support |
| Request for a demo, proposal or evaluation | Name, corporate email, telephone, company, role, size, stated need | Present the solution; prepare a proposal; conduct the negotiation; send usage guidance | Preliminary procedures to a contract (art. 7, V) | Cloud provider; Salesforce; sales automation tool | 24 months from the last contact, if there is no conversion | We will not be able to present the solution or prepare a proposal |
| Contracting and performance of services (Client contacts) | Name, email, telephone, role, company, CNPJ, billing and collection data, environment access credentials (stored in protected form) | Perform the contract; invoice and collect; provide support; comply with tax and accounting obligations; communicate about the service | Performance of a contract (art. 7, V); Legal obligation (art. 7, II); Legitimate interest (art. 7, IX) | Cloud provider; Salesforce; accounting; financial institutions and payment providers; legal advisers where necessary | 5 years after the end of the contract (tax and limitation periods) | We will not be able to contract, invoice or provide the service |
| Use of Datago platforms in the SaaS model (Nitzap, Xrep, Data Mining, Super Kanban), users designated by the Client | Full processing: name, corporate email, telephone, company, role, Salesforce organisation and user ID, username, time zone, WhatsApp identifier and associated number, activity logs. Storage and transmission only, with no access for our own purposes: message and attachment metadata and content | Authenticate and validate access; operate the contracted features; host and transmit the service history on the Client's behalf; record interactions and create leads/contacts in the CRM; provide support; ensure security and traceability | Performance of a contract (art. 7, V); Legitimate interest (art. 7, IX) for security and abuse prevention. Where Datago acts as Processor, the legal basis is defined by the Client as Controller | Cloud provider; Salesforce; Meta Platforms (WhatsApp Business Platform); sub-processors listed in the DPA | For the term of the contract. Once the contract ends: 30 days for the Client to request a backup and, after that period, full erasure (see Section 10.1) | It will not be possible to create an account, authenticate, access or use the Services |
| Use of Datago platforms in the On-Premise model, licensed users (see Section 3.3) | User login, name, corporate email, company, role, activation date and platform connection status. We do not process conversation, attachment, contact or service history content | Control licensing and activation; size and invoice the contract; provide technical support; ensure licensing integrity | Performance of a contract (art. 7, V); Legitimate interest (art. 7, IX) for licence control and prevention of misuse | Cloud provider (licensing data); Salesforce (contract management). There is no sharing of conversation content, which never reaches Datago | Licensing data tied to the contract: 5 years after its end, for tax and accounting obligations (see Section 10.2) | It will not be possible to license, activate or support the installation |
| Marketing, newsletter and content | Name, email, company, role, preferences and history of interaction with communications | Send newsletters, materials, invitations and promotional communications; segment content by professional profile | Consent (art. 7, I) | Email marketing tool; marketing automation; media platforms, according to consent | Until consent is withdrawn or 24 months of total inactivity, whichever comes first | We will not send marketing communications. There is no impact on other services |
| Events, trade fairs and exchange of business cards | Name, email, telephone, company, role and information shared in conversation | Establish a commercial relationship; follow up on the contact; send B2B institutional information | Legitimate interest (art. 7, IX) for initial B2B contact; Consent (art. 7, I) for subsequent promotional communications | Salesforce; sales automation and email marketing tools | 24 months from the last contact | We will not be able to establish the commercial contact |
| Data obtained from third parties and public sources (prospecting and Datago Data Mining) | Company registration data; name, role, corporate email and business telephone of representatives; project and construction data; size, estimated revenue, CNAE code and location | B2B commercial prospecting; database enrichment and deduplication; offering products and services to companies | Legitimate interest (art. 7, IX), with a documented assessment (LIA) and compliance with art. 7, §§ 3 and 4 | Cloud provider; Salesforce; data suppliers; sales automation | 24 months from obtaining the data or from the last effective contact, whichever is later | Not applicable, as the data is not provided by the data subject. See Section 6 |
| Suppliers, service providers and partners | Name, email, telephone, company, role, banking and billing data | Contract and manage the relationship; make payments; comply with legal obligations | Performance of a contract (art. 7, V); Legal obligation (art. 7, II) | Accounting; financial institutions; cloud provider | 5 years after the end of the relationship | We will not be able to contract or make payments |
| Interaction on social media | Name, profile, email (where provided), public content of the interactions | Respond to messages and comments; measure reach; target institutional content | Legitimate interest (art. 7, IX); Consent (art. 7, I) for targeted advertising | LinkedIn, Meta (Facebook/Instagram), Google and other platforms, according to the channel | For as long as the interaction lasts and according to the platform's policy | We will not be able to respond to the interaction |
| Job applicants | CV and the data it contains | Conduct the selection process | Preliminary procedures to a contract (art. 7, V) | Recruitment tool, where applicable | 12 months, unless consent is given for a talent pool | It will not be possible to take part in the selection process |
5.1. Cross-cutting purposes
Regardless of the collection scenario, personal data may also be processed for:
- prevention of fraud, abuse and security incidents, on the basis of legitimate interest (art. 7, IX);
- compliance with a legal or regulatory obligation and response to requests from competent authorities (art. 7, II);
- the regular exercise of rights in judicial, administrative or arbitral proceedings (art. 7, VI).
5.2. On legitimate interest
Where we rely on legitimate interest, we first carry out a balancing test (Legitimate Interest Assessment, LIA), evaluating the legitimacy of the purpose, the necessity of the processing and the balance with the data subject's rights and freedoms. We process only the data strictly necessary.
The data subject may, at any time and free of charge:
- request information about that processing and about the balancing test (art. 10, § 3);
- object to processing based on legitimate interest (art. 18, § 2).
5.3. On consent
Where the legal basis is consent, it will be freely given, informed, unambiguous and collected by affirmative action, never presumed from browsing, from silence, from pre-ticked boxes or from the mere submission of data. Each consent is specific to a purpose.
Consent may be withdrawn at any time, free of charge and by a facilitated procedure, through the channels in Section 16 or through the unsubscribe link present in every marketing communication. Withdrawal does not affect the lawfulness of prior processing or of processing based on other legal bases.
6. Data obtained from public sources and third parties
Part of our commercial activity (and the operation of Datago Data Mining) involves data that is not collected directly from the data subject, but obtained from public databases, official registries and specialised business data suppliers.
In those cases, we adopt the following safeguards:
- we process only professional contact data in a B2B context: name, role, corporate email and business telephone linked to a legal entity;
- we do not process sensitive data, personal-context data or data of natural persons outside the exercise of a professional activity;
- we verify the lawfulness of the source and require contractual safeguards from data suppliers;
- we maintain a documented legitimate interest assessment (LIA) specific to that purpose;
- we inform the data subject of the origin of the data on request, under art. 9, II;
- in every communication sent from those databases, we offer a simple and free mechanism to object and unsubscribe;
- we respect the data subject's objection immediately, keeping only the minimum data necessary to ensure they are not contacted again (suppression list).
If you have been contacted by Datago and wish to know where your data came from, or wish to object to the processing, write to contato@datago.com.br.
7. Cookies and similar technologies
We use cookies and equivalent technologies, including web beacons, pixels and SDKs, in accordance with the ANPD's Guidance on Cookies and Personal Data Protection.
| Category | Function | Requires consent? |
|---|---|---|
| Necessary | Basic operation, security, load balancing, recording the cookie preference itself | No |
| Functional | Remember preferences, language and personalisations | Yes |
| Analytics | Access statistics and browsing behaviour | Yes |
| Marketing | Measure advertising effectiveness and display relevant advertising | Yes |
How consent works on our site:
- on first access, we display a banner with Accept all, Reject all and Customise, with equal visual prominence;
- non-necessary cookies remain disabled until there is active acceptance;
- the preference may be changed or withdrawn at any time through the "Cookie preferences" link, available in the footer of every page;
- it is also possible to block or delete cookies through browser settings, which may affect site features.
7.1. Analytics and media tools, and how to opt out
| Tool | Purpose | Opt-out mechanism |
|---|---|---|
| Google Analytics | Audience and site usage metrics | Opt-out add-on · How Google handles data |
| Google Ads | Advertising and remarketing | Ad settings |
| Meta (Facebook/Instagram) Pixel | Advertising and measurement | Ad preferences |
| LinkedIn Insight Tag | B2B advertising and measurement | LinkedIn ad settings |
| Media platforms generally | Behavioural advertising | YourOnlineChoices · DAA WebChoices |
We reserve the right to add or remove analytics tools, always updating this Policy and the preferences panel.
8. Sharing of personal data
We do not sell, rent or trade personal data. Nor do we share Client data for any purpose that has not been authorised by them or that does not arise from performance of the contracted service.
We share data only where necessary for the purposes of this Policy, always under a contract imposing confidentiality, security and purpose limitation.
| Category of recipient | Purpose |
|---|---|
| Infrastructure and datacentre | Hosting, database, backup and content delivery |
| CRM platform | Relationship management, service and operation of Datago's native products |
| Messaging | Operation of Nitzap and sending of service communications, including the WhatsApp Business platform infrastructure |
| Analytics and advertising | Audience metrics and digital advertising, according to consent |
| Marketing and sales automation | Email marketing, nurturing and lead management |
| Data suppliers | Database enrichment for B2B prospecting (Data Mining) |
| Payment providers and financial institutions | Collection, reconciliation and transfers |
| Professional service providers | Accounting, legal advice and audit, under professional confidentiality |
| Public authorities | Upon court order, request from a competent authority or legal or regulatory obligation |
Information about the sharing of your data may be requested at any time through the channels in Section 16, under art. 18, VII, of the LGPD.
8.1. Corporate transactions
Should Datago sell, transfer, merge, spin off or reorganise part or all of its business, shares or assets, including during preliminary negotiations and due diligence processes, personal data may be shared with the third parties involved, whether actual or potential, always under a confidentiality agreement.
The same applies in the event of an acquisition of Datago, merger, judicial reorganisation, bankruptcy or an equivalent event. In those cases, data subjects will be notified and the successor entity will remain bound by the safeguards in this Policy, unless a new policy is communicated with reasonable notice.
9. Infrastructure and international transfer of data
The infrastructure supporting Datago's platforms in the SaaS model is contracted from specialised datacentre providers, under a contract imposing confidentiality, security and purpose limitation obligations, prohibiting access to Client content for any purpose of their own.
Location of the data. In the SaaS model, the infrastructure of Datago's platforms is, by default, located in the United States of America. In that configuration, there is an international transfer of personal data, carried out on the terms described below.
The Client may, by specific negotiation, indicate another provider or another cloud region, including in Brazil, or opt for the On-Premise model. The configuration that applies to each Client is set out in its contract or Service Order, and the data subject may enquire about it through the channels in Section 16.
The international transfer is carried out on the basis of arts. 33 to 36 of the LGPD, in compliance with ANPD Resolution No. 19/2024, by means of:
- Standard Contractual Clauses approved by the ANPD; or
- specific contractual clauses or approved binding corporate rules; or
- transfer to a country with an adequate level of protection, where so recognised by the ANPD; or
- specific and prominent consent from the data subject, where applicable.
The data subject may request, through the channels in Section 16, information about the destination countries of their data and about the safeguard mechanisms adopted.
In the On-Premise model, the geographic location of conversations and other operational data is determined exclusively by the Client, which holds and governs the infrastructure. In that scenario Datago carries out no transfer of content. Only the licensing data described in Section 3.3 passes through its infrastructure.
10. Retention periods and erasure
We keep personal data only for as long as necessary to fulfil the purposes that justified its collection. Under no circumstances do we retain data for an indefinite period.
10.1. End of contract: 30-day window and full erasure
Once the contract for any Datago platform ends, the following rule applies:
- A window of 30 (thirty) calendar days, counted from termination, during which the Client may request the extraction or full backup of its data, in a structured, commonly used format;
- After those 30 days, Datago proceeds with the full erasure of the Client's operational and content data in its production and backup environments, including conversations, attachments, contacts, service histories and settings;
- Erasure is definitive and irreversible. After that period it is not technically possible to recover the data, even on request.
The return is made in a structured, commonly used format, suitable for import into another solution, also satisfying the right to portability provided for in art. 18, V, of the LGPD.
Once erasure is complete, Datago issues, at the Client's request, a formal statement of data erasure, indicating the date, scope and environments covered. The document serves as evidence in audit and contract closure processes.
We recommend that the Client carry out the extraction within the window, as the loss of data after that period is unrecoverable.
10.2. Mandatory legal exception
The erasure described above does not cover data whose retention is required by law, under art. 16, I, of the LGPD. The following are retained:
| Category | Period | Basis |
|---|---|---|
| Contracts, invoices, accounting and billing records | 5 years after the end of the contract | Arts. 173 and 174 of the National Tax Code; art. 206 of the Civil Code |
| Internet application access logs | 6 months, extendable by court order | Art. 15 of the Internet Civil Framework |
| Records necessary for defence in judicial, administrative or arbitral proceedings, where a dispute has been brought or is reasonably expected | For as long as the need lasts | Art. 7, VI, and art. 16, I |
These records are kept with restricted access, used exclusively for the legal purpose that justifies their retention, and erased at the end of the period.
10.3. Other periods
| Category | Period |
|---|---|
| Leads, prospects and commercial contacts without conversion | 24 months from the last contact |
| Data obtained through B2B prospecting and Data Mining | 24 months from obtaining the data or from the last effective contact, whichever is later |
| Marketing and newsletter data | Until consent is withdrawn or 24 months of total inactivity |
| Applicant CVs | 12 months, unless consent is given for a talent pool |
| Cookies | According to the individual period of each cookie, stated in the preferences panel |
Once the period has elapsed, the data is erased or irreversibly anonymised, save for the situations in art. 16 of the LGPD.
11. Information security
We adopt technical and administrative measures capable of protecting personal data from unauthorised access and from accidental or unlawful destruction, loss, alteration, communication or dissemination (art. 46 of the LGPD), including:
- encryption of data in transit through TLS in all communications between clients, applications and services;
- encryption of stored credentials, tokens and connection keys, with recognised market algorithms;
- profile-based access control, with the principle of least privilege and periodic review;
- multi-factor authentication (MFA) for critical systems and client environments;
- logical segregation of data per client and separation between development, staging and production environments;
- logging and monitoring (audit logs) of relevant accesses and operations;
- backup routines and periodic recovery tests;
- management of corporate devices, with disk encryption, automatic screen lock and anti-malware;
- confidentiality agreements with employees and service providers;
- periodic team training in security and data protection;
- security assessment of suppliers before engagement.
In the On-Premise model, the measures above apply to the licensing data under our management and to our own processes and devices. Security of the infrastructure hosting the installation (servers, network, backup, encryption at rest and access control over content) is the Client's responsibility. Datago provides secure configuration recommendations and minimum environment requirements in the product's technical documentation.
Security also depends on the data subject's own environment. We recommend keeping devices up to date, using strong and unique passwords, enabling multi-factor authentication and not sharing credentials.
No system is absolutely impenetrable. We undertake to maintain continuous improvement efforts and to act transparently should an incident occur.
11.1. Limits on the use of Client content
Regardless of the deployment model, Datago accepts the following prohibitions regarding the content of conversations, service records and Client databases:
- we do not use that content for our own commercial or analytical purposes;
- we do not cross-reference or combine databases of different Clients, under any circumstances;
- we do not sell, assign or make that content available to third parties;
- we do not use the content for purposes other than those authorised by the Client as Controller;
- any product metrics are produced exclusively from our own operational data, with no access to the individual content of messages.
These prohibitions are set out in the Data Processing Addendum (DPA) and are auditable by the Client under the terms set out there.
11.2. Use of artificial intelligence
We recognise that the use of data in artificial intelligence systems is today one of our Clients' main governance concerns, particularly in the financial sector and in regulated sectors. We therefore expressly state that:
- Client data and content are not used to train, tune, refine or feed back into artificial intelligence models, whether developed by Datago, by partners or by third parties;
- we do not supply Client or End User content to third parties for the purpose of training models, in any form, including in aggregated form;
- there is no use of data across different Clients through any automated or machine-learning feature. Each Client remains isolated, with no information from one influencing results presented to another;
- any automation features available in the product, such as flows, routing and configurable replies, operate on the Client's own database, under rules defined by the Client.
These prohibitions are contractual, are set out in the Data Processing Addendum (DPA) and remain valid after the end of the contract as regards data processed during its term.
Should we incorporate into the product features based on third-party artificial intelligence models, this will be communicated to Clients in advance, identifying the supplier, the purpose, the contractual guarantees of non-retention and non-training, and with the possibility of refusal by the Client.
12. Security incidents
We maintain an incident response plan with procedures for detection, containment, risk assessment, remediation and communication.
Where a security incident occurs that may give rise to relevant risk or damage to data subjects, we will notify:
- the ANPD, within 3 (three) business days from becoming aware of the incident, under art. 48 of the LGPD and ANPD Resolution No. 15/2024;
- the affected data subjects, within the same period, stating the nature of the data involved, the data subjects affected, the technical security measures adopted, the risks identified and the steps under way;
- the Client as Controller, immediately, where Datago acts as Processor.
In the On-Premise model, incidents occurring on the Client's infrastructure are for the Client itself to investigate and notify, as Controller and holder of the environment. Datago will provide the technical support set out in the contract and will immediately notify the Client of any vulnerability identified in the product that may affect it.
13. Automated decisions
We use automation in our products and channels: chatbots, automated flows, routing and distribution of service, and lead qualification and segmentation.
Under art. 20 of the LGPD, the data subject has the right to request a review of decisions taken solely on the basis of automated processing that affect their interests, as well as to receive clear information about the criteria and procedures used, subject to commercial and industrial secrecy.
We do not carry out automated processing with significant legal effects on natural persons, such as granting credit, personal risk assessment or determining access to rights.
14. Children and adolescents
Our services are directed at people over 18 years of age, in a professional context. We do not intentionally collect data of children or adolescents, nor do we offer information society services directly to that audience.
Should we become aware of the collection of a child's data without the specific and prominent consent of at least one parent or legal guardian (art. 14, § 1), we will proceed with immediate erasure. Parents and guardians may contact us through the channels in Section 16.
15. Interaction with third-party products and services
Our sites and solutions may contain links to, integrate with or interoperate with third-party websites, applications and services that we do not own and that are not under our control, notably CRM, messaging and infrastructure platforms.
Datago is not responsible for the privacy practices, terms or content of those services. We recommend reading their respective privacy policies and terms of use, in particular:
- WhatsApp and Meta Platforms: the processing of messages and metadata on the messaging platform's infrastructure is governed by Meta's own policies, over which Datago exercises no control;
- Salesforce: the processing carried out inside the Client's org is governed by the contract between the Client and Salesforce.
16. Data subject rights
Under art. 18 of the LGPD, you may, at any time and at no cost (art. 18, § 5):
- Confirm the existence of processing;
- Access your data;
- Correct incomplete, inaccurate or outdated data;
- Request the anonymisation, blocking or erasure of unnecessary or excessive data, or data processed in breach of the law;
- Request portability to another supplier, upon express request and subject to commercial and industrial secrecy;
- Request the erasure of data processed on the basis of consent, save for the situations in art. 16;
- Obtain information about sharing with public and private entities;
- Obtain information about the possibility of not giving consent and about the consequences of refusal;
- Withdraw consent at any time;
- Object to processing carried out on a basis that dispenses with consent, under art. 18, § 2;
- Know the origin of the data, where it was not collected directly from you (art. 9, II);
- Request a review of automated decisions (art. 20);
- Petition the ANPD against the controller (art. 18, § 1) and file a complaint with consumer protection bodies.
16.1. How to exercise your rights
Send your request to contato@datago.com.br, stating your name, the right you wish to exercise and the information needed to identify you.
Response times:
- immediate, for requests in simplified form;
- up to 15 (fifteen) days, for the clear and complete statement on origin, absence of a record, criteria and purpose of the processing (art. 19, II);
- for complex requests, we will inform you of the estimated time and the reason.
Where Datago acts as Processor (Section 3.2), decisions about the processing rest with the Client as Controller. In those cases, we receive your request, forward it to the responsible Controller and provide the technical support needed to handle it, informing you that it has been forwarded. The substantive response comes from the Controller.
We may request additional information to confirm your identity, solely as a security measure. If we are unable to meet the request, we will state the factual or legal reason. We ask that you try to resolve the matter with us before approaching the ANPD, but that is your right and may be exercised at any time.
16.2. Account deletion
To delete your account on any Datago platform, write to contato@datago.com.br or ask your organisation's administrator.
If you are a user of an account contracted by a company, deletion also depends on instruction from the Client as Controller. Once the contract ends, the erasure rule in Section 10.1 applies.
16.3. Unsubscribing from marketing communications
You may unsubscribe from promotional communications at any time:
- through the unsubscribe link in the footer of all our marketing emails; or
- by email to contato@datago.com.br with the subject "Unsubscribe".
Unsubscribing is free of charge and processed promptly. It does not apply to transactional and service messages (ticket, billing, security and contractual change notices), which are necessary to perform the contract.
17. Data Protection Officer (DPO)
Under art. 41, § 1, of the LGPD, Datago appoints as Data Protection Officer:
- Name: Andressa Sabadini de Sales
- Email: contato@datago.com.br
- Telephone: +55 (27) 99997-0276
- Correspondence address: Rua Victorino Cardoso, 235, Sala 04, Andar 01, Jardim Camburi, Vitória, Espírito Santo, CEP 29.090-820, Brazil
This is the official channel of communication between Datago, data subjects and the ANPD, for clarifications, complaints, communications and requests relating to this Policy.
18. Changes to this Policy
This Policy may be updated at any time to reflect legal, regulatory, technological or business changes.
The version in force will always be available at https://datago.com.br/politica-de-privacidade.html, indicating the date of the last update. In the event of material changes, particularly new purposes, new legal bases or a relevant change in sharing, we will notify data subjects by email or by a prominent notice on the site and on the platforms, with reasonable advance notice.
Where a change depends on consent, consent will be requested again.
19. Governing law and venue
This Policy is governed by Brazilian law.
The courts of the judicial district of Vitória, Espírito Santo, are elected to settle disputes arising from it, without prejudice to the venue of the data subject's domicile, where the data subject is a consumer or where the law so provides.
Version history
| Version | Date | Changes |
|---|---|---|
| 2.1 | 07/09/2026 | Statement of the default location of the SaaS infrastructure in the United States, with the alternatives of a Client-designated cloud and On-Premise; a dedicated section on the use of artificial intelligence, with an express prohibition on training and on use across Clients; return in a structured format and a formal statement of erasure at the end of the contract; prohibition on sharing for purposes not authorised by the Client; forwarding of requests to the Controller where Datago acts as Processor |
| 2.0 | 01/07/2026 | Full revision. Identification of the Controller and the DPO; definition of the Controller and Processor roles; Nitzap deployment models (SaaS, On-Premise and hybrid) and their effects on processing; occasional technical access in the Client's environment; master table of processing activities by collection scenario, with purpose, legal basis, sharing, retention and consequences of non-provision; a dedicated section on data obtained from third parties and public sources; limits on the use of Client content, including a prohibition on AI training; 30-day window and full erasure after the end of the contract; active consent for cookies and opt-out mechanisms; international transfer under ANPD Resolution No. 19/2024; incident notification under ANPD Resolution No. 15/2024; automated decisions; children and adolescents; account deletion and marketing unsubscribe |
| 1.0 | 01/2024 | Initial version |
DATAGO TECNOLOGIA LTDA · CNPJ 30.728.220/0001-05 · Salesforce Partner
Rua Victorino Cardoso, 235, Sala 04, Andar 01, Jardim Camburi, Vitória/ES, CEP 29.090-820
Rua Amado Almeida, 77, Pav. 3, Glória, São Gabriel da Palha/ES, CEP 29.780-000
contato@datago.com.br · +55 (27) 99997-0276