Privacy Policy
FunnelChat, as the controller of personal data, presents this Privacy Policy (“Policy”) describing how we collect, use, store, share and protect the personal data of users of the FunnelChat Manager platform (“Platform”).
This Policy was prepared in compliance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA) and other applicable data protection laws.
1. Introduction and Commitment
1.1. We respect the privacy of our users and are committed to protecting their personal data. This Policy details our data processing practices in a transparent, clear and accessible manner, as required by Article 9 of applicable data protection laws.
1.2. By using the Platform, the User declares that they have read and understood this Policy. We recommend reading this document periodically, as it may be updated to reflect changes in our practices or in the law.
2. Data Controller
2.1. The controller of the personal data processed by the Platform is:
- Legal name: FunnelChat
- Website: manager.whatsgo.wa-api.io
2.2. Data Protection Officer (DPO):
- Email: privacy@funnelchat.com
- Service channel: available Monday to Friday, from 9 a.m. to 6 p.m. (US Eastern Time (ET)), with a response time of up to 15 (fifteen) business days, in accordance with applicable data protection laws.
3. Personal Data Collected
We collect the following types of personal data, organized by category:
3.1. Registration Data
Collected when registering and maintaining an account on the Platform:
- Full name;
- Email address;
- CPF or CNPJ (for billing and tax purposes);
- Phone number;
- Address (when required for billing);
- Company name and position (when applicable).
3.2. Financial Data
Related to contracting and paying for the services:
- Payment data processed by Stripe (we do not store full credit card data on our servers);
- Transaction and invoice history;
- Contracted plan and subscription status;
- Tax data for billing.
3.3. Usage Data
Collected automatically while using the Platform:
- IP address;
- Browser type (User Agent) and operating system;
- Pages visited and time spent;
- Date and time of access;
- Logs of actions performed on the Platform;
- Device information and screen resolution.
3.4. API and Instance Data
Related to the technical use of the Platform:
- Data of the configured WhatsApp instances (numbers, status, settings);
- Configured webhook URLs;
- API keys and access tokens;
- API call logs (endpoints, parameters, responses);
- Usage metrics (messages sent/received, media processed).
3.5. Communication Data
When the User contacts us through support channels:
- Content of emails and support messages;
- Support records.
3.6. Cookies and Tracking Technologies
We use cookies and similar technologies as detailed in our Cookie Policy.
4. Purposes and Legal Bases for Processing
We process personal data based on the following purposes and legal grounds set out in applicable data protection laws (including the GDPR):
| Purpose | Legal Basis (GDPR) | Data Used |
|---|---|---|
| Account creation and maintenance | Contract performance (item V) | Registration |
| Provision of the contracted services | Contract performance (item V) | Registration, API, Usage |
| Payment processing | Contract performance (item V) | Registration, Financial |
| Billing and invoice issuance | Contract performance (item V) | Registration, Financial |
| Compliance with fiscal and tax obligations | Legal obligation (item II) | Registration, Financial |
| Technical support and customer service | Contract performance (item V) | Registration, Communication, Usage |
| Platform security and fraud prevention | Legitimate interest (item IX) | Usage, IP, Logs |
| Service improvement and user experience | Legitimate interest (item IX) | Usage, Navigation |
| Sending service-related (transactional) communications | Contract performance (item V) | Registration |
| Sending marketing communications | Consent (item I) | Registration |
| Compliance with judicial or administrative decisions | Legal obligation (item II) | As requested |
| Analytics and aggregated metrics | Legitimate interest (item IX) | Usage (anonymized) |
4.1. Where the legal basis is consent, the User may revoke it at any time, without prejudice to the lawfulness of the processing carried out previously. Revocation can be done through the account settings or by email at privacy@funnelchat.com.
4.2. Legitimate interest as a legal basis is used exclusively when the fundamental rights and freedoms of the data subject requiring the protection of personal data do not prevail, as documented by the Company (Data Protection Impact Assessment).
5. Data Sharing
5.1. We may share personal data with third parties in the following cases:
5.1.1. Payment Processors
- Stripe, Inc. (USA): processing of credit card payments and international methods. Data shared: name, email, payment data. Privacy policy: stripe.com/privacy;
5.1.2. Infrastructure Providers
- Cloud hosting providers for data storage and processing;
- CDN (Content Delivery Network) providers for static content distribution;
- Object storage providers (S3-compatible) for media.
5.1.3. Communication Providers
- Email providers (SMTP) for sending transactional and marketing emails;
- Notification services for Platform alerts.
5.1.4. Competent Authorities
- When required by law, regulation, judicial process or valid government request;
- To protect the rights, property or safety of the Company, its users or the public.
5.2. All third parties with whom we share data are contractually obligated to maintain the confidentiality and security of the data, using it exclusively for the contracted purposes.
5.3. The Company does NOT sell, rent or trade its users' personal data to third parties for marketing purposes.
6. International Data Transfer
6.1. Some of our service providers are located outside your country of residence, notably in the United States (for example, Stripe). In these cases, the international transfer of data occurs in compliance with applicable international transfer safeguards (Articles 33 to 36), based on the following safeguards:
- Standard contractual clauses for data protection;
- Certifications and seals recognized by the competent data protection authority (when available);
- Complementary technical and organizational measures (encryption in transit and at rest).
6.2. Personal data transferred internationally remains subject to the protections set out in this Policy and in applicable law.
7. Data Retention
7.1. We keep personal data for as long as necessary to fulfill the purposes for which it was collected, according to the following periods:
| Data Type | Retention Period | Justification |
|---|---|---|
| Registration data | Account term + 6 months | Enable reactivation and contract fulfillment |
| Financial and tax data | 5 years after the transaction | Fiscal/tax obligation (applicable tax law Art. 173) |
| Access logs (IP, date/time) | 6 months | applicable legal retention obligations |
| API and webhook logs | 90 days | Technical support and incident resolution |
| Communication data (support) | 2 years | Service history and quality |
| WhatsApp instance data | Account term + 30 days | Contract fulfillment |
| Session cookies | Until the session ends | Essential functionality |
7.2. At the end of the retention period, the data will be anonymized or permanently deleted, except where retention is required by law.
8. Data Subject Rights
8.1. In compliance with Articles 17 to 22 of applicable data protection laws, the data subject has the following rights:
- Confirmation of the existence of processing;
- Access to the data;
- Correction of incomplete, inaccurate or outdated data;
- Anonymization, blocking or deletion of unnecessary data or data processed in non-compliance with applicable data protection laws;
- Portability of the data to another service or product provider;
- Deletion of personal data processed based on consent;
- Information about public and private entities with which the controller has shared data;
- Information about the possibility of not consenting and about the consequences of refusal;
- Revocation of consent.
8.2. To exercise your rights, visit the GDPR - Data Subject Rights page or contact our Data Protection Officer by email at privacy@funnelchat.com.
8.3. We will respond to requests within 15 (fifteen) business days, as provided by law. In highly complex cases, the deadline may be extended by notifying the data subject.
9. Data Security
9.1. We adopt appropriate technical and organizational measures to protect personal data against unauthorized access, destruction, loss, alteration or any form of inappropriate processing, including:
- Encryption in transit: all communications are carried out via HTTPS/TLS;
- Encryption at rest: sensitive data stored with AES-256-GCM;
- Authentication: support for two-factor authentication (2FA);
- Access control: least-privilege principle for data access;
- API tokens: authentication keys with a minimum of 16 characters;
- Monitoring: access logs and detection of anomalous activity;
- Backup: automated backup routines with encryption;
- Infrastructure: servers in protected environments with geographic redundancy.
9.2. Despite our efforts, no security system is completely invulnerable. The User must adopt good security practices, such as using strong passwords, enabling 2FA and not sharing access credentials.
10. Security Incidents
10.1. In the event of a security incident that may pose relevant risk or harm to data subjects, the Company will:
- Notify the the competent data protection authority within a reasonable time, in accordance with applicable data protection laws;
- Notify the affected data subjects, informing them of the nature of the affected personal data, the measures taken and the recommendations to mitigate possible effects;
- Take immediate measures to contain the incident and minimize its effects.
10.2. The Company maintains a documented and up-to-date incident response plan, with procedures for identification, containment, eradication and recovery.
11. Minors' Data
11.1. The Platform is not intended for minors under 18 (eighteen) years of age. We do not intentionally collect personal data of children or adolescents.
11.2. If we become aware that we have collected data of a minor without the proper consent of the parents or legal guardians, we will take immediate measures to delete such data, in accordance with applicable data protection laws.
12. Changes to the Policy
12.1. This Policy may be updated periodically to reflect changes in our data processing practices or changes in applicable law.
12.2. Substantial changes will be communicated by email and/or notification on the Platform at least 15 (fifteen) days before they take effect.
12.3. The date of the last update will always be shown at the top of this document.
13. DPO Contact
For questions related to privacy and personal data protection, contact our Data Protection Officer:
- DPO email: privacy@funnelchat.com
- General email: soporte@funnelchat.com
- WhatsApp: +1 (334) 530-5858
If you are not satisfied with our response, the data subject may file a complaint with the the competent data protection authority:
14. Scope
14.1. This Policy applies to visitors of our website, customers of the Platform and the end users of customers whose data is processed through the Service.
14.2. Where we act as a processor on behalf of a customer, the processing of end-user data is also governed by the contract and the Data Processing Agreement (DPA) entered into with that customer.
15. Funnelchat's Role (Controller vs. Processor)
15.1. We act as a controller when we collect data directly from website visitors, leads and customers to manage our business relationship.
15.2. We act as a processor when we process data on behalf of customers, including WhatsApp conversations, contact data and automated messages, in accordance with the customer's instructions.
16. Legal Bases under the GDPR
16.1. We process personal data on the basis of contract performance, consent, legitimate interest and compliance with legal obligations, as applicable.
16.2. Where processing is based on consent, the data subject may withdraw it at any time, without affecting the lawfulness of processing already carried out.
17. Artificial Intelligence
17.1. We do not use customer data to train artificial-intelligence models without express authorization.
17.2. Any automated decisions made available by the Platform are configured and supervised by the customer, who is responsible for their effects.
18. Customer Responsibility
18.1. The customer, as controller of its end users' data, is responsible for obtaining the necessary legal bases and consents and for complying with applicable law.
18.2. The customer is responsible for the appropriate use of WhatsApp and automations, as well as for handling data-subject requests relating to data under its control.
19. International Compliance
19.1. Data may be processed in the United States and other countries where our providers operate, under standard contractual clauses (SCCs) and equivalent security measures.
19.2. We seek to operate in compliance with the GDPR, the CCPA/CPRA and other data protection laws applicable to cross-border operations.
FunnelChat
Other legal documents