Data protection

GeZap and the LGPD

Last updated: July 4, 2026

GeZap treats Brazil's LGPD (General Data Protection Law) as part of the product, not paperwork. This page explains our role in processing personal data, your rights as a data subject, and the security and privacy measures we adopt.

1. Our role: processor, not controller

The business that contracts GeZap (the clinic, salon, or office) is the controller of its own clients' data: it decides what happens with that data. GeZap acts as a processor: we handle personal data only per the instructions and settings defined by the contracting business, to enable scheduling, service delivery, and communication.

If you're a client of a business that uses GeZap, your data is that business's responsibility. GeZap provides the technology, infrastructure, and security measures for that processing to be done properly.

2. Data subject rights

  • Confirmation that your data is being processed.
  • Access to the personal data we hold about you.
  • Correction of incomplete, inaccurate, or outdated data.
  • Anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data.
  • Portability of your data to another service provider.
  • Deletion of data processed based on your consent.
  • Information about who we share your data with.
  • Information about the option not to give consent and the consequences of that choice.
  • Withdrawal of consent, at any time.
  • Review of decisions made solely through automated processing.

To exercise any of these rights, contact our data protection officer at privacy@gezap.com.br. If your request involves social login data (Google, Facebook), also see the Social Data Exclusion page.

  • Contract performance, to provide the service contracted by the business you deal with.
  • Consent, when you expressly authorize it, such as image use in photos and videos.
  • Compliance with a legal or regulatory obligation.
  • Legitimate interest, for security, fraud prevention, and platform improvement, always respecting your fundamental rights and freedoms.

4. Information security

  • Passwords protected with irreversible encryption (BCrypt).
  • Two-factor authentication (2FA/TOTP) available, which any system user can enable.
  • Each contracting business's data is isolated at the database level, with no sharing between different businesses.
  • An audit trail records who changed each piece of information and when.
  • Continuous, automated database backups.

5. Data retention and deletion

WhatsApp conversations and media are retained for up to 90 days by default, a period configurable by the contracting business, and are automatically deleted at the end of that period.

When a contracting business's contract ends, that business's data (including database records and files) is kept for up to 3 months, in case the business resumes using GeZap. After that period, the data is permanently deleted.

6. International data transfer

Our application and database servers are hosted in Germany, following internationally recognized information security standards.

  • Artificial intelligence (OpenAI): processes messages to generate the AI receptionist's replies; the provider does not use this data to train its models.
  • File and attachment storage, such as photos and WhatsApp media (Cloudflare).
  • Transactional email delivery (Resend).

These international transfers are covered by appropriate contractual safeguards, per ANPD Resolution (Resolução CD/ANPD) No. 19/2024.

7. Automated decision-making

The AI receptionist can create, reschedule, and cancel appointments automatically during the conversation, without prior human review. You may request a review of that decision at any time by contacting the business you deal with, or directly with our data protection officer.

8. Data Protection Officer

Data protection officer contact: privacy@gezap.com.br.

9. Updates to this page

This page may be updated to reflect legal, operational, or technical changes. The current version will always be publicly available here.