IAatendeIAatendeBack to site
United States and Brazil

Legal compliance

iaatende.com · version of October 7, 2026

In short

We operate in the United States and Brazil and follow the privacy, messaging and consumer protection laws of both countries. This page shows, rule by rule, what the law requires and how we comply.

1.What we do in practice

  • Agents identify themselves as artificial intelligence at the start of every conversation and hand off to a person when the customer asks.
  • Marketing messages only with recorded consent. Transactional messages only to people who initiated the contact.
  • STOP, SAIR and unsubscribe links on every channel. Requests take effect immediately and are logged.
  • SMS in the United States only between 8 a.m. and 9 p.m. in the recipient's local time.
  • Each customer's data is kept separate. Nothing is sold or used to train models.
  • Named data protection officer and dedicated channel: privacy@iaatende.com.

2.United States

RuleWhat it requiresHow we comply
TCPA (47 U.S.C. § 227) and FCC rules (47 C.F.R. § 64.1200)Prior express written consent for marketing texts and automated calls; National Do Not Call Registry; 8 a.m. to 9 p.m. windowConsent recorded per contact, immediate STOP, time window enforced by the system, internal block list
CAN-SPAM Act (15 U.S.C. § 7701 et seq.)Truthful sender and subject, postal address, opt-out within 10 business daysEvery commercial email carries identification, address and an unsubscribe link honored immediately
CCPA/CPRA (Cal. Civ. Code § 1798.100 et seq.) and state privacy lawsTransparency; rights to access, delete, correct and port; service provider contractPublic Privacy Policy, response within 45 days, processor contract with every customer
California bot disclosure (Bus. & Prof. Code § 17941) and FTC rules against deceptionDo not pose as a human when asked; do not deceive consumersAgents introduce themselves as AI and never deny it
COPPA (15 U.S.C. §§ 6501 to 6506)No collection from children under 13 without parental consentService directed to businesses; minors' data deleted when identified
State breach notification laws (e.g., Fla. Stat. § 501.171)Notify affected individuals within set deadlinesIncident response plan with notice within 30 days

3.Brazil

RuleWhat it requiresHow we comply
LGPD (Law 13,709/2018)Legal basis for each processing activity, data subject rights, data protection officer, security, incident notification, international transfer rulesPrivacy Policy with legal bases per purpose, named officer, response within 15 days, ANPD standard clauses (Resolution CD/ANPD No. 19/2024), incident notice within 3 business days (Resolution CD/ANPD No. 15/2024)
Brazilian Internet Act (Law 12,965/2014)Access logs kept for 6 months; confidentiality of communicationsLogs kept for the legal period and protected
Consumer Defense Code (Law 8,078/1990)Clear information, 7-day withdrawal right for distance contracts, consumer's venueTerms of Service with no-penalty cancellation, guaranteed withdrawal and consumer venue
ANPD rules for small processing agents (Resolution CD/ANPD No. 2/2022)Simplified rules for small businessesApplied where available, without reducing data subject rights
Meta policies for WhatsApp Business, Instagram and MessengerConsent, approved templates outside the 24-hour window, opt-outApproved templates, window respected, immediate SAIR

4.Reporting channel and contact

Anyone may report an improper message, an agent error or a privacy concern at privacy@iaatende.com. We reply within 5 business days. Authorities may contact the officer, Anderson Luciano Soares, at the same address.

Related documents: Privacy Policy · Terms of Service.