plati.

Plati Privacy Policy

Last updated: September 23, 2026

This Policy explains how PLATI AI ATIVIDADE DE INTERNET LTDA, Brazilian company registration (CNPJ) 49.221.685/0001-95, processes personal data across its websites, applications and services, including Plati Lite. Our address is Avenida Brigadeiro Faria Lima, 1811, Suite 1119, Jardim Paulistano, postal code 01452-001, São Paulo/SP, Brazil. Contact our privacy and data protection officer channel at [email protected].

1. Scope and our role

This Policy covers visitors, account holders, team members, contacts interacting with connected channels, recipients of shared content and people using Plati payment pages.

Plati acts as a controller when determining the purposes and means of processing for its direct relationship with users and visitors, including registration, authentication, support, security, commercial administration and service usage analytics.

When a business customer connects conversations and operational data for processing under its instructions, Plati acts as a processor and the customer determines the purposes. Our role depends on the activity, not simply the product name. Specific contracts may further define responsibilities and instructions.

If you communicate with a business using Lite, that business's privacy policy also applies. You may direct requests about that relationship to the business; Plati assists within its responsibilities.

2. Data we process

Some information comes from you and some from channels, conversation participants, applications and authorized providers. Imported content may include sensitive personal data even when Plati does not request it. Avoid connecting or submitting unnecessary information; sensitive data requires the specific conditions established by applicable law.

3. Purposes and legal grounds

We use data to create and authenticate accounts, deliver contracted features, synchronize conversations, answer questions, produce transcripts and summaries, maintain context, execute instructions and enable collaboration. In our direct relationship with users, these activities may rely on contract performance or steps requested before entering a contract. As a processor, we follow the customer's instructions and the legal basis established for its operation.

We also use data for support, operation, abuse prevention, security, performance measurement and improvements to the experience. Depending on the activity, the grounds may be contract performance, legal obligations or legitimate interests, taking necessity and individuals' rights into account. We request consent when required, including for optional uses relying on that basis.

Contract and transaction data supports billing, legal obligations and the exercise of rights. Promotional communications must respect the applicable basis and the ability to object or withdraw consent. Accepting the Terms does not provide blanket consent for any use of personal data.

4. AI, memory and training

To respond or act, Lite processes information relevant to the task, which may include conversation excerpts, files and integration results, using large language models (LLMs) supplied by AI providers. Generating an answer involves processing by the provider; this is different from model training.

Plati does not use your WhatsApp conversations to train AI models or provide them to third parties for that purpose. We do not sell personal data. Using content to perform tasks, create summaries and maintain contextual memory is part of providing the service, not permission for general model training.

Memory may include facts and preferences extracted from interactions to assist future requests. It can be incomplete or inaccurate and does not replace the source information. You may request correction or deletion through our privacy channel, including derived content that remains associated with you.

AI technical records may include the model, token volume, latency, tools invoked, identifiers and errors. This telemetry is distinct from conversation history maintained for the product. Human access to content may occur as necessary for requested support, investigation of errors or abuse, security or legal obligations, with access restricted to the relevant purpose.

5. Integrations and Google data

Connecting applications is optional. Access depends on the permissions granted and connection settings. Integrations may be private or shared with authorized workspace members. Integration intermediaries and user-configured MCP servers may process data and authorizations to perform tasks.

If you connect Gmail, Google Calendar, Google Sheets or another available Google service, Lite may access data within authorized scopes, such as messages and attachments, events or spreadsheet content, to retrieve information and carry out requested features.

Our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including Limited Use requirements where applicable. Google API data is not used for targeted advertising, sale or training general-purpose models. Processing by AI providers must be limited to authorized features and exceptions permitted by applicable policies.

Human access to data subject to Google's Limited Use requirements is restricted to permitted cases, such as your affirmative authorization to examine specific content, security or legal requirements. You can revoke a connection in Lite or through your Google account permissions. Disconnecting prevents new access authorized through that connection but does not automatically erase previously imported data or reverse completed actions. Request deletion at [email protected].

6. Who may receive data

Providers vary by feature. Providers processing data on our behalf must follow applicable instructions and conditions. Services you independently engage or connect may also operate under their own policies; review their practices before granting access.

7. Sharing, teams and external clients

Workspace information may be available to members according to their roles and feature visibility. A private integration differs from a shared connection. Review your settings and workspace membership.

Sharing links may make content available outside your account, depending on configured access restrictions and expiry. Recipients may copy received material; revoking a link does not retrieve existing copies. MCP/API clients, including external assistants you authorize, receive data needed for permitted queries and actions and process it under their own terms.

Summaries and notifications sent by email or WhatsApp may contain workspace information. Protect destination channels and review available preferences.

8. Cookies, local storage and measurement

We use cookies and local storage for sessions, authentication, security and preferences. We also use analytics technologies to understand navigation, interactions, performance and errors. Advertising tools on website pages may measure campaigns and conversions.

These technologies are not limited to administrative environments. Depending on the page and its configuration, they include usage analytics tools, campaign measurement tools and advertising pixels. Data may include identifiers, IP address, device, visited pages and events. This does not authorize using private conversation content or Google API data for advertising targeting.

You may block or delete cookies and local data through browser settings and adjust preferences through available controls. Blocking essential technologies can affect access. Where processing relies on consent, specific consent must be obtained and may be withdrawn. Contact our privacy channel for questions or requests.

9. Retention, disconnection and deletion

We retain data as necessary for the stated purposes, service delivery and applicable obligations. The period depends on the category, operational need, contract and legal requirements. A channel's history import window is not itself a deletion period for stored data.

Disconnecting a channel or application, cancelling a plan, deactivating an account and deleting data are separate operations. Deactivation stops ordinary account use but does not mean all content, memory, media, logs and backups have been erased. Request deletion expressly through our privacy channel.

For data processed on a customer's behalf, we maintain the commitment to delete, return or anonymize data within 30 days after contract termination or a valid controller request, subject to legally permitted retention and specific contractual conditions. This commitment requires handling the request; it does not mean instant deletion through a deactivation button.

Data needed for legal obligations and the exercise of rights may be retained for the relevant period, with restricted purposes and access. We will explain reasons preventing complete deletion. We do not apply a blanket five-year retention period to all conversation content.

Backups follow separate replacement and deletion cycles and may retain data for an additional restricted period. They are not intended for everyday use. Handling requests must account for these copies and prevent inappropriate reintroduction of deleted data during restoration. You may request details about the categories and periods applicable to your case.

10. Security and incidents

Measures include access controls, workspace separation, credential protection, encryption at applicable transport and storage layers, audit records and backups. AI processing and integrations require technical access to relevant content; we do not describe Lite as a service in which only the user can decrypt all data.

No system eliminates all risks. If an incident occurs, we will take containment, assessment and notification measures according to our responsibilities. As a processor, we will notify the customer controller without undue delay and within 72 hours of becoming aware of an incident that may cause relevant risk or harm, subject to any shorter contractual deadline.

When Plati acts as controller, required notifications to Brazil's ANPD and affected individuals will follow applicable legal deadlines. The contractual customer notice period does not replace the controller's regulatory notification deadline.

11. Processing outside Brazil

International infrastructure, AI models and integrations may involve storing or processing data outside Brazil. Transfers must comply with the mechanisms and safeguards required by Brazil's LGPD and ANPD regulations, as applicable, including appropriate contractual clauses. You may request information about recipients, countries and applicable mechanisms through our privacy channel.

12. Your rights and choices

You may request confirmation and access, correction, information about sharing, portability where applicable, and anonymization, blocking or deletion in the circumstances provided by law. You may also withdraw consent, object to unlawful processing and request review of decisions based solely on automated processing that affect your interests, where applicable.

Email [email protected], identifying your relationship with Plati and your request. We may request proportionate information to verify identity and protect others' data. Do not send passwords or banking credentials. We will respond within applicable legal conditions and deadlines and explain any limitations.

For data belonging to a business using Lite, we may direct you to the controller and assist it with your request. You do not need to rely on an automated export or deletion feature to exercise your rights. You may also contact the ANPD and competent authorities.

13. Children and adolescents

Services are intended for users aged 18 or older. We do not seek registrations from children or adolescents. Minors' data may incidentally appear in customer-connected content; processing requires applicable legal protections, their best interests and minimization. Contact our privacy channel if you identify inappropriate registration or processing.

14. Changes and contact

We will update this Policy when the product or processing practices change materially. The version date appears above. Material changes will be communicated appropriately; new purposes requiring consent depend on specific authorization before the new use.

Privacy and data protection officer: [email protected]. Product support: [email protected]. See our Terms of Use (Portuguese) and the Portuguese Privacy Policy.