01Who is responsible for the processing
When it decides the purposes and means of processing, the controller is:
- Legal entity
- Cloud Global Technology (CGT)
- CNPJ
- 63.633.156/0001-20
- Address
- Avenida Brigadeiro Faria Lima, 1811, ESC 1119, Jardim Paulistano, São Paulo/SP, CEP 01452-001, Brazil
CGT may act in different roles depending on the context:
- Controller: when it processes data to run its website, answer enquiries addressed to CGT itself, negotiate and deliver its services, administer its own accounts and applications, or meet its own obligations.
- Processor: when it processes data on behalf of a business client and under that client instructions, for example when hosting or administering support channels, technical support, messaging integrations or IT environments. In that case the client is normally the controller and defines the applicable purposes, legal bases and retention periods.
- Meta and other providers: Meta Platforms, WhatsApp and other platforms process certain data under their own rules and policies. This Policy does not replace those third-party policies.
Where a request relates to data controlled by a CGT client, we may forward it to the responsible client and provide the support needed to handle it.
02Scope
This Policy applies to:
- trycgt.com and associated pages operated by CGT;
- forms, email, phone, WhatsApp and other CGT commercial channels;
- CGT business pages, profiles and accounts on Facebook and Instagram;
- conversations received through WhatsApp Business, Messenger and Instagram Direct;
- CGT applications and integrations registered on the Meta for Developers platform;
- managed IT, co-managed IT, support, cloud, security, backup, automation and integration services delivered by CGT;
- portals, systems and operational tools provided or administered by CGT, where this Policy is referenced in those environments.
This Policy does not govern processing carried out independently by CGT clients, Meta, Microsoft, Google or other third parties. Please also consult those controllers policies when using their products.
03Personal data we may process
The data actually processed depends on the relationship and on the feature in use.
3.1. Website and commercial enquiries
We may process:
- name, job title, company and country;
- email, phone and contact identifiers;
- the content of the request, technical needs and support history;
- data needed to prepare a proposal, contract and invoice;
- IP address, date and time of access, browser, device, page visited and technical security records;
- local preferences for language, theme and dismissal of notices stored in the browser.
3.2. WhatsApp, Facebook, Messenger, Instagram and Meta applications
Depending on the channel used, the permissions granted and the feature enabled, we may receive:
- identifiers supplied by the platform, such as identifiers linked to a page, account, Instagram, WhatsApp Business Account or app;
- public name, username, profile picture and public information made available by the platform;
- phone number and WhatsApp display name, where available;
- messages, comments, replies, mentions and other interactions initiated or authorised by the user;
- images, audio, video, documents and other attachments sent in the conversation;
- date, time, origin, send, delivery and read status, and other interaction metadata;
- data from pages, professional profiles, business accounts and commercial assets that the administrator authorises the application to access;
- content and metrics needed to publish, reply, moderate or measure interactions, where that feature is expressly enabled;
- technical authentication, authorisation, webhook and audit data needed to keep the integration secure.
The exact data category depends on the products and permissions approved by Meta for each application. CGT limits processing to the minimum necessary for the requested feature.
We do not ask for Facebook, Instagram or WhatsApp passwords. Tokens, keys and technical credentials are protected and must not be sent by message or email.
3.3. Delivery of IT services
In the relationship with business clients, we may process data about representatives, administrators and end users, such as:
- professional identification and corporate contact details;
- job title, team, location, manager and relationship with the organisation;
- accounts, permissions, licences, devices and IT assets;
- tickets, messages, support records and technical evidence;
- access, security, availability and operation execution logs;
- information needed for user onboarding, changes and offboarding;
- documents and data supplied by the client within the contracted scope.
Where CGT acts as processor, the controlling client is responsible for defining which data may be processed and for ensuring an adequate legal basis.
3.4. Sensitive personal data
CGT services are not generally intended to collect sensitive personal data. However, a person may spontaneously include sensitive information in a message, or a client in sectors such as healthcare may engage CGT to operate an environment containing such data.
In those situations processing will be limited to what is necessary, will observe the grounds in article 11 of the LGPD and, where CGT is a processor, will follow the instructions and responsibilities of the controlling client. Legitimate interest will not be used as a legal basis for sensitive personal data.
04How we obtain the data
We may obtain data:
- directly from the data subject, when they get in touch or use a service;
- from client companies and their authorised representatives;
- from Meta, WhatsApp, Facebook, Instagram, Messenger and other integrated platforms;
- from identity, cloud, security and collaboration providers authorised by the client;
- automatically, through technical records needed for operation and security;
- from legitimate public sources, where needed for business contact and consistent with the data subject expectations.
05Purposes of processing
We may process data to:
- receive, organise, route and answer enquiries;
- run a commercial assessment, prepare proposals and take pre-contractual steps;
- perform contracts and deliver IT support and services;
- maintain support history and continuity;
- integrate WhatsApp, Messenger, Facebook and Instagram with support and automation systems;
- publish, reply, moderate or measure content where the account administrator enables those functions;
- administer contracted accounts, permissions, devices, systems and infrastructure;
- authenticate users and prevent fraud, abuse and unauthorised access;
- monitor availability, security and technical performance;
- meet legal, regulatory and tax obligations and valid orders from authorities;
- exercise rights in administrative, arbitration or court proceedings;
- improve processes and services using aggregated or anonymised data;
- send commercial communications where there is a legal basis, allowing objection or unsubscribe.
CGT does not sell personal data and does not use data received from Meta platforms for third-party behavioural advertising.
06Legal bases
Depending on the purpose, CGT may rely on the following LGPD bases:
- preliminary procedures and performance of a contract (art. 7, V);
- compliance with a legal or regulatory obligation (art. 7, II);
- regular exercise of rights (art. 7, VI);
- legitimate interest of CGT, of clients or of third parties, following an assessment of purpose, necessity, expectation and safeguards (art. 7, IX);
- consent, where that is the appropriate basis, with the possibility of withdrawal (art. 7, I);
- other grounds set out in the LGPD where applicable to the specific case.
Where CGT acts as processor, defining the legal basis is the responsibility of the controlling client, without prejudice to CGT own duties.
07Data sharing and processors
We may share data, to the extent necessary, with:
- the business client responsible for the channel, system or support desk;
- Meta Platforms, WhatsApp, Facebook, Messenger and Instagram;
- Chatwoot and the managed infrastructure used for conversation management;
- hosting, cloud computing, CDN, email, security, backup and monitoring providers;
- Microsoft, Google and other providers authorised within the client environment;
- professional consultants, accountants, auditors and legal advisers bound by confidentiality duties;
- public authorities, where there is a legal obligation, a valid order or a need to protect rights.
Providers are selected according to the purpose of the service and must receive only the necessary data. Wherever applicable, CGT puts in place contracts, instructions, access controls and other safeguards for processing by processors and sub-processors.
The data subject may request information about the entities with which their data has been shared.
08International transfers
Some technology providers operate infrastructure or teams in other countries. Data may therefore be stored, accessed or processed outside Brazil.
Where an international transfer is subject to the LGPD, CGT will adopt a valid mechanism under articles 33 to 36 of the LGPD and ANPD Resolution 19/2024, such as standard contractual clauses, an adequacy decision or another applicable legal ground. Transfers will be limited to the minimum necessary and subject to security and transparency measures.
09Data retention
Data is kept for as long as necessary to fulfil the purposes described in this Policy and the applicable legal, contractual and rights-defence periods.
As general criteria:
- commercial contacts are kept while there is a negotiation, a relationship or a legitimate expectation of continuity;
- client and service data is kept during the contract and for the period needed to meet obligations or defend rights;
- conversations administered for clients follow the contract, the instructions and the retention policy of the controlling client;
- technical and access records may be kept for the periods required by law, including where the Marco Civil da Internet applies;
- data subject to a deletion request will be erased or anonymised, unless there is a legal obligation or authorisation to retain it;
- residual copies may remain temporarily in protected backups until the normal replacement cycle, without use for new purposes.
Specific periods may vary by service. The data subject may request information about the criterion applicable to their case.
10Data subject rights
Under the LGPD, the data subject may request, where applicable:
- confirmation that processing exists;
- access to the personal data;
- correction of incomplete, inaccurate or out-of-date data;
- anonymisation, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law;
- portability, subject to commercial and industrial secrecy and the applicable regulation;
- deletion of data processed on the basis of consent, save for the legal grounds for retention;
- information about data sharing;
- information about the possibility of withholding consent and the consequences of doing so;
- withdrawal of consent;
- objection to processing carried out in breach of the LGPD;
- review of decisions taken solely on the basis of automated processing that affect their interests;
- to petition the National Data Protection Authority (ANPD) and consumer protection bodies.
To protect the data subject and third parties, CGT may request reasonable information to confirm identity and locate the data. Confirmation and simplified access will be handled within the statutory periods; full requests will be answered under the terms of the LGPD.
11Data deletion and instructions for Meta users
This section may be used as the public data deletion instruction for CGT applications integrated with Facebook, Instagram, Messenger and WhatsApp.
How to request it
- 1
Send an email to info@trycgt.com with the subject “Data deletion — Meta”.
- 2
State the platform involved: WhatsApp, Facebook, Messenger or Instagram.
- 3
State the name of the CGT app or channel used, if you know it.
- 4
Provide the profile name, phone number or another identifier sufficient to locate the interaction. Do not send a password, authentication code, token or sensitive document in the first contact.
- 5
CGT may ask for additional identity confirmation and will provide the case reference and the outcome of the request.
Where CGT is the controller, it will delete or anonymise the applicable data, unless retention is necessary to meet a legal obligation, perform a contract, prevent fraud, exercise rights or meet another ground set out in the LGPD.
Where CGT acts as processor for a business client, it will forward the request to the controlling client or direct the data subject to the correct channel, and will provide technical support for handling it.
Removing an application authorisation in Facebook or Instagram settings stops future access under Meta rules, but may not automatically delete records that must be handled by CGT or by the controlling client. The request above allows those records to be located and assessed.
CGT will seek to complete the operational deletion step within 30 days, unless validation is needed, a retention obligation applies or there is justified complexity. Statutory rights and deadlines prevail.
12Cookies, local storage and similar technologies
As at the date of this version, the CGT corporate website does not use advertising cookies, behavioural profiling or third-party tracking. The site uses strictly necessary local storage to remember language, theme, dismissal of notices and interface preferences.
Hosting and security providers may process IP addresses and technical records needed to serve, protect and diagnose the service.
If CGT begins to use analytics, pixels, advertising or non-essential cookies, this Policy and the preferences mechanism will be updated before activation, with transparency and consent where required.
13Security and incidents
CGT adopts technical and administrative measures proportionate to the risks, which may include:
- access control and least-privilege principle;
- authentication, credential management and environment segregation;
- encryption in transit and, where applicable, at rest;
- monitoring, audit logging, backups and system updates;
- confidentiality obligations and supplier management;
- incident response, containment and investigation procedures.
No system is entirely immune to risk. Where CGT acts as controller and an incident may cause relevant risk or harm, it will make the notifications required to the ANPD and to data subjects within the periods and conditions of ANPD Resolution 15/2024. Where it acts as processor, it will notify the controlling client and provide the cooperation set out in the contract and in law.
14Children and adolescents
The CGT website and commercial services are aimed at businesses and are not directed at children.
However, clients in sectors such as healthcare may use systems administered by CGT to serve guardians or minors. In those cases the controlling client must ensure the best interest, the legal basis and the applicable authorisations, and CGT will process the data as processor under their instructions and the relevant safeguards.
If CGT identifies improper direct collection of a child data on its own channel, it will take steps to restrict or delete the processing.
15Automated decisions and artificial intelligence
As at the date of this version, CGT does not use the data covered by this Policy to take decisions based solely on automated processing that produce legal effects or significantly affect the data subject.
Automation may be used to classify, route, record or prioritise requests, always with the possibility of human review where necessary. If that scenario changes materially, this Policy will be updated and the rights set out in the LGPD will be preserved.
16User and client responsibilities
Users should avoid sending passwords, tokens, authentication codes, financial data or sensitive data that is not necessary for the enquiry.
Clients using integrations operated by CGT are responsible for:
- using the services lawfully and transparently;
- obtaining authorisations and defining legal bases when acting as controllers;
- limiting access for their own teams;
- configuring retention and permissions consistent with their needs;
- notifying CGT of data subject requests and incidents related to the service;
- not instructing CGT to carry out processing contrary to the law or to platform rules.
17Changes to this Policy
This Policy may be updated to reflect legal, operational or technological changes, or changes in application features. The version in force will state the date it was last updated.
Material changes may be communicated through appropriate channels. Continued use of the services will be subject to the version in force, without prejudice to specific consent where required.
18Contact and complaints
For questions, rights requests or privacy complaints:
- Company
- Cloud Global Technology (CGT)
- Address
- Avenida Brigadeiro Faria Lima, 1811, ESC 1119, Jardim Paulistano, São Paulo/SP, CEP 01452-001, Brazil
If the response is not satisfactory, the data subject may petition the National Data Protection Authority (ANPD) and, where applicable, consumer protection bodies.