1. About us
Z·Apply is a SaaS platform for customer service over WhatsApp and Instagram with artificial intelligence, CRM, unified inbox, scheduling and external integrations. The service is operated in Brazil and serves companies that need to organize customer service, lead capture and scheduling operations in a multi-tenant environment.
Data controller: 51425442 LEANDRO ROBERTO DA SILVA, registered under CNPJ 51.425.442/0001-10, headquartered at Rua Panamá, 131 — Bairro Casa Branca, Santo André/SP, CEP 09015-680.
Data Protection Officer (DPO): Leandro Roberto da Silva — privacidade@z-apply.com.
2. Data we collect
We may process the following categories of data, depending on platform usage:
Registration data
- Name, email, phone number, company name and tax ID (CNPJ), when provided.
Operational data
- WhatsApp and Instagram conversations processed by the platform.
- Captured leads, appointments, internal notes and interaction history.
Usage data
- Access logs, pages visited within the dashboard, IP address and browser type.
Data from external integrations
-
Google Calendar: when you connect your Google account, we access
authorized calendar event data to synchronize appointments and check availability. This
may include event title, date, time and participants. We use the scopes
https://www.googleapis.com/auth/calendar,https://www.googleapis.com/auth/calendar.eventsandhttps://www.googleapis.com/auth/userinfo.email(to identify the connected account). - WhatsApp / Instagram Messaging: messages received and sent through the connected number or account, and conversation metadata. What Meta sends us and what we do with it is detailed in the Instagram and Meta section.
- Telegram and Mercado Livre: when a business connects these channels, we receive the messages and questions sent to it through them.
Payment data
- In the current product state, Z·Apply does not process payments between the customer company and its end customers and does not store credit card data.
3. How we use the data
- Provide the contracted service, including customer service, CRM, scheduling, reports and dashboard operations.
- Synchronize appointments with Google Calendar when the integration is active.
- Send operational notifications, such as lead alerts, handoffs and status changes.
- Improve the product based on aggregated and anonymized usage data.
- Comply with legal, regulatory and security obligations.
4. Google Calendar — Limited Use
Specifically, Z·Apply:
- Only accesses Google Calendar data to create, update and remove appointment events originated in Z·Apply, and to check time availability (busy periods).
- Does not use Google Calendar data for advertising, marketing or sale to third parties.
- Does not share Google Calendar data with third parties, except as necessary to provide the service (e.g., infrastructure provider) or when required by law.
- Does not use Google Calendar data to train artificial intelligence or machine learning models, our own or third-party.
- Does not allow humans to read Google Calendar data, except: (a) with the user's explicit consent; (b) for security purposes; (c) to comply with legal obligations; or (d) for necessary internal operations using aggregated/anonymized data.
- Stores Google access tokens encrypted and per-company, with multi-tenant isolation.
- Allows the user to revoke access at any time, directly in the Z·Apply dashboard (Settings → Google Calendar → Disconnect) or in the Google account security settings.
5. Instagram and Meta — use of Platform Data
What we receive from Meta
- The identifier of the connected professional account and the profile
@handle. - The access token issued by Meta, stored encrypted, isolated per company and revoked when the integration is disconnected.
- Direct messages received and sent through the connected account, with the identifier Meta assigns to the sender, the display name and the timestamp.
Permissions we request
instagram_business_basic— identify the professional account being connected.instagram_business_manage_messages— read and reply to that account's direct messages.
We do not request publishing, advertising, audience insights or feed reading permissions.
What Z·Apply does NOT do with this data
- Does not sell, rent or transfer data obtained through Instagram.
- Does not use this data for advertising, ad targeting or building marketing profiles.
- Does not use conversation content to train artificial intelligence models, our own or third-party.
- Does not publish, like, follow or interact on behalf of the account holder.
- Does not allow Z·Apply staff to read conversations, except: (a) at the customer's own request, during support; (b) to investigate a security incident; or (c) under legal obligation.
- Does not combine this data with data from other customer companies — the isolation between businesses applies here too.
Processing by artificial intelligence
When automated service is enabled, the message content and the contact's context are sent to our language model provider to generate the reply. This is described in detail in the International data transfer section, and the provider is contractually barred from using that content to train models.
Deletion
You can request deletion at any time — including by removing Z·Apply from your Instagram settings, which notifies us automatically. Step-by-step instructions are available at User Data Deletion.
6. International data transfer
To provide the service, some processors acting on our behalf may process information outside Brazilian territory, always observing Article 33 of the LGPD. The relevant flows are:
- OpenAI (language model): receives the end customer's message content and the context needed to reply — the recent conversation history and, where they exist, the contact's name, tags, internal notes, past appointments and summaries of previous conversations. Processing takes place in the United States. It is the only model provider in use; should we ever adopt another, this policy will be updated beforehand.
- Meta Platforms (Instagram Messaging): global processing of message delivery, with servers in the United States, Ireland and other countries.
- Google (Calendar): global processing of calendar events through Google APIs.
- Infrastructure provider (Cloudflare, hosting): CDN and edge protection with global presence; persisted content is stored in Brazil.
The transfer is based on the performance of the contract with the customer company (Art. 33, V and VI). We maintain contractual clauses with each processor requiring a protection standard compatible with the LGPD. The complete and current list of processors and sub-processors can be requested through the privacy channel at the end of this page.
7. Storage and security
- The service is operated in Brazil and uses contracted infrastructure compatible with the product's operation.
- Credentials, OAuth tokens and other sensitive secrets are protected by encryption at rest (AES via Django EncryptedField) and isolated per company.
- Multi-tenant isolation: each company can only access its own data.
- Dashboard access is controlled by role (RBAC), with roles such as administrator, manager and collaborator.
- Backup and continuity routines are executed according to the environment's operation.
- All connections to the service use HTTPS / TLS.
- OAuth states are cryptographically signed (Django signing) with expiration to mitigate CSRF.
8. Data sharing
- We do not sell personal data.
- We share data only with (a) hosting infrastructure providers; (b) integration services configured by the user (Google, Meta/Instagram, Telegram, Mercado Livre); (c) the language model provider that generates automated replies; (d) when required by court order or competent legal authority.
- WhatsApp message transport: some businesses use a third-party transport service, which necessarily sees the messages passing through it. For the others, transport runs on Z·Apply's own server, with no intermediary. You may ask our privacy channel which case applies to the business you talked to.
- Technical monitoring: error and performance records go to observability tooling, without message content and with automatic disposal after 30 days.
- Each customer company accesses only its own data — there is no cross-tenant reading.
9. Data retention
- Conversations, contacts and appointments are kept while the business account is active and as long as they are necessary to provide the service.
- After cancellation, data may be retained for up to 90 days for possible reactivation and, after that period, is permanently deleted by an automated routine that runs daily.
- Files sent in conversations (photo, audio, video, document) are not stored by us: we keep only the channel's source address, and the file is streamed on demand.
- Google OAuth tokens are immediately revoked when the integration is disconnected from the dashboard; the same applies to the Instagram token.
- Early deletion can be requested at any time — see User Data Deletion — subject to applicable legal and technical obligations.
10. Data subject rights
Under Brazil's LGPD (Law No. 13,709/2018), and where applicable equivalent rights under the GDPR, the data subject may request:
- Confirmation of the existence of data processing.
- Access to their data.
- Correction of incomplete, inaccurate or outdated data.
- Anonymization, blocking or elimination of unnecessary or non-compliant data.
- Data portability.
- Deletion of personal data processed under consent.
- Information about public and private entities with which data was shared.
- Revocation of consent, when that is the applicable legal basis.
To exercise any of these rights, use our public form: Data Subject Request (in Portuguese). If what you want is to erase your data, the full path is described at User Data Deletion. You can also write to our DPO at privacidade@z-apply.com. We respond within 15 business days from the receipt of the request (LGPD, Art. 19).
11. Cookies
The site uses technical session cookies for authentication, dashboard operation and user experience maintenance. We may also use aggregated site usage measurement (analytics) for operational stability and product improvements.
We do not use third-party advertising tracking cookies.
12. Changes to this policy
This policy may be updated periodically. Relevant changes may be communicated by email, notice in the dashboard or by other appropriate means. The date in the header of this document reflects the current version, and previous versions can be requested through the privacy channel.
13. Contact
For general product questions: contato@z-apply.com.
For privacy questions, information security, exercise of LGPD/GDPR rights or contact with the Data Protection Officer: privacidade@z-apply.com.