Privacy Policy
Last updated: June 12, 2026
This Privacy Policy describes how IAChatbot ("we", "us" or "our") collects, uses, stores and protects personal information when you use our AI chatbot software-as-a-service (SaaS) platform, website, APIs and related services, including interactions through WhatsApp, Instagram and other channels connected via the official Meta APIs.
1. Who we are
IAChatbot provides custom AI chatbot solutions for businesses. We act as a data processor on behalf of our business customers when handling end-user conversations, and as a data controller for account, billing and website-related information.
2. Information we collect
Depending on how you interact with our services, we may collect:
- Account and business information: company name, contact name, email address, phone number, billing details and service configuration data provided when signing up or requesting a demo.
- End-user conversation data: names, phone numbers, usernames, message content, media files (audio, images, documents), metadata and other information exchanged through connected channels such as WhatsApp and Instagram.
- Technical and usage data: IP address, browser type, device information, log files, cookies and analytics related to website and platform usage.
- Integration data: information retrieved from or sent to third-party systems you connect (such as CRM, ERP or scheduling tools), as authorized by you or your organization.
3. How we use information
We use collected information to:
- Provide, operate, maintain and improve our AI chatbot SaaS platform;
- Configure, train and optimize chatbot responses for your business;
- Respond to support requests, demos and commercial inquiries;
- Process payments, manage subscriptions and send service-related communications;
- Monitor performance, prevent fraud, abuse and security incidents;
- Comply with legal, regulatory and contractual obligations.
We do not use end-user conversation content to train general-purpose AI models for unrelated third parties without appropriate authorization.
4. Legal bases for processing
Where applicable under GDPR and similar laws, we process personal data based on contract performance, legitimate interests (such as platform security and service improvement), consent and legal obligation. Under LGPD, processing may rely on consent, contract execution, legitimate interest or compliance with legal obligations, as applicable.
5. Sharing of information
We do not sell or rent your personal information. We may share data only with:
- Service providers: cloud hosting, messaging infrastructure, payment processors, analytics and support tools that help us deliver the service, under contractual confidentiality and security obligations;
- Meta and messaging partners: when required to operate WhatsApp, Instagram or other official messaging integrations;
- Your authorized integrations: CRM, ERP, email or other systems you connect to the platform;
- Legal authorities: when required by law, court order or to protect rights, safety and security.
6. International transfers
Your information may be processed in countries other than your own. When we transfer data internationally, we apply appropriate safeguards such as standard contractual clauses and security measures consistent with applicable data protection laws.
7. Data retention
We retain personal data only for as long as necessary to provide the service, fulfill contractual obligations, resolve disputes, enforce agreements and comply with legal requirements. Retention periods may vary depending on the type of data and your account settings.
8. Security
We implement technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure or destruction, including encryption in transit and at rest, access controls, monitoring and regular security reviews.
9. Your rights
Depending on your location, you may have the right to access, correct, update, delete, restrict or object to processing of your personal data, request portability and withdraw consent where processing is consent-based. You may also lodge a complaint with a data protection authority.
To exercise your rights, contact us at: developer@iachatbot.com.br.
10. Cookies and Google Analytics 4
Our website iachatbot.com.br uses cookies and similar technologies:
- Strictly necessary cookie (
cookie_consent): stores whether you accepted or declined analytics cookies. - Analytics cookies (Google Analytics 4) — only after explicit consent via our cookie banner: we measure visits, page views, traffic sources and interactions (WhatsApp clicks, contact form submissions, etc.). Provider: Google Ireland Limited / Google LLC, measurement property G-6V9Q8L64G2. We use Google Consent Mode v2. Google privacy policy: policies.google.com/privacy.
- Heatmaps and session recording (Microsoft Clarity) — aggregated, anonymous capture of clicks, scrolling and navigation to improve usability; form fields and sensitive text are masked. Before consent it runs cookieless; after consent it may use cookies. Provider: Microsoft Corporation. Microsoft privacy statement.
Analytics cookies are not activated until you click Accept. You may refuse, accept or change your choice via the banner or the Manage cookies link in the site footer.
Legal basis (LGPD/GDPR): consent for analytics cookies; legitimate interest for aggregated, anonymous usage analysis (heatmaps) with data masking.
11. Children's privacy
Our services are intended for businesses and are not directed at children under 13 (or the minimum age required by applicable law). We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated revision date. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
13. Contact
If you have questions about this Privacy Policy or our data practices, contact us at: developer@iachatbot.com.br.
