iZap Platform Privacy Policy

Last updated: July 22, 2026 · Version 2.4

1. Who We Are
iZap respects your privacy and is committed to protecting the personal data processed on its platform. iZap is operated by iZap Labs LTDA, enrolled under CNPJ nº 18.051.583/0001-45, headquartered at Avenida Paulista, nº 171, 4º andar, Bela Vista, São Paulo/SP, CEP 01311-904.
This Privacy Policy explains how we collect, use, store, share, and protect personal data in connection with the provision of our services, in compliance with the LGPD (Brazilian General Data Protection Law, Law No. 13.709/2018) and, where applicable, the European GDPR (see the specific section near the end).
2. Data Controller and Processor
When a client company uses iZap to communicate with its own consumers, patients, or users, that company generally acts as the controller of the personal data related to the service, determining the purposes and legal bases of the processing. In these cases, iZap acts as processor, processing data in accordance with the client's instructions and within the applicable technical and contractual limits.
iZap acts as controller with respect to data it processes for its own purposes, such as registering contracting clients, billing, security, fraud prevention, and improving the Platform.
3. What Data We May Process
Depending on how the Platform is used, we may process the following categories of data:
Identification data: name, phone number, email, and user identifiers.
Account and business data: account and company registration data, billing and payment information, and support tickets.
Communication data: messages sent and received, timing and frequency of interactions, read and delivery status, media files, documents, images, and audio.
Behavioral and operational data: interaction history, recorded preferences, history of orders, service requests or transactions, and geolocation data, where provided.
Technical data: IP address, device type, access and activity logs, cookies and similar technologies, and Platform performance and usage data.
Data may be provided by you, by the business client, by Meta/WhatsApp, through forms, ads, integrations, or contact imports.
4. What We Use the Data For
Personal data processed by iZap is used to:
provide the contracted services;
process messages and automate customer service;
provide reports, analytics, and metrics;
offer technical support;
monitor security, prevent fraud, and investigate incidents;
comply with legal and regulatory obligations;
improve the stability, operation, and experience of the Platform.
5. Legal Bases and Purposes
When iZap acts as processor, the processing of conversation content and end-user data is carried out under the documented instructions of the controlling client and based on the legal basis defined by that client — iZap does not choose this basis. For iZap's own purposes, the following legal bases apply:
Conversation content and end-user data (service delivery, automation, and requested support) → processor, under the instruction and legal basis of the controlling client → retained for the duration of the contract and for up to 90 days after its termination;
Registration, administrative, and billing data relating to the relationship between iZap and the contracting client → performance of a contract → iZap as controller;
Technical telemetry, security, fraud prevention, and access logs → legitimate interest aimed at the security, continuity, and technical improvement of the service (with a right to object) and legal obligation → controller → up to 12 months;
Genuinely anonymous statistics → outside the scope of the LGPD;
Quality assessment that uses conversation content → only under the instruction of the controlling client or subject to prior anonymization;
Billing and tax obligations → compliance with a legal obligation → controller → 5 years;
Marketing to existing clients about similar products and services → legitimate interest, with the option to opt out at any time;
Other marketing communications → consent → controller → until withdrawn;
Analytics cookies → consent (see the section on cookies).
Sensitive data follow the specific legal bases under Article 11 of the LGPD (see the dedicated section). You may object to processing based on legitimate interest through the channels indicated at the end of this Policy.
6. What We Do Not Do with the Data
iZap does not train artificial intelligence models — its own or third parties' — using conversations or personal data belonging to its clients' end users, which includes training, fine-tuning, and retraining. “Improvement of the Platform” refers to service delivery, technical observability, support, and aggregated or anonymized statistics — not the creation of training datasets from client content. Quality assessment that uses conversation content occurs only under the instruction of the controlling client or subject to prior anonymization.
Under the API usage policies of the AI providers we operate with, submitted content is not used to train their models. Human access to content occurs only when necessary for requested support or for security purposes, subject to confidentiality. We do not sell, rent, or share personal data with third parties for those third parties' own commercial purposes.
7. Role of iZap and the Contracting Client
When iZap acts as processor, the contracting client, acting as controller, is responsible for:
determining the purpose and legal basis of the processing;
obtaining consent or opt-in when necessary;
providing its own privacy policy to its end users;
meeting the regulatory obligations of its industry.
Data subject requests relating to data processed under the responsibility of the contracting client may be forwarded to that controller, who determines the primary purpose of the processing.
8. Data Sharing
iZap may share personal data, when necessary, with the following categories of recipients, indicating the role of each:
cloud infrastructure and hosting providers (infrastructure processors);
artificial intelligence model and service providers (processors; no retention for training purposes);
communication and integration platforms, such as WhatsApp and Meta (independent controller or processor, depending on the service and the applicable terms);
transcription, email, support, and observability providers (processors);
auditors and consultants, subject to a duty of confidentiality;
public authorities, regulators, or judicial bodies, where there is a legal obligation or a valid order.
The updated list of subprocessors and the countries involved is available upon request through the privacy channel and, for clients, in the Data Processing Agreement (DPA), with prior notice of changes and the possibility of objection. Whenever applicable, we adopt contractual and technical mechanisms to require an adequate level of data protection from these third parties.
9. International Data Transfers
Some vendors or technology partners may process data outside Brazil. In such cases, iZap adopts the mechanism applicable under ANPD Resolution No. 19/2024 — as a rule, standard contractual clauses with vendors, or another legally appropriate safeguard. The list of countries and parties involved is available through the privacy channel.
10. Artificial Intelligence, Automated Decisions, and Personal Data
iZap uses AI to support automation and service flows. In the context of AI:
we apply data minimization whenever possible;
we maintain segregation between client environments;
we may record technical logs for traceability and security;
we recommend human oversight for critical decisions;
we seek to reduce misuse, bias, and operational risks.
AI may classify intentions, prioritize or route service requests, and qualify leads. Where a decision is made solely on the basis of automated processing of personal data and affects the data subject's interests, the data subject may request a review of it and clear information about the criteria and procedures used, subject to trade and industrial secrets. For processing subject to the GDPR or the UK GDPR, the criteria and rights set out in those laws additionally apply. Despite the measures adopted, AI systems may generate inadequate or inaccurate responses, which is why we recommend monitoring and human validation.
11. Sensitive Personal Data
The Platform may process sensitive personal data (Article 5, item II, of the LGPD) — including health data (symptoms, diagnoses, test results, prescriptions, clinical images) and biometric data — when entered by clients in industries such as healthcare, aesthetics, and insurance.
In such cases, iZap acts as processor, processing this data under the instruction of the controlling client and for the purpose defined by that client, with additional controls (enhanced segregation, minimum access, and access logging). The legal bases under Article 11 of the LGPD apply, which are not limited to consent (for example, protection of health in a procedure carried out by a health professional or service, or compliance with a legal obligation). Determining the appropriate legal basis is the responsibility of the controlling client; iZap does not use this data for an incompatible purpose of its own.
12. Information Security
We adopt technical and organizational measures appropriate to the nature of the operation, which may include, as applicable: encryption of data in transit and at rest, role- and permission-based access control, logical segregation of environments by client, backups, monitoring of anomalous activity, and audit logs, in addition to internal confidentiality commitments and privacy-by-design practices.
No system is completely secure, and absolute security cannot be guaranteed. Detailed technical measures may be made available to clients and auditors through a specific exhibit.
13. Retention and Deletion
We retain personal data for the periods set out below, according to the purpose:
Conversations and media: for the duration of the contract and for up to 90 days after its termination, unless a legal obligation requires otherwise;
Technical and security logs: up to 12 months;
Billing and tax data: 5 years;
Backups: a technical cycle of up to 90 days;
Canceled accounts: deletion or anonymization within up to 90 days after termination, except for legally required retention.
The period of up to 90 days after termination covers the client's data-export window and the technical retention of backups until their rotation, after which permanent deletion occurs. In long-term contracts, retention of older conversations may be configurable according to the contracted plan. After the purpose or the contractual relationship ends, the data may be deleted or anonymized, except where legally required to be retained.
14. Data Subject Rights
Under the LGPD, the data subject may request, where applicable:
confirmation of the existence of processing and access to the data;
correction of incomplete, inaccurate, or outdated data;
anonymization, blocking, or deletion of unnecessary data or data processed in non-compliance with the law;
deletion of data processed on the basis of consent;
portability and information about data sharing;
information about the possibility of not consenting and the consequences thereof;
objection to processing based on a legal basis other than consent;
review of decisions made solely on the basis of automated processing, and information about the criteria used;
withdrawal of consent, where consent is the applicable legal basis;
the right to lodge a petition with the ANPD (Brazilian National Data Protection Authority).
We verify the identity of the requester. Requests for confirmation and access are handled within the timeframes set by the LGPD, including a complete response within 15 days; other requests are handled within the applicable legal or regulatory timeframes and, absent a specific timeframe, within a reasonable period, taking into account their complexity. When iZap acts as processor, we forward the request to the controlling client and cooperate in fulfilling it.
15. Security Incidents
If iZap is the controller, it will notify the ANPD and the data subjects within the legal timeframes (3 business days, pursuant to ANPD Resolution No. 15/2024). If it acts as processor, it will notify the controlling client without undue delay, within 24 hours of becoming aware of the incident, with the necessary information, so that the controller can meet its legal notification deadline.
We maintain a response plan appropriate to the severity of the event, including containment, impact assessment, and remediation. Operational details may be set out in the Data Processing Agreement (DPA).
16. Cookies and Similar Technologies
iZap uses cookies and similar technologies organized by category: essential cookies (necessary for operation, authentication, and security), which do not require consent; and analytics or experience-improvement cookies, which require your consent and are only loaded after you authorize them.
You may accept or decline non-essential cookies, or manage your preferences through the site's consent mechanism, and withdraw them at any time. Disabling certain cookies may affect the operation of parts of the Platform. Accepting cookies does not amount to acceptance of this Policy, which is provided for information purposes only.
17. Data of Children and Adolescents
The Platform is not intended for the creation of accounts by minors. However, clients in industries such as pediatrics, education, and family services may enter data belonging to minors; in such cases, iZap acts as processor, under the controller's instructions, applying minimization and enhanced security and prohibiting any use incompatible with the best interests of the child or adolescent. The legal basis and consent from parents or legal guardians, where required, are the responsibility of the controlling client.
18. Users in the European Economic Area and the United Kingdom (GDPR)
This section applies where a given iZap processing activity falls within the territorial scope criteria of Article 3 of the GDPR (EU 2016/679) or the UK GDPR — in particular, establishment in Europe, the targeted offering of goods or services to individuals in the European Economic Area (EEA) or the United Kingdom, or the monitoring of behavior in those regions. A European client's subscription to iZap does not, on its own, trigger this applicability, without prejudice to the contractual obligations applicable to iZap as processor or sub-processor, and the mere location of an individual in the EEA does not, by itself, trigger the application of the GDPR.
Roles and legal bases: iZap acts as processor with respect to conversations and content processed under the instruction of the controlling client, and as controller with respect to registration, billing, security, and account administration. The legal bases under Article 6 include performance of a contract, legal obligation, legitimate interest (subject to a balancing test and a right to object), and consent; special categories of data under Article 9, including health data, are processed under the client's valid instructions and subject to a specific condition under Article 9.
International transfer: transfers of data from the EEA to Brazil may be based on the applicable adequacy decision (EU–Brazil mutual adequacy, in effect as of 2026), without the need for SCCs. Subsequent transfers to countries not covered by an adequacy decision will rely on Standard Contractual Clauses (SCCs) or another valid mechanism, together with any required assessments and supplementary measures. For the United Kingdom, the mechanisms under the UK GDPR apply (for example, the UK Addendum to the SCCs or the IDTA), as applicable. A copy of the safeguards is available upon request.
Your rights: access and copies, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights relating to automated decisions. We respond within 1 month (extendable by a further 2 months, with justification). You may lodge a complaint with the competent supervisory authority in your country and object at any time to processing for direct marketing purposes, independently of your acceptance of the Terms and of cookie consent.
EU representative (Article 27): if iZap is subject to Article 27, it will appoint in writing and identify a representative in the EEA before beginning the relevant processing; the United Kingdom is addressed separately under the UK GDPR.
19. Changes to This Policy
This Policy may be updated periodically to reflect operational improvements and legal, regulatory, or technological changes. The current version will be available through iZap's official channels. The introduction of new categories of data or of a materially different purpose will be accompanied by adequate notice and, where required, a new legal basis or consent — continued use alone will not be treated as acceptance.
20. Data Protection Officer and Contact
For questions, privacy-related requests, or the exercise of rights, please contact us through the privacy channel:
Data protection officer and privacy contact: Ivan Carmo da Rocha Neto
Email: info@izap.ai
Phone: +55 (11) 5104-4485
Address: Avenida Paulista, nº 171, 4º andar, Bela Vista, São Paulo/SP, CEP 01311-904