Legal Document

Privacy Policy

Last updated: March 28, 2026  ·  Version 2.0

UNNICA CRM, a customer relationship management platform that integrates WhatsApp, Instagram, and sales automations, takes seriously the privacy of its users. This policy explains, in plain terms, what data we collect, why we collect it, and what we do with it. Please read carefully; for any questions, contact us at the email address listed at the end of this document.

1. Who we are

UNNICA CRM is developed and operated by InovareX Ltda, CNPJ 61.225.347/0001-27, headquartered at Av. Brig. Faria Lima, 1811, Suite 115, Jardim Paulistano, São Paulo/SP, ZIP 01452-001, Brazil. We are responsible for the processing of personal data described in this policy and act as controllers under the LGPD (Brazilian General Data Protection Law, No. 13,709/2018).

2. Data we collect

We collect only what is necessary for the system to function. We divide data into three categories:

Registration data

Name, email address, and phone number provided at registration. Used for authentication, service communication, and support.

Platform operational data

Leads, contacts, deals, tasks, and conversations created or imported by the user within the CRM. This data belongs to the user; UNNICA CRM acts as a processor, not an owner of this information.

Integration data (when authorized)

When the user connects external services (Google Calendar, WhatsApp Business, or Instagram), we collect the minimum data required for each integration, always with explicit authorization.

3. Google integration

Limited Use Disclosure : Google API Services

UNNICA CRM offers an optional integration with Google Calendar. By connecting your Google account, the user authorizes access to the following scopes via OAuth 2.0:

https://www.googleapis.com/auth/calendar.readonly

Read access to Google Calendar events, used exclusively to import appointments as tasks in UNNICA CRM. We read only events from the primary calendar, within a 30-day window from the sync date. We never modify, create, or delete events in Google Calendar.

email and profile

Google account email address and name, used to identify which account is connected to the user's profile in UNNICA CRM.

Limited Use Statement

UNNICA CRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

UNNICA CRM's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • ·Data is used exclusively to provide the Google Calendar synchronization functionality described above.
  • ·We do not transfer Google API data to third parties, except when strictly necessary to provide the functionality requested by the user or when required by law.
  • ·We do not use Google API data to display advertising.
  • ·We do not use Google API data for data mining, AI model training, or any processing unrelated to providing the service to the user.
  • ·Human members of the UNNICA team do not have access to Google Calendar data, except upon explicit request by the user for technical support purposes.

Google access tokens are stored in encrypted form. The user can revoke access at any time by visiting My Google Account > Connected apps and services. After revocation, all tokens are invalidated and removed from our servers within 24 hours.

4. WhatsApp and Instagram integration (Meta)

Meta Platform : WhatsApp Business API and Instagram Messaging API

UNNICA CRM integrates Meta messaging channels through official APIs. Use of these integrations is subject to the Meta Platform Policy and the usage policies of each product.

WhatsApp Business API

Allows sending and receiving text messages, media, and templates via the user's WhatsApp Business number. Conversation data (sent and received messages) is stored in UNNICA CRM's database linked to the corresponding lead, for service history purposes. Bulk messaging occurs exclusively through Meta-approved templates and within the platform's business hours and consent policies.

Instagram Messaging API

Allows receiving and responding to direct messages (DMs), story mentions, and comment activations on posts linked to an Instagram Business account. The permissions used are instagram_manage_messages, instagram_manage_comments and pages_manage_metadata. Instagram does not allow bulk messaging; all Instagram communication occurs within the 24-hour window after user interaction or through response automations configured by the account administrator.

Message data handling

  • ·Messages are stored solely for display in the service history of each lead. We do not analyze message content for commercial or advertising purposes.
  • ·We do not share conversation content with third parties, except when required by a competent authority.
  • ·The user may request deletion of all conversations linked to their account at any time by email.
  • ·Responsibility for compliance with Meta policies, including obtaining recipient consent to receive messages, lies with the operator of the connected account.

5. Integration with Artificial Intelligence Providers

AI Transparency

UNNICA CRM uses third-party Artificial Intelligence models to generate responses, analyze sentiment, qualify leads, transcribe audio, and automate customer service. We operate in multi-provider cascade with automatic failover. Below is the complete and up-to-date list of integrated AI services, in compliance with Google Cloud OAuth Verification and LGPD (Art. 9, transparency about automated processing).

OpenAI (openai.com)

Models used: GPT-4, GPT-4o, and GPT-4o-mini. Used for conversational response generation, intent analysis, and audio transcription (via Whisper). Configured with Zero Data Retention : OpenAI does not use your conversations to train their models.

Privacy policy: openai.com/policies/privacy-policy

Anthropic (anthropic.com)

Models used: Claude Opus and Claude Sonnet. Used for long-text analysis, structured reasoning, and autonomous agents. Configured with Zero Data Retention : Anthropic does not use your conversations to train their models.

Privacy policy: anthropic.com/privacy

Google (Google AI / Gemini)

Models used: Google Gemini (Gemini 2.0 Flash and versions available via Google AI Studio / Vertex AI). Used for fast classification, summaries, and high-volume tasks. Configured with Zero Data Retention : Google does not use your conversations to train their models.

Privacy policy: policies.google.com/privacy

Privacy and security guarantees

  • ·Zero Data Retention (ZDR) enabled with all providers: your conversations are not stored by AI providers after processing.
  • ·We do not use user data to train AI models : neither ours nor the providers'.
  • ·Data Processing Agreements (DPA) signed with all three providers.
  • ·Locally encrypted logs with auditable retention, allowing traceability of each automated decision for up to 6 years (LGPD).
  • ·Users can request at any time (via dpo@unnica.com.br) that their conversations no longer be processed by AI.

Since UNNICA CRM is a multichannel platform with integrated AI, AI processing is an essential component of the service. If you wish to use the system without any AI processing, contact the DPO to configure an account with AI disabled.

6. How we use your data

  • ·Provide the UNNICA CRM service and ensure its correct operation.
  • ·Sync Google Calendar events as tasks within the platform.
  • ·Process and display messages received via WhatsApp and Instagram.
  • ·Send operational notifications related to platform use, with no advertising purposes.
  • ·Provide technical support and customer service.
  • ·Comply with applicable legal obligations.

7. Storage, security, and retention

Data is stored on the infrastructure of Supabase, with encryption in transit (TLS 1.2+) and at rest (AES-256). Third-party tokens (Google OAuth, Meta) are stored encrypted and never exposed in plain text. Role-based access controls (Row Level Security) ensure each user accesses only their organization's data.

Data retention

  • ·Account and platform data, retained while the account is active.
  • ·Google Calendar data, retained while the integration is active; deleted within 24h after disconnection.
  • ·WhatsApp and Instagram conversations, retained while the account is active or until a deletion request.
  • ·After account closure, all data is removed within 30 days, unless legal retention is required.

8. Data sharing

We do not sell, rent, or commercialize personal data. Sharing occurs only in the following situations:

  • ·Essential service providers (hosting, authentication, payment processing), always bound by confidentiality agreements and restricted to the minimum necessary.
  • ·Compliance with legal obligations or court orders, when required by a competent authority.
  • ·Protection of rights, in cases of fraud investigation, misuse, or security breaches.

9. Your rights (LGPD)

In accordance with the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018), you have the following rights over your personal data:

Access

Know what data we store about you.

Correction

Fix incorrect or outdated data.

Deletion

Request the removal of your personal data.

Portability

Receive your data in a structured format.

Withdrawal

Withdraw previously granted consents.

Objection

Object to processing in certain situations.

To exercise any of these rights, send your request to privacidade@unnica.com.br. We respond within 15 business days.

10. Cookies and tracking

UNNICA CRM uses strictly necessary session cookies to maintain the user's authentication state. We do not use third-party tracking cookies, advertising pixels, or behavioral analytics tools.

11. Changes to this policy

This policy may be updated to reflect changes in the service or legislation. Significant changes will be communicated by email with at least 15 days' notice. The last update date is always shown at the top of the document. Continued use after changes implies acceptance of the current version.

12. Contact and data officer

For questions, requests, or to exercise your rights, contact us:

Privacy and LGPD: privacidade@unnica.com.br

General support: contato@unnica.com.br

Ler esta página em português