Bright Digital AI Privacy Policy

Provisional version, under legal review. Published on 4 October 2026.

Version: 1.0 (provisional)
Effective from: 4 October 2026
Portuguese version: Política de Privacidade. If the two versions differ, the Portuguese version prevails.

On this page
  1. 1. Who we are
  2. 2. Quick summary
  3. 3. Our role: controller or processor
  4. 4. What data we process
  5. 5. Why we use data and on what legal basis
  6. 6. Artificial intelligence
  7. 7. Who we share data with
  8. 8. Sub-processors and international transfers
  9. 9. How long we keep data
  10. 10. Security
  11. 11. Cookies
  12. 12. Your rights and how to exercise them
  13. 13. Children and teenagers
  14. 14. Changes to this policy
  15. 15. Contact

1. Who we are

Bright Digital provides Bright Digital AI, a WhatsApp customer service and sales platform with artificial intelligence (AI) assistants and a CRM. Our clients are companies that use the platform to talk to their own customers.

Legal name BRIGHT DIGITAL LTDA
CNPJ (Brazilian company number) 48.420.424/0001-31
Website www.brightdigitalai.com
Contact email contato@brightdigitalai.com
Data Protection Officer (encarregado) Privacy channel: privacidade@brightdigitalai.com
DPO email privacidade@brightdigitalai.com

2. Quick summary

3. Our role: controller or processor

The law distinguishes whoever decides about data (the controller) from whoever processes it on someone else's behalf (the processor, called operador in the LGPD). Bright Digital has both roles, depending on the data.

Data Bright Digital's role Who decides
Accounts of client companies' users (login, password, two-step verification) Controller Bright Digital
Billing, invoices and payments Controller Bright Digital
Platform security and audit logs Controller Bright Digital
Our website and the enquiries we receive through it Controller Bright Digital
Bright Digital's own WhatsApp conversations with people interested in the product Controller Bright Digital
Conversations, media and contacts of each client company's end customers Processor The client company

Where we are the processor, the client company is the controller. It decides what the data is used for, how long it is kept and how the AI assistant behaves. We follow its instructions under the contract and the data processing agreement (LGPD art. 39; GDPR art. 28).

4. What data we process

4.1 Data for which we are the controller

Category Examples Source
Account data Name, email, mobile number, company, role, language, time zone and display preferences You or your company's administrator
Two-step verification (2FA) Authenticator app secret, recovery codes (stored in protected form), trusted devices You, when you turn on 2FA
Sessions and security logs Date and time of access, IP address, browser, login attempts, open sessions Generated by using the platform
Audit logs Who did what and when: settings changes, invitations, support access Generated by using the platform
Usage and billing AI usage (tokens, model, cost), messages sent, transcriptions, plan, prices, invoices, payment and tax invoice details Generated by use and supplied by the company
Support Messages and attachments you send to our support You
Website and sales enquiries Name, email, mobile number and messages from people who contact us; conversations with Bright Digital on WhatsApp You
Website cookies and analytics See section 11 Your browser

4.2 Data for which we are the processor (on behalf of the client company)

Category Examples
WhatsApp messages Text of messages received and sent, captions, shared locations, shared contacts, button replies, reactions, date and time
Media Photos, audio, video, documents and stickers, sent by the end customer or by the company. We store the file when it arrives, because Meta's link expires
Contact data WhatsApp number, WhatsApp profile name, tags, notes and deal data the company records in the CRM
Delivery statuses Sent, delivered, read or failed, with Meta's error codes
Raw Meta archive An exact copy of each technical notification (webhook) Meta sends us. It is used only to recover messages and media after a failure
AI processing Audio transcription, image analysis and replies generated by the AI assistant
Alerts Internal notices for the company's staff, for example "a customer asked for a person". By default an alert carries only the name, the last 4 digits and a link. If the company turns it on, it also carries an excerpt of up to 100 characters of the last message

The client company decides what data it collects from its customers. We do not ask for sensitive data, but an end customer may volunteer sensitive information in a conversation (LGPD art. 11; GDPR art. 9). It is protected like the rest of the conversation and follows the company's rules.

This table covers data for which we are the controller. For data we process as a processor, the legal basis is set by the client company.

Purpose Data LGPD legal basis (art. 7) GDPR legal basis (art. 6)
Create and maintain your account, log you in Account data Performance of a contract (V) Contract, 6(1)(b)
Protect the account with 2FA and detect improper access 2FA, sessions, security logs Performance of a contract (V) and legitimate interest (IX) Contract, 6(1)(b), and legitimate interest, 6(1)(f)
Keep access logs for at least 6 months Date, time and IP of access Legal obligation (II): Marco Civil da Internet, art. 15 Legitimate interest, 6(1)(f)
Record actions on the platform and our support staff's access Audit logs Legitimate interest (IX) and exercise of rights (VI) Legitimate interest, 6(1)(f)
Measure usage, issue invoices and tax invoices, collect payment Usage and billing Performance of a contract (V) and legal obligation (II) Contract, 6(1)(b), and legal obligation, 6(1)(c)
Handle support requests Support Performance of a contract (V) Contract, 6(1)(b)
Answer enquiries and present the product Website and sales enquiries Pre-contractual steps (V) and legitimate interest (IX) 6(1)(b) and 6(1)(f)
Tell you about service changes, security and incidents Account email Performance of a contract (V) and legal obligation (II) 6(1)(b) and 6(1)(c)
Website analytics and marketing Non-essential cookies Consent (I) Consent, 6(1)(a)
Defend our rights in proceedings Contracts, records, invoices Exercise of rights (VI) Legitimate interest, 6(1)(f)

Where we rely on legitimate interest, we first assess whether it respects your rights (LGPD art. 10). You can ask for that assessment by writing to the DPO.

6. Artificial intelligence

7. Who we share data with

We do not sell or rent personal data. We share it only:

8. Sub-processors and international transfers

8.1 List of sub-processors

This list is kept up to date. Under the contract, we notify client companies before adding a new sub-processor that will process their data. Last updated: 4 October 2026.

Provider What it does Data Where it processes Transfer mechanism
Meta (WhatsApp Cloud API) Sends and receives WhatsApp messages Messages, media, numbers, statuses United States and other countries As described in section 8.2
Anthropic AI models (Claude) Conversation messages, images United States As described in section 8.2
OpenRouter, for DeepSeek models Routes requests to DeepSeek models, with zero data retention and only providers outside China Conversation messages United States and providers outside China As described in section 8.2
Groq Audio transcription Conversation audio United States As described in section 8.2
Other AI providers Additional models, only when a company chooses them Conversation messages Stated before they are added Stated before they are added
Cloud provider with servers in Brazil, to be confirmed Servers, database, files and backups of the platform All Brazil, São Paulo No transfer
Transactional email provider, to be confirmed Sending platform emails (alerts, invitations, invoices) Email, name, content of the notice Stated before it is added Stated before it is added
Banco Inter Billing by Pix and boleto (once billing is live) The company's billing data Brazil No transfer
Efí Recurring card billing (once billing is live) The company's billing data Brazil No transfer
Cloudflare Hosting and delivery of this website (www.brightdigitalai.com) Technical connection data, such as IP address and browser Cloudflare's global network, including the United States As described in section 8.2

Meta's messaging charges are billed by Meta directly to the client company. Bright Digital does not handle that payment.

8.2 International transfers

You can ask the DPO for a copy of the safeguards we use.

9. How long we keep data

The periods below are the platform's current settings. They are still under legal and accounting review and may be adjusted. Any change will be published on this page.

9.1 During the contract

Data Period
End customers' conversations and media Set by each client company. Default: 5 years
Raw Meta archive 90 days, then deleted automatically
Meta notifications that could not be linked to any company 30 days, then deleted automatically
Access logs (date, time and IP) 12 months, then deleted automatically. Never less than 6 months, as the Marco Civil requires
Login sessions Deleted automatically when they expire
2FA trusted device 180 days
Account data For as long as the account exists
Support tickets For as long as needed to resolve the request and, after that, for the period required by law or needed to defend our rights
Bright Digital's sales enquiries (website and WhatsApp) For as long as needed to answer and follow up the enquiry and, after that, for the period required by law or needed to defend our rights

9.2 When a company closes its account

  1. Export. The company receives a full copy of its data, in an open format.
  2. Read-only window of 30 days. Staff can still see everything, without changing it, and download the export.

  3. Deletion. When the window ends, we delete the conversations, media, contacts, CRM records and the raw Meta archive from the platform. The company's encryption keys are destroyed, which makes any remaining encrypted copy unreadable.

  4. Backups. Backup copies expire by rotation within 35 days of the deletion.

  5. Certificate. The company receives a deletion certificate, and an addendum when the backups expire.

A company may instruct us in writing to keep its archive longer, for example to meet a legal obligation of its own. In that case we keep it on its behalf and on its instruction.

Data Period Reason
Invoices, tax invoices and payments 5 years counted from 1 January of the year after the transaction, or longer while a tax dispute is open Brazilian Tax Code (CTN) arts. 173 and 195; Civil Code art. 1,194
Contracts, data processing agreement, export records and deletion certificates 10 years after the contract ends Defence of rights; Civil Code art. 205
Security incident records 5 years ANPD Resolution CD/ANPD 15/2024, art. 10
Platform audit log 5 years. Name, email and IP are held separately and deleted sooner, on the access-log period Accountability (LGPD art. 6 X and art. 37)
Records of our support staff's access to company accounts 5 years Accountability and defence of rights
Usage ledger (tokens, costs) About 6 years, with no contact or message identifiers Supporting record for billing
Anonymous usage totals (counts and costs, with no personal data) No limit Not personal data (LGPD art. 12)

Users of the closed company have their account deleted, unless they belong to another company on the platform.

10. Security

A summary of our measures (LGPD arts. 46 to 49; GDPR art. 32):

No system is 100% secure, but we review these measures continuously.

11. Cookies

12. Your rights and how to exercise them

12.1 What they are

Under the LGPD (art. 18) and the GDPR (arts. 15 to 22), you may ask for:

Some data cannot be deleted while the law requires it to be kept (section 9.3). In that case we explain the reason and the period.

12.2 How to exercise them

You are Contact
An end customer of a company that uses Bright Digital AI (you chatted with it on WhatsApp) The company itself, which is the controller of your data. It handles your request and we carry out the technical part on its instruction. If you write to us, we forward the request to the company and let you know.
A user at a client company (you have a login on the platform) Bright Digital, at the DPO's email: privacidade@brightdigitalai.com
Someone who contacted us through the website or Bright Digital's WhatsApp Bright Digital, at the same email

To protect you, we may ask you to confirm your identity before acting, for example by replying from your account's email address.

12.3 Deadlines

There is no charge.

12.4 Complaints

If you are not satisfied, you can complain to the Brazilian National Data Protection Authority (ANPD) at www.gov.br/anpd. If you are in the European Union, you can also complain to the data protection authority of your country.

13. Children and teenagers

Bright Digital AI is a business service and is not intended for children. Platform accounts are for people aged 18 or over only. We do not knowingly collect children's data. If a client company chats with children or teenagers on WhatsApp, it is responsible for meeting the specific rules for that data (LGPD art. 14; GDPR art. 8). If you learn that we have received a child's data improperly, write to the DPO.

14. Changes to this policy

We may update this policy when the service or the law changes. The version date is at the top of the page. Important changes are announced by email to client companies and on the platform, in advance whenever possible.

15. Contact

Back to top