Privacy Policy — KodaCRM
Original version: 12/08/2026
Last updated: 12/08/2026
Effective version at: https://kodacrm.com.br/politica-de-privacidade
KodaCRM created this Privacy Policy (the "Policy") to explain how it handles personal data when you contract, install, or use our support and automation solutions, or when you access our Site.
KodaCRM is a CRM (Customer Relationship Management) and omnichannel support and sales management software, provided as a Software as a Service (SaaS): we host and manage the cloud infrastructure so the Client can operate the Software. This design is crucial for understanding who handles what — which is why there is a chapter dedicated to this topic below (see chapter Specifics of the SaaS model and KodaCRM's role as a Processor).
This Policy is an inseparable part of the KodaCRM Terms and Conditions of Use. In case of doubt or to exercise your rights as a Data Subject, contact us through the channels provided at the end of the document.
SUMMARY - INFORMATION CONTAINED IN THIS POLICY
- Definitions
- To whom this Policy applies
- What data we collect and how
- Purposes of data processing
- Applicable legal bases
- With whom we share your data
- Specifics of the SaaS model and KodaCRM's role as a Processor
- How long we keep your data
- How we protect your data
- Data Subject's Rights
- Cookies
- International Data Transfer
- Data Protection Officer and contact channels
- Changes to this Policy
1. Definitions
To facilitate reading, some terms used throughout this Policy:
- Client: A natural or legal person who contracts the KodaCRM license and manages, under their responsibility, the data entered into the platform.
- User: A person indicated by the Client to use KodaCRM (administrator or internal user) or who only browses the Site.
- Data Subject: Natural person to whom the personal data refer.
- Controller / Processor: LGPD concepts: the Controller makes decisions about processing; the Processor processes data according to the Controller's instructions.
- LGPD: Law No. 13,709/2018 — General Data Protection Law (Brazil).
- ANPD: National Data Protection Authority.
- Site: Main domain and subdomains operated in the context of KodaCRM, accessible at https://kodacrm.com.br.
- Cloud Infrastructure (SaaS): Servers managed by KodaCRM where the platform and Client data are securely hosted.
- Meta Platforms: Platforms operated by Meta Platforms, Inc. (WhatsApp, Instagram, and Facebook Messenger), whose connections and integrations to KodaCRM occur strictly in an authorized manner via Meta's Official API. We do not use unofficial APIs or unauthorized connection methods for these networks.
- Third-Party Integration Channels: Social networks, messengers, marketplaces, payment gateways, and other systems integrable with KodaCRM via APIs, webhooks, or connectors, activated and configured under the Client's exclusive responsibility, acting as the Controller of the data they decide to route through each channel.
- Subscription Plan: KodaCRM usage license for a determined period, contracted by the Client through our sales channels or partner payment platforms.
- Processing: Any operation performed with personal data (collection, storage, transmission, deletion, etc.), pursuant to Art. 5, X, of the LGPD.
2. To whom this Policy applies
This Policy applies to the following Data Subjects:
- Site visitors and leads who fill out contact forms;
- Clients who contract the KodaCRM software license;
- Users appointed by Clients to operate the Software.
This Policy does not apply directly to the end contacts (leads, the Client's customers, message recipients) whose data the Client enters or routes through KodaCRM. Regarding this data, the Client is the exclusive Controller and KodaCRM acts strictly as a Processor — it is their responsibility to maintain their own privacy policy, obtain applicable consents, and handle data subject requests (see chapter Specifics of the SaaS model and KodaCRM's role as a Processor).
3. What data we collect and how
KodaCRM collects personal data in three distinct contexts. Each has its own source and purpose, described below.
3.1. Data you provide us directly
When you register to use KodaCRM, fill out forms on the Site, or interact with our social networks, we collect:
- Identification and contact: Name, email, phone, and CPF or CNPJ (the latter for billing and license validation).
- Access credentials: Password (stored in hash) and records of acceptance of the Terms and this Policy.
- Installation data: Domain and subdomains registered by the Client to link the license.
- Spontaneous messages: When you write to us, we occasionally store the message content for reply and customer service history.
- Social media profile picture: When you contact us via WhatsApp, Instagram, or Facebook, your profile picture may be visible to our customer service (it is not extracted or stored by us).
3.2. Data collected automatically
While browsing the Site and using the KodaCRM administrative panel, we automatically log:
- Access logs: IP address, action date and time, device, and browser, pursuant to Art. 15 of Law No. 12,965/2014 (Brazilian Civil Rights Framework for the Internet).
- Cookies: Mechanisms and consent management are detailed in the Cookies chapter of this Policy.
3.3. Technical licensing system data
Due to the SaaS nature of KodaCRM, we store the operational data (messages, contacts, conversations, pipelines, files, and end-customer data) entered by the Client strictly to provide the service. For platform operation, security, and auditing, we collect:
- License key and status (active/inactive);
- Subdomains registered in the installation;
- Aggregated system login statistics;
- Installation server IP and Software version;
- Connection status and technical identifiers from Meta's official API integrations (WhatsApp Business Platform, Instagram, Facebook Messenger): App ID, WABA ID, OAuth tokens, webhook events, and quality indicators provided by Meta itself.
This data is processed exclusively for security, abuse prevention, compliance auditing, and operational stability.
4. Purposes of data processing
We process the aforementioned data exclusively for the purposes below. Any processing for a purpose not provided for in this Policy will require a new legal basis or new consent.
- Contract operation: Identify Client and User, bill, validate the license, provide technical support, and communicate contractual aspects (renewals, plan changes, official announcements).
- Institutional communication and marketing: Answer questions, send content and news about KodaCRM, measure campaigns, and segment communication — always with an opt-out possibility.
- Security and fraud prevention: Identify attempts at piracy, abuse, fraud, and protect infrastructure integrity.
- Fulfillment of legal obligations: Comply with court orders, ANPD requests, and other legal obligations (especially the Brazilian Civil Rights Framework for the Internet).
- Regular exercise of rights: Defense in judicial, administrative, or arbitral proceedings.
- Site measurement and improvement: Analyze traffic, visitor behavior, and page/campaign performance, observing the consent regime described in the Cookies chapter.
5. Applicable legal bases
Each purpose finds a legal basis in the LGPD, according to the table below:
| Data | Purpose | Legal basis (LGPD) |
|---|---|---|
| Client and User Registration | Formation and execution of the KodaCRM license contract | Contract execution (Art. 7, V) |
| Communication with Data Subject and direct marketing | Customer service, contractual and promotional communication | Contract execution (Art. 7, V) and legitimate interest (Art. 7, IX), with opt-out |
| IP, session, device, and browser logs | Security, activity logging, and compliance with the Brazilian Internet Framework | Legal obligation (Art. 7, II) and legitimate interest (Art. 7, IX) |
| Usage, integrations, and infrastructure data | Provision of the SaaS service, fraud prevention, and infrastructure protection | Contract execution (Art. 7, V) and legitimate interest (Art. 7, IX) |
| Cookies strictly necessary for the Site | Technical functioning and navigation security | Legitimate interest (Art. 7, IX) |
| Optional cookies (statistical, marketing, and functional) | Measurement, personalization, and targeted advertising | Consent (Art. 7, I) |
You may revoke consents at any time through the channels provided at the end of this Policy.
6. With whom we share your data
KodaCRM shares personal data only with third parties essential for operating the solutions, the Site, and the licensing system. These third parties fall into three groups: (i) Processors, who process data under our instructions; (ii) Partner Controllers, who process data autonomously for their own purposes; and (iii) Independent Controllers triggered by the Client itself.
6.1. Processors
Contracted Processors are organized into functional categories. We maintain data processing agreements and demand minimum information security standards compatible with the LGPD.
- Corporate infrastructure and hosting: Renowned cloud providers where KodaCRM and Client data are securely hosted.
- Global CDN network and edge protection: Used for hosting the institutional Site for security and performance.
- Communication and transactional email: Tools for sending confirmation, password reset, and support emails.
An updated nominal list of Processors may be requested at any time by the Data Subject, under Art. 18, VII, of the LGPD, by emailing contato@kodacrm.com.br.
6.2. Partner Controllers
Some relationships involve third parties who process personal data for their own purposes, acting as autonomous Controllers (not Processors):
- Payment platforms and gateways: Payment processors that collect and handle billing, reconciliation, and fraud prevention data according to their own policies.
- Meta Platforms, Inc. / WhatsApp LLC: Provider of official APIs for WhatsApp Business Platform, Instagram Direct, and Facebook Messenger.
6.3. Site measurement tools
The institutional Site may use third-party tools for statistical traffic analysis, campaign measurement, and advertising segmentation. These tools collect technical visitor data (IP address, device identifiers, pages visited, browsing time) to improve experience and performance.
The activation of these tools occurs through consent provided by the cookie banner — see the Cookies chapter.
6.4. Third-Party Integrations configured by the Client
KodaCRM is an omnichannel platform designed to integrate with multiple channels and systems — social networks, messengers, marketplaces, payment gateways, and others — via APIs, webhooks, or connectors. Activating these integrations is the exclusive decision of the Client, acting as Controller of the data they decide to route through each channel.
7. Specifics of the SaaS model and KodaCRM's role as a Processor
KodaCRM is provided under a SaaS (Software as a Service) model. This means that:
- Custody and infrastructure: The Software runs on cloud servers managed by us. KodaCRM guarantees the security, backups, and availability of the infrastructure for the Client to operate.
- Separation of roles under the LGPD:
- Regarding operational data processed in KodaCRM, such as messages, conversation history, files, contacts, and the Client's end-customer data, the Client acts as the Controller and KodaCRM acts as the Processor, processing such data only according to the Client's instructions and exclusively for providing the contracted service.
- Client Responsibilities: It is up to the Client, as a Controller, to:
- Provide a privacy notice to its users and end customers;
- Obtain consent or define the applicable legal basis for data processing performed through KodaCRM;
- Ensure the secure use of access credentials to the platform;
- Directly respond to requests from data subjects whose data is processed on its KodaCRM instance.
8. How long we keep your data
Personal data kept by KodaCRM is stored only for the time necessary to fulfill the purposes for which it was collected, observing legal and regulatory deadlines:
- Registration and billing data: Kept for the duration of the contract and, after termination, for the applicable legal statute of limitations (e.g., 5 years for tax and civil obligations, per the Brazilian Civil Code and National Tax Code).
- Access logs (IP, date, and time): Mandatorily kept for a minimum period of 6 (six) months, as required by Art. 15 of the Brazilian Internet Framework (Law No. 12,965/2014).
- Customer service and support data: Maintained for up to 2 (two) years after service completion for history, quality control, and defense in potential disputes.
- Data for sending marketing/communication: Stored until the Data Subject requests unsubscription (opt-out) or revokes their consent.
After the deadlines expire, data will be securely deleted or anonymized for statistical purposes.
9. How we protect your data
We adopt technical, administrative, and organizational measures capable of protecting the personal data under our custody against unauthorized access, destruction, loss, alteration, communication, or any form of inadequate or illicit processing.
Among the measures implemented are:
- Use of encryption and secure protocol (HTTPS/TLS) in Site data traffic and license communication;
- Storage of access credentials using secure hashing algorithms;
- Restriction of access to internal systems and data only to authorized employees and contractors;
- Security monitoring and continuous application of software patches and updates on our infrastructure.
10. Data Subject's Rights
Under Art. 18 of the LGPD, you, as the Subject of personal data processed by KodaCRM, have the following rights:
- Confirmation and Access: Confirm the existence of processing and access your personal data.
- Correction: Request correction of incomplete, inaccurate, or outdated data.
- Anonymization, Blocking, or Deletion: Request the anonymization, blocking, or deletion of unnecessary, excessive data or data processed in non-compliance with the LGPD.
- Portability: Request data portability to another service or product provider.
- Data Deletion: Request the deletion of personal data processed based on consent, except for retention cases provided by law.
- Information on Sharing: Obtain information about public and private entities with which we share your data.
- Information on the Option Not to Consent: Be informed about the possibility of not giving consent and the consequences of refusal.
- Consent Revocation: Revoke consent at any time, simply and free of charge.
To exercise any of these rights, contact us at: contato@kodacrm.com.br or privacidade@kodacrm.com.br.
11. Cookies
Cookies are small text files saved in your browser when you visit our Site. They help the site recognize your device on future visits.
We divide the cookies used on our Site into:
- Strictly Necessary: Essential for proper Site navigation and functioning. Cannot be disabled.
- Performance and Analytics: Collect information on how visitors use the site, allowing us to analyze and improve performance.
- Functional: Allow the Site to remember choices you made.
- Advertising and Marketing: Used to direct relevant ads and content according to your profile.
You can manage and alter your cookie preferences at any time through the consent management tool on the Site or by adjusting your browser settings.
12. International Data Transfer
We use IT infrastructure services and cloud providers that may be located or have servers outside Brazil.
In these cases, we ensure the international data transfer is performed in compliance with Chapter V of the LGPD, assuring that the destination country or receiving organization offers a level of personal data protection adequate to that provided by Brazilian legislation.
13. Data Protection Officer and contact channels
If you have doubts, comments, or wish to exercise your rights regarding personal data processing, contact our Data Protection Officer (DPO):
- Privacy Channel: KodaCRM
- Contact Email:
contato@kodacrm.com.br/privacidade@kodacrm.com.br - Website: https://kodacrm.com.br
14. Changes to this Policy
We reserve the right to alter or update this Privacy Policy at any time to reflect improvements in our tools, or legal/regulatory adjustments.
Whenever relevant changes are made, we will publish the new version on this page with the revised update date. We recommend that you consult this Policy periodically to stay informed about how your data is protected.