Privacy Policy — KodaCRM

Original version: 12/08/2026
Last updated: 12/08/2026
Effective version at: https://kodacrm.com.br/politica-de-privacidade

KodaCRM created this Privacy Policy (the "Policy") to explain how it handles personal data when you contract, install, or use our support and automation solutions, or when you access our Site.

KodaCRM is a CRM (Customer Relationship Management) and omnichannel support and sales management software, provided as a Software as a Service (SaaS): we host and manage the cloud infrastructure so the Client can operate the Software. This design is crucial for understanding who handles what — which is why there is a chapter dedicated to this topic below (see chapter Specifics of the SaaS model and KodaCRM's role as a Processor).

This Policy is an inseparable part of the KodaCRM Terms and Conditions of Use. In case of doubt or to exercise your rights as a Data Subject, contact us through the channels provided at the end of the document.


SUMMARY - INFORMATION CONTAINED IN THIS POLICY

  1. Definitions
  2. To whom this Policy applies
  3. What data we collect and how
  4. Purposes of data processing
  5. Applicable legal bases
  6. With whom we share your data
  7. Specifics of the SaaS model and KodaCRM's role as a Processor
  8. How long we keep your data
  9. How we protect your data
  10. Data Subject's Rights
  11. Cookies
  12. International Data Transfer
  13. Data Protection Officer and contact channels
  14. Changes to this Policy

1. Definitions

To facilitate reading, some terms used throughout this Policy:


2. To whom this Policy applies

This Policy applies to the following Data Subjects:

This Policy does not apply directly to the end contacts (leads, the Client's customers, message recipients) whose data the Client enters or routes through KodaCRM. Regarding this data, the Client is the exclusive Controller and KodaCRM acts strictly as a Processor — it is their responsibility to maintain their own privacy policy, obtain applicable consents, and handle data subject requests (see chapter Specifics of the SaaS model and KodaCRM's role as a Processor).


3. What data we collect and how

KodaCRM collects personal data in three distinct contexts. Each has its own source and purpose, described below.

3.1. Data you provide us directly

When you register to use KodaCRM, fill out forms on the Site, or interact with our social networks, we collect:

3.2. Data collected automatically

While browsing the Site and using the KodaCRM administrative panel, we automatically log:

3.3. Technical licensing system data

Due to the SaaS nature of KodaCRM, we store the operational data (messages, contacts, conversations, pipelines, files, and end-customer data) entered by the Client strictly to provide the service. For platform operation, security, and auditing, we collect:

This data is processed exclusively for security, abuse prevention, compliance auditing, and operational stability.


4. Purposes of data processing

We process the aforementioned data exclusively for the purposes below. Any processing for a purpose not provided for in this Policy will require a new legal basis or new consent.

  1. Contract operation: Identify Client and User, bill, validate the license, provide technical support, and communicate contractual aspects (renewals, plan changes, official announcements).
  2. Institutional communication and marketing: Answer questions, send content and news about KodaCRM, measure campaigns, and segment communication — always with an opt-out possibility.
  3. Security and fraud prevention: Identify attempts at piracy, abuse, fraud, and protect infrastructure integrity.
  4. Fulfillment of legal obligations: Comply with court orders, ANPD requests, and other legal obligations (especially the Brazilian Civil Rights Framework for the Internet).
  5. Regular exercise of rights: Defense in judicial, administrative, or arbitral proceedings.
  6. Site measurement and improvement: Analyze traffic, visitor behavior, and page/campaign performance, observing the consent regime described in the Cookies chapter.

5. Applicable legal bases

Each purpose finds a legal basis in the LGPD, according to the table below:

Data Purpose Legal basis (LGPD)
Client and User Registration Formation and execution of the KodaCRM license contract Contract execution (Art. 7, V)
Communication with Data Subject and direct marketing Customer service, contractual and promotional communication Contract execution (Art. 7, V) and legitimate interest (Art. 7, IX), with opt-out
IP, session, device, and browser logs Security, activity logging, and compliance with the Brazilian Internet Framework Legal obligation (Art. 7, II) and legitimate interest (Art. 7, IX)
Usage, integrations, and infrastructure data Provision of the SaaS service, fraud prevention, and infrastructure protection Contract execution (Art. 7, V) and legitimate interest (Art. 7, IX)
Cookies strictly necessary for the Site Technical functioning and navigation security Legitimate interest (Art. 7, IX)
Optional cookies (statistical, marketing, and functional) Measurement, personalization, and targeted advertising Consent (Art. 7, I)

You may revoke consents at any time through the channels provided at the end of this Policy.


6. With whom we share your data

KodaCRM shares personal data only with third parties essential for operating the solutions, the Site, and the licensing system. These third parties fall into three groups: (i) Processors, who process data under our instructions; (ii) Partner Controllers, who process data autonomously for their own purposes; and (iii) Independent Controllers triggered by the Client itself.

6.1. Processors

Contracted Processors are organized into functional categories. We maintain data processing agreements and demand minimum information security standards compatible with the LGPD.

An updated nominal list of Processors may be requested at any time by the Data Subject, under Art. 18, VII, of the LGPD, by emailing contato@kodacrm.com.br.

6.2. Partner Controllers

Some relationships involve third parties who process personal data for their own purposes, acting as autonomous Controllers (not Processors):

6.3. Site measurement tools

The institutional Site may use third-party tools for statistical traffic analysis, campaign measurement, and advertising segmentation. These tools collect technical visitor data (IP address, device identifiers, pages visited, browsing time) to improve experience and performance.

The activation of these tools occurs through consent provided by the cookie banner — see the Cookies chapter.

6.4. Third-Party Integrations configured by the Client

KodaCRM is an omnichannel platform designed to integrate with multiple channels and systems — social networks, messengers, marketplaces, payment gateways, and others — via APIs, webhooks, or connectors. Activating these integrations is the exclusive decision of the Client, acting as Controller of the data they decide to route through each channel.


7. Specifics of the SaaS model and KodaCRM's role as a Processor

KodaCRM is provided under a SaaS (Software as a Service) model. This means that:

  1. Custody and infrastructure: The Software runs on cloud servers managed by us. KodaCRM guarantees the security, backups, and availability of the infrastructure for the Client to operate.
  2. Separation of roles under the LGPD:
    • Regarding operational data processed in KodaCRM, such as messages, conversation history, files, contacts, and the Client's end-customer data, the Client acts as the Controller and KodaCRM acts as the Processor, processing such data only according to the Client's instructions and exclusively for providing the contracted service.
  3. Client Responsibilities: It is up to the Client, as a Controller, to:
    • Provide a privacy notice to its users and end customers;
    • Obtain consent or define the applicable legal basis for data processing performed through KodaCRM;
    • Ensure the secure use of access credentials to the platform;
    • Directly respond to requests from data subjects whose data is processed on its KodaCRM instance.

8. How long we keep your data

Personal data kept by KodaCRM is stored only for the time necessary to fulfill the purposes for which it was collected, observing legal and regulatory deadlines:

After the deadlines expire, data will be securely deleted or anonymized for statistical purposes.


9. How we protect your data

We adopt technical, administrative, and organizational measures capable of protecting the personal data under our custody against unauthorized access, destruction, loss, alteration, communication, or any form of inadequate or illicit processing.

Among the measures implemented are:


10. Data Subject's Rights

Under Art. 18 of the LGPD, you, as the Subject of personal data processed by KodaCRM, have the following rights:

  1. Confirmation and Access: Confirm the existence of processing and access your personal data.
  2. Correction: Request correction of incomplete, inaccurate, or outdated data.
  3. Anonymization, Blocking, or Deletion: Request the anonymization, blocking, or deletion of unnecessary, excessive data or data processed in non-compliance with the LGPD.
  4. Portability: Request data portability to another service or product provider.
  5. Data Deletion: Request the deletion of personal data processed based on consent, except for retention cases provided by law.
  6. Information on Sharing: Obtain information about public and private entities with which we share your data.
  7. Information on the Option Not to Consent: Be informed about the possibility of not giving consent and the consequences of refusal.
  8. Consent Revocation: Revoke consent at any time, simply and free of charge.

To exercise any of these rights, contact us at: contato@kodacrm.com.br or privacidade@kodacrm.com.br.


11. Cookies

Cookies are small text files saved in your browser when you visit our Site. They help the site recognize your device on future visits.

We divide the cookies used on our Site into:

You can manage and alter your cookie preferences at any time through the consent management tool on the Site or by adjusting your browser settings.


12. International Data Transfer

We use IT infrastructure services and cloud providers that may be located or have servers outside Brazil.

In these cases, we ensure the international data transfer is performed in compliance with Chapter V of the LGPD, assuring that the destination country or receiving organization offers a level of personal data protection adequate to that provided by Brazilian legislation.


13. Data Protection Officer and contact channels

If you have doubts, comments, or wish to exercise your rights regarding personal data processing, contact our Data Protection Officer (DPO):


14. Changes to this Policy

We reserve the right to alter or update this Privacy Policy at any time to reflect improvements in our tools, or legal/regulatory adjustments.

Whenever relevant changes are made, we will publish the new version on this page with the revised update date. We recommend that you consult this Policy periodically to stay informed about how your data is protected.