Myndchat Data Processing Addendum
This is the agreement governing Myndchat's processing of the personal data of the people who talk to you over the channels connected to the platform. You are the one who decides about that data; we merely carry it out. This document puts that in binding terms, not merely descriptive ones.
Brazil's General Data Protection Law separates two roles: the controller, who decides why and how data is processed, and the processor, who processes on the controller's behalf. Article 39 requires the processor to follow the controller's instructions — and an instruction that is not written down is not an instruction. This agreement is where your instructions are written down.
It covers, among other things:
- exactly which data we process on your behalf, for how long, and for what;
- what we never do with it — and why that does not rest on our goodwill alone;
- who our subprocessors are, how you find out about a new one, and how to object;
- what happens in a security incident, within what deadline and with what content we notify you;
- how we assist when a data subject exercises rights against you;
- what happens to the data when the agreement ends.
This agreement applies automatically, with no separate signature. It forms part of the Terms of Service and takes effect, for you, the moment you accept the Terms and connect your first channel. If your legal team needs a signed copy, write to juridico@myndchat.com and we will sign this same wording — what we do not do is negotiate different versions per customer, because a processor operating under different rules for each customer cannot hold to any of them rigorously.
Where this agreement uses terms with a technical meaning — controller, processor, data subject, processing, incident — the meaning is the one in article 5 of the LGPD. Where it diverges from the Terms of Service on data protection matters, this agreement prevails.
Contents
- 1. The parties, and when this agreement applies
- 2. Who is controller and who is processor
- 3. Subject matter: what we process, whose, and for how long
- 4. Processing only on documented instructions
- 5. What the Customer warrants
- 6. Confidentiality and authorised personnel
- 7. Security measures
- 8. Subprocessors
- 9. International transfers
- 10. Assistance with data subject requests
- 11. Security incidents
- 12. Demonstrating compliance, and audits
- 13. Retention, return and deletion
- 14. Artificial intelligence
- 15. Allocation of liability between the parties
- 16. Term, changes and precedence
1. The parties, and when this agreement applies
On one side, MYNDCHAT TECNOLOGIA LTDA, company number (CNPJ) 65.434.606/0001-80, registered at Avenida Brigadeiro Faria Lima, 1811, Sala ESC 1119, Jardim Paulistano, São Paulo/SP, 01452-001, Brazil, referred to here as Myndchat. On the other, you — the company or professional who holds the account — referred to here as the Customer.
This agreement applies to the processing of personal data of end contacts: the people who talk to the Customer over WhatsApp, Instagram Direct, Facebook Messenger or TikTok, through channels the Customer connected to the platform.
It does not apply to the Customer's own data or that of their team — sign-up, billing, product usage. For those, Myndchat is the controller, decides on its own and answers directly, and the Privacy Policy explains what it does with them. The two relationships coexist and must not be confused.
About the moment this agreement takes effect. As of this date, the Myndchat website is live and the platform is under construction. The obligations described here begin to take effect, for each Customer, when they create an account, accept the Terms and connect a channel. We publish it in advance because whoever is about to subscribe must be able to read the instrument before deciding, and because the platforms we integrate with require the documents to be published and live before authorising the integration.
| Subject | Address |
|---|---|
| Contractual matters and a signed copy of this document | juridico@myndchat.com |
| Privacy, data subject rights and this agreement | privacidade@myndchat.com |
| Data Protection Officer | encarregado@myndchat.com |
| Incidents and vulnerabilities | seguranca@myndchat.com |
Myndchat's Data Protection Officer is Bernardo Prantz Pin. Appointing a DPO is optional for a processor under the law; we treat it as mandatory, because the Customer needs a named counterpart when a data subject comes to them.
2. Who is controller and who is processor
This is the section that organises everything else, which is why it comes before any concrete obligation.
| Data | Controller | Processor | Who answers the data subject |
|---|---|---|---|
| Of the end contacts who talk to the Customer | The Customer | Myndchat | The Customer, with our assistance under section 10 |
| Of the Customer and their team: sign-up, billing, product usage | Myndchat | The providers listed on the Subprocessors page | Myndchat, directly |
| Of visitors to the website | Myndchat | The providers listed on the Subprocessors page | Myndchat, directly |
As controller of the end contacts' data, the Customer is the one who defines the purpose of each conversation, chooses the legal basis, obtains consent where consent is the applicable basis, sets retention periods within what the platform offers, and answers to the data subject and to the authority.
As processor, Myndchat executes. We do not decide why a message is sent, to whom, or with what content. We do not choose the Customer's legal basis. We are not a party to the relationship between the Customer and their own consumer.
This is not legal formality: it changes what we do in practice. No data processed as processor is used for Myndchat's own purposes, cross-referenced between different organisations, sold, transferred, used for advertising, or used to train artificial intelligence models, ours or anyone else's. Section 4 turns that into an obligation and section 14 covers the artificial intelligence case in detail.
If Myndchat ever came to determine the purpose or essential means of processing end contact data, it would cease to be a processor as to that processing and would take on controller obligations for it. That is not what we do today, and the possibility is written down because the law looks at substance rather than at labels.
3. Subject matter: what we process, whose, and for how long
The nature of the processing is the operation of a conversation automation and support platform: receiving, storing, organising, displaying, processing through automation, indexing for search and transmitting messages exchanged between the Customer and their end contacts.
The data subjects are the Customer's end contacts: the people who start or receive a conversation over a connected channel. The categories of data processed on the Customer's behalf, with the default retention period for each:
| Data category | Where it comes from | Default retention |
|---|---|---|
| Contact name and channel identifier | From the messaging platform, when the conversation arrives | 12 months |
| Phone number, in the case of WhatsApp | From the messaging platform | 12 months |
| Profile picture, where the channel sends one | From the messaging platform | 12 months |
| Full message content, in both directions | From the conversation | 12 months, configurable downward by the Customer |
| Images, audio, video and documents exchanged | From the conversation | 6 months, configurable downward by the Customer |
| Tags, custom fields and segments | Created by the Customer or by their automation | 12 months |
| Lead qualification | From the automation or the artificial intelligence layer | 12 months |
| Contact variables and contact memory | Written by explicit action of an automation or an agent | 12 months |
| Conversation variables | From the automation in progress | Discarded when the conversation ends |
| Deals, sales pipeline and journey events | Recorded by the Customer or by their automation | 12 months |
| Contact source and source ad | From the messaging platform | 12 months |
| Campaign and sequence membership | From the sending done by the Customer | 12 months |
| Internal team notes about the contact | Written by the agent, never sent to the contact | 12 months |
| Automation execution trace | From the automation engine | 90 days |
| Record of opt-in and opt-out | From the contact's own act or from the Customer's record | For as long as the organisation exists |
The opt-out record has a different retention period on purpose: it survives the deletion of that contact's other data. If it were deleted along with the rest, the person would start receiving messages again on the next import, and their request would stop being honoured.
The platform is not intended for the deliberate collection of sensitive data or of children's and adolescents' data. Because conversation content is written by third parties, Myndchat cannot prevent sensitive data from appearing in a message, and treats it with the same rigour as everything else. It falls to the Customer, as controller, to assess the applicable legal basis and to comply with article 14 of the LGPD where a child's or adolescent's data is involved.
The duration of the processing is the duration of the agreement between the parties, extended only by the deletion periods in section 13.
4. Processing only on documented instructions
Myndchat processes end contact data exclusively on the Customer's documented instructions. The following count as documented instructions for all purposes of this agreement:
- this agreement, the Terms of Service and the Privacy Policy;
- the settings the Customer applies inside the platform — retention periods, automations, integrations, team permissions and connected channels;
- written instructions the Customer sends to the addresses in section 1 and that Myndchat confirms in writing.
Beyond that, and without exception, Myndchat does not:
- use the data for its own purposes;
- cross-reference data between different customer organisations;
- sell, rent or transfer the data to third parties;
- use the data for advertising, ours or anyone else's;
- use the data to train artificial intelligence models, ours or third parties';
- access conversation content outside the cases in section 7.
This does not rest on our word alone. The agreement Myndchat holds with Meta to operate as a technology provider requires us to process data obtained through their platforms exclusively on the customer's behalf and in accordance with their instructions, and prohibits using it for any other purpose or disclosing it to third parties. Breaching this section would also put us in breach of that agreement, with loss of access to the channels.
If an instruction from the Customer appears to Myndchat to be contrary to data protection law, we will tell the Customer in writing and may suspend execution of that specific instruction until the point is clarified. We do not shut down the whole service over it.
Myndchat may process data outside the Customer's instructions where required by law or by order of a competent authority. In that case, it will inform the Customer before complying, unless the rule itself forbids the notice, and will limit compliance to what is strictly required.
5. What the Customer warrants
This agreement runs both ways. Myndchat can only be a compliant processor if the Customer is a compliant controller, and the warranties below are the counterpart of the obligations in the other sections.
The Customer states and warrants that they:
- hold a valid legal basis for every processing they instruct, including outbound messaging, and keep evidence of that basis;
- obtained the opt-in required by each channel's policies before starting a conversation, and honour opt-outs;
- informed their data subjects, clearly, about the processing and about the existence of a processor;
- do not use the platform for processing that requires a data protection impact assessment without having carried one out, where it is required of them;
- keep the contact details of their own Data Protection Officer up to date, where they have one, and answer data subjects within the statutory deadlines;
- configure retention periods and team permissions in line with their own privacy policy.
The Customer is solely responsible for the content they send and the lists they import. Myndchat does not pre-screen the legality of each message — it could not do so without reading everyone's conversations, which is exactly what this section and section 7 exist to prevent.
The Acceptable Use Policy supplements this section and forms part of this agreement. It is published as a page of its own, listed alongside, and describes what may not be done with the platform, the consent rule the channels require, and the enforcement ladder for abusive use, step by step.
6. Confidentiality and authorised personnel
Data processed on the Customer's behalf is confidential. The duty of confidentiality does not end with the agreement: it continues for as long as the data exists in any copy under Myndchat's control.
Internal access is restricted to the people who need it for their own role, under a written confidentiality undertaking that survives the end of their engagement. Each person and each system component sees only what is necessary — the principle of least privilege, applied internally as well.
Internal access to conversation content is exceptional. It requires a written justification, is time-limited, is fully logged, and the log appears in the audit trail of the Customer's own organisation — meaning the Customer can see that access happened, by whom and when, without depending on Myndchat to tell them.
The cases in which such access may occur are: an express request from the Customer, investigation of a security incident, investigation of reported abusive use, and compliance with a legal order. There is no case of access out of curiosity, for product analysis, or for model improvement.
7. Security measures
Myndchat adopts the technical and administrative measures required by articles 46 to 49 of the LGPD. Those below are the ones we actually apply, and they are the same ones declared in the Privacy Policy — the Customer does not receive a more generous list here than the one we publish to the market.
- Encrypted communication in transit across the entire service, without exception.
- Credentials for the Customer's channel accounts encrypted at rest, with the key managed outside the database, so that a copy of the database does not hand them over. They are never sent to the browser, never appear in logs, and are never displayed, not even partially.
- Isolation between organisations enforced in the database and on the server, independently: if one layer fails through a mistake of ours, the other keeps blocking.
- Automated tests that attempt to break isolation between organisations and that fail if the control is removed.
- Two-factor authentication available to everyone and mandatory for the administrator role on paid plans.
- Passwords checked against public breached-credential datasets at sign-up and on change, rejecting any that have appeared in a leak.
- An immutable audit trail recording who accessed what, when and from where.
- Media accessible only through a signed, temporary address scoped to the organisation. Never through a permanent public link.
- Sensitive data kept out of error and diagnostic logs, by a list of what may be logged rather than a list of what is forbidden — so a new field is born outside the log.
- Automated scanning for credentials in code and for vulnerabilities in dependencies on every change.
- Backups from the very first record, with a restore procedure that is tested and not merely documented.
We do not claim certifications we do not hold. None of the measures above is presented as a seal, a standard or a third-party audit: they are controls we implement and test. If and when we obtain a certification, it will be declared here with its name and date. A DPA hinting at certified compliance that does not exist would be the most expensive false statement in this set of documents.
The measures may evolve. Myndchat may replace one control with another, provided the level of protection does not decrease. A material reduction in the level of protection is communicated to the Customer before it takes effect.
Anyone who identifies a security flaw may write to seguranca@myndchat.com. We review every report received and take no action against anyone reporting in good faith, without exploiting the flaw beyond what is needed to demonstrate it and without accessing third-party data.
8. Subprocessors
Myndchat uses providers that carry out part of the service and, in doing so, process data on the Customer's behalf. Those are the subprocessors. By accepting this agreement, the Customer gives general authorisation for the use of subprocessors, on the conditions in this section.
The full list, with each provider's name, their exact role in the product, the category of data they receive and the country where they process it, is published on the Subprocessors page. It is versioned, and the date of the last verification appears on the page itself.
Each subprocessor is bound by contract to data protection obligations no less stringent than those in this document, limited to the function it performs. Myndchat is answerable to the Customer for its subprocessors' acts as if they were its own.
| Event | What Myndchat does | Deadline |
|---|---|---|
| A new subprocessor is added | Publishes the change on the Subprocessors page and notifies the Customer at the account contact address | At least 30 days before the provider begins processing data |
| A subprocessor is replaced | Same procedure, identifying who leaves and who arrives | At least 30 days beforehand |
| The Customer raises a reasoned objection | Reviews it and looks for a technical alternative avoiding the objected provider | Reply within 15 days of the objection |
| An objection that cannot be accommodated | Says so in writing; the Customer may terminate without penalty and export their data | Termination available for 30 days after the reply |
An honest caveat about objecting. The channel providers — Meta and TikTok — cannot be substituted: they are the very channel the Customer chose to connect. Objecting to them amounts to not using that channel. The same holds for the infrastructure provider while it hosts the entire platform. We say so here rather than promising an alternative that does not exist.
A provider engaged by the Customer themselves — a webhook endpoint, a system they integrate over an API — is not a Myndchat subprocessor. From the moment data leaves for a destination chosen by the Customer, the Customer answers for it.
9. International transfers
Some subprocessors process data outside Brazil. That is not a detail to be buried in an annex: it is a direct consequence of the messaging channels being operated by foreign companies.
Transfers rely on the mechanisms in article 33 of the LGPD, as applicable to each provider:
| Mechanism | When it applies | Legal basis |
|---|---|---|
| Adequacy decision | A provider processing in a country recognised by the authority as offering adequate protection | Article 33, I, of the LGPD |
| Standard contractual clauses | A provider processing in a country without an adequacy decision — today, most of them | Article 33, II, point b, and the standard clauses approved by the national authority |
| Performance of a contract with the data subject | Specific situations where the transfer is necessary to deliver what the data subject asked for | Article 33, IX |
The standard clauses adopted are those approved by the national authority, incorporated in full and without changes to their text. The regulatory deadline for incorporating them has already passed, and Myndchat has treated them as in force since then.
For each provider, the country of processing and the applicable mechanism appear on the Subprocessors page. When a provider's country of processing changes, the change follows the notice procedure in section 8.
10. Assistance with data subject requests
The Customer is the one who answers the data subject, because the Customer is the controller. Myndchat cannot decide, on the Customer's behalf, about data that is not ours — nor about the legal basis that justified the processing.
What Myndchat provides, and which is the assistance required by articles 38, 18 and 19 of the LGPD:
- features within the platform to locate, export, correct and delete a specific contact's data, so the Customer can respond without depending on us;
- a reply to a Customer request for assistance that the platform cannot resolve on its own, within 10 calendar days of receipt;
- the information only Myndchat holds — what was processed, when, by which component — where the Customer needs it in order to reply;
- forwarding to the Customer, within 5 business days, of any data subject request that reaches us directly, with confirmation to the data subject that it was forwarded.
If a data subject comes to us directly, we do not ignore them. We explain who the controller is, forward the request to the responsible Customer, confirm to the data subject that we forwarded it, and support the response as far as it is technically within our reach. What we do not do is decide, on the Customer's behalf, about data that is not ours.
The same applies to requests from the national authority and to judicial orders directed at the Customer's data: we inform the Customer before complying, except where the rule itself forbids the notice, and we limit compliance to what is strictly required.
Myndchat assists the Customer, as far as it is able, in preparing a data protection impact assessment where one is required, providing technical information about the processing it carries out.
11. Security incidents
A security incident is any event causing unauthorised access, destruction, loss, alteration, leakage or disclosure of personal data, even accidentally.
The Customer, as controller, is the one who notifies the national authority and the data subjects. Myndchat's obligation is to notify the Customer quickly and with enough content for them to meet theirs.
| Stage | Deadline | What Myndchat does |
|---|---|---|
| Initial notice to the Customer | Without undue delay, and at most 24 hours from our becoming aware | Reports that an incident occurred and what is known so far, even if the investigation is not complete |
| Full information | Within 3 business days of our becoming aware | Provides the information required by article 48, § 1, of the LGPD, to the extent it is within our reach |
| Updates | For as long as the investigation lasts | Reports any material new fact as soon as it is established, without waiting for closure |
| Record | Kept for at least 5 years | Records every incident, including those not notified to the authority, with the minimum information required by regulation |
The notice includes, to the extent established: the nature and categories of data affected, the approximate number of data subjects affected, the technical and security measures that were in place, the likely risks, the mitigation or reversal measures adopted, and the Data Protection Officer's contact details.
The 3 business day deadline is the full regulatory deadline, and Myndchat adopts it deliberately, without invoking the doubled deadline available to small-scale processing agents. The reason is written in the Privacy Policy: the nature of the processing we carry out rules out that classification, and in case of doubt we choose the shorter deadline.
Myndchat does not notify the Customer's data subjects of an incident on its own initiative, unless the authority so determines or the Customer asks in writing. Two uncoordinated communications about the same event only confuse the people who need to understand what happened.
12. Demonstrating compliance, and audits
Myndchat makes available to the Customer the information needed to demonstrate compliance with this agreement, in the manner set out below, which is what a company of our size can sustain honestly.
| Resource | How to obtain it | Cost |
|---|---|---|
| Public documentation: this agreement, the Privacy Policy, the Subprocessors page and the Cookie Policy | Available on the website, versioned | None |
| The organisation's own audit trail, including internal accesses to content | Inside the platform, at any time | None |
| The Customer's security questionnaire answered in writing | Request to juridico@myndchat.com | None, once a year |
| On-site audit or audit by an independent third party | Reasoned request, with scope and auditor agreed in advance | Auditor's costs borne by the Customer |
An on-site or third-party audit is limited to one per year, except where it follows a confirmed security incident or an order from an authority, in which case there is no limit and no waiting period. It is scheduled at least 30 days in advance, takes place during business hours, and must not compromise the security or confidentiality of other customers' data.
What we do not offer, said plainly: we hold no third-party certification, we have no independent audit report, and we do not pretend otherwise. If the Customer's procurement process requires one of those, this is the moment to find out — not after signing.
13. Retention, return and deletion
During the agreement, each data category is kept for the period in section 3, and the Customer may shorten the configurable periods at any time inside the platform. A period shortened by the Customer prevails over the default.
When the agreement ends, for any reason:
| Stage | Deadline | What happens |
|---|---|---|
| Export window | 30 days from termination | The Customer may export their data in a machine-readable format, at no cost |
| Deletion from database and storage | Within 60 days of termination | The data is deleted from production systems |
| Backups | Within 90 days of termination | Backups still containing the data are overwritten in the normal cycle |
| Channel credentials | At the moment of disconnection or termination | Revoked at the provider and deleted locally |
Deletion here means removal from the database, from file storage and, in the appropriate cycle, from backups as well. It does not mean merely hiding the record in the interface.
Three exceptions, declared rather than hidden. First: data Myndchat must keep under a legal obligation of its own — application access logs, tax documents, incident records — remains for the period of that obligation, isolated and not used for any other purpose. Second: a judicial order or the need to defend a claim suspends deletion of that specific item, for as long as strictly necessary. Third: the end contact's opt-out record survives the purge, for the reason explained in section 3.
Myndchat confirms deletion in writing on the Customer's request, stating what was deleted and what remained under the exceptions above.
14. Artificial intelligence
The artificial intelligence layer is an optional add-on. Until the Customer subscribes to it and switches it on, no conversation data is sent to any language model provider. This section only takes effect for those who use it.
When switched on, what is sent to the model provider is a slice assembled for that particular reply, not the Customer's database:
| What is sent | To whom | What the provider does with it |
|---|---|---|
| Up to fifteen recent messages from the conversation, a compacted summary, the instructions the Customer configured, and the relevant variables and memories for that contact | The language model provider, to generate the reply, summary or translation | Does not use it to train models, by contractual obligation. Deletes the content within 30 days |
| The text of the questions and answers registered by the Customer and of the indexed conversations, converted into a numeric representation | The embedding provider, for similarity search | Does not use it to train models. Keeps abuse-monitoring records for up to 30 days |
What the artificial intelligence layer never receives, and this is verifiable in the content sent:
- secrets, access keys or environment variables;
- data from another organisation, including in similarity search, which is restricted to the organisation in the query itself on top of database isolation;
- billing data, identification documents and credentials;
- any tool able to write to the database, move money or change permissions.
Contact memory is only written by explicit action of an automation or an agent. Never by inference of the model. A system that let the model decide on its own what to remember about a person would be building a profile that nobody instructed — and without a legal basis from the Customer to support it.
Lead qualification produced with the help of the artificial intelligence layer may constitute automated decision-making. As controller, the Customer answers for the data subject's right to review under article 20 of the LGPD; Myndchat provides, inside the platform, the record of what led to that qualification, so that review is possible.
15. Allocation of liability between the parties
The LGPD provides for joint and several liability between controller and processor in certain cases, and this agreement neither excludes nor could exclude what the law establishes towards the data subject.
As between the parties, and without prejudice to what a data subject may claim from either of them, liability is allocated as follows:
| Situation | Who answers as between the parties |
|---|---|
| Processing without a valid legal basis, a message sent without opt-in, an unlawful purpose, irregular content | The Customer, who made the decision |
| Myndchat failing to follow a documented instruction from the Customer | Myndchat |
| A security failure in a system under Myndchat's control | Myndchat, including the acts of its subprocessors |
| A failure in a third-party system chosen by the Customer, to which they directed the data | The Customer |
If one party is pursued over a matter that, under the table above, is the other's responsibility, that other party shall reimburse whatever was paid out, provided it was informed in time to take part in the defence.
Liability caps, the scope of indemnities and jurisdiction are not fixed in this document. They live in the Terms of Service, which govern the contractual relationship as a whole, and where the jurisdiction question is already addressed with the statutory reservation that applies where the Customer is a consumer. This agreement deals with data protection, and does not repeat — nor contradict — what is already there.
16. Term, changes and precedence
This agreement is in force for as long as the relationship between the parties lasts, and the obligations that by their nature survive — confidentiality, deletion, incident records — continue for the period stated in each section.
Myndchat may amend this agreement. An amendment that reduces protection for data subjects or broadens what we do with the data is communicated to the Customer at least 30 days in advance, at the account contact address, and a Customer who does not agree may terminate without penalty within that period. Corrections to wording, references or links are published without that notice, because they change no obligation.
The effective date and version number at the top of this page state which wording is in force. The previous version stays available, so the Customer can verify which text governed each period.
On matters of personal data protection, this agreement prevails over the Terms of Service and over any other instrument between the parties. On all other matters, the Terms prevail.
The Portuguese version of this document prevails in case of divergence with the English version.