---
title: "Privacy Policy | Zaiped"
description: "How Zaiped, a product of Nivens, handles personal data on the WhatsApp Business Platform: what we process, on what legal basis, who we share it with, how long we keep it and how to request deletion."
lang: "en-US"
canonical: "https://zaiped.com/en/privacy"
alternate: "https://zaiped.com/privacy"
---

# Privacy Policy

Last updated: September 10, 2026

This Policy explains which personal data Zaiped processes, why, who we share it with and what you can require from us. It covers the website, the panel and everything the panel operates on Meta's WhatsApp Business Platform.

## 1. Who we are

Zaiped is a WhatsApp panel for businesses. It is a brand and product of NIVENS COMERCIO DE MERCADORIAS LTDA., a Brazilian limited liability company registered under CNPJ (Brazilian corporate taxpayer registry) no. 44.033.204/0001-02, referred to in this Policy as "Zaiped", "we" or "us".

- Legal name: NIVENS COMERCIO DE MERCADORIAS LTDA.
- Trade name: NIVENS
- CNPJ: 44.033.204/0001-02
- Address: R. Voluntários da Pátria, 1560, apto. 54 bloco A, Santana, São Paulo, SP, CEP 02010-300
- General contact: contato@zaiped.com
- Privacy, data protection and Data Protection Officer: privacidade@zaiped.com

We are a Brazilian company and we process personal data under Law no. 13,709/2018 (the Brazilian General Data Protection Law, LGPD). When we process data of individuals in the European Economic Area or the United Kingdom, we also apply Regulation (EU) 2016/679 (GDPR).

This Policy covers the whole service, and not just the website: the zaiped.com address, the panel our customers work in, and the integrations that panel operates on their behalf. What it does not cover is what each customer decides to do with data inside their own account, and section 3 explains exactly why.

## 2. Who this Policy applies to

Three groups of people appear here, and what we say changes depending on the group. Reading the right one is what avoids confusion about who answers for what.

- Customers and panel users: the business that uses Zaiped and the people it authorizes to operate the account, including collaborators and invited professionals.
- Our customers' contacts: the people who talk to that business over its WhatsApp number, or whom the business adds to its own base. If you received a message from a business that uses Zaiped, you are in this group.
- Website visitors: anyone who simply browses zaiped.com without having an account.

If you are a contact of a business and want to exercise rights over your data, start with the business you talked to. It is the one that decides what happens to that data. Even so, section 12 explains how to reach us and what we do when a request arrives here.

## 3. Our two roles: controller and processor

This is the most important section of the document, because it determines how every other section reads. Zaiped acts in two different roles at the same time, over different sets of data.

We are the CONTROLLER of data belonging to whoever hires and uses the panel. This is the data that exists because you have an account with us: registration details, sign-in email, branch data, invited team members, billing records and technical usage data. For that data, we decide the purposes and means of processing, and we are the ones you hold accountable.

We are the PROCESSOR of data that flows through a customer's account. This includes contacts, phone numbers, contact records, documents attached to those records, appointments and everything that moves through the customer's WhatsApp Business account. For that data, the customer decides the purposes and means and is therefore the controller. We only process it on their behalf, following their instructions, which are the operations the panel offers.

The practical consequence runs both ways: we do not use a customer's contacts for our own purposes, we do not cross-reference them between accounts, we do not sell them and we do not turn them into a marketing base of our own. On the other side, it is up to the customer to have a legal basis for processing that data, to obtain the consent WhatsApp's rules require and to answer to data subjects. The Terms of Use detail this split.

A given set of data never changes role on its own. When you, as a customer, write to us asking for support, the content of that conversation is data for which we are the controller, even if it mentions one of your contacts.

## 4. Data we process

We process only what the service needs in order to work. The list below is exhaustive as to categories.

Account and access data, for which we are the controller:

- Identification: name, email and, when you sign in with Google, the profile picture that provider returns.
- Authentication: session records, an email-verified marker and the hash of the sign-in codes we email you. We do not store passwords, because the product does not use passwords.
- Branches: name, full address, time zone, business hours and other details the business registers about its own locations.
- Team: the email of invited people, the role assigned, and the dates of invitation, acceptance and revocation.
- Credits and billing: credit packs purchased, wallet balance, the artificial intelligence usage statement and Stripe identifiers. Card data never passes through us; it goes straight to Stripe.
- Technical data: IP address, browser information and access logs generated by our infrastructure, used to operate, debug and protect the service.
- Public-page audience data, only with consent: page visited, approximate visit source, device type and general interactions measured by Google Analytics.

Customer contact data, for which we are the processor:

- Phone number in international format, which is the minimum data every contact has.
- The name typed by the business and the profile name shown by WhatsApp.
- An optional contact record filled in by the business: email, tax ID, date of birth, a free-form address line and notes.
- The stage in the service funnel and the history of changes to that stage.
- Sales recorded manually on the contact record: description, amount and date.
- Documents attached to the record, such as contracts, medical test results and prescriptions, including the file itself and the text automatically extracted from it.
- Appointments: date, time, professional, price, status and notes.
- Payments generated by the panel: amount, status and Stripe identifiers.
- The moment of the last message received from that number, which is what governs the WhatsApp service window.
- The WhatsApp conversation history between that number and the business: the text of each message, attached files, delivery state and who sent each one.

Documents attached to a contact record may contain sensitive personal data, such as health information in a test result or a prescription. The customer decides to attach them, and the burden of having a specific legal basis for that is theirs, under article 11 of the LGPD. We process those files only to store them, display them to whoever has access to the account, and extract the text that feeds that account's agent responses.

WhatsApp message content is stored by us, as of the inbox launch. For every message exchanged between the customer and their contact we keep: Meta's message identifier, the direction (received or sent), the type, the text or caption, the attached file when there is one, the moment it was sent, the delivery and read state, and the pricing object Meta returns. We also keep who sent it on the business side: a person, the AI agent, the appointment reminder, a broadcast or a payment request. This content exists so the business can reply from the panel, so the AI agent can answer with the conversation history, and so the business can see delivery and cost of its own sends. It is deleted along with the contact and along with the account, like the rest of its data.

Integration credentials: we store the customer's WhatsApp Business account identifier, the phone number identifier, the verified name, the quality rating assigned by Meta, and the access token Meta issues on the customer's behalf. The token and the two-step verification PIN are encrypted at rest and are never returned to the browser.

## 5. Where the data comes from

- From you: registration, branch data, contacts you type in, documents you upload and information exchanged with support.
- From Meta: when someone messages the business's number, we receive that person's number and profile name. That is how a contact can appear in the base without anyone adding it. We also receive events about the WhatsApp Business account, such as message template approvals and changes to the number's quality.
- From Google: when you use social sign-in, we receive your name, email, an email-verified indicator and profile picture. When you accept Analytics, we receive aggregated reports about visits to public pages.
- From Stripe: confirmation of credit purchases, payment results and the status of the customer's payout account.
- From your browsing: technical data and logs generated by the website and backend infrastructure.

## 6. What we use it for, and on what legal basis

Each purpose has a stated legal basis, as article 9 of the LGPD requires. Where we cite the GDPR, the equivalent basis appears in parentheses.

- Providing the contracted service: creating and maintaining the account, connecting the WhatsApp Business account, sending and receiving messages, managing contacts, schedule and knowledge base. Basis: performance of a contract (LGPD art. 7, V; GDPR art. 6.1.b).
- Authenticating and protecting access: sending sign-in codes, maintaining sessions, applying attempt and sending limits. Basis: performance of a contract and legitimate interest in security (art. 7, V and IX; art. 6.1.b and 6.1.f).
- Billing for the service: selling credits, receipts and the record of the usage that debits them. Basis: performance of a contract and compliance with legal and regulatory obligations (art. 7, V and II; art. 6.1.b and 6.1.c).
- Processing contact data on the customer's behalf: everything the panel does to the customer's base. Basis: we do not define it here. The customer, as controller, defines it; we act as processor on their instruction.
- Maintaining and improving the service: error diagnosis, performance measurement, abuse and fraud prevention. Basis: legitimate interest (art. 7, IX; art. 6.1.f).
- Understanding the audience of public pages: measuring visits and general interactions with Google Analytics. Basis: your consent (LGPD art. 7, I; GDPR art. 6.1.a).
- Communicating with you about the service: operational notices, changes to these documents, support replies. Basis: performance of a contract and legitimate interest (art. 7, V and IX).
- Complying with the law and exercising rights: keeping records the law requires, responding to competent authorities and defending ourselves in proceedings. Basis: compliance with a legal obligation and the regular exercise of rights (art. 7, II and VI; art. 6.1.c and 6.1.f).

We do not sell personal data, we do not rent it and we do not share it for third-party advertising. We do not use our customers' contact data to train artificial intelligence models, ours or anyone else's.

We do not make automated decisions that produce legal effects concerning you or that significantly affect you. Responses generated by the artificial intelligence agents are conversation content, and section 8 explains their limits.

## 7. WhatsApp, Meta and what changes because of that

Zaiped operates on Meta's WhatsApp Business Platform (Cloud API) as a technology provider. That has concrete consequences for personal data, and they need to be clear.

Each customer connects their own WhatsApp Business account. The connection is made through Meta's embedded signup flow, inside the panel, and at the end of it Meta issues us a token authorizing us to operate on that customer's behalf. The WhatsApp Business account, the number and the history belong to the customer, not to us. The customer can revoke that access at any time through Meta's business panel, and from then on we can no longer operate that number.

Messages travel through Meta's infrastructure, which acts as the customer's processor on that leg. According to Meta's public documentation, the Cloud API retains messages for a maximum of 30 days in order to deliver and retransmit them, and user identifiers for up to 30 days after the last status update. That retention period is Meta's and is not controlled by us.

Meta imposes its own rules about who may receive a message from a business. The customer must obtain and keep a record of each person's consent (opt-in) before starting a conversation, must honor unsubscribe requests, and must follow the WhatsApp Business Messaging Policy. We pass these obligations on contractually and may suspend accounts that break them, but the party talking to the data subject is the customer.

We also receive events from Meta about the customer's account: message template status, changes to the number's quality and sending limits, and notices of restriction or ban. These events arrive at an endpoint of ours whose origin is verified by cryptographic signature before any processing takes place.

Zaiped is not affiliated with Meta. WhatsApp and Meta are trademarks of Meta Platforms, Inc.

## 8. Artificial intelligence

The panel offers artificial intelligence agents that answer questions using the account's knowledge base. To do that, part of the data leaves our infrastructure and goes to model providers. This section says exactly what.

Artificial intelligence calls are routed through OpenRouter, which forwards them to the models. Today, response generation and document reading use a Google model, and knowledge base indexing uses an OpenAI embeddings model. The access key is ours, not the customer's.

What is sent to the model with each question:

- The instructions the business wrote for the agent.
- The branch profile: name, address, hours and amenities.
- The knowledge base excerpts the search deemed relevant, drawn from products, services, promotions, giveaways and frequently asked questions.
- When the conversation is linked to a contact, that contact's record: name, phone number, funnel stage, email, tax ID, date of birth, address, notes and recent purchases.
- The history of the conversation in progress.

When a document is attached to a contact record, the file is sent to the model for text extraction, and that text becomes part of that contact's knowledge base. If the document contains sensitive data, that data will be processed by the model provider. The customer decides to attach it, and the customer is the one who needs a legal basis for doing so.

We do not use, and we contractually require our providers not to use, our customers' data to train models. Agent responses are generated automatically and may contain errors; they do not replace human review, and neither the business nor we treat them as professional advice.

Agents can take actions in the account, such as checking the schedule and booking, rescheduling or canceling appointments, always within the scope of the account that created them.

## 9. Who we share data with

We share personal data only with the providers needed to deliver and improve the service. The list below is complete and identifies each provider by name. We do not use advertising tools or social media pixels.

Beyond these, we may share data with public authorities under a valid legal request, with legal and accounting advisors bound by confidentiality, and with a successor in the event of a merger, acquisition or corporate reorganization, in which case this Policy continues to apply until it is replaced with prior notice.

| Provider | What we use it for | Where it operates |
| --- | --- | --- |
| Meta Platforms, Inc. | WhatsApp Business Platform: sending and receiving messages, embedded account signup and notices about the customer's account. | United States and other countries |
| Convex, Inc. | Database, backend function execution, operational logs and scheduled jobs. | United States |
| Cloudflare, Inc. | Hosting and delivery of the website and the panel, with the corresponding access logs. | United States and global network |
| BunnyWay d.o.o. (Bunny.net) | Storage and delivery of files: catalog images and documents attached to contact records. | European Union and global network |
| Resend, Inc. | Transactional email delivery: sign-in codes and team invitations. | United States |
| Google LLC | Social sign-in; the language model that generates agent responses and reads documents; and Google Analytics, only after consent, to measure visits to public pages. | United States |
| Stripe, Inc. | Selling the credit packs, processing of the payments customers charge their own clients, and identity verification for payouts. | United States and Ireland |
| OpenRouter, Inc. | Routing artificial intelligence calls to model providers, including the OpenAI embeddings model used for the knowledge base. | United States |

## 10. International transfers

Most of our suppliers are located outside Brazil, so personal data processed here is transferred to other countries, mainly the United States and the European Union. The table in section 9 indicates where each one operates.

This applies to data of Brazilian contacts as well, including phone number, tax ID, date of birth and the content of documents attached to contact records, when they are processed by the artificial intelligence providers or stored in the file delivery network.

These transfers rely on the grounds in article 33 of the LGPD, in particular necessity for the performance of a contract and the contractual clauses agreed with each supplier. For data subject to the GDPR, we use the European Commission's Standard Contractual Clauses or an equivalent mechanism offered by the supplier.

## 11. How long we keep data

We keep personal data for as long as it is necessary for the purposes in section 6, and after that only for the period the law requires.

- Account data and account content: for as long as the account exists. Once the account is closed, we delete or anonymize it within 90 days, except for what must be kept under a legal obligation.
- Contact, schedule and document data: for as long as the customer keeps it in the account. Deleting it in the panel removes both the record and the corresponding file, and deleting a contact also removes that contact's funnel history, recorded sales and documents.
- Billing and tax records: for the period required by applicable law, currently five years, counted as the law provides.
- Access logs and infrastructure logs: for our providers' retention period, and at minimum the period required by article 15 of the Brazilian Internet Civil Framework where applicable.
- Message content: kept by us for as long as the contact and the account exist, as described in section 4. Deleting the contact deletes their conversations; closing the account deletes all of them. On Meta's infrastructure the period is a different one, up to 30 days, as described in section 7.

Backup copies may survive for up to 90 days after deletion, through the natural rotation cycle of those copies, and during that window they are not used for any purpose other than disaster recovery.

## 12. How to delete your data

You can request deletion of your data at any time, free of charge and without having to give a reason. This section is the official path for that, and it is the one our registrations with third parties point to.

If you use the panel, there are two paths, and both are valid:

- In the panel: directly delete the records you want removed, such as contacts, documents, branches and appointments. Deletion erases the data rather than merely hiding it.
- By email: write to privacidade@zaiped.com from the email address registered on the account, stating what you want deleted. If you want the account closed and fully deleted, say so explicitly.

If you are a contact of a business that uses Zaiped and received a message from it, the controller of that data is the business, not us. Write to them first. If you do not know how to reach them, or if they do not respond, write to privacidade@zaiped.com with the phone number used in the conversation and the name of the business: we will identify the account, forward the request to the responsible customer and, where it falls to us, carry out the deletion directly.

Timelines: we acknowledge receipt and respond within 15 days. Deletion from live systems happens within that same period, and removal from backup copies completes within 90 days.

What we cannot delete on request: data the law requires us to keep, such as tax records of payments already made, and data needed for the regular exercise of rights in legal proceedings. In those cases we state exactly what was retained and why.

Deletion of data held in Meta's infrastructure follows Meta's rules, described in section 7. Revoking Zaiped's access to the WhatsApp Business account does not, by itself, erase what Meta holds.

## 13. Your rights

The LGPD grants you, as a data subject, the rights below. They are exercised free of charge by writing to privacidade@zaiped.com.

- Confirmation that we process your data, and access to it.
- Correction of incomplete, inaccurate or out-of-date data.
- Anonymization, blocking or deletion of unnecessary or excessive data, or data processed unlawfully.
- Portability to another provider, upon express request.
- Deletion of data processed on the basis of consent, within the limits of the law.
- Information about who we share your data with, which section 9 already sets out.
- Information about the option not to consent and the consequences of refusing.
- Withdrawal of consent, where consent is the legal basis used.
- Objection to processing carried out on the basis of legitimate interest.
- Review of automated decisions affecting your interests, noting that we do not make such decisions today, as stated in section 6.

If you are in the European Economic Area or the United Kingdom, the corresponding GDPR rights also apply, including the right to lodge a complaint with the data protection authority in your country.

To act on a request we need to confirm it comes from you. That is why we ask that you write from the registered email address or, in the case of contacts, that you provide details allowing us to locate the record. We respond within 15 days.

In Brazil, you may also lodge a complaint with the National Data Protection Authority (ANPD).

## 14. How we protect data

We apply technical and administrative measures to protect personal data against unauthorized access, loss and improper alteration. The main ones:

- Encrypted traffic in transit and data encrypted at rest across our providers' infrastructure.
- Passwordless sign-in, by one-time code sent to your email or by a verified Google account, with attempt and sending limits.
- Authorization enforced on the server for every operation, not only in the interface: the signed-in user and the owner of the data are resolved separately, and access is checked document by document.
- Distinct access roles for owner, collaborator and professional, with branch scoping enforced on reads and writes alike.
- WhatsApp Business account access tokens and two-step verification PINs encrypted at rest, opened only by internal routines and never returned to the browser.
- The origin of automated notices from Meta and Stripe verified by cryptographic signature before anything is written.
- Contact documents accessed through a short-lived temporary link, issued only to someone who has already proven they have access to the account.
- Per-account usage limits on message sending, artificial intelligence calls and file uploads, which contain abuse and reduce the damage of a compromised credential.

No system is immune. If a security incident occurs with material risk to data subjects, we will notify those affected and the ANPD within the deadlines and in the manner the law requires.

## 15. Cookies and similar technologies

We use necessary cookies for the website and panel to work. With your consent, we also use Google Analytics to measure visits to Zaiped's public pages. We do not use Analytics on authenticated panel routes, and we do not use advertising or profiling cookies or social media pixels.

- Language: stores the language you chose, so the page opens in the right one on your next visit.
- Interface state: stores panel display preferences, such as a collapsed sidebar.
- Session: keeps you signed in while you use the panel.
- Cookie preference: records for one year whether you accepted or rejected Analytics, so we can respect your choice.
- Google Analytics: when accepted, measures pages visited, approximate visit source, device and general interactions on public pages. Google may set its own measurement cookies, such as _ga.

Necessary cookies do not require prior consent. Google Analytics is optional: the tag is not loaded before acceptance, and refusing does not limit the website or panel. We process audience data based on your consent, which you can withdraw by deleting Zaiped's cookies in your browser; on your next visit, we will ask again.

You can block or delete cookies through your browser. If you block session cookies, the panel will no longer be able to keep you signed in.

## 16. Children and adolescents

Zaiped is a work tool, intended for businesses and for people over the age of 18. We do not offer the service to children or adolescents and we do not knowingly collect their data for our own purposes.

A contact registered by a customer may be a minor. In that case, processing is carried out in the best interests of the child or adolescent, and it falls to the customer, as controller, to observe article 14 of the LGPD, including the requirement of specific consent from at least one parent or legal guardian where it applies.

If you become aware that a child's data has reached us outside these conditions, write to privacidade@zaiped.com and we will act to remove it.

## 17. Changes to this Policy

We may change this Policy to reflect changes in the service, in the law or among our suppliers. The last-updated date at the top of the page is always that of the version in force.

When a change is material, and in particular when it broadens the purposes of processing or adds a new subprocessor that receives contact data, we will give notice by email or in the panel at least 15 days in advance. Continuing to use the service after the effective date means you agree to the new version.

## 18. Contact and Data Protection Officer

Questions, data subject requests, complaints and the exercise of any right in this Policy all go to the same address, which is also the channel for our Data Protection Officer:

- Privacy and Data Protection Officer: privacidade@zaiped.com
- General matters and support: contato@zaiped.com
- Postal address: NIVENS COMERCIO DE MERCADORIAS LTDA., R. Voluntários da Pátria, 1560, apto. 54 bloco A, Santana, São Paulo, SP, CEP 02010-300

We respond within 15 days. If you are not satisfied with our response, you may escalate to the Brazilian National Data Protection Authority or, under the GDPR, to the data protection authority in your country.