Quick summary: Zymplo receives your WhatsApp messages to process them with AI and return useful responses (reminders · payment collection · invoices · etc). We do not sell your data · we do not share it with advertising third parties · you can delete your account whenever you want at
/en/legal/delete-account/.
1. Who operates Zymplo
Zymplo is operated by Zymplo Inc., a company incorporated in Delaware (USA), EIN 30-1486305, DUNS 145007664, with registered address in Newark, DE 19713, USA.
For privacy inquiries: privacy@zymplo.com.
2. What data we collect
- WhatsApp messages you send to the Zymplo number (text · audio · images · documents · location).
- Your phone number (provided automatically by Meta's API when you write).
- Conversation metadata: timestamps · detected language · country detected via phone prefix.
- Data you share voluntarily: client names · collection amounts · photos of receipts · document numbers (CPF · RUC · RFC · etc · only the ones you choose to use).
- Usage data: which tools you used (collection · NFS-e · reminders · etc) · no advertising tracking.
What we do NOT collect
- Your WhatsApp contact list.
- Messages from other chats that are NOT with Zymplo.
- Your GPS location (unless you explicitly share it).
- Biometric data · sensitive information unrelated to your business.
3. What we use your data for
- Process your messages with AI models (Anthropic Claude · OpenAI GPT · providers with signed NDA + DPA).
- Execute the actions you requested (create a payment collection · send a reminder · issue an NFS-e · etc).
- Improve service quality (aggregated and anonymized analytics).
- Comply with local legal obligations (LGPD Brazil · Law 1682/01 Paraguay · etc).
4. Legal bases
- Consent: by sending us a first message you accept this policy (implicit opt-in if the message contains substantive content · explicit if you just write "hello").
- Contract performance: to deliver the service you requested.
- Legitimate interest: for fraud prevention and service improvement.
- Legal obligation: retention of issued NFS-e for the fiscal period (5 years in Brazil).
5. Who we share with
- Meta (WhatsApp Business API): messaging infrastructure · signed DPA.
- AI providers: Anthropic · OpenAI · xAI (they process your messages in real time · signed DPAs · we do not train models with your data).
- Stripe / Mercado Pago: only if you activate payment features.
- Cloudflare · Oracle Cloud: hosting · CDN.
- Resend: transactional emails.
- Authorities: only under a valid court order from the corresponding country.
We do NOT sell · do NOT rent · do NOT share for advertising.
6. Google data (Google Calendar)
If you connect your Google account, Zymplo requests the minimum events permission for your Google Calendar (https://www.googleapis.com/auth/calendar.events) so that, from WhatsApp, you can:
- See the events on your agenda for the day.
- Create, update and delete events and appointments at your request (including payment collections and reminders).
We process that data in real time to execute what you requested · we do not keep copies of your calendar on our servers beyond what is necessary for the active feature. You can disconnect your account and revoke access at any time from your Google account or by asking via WhatsApp.
Limited Use (Google API Services User Data Policy): Zymplo's use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy, including its
Limited Use requirements. Specifically: we do not use your Google Calendar data for advertising · we do not sell it or transfer it to third parties, except to operate the feature you requested, under a valid legal requirement, or with your explicit consent · and we do not use it to train generalized AI models.
7. Retention
- Messages and operational data: up to 30 days (free plan) or up to 12 months (paid plans) after the last interaction.
- Issued NFS-e: 5 years (fiscal obligation).
- Technical logs: 90 days.
- Encrypted backups: 30 days after account deletion.
8. Your rights (LGPD · GDPR · CCPA)
- Access: request a copy of all your data.
- Rectification: correct inaccurate data.
- Deletion ("right to be forgotten"): see /en/legal/delete-account/.
- Portability: export your data in JSON.
- Objection: refuse non-essential uses.
- Withdrawal of consent: at any time without affecting prior processing.
Exercise your rights by emailing privacy@zymplo.com. We respond within 15 business days at most.
9. Security
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Role-restricted data access · audit logs.
- Encrypted backups · disaster recovery tested monthly.
- Quarterly key rotation policy.
10. Minors
Zymplo is NOT directed at anyone under 18. If we discover a minor's data, we delete it immediately. If you are a guardian and notice this: privacy@zymplo.com.
11. International transfers
Data may be processed in the USA · Brazil · Paraguay · countries where our providers operate. All comply with SCCs (Standard Contractual Clauses) or local equivalents.
12. Changes to this policy
We will notify you via WhatsApp of any material changes · 30 days in advance. Minor changes (typographical · clarifications) without notification.
13. Regulatory authority
You can file a complaint with your local authority: ANPD (Brazil) · MITIC (Paraguay) · INAI (Mexico) · AEPD (Spain) · SIC (Colombia) · etc.