United States and Brazil
Legal compliance
iaatende.com · version of October 7, 2026
In short
We operate in the United States and Brazil and follow the privacy, messaging and consumer protection laws of both countries. This page shows, rule by rule, what the law requires and how we comply.
1.What we do in practice
- Agents identify themselves as artificial intelligence at the start of every conversation and hand off to a person when the customer asks.
- Marketing messages only with recorded consent. Transactional messages only to people who initiated the contact.
- STOP, SAIR and unsubscribe links on every channel. Requests take effect immediately and are logged.
- SMS in the United States only between 8 a.m. and 9 p.m. in the recipient's local time.
- Each customer's data is kept separate. Nothing is sold or used to train models.
- Named data protection officer and dedicated channel: privacy@iaatende.com.
2.United States
| Rule | What it requires | How we comply |
|---|---|---|
| TCPA (47 U.S.C. § 227) and FCC rules (47 C.F.R. § 64.1200) | Prior express written consent for marketing texts and automated calls; National Do Not Call Registry; 8 a.m. to 9 p.m. window | Consent recorded per contact, immediate STOP, time window enforced by the system, internal block list |
| CAN-SPAM Act (15 U.S.C. § 7701 et seq.) | Truthful sender and subject, postal address, opt-out within 10 business days | Every commercial email carries identification, address and an unsubscribe link honored immediately |
| CCPA/CPRA (Cal. Civ. Code § 1798.100 et seq.) and state privacy laws | Transparency; rights to access, delete, correct and port; service provider contract | Public Privacy Policy, response within 45 days, processor contract with every customer |
| California bot disclosure (Bus. & Prof. Code § 17941) and FTC rules against deception | Do not pose as a human when asked; do not deceive consumers | Agents introduce themselves as AI and never deny it |
| COPPA (15 U.S.C. §§ 6501 to 6506) | No collection from children under 13 without parental consent | Service directed to businesses; minors' data deleted when identified |
| State breach notification laws (e.g., Fla. Stat. § 501.171) | Notify affected individuals within set deadlines | Incident response plan with notice within 30 days |
3.Brazil
| Rule | What it requires | How we comply |
|---|---|---|
| LGPD (Law 13,709/2018) | Legal basis for each processing activity, data subject rights, data protection officer, security, incident notification, international transfer rules | Privacy Policy with legal bases per purpose, named officer, response within 15 days, ANPD standard clauses (Resolution CD/ANPD No. 19/2024), incident notice within 3 business days (Resolution CD/ANPD No. 15/2024) |
| Brazilian Internet Act (Law 12,965/2014) | Access logs kept for 6 months; confidentiality of communications | Logs kept for the legal period and protected |
| Consumer Defense Code (Law 8,078/1990) | Clear information, 7-day withdrawal right for distance contracts, consumer's venue | Terms of Service with no-penalty cancellation, guaranteed withdrawal and consumer venue |
| ANPD rules for small processing agents (Resolution CD/ANPD No. 2/2022) | Simplified rules for small businesses | Applied where available, without reducing data subject rights |
| Meta policies for WhatsApp Business, Instagram and Messenger | Consent, approved templates outside the 24-hour window, opt-out | Approved templates, window respected, immediate SAIR |
4.Reporting channel and contact
Anyone may report an improper message, an agent error or a privacy concern at privacy@iaatende.com. We reply within 5 business days. Authorities may contact the officer, Anderson Luciano Soares, at the same address.
Related documents: Privacy Policy · Terms of Service.