Privacy Policy
Last updated: July 27, 2026
The legally binding version of these terms is the one written in Portuguese (Brazil). This translation is a courtesy.
Conversa Labs LTDA (CNPJ 67.791.399/0001-47), operator of the Conversa Labs brand (conversalabs.com.br), respects your privacy and processes personal data in accordance with the General Data Protection Law (Law No. 13.709/2018 — LGPD, Brazil's general data protection statute) and the Internet Civil Framework (Marco Civil da Internet, Law No. 12.965/2014).
1. Controller and Data Protection Officer (DPO)
Controller: Conversa Labs LTDA, CNPJ 67.791.399/0001-47, with its
registered office at Av. José Silva de Azevedo Neto, 200, Bl. 004, Sala 0104 — Barra da Tijuca, Rio de Janeiro/RJ, CEP 22.775-056.
Data Protection Officer (DPO): Guilherme Jansen de Lima Benevenuto —
contato@conversalabs.com.br.
2. Roles of the parties: when we are controllers and when we are processors
The LGPD assigns different obligations depending on each party’s role in each processing activity. In this relationship there are three distinct situations, and confusing them would lead to wrong conclusions about who answers for what:
- We are CONTROLLERS of the subscriber’s own data and of this site’s visitors: registration, contact, billing data, portal access logs, and licensing telemetry. We decide the purposes of those processing activities, and it is those that the remainder of this Policy addresses.
- The subscriber is CONTROLLER of their customers’ and contacts’ data, processed inside the accounts they operate on their own installation. Decisions about purpose, legal basis, privacy notice, handling of data subject requests, and retention period for that data are theirs. We have no say over that content and we do not access it in the ordinary course of the service.
- We are PROCESSORS in a single scenario: when our team accesses a specific account by reason of the human assistance add-on, subject to the subscriber’s prior authorization for that account. In that scenario we act strictly under their instructions (Article 39), we record every operation in an immutable trail (Article 37), and we do not use the data for our own purposes.
The full conditions of the processing carried out as a processor are set out in the Data Processing Agreement (DPA), and the specific authorization is in the Account Access Authorization Term.
3. Data we collect
- Identification and contact: name, email, phone, and CPF/CNPJ (in the Brazil flow, required for issuing the charge).
- 5-day free trial: minimal collection of name, email, and WhatsApp to confirm the email, provision the trial environment, and prevent multiple use. We also keep a derived technical identifier (a hash of the email + phone), which does not allow the direct re-identification of the person and serves only as anti-reuse and anti-fraud control.
- Payment data: processed directly by a payment gateway. We do not store complete card data.
- Usage and provisioning data: information about the license, the provisioned environment, and platform access.
- Licensing telemetry: installation identifier (install_id), host/domain, version and edition, server IP, and aggregate counts (number of installations, accounts, users/seats, and domains), used only to validate the license, enforce plan/add-on limits, and prevent fraud and abuse. These are aggregate counts only — not the content or the data of the subscriber's end customers.
- Community content: messages and posts you make in community spaces may be visible to other members.
- Browsing data: technical information and anonymous usage metrics from the site.
The subscriber's end customers' data (conversations, contacts, messages, and media) is NOT collected or processed by us. Such data resides exclusively on the subscriber's server (VPS), which is the Controller with respect to it; Conversa Labs does not act as a processor of that data. From the subscriber's operation we collect only the licensing telemetry described above — aggregate counts, never the content of the end customers.
4. What we use it for
- Process VIP List enrollment and billing.
- Release and manage the 5-day free trial (confirm the email, provision the trial account, and automatically delete it at the end of the period).
- Issue the license, provision the environment, and grant access.
- Communicate news, access instructions, support, and the community.
- Prevent fraud and abuse and ensure the security of the service.
- Comply with legal, tax, and regulatory obligations.
5. Legal bases
We process your data based on the performance of a contract (your enrollment and use of the platform), on compliance with a legal obligation, on legitimate interest (security, fraud prevention, and product improvement), and on consent, where applicable (e.g., marketing communications).
6. Sharing
We share data only with partners necessary for the operation, such as the payment gateway, infrastructure and hosting providers, and our licensing system. When the subscriber enables the AI features, conversation content necessary for processing may be sent to the third-party AI provider they connect (e.g., OpenAI, Anthropic), acting as a processor; the choice of provider, the key configuration, and the compliance of this flow are the subscriber's responsibility, and the processing by that provider is governed by the provider's own policy and may occur outside Brazil (international transfer, with the safeguards of Article 33 of the LGPD). We may also share when required by a competent authority or by law. We do not sell your data.
7. Subprocessors
To operate the service we rely on the suppliers listed below, which process personal data on our behalf. The list is kept up to date; the addition or replacement of a subprocessor that processes data on behalf of a subscriber is notified at least 30 (thirty) days in advance, as set out in the DPA.
- Infrastructure and hosting — servers running the licensing hub, the portal, and this website. Purpose: performance of the service. Location: Brazil and/or abroad, with the safeguards of Article 33 of the LGPD.
- Payment gateways (Asaas and Stripe) — Purpose: process charges, issue receipts, and prevent fraud. They process billing data directly; we do not store complete card numbers.
- Transactional email provider — Purpose: send confirmations, billing notices, access details, and portal notifications.
- Discord — Purpose: operate the community and the official service channel for those who contract assistance. It processes the profile data the subscriber themselves provides to that platform.
- Artificial intelligence providers — when the subscriber enables the AI features with their own key. In that case the relationship with the provider is the subscriber’s own; see the Sharing clause.
We are answerable to the subscriber for the acts of the subprocessors we engage. We do not sell, rent, or assign personal data to third parties for marketing purposes.
8. Cookies
We use only essential cookies and anonymous performance metrics. We do not use advertising tracking cookies without your consent.
9. Storage and security
We adopt technical and organizational measures to protect your data, including encryption of sensitive credentials and access control. Data may be stored on servers in Brazil or abroad, always with adequate safeguards under the LGPD. Any international data transfers — for example, when using infrastructure or AI providers based abroad — observe the grounds and safeguards of Article 33 of the LGPD (adequate contractual clauses, equivalent protection guarantees, or specific consent, as the case may be).
10. Security incidents
We maintain a process for detecting, responding to, and recording incidents. Should a security incident occur that may give rise to relevant risk or harm to data subjects, we will notify the National Data Protection Authority (ANPD) and the affected data subjects within a reasonable period, pursuant to Article 48 of the LGPD, stating: the nature of the data affected, the data subjects involved, the technical protection measures used, the risks, the reasons for any delay, and the steps taken to reverse or mitigate the effects.
Where the incident occurs in data we process as processors, we will notify the subscriber (controller) within 48 (forty-eight) hours of becoming aware, so that they can comply with the duties the law assigns to them, with our technical support. Details in the DPA.
11. Retention
We keep data only for as long as necessary for the purposes of this Policy or as required by law. Once the relationship ends, the data is deleted or anonymized, except for the legal cases requiring retention. The periods, by category, are as follows:
- Subscriber registration and contact: for the duration of the relationship and for 5 (five) years after its end, for the regular exercise of rights (Article 7, VI, and Article 16, I, of the LGPD).
- Billing and tax data (NFS-e — Brazilian electronic service invoice): 5 (five) years, by legal and tax obligation (Article 16, I).
- Licensing telemetry: 12 (twelve) months, to enforce the contracted limits and prevent fraud.
- Assistance access trail: 5 (five) years after the access. It is accountability evidence (Article 37) and protects both parties — which is why it is retained even after the add-on has been cancelled.
- Portal access logs: 6 (six) months, by legal obligation (Article 15 of the Marco Civil da Internet).
- Support communications: 2 (two) years after the support request is closed.
5-day free trial: the trial account and its respective data are automatically deleted after 5 (five) days. After deletion, we keep only the technical identifier (hash) derived from the email and the phone — data that does not allow the direct re-identification of the person — for as long as necessary to prevent reuse of the trial and prevent abuse. The hash is processed on the basis of legitimate interest (security and fraud prevention), pursuant to Article 7, IX, of the LGPD.
12. Your rights (Article 18 of the LGPD)
You may, at any time, request: confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing, and revocation of consent. Simply write to contato@conversalabs.com.br.
13. Minors' data
The platform is intended for individuals over 18 years of age. We do not intentionally collect data from minors; if you identify improper processing, contact the Data Protection Officer for removal.
14. Changes
This Policy may be updated. The version in force is always the one published on this page, with the date indicated at the top.
12. Problem reporting (Bug Report)
When you use the Report a problem feature within the platform, we collect and process the submitted data exclusively to: (a) diagnose, reproduce, and fix the reported problem; (b) improve the stability and quality of the product; and (c) communicate the progress of the report to you. The processing occurs based on your free, informed, and unambiguous consent (Article 7, I, of the LGPD; and Article 6(1)(a) of the GDPR, where applicable), expressed at the time of submission and recorded (date/time, terms version, IP, and user agent) for evidentiary purposes.
Depending on what you submit, the report may contain:
- Report content: title, description, type, and severity; attachments you add (screenshots, annotated images, screen recordings, files).
- Reporter and account identification: name, email, user role, account identification and plan.
- Technical context: browser, operating system, device, resolution, language, time zone, application version, license, and environment.
- Diagnostic telemetry: console logs and recent network failures (metadata only — method, path, status, duration; without request/response bodies).
- Affected component: identification of the element/screen you selected.
Minimization and masking: we automatically mask sensitive information (tokens, passwords, emails, CPF, phone numbers) in the logs, and you can hide areas of the screenshots and recordings before submitting. To manage and fix the reports, the data is forwarded to our processors — Linear (issue management) and GitHub (code repository) — which process it on our behalf, in accordance with their respective terms. We do not sell or transfer this data to third parties for their own purposes. Reports and attachments are retained for as long as necessary for diagnostics and the product quality history, and are deleted together with the deletion of the account. You may, at any time, revoke consent (without affecting the processing already carried out) and exercise the rights of Article 18 of the LGPD through the channel indicated in Section 9.
15. Contact
For privacy matters, contact our Data Protection Officer, Guilherme Jansen de Lima Benevenuto, at contato@conversalabs.com.br. Conversa Labs LTDA — CNPJ 67.791.399/0001-47.