This Policy describes, in direct and auditable language, the processing of personal data performed by DialogOps (controller) in the context of the institutional site, the subscription process, and the operation of the Platform. The vocabulary and legal references vary depending on the selected legal region — the regional section below highlights the applicable law, the reference authority, and local specifics. In the event of divergence between translated versions, the Portuguese version prevails.
1. What data we process
We process the following categories: (a) registration data — name, email, phone, tax ID, business name, billing address; (b) access credentials — password hash, session tokens, authentication factors; (c) Platform usage data — access logs, IP, device, browser, actions performed, operational metrics; (d) operational content — messages sent/received by your Users and end-customers, attachments, internal notes, service records; (e) payment data — minimum information needed for issuing the charge (payer tax ID, amount, status), processed by the contracted payment gateway (Gerencianet/EfiPay), which has its own policies; (f) commercial communication data — when you contact us via form, email, or support.
2. Why we use your data (purposes)
We use data strictly to: (i) perform the contract — create and maintain your account, process payments, provide technical support, guarantee operational continuity, issue invoices and tax documents; (ii) comply with legal obligations — retain records as required by applicable law, tax obligations, and cooperation with authorities when formally requested; (iii) protect security — detect attempts of fraud, abuse, intrusion, and investigate incidents; (iv) improve the product — analyze aggregate and anonymized usage to prioritize improvements; (v) communicate relevant service changes, term updates, and critical operational notices. Marketing communications are sent only with an appropriate legal basis (consent or legitimate interest) and may be canceled at any time.
3. Applicable legal grounds
Depending on the context, processing may be based on service performance, fraud prevention, security, legal obligations, internal product improvement, and user choice for optional storage or tracking categories.
4. Your rights as a data subject
Estados Unidos · FTC e leis estaduais, como CCPA/CPRA
- Know/access, delete e correct, quando aplicável.
- Opt-out de sale/share ou targeted advertising, quando aplicável.
- Limitação de uso de dados sensíveis nas hipóteses legais cabíveis.
5. Cookies, local storage, and telemetry
Cookies não essenciais podem ser recusados; quando tecnicamente aplicável, sinais como Global Privacy Control mantêm categorias opcionais desligadas até escolha manual.
O cenário norte-americano é fragmentado por estado; por isso usamos uma experiência mais conservadora do que o mínimo federal.
6. Sharing, retention, and security
We share data only with essential processors for service delivery — cloud infrastructure providers, payment gateway, official Meta/WhatsApp partners, and AI models — all under contracts with confidentiality obligations compatible with applicable law. We do not sell, rent, or transfer personal data to third parties for commercial purposes. Any international transfers are made to countries with adequate protection levels or via specific contractual clauses, as required by the applicable jurisdiction. Data is retained for as long as necessary for the contracted purposes and legal obligations of the applicable jurisdiction (including minimum retention of access logs, fiscal data, and operational data per local rules). We adopt reasonable technical measures — encryption in transit (TLS), access controls by profile, environment segregation, log monitoring, and periodic reviews.
We may rely on U.S. or international providers for infrastructure, messaging, email, and AI services. We aim to document roles, limit optional disclosures, and keep non-essential tracking off until the user chooses otherwise.
7. Data Protection Officer (DPO), incidents, and contact
Privacy requests, incident communications involving your data, or doubts about this Policy may be sent to the Data Protection Officer (DPO) through the official channels published on the site. Within a reasonable timeframe (and within the limits required by the law applicable to your jurisdiction), we notify the competent authority and, when applicable, the affected data subjects of relevant security incidents. The specific reference authority for your region (ANPD in Brazil, INAI in Mexico, AAIP in Argentina, URCDP in Uruguay, state regulators in the US, etc.) appears in the regional section. This Policy may be revised at any time; material changes are communicated with reasonable advance notice through registered channels.
Because the U.S. framework is fragmented, the relevant complaint path may depend on the state involved. California users, for example, may rely on rights and complaint channels tied to the CCPA/CPRA ecosystem.
State privacy regulators; for California, the California Attorney General / CPPA