Privacy
Your privacy, no legalese.
We believe you deserve to understand how your data is handled — for real, no fine print.
Your privacy in 2 minutes
A summary of the key points. For the full version, see below.
What we collect
Name, email, phone, usage data and technical data. Nothing beyond what's necessary.
Why we use it
To operate the platform, improve your experience and keep everything secure.
Cookies
We use essential cookies and, with your consent, analytics. You choose.
Who we share with
Infra (AWS), WhatsApp, AI (Claude/GPT). We never sell your data.
Security
End-to-end encryption, data isolation, 24/7 monitoring. Your data stays in Brazil.
Your rights
Access, correction, deletion, portability and more. Contact us: privacidade@catalisa.io
Full Privacy Policy
Full Privacy Policy
Complete legal version in accordance with LGPD
Last updated: March 2026
This Privacy Policy describes how Catalisa collects, uses, stores and protects your personal data. Data Controller: Catalisa Tecnologia e Dados LTDA CNPJ (Tax ID): 49.646.439/0001-85 Address: Rodovia Raposo Tavares, 7389 - Sao Paulo - SP - Brazil - 05577-902 Data Protection Officer (DPO): Email: privacidade@catalisa.io Contact channel: privacidade@catalisa.io
This Policy applies to the processing of personal data carried out by Catalisa in two categories: (a) Platform user data: personal information provided by you when creating an account, using our services or interacting with our website. (b) Users' customer data: personal information of third parties (the User's end customers) that is processed through the Platform, especially via WhatsApp integrations. For this data, the relationship between Catalisa and the User follows the roles defined in Section 13. This Policy is an integral part of the Platform's Terms of Service.
We collect the following categories of personal data:
- Registration data (legal basis: contract performance): full name, corporate email, phone number, company name, job title, tax ID. Collected at the time of registration on the Platform.
- Usage data (legal basis: legitimate interest): Platform interactions, features used, access logs, usage times, actions taken. Collected automatically during use.
- Communication data (legal basis: contract performance): messages processed by the Platform, message templates, Workflow and AI Agent configurations. Processed according to User instructions.
- Technical data (legal basis: legitimate interest): IP address, browser type and version, operating system, device, screen resolution, pages accessed, time spent. Collected automatically by cookies and similar technologies.
The processing of personal data by Catalisa is based on the following legal bases provided by the LGPD (Brazilian General Data Protection Law):
- Contract performance (Art. 7, V): processing necessary for the provision of contracted services, including account creation, message processing, Workflow execution and technical support.
- Legitimate interest (Art. 7, IX): processing necessary to improve the Platform, ensure security, prevent fraud, perform usage analytics and send service communications. We conduct a Legitimate Interest Assessment (LIA) to ensure our interests do not override the data subject's rights.
- Consent (Art. 7, I): used for specific purposes such as marketing communications, analytical and marketing cookies, and participation in surveys. Consent may be revoked at any time without prejudice to prior processing.
- Legal obligation (Art. 7, II): processing necessary to comply with legal and regulatory obligations, including retention of fiscal and financial data, compliance with requests from competent authorities and maintenance of legally required records.
We use your personal data for the following purposes:
- Service provision: operating the Platform, processing automations and Workflows, running AI Agents and providing contracted features.
- Account management: creating and maintaining your account, authenticating access, managing permissions and preferences.
- Technical support: handling support requests, diagnosing issues and providing technical assistance.
- Service communications: sending notifications about maintenance, updates, terms changes and essential service information.
- Platform improvement: analyzing usage patterns (in aggregate), identifying improvements, developing new features and fixing bugs.
- Security: monitoring suspicious activities, preventing fraud, detecting vulnerabilities and protecting Platform integrity.
- Legal compliance: meeting legal and regulatory obligations and responding to requests from competent authorities.
- Marketing (with consent): sending communications about new features, educational content and offers, only when authorized by the data subject.
Our website and Platform use cookies and similar technologies to improve your experience. We use Google Tag Manager (GTM) and Google Analytics 4 (GA4) with Consent Mode v2 implemented. Cookie categories:
- Strictly necessary cookies: essential for Platform operation, including authentication, security and session preferences. Stored via localStorage and session cookies. Do not require consent.
- Analytical cookies (GA4): collect aggregated data about website and Platform usage for improvement purposes. Include: _ga (user identification, 2 years), _ga_* (session state, 2 years). Require consent.
- Marketing cookies: used to deliver relevant communications. Activated only with explicit consent via the cookie banner.
- External resources (images): our website may load illustrative images from third-party services, such as Unsplash (Imgur Inc.), to enrich editorial content. When loading these images, your browser makes direct requests to the provider's servers, which may receive technical data such as IP address, user-agent and the URL of the visited page. These resources are loaded based on legitimate interest (LGPD Art. 7, IX) to improve user experience. They do not require additional consent, as they do not install cookies or trackers.
We do not sell your personal data. We share data only with the following categories of recipients, to the extent necessary for the purposes described in this Policy:
- Infrastructure providers (AWS/GCP): hosting, storage and data processing. Servers located in Brazil, with replication for service continuity.
- Meta/WhatsApp: message processing through the WhatsApp Business API. Necessary for communication integration functionality. Subject to WhatsApp's Terms of Service and Privacy Policy.
- Anthropic (Claude): natural language processing and content generation by AI Agents. Data may be transferred to servers in the United States (see Section 8).
- OpenAI (GPT): natural language processing and content generation by AI Agents. Data may be transferred to servers in the United States (see Section 8).
- Unsplash (Imgur Inc.): provision of illustrative images for the website's editorial content. When loading pages with external images, your browser makes requests to Unsplash servers, which may receive technical data (IP address, user-agent). No personal data is actively shared by Catalisa. Subject to Unsplash's Privacy Policy (unsplash.com/privacy).
- Microsoft Clarity: behavioral analytics and heatmap tool to improve user experience. May collect interaction data such as clicks, scrolling and mouse movements. Subject to Microsoft's Privacy Policy.
- Competent authorities: when required by law, judicial or administrative order, or to protect rights in legal proceedings.
Some of our sub-processors, specifically Anthropic and OpenAI, operate servers in the United States. This means that personal data processed by AI Agents may be transferred outside of Brazil. To ensure adequate protection of internationally transferred data, we adopt the following safeguards in accordance with the LGPD (Art. 33): (a) Standard contractual clauses with data protection commitments equivalent to those of Brazilian legislation. (b) International transfer impact assessment to verify the level of protection in the destination country. (c) Guarantees that sub-processors apply adequate technical and organizational measures for data protection. We minimize the transfer of personal data abroad, using anonymization and pseudonymization whenever possible before sending data for AI model processing.
We implement robust technical and organizational measures to protect your personal data against unauthorized access, destruction, loss, alteration or leakage:
- Encryption in transit (TLS 1.2+) for all communications between the browser and our servers.
- Encryption at rest (AES-256) for data stored in our databases and file systems.
- Multi-tenant isolation with role-based access control (RBAC), ensuring each organization accesses only its own data.
- Automatic sensitive data masking (PII masking) in logs and development environments.
- Automatic backups with geographic redundancy and periodic restoration testing.
- 24/7 monitoring with anomaly detection and real-time security alerts.
- Primary infrastructure hosted in data centers in Brazil with security certifications (ISO 27001, SOC 2).
- Periodic penetration testing conducted by specialized teams.
- Security and privacy training program for all employees.
We retain your personal data only for as long as necessary to fulfill the purposes described in this Policy, observing the following periods:
- Account data: retained while the account is active, plus 6 (six) months after closure to allow reactivation and meet legal obligations.
- Access and security logs: retained for 12 (twelve) months, as required by the Marco Civil da Internet (Law No. 12,965/2014).
- Communication data (messages): retained according to the User's Workflow configuration, plus 90 (ninety) days after deletion for backup and recovery purposes.
- Financial and fiscal data: retained for 5 (five) years, as required by Brazilian tax legislation.
- Anonymized and aggregated data: may be retained indefinitely, as they do not allow identification of the data subject.
In accordance with the LGPD (Brazilian General Data Protection Law), you have the following rights regarding your personal data:
- Confirmation of processing: know whether Catalisa processes your personal data.
- Data access: obtain a copy of the personal data we hold about you.
- Data correction: request correction of incomplete, inaccurate or outdated data.
- Anonymization, blocking or deletion: request when data is unnecessary, excessive or processed in non-compliance with the LGPD.
- Data portability: obtain your data in a structured format for transfer to another service provider.
- Deletion of consent-based data: request deletion of data whose processing was based on consent.
- Information about sharing: know which public and private entities your data was shared with.
- Objection to processing: object to processing based on legitimate interest, if you believe your rights prevail.
- Review of automated decisions: request human review of decisions made solely based on automated processing of personal data, including AI Agent decisions.
The Platform uses AI Agents that process personal data in an automated manner to generate responses, classify requests and execute Workflows. In accordance with the LGPD (Art. 20), you have the right to request human review of decisions made solely based on automated processing of personal data that affect your interests, including profiling decisions. To request human review or obtain information about the logic used in automated decisions, contact our Data Protection Officer at privacidade@catalisa.io. We will respond within 15 (fifteen) business days.
When the User processes personal data of their own customers through the Platform (especially via WhatsApp integrations), the parties operate in the following roles: - User: Controller of their customers' personal data. Responsible for defining the purpose and legal basis for processing, informing their customers about the use of the Platform and handling data subject rights requests. - Catalisa: Processor of the User's customers' personal data. Processes data exclusively according to the User's instructions and for the provision of contracted services. The User is responsible for: (a) Ensuring they have a valid legal basis for processing their customers' data through the Platform. (b) Providing clear information to their customers about data processing, including the existence of AI processing. (c) Handling data subject rights requests in a timely manner. (d) Entering into a Data Processing Agreement (DPA) with Catalisa, when necessary, available upon request.
In the event of a security incident that may pose a risk or relevant harm to personal data subjects, Catalisa will take the following measures: (a) Notification to the National Data Protection Authority (ANPD) within 72 (seventy-two) hours after confirmation of the incident, in accordance with Art. 48 of the LGPD. (b) Communication to affected data subjects, within a reasonable timeframe, containing: description of the nature of the affected data, information about the risks, measures taken to mitigate the effects and guidance for the data subject. (c) Internal incident record with complete documentation: nature, affected data, impacted data subjects, technical measures taken and results of containment actions. (d) Notification to the User (when acting as Processor) so that they may take the necessary measures with their customers.
When you connect a Google account to the Catalisa Platform, we access and use data from that account solely to provide the features you enable. Catalisa's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Google Calendar: we check your availability (free and busy periods) and create, update and cancel calendar events that you — or automations and AI agents you configure — request. Used, for example, to schedule meetings with your customers during a conversation.
- Gmail (send): we send emails on your behalf when you, or an automation you configure, trigger a send from the Platform (for example, meeting confirmations and follow-up messages). We do not read your inbox.
- Account identification: we access your Google email address only to identify which account was connected, so you can recognize and manage it.
- We do not use data obtained from Google APIs for advertising, and we do not sell it.
- We do not transfer data obtained from Google APIs to third parties except as necessary to provide the features described, when required by law, or with your explicit consent.
- Humans do not read this data, except (i) with your explicit consent, (ii) for security purposes (such as investigating abuse or incidents), (iii) to comply with a legal obligation, or (iv) when the data is aggregated and anonymized.
- Access tokens are stored encrypted. You can revoke access at any time within the Platform or at myaccount.google.com/permissions.
Minors. Our services are not intended for individuals under 18 (eighteen) years of age. We do not intentionally collect personal data from minors. If you become aware that data from a minor has been collected, please contact us so we can delete it. Changes to this Policy. We may update this Privacy Policy periodically. Significant changes will be communicated with a minimum of 30 (thirty) days' advance notice by email or Platform notification. Continued use of the Platform after the notice period constitutes acceptance of the updated Policy. Contact. To exercise your rights, clarify questions or submit complaints about this Policy: DPO email: privacidade@catalisa.io General email: contato@catalisa.io WhatsApp: +55 11 97730-3414 Jurisdiction. The courts of Sao Paulo, State of Sao Paulo, Brazil, are elected to resolve any disputes arising from this Policy.