LEGAL
Privacy Policy
What data Zaplin processes, why, with whom and for how long, and how to exercise your rights under the LGPD (Brazil's data protection law).
Last updated: October 2, 2026
Draft pending legal review
This text describes what Zaplin does today and is still being reviewed by a lawyer. It may change before the final version; the date above shows when it last changed.
Who we are
Zaplin is operated by NZK TECNOLOGIA LTDA ("NZK", "we"). This policy covers the zaplin.com.br site, the app at app.zaplin.com.br and the Zaplin API.
For anything about your data, write to contato@zaplin.com.br.
Who decides about each piece of data
The LGPD separates whoever decides about data (the controller) from whoever processes it on someone else's behalf (the processor). Both roles exist in Zaplin:
- Your account and workspace data (name, email, members, subscription): NZK is the controller.
- Your company's contacts' data (the numbers, names, conversations, messages, groups, pipelines, forms and everything your team records about them): the customer company is the controller, and NZK is the processor, handling that data only to provide the service and as the company instructs.
So it is up to the customer company to have a legal basis to talk to its contacts and to answer their requests. If a customer's contact reaches us, we forward the request to the company and help it respond.
Data we process
- Account: name, email, photo and language. If you sign in with Google or Apple, we receive your name, email and photo from them, and keep the tokens they issue for that connection.
- Workspace and team: workspace name, time zone, business hours, members, roles, teams, invitations (with the invited email and the optional message) and when each member was last active.
- Session and security: the IP address and browser (user agent) of each session, and an audit log of the actions taken in the workspace.
- WhatsApp: the connected number and the connection's state; contacts (phone, name, email, tags and custom fields); groups and their participants' phones and names; the text of messages sent and received, files sent through Zaplin, delivery and read status, and the team's internal notes.
- CRM and campaigns: pipelines and their items (title, value, owner, history), reminders, campaigns and their recipients, lists and segments, and the answers to published forms, including the consent checkbox.
- Automations: each run's input and output data, and the events received from integrations such as Stripe and Hotmart (the buyer's name, email and phone, product and amount).
- Artificial intelligence: the AI profiles' instructions, conversations with the Assistant, the files, texts and pages added to Knowledge with their vectors (embeddings), and each call's usage (model, tokens and cost).
- Developers: API keys (we keep only the prefix and a hash), service accounts, OAuth apps and connections (tokens kept only as hashes), webhook endpoints and the delivery history.
- Payment: the Stripe customer id, the plan, the subscription status, add-ons and packs bought. Card details stay with Stripe; we never receive them.
- Site and app usage: pages viewed and usage events, as described under Cookies.
Why we use it and on what legal basis
- Providing the service you contracted (performance of a contract): signing in, connecting numbers, storing and showing conversations, running automations, campaigns, reminders and the AI, and billing the subscription.
- Security and fraud prevention (legitimate interest and legal obligation): sessions, rate limits, the audit log and access records, which the law (Brazil's Marco Civil da Internet) requires us to keep.
- Service emails (performance of a contract): sign-in links, invitations, receipts, billing notices, and the notifications and digests you turn on.
- Improving the product (legitimate interest): usage metrics with no name, email or phone. You can turn off the ones your browser sends in the cookie settings.
- Legal and tax obligations: invoices, payment records and requests from authorities.
We do not sell personal data or use it for advertising.
How Zaplin connects to WhatsApp
Each number is connected by QR code to a WhatsApp Web session kept by a gateway (OpenWA) that NZK runs on its own server. Messages, delivery receipts and the connection's state reach Zaplin through that gateway; to send a file, the gateway receives a temporary link valid for one hour.
Zaplin is not affiliated with WhatsApp or Meta. Messages travel through WhatsApp and are also subject to Meta's terms and privacy policy.
Contacts who reply SAIR, PARAR, STOP or CANCELAR stop receiving the workspace's campaigns, list reminders and automation sends until they reply VOLTAR. Inbox conversations carry on.
Artificial intelligence
The AI features (Run Prompt in automations, the Assistant and Knowledge) use the OpenAI API, in the United States, or another model provider NZK contracts and lists in this policy.
- With Run Prompt, we send the provider the AI profile's instructions, the automation's prompt, the relevant Knowledge excerpts and up to the conversation's last 50 messages.
- With the Assistant, we send your messages and the workspace data its tools read to answer, within your permissions.
- With Knowledge, the content of files, texts and pages is sent to produce the vectors used in search.
The AI acts only where your team sets it up. The Assistant asks for confirmation before risky actions and never reports success before the system confirms it. NZK does not use your data to train models.
Who we share it with
We use providers that process data on our behalf (sub-processors), each only for its part of the service:
- OpenAI: the AI features described above.
- Stripe: payments, subscriptions and the invoice portal.
- Resend: sending the service's emails.
- Cloudflare (R2): file storage and database backups.
- PostHog: site and app usage metrics (events with no name, email or phone, with the originating IP address).
- Google and Apple: only if you choose to sign in with them.
- Server provider: the servers Zaplin, its database and the WhatsApp gateway run on.
We also send data wherever your team tells us to: webhooks, automation HTTP requests, apps connected through OAuth and the API. Those destinations are the customer company's choice.
Beyond that, we share data only when the law or an order from a competent authority requires it.
International transfers
Some providers (such as OpenAI, PostHog, Stripe, Resend and Cloudflare) may process data outside Brazil, mainly in the United States. In those cases the transfer follows what the LGPD allows, such as performing the contract with you and contractual clauses with those providers.
Cookies
We use few cookies, all our own (first-party):
whatsapp_crm.session_token: keeps you signed in to the app. Necessary; lasts 7 days and renews with use.whatsapp_crm.state: protects signing in with Google or Apple. Necessary; lasts a few minutes.whatsapp-crm_ephemeral: holds the workspace name while you create it. Necessary; lasts 15 minutes.analytics_consent: stores your cookie choice. Necessary; lasts 180 days.NEXT_LOCALEandtheme: remember the language and the light or dark theme you chose.ph_whatsapp-crm_ph: identifies the browser anonymously in usage metrics (PostHog). Analytics; lasts up to a year.
Usage metrics start on, and you can turn them off at any time: in the cookie notice, under "Cookies" in the site's footer, or in the app's cookie preferences. If your browser sends the Do Not Track signal, they stay off. We do not record sessions and use no advertising cookies.
How long we keep it
- Messages, files and CRM data: while the workspace exists.
- Raw events received from WhatsApp and integrations: 7 days.
- Full text of AI prompts and responses: 30 days. Usage (model, tokens and cost) stays while the workspace exists.
- Automation run input and output data: 30 days.
- Webhook delivery history: 30 days.
- Audit log: 12 months.
- Email sign-in link: 15 minutes, single use. Invitations: 7 days.
- A workspace cancelled or suspended for non-payment: stays read-only, with export, for 60 days and is then deleted for good, files included. Backups expire on their normal cycle.
- Payment and access records: for as long as the law requires.
Deleting a contact deletes their conversations, messages, files, notes and pipeline items for good. The workspace owner can delete the workspace at any time, and the deletion is immediate and final.
To close your user account, write to contato@zaplin.com.br.
Security
All traffic uses HTTPS. Integration secrets are stored encrypted, API keys and OAuth tokens only as hashes, and the platform's credentials in a secrets vault. Each member sees only what their role and scope allow, actions go to the audit log, and the database is backed up continuously.
No system is infallible. If we learn of an incident that may cause significant risk or harm, we notify those affected and the ANPD as the LGPD requires. If you notice something, write to contato@zaplin.com.br.
Your rights
Under the LGPD, you may ask for:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of data that is unnecessary, excessive or processed unlawfully;
- portability of your data;
- information about whom we share it with;
- review of decisions made solely by automated processing;
- withdrawal of consent, where processing depends on it.
Send your request to contato@zaplin.com.br. We may ask you to confirm your identity first. If you are a contact of a company that uses Zaplin, talk to that company first, as it is the controller of your data; we help it respond.
You may also file a complaint with Brazil's National Data Protection Authority (ANPD).
Children and teenagers
Zaplin is a service for businesses and is not meant for anyone under 18.
Changes to this policy
When Zaplin starts collecting, keeping or sharing data differently, this policy changes with it, with a new date at the top. Significant changes are announced by email or in the app before they take effect. See also the Terms of Service.
Contact
NZK TECNOLOGIA LTDA, responsible for Zaplin. Email: contato@zaplin.com.br. Personal data requests, including to the data protection officer, go to the same address.