Bright Digital AI Privacy Policy
Provisional version, under legal review. Published on 4 October 2026.
On this page
- 1. Who we are
- 2. Quick summary
- 3. Our role: controller or processor
- 4. What data we process
- 5. Why we use data and on what legal basis
- 6. Artificial intelligence
- 7. Who we share data with
- 8. Sub-processors and international transfers
- 9. How long we keep data
- 10. Security
- 11. Cookies
- 12. Your rights and how to exercise them
- 13. Children and teenagers
- 14. Changes to this policy
- 15. Contact
1. Who we are
Bright Digital provides Bright Digital AI, a WhatsApp customer service and sales platform with artificial intelligence (AI) assistants and a CRM. Our clients are companies that use the platform to talk to their own customers.
| Legal name | BRIGHT DIGITAL LTDA |
| CNPJ (Brazilian company number) | 48.420.424/0001-31 |
| Website | www.brightdigitalai.com |
| Contact email | contato@brightdigitalai.com |
| Data Protection Officer (encarregado) | Privacy channel: privacidade@brightdigitalai.com |
| DPO email | privacidade@brightdigitalai.com |
2. Quick summary
-
If your company is a Bright Digital AI client, we look after your account, security and billing data. The conversations with your customers belong to your company: we only process them to provide the service, on your instructions.
-
If you chatted on WhatsApp with a company that uses Bright Digital AI, that company decides about your data. Contact it first. We help the company handle your request.
-
We do not sell personal data. We do not use the conversations of our clients' customers to train AI models or for our own purposes.
-
Data is hosted in Brazil, in São Paulo. Some providers, such as the AI providers, are in other countries. The list is in section 8.
-
You can ask for access, correction, deletion and other rights. We answer within 15 days (LGPD) or within one month (GDPR).
3. Our role: controller or processor
The law distinguishes whoever decides about data (the controller) from whoever processes it on someone else's behalf (the processor, called operador in the LGPD). Bright Digital has both roles, depending on the data.
| Data | Bright Digital's role | Who decides |
|---|---|---|
| Accounts of client companies' users (login, password, two-step verification) | Controller | Bright Digital |
| Billing, invoices and payments | Controller | Bright Digital |
| Platform security and audit logs | Controller | Bright Digital |
| Our website and the enquiries we receive through it | Controller | Bright Digital |
| Bright Digital's own WhatsApp conversations with people interested in the product | Controller | Bright Digital |
| Conversations, media and contacts of each client company's end customers | Processor | The client company |
Where we are the processor, the client company is the controller. It decides what the data is used for, how long it is kept and how the AI assistant behaves. We follow its instructions under the contract and the data processing agreement (LGPD art. 39; GDPR art. 28).
4. What data we process
4.1 Data for which we are the controller
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, mobile number, company, role, language, time zone and display preferences | You or your company's administrator |
| Two-step verification (2FA) | Authenticator app secret, recovery codes (stored in protected form), trusted devices | You, when you turn on 2FA |
| Sessions and security logs | Date and time of access, IP address, browser, login attempts, open sessions | Generated by using the platform |
| Audit logs | Who did what and when: settings changes, invitations, support access | Generated by using the platform |
| Usage and billing | AI usage (tokens, model, cost), messages sent, transcriptions, plan, prices, invoices, payment and tax invoice details | Generated by use and supplied by the company |
| Support | Messages and attachments you send to our support | You |
| Website and sales enquiries | Name, email, mobile number and messages from people who contact us; conversations with Bright Digital on WhatsApp | You |
| Website cookies and analytics | See section 11 | Your browser |
4.2 Data for which we are the processor (on behalf of the client company)
| Category | Examples |
|---|---|
| WhatsApp messages | Text of messages received and sent, captions, shared locations, shared contacts, button replies, reactions, date and time |
| Media | Photos, audio, video, documents and stickers, sent by the end customer or by the company. We store the file when it arrives, because Meta's link expires |
| Contact data | WhatsApp number, WhatsApp profile name, tags, notes and deal data the company records in the CRM |
| Delivery statuses | Sent, delivered, read or failed, with Meta's error codes |
| Raw Meta archive | An exact copy of each technical notification (webhook) Meta sends us. It is used only to recover messages and media after a failure |
| AI processing | Audio transcription, image analysis and replies generated by the AI assistant |
| Alerts | Internal notices for the company's staff, for example "a customer asked for a person". By default an alert carries only the name, the last 4 digits and a link. If the company turns it on, it also carries an excerpt of up to 100 characters of the last message |
The client company decides what data it collects from its customers. We do not ask for sensitive data, but an end customer may volunteer sensitive information in a conversation (LGPD art. 11; GDPR art. 9). It is protected like the rest of the conversation and follows the company's rules.
5. Why we use data and on what legal basis
This table covers data for which we are the controller. For data we process as a processor, the legal basis is set by the client company.
| Purpose | Data | LGPD legal basis (art. 7) | GDPR legal basis (art. 6) |
|---|---|---|---|
| Create and maintain your account, log you in | Account data | Performance of a contract (V) | Contract, 6(1)(b) |
| Protect the account with 2FA and detect improper access | 2FA, sessions, security logs | Performance of a contract (V) and legitimate interest (IX) | Contract, 6(1)(b), and legitimate interest, 6(1)(f) |
| Keep access logs for at least 6 months | Date, time and IP of access | Legal obligation (II): Marco Civil da Internet, art. 15 | Legitimate interest, 6(1)(f) |
| Record actions on the platform and our support staff's access | Audit logs | Legitimate interest (IX) and exercise of rights (VI) | Legitimate interest, 6(1)(f) |
| Measure usage, issue invoices and tax invoices, collect payment | Usage and billing | Performance of a contract (V) and legal obligation (II) | Contract, 6(1)(b), and legal obligation, 6(1)(c) |
| Handle support requests | Support | Performance of a contract (V) | Contract, 6(1)(b) |
| Answer enquiries and present the product | Website and sales enquiries | Pre-contractual steps (V) and legitimate interest (IX) | 6(1)(b) and 6(1)(f) |
| Tell you about service changes, security and incidents | Account email | Performance of a contract (V) and legal obligation (II) | 6(1)(b) and 6(1)(c) |
| Website analytics and marketing | Non-essential cookies | Consent (I) | Consent, 6(1)(a) |
| Defend our rights in proceedings | Contracts, records, invoices | Exercise of rights (VI) | Legitimate interest, 6(1)(f) |
Where we rely on legitimate interest, we first assess whether it respects your rights (LGPD art. 10). You can ask for that assessment by writing to the DPO.
6. Artificial intelligence
-
What the AI does. When a client company turns on an assistant, the conversation's messages are sent to the AI model chosen by the company to generate the reply. Audio is transcribed to text and images may be analysed to understand the request.
-
Who chooses the model. Each company chooses the model for each assistant, from the providers in section 8. The company is told where each model processes data before it chooses.
-
No training. We do not use the conversations of our clients' customers to train AI models. We contract the AI providers on terms that do not allow that use.
-
Disclosure as AI. Each company configures how its assistant introduces itself: as an AI from the start, only when asked, or without mention. The company is responsible for that choice.
-
Automated decisions. The AI helps with customer service and may suggest tags or pipeline stages. Bright Digital does not take decisions with legal effects on you based solely on automated processing. If a client company does so, you may ask it to review the decision (LGPD art. 20; GDPR art. 22).
7. Who we share data with
We do not sell or rent personal data. We share it only:
- with the sub-processors in section 8, to provide the service;
- with the client company, which owns its own conversations and contacts;
- with authorities, when the law or a court order requires it;
- with our accountant, to meet tax obligations (billing data only).
8. Sub-processors and international transfers
8.1 List of sub-processors
This list is kept up to date. Under the contract, we notify client companies before adding a new sub-processor that will process their data. Last updated: 4 October 2026.
| Provider | What it does | Data | Where it processes | Transfer mechanism |
|---|---|---|---|---|
| Meta (WhatsApp Cloud API) | Sends and receives WhatsApp messages | Messages, media, numbers, statuses | United States and other countries | As described in section 8.2 |
| Anthropic | AI models (Claude) | Conversation messages, images | United States | As described in section 8.2 |
| OpenRouter, for DeepSeek models | Routes requests to DeepSeek models, with zero data retention and only providers outside China | Conversation messages | United States and providers outside China | As described in section 8.2 |
| Groq | Audio transcription | Conversation audio | United States | As described in section 8.2 |
| Other AI providers | Additional models, only when a company chooses them | Conversation messages | Stated before they are added | Stated before they are added |
| Cloud provider with servers in Brazil, to be confirmed | Servers, database, files and backups of the platform | All | Brazil, São Paulo | No transfer |
| Transactional email provider, to be confirmed | Sending platform emails (alerts, invitations, invoices) | Email, name, content of the notice | Stated before it is added | Stated before it is added |
| Banco Inter | Billing by Pix and boleto (once billing is live) | The company's billing data | Brazil | No transfer |
| Efí | Recurring card billing (once billing is live) | The company's billing data | Brazil | No transfer |
| Cloudflare | Hosting and delivery of this website (www.brightdigitalai.com) | Technical connection data, such as IP address and browser | Cloudflare's global network, including the United States | As described in section 8.2 |
Meta's messaging charges are billed by Meta directly to the client company. Bright Digital does not handle that payment.
8.2 International transfers
-
From the European Economic Area to Brazil. The European Union has recognised Brazil as providing an adequate level of protection (Commission Implementing Decision (EU) 2026/179, January 2026), and Brazil has recognised the European Union in the same way. European buyers' data can therefore come to our servers in São Paulo without additional clauses (GDPR art. 45).
-
From Brazil to other countries, such as the United States, we use the LGPD mechanisms (art. 33), in particular the standard contractual clauses approved by the ANPD.
-
Data of people in the European Union sent outside Brazil and the EU: we use the European Commission's standard contractual clauses or another valid mechanism (GDPR art. 46), or the provider's certification under the EU-US Data Privacy Framework where it exists.
You can ask the DPO for a copy of the safeguards we use.
9. How long we keep data
The periods below are the platform's current settings. They are still under legal and accounting review and may be adjusted. Any change will be published on this page.
9.1 During the contract
| Data | Period |
|---|---|
| End customers' conversations and media | Set by each client company. Default: 5 years |
| Raw Meta archive | 90 days, then deleted automatically |
| Meta notifications that could not be linked to any company | 30 days, then deleted automatically |
| Access logs (date, time and IP) | 12 months, then deleted automatically. Never less than 6 months, as the Marco Civil requires |
| Login sessions | Deleted automatically when they expire |
| 2FA trusted device | 180 days |
| Account data | For as long as the account exists |
| Support tickets | For as long as needed to resolve the request and, after that, for the period required by law or needed to defend our rights |
| Bright Digital's sales enquiries (website and WhatsApp) | For as long as needed to answer and follow up the enquiry and, after that, for the period required by law or needed to defend our rights |
9.2 When a company closes its account
- Export. The company receives a full copy of its data, in an open format.
-
Read-only window of 30 days. Staff can still see everything, without changing it, and download the export.
-
Deletion. When the window ends, we delete the conversations, media, contacts, CRM records and the raw Meta archive from the platform. The company's encryption keys are destroyed, which makes any remaining encrypted copy unreadable.
-
Backups. Backup copies expire by rotation within 35 days of the deletion.
- Certificate. The company receives a deletion certificate, and an addendum when the backups expire.
A company may instruct us in writing to keep its archive longer, for example to meet a legal obligation of its own. In that case we keep it on its behalf and on its instruction.
9.3 What Bright Digital keeps after closure, by legal obligation or for defence
| Data | Period | Reason |
|---|---|---|
| Invoices, tax invoices and payments | 5 years counted from 1 January of the year after the transaction, or longer while a tax dispute is open | Brazilian Tax Code (CTN) arts. 173 and 195; Civil Code art. 1,194 |
| Contracts, data processing agreement, export records and deletion certificates | 10 years after the contract ends | Defence of rights; Civil Code art. 205 |
| Security incident records | 5 years | ANPD Resolution CD/ANPD 15/2024, art. 10 |
| Platform audit log | 5 years. Name, email and IP are held separately and deleted sooner, on the access-log period | Accountability (LGPD art. 6 X and art. 37) |
| Records of our support staff's access to company accounts | 5 years | Accountability and defence of rights |
| Usage ledger (tokens, costs) | About 6 years, with no contact or message identifiers | Supporting record for billing |
| Anonymous usage totals (counts and costs, with no personal data) | No limit | Not personal data (LGPD art. 12) |
Users of the closed company have their account deleted, unless they belong to another company on the platform.
10. Security
A summary of our measures (LGPD arts. 46 to 49; GDPR art. 32):
-
Isolation between companies. Each company sees only its own data. Isolation is enforced in the database as well as in the application, and is tested automatically on every change to the system.
-
Encryption. Connections protected by HTTPS. Credentials and sensitive files encrypted with a separate key for each company. Encrypted backups.
-
Two-step verification (2FA), mandatory for administrators and available to everyone.
- Audit logs that cannot be altered once written.
-
Our staff's access. Only authorised Bright Digital staff can enter a company's account, through time-limited support access with a recorded reason, audited. The company can see that access.
-
Private media, served only through temporary links.
- Incidents. If an incident may cause significant risk or harm, we notify the ANPD and the data subjects where the law requires it, and we notify affected client companies without undue delay so they can meet their own obligations.
No system is 100% secure, but we review these measures continuously.
11. Cookies
-
Essential cookies. The platform uses cookies needed to log you in, keep your session, remember a trusted device and protect forms against fraud. The platform does not work without them, so they do not require consent.
-
Analytics and marketing. We do not use analytics or advertising cookies. If we ever do, we will ask for your consent first, and you can change your choice at any time.
- This website. www.brightdigitalai.com uses no cookies and no tracking tools. It is hosted by Cloudflare, which processes technical connection data, such as your IP address, to deliver the pages securely.
12. Your rights and how to exercise them
12.1 What they are
Under the LGPD (art. 18) and the GDPR (arts. 15 to 22), you may ask for:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or out-of-date data;
- anonymisation, blocking or deletion of data that is unnecessary or processed unlawfully;
- portability of your data;
- deletion of data processed on the basis of your consent;
- information on who we share data with;
- information on the option not to consent and its consequences;
- withdrawal of consent;
- objection to processing, including processing based on legitimate interest;
- restriction of processing (GDPR);
- review of decisions taken solely by automated processing.
Some data cannot be deleted while the law requires it to be kept (section 9.3). In that case we explain the reason and the period.
12.2 How to exercise them
| You are | Contact |
|---|---|
| An end customer of a company that uses Bright Digital AI (you chatted with it on WhatsApp) | The company itself, which is the controller of your data. It handles your request and we carry out the technical part on its instruction. If you write to us, we forward the request to the company and let you know. |
| A user at a client company (you have a login on the platform) | Bright Digital, at the DPO's email: privacidade@brightdigitalai.com |
| Someone who contacted us through the website or Bright Digital's WhatsApp | Bright Digital, at the same email |
To protect you, we may ask you to confirm your identity before acting, for example by replying from your account's email address.
12.3 Deadlines
-
LGPD: we confirm immediately in simplified form, and send the full answer within 15 days of the request (art. 19).
-
GDPR: we answer within one month. For complex requests, this may be extended by two further months, with notice and reasons within the first month (art. 12(3)).
There is no charge.
12.4 Complaints
If you are not satisfied, you can complain to the Brazilian National Data Protection Authority (ANPD) at www.gov.br/anpd. If you are in the European Union, you can also complain to the data protection authority of your country.
13. Children and teenagers
Bright Digital AI is a business service and is not intended for children. Platform accounts are for people aged 18 or over only. We do not knowingly collect children's data. If a client company chats with children or teenagers on WhatsApp, it is responsible for meeting the specific rules for that data (LGPD art. 14; GDPR art. 8). If you learn that we have received a child's data improperly, write to the DPO.
14. Changes to this policy
We may update this policy when the service or the law changes. The version date is at the top of the page. Important changes are announced by email to client companies and on the platform, in advance whenever possible.
15. Contact
- Data Protection Officer: privacidade@brightdigitalai.com
- General contact: contato@brightdigitalai.com
- Data deletion instructions: www.brightdigitalai.com/en/data-deletion