Skip to content
InstagramWhatsAppMessengerTikTokMyndchat AI
By business typefor Creatorsfor eCommercefor SM Marketersfor Agenciesfor Brands
By use caseCollect EmailsRequest to FollowRespond to CommentsFollow to DM
AboutPricingSecurity
en
  • InstagramAutomate your Instagram marketingWhatsAppConnect with your customers instantlyMessengerAutomated replies on Facebook MessengerTikTokTurn views into salesMyndchat AIA smarter way to automate chat
  • By business type
    for Creatorsfor eCommercefor SM Marketersfor Agenciesfor Brands
    By use case
    Collect EmailsRequest to FollowRespond to CommentsFollow to DM
  • About
  • Pricing
  • Security
Terms of ServicePrivacy PolicyData Processing AddendumSubprocessor ListCookie PolicyAcceptable Use PolicyRefund Policy
Effective date: 18 August 2026

Myndchat Privacy Policy

Myndchat is a conversation automation platform. Businesses use Myndchat to serve their own customers over WhatsApp, Instagram Direct, Facebook Messenger and TikTok. This document explains what we do with personal data: yours, if you subscribe to Myndchat or visit this website, and other people's, when it passes through the platform on behalf of one of our customers.

We process personal data in two situations that the law keeps apart, and that this document keeps apart with it: on our own decision, when you subscribe to Myndchat or browse this website, and on a customer's instruction, when it is that customer who decides what happens to the data of the people talking to them. Section 2 explains the difference and sits at the very beginning on purpose, because it determines whom you should ask for what.

This policy describes the processing of personal data of the following data subjects:

  • people who subscribe to Myndchat and the members of that organisation's team, including those who only operate the platform day to day;
  • visitors to myndchat.com;
  • anyone who writes to us at any of the addresses published in section 1;
  • the end contacts who talk to our customers over the connected channels — for those, Myndchat is a processor and the customer is the one answerable for the processing, as section 4 explains.

It covers the myndchat.com website and the Myndchat platform, including the integrations with WhatsApp Business Platform, Instagram, Messenger and TikTok. It does not cover what each customer does on its own outside Myndchat, nor what the messaging platforms do with your data as owners of the channel: each has its own policy, and section 9 identifies all of them.

If you have a question about any point in this document, or want to exercise a right under the Brazilian General Data Protection Law, write to privacidade@myndchat.com. Section 13 states how long we take to answer and how we confirm the identity of whoever asks before handing over personal data.

Table of Contents

  1. 1. Who we are and how to reach us
  2. 2. The distinction that organises this policy
  3. 3. Data we process as controller
  4. 4. Data we process as processor
  5. 5. Isolation between customers
  6. 6. Cookies and similar technologies
  7. 7. Artificial intelligence
  8. 8. Automated decisions and the right to review
  9. 9. Sharing and subprocessors
  10. 10. International transfers
  11. 11. Information security
  12. 12. Retention and deletion
  13. 13. Your rights as a data subject
  14. 14. Security incidents
  15. 15. Children and adolescents
  16. 16. Application access logs
  17. 17. Changes to this policy
  18. 18. Effective date and version

1. Who we are and how to reach us

Myndchat is a conversation automation platform that businesses use to serve their own customers over WhatsApp, Instagram Direct, Facebook Messenger and TikTok. This policy explains what we do with personal data, in which situations, on what legal basis and for how long.

FieldValue
Legal nameMYNDCHAT TECNOLOGIA LTDA
Company registration (CNPJ)65.434.606/0001-80
AddressAvenida Brigadeiro Faria Lima, 1811, Sala ESC 1119, Jardim Paulistano, São Paulo/SP, 01452-001, Brazil
Phone+55 48 98434-0133
Data Protection OfficerBernardo Prantz Pin
Data Protection Officer contactencarregado@myndchat.com
Privacy and data subject rightsprivacidade@myndchat.com
Supportsupport@myndchat.com
Security and incidentsseguranca@myndchat.com
Report abuseabuso@myndchat.com

The Data Protection Officer is the point of contact between you, us and the Brazilian data protection authority. You may write to them directly about anything in this policy, including complaints.

About the moment this policy takes effect. As of this date, the Myndchat website is live and the platform is under construction. The processing described in sections 3, 4, 5, 7, 8 and 12 concerns the platform and begins, for each customer, when they create an account and connect a channel. Until then, the only processing under way is the one described in section 6, which covers the website. We publish the policy in advance because whoever signs up must be able to read what will be done with the data before deciding, and because the platforms we integrate with require the policy to be published and live before authorising the integration.

2. The distinction that organises this policy

This is the most important section of the document, and it sits near the top on purpose. Myndchat holds two different roles at the same time, and what you can require from us depends on which one applies to you.

We are the CONTROLLER of the data of whoever subscribes to the platform. If you signed up for Myndchat, or you are part of the team of a business that did, we decide why and how we process your account, billing and product usage data. In that case, you exercise your rights directly with us.

We are the PROCESSOR of the data of our customers' end contacts. If you spoke to a shop, a clinic or an agency over WhatsApp, Instagram, Messenger or TikTok, and that business uses Myndchat, then the conversation passes through our systems — but the party that decides the purpose of that processing, collects your consent and answers for it is the business you spoke to, not Myndchat. We process that data under their instructions.

If you are an end contact and want to access, correct or delete your data, the route is to contact the business you spoke to. They are the controller. If you write to us anyway, we will not ignore you: we forward the request to the responsible customer, confirm to you that we did, and support the response within what is technically available to us. What we cannot do is decide, on their behalf, about data that is not ours.

This separation is not legal formality: it changes what we do in practice. No data processed in our role as processor is used for our own purposes, cross-referenced between different organisations, sold, shared for advertising or used to train artificial intelligence models. Section 4 sets that out.

3. Data we process as controller

This is the data of whoever subscribes to Myndchat and of that organisation's team. Below is what we collect, what for, on what legal basis and for how long we keep it.

DataWhat it is forLegal basisHow long
Name, e-mail and phoneIdentify the account holder, authenticate access and communicate about the servicePerformance of a contract (art. 7, V)While the account is active, plus 5 years
Password, in hashed formAuthenticate accessPerformance of a contract (art. 7, V)While the account exists
Second authentication factor and recovery codesProtect the account against unauthorised accessPerformance of a contract and legitimate interest in security (art. 7, V and IX)While the feature is enabled
Tax identification number of the responsible partyIssue tax documents, identify the contracting party and prevent fraudLegal obligation and performance of a contract (art. 7, II and V)5 years after the last tax document
Billing addressIssue tax documents and charge the subscriptionLegal obligation and performance of a contract (art. 7, II and V)5 years
Subscription, plan, add-ons and payment statusGrant the contracted access and charge correctlyPerformance of a contract (art. 7, V)5 years
Billing identifiers, card brand, last four digits and expiry dateDisplay the stored payment method and process the recurring chargePerformance of a contract (art. 7, V)While active, plus 5 years from the last charge
Record of acceptance of the terms, with version, date, time and IP addressProve that the contract was accepted and in which versionPerformance of a contract and exercise of rights (art. 7, V and VI)While the account is active, plus 5 years
Audit trail: who did what, when and from which IP addressSecurity, incident investigation and due processLegitimate interest and exercise of rights (art. 7, IX and VI)24 months
Application access logsComply with art. 15 of the Brazilian Internet Civil FrameworkLegal obligation (art. 7, II)6 months
Error reports, with route, screen context and screenshotDiagnose a defect you reportedLegitimate interest (art. 7, IX)90 days
Usage metrics, active contact count and artificial intelligence consumptionApply plan limits, warn before blocking and charge overagePerformance of a contract (art. 7, V)24 months, and 5 years for what supported an invoice
Access credentials for your channel accountsSend and receive messages on your behalf, which is the core function of the servicePerformance of a contract (art. 7, V)Until you disconnect the channel or close the account
IP address and request dataLimit abuse, prevent fraud and protect the platformLegitimate interest (art. 7, IX)6 months

We never collect the full card number or the security code. Those fields are filled in inside an isolated component provided and operated by our payment processor, and they do not pass through our servers, our logs or our backups.

4. Data we process as processor

This is the data of the people who talk to our customers. Here Myndchat decides nothing about purpose: the controller is the business using the platform, and it defines why it talks to you, on what legal basis and for how long it intends to keep the data.

DataWhere it comes fromDefault retention
Contact name and channel identifierFrom the messaging platform itself, when the conversation arrives12 months
Phone number, in the case of WhatsAppFrom the messaging platform12 months
Profile picture, when the channel sends itFrom the messaging platform12 months
Full message content, in both directionsFrom the conversation12 months, configurable to less by the customer
Images, audio, video and documents exchangedFrom the conversation6 months, configurable to less by the customer
Tags, custom fields and segmentsCreated by the customer or by their automation12 months
Lead qualificationFrom the automation or the artificial intelligence layer12 months
Contact and conversation variables, and contact memoryWritten by an explicit action of an automation or an agent12 months, and conversation variables are discarded when the conversation ends
Deals, sales pipeline and journey eventsRecorded by the customer or by their automation12 months
Contact source and originating advertisementFrom the messaging platform12 months
Participation in campaigns and sequencesFrom the sends made by the customer12 months
Record of opt-in and opt-outFrom the contact's own statement or the customer's recordFor as long as the organisation exists
Internal team notes about the contactWritten by the agent, never sent to the contact12 months

The opt-out record has a different retention period on purpose: it survives the deletion of the rest of that contact's data. If we deleted the opt-out along with everything else, the person would start receiving messages again on the next import, and their request would stop being honoured.

What we never do with this data, without exception:

  • We do not use it for Myndchat's own purposes.
  • We do not cross-reference data between different customer organisations.
  • We do not sell it, rent it or transfer it to third parties.
  • We do not use it for advertising, ours or anyone else's.
  • We do not use it to train artificial intelligence models, ours or third parties'.
  • We do not access conversation content outside the cases in section 11, and every internal access is logged and visible to the customer in their own audit trail.

This is not only our own policy. Our contract with Meta to operate as a technology provider requires us to process data obtained through its platforms exclusively on behalf of the customer and according to their instructions, and forbids using it for any other purpose or disclosing it to third parties.

5. Isolation between customers

The platform is used by several organisations at the same time on the same infrastructure. What stops one from seeing another is not the way the screens are arranged: it is the architecture.

  • Each organisation is a data boundary in the database, enforced by the database itself and not only by the application. A query attempting to reach another organisation's data is rejected at the source.
  • The check also exists on the server, independently. The two layers work together: if one fails through a mistake of ours, the other keeps blocking.
  • The isolation applies equally to the store used by the artificial intelligence similarity search. One customer's knowledge base does not reach another.
  • The identifiers used in page addresses are not sequential, which prevents discovering third-party records by guessing.
  • Files and media live in a path separated by organisation and are served only through a temporary, signed address. There is no permanent public link to conversation media.
  • Real-time access to the inbox is authorised per organisation. Attempting to subscribe to another organisation's channel is blocked and logged.

We test this isolation by attacking it: we create separate organisations and try, through every available route, to read, alter and delete one organisation's data from the other. A control is only considered valid when there is a test that fails if the control is removed.

6. Cookies and similar technologies

This section summarises what we do with cookies. The full detail — the measured inventory, what each category does and how to block cookies through your browser — is in the Cookie Policy, which is a document of its own and is listed alongside. Where the two overlap, the Cookie Policy prevails, being the more specific one about your browser.

A cookie is a small file that a website stores in your browser. We apply the same treatment here to equivalent technologies, such as browser local storage and measurement pixels.

Nothing that is not strictly necessary loads before you decide. Until you choose, no third-party script runs, no pixel fires and no non-essential cookie is stored. Closing the notice, clicking outside it or continuing to browse is not consent: without an affirmative action from you, nothing is released and the notice comes back.

We use four categories, and they are the same in the notice, in the settings panel and here:

CategoryWhat it is forInitial stateLegal basis
EssentialMaking the website and the platform work: keeping the session, remembering the chosen language, protecting forms against forged requests and storing your own consent choiceAlways on, and cannot be turned offLegitimate interest, as strictly necessary (art. 7, IX)
PreferenceRemembering interface choices that are not required for the service to workOffConsent (art. 7, I)
AnalyticsMeasuring audience and understanding how the site is used, in order to improve itOffConsent (art. 7, I)
AdvertisingDisplaying and measuring targeted advertisingOffConsent (art. 7, I)

The cookies and technologies actually in use today, measured in the browser rather than estimated:

NameCategoryWho stores itWhat it holdsDuration
Language cookieEssentialMyndchat (first party)Only the chosen language code, pt or en. It holds no identifier and cannot be used to recognise you1 year
Consent cookieEssentialMyndchat (first party)Your choice per category, when it was made and the version of this policy6 months, after which the question is asked again

We use no service in the Preference, Advertising and Analytics categories at this time — all three are empty, and we measured that in the browser rather than assuming it. The categories still exist in the panel because, if a service ever enters any of them, that service starts off and depends on your consent — rather than on a silent change to the structure of the notice.

You can change your mind at any time, free of charge and in the same place: the Privacy Settings link, in the footer of every page, reopens the panel. Withdrawing is as simple as accepting, and withdrawal actually removes the cookies in that category rather than merely recording the refusal. You can also block or delete cookies through your browser settings; in that case some functions may stop working.

We keep a record of your consent, as the law requires of anyone relying on it: the consent identifier, what was accepted and what was refused, when, the version of this policy and the origin of the choice. The identifier is shown to you inside the Privacy Settings panel, so that you can ask us for the data of your own consent.

We ask the question again when this policy changes version, when a new service enters a non-essential category, and every six months.

7. Artificial intelligence

Myndchat uses artificial intelligence in tiers, and most conversations never reach a generative model. We describe here exactly what leaves our infrastructure, where it goes and under what guarantee.

The automation resolves in layers, and only moves to the next when the current one cannot answer:

LayerWhat it doesWhat leaves our infrastructure
FlowchartThe decision tree built by the customer themselves. It always tries firstNothing. No content leaves
Similarity searchLooks for the answer in a question-and-answer base registered by the customer, comparing meaning rather than exact wordingThe text is converted into a numeric representation by an external provider. No text generation happens in this layer
Generative modelLast resort: it only runs when neither the flowchart nor the similarity search resolved the messageA slice of the conversation, described below

When the last layer runs, what we send to the provider is bounded before the call and capped: at most the last fifteen messages of that conversation, plus a compacted summary of what came before, plus the business information the customer registered, plus the variables and memory of that contact which are relevant to answering.

What is never sent to an artificial intelligence provider:

  • No password, key, credential or secret.
  • No data from another organisation, under any circumstance — including in the similarity search, which is scoped to the organisation in the query itself and not only by the database rule.
  • No billing data and no identity document.
  • No personal data beyond what is necessary to answer the message at hand.

The model also has no power to act on its own. It produces a suggested reply and a classification; any action with real effect only happens if the output matches a closed list of permitted actions, checked by our own code. The model does not write to the database, does not change permissions, does not touch billing and does not decide account suspensions.

About the providers that receive this content, and under what guarantee:

ProviderFunctionUse for model trainingRetention by the provider
AnthropicGenerating replies, conversation summaries and translationProhibited by the commercial application programming interface terms applicable to our accountDeletion within 30 days. Content flagged for violating the provider's usage policy may be retained longer by them
OpenAIConverting text into a numeric representation for the similarity searchData sent through the application programming interface is not used to train models, absent an express opt-in that we have not madeAbuse monitoring logs for up to 30 days

We describe what is actually contracted, not what would be nicer to announce. The training prohibition is contractual and in force. The short abuse-monitoring retention window exists and is real: we have requested a zero data retention agreement from both providers, which is subject to their prior approval. Until such an agreement is in force, what is written in the table above applies, and this policy will be updated, with a new version, on the day that changes.

We log, per call, which category of data was sent. That is what allows us to answer a data subject request about what was shared with precision.

8. Automated decisions and the right to review

Part of what the platform does is decided automatically, without human intervention at the time. You have the right to know what that is, on what criteria, and to request a review.

What is decided automaticallyOn what criteriaWhat it means for you
Qualifying a contact as a leadThe content of the conversation and the rules the business itself registered about its own operationIt changes the priority and the order in which the business talks to you. It does not deny service, does not set prices and does not affect credit
Routing the conversation to a person or a teamRules configured by the business over data it already holds: intent marked in the conversation, tag, channel, time of day. No model is called for this decisionIt defines who on the team serves you
Automatic reply by the flowchart or by artificial intelligenceThe tree built by the business and the business information it registeredYou receive an automated reply, with escalation to a person when you ask, when the subject falls outside scope, or when confidence is low

None of these decisions restricts your access to a product or service, sets a price for you, affects a credit assessment or produces legal effects. Even so, the right to review applies.

To request a review of an automated decision, write to privacidade@myndchat.com. If the decision was made inside a customer's account, we forward the request to them as the controller and let you know. The review is carried out by a person. We respond within 15 days.

On our side, as controller, we also use automated processing to detect abusive use of the platform by our own customers — unsolicited messaging, scams, prohibited content. Warnings and observation may be automatic. Limiting or suspending an account requires a decision by a person, recorded with author and reason, and the customer has an appeal channel with human review. Artificial intelligence may flag and prioritise; it never decides a suspension.

9. Sharing and subprocessors

We do not sell personal data and we do not share it for third-party advertising. We share only with suppliers that carry out part of the service on our behalf, and only what is necessary for that function. Each of them is bound by contractual obligations of confidentiality, security and purpose limitation.

The public, versioned and complete list is on the Subprocessors page, which is the official source: there each provider appears separated by state — who already processes data today, who is planned for the platform, and which functions have no provider chosen yet. The summary below repeats the planned providers, without that separation:

SupplierFunction in the productCategory of data receivedWhere it processes
SupabaseDatabase, authentication, media storage, real time and similarity searchPractically all data in sections 3 and 4Outside Brazil
VercelHosting, page delivery and scheduled task executionRequest data, IP address and content in transitOutside Brazil
StripeSubscription billing and payment processingName, e-mail, tax identification number, billing address and card data, the latter collected directly by their componentOutside Brazil
Meta PlatformsWhatsApp, Instagram Direct and Facebook Messenger channelsMessage content, phone number, contact identifier and profile, mediaOutside Brazil
TikTokTikTok direct message channelMessage content and contact identifierOutside Brazil
AnthropicReply generation, summary and translation in the artificial intelligence layerThe conversation slice described in section 7Outside Brazil
OpenAIConverting text into a numeric representation for similarity searchText of the registered questions and answers and of the indexed conversationsOutside Brazil
GoogleAssisted address completion in formsThe text typed into the address field and the IP addressOutside Brazil
Google AnalyticsAudience measurement for the websiteMeasurement identifier and browsing data, only with your consentOutside Brazil
SentryError capture with already filtered contextRoute, correlation identifier and a fragment of screen stateOutside Brazil

Almost none of them processes data yet. As of this date only the website is live, and the only provider actually processing personal data is the one hosting and delivering the pages. The others begin processing when the corresponding platform function goes into operation. The Subprocessors page states, provider by provider, which state each one is in.

We choose suppliers on technical capability, security maturity and willingness to take on by contract the obligations the law imposes on us. Before adding a new supplier to this list, we assess those three things. A change of supplier is announced to customers at least 30 days in advance, produces a new version of the Subprocessors page and a new version of this policy.

We may also share data where there is a court order, a request from a competent authority under the law, or a need to exercise our rights in proceedings. In those cases we inform the data subject whenever the law allows.

10. International transfers

All the suppliers listed in section 9 process data outside Brazil. That is an international transfer, and it requires its own legal ground.

DestinationGround for the transfer
European Union, European Economic Area and European Union institutionsAdequacy decision issued by the Brazilian data protection authority, recognising those destinations as providing an adequate level of protection (art. 33, I of Law 13.709/2018)
United States and other destinationsStandard contractual clauses approved by the Brazilian data protection authority, adopted in full and without modification, under art. 33, II, item b of Law 13.709/2018

You have the right to receive the full text of the clauses used in a transfer involving your data. Ask at privacidade@myndchat.com and we respond within 15 days, preserving third-party trade secrets where applicable.

Brazilian law continues to apply to processing carried out abroad whenever the collection takes place in Brazilian territory or the service is offered to the Brazilian public.

11. Information security

We hold private conversations belonging to people who never signed up for Myndchat. That demands above-average rigour, and the measures below are the ones we actually apply.

  • Encrypted communication in transit across the entire service, without exception.
  • Access credentials for your channel accounts encrypted at rest, with a key managed outside the database, so that a copy of the database does not hand them over. They are never sent to the browser, never appear in logs and are never displayed, not even partially.
  • Passwords checked against public breach databases at sign-up and at password change, rejecting those already known to have leaked.
  • Second authentication factor available to everyone and required for the administrator role on paid plans.
  • Least privilege access: each person and each component sees only what their own function requires.
  • Isolation between organisations enforced in the database and on the server, independently, as described in section 5.
  • An immutable audit trail recording who accessed what, when and from where.
  • Internal access to customer data is exceptional, requires a written justification, is time-limited and is fully logged. Access to conversation content appears in the organisation's own audit trail, visible to the customer.
  • Automated scanning for credentials in the code and for vulnerabilities in dependencies, on every change.
  • Automated tests that attempt to break isolation between organisations and that fail if the control is removed.
  • Backups from the first record onward, with a restore procedure that is tested rather than merely documented.
  • Sensitive data kept out of error and diagnostic logs, by listing what is allowed rather than what is forbidden — so a new field starts outside the log.

We do not claim certifications we do not hold. None of the measures above is presented as a seal, a standard or a third-party audit: they are controls we implement and test. If and when we obtain a certification, it will be stated here by name and date.

If you find a security flaw, write to seguranca@myndchat.com. We review every report received and we take no action against anyone who reports in good faith, without exploiting the flaw beyond what is needed to demonstrate it and without accessing third-party data.

12. Retention and deletion

We keep each type of data for as long as the purpose justifying it requires, or for the period the law demands. When the period ends, the data is deleted — and deletion here means removal from the database, from file storage and, in the due cycle, from backups as well.

DataPeriodCounted from
Application access logs6 monthsDate of the record
Conversations and messages12 months, configurable to less by the customerLast message in the conversation
Images, audio, video and documents6 months, configurable to less by the customerDate received
Automation execution traces and internal events90 daysDate of the event
Audit trail24 monthsDate of the record
Record of acceptance of the termsWhile the account is active, plus 5 yearsAccount closure
Billing and tax data5 yearsIssue of the document
Security incident records5 years, at minimumDate of the record
Error reports and screenshots90 daysDate of the report
Cookie consent recordsWhile valid, plus 5 yearsWithdrawal or expiry
End contact opt-out recordsFor as long as the organisation exists—
Channel credentialsRevoked immediatelyChannel disconnection or account closure

When an account is closed, the sequence is this:

  • You have 30 days to export your data in a readable format.
  • After that period, the data is deleted from the database and from storage within 60 days.
  • Backups still containing that data are overwritten in the normal cycle, within 90 days.
  • Credentials for connected channels are revoked immediately on closure, not at the end of the periods above.

A period may be suspended, for that specific item only, where there is a longer legal retention obligation, a court order or a need to defend ongoing proceedings. In that case the data is blocked for any other purpose.

13. Your rights as a data subject

Brazilian law grants you the rights below. They apply whether you are our customer or an end contact of a customer — what changes is the route, explained at the end of this section.

RightWhat it means in practice
ConfirmationKnowing whether we process any data about you
AccessReceiving a copy of the data we hold about you
CorrectionCorrecting incomplete, inaccurate or outdated data
Anonymisation, blocking or deletionRequesting removal of unnecessary or excessive data, or data processed outside the law
PortabilityReceiving your data in a format that lets you take it to another provider
Deletion of data processed on consentWhere the basis is your consent, requesting that the data be erased
Information about sharingKnowing which public and private entities we share your data with
Information about refusingKnowing that you may withhold consent and what happens if you do
Withdrawal of consentWithdrawing, at any time and free of charge, a consent you have given
Review of automated decisionsAsking for a person to review a decision taken solely by automated processing, as described in section 8
ObjectionObjecting to processing that relies on a legal basis other than consent

How to exercise them, and what to expect:

  • Write to privacidade@myndchat.com, or directly to the Data Protection Officer at encarregado@myndchat.com.
  • We respond within 15 days. If the request is complex and we need more time, we tell you within that period, with the reason.
  • Before acting, we confirm the request really is yours. Verification uses data we already hold and is proportionate to what is being asked; for access and deletion requests it is stricter, because answering the wrong request is itself a data breach.
  • There is no charge. We do not charge for the exercise of a right.
  • If we refuse a request, we say why and on what grounds.

If you are an end contact of one of our customers, the route is different. The party controlling your data is the business you spoke to, and the request should be addressed to them. If you do not know how to reach them, or prefer to talk to us, write anyway: we forward your request to the responsible customer, confirm to you that we have done so, and support the response technically. What we do not do is decide, on our own, about data we do not control.

You may also lodge a complaint with the Brazilian data protection authority. We would rather resolve matters directly with you, but that right exists and does not depend on contacting us first.

14. Security incidents

We have a written incident response procedure, defined before we needed it, with the steps of contain, assess, fix, communicate, record and learn.

Where a security incident may result in relevant risk or harm to data subjects, we notify the Brazilian data protection authority and the affected data subjects within three business days, counted from the moment we know the incident affected personal data. The notice describes the nature and category of the affected data, the number of data subjects, the security measures in place before and after, the risks involved and what we will do to reverse or mitigate the effects.

Notice to data subjects is given in plain language and directly, whenever it is possible to identify who was affected. Where it is not, we publish it prominently for a minimum of three months.

We keep a record of every incident for a minimum of five years, including those that did not require notification, together with the assessment that led to that conclusion.

Where an incident affects data we process as processor, we immediately notify the customer acting as controller and support them in meeting their own obligations, as it is they who notify the authority and the data subjects.

15. Children and adolescents

Myndchat is a work tool contracted by businesses. It is not intended for anyone under 18, is not directed at children or adolescents, and does not knowingly collect their data for our own purposes. Creating an account requires legal capacity and business use.

Conversations handled by our customers may in practice involve children or adolescents, because whoever writes to a shop on WhatsApp can be anyone. In those cases the controller is the customer, and it is their duty to process that data in the best interest of the minor and to obtain specific, prominent consent from at least one parent or legal guardian where the law requires it.

If we learn that data of children or adolescents is being processed on the platform contrary to the law, we notify the responsible customer, require them to put it right, and may limit or suspend the feature involved. If you believe this is happening, write to privacidade@myndchat.com.

16. Application access logs

As an internet application provider incorporated as a legal entity and operating for economic purposes, we keep application access logs — date, time and IP address of each access — for six months, under confidentiality and in a controlled environment, in accordance with art. 15 of the Brazilian Internet Civil Framework.

These logs are only disclosed under a court order, and the content of private communications is only disclosed in the cases and in the manner the law establishes. A competent administrative authority may request registration data as provided by law.

We do not keep logs of access to other internet applications and we do not keep personal data that is excessive in relation to the purpose that justified it.

17. Changes to this policy

This policy may change. When it does, we publish a new version with its own number and effective date, and we keep previous versions reachable through the link at the top of this page.

If the change is material — a new purpose, a new legal basis, a new subprocessor in a non-essential category, a change to a retention period or to an international transfer destination — we notify customers prominently and in advance, rather than merely swapping the text.

A version change to this policy or to the Terms of Service triggers a new acceptance inside the platform. Until it is accepted, the customer continues handling existing conversations, and bulk sending features are temporarily unavailable. A version change also causes the cookie question to be asked again.

18. Effective date and version

FieldValue
Version1.0
Effective date18 August 2026
Previous versionNone. This is the first published version
LanguagesBrazilian Portuguese and English

In the event of any discrepancy between the Portuguese and the English version of this document, the Portuguese version prevails. This policy is governed by Brazilian law.

© 2026, Myndchat, Inc.

en
Product
InstagramTikTokWhatsAppMessengerMyndchat AISMS marketingFor BrandsFor eCommerceIntegrationsPricing
Resources
Help centerCommunityBlogChronically onlineHow toVideo courseChatbot examples
Myndchat
AboutManifestoCareersPressPrivacy & security
Problems
Can't keep upViral but brokeWrong link, wrong timeCan't log offRenting your audienceDrowning in comments
Partners
Myndchat for agenciesHire an agencyJoin the affiliate program
Other
Status pageChangelogPrivacy policyTerms of service
Get started freeGet started freeGet started free