OMARCUSDEV
Privacy Policy
Last updated: August 6, 2026 · Versão em português · Terms of Service
1. Who we are
OMARCUSDEV is the trade name of M Vinicius Costa Goncalves Tecnologia Ltda, registered under Brazilian company number (CNPJ) 57.751.797/0001-86, headquartered in Porto Alegre/RS, Brasil (“we”). We operate a WhatsApp customer-service and conversation-automation platform offered to businesses under our product brands.
This policy describes how we handle personal data on our websites, in our web dashboard, and in our integrations with the WhatsApp Business Platform, under Brazil's General Data Protection Law (Law 13,709/2018 — LGPD).
2. Two distinct roles: controller and processor
Two sets of data must be distinguished, because our obligations differ for each:
- Our customers' data (the business that subscribes to the service and the people who use the dashboard). Here we are the controller: we decide the purposes of processing.
- Conversation data exchanged between our customer and their own WhatsApp contacts. Here we are a processor: we handle that data on the customer's instructions, and the customer is the controller of that relationship. If you messaged a business that uses our platform and want to exercise rights over those messages, address the request to that business — we support them in executing it.
3. Data we collect
- Account: name, email, password (stored hashed), phone number, company and subscription plan.
- Billing: transaction identifiers, payment status and minimal tax data. We do not store full card numbers — processing is handled by the payment providers listed in section 6.
- WhatsApp connection: connected phone number, WhatsApp Business account identifiers (WABA ID, phone number ID), access tokens and connection status.
- Conversation content: messages sent and received (text, media, audio, documents), contact display name and number, timestamps, delivery status and technical message metadata.
- AI agent configuration: prompts, instructions, knowledge base and documents the customer uploads to train their assistant.
- Usage and diagnostics: access logs, IP address, user agent, product events, errors and performance metrics.
- Website browsing: pages visited, traffic source and campaign parameters (UTM), via cookies and pixels.
4. How we use it
- Deliver the service: connect the WhatsApp account, send and receive messages, organize conversations and generate automated replies with artificial intelligence.
- Authenticate users and keep the platform secure.
- Bill customers, issue invoices and enforce plan limits.
- Provide technical support and investigate incidents.
- Improve the product through aggregated usage metrics.
- Send service changes and operational notices, and — with consent — marketing communications.
- Comply with legal and regulatory obligations.
We do not use customer conversation content to train our own or any third party's AI models. Messages are sent to AI providers solely to generate the reply for that specific conversation.
We do not sell personal data.
5. Legal bases (LGPD)
- Performance of a contract (art. 7, V) — operating the platform for our customers.
- Legitimate interest (art. 7, IX) — security, fraud prevention and product improvement.
- Compliance with legal obligation (art. 7, II) — tax and regulatory duties.
- Consent (art. 7, I) — non-essential cookies and marketing communications.
6. Who we share with
We share data only with vendors required to operate the service, under contractual confidentiality and security obligations:
- Meta Platforms (WhatsApp Business Platform): sending and receiving messages. We act as a Tech Provider and processing follows Meta's terms.
- Amazon Web Services: hosting, database and media storage (us-east-1 region, United States).
- Amazon Bedrock: generation of AI replies (Anthropic Claude models), running on AWS infrastructure.
- Payment processors (Cakto and AbacatePay): card and Pix billing.
- PostHog: product analytics.
- Meta Pixel and Google: campaign measurement on our marketing websites.
- Public authorities, upon a valid legal request.
7. International transfers
Our infrastructure and AI providers operate in the United States. By using the platform, your data is transferred outside Brazil, with contractual safeguards agreed with those vendors, under art. 33 of the LGPD.
8. Retention and deletion
- Account and conversation data are retained while the subscription is active.
- After account closure, data is deleted upon request, except records we are legally required to keep (for example, tax data and access logs under the Brazilian Internet Civil Framework).
- Deletion performed by the platform is permanent: records are removed, not merely hidden.
- To request deletion at any time, write to contato@omarcusdev.com.br.
9. Security
We use encryption in transit (TLS), per-tenant data isolation, credential-based access control and environment segregation. No system is immune to incidents; in the event of a material breach we will notify affected data subjects and the Brazilian data protection authority (ANPD) under art. 48 of the LGPD.
10. Your rights
The LGPD grants confirmation of processing, access, correction, anonymization, portability, erasure, information about sharing, and withdrawal of consent. To exercise them, write to contato@omarcusdev.com.br. We respond within 15 days.
11. Cookies
We use essential cookies (session and authentication) plus measurement and marketing cookies. You can block non-essential cookies in your browser settings; essential ones are required for the dashboard to work.
12. Minors
The platform is intended for businesses and is not directed at people under 18. We do not knowingly collect data from children or adolescents.
13. Changes
We may update this policy. Material changes will be announced by email or in-dashboard notice, and the last-updated date at the top of this page always reflects the version in force.
14. Contact
Data Protection Officer and support: contato@omarcusdev.com.br
M Vinicius Costa Goncalves Tecnologia Ltda — CNPJ 57.751.797/0001-86 — Porto Alegre/RS, Brasil