IAatendeIAatendeBack to site
CCPA/CPRA · TCPA · LGPD

Privacy Policy

iaatende.com · businesses and professionals · version of October 7, 2026

In short
  • Your business's customer data belongs to you. We process it only to deliver the service, under your instructions.
  • We do not sell personal information, do not share it for advertising and do not use conversations to train AI.
  • Anyone who replies STOP or SAIR stops receiving messages immediately.
  • You can ask for access, correction or deletion of your data at privacy@iaatende.com.

1.Who we are

iaatende.com is operated by two companies of the same group. Which one is responsible for your data depends on where you contract or use the service:

CompanyWhen it applies
IAatende LLC, a Florida limited liability company, United StatesCustomers, visitors and end consumers in the United States
IAATENDE LTDA, CNPJ 67.083.610/0001-77, Rua Coronel Vigilato Prudente, 11, Jardim das Mangabeiras, Nova Lima/MG, 34.006-180, BrazilCustomers, visitors and end consumers in Brazil

In this policy, "we" means the applicable company. The official address of the service is iaatende.com. We have no relationship with similarly named sites on other domains. Privacy contact: privacy@iaatende.com.

2.Our two roles

We provide artificial intelligence agents that serve the customers of the businesses that hire us. We therefore act in two roles:

SituationWho decides about the dataOur role
You visit the site, talk to Lyra, ask for a quote or subscribeWe do"Business" under the CCPA; controller under the LGPD (art. 5, VI)
You are a customer of a business that uses IAatende and you talk to its agentsThe business that hired the service"Service provider" under the CCPA (Cal. Civ. Code § 1798.140(ag)); processor under the LGPD (art. 5, VII and art. 39)

If you are an end consumer of one of our customers and want to exercise a right over your data, direct your request to the business you contacted. If it reaches us, we forward it to that business and support its response.

3.Data we process

WhoseWhat
Visitors and prospectsName, email, phone or WhatsApp number, business name and trade, language, messages exchanged with Lyra (text and, if you use the microphone, the transcribed audio) and technical access logs (IP address, date, time, browser)
CustomersBusiness and signer details, billing details, last four digits and brand of the card (the full number stays only with the payment processor), agent configuration and support history
End consumers of our customers (as service provider)Name, phone, email, address provided, conversation content, appointments, quotes and service history, depending on the channel used (website chat, SMS, WhatsApp, Instagram, Facebook, email or phone)

We do not ask for sensitive data (health, religion, political opinion, racial origin, biometrics). If someone mentions it in a conversation, we process only what is needed to reply and use it for nothing else.

The service is not directed to anyone under 18, and we do not knowingly collect data from children under 13 (COPPA, 15 U.S.C. §§ 6501 to 6506) or from children and adolescents in Brazil (LGPD, art. 14). If we learn that this happened, we delete the data.

4.Purposes and legal bases

What we use it forLegal basis (LGPD) / business purpose (CCPA)
Reply to your contact and present the quote you asked forSteps prior to a contract (LGPD, art. 7, V); performing services (CCPA § 1798.140(e))
Follow up with people who showed interestLegitimate interest (art. 7, IX), with opt-out at any time
Provide the contracted service, install and run the agentsPerformance of a contract (art. 7, V)
Bill, invoice and meet tax and accounting obligationsLegal obligation (art. 7, II)
Keep website access logs for 6 monthsLegal obligation (art. 7, II; Brazilian Internet Act, Law 12,965/2014, art. 15)
Prevent fraud, abuse and security incidentsLegitimate interest (art. 7, IX); security and integrity (CCPA)
Defend rights in court, administrative or arbitration proceedingsExercise of rights (art. 7, VI)
Serve end consumers on behalf of a customerLegal basis defined by the customer as controller/business

We do not use personal data for purposes incompatible with those disclosed at collection.

5.Artificial intelligence

Lyra and the other agents are artificial intelligence assistants and say so at the start of every conversation. They never pose as humans. When the matter requires it, the conversation is handed to a person on the customer's team with a summary.

No decision with legal or similarly significant effects on you is made solely by automated means. You may ask for human review (LGPD, art. 20).

We do not use conversations to train artificial intelligence models and only contract model providers whose terms prohibit such use. Each customer has its own database, separate from the others.

6.Messaging, SMS, WhatsApp and email

Our agents send messages only within the rules of each channel and each country:

  • SMS in the United States (TCPA, 47 U.S.C. § 227, and FCC rules, 47 C.F.R. § 64.1200): marketing texts only with the recipient's prior express written consent, obtained by our customer; transactional texts (appointment confirmation, requested quote, reminder) only to people who initiated the contact. We respect the 8 a.m. to 9 p.m. window in the recipient's local time and the National Do Not Call Registry. Replying STOP ends messages immediately; HELP returns instructions.
  • Email in the United States (CAN-SPAM Act, 15 U.S.C. § 7701 et seq.): identified sender, truthful subject line, sender's postal address and an unsubscribe link in every commercial message, honored within 10 business days.
  • WhatsApp, Instagram and Facebook: we follow Meta's business messaging policies. Outside the 24-hour window after the customer's last message, we send only approved templates with consent.
  • Brazil: messages only to people who gave their contact to the customer or consented, with an opt-out in every message. Replying SAIR ends messages immediately. We comply with the Consumer Defense Code (Law 8,078/1990) and applicable telemarketing block lists.

Opt-outs are final and logged per channel.

7.Sharing

We do not sell personal information and do not share it for cross-context behavioral advertising, as defined in the CCPA (Cal. Civ. Code § 1798.140(ad) and (ah)). We do not sell or rent data in Brazil either. We share only what is necessary with providers that help us deliver the service, bound by contract and confidentiality:

  • server and database hosting;
  • language processing by artificial intelligence models;
  • SMS, messaging and transactional email delivery;
  • card and Pix payment processing;
  • invoicing and accounting services.

We may also disclose data to public authorities when required by law, court order or a reasoned request from a competent authority, and in a corporate reorganization, with prior notice.

8.International transfers

Our main infrastructure is in the United States. Data of people in Brazil may be transferred to and stored there, under articles 33 to 36 of the LGPD and the standard contractual clauses approved by the Brazilian Data Protection Authority (ANPD Resolution CD/ANPD No. 19/2024). Data of people in the United States stays on servers in the United States, except when an AI model provider temporarily processes conversation text in another region, always under contract.

9.How long we keep data

DataPeriod
Website conversation without a purchaseUp to 12 months after the last contact, or earlier if you ask for deletion
Customer and contract dataDuring the contract and afterwards for the legal tax and limitation periods (up to 7 years for tax records in the United States; up to 5 years in Brazil)
End-consumer data of our customersDuring the contract. At the end, returned to the customer or deleted within 30 days, as instructed (LGPD, art. 16)
Consent and opt-out records5 years, as proof of compliance (TCPA and LGPD)
Website access logs6 months (Brazilian Internet Act, art. 15)

10.Security and incidents

We use encrypted connections (TLS), role-based access, separation of each customer's data, event logging and backups (LGPD, art. 46). No system is fully secure, so we keep an incident response plan.

If a security incident poses a relevant risk or harm, we notify: in the United States, affected individuals and, where required, state authorities within the deadlines of the applicable state law (in Florida, Fla. Stat. § 501.171, within 30 days); in Brazil, the ANPD and data subjects within three business days (LGPD, art. 48, and Resolution CD/ANPD No. 15/2024). When acting as a service provider, we notify the customer without undue delay.

11.Your rights

United States (CCPA/CPRA and state laws)

If you live in California, you have the right to know what personal information we collect and how we use it, to request deletion, correction and portability, and not to be discriminated against for exercising these rights (Cal. Civ. Code §§ 1798.100 to 1798.125). Because we do not sell or share personal information, there is no opt-out to exercise; we nevertheless honor Global Privacy Control signals. Equivalent rights are granted to residents of other states with privacy laws in force (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Maryland and New Jersey), under each law.

We respond within 45 days, extendable by another 45 with notice. We may ask for information to verify your identity. You may use an authorized agent, who must prove the authorization.

Brazil (LGPD, art. 18)

  • confirmation that we process your data and access to it;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion of unnecessary, excessive or unlawfully processed data;
  • portability to another provider;
  • information about whom we share your data with;
  • withdrawal of consent and objection to irregular processing;
  • human review of decisions made solely by automated means (art. 20).

We reply immediately in simplified form, or within 15 days with a complete statement (art. 19). You may also complain to the ANPD.

How to exercise

Write to privacy@iaatende.com. Exercising your rights is free of charge.

12.Cookies

The site uses only what it needs to work (chosen language and conversation session). We use no advertising cookies and no third-party trackers. Fonts are loaded from Google Fonts, which may log your IP address to deliver them.

13.Data protection officer and contact

Anderson Luciano Soares, data protection officer (LGPD, art. 41) and privacy lead for both companies.

Email: privacy@iaatende.com · contact@iaatende.com
IAatende LLC · Florida, United States
IAATENDE LTDA · Rua Coronel Vigilato Prudente, 11, Jardim das Mangabeiras, Nova Lima/MG, 34.006-180, Brazil

14.Changes

We may update this policy. The version in force is always the one published on this page, with the date at the top. Material changes are notified to customers by email in advance. Other language versions are translations; in case of conflict, the English version prevails for IAatende LLC and the Portuguese version for IAATENDE LTDA.