Privacy

Privacy Policy

Last updated: March 2026

At RedSync, we take your privacy seriously. This document clearly explains how we collect, use, and protect your information when you use our platform.

1. Who We Are

REDSYNC Ecossistema e Tratamento de Dados LTDA (CNPJ 53.734.743/0001-51) is the company responsible for this platform.

Data Protection Officer (DPO): [email protected]

2. Roles: Controller and Processor

RedSync as Controller — when we collect and process data from our customers (the companies and their employees who subscribe to the platform). In this case, we make the decisions about processing your registration, payment, and usage data.

RedSync as Processor — when we process data entered by our customers within the platform (CRM contacts, Chat messages, AI Agent documents, etc.). In this case, our customer is the data controller and we follow their instructions.

If you are an end consumer interacting with one of our customers through Chat (WhatsApp, Instagram, or another channel), the controller of your data is the company you are communicating with. To exercise your rights regarding that data, contact that company directly.

3. What Data We Collect

3.1 Registration and Account Data

  • Name and email — identification, authentication, and communication
  • Profile photo — interface personalization (optional)
  • Company data (name, CNPJ) — business account identification
  • Payment data — subscription processing via Stripe
  • Access logs (IP, date/time, action) — security and auditing

3.2 Data Processed in Modules

When you use the platform's modules, the data you enter is processed according to the controller's (your company's) instructions.

Intelligence (Marketing Analytics)

OAuth access tokens from external platforms (Meta Ads, Google Ads, Instagram, Google Analytics, LinkedIn, Google My Business), performance metrics from connected accounts, and custom dashboards.

Chat (Omnichannel Customer Service)

Messages from conversations via WhatsApp, Instagram, Facebook, and other channels; contact data (name, phone, email, tags); interaction history; templates and automated workflows; media files sent and received.

CRM (Customer Relationship Management)

Company and contact data (name, phone, email, address), deals/opportunities (values, stages, assignees), registered products and services.

Tasks

Tasks, subtasks, comments, attachments, assignees, and due dates.

AI Agents

Conversations with AI agents, knowledge base documents, agent configurations, and response quality feedback.

Automations

Business rules that process data between modules and automation execution history.

3.3 Automatically Collected Data

IP address, browser type and operating system, pages accessed, time of use, and cookies essential to the session. Subject to consent, we also collect audience metrics via Google Analytics 4 — see section 12 (Cookies).

4. How We Use Your Data

What we do not do: we do not sell personal data, we do not use the content of your conversations or documents to train AI models, we do not share data between different accounts, and we do not display advertising on the platform.

  • Provide the contracted service: authentication, access, and features
  • Process payments and issue invoices via Stripe
  • Communication: service notices, security alerts, notifications
  • Security: prevention of unauthorized access and fraud detection
  • Product improvement: aggregated and anonymized usage analysis
  • Compliance with legal obligations and court orders

5. Artificial Intelligence and Data

When you use the AI Agents module, conversation content is sent to external providers (OpenAI, Anthropic, or Google) to generate responses. Data sent via API is not used for model training by these providers.

Knowledge base documents are stored on our infrastructure and sent as context only during response generation. You can delete conversations and documents at any time.

6. With Whom We Share Data

We share data only with strictly necessary third parties:

We may also share data with public authorities when required by law or court order. We do not share data with advertising companies or data brokers.

  • Supabase (AWS) — database, authentication, and storage (USA)
  • Stripe — payment processing (USA)
  • Meta Platforms — WhatsApp Business API, Instagram, Facebook (USA)
  • Google — Ads, Analytics, My Business, Search Console APIs and Google Analytics 4 for website audience measurement, subject to consent (USA/Ireland)
  • OpenAI — AI Agent conversation processing (USA)
  • Anthropic — AI Agent conversation processing (USA)
  • Oracle Cloud (OCI) — infrastructure hosting (Brazil — GRU)

7. International Data Transfer

Your data may be transferred to the United States, where our sub-processors' servers are located. This transfer is carried out in accordance with Art. 33 of the LGPD. All sub-processors maintain security standards equivalent to or higher than those required by Brazilian law. The primary hosting infrastructure (Oracle Cloud) is located in Brazil.

8. How Long We Store Data

After account deletion, all data is removed within 30 days, except where legally required to retain.

  • Account and profile data — while the account is active + 6 months after deletion
  • Access logs — 6 months (Marco Civil da Internet, Art. 15)
  • Chat messages — while the account is active (archived after 90 days of inactivity)
  • CRM and Tasks data — while the account is active
  • AI conversations and knowledge base — while the account is active (deletable at any time)
  • Payment data — 5 years after the transaction (tax obligation)
  • OAuth tokens — while the integration is active (revoked upon disconnection)

9. Data Security

We adopt technical and organizational measures to protect your data:

No system is 100% secure. We recommend using strong passwords and enabling two-factor authentication when available.

  • Encryption in transit (TLS/HTTPS) and at rest
  • Secure authentication with JWT tokens and rate limiting
  • Row Level Security (RLS) — each account can only access its own data
  • OAuth tokens stored securely and encrypted
  • Security headers (Helmet, restricted CORS)
  • Complete isolation between different customer accounts

10. Security Incidents

In the event of a security incident that poses a risk to data subjects, we commit to notifying the Brazilian National Data Protection Authority (ANPD) and affected data subjects, in accordance with Art. 48 of the LGPD, reporting the nature of the data, the risks, and the measures taken.

11. Your Rights (LGPD, Art. 18)

You have the right, at any time, to:

To exercise your rights: [email protected]. You can also access, edit, and delete your data directly in the platform Settings.

Response time: up to 15 business days. If your rights are not addressed, you may file a complaint with the ANPD at www.gov.br/anpd.

  • Confirm whether we process your personal data
  • Access and obtain a copy of your data
  • Correct incomplete, inaccurate, or outdated data
  • Request anonymization, blocking, or deletion of unnecessary data
  • Port your data to another provider
  • Request deletion of data processed based on consent
  • Know with whom we share your data
  • Revoke your consent

12. Cookies

We use strictly necessary cookies, which do not require consent: authentication session (to keep you logged in) and theme (light/dark) and language preferences.

With your consent, we also use Google Analytics 4 analytics cookies (Google Ireland Limited / Google LLC), which help us understand how the site's pages are accessed and improve them. These cookies collect pseudonymized browsing data — pages visited, time on page, traffic source, device and browser type, and truncated IP address. We do not use them for targeted advertising and we do not sell this data.

Until you allow it, Google Analytics runs in restricted mode (Consent Mode v2): no analytics cookie is stored in your browser and no identifier is sent. The legal basis is your consent (LGPD, Art. 7, I).

You may grant or withdraw consent at any time through the “Cookie preferences” link in the site footer. Withdrawing is as simple as granting and does not affect how the rest of the site works. You can also block or delete cookies in your browser settings.

13. Children's Data

RedSync is a B2B platform intended for companies and professionals over 18 years of age. We do not intentionally collect data from minors. If you are a legal guardian and believe a minor has provided data, please contact [email protected].

14. Data Processing Agreement (DPA)

For customers on Enterprise, Scale, and White Label plans, we offer a DPA that formalizes the responsibilities between controller and processor. To request one, contact [email protected].

15. Changes to This Policy

We may update this policy periodically. Significant changes will be communicated via email or platform notice. Continued use after notification constitutes acceptance of the changes.

16. Contact

For questions, suggestions, or requests: