← Back to sign in
LATAM CRM · Public information

Privacy Policy
and Security

How data is used in the application, what security precautions are adopted, and how to contact us regarding your information.

Last update: · Free consultation, no login required.

01. Controller and contact

O LATAM CRM is the controller designated for the operation of this internal-use application, aimed at business relationship management and the activities of authorized persons.

This policy covers user, collaborator, and business contact data processed in the application. It does not replace the policies of external sites accessed via links or the specific obligations of each organization that provides data to the CRM.

Privacy and security channel

privacidade@investseikol.com

Use this contact for questions, personal data requests, or reporting a possible incident. Do not send passwords, access codes, or API keys.

02. What data is processed

  • Account and identification: name, email, profile photo when available, account identifier, authentication information, and access profile.
  • Business relationship: contact and lead data, such as name, phone number, email, WhatsApp, public profiles, contact origin, notes, interaction history, and qualifications registered by authorized users or obtained through prospecting integrations.
  • Activities and internal records: tasks, goals, CRM movements, reports, and change logs, according to the modules used.
  • Attendance (Ponto): dates and times of punches, geographic location, and precision provided by the device at the moment of registration, in addition to corrections and respective justifications. Attendance registration uses location permission; it is not continuous background location tracking.
  • Communications: recipients, message content, sending history, and email open or click events when communication tracking is enabled.
  • Technical data: request and usage information necessary for operation, error diagnostics, and security, which may include IP address and browser or device information.

Data varies according to the access profile and resources used. When registering information of other people, the user must have authorization or another appropriate legal basis and limit the content to what is necessary for the activity.

03. What we use the data for

Data is used to authenticate users, evaluate access requests, apply permissions, organize business contacts and activities, register attendance, generate reports, execute communications requested by authorized users, and maintain service security and continuity.

Artificial intelligence resources may support analysis, translation, and content production. The outputs of these resources require human review and should not be treated as a definitive decision about a person.

The basis for processing depends on each purpose and the relationship with the data subject: execution of contracts and related procedures, compliance with legal obligations, regular exercise of rights, legitimate interest where applicable, or consent when required. Access to the application alone does not represent general consent for any data use.

The service is intended for authorized professional use, not for children. If you identify data of a child or adolescent improperly entered, communicate the privacy channel for assessment.

04. Services and integrations used

The operation uses third-party services. Depending on the feature triggered, relevant data may be processed by:

  • Clerk: authentication, accounts, sessions, and profile information necessary for access control.
  • Google: authentication when chosen by the user; Gmail/Google Workspace for sending emails configured in the service; YouTube Data API for consulting public channel and video information during prospecting. The information authorized at login is presented by Google itself.
  • Green API / WhatsApp: processing of phone numbers and content necessary for messages sent by integrated resources.
  • OpenAI, via AI integration: processing of content sent to analysis, translation, and narration functions. Lead analysis applies reduction of direct identifiers, but this does not equate to a guarantee of anonymization of all text entered by users.
  • GitHub: storage of backups configured for service recovery, which may contain application data.

Authorized users and administrators may consult or export data according to their permissions. Information may also be provided to comply with a legal obligation or valid order from a competent authority.

The use of these providers may involve processing outside the data subject's country. The terms of each service and applicable legal requirements must be considered, including rules on international transfers.

05. Cookies and local storage

The application and its authentication provider use session mechanisms to maintain authenticated access. The browser or device may also store interface preferences and information necessary for operational continuity, such as an attendance record pending confirmation.

You can manage cookies and storage through your browser or device settings. Blocking or deleting them may end the session and affect functionality. Email open and click events, when enabled, are distinct from these session mechanisms.

06. Security and access

The application uses authentication, profile-based access control, and administrative approval for restricted features. The published site uses HTTPS, and the service maintains logs of certain operations and settings to support traceability.

There are backup mechanisms and technical access restrictions. No measure eliminates all risks; this policy does not represent a guarantee of invulnerability, security certification, or a promise of recovery within a specific timeframe.

Protect your email and credentials, do not share accounts, and close your session on shared devices. Suspicions of unauthorized access, leaks, or misuse of data should be reported to privacidade@investseikol.com.

07. Storage and retention

Data may remain in systems and backups to meet service purposes, legal obligations, auditing, and exercise of rights. The need for retention must be evaluated according to the data category and the relationship involved; this policy does not establish a single timeframe for all records.

A deletion request does not imply immediate elimination of all data, especially when there is a retention obligation or backups subject to their own cycles. Applicable conditions can be consulted through the privacy channel.

08. Your rights and how to request

According to applicable legislation, you may request confirmation of processing and access to your data, correction, information about sharing, opposition or applicable limitation, portability when applicable, and anonymization, blocking, or elimination in the cases provided by law. When processing depends on consent, you may request its revocation.

Send your request to privacidade@investseikol.com , indicating the link to the application and the request. Identity confirmation proportional to the request may be necessary to protect data against unauthorized access.

Requests will be evaluated considering the rights of the data subject and applicable retention obligations. Email is the channel for these requests; this page does not automatically execute account or record deletion.

Data protection rules pertinent to each operation apply, including the Brazilian General Data Protection Law (Law No. 13.709/2018), where applicable, and the right to appeal to the competent authority.

09. Updates to this policy

This page may be updated to reflect changes in the application and its data processing. The date at the beginning identifies the current version. Changes that depend on specific information or consent must comply with applicable legal requirements.

This page is public to allow consultation before registration. Reading it does not require creating an account, providing data, or logging in with Google.