Legal document

Privacy Policy

Version 2026-06-01Last updated: 2026-06-01
This text is a sample and must be reviewed by qualified legal counsel before the v1 launch.

Agentito Privacy Policy

Last updated: June 1, 2026

1. Data controller

Agentito is operated by [Legal entity to be completed] (hereinafter "we" or "Agentito"). Contact: privacy@agentito.io

2. Data we collect

We collect only the data necessary to provide the service:

  • Account data: name, email, country, currency, timezone.
  • Usage data: bot conversations, processed WhatsApp messages, AI agent runs, audit logs.
  • Billing data: managed directly by Stripe or MercadoPago; Agentito does not store card numbers.
  • WhatsApp contact data: E.164 phone number, profile name, conversation history — data of your business's end users.

| Processing | Legal basis | |---|---| | Service provision | Contract (LGPD Art. 7-V / GDPR Art. 6.1.b) | | Billing and accounting | Legal obligation | | Service improvement | Legitimate interest | | Audit log | Legal obligation and legitimate security interest |

4. Data sharing with third parties

We share data with the following trusted providers:

  • Anthropic: language model (Claude) for the AI agent. Data transmitted: conversation content without direct personal identifiers.
  • Meta: WhatsApp Business Cloud API for sending and receiving messages.
  • Stripe / MercadoPago: payment processors. They do not receive contact data.
  • Active integrations: Tiendanube, Shopify, WooCommerce, MercadoLibre, Google Sheets/Calendar. Only receive data that your tools authorize us to share.
  • Neon (Postgres), Vercel, Railway: infrastructure. Data on servers in Brazil / United States.

We do not sell data to third parties.

5. Data retention

  • Account data: while the account is active + 90 days after deletion.
  • WhatsApp messages: 12 months (configurable).
  • Compliance audit logs: indefinite (LGPD / GDPR — legitimate interest basis).

6. Your rights

Under LGPD (Art. 18), GDPR (Arts. 15-22), and Argentine Law 25,326:

  • Access: you can download all data for a contact from the dashboard → Contacts → Privacy → Download data.
  • Rectification: contact us by email.
  • Erasure: you can anonymize all data for a contact from the dashboard → Privacy → Permanently delete.
  • Portability: the ZIP export includes all data in open formats (JSON, CSV).
  • Objection: you can opt out of marketing communications by replying to any of our emails.

7. Security

We apply AES-256 encryption at rest for integration credentials, TLS 1.3 in transit, and Row-Level Security policies in the database. Data from different customers is logically isolated.

8. Data Protection Officer (DPO)

[Name to be designated before launch] — privacy@agentito.io

Formal DPO designation for EU customers will be completed before launch in European markets.

9. Modifications

We will notify you by email at least 15 days before material changes to this policy.

10. Contact

To exercise your rights or make enquiries: privacy@agentito.io