Data Deletion Instructions
Provisional version, under legal review. Published on 4 October 2026.
On this page
- 1. Which case is yours?
- 2. End customer of a company that uses Bright Digital AI
- 3. Platform user or Bright Digital contact
- 4. Client company closing its account
- 5. People who interacted with the Bright Digital AI app through Meta
- 6. What we delete and what we keep
- 7. Timeframes
- 8. The confirmation you receive
- 9. Contact
This page explains how to request deletion of your personal data processed by Bright Digital AI, Bright Digital's WhatsApp customer service platform (BRIGHT DIGITAL LTDA, CNPJ 48.420.424/0001-31). More detail is in our Privacy Policy.
1. Which case is yours?
| You are | What to do | Section |
|---|---|---|
| An end customer: you chatted on WhatsApp with a company that uses Bright Digital AI | Contact that company first | 2 |
| A user at a client company: you have a login on the platform | Write to Bright Digital | 3 |
| A client company that wants to close its account and delete everything | The administrator requests closure | 4 |
| Someone who connected a Meta account to the Bright Digital AI app | Remove the app in Meta and write to us | 5 |
| Someone who talked to Bright Digital itself (website or WhatsApp) | Write to Bright Digital | 3 |
2. End customer of a company that uses Bright Digital AI
Your conversations, photos, audio and number belong to the company you talked to. It is the controller of the data and decides about it. Bright Digital only processes that data on its behalf (as processor).
How to request:
- Ask the company directly for deletion, on its own WhatsApp or through the privacy channel it gives.
- The company reviews the request and instructs us. Bright Digital deletes the data as instructed.
If you cannot reach the company, or do not know which company it is, write to privacidade@brightdigitalai.com with:
- the WhatsApp number you used;
- the company's name or its WhatsApp number, if you know it;
- what you would like done.
We forward your request to the company without delay and let you know. We do not delete a company's data on our own initiative, because the decision is the company's, but we follow up on the request.
To stop receiving messages, you can also reply to the company with the word it tells you to use, or block the number in WhatsApp itself.
3. Platform user or Bright Digital contact
Here Bright Digital is the controller and handles your request directly.
How to request today: send an email to privacidade@brightdigitalai.com with the subject "Data deletion", from the email address registered on the platform, stating:
- your name and the account email;
- the company you belong to on the platform, if any;
- whether you want the whole account deleted or only some data.
Coming soon: each company's administrator will be able to record and resolve privacy requests directly on the platform, in a dedicated screen. This page will be updated when that feature is available.
Before deleting, we may ask you to confirm your identity, so that no one can delete someone else's account.
If you are a user at a company that remains a client, the company's administrator can also remove your access. If you do not belong to any other company on the platform, your account is deleted. Messages you wrote on the company's behalf stay with the company, because they are part of its conversations with its customers.
4. Client company closing its account
The company's administrator requests closure by email at privacidade@brightdigitalai.com. From then on:
| Step | What happens | When |
|---|---|---|
| 1. Export | We build a full copy of the company's data (conversations, media, contacts, CRM, settings, invoices), in an open format, for the administrator to download | At the start of closure |
| 2. Read-only window | Staff can see everything without changing it, and download the export. The company can choose "return and delete" (the default) or "delete without export" | 30 days |
| 3. Deletion from the platform | We delete all the company's data and destroy its encryption keys | When the 30-day window ends |
| 4. Deletion from backups | Backup copies expire by rotation | Within 35 days of the deletion |
| 5. Certificate | We send the deletion certificate, and an addendum when the backups expire | At deletion and at backup expiry |
If the company needs us to keep its archive longer, for example for a legal obligation of its own, it can instruct us in writing before the window ends.
5. People who interacted with the Bright Digital AI app through Meta
Bright Digital AI uses an app registered on Meta's platform to send and receive messages through the WhatsApp Cloud API.
If you connected a Meta account or a WhatsApp Business number to the app (for example, as your company's administrator):
-
Remove the Bright Digital AI app's access in your Meta business portfolio settings, under integrations or connected partners.
-
Email privacidade@brightdigitalai.com asking for deletion of the data linked to that connection.
When we receive the request, we delete the Meta access tokens, the number's connection data and your platform account data, as described in sections 3 and 4.
If you only chatted on WhatsApp with a company that uses Bright Digital AI, you do not have an account with us. Follow section 2.
6. What we delete and what we keep
We delete all the personal data covered by the request, except what the law requires us to keep or what we need to defend ourselves in proceedings. That data is kept with restricted access and deleted when its period ends.
| Data | What happens | How long it stays | Reason |
|---|---|---|---|
| Account data, 2FA, preferences | Deleted | Not kept | |
| Conversations, media and contacts (of the client company) | Deleted on the company's instruction | Not kept, unless the company instructs otherwise in writing | LGPD art. 39 |
| Raw Meta archive | Deleted | Not kept (and never longer than 90 days) | |
| Access logs (date, time and IP) | Kept until the period ends, then deleted | 6 to 12 months from the access | Marco Civil da Internet, art. 15 |
| Invoices, tax invoices and payments | Kept | 5 years from 1 January of the following year | Brazilian Tax Code (CTN) arts. 173 and 195 |
| Contracts, export records and deletion certificates | Kept | 10 years after the contract ends | Defence of rights |
| Security incident records | Kept | 5 years | ANPD Resolution CD/ANPD 15/2024 |
| Platform audit log | Kept, but the name, email and IP are deleted sooner. Only a meaningless reference remains | 5 years | Accountability |
| Records of our support staff's access | Kept | 5 years | Accountability |
| Backups | Expire by rotation | Up to 35 days | Security |
| Anonymous usage totals | Kept | No limit | Not personal data |
If a backup ever has to be restored, we re-apply every deletion before the platform goes back online, so that nothing deleted reappears.
7. Timeframes
-
Answer to your request: we confirm receipt immediately and send the full answer within 15 days (LGPD art. 19). For people in the European Union, within one month (GDPR art. 12(3)), extendable by two further months for complex requests, with notice.
-
Deletion from the platform: within the same periods.
- Deletion from backups: within 35 days of deletion from the platform.
- End-customer requests forwarded by the company: we carry out the company's instruction within the period set in our contract and data processing agreement with it.
8. The confirmation you receive
When deletion is complete, we send an email with:
- the date of deletion;
- what was deleted;
- what was kept, why, and until when;
- the date the backups expire;
- a reference number for the request.
Companies that close their account also receive the deletion certificate (as a PDF and as a digitally signed file that can be verified later), with an addendum when the backups expire.
9. Contact
- Data Protection Officer: privacidade@brightdigitalai.com
- General contact: contato@brightdigitalai.com
If you are not satisfied with our answer, you can complain to the Brazilian National Data Protection Authority (ANPD) at www.gov.br/anpd or, if you are in the European Union, to the data protection authority of your country.