Whatsplaid
Plans
Search the site

Privacy Policy

As Whatsplaid collects, uses, shares, protects, and retains personal data on its platform for support, sales, automation, AI, website, contact channels, integrations, and related services.

Whatsplaid recognizes the importance of protecting personal data.

This Privacy Policy has been structured to comply with the Brazilian General Data Protection Law (LGPD), the European Union General Data Protection Regulation (GDPR), the UK GDPR, and, when applicable, the privacy laws of other jurisdictions, such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).

The specific application of each legislation depends on factors such as the resident's location, the location of data collection, the purpose of processing, Whatsplaid's role in the operation, and the contractual relationship with our clients.

1. Overview

This Policy explains how Whatsplaid handles personal data on its website, platform, applications, APIs, integrations, forms, support channels, business activities, marketing communications, and related services for support, sales, automation, and artificial intelligence for WhatsApp.

Personal data are information that identify or can identify a natural person, directly or indirectly. Depending on the applicable legislation, they may also include online identifiers, browsing data, device information, geolocation, and inferences associated with a person or consumer.

By using our services, contracting Whatsplaid, accessing our channels, or interacting with our forms, you acknowledge that your personal data may be processed in accordance with this Policy and the applicable contracts, terms of use, specific notices, and consent preferences.

2. Who we are

We are Whatsplaid, a platform that offers solutions for customer service, sales, lead capture, shared inbox, tickets, CRM, automations, AI agents, knowledge base, reports, and integrations with third-party systems, especially connected to WhatsApp.

IN2, LLC
7345 W Sand Lake RD,
STE 210 Office 4761
Orlando, FL 32819 US

You can contact us by email at support@whatsplaid.com. For data protection matters, use the contacts indicated in the “Contact and Data Officer” section.

3. Whatsplaid's roles

Whatsplaid can act in different roles depending on the context of the processing.

3.1. Whatsplaid as controller

Whatsplaid acts as a controller when it determines the purposes and means of processing, for example in activities such as marketing, sales, commercial support, support, billing, customer relationship, website security, administrative management, legal compliance, and analysis of our channel usage.

3.2. Whatsplaid as operator or processor

Whatsplaid acts as an operator, processor, or service provider when processing personal data on behalf of a client company that uses the platform to operate support, sales, automations, campaigns, messages, tickets, CRM, AI agents, knowledge base, integrations, and communications with end consumers.

In these cases, the client company is generally the data controller of its end consumers' data. Whatsplaid processes these data according to the client's contractual instructions and the resources configured on the platform.

3.3. Customer responsibilities

Whatsplaid clients must inform their end consumers about the use of the platform, obtain necessary legal bases or consents, maintain their own privacy policies, set campaign rules lawfully, and respond to data subject requests when they are data controllers.

4. Processed data

The data processed varies according to the platform usage, channels used, the client's settings, and applicable legislation.

4.1. Identification and contact data

  • Name, surname, email, phone, WhatsApp, fiscal document when necessary, and professional contact data.
  • Company, position, segment, business address, country, language, and information necessary for commercial support.

4.2. Account, contract, and billing data

  • Registration data, credentials, user permissions, access logs, contracted plan, support history, and contractual information.
  • Payment data, billing, invoices, refunds, fraud prevention, and compliance with fiscal and accounting obligations.

4.3. End consumer data processed on the platform

  • End customer data sent or imported by client companies, such as name, email, phone, identifiers, conversations, messages, purchases, orders, tickets, leads, preferences, support history, and interactions.
  • Data from integrations with WhatsApp, e-commerce, CRM, ERP, APIs, widgets, spreadsheets, documents, imports, and communication channels configured by the client.

4.4. Technical, browsing, and device data

  • IP address, device identifiers, browser, operating system, accessed pages, traffic source, usage events, security logs, and cookies.
  • Approximate or precise geolocation when enabled by the user, client, or necessary for a specific feature with applicable legal basis.

4.5. Sensitive data

Whatsplaid generally does not request sensitive personal data. If a client enters sensitive data on the platform or configures treatments involving such data, they must ensure an appropriate legal basis and instructions compliant with applicable legislation.

6. Cookies and similar technologies

We use cookies and similar technologies for website operation, security, preferences, usage analysis, campaign measurement, and, when applicable, advertising.

6.1. What are cookies?

Cookies are small files stored in the browser or device. They can identify a session, remember preferences, measure interactions, or enable essential features.

6.2. Cookie categories

  • Essential: necessary for website operation, security, session, and proper display.
  • Preferences: used to remember language, region, and user choices.
  • Analytics: used to understand navigation, performance, and usage of services.
  • Marketing: used for campaign measurement, remarketing, and ad personalization, when applicable.

6.3. Examples of cookies

  • PHPSESSID: used for session and basic website operation.
  • _ga: used by Google tools for analysis and measurement, when enabled.
  • _fbp: used by Meta/Facebook tools for measurement and advertising, when enabled.

6.4. Consent and preferences

In regions where the law requires prior consent for non-essential cookies, Whatsplaid will seek to obtain consent before activating analytical or marketing cookies. You can also manage cookies in your browser, block cookies, or delete existing cookies.

7. Sharing and subprocessors

We may share personal data with vendors, operators, subprocessors, and partners when necessary to provide, protect, operate, measure, or improve the services.

7.1. Categories of recipients

  • Infrastructure providers, hosting, cloud computing, storage, backup, and security.
  • Communication tools, email, WhatsApp, customer service, CRM, automation, artificial intelligence, and support.
  • Payment providers, billing, tax issuance, accounting, and legal.
  • Analytics tools, ad measurement, fraud prevention, and availability monitoring.
  • Customer-configured integrations, such as e-commerce, CRM, ERP, spreadsheets, documents, gateways, third-party APIs, and messaging providers.
  • Public authorities, courts, or regulators when required by law or necessary for the defense of rights.

7.2. End user data

When Whatsplaid acts as an operator/processor, sharing related to end consumer data follows the instructions of the data controller, platform settings, and applicable contracts.

7.3. Sale or sharing for behavioral advertising

Whatsplaid does not sell personal data in the common sense of selling for money. Some legislations, such as California's CCPA/CPRA, may define "sale" or "sharing" broadly, including certain uses of cookies, pixels, and behavioral advertising. When applicable, Whatsplaid will provide mechanisms for choice, opt-out, or preference management.

8. International transfers

Whatsplaid may process, store, or transfer personal data to countries different from where the data subject is located, including due to cloud infrastructure, support tools, analytics, communication, payments, integrations, and international vendors.

When required by applicable legislation, we will adopt appropriate mechanisms for international transfers, such as standard contractual clauses, contracts with operators/subprocessors, adequacy decisions, technical and organizational safeguards, or other mechanisms recognized by applicable law.

Clients using the platform to process end consumer data should assess their own obligations regarding international transfer, especially when configuring integrations, imports, exports, automations, AI agents, or their own subprocessors.

9. Retention and security

9.1. Retention

We will retain personal data for as long as necessary to fulfill the purposes described in this Policy, provide services, fulfill contracts, meet legal obligations, resolve disputes, preserve rights, maintain security, prevent fraud, and comply with tax, accounting, or regulatory requirements.

When acting as an operator/processer, data retention on the platform may depend on the controller's settings, the applicable contract, backups, technical logs, and legal obligations.

Anonymized or aggregated data, without a reasonable possibility of identifying a person, may be kept for an indefinite period.

9.2. Security

We adopt technical and organizational measures aimed at protecting personal data against unauthorized access, destruction, loss, alteration, communication, or improper processing. These measures may include access controls, logs, incident management, backups, environment segregation, monitoring, encryption when applicable, and internal security processes.

No system is absolutely secure. In the event of a security incident that may pose a risk or significant damage, we will assess the obligations to notify data subjects, clients, competent authorities, and other affected parties in accordance with applicable legislation.

10. Rights of data subjects

Depending on the applicable legislation and Whatsplaid's role in processing, you may exercise rights related to your personal data, such as:

  • Confirm whether we process your personal data.
  • Access the personal data processed.
  • Correct incomplete, inaccurate, or outdated data.
  • Request anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data.
  • Request portability, when applicable.
  • Revoke consent and obtain information about the consequences of the refusal.
  • Object to certain processing, when applicable.
  • Request restriction of processing, when applicable.
  • Request information about sharing and recipients.
  • Present complaint to the competent authority.

When Whatsplaid acts as an operator/processer on behalf of a client, we may direct your request to the data controller client or assist them in responding, in accordance with the contract and applicable law.

11. Rights by region

11.1. Brazil - LGPD

If LGPD applies, you may exercise the rights provided for in Law 13.709/2018, including confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, information about the consequences of refusal of consent, revocation of consent, and petitioning the National Data Protection Authority (ANPD).

11.2. European Economic Area and United Kingdom - GDPR and UK GDPR

If GDPR or UK GDPR applies, you may have rights to access, rectify, erase, restrict, data portability, object, withdraw consent, and file a complaint with the competent supervisory authority.

When Whatsplaid is subject to GDPR or UK GDPR regarding specific processing, we will inform you of the applicable legal bases, recipients or categories of recipients, retention criteria, relevant international transfers, and applicable safeguards.

11.3. California - CCPA/CPRA

If California law applies to you and the activity in question, you may have the right to know what categories of personal data we collect, sources, purposes, categories of third parties, the right to access, correct, delete, limit the use of sensitive personal information, opt-out of sale or sharing, and not be discriminated against for exercising these rights.

Whatsplaid does not sell personal data for money. If cookies, pixels, or similar technologies are considered “sharing” or “sale” under applicable law, we will provide appropriate opt-out mechanisms when required.

11.4. Other jurisdictions

Users from other regions may have additional rights under local privacy and data protection laws. Whatsplaid will evaluate requests according to the applicable law for the specific processing.

12. Children and adolescents

Whatsplaid's services are not directed at children. We do not intentionally seek to collect personal data from children for marketing purposes.

When Whatsplaid clients set up programs, campaigns, or registrations involving minors, the data controller must ensure an appropriate legal basis, parental consent when required, and compliance with applicable law.

13. Automation, profile, and AI

The Whatsplaid platform may enable automations, segmentations, communication flows, automated support, lead qualification, AI agents, knowledge-based responses, conversation routing, tickets, profile-based campaigns, and reports configured by clients.

These features may use transactional data, messages, conversation history, purchase behavior, engagement, preferences, documents, knowledge bases, and operational events to generate communications, responses, reports, or automated actions.

When Whatsplaid acts as an operator/processer, the client company is responsible for configuring these automations in a manner compliant with applicable law, including informing data subjects, legal bases, opt-out options, and impact assessments when necessary.

Whatsplaid may also use aggregated, anonymized, or operational data to improve products, security, support, abuse detection, platform quality, and business intelligence.

14. Contact and responsible person

For questions, requests, or exercising rights related to personal data, contact us.

Support: support@whatsplaid.com
Data Officer: Josué Felipe Garcia
Data officer's email: lgpd@josuegarcia.com.br

When submitting a request, we may ask for additional information to confirm your identity, locate the data, identify the applicable controller, and prevent unauthorized access to third-party data.

15. Updates

We may update this Privacy Policy periodically to reflect legal, regulatory, operational, technical, contractual, or product changes.

When the change is significant, we may communicate through the website, platform, email, account notice, or other appropriate channels. The most recent version will be available on this page.