1. Who we are and who this policy covers
FOSInfo is a Brazilian company based in Casimiro de Abreu, State of Rio de Janeiro, that provides an AI-powered customer service platform for WhatsApp, Instagram, Messenger, e-mail and website chat. We are a Tech Provider on Meta's WhatsApp Business Platform and use Meta's official APIs to connect our clients' accounts.
This policy applies to:
- Visitors of fosinfoai.app and its pages;
- Clients: businesses and professionals that subscribe to the FOSInfo platform, and the users (agents and administrators) they register;
- End contacts: people who talk to our clients through the channels connected to the platform;
- Meta Platform Data received through the integrations with WhatsApp Business, Instagram and Facebook Pages.
The platform is accessed on addresses under the fosinfoai.app domain (for example chat.fosinfoai.app or yourcompany.fosinfoai.app) or on the client's own domain, on the dedicated server plan.
2. Our roles: controller and processor
Under the Brazilian General Data Protection Law (Law No. 13,709/2018, "LGPD") FOSInfo acts in two distinct roles:
| Situation | FOSInfo's role | Who decides on the processing |
|---|---|---|
| Data of website visitors, clients and the users they register (account, billing, support, communications) | Controller | FOSInfo |
| Data of end contacts processed inside the platform (messages, phone numbers, names, media, notes) and Meta Platform Data obtained on the client's behalf | Processor | The client, who is the controller and is responsible for the legal basis of its relationship with the people it serves |
When acting as processor we handle data exclusively under the client's instructions and the contract signed with the client. If you are an end contact of a FOSInfo client and want to exercise your rights, the fastest route is the business that serves you; we also accept the request and forward it, as described in section 12.
3. Data we collect
3.1 Website visitors
Technical logs generated automatically by the hosting infrastructure: IP address, date and time, pages viewed, browser and device type. The website uses no third-party tracking tools and no advertising cookies. When you click "Chat on WhatsApp" you are taken to the WhatsApp app, whose terms apply to that conversation.
3.2 Clients and platform users
- Registration data: name, e-mail, phone, company, tax ID, job title;
- Login credentials (passwords are stored only in encrypted form), login and activity logs;
- Billing and payment data, processed by payment providers; we do not store full card numbers;
- Content of support and onboarding interactions (messages, e-mails, calls).
3.3 End contacts (on behalf of the client)
- Channel identifiers: WhatsApp phone number, Instagram or Messenger user ID, e-mail;
- Name and profile picture made available by the channel;
- Content of the messages exchanged with the client, including text, images, audio, video, documents and location;
- Metadata: dates, times, delivery and read status, labels, assignments and notes recorded by the client's team;
- Data the client chooses to record in the platform's CRM, such as appointments, charges and contracts.
4. Meta Platform Data
To provide the service, FOSInfo accesses data through Meta's official APIs: the WhatsApp Business Platform (Cloud API and Embedded Signup), the Messenger Platform and the Instagram Messaging API. This data is called "Platform Data" in the Meta Platform Terms and includes:
- Identifiers of the client's business assets: WhatsApp Business Account (WABA) ID, phone number IDs, Facebook Page IDs and Instagram professional account IDs;
- Access tokens granted by the client when connecting the account, stored encrypted;
- Message templates, quality rating and messaging limits of the number, sending metrics;
- Messages received and sent, media and status events delivered by webhook;
- Public profile data of contacts who start a conversation (profile name and picture).
How we use Platform Data. We use this data only to provide the service the client subscribed to, following the client's instructions: receive and send messages, manage templates, display conversations in the inbox, run the AI and produce reports for the client itself. We do not use Platform Data for advertising, to build profiles of people outside the relationship with the client, to sell or license it to third parties, or to train general-purpose AI models. We comply with the Meta Platform Terms, the Developer Policies and the WhatsApp Business terms.
The client can revoke our access at any time by disconnecting the inbox in the platform or by removing the FOSInfo integration in its Meta account settings (WhatsApp Manager, Page settings or Business Integrations). Upon revocation, or when the data is no longer needed, we delete it as described in section 9.
5. Purposes and legal bases
| Purpose | Legal basis (LGPD, art. 7) |
|---|---|
| Create and maintain the client account, deliver the platform, connect channels, send and receive messages, issue invoices | Performance of a contract (item V) |
| Provide technical support and onboarding, communicate service changes and security notices | Performance of a contract and legitimate interest (items V and IX) |
| Keep access logs, prevent fraud and abuse, protect the platform and client accounts | Legal obligation (Brazilian Internet Act, art. 15) and legitimate interest (items II and IX) |
| Comply with tax and accounting obligations and valid orders from authorities | Legal obligation and exercise of rights (items II and VI) |
| Send marketing communications about FOSInfo news | Consent (item I), which can be withdrawn at any time |
| Process end-contact data on behalf of the client | The legal basis is defined by the client, as controller; FOSInfo acts as processor |
6. How the AI handles data
The platform includes an AI agent that replies, classifies, schedules and collects payments inside conversations, always configured and supervised by the client. To work, the AI reads the content of the ongoing conversation and the knowledge base the client registered (products, hours, policies).
- Client conversation content is not used to train general-purpose models, neither ours nor our providers'.
- Language model providers are engaged as processors, contractually bound not to retain data for training and to process it only to generate the requested reply.
- The client decides in which inboxes the AI operates, can pause it in any conversation and can take over at any time.
- AI-generated replies are flagged internally in the platform, and clients are instructed to inform their contacts about automated service when the law or the channel's policies require it.
7. Who we share data with
We do not sell, rent or transfer personal data. We share only what is necessary, with:
- Meta Platforms: to deliver and receive messages on WhatsApp, Instagram and Messenger, under Meta's own terms;
- Cloud infrastructure providers that host the platform, under confidentiality agreements and without functional access to the data;
- AI model providers, only when the client enables the AI, as described in section 6;
- Payment, transactional e-mail and e-signature providers, for the features the client subscribed to;
- Public authorities, when there is a legal obligation or a valid order. We log every request, assess its legality and disclose the minimum necessary.
8. International transfers
Meta processes messages on servers outside Brazil, and some infrastructure and AI providers may operate in other countries. In those cases the transfer relies on article 33 of the LGPD, through contractual data protection clauses and providers with recognised security standards. By using the platform the client acknowledges this transfer as necessary for the performance of the contract.
9. How long we keep data
| Data | Period |
|---|---|
| Conversations, contacts and CRM records of the client | While the account is active, according to the client's retention settings |
| Meta Platform Data (tokens, IDs, messages received via webhook) | While the integration is connected and the data is needed for the service. Deleted within 30 days after disconnection, account closure, a data subject request or a request from Meta |
| Client registration and billing data | During the contract and for the statutory retention period of tax documents (up to 5 years) |
| Application access logs | 6 months, under article 15 of the Brazilian Internet Act |
| Backups | Up to 30 days after deletion from the primary environment |
After the account is closed, the client has 30 days to export its data. After that period the data is deleted or irreversibly anonymised, unless a legal retention obligation applies.
10. How we protect data
- Encryption in transit (TLS) on all connections and encryption at rest for stored data;
- Meta access tokens and passwords stored encrypted, with access restricted to system processes;
- Role- and inbox-based access control, two-factor authentication available to all users, least-privilege principle within the FOSInfo team;
- Isolated environments per client, audit logs and availability monitoring;
- Regular security updates and vendor assessment;
- Incident response plan: in the event of a security incident that may cause relevant risk, we notify the Brazilian Data Protection Authority (ANPD), the affected clients and, when Platform Data is involved, Meta, within the applicable deadlines (LGPD, art. 48).
11. Your rights
Under article 18 of the LGPD you may, at any time and free of charge, request:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymisation, blocking or deletion of unnecessary data or data processed in breach of the law;
- portability of your data to another provider;
- information on the entities with which we share data;
- withdrawal of consent and information on the consequences of not providing a piece of data;
- objection to processing based on legitimate interest.
We reply within 15 days. If you are an end contact of a FOSInfo client, we may need to confirm the request with that client, who is the controller of your data. You may also file a complaint with the ANPD.
12. How to request deletion
We keep a simple, clearly marked channel for requests to modify or delete data, including Meta Platform Data, as required by the Meta Platform Terms.
- FOSInfo client Delete contacts, conversations or the whole account from the platform dashboard, or send the request by e-mail or WhatsApp (section 16). To revoke FOSInfo's access to your Meta assets, disconnect the inbox or remove the integration in WhatsApp Manager, in your Page settings or in Meta Business Integrations.
- End contact of a client Ask the business that serves you directly, or send the request to FOSInfo with the phone number or profile used in the conversation and the name of the business. We forward it to the client and confirm the deletion.
- Timing and confirmation We delete data from the primary environment within 30 days and from backups within a further 30 days. You receive a confirmation through the same channel used for the request.
Full instructions are available at fosinfoai.app/en/data-deletion.
13. Cookies
The fosinfoai.app website uses no tracking or advertising cookies. The FOSInfo platform uses only strictly necessary cookies to keep the authenticated user session and interface preferences. You can clear them in your browser; you will then need to sign in again.
14. Minors
The platform is intended for businesses and professionals; we do not accept accounts from people under 18. Minors may talk to our clients through the connected channels; in that case the client, as controller, is responsible for complying with article 14 of the LGPD. If we identify children's data processed without an adequate legal basis, we delete it.
15. Changes to this policy
We may update this policy to reflect changes in the law, in our services or in the requirements of the platforms we integrate with. Material changes are communicated to clients by e-mail or in-platform notice at least 15 days in advance. The current version is always on this page, with the update date at the top. In case of conflict, the Portuguese version prevails.
16. Contact and Data Protection Officer
FOSInfo · Casimiro de Abreu, RJ, Brazil
Data Protection Officer (DPO): privacidade@fosinfo.com.br
WhatsApp: +55 22 2778-1148 · Website: fosinfoai.app
Use the subject "Privacy" to speed up handling. We reply within 15 days.
Related documents: Terms of Service · Data deletion instructions · Política de Privacidade (Português).
