Privacy and data protection
Privacy Policy
Last updated: May 30, 2026
This Privacy Policy explains how GeZap processes personal data in the internal system, communication integrations, and social login access. Its purpose is to provide transparency about which data may be used, why it is used, and how users can exercise their rights.
1. Scope of this policy
GeZap is a platform for management, service, scheduling, digital communication, campaigns, and integrations with external channels such as WhatsApp Business, email, calendar services, and social authentication providers.
In many cases, data is controlled by the contracting company that uses GeZap. In these scenarios, GeZap acts as supporting technology to process, store, audit, and protect information according to the settings and permissions defined by the responsible company.
2. Data that may be processed
- System user data, such as name, email, permissions, and access history.
- Customer, lead, professional, service, resource, and appointment data.
- Session, service, campaign, and notification records.
- Communication messages and metadata, such as sending, delivery, and read status.
- WhatsApp Business integration data, business account identifiers, connected phone numbers, templates, categories, languages, statuses, and technical events.
- Technical audit, authentication, security, log, and integration event data.
3. Purposes of use
- Enable secure system access and user permission control.
- Organize scheduling, service, sessions, and operational history.
- Send messages, notifications, reminders, and communications configured by the company.
- Create, view, and manage WhatsApp message templates.
- Track delivery, read, failure, template approval, and other events required for integrations.
- Record audits, prevent misuse, and preserve traceability.
- Improve platform stability, security, support, and operation.
4. Social authentication
The system may allow login through providers such as Google, Facebook, and GitHub. In these cases, GeZap uses only the minimum information needed to authenticate the user, such as technical identifiers and the email linked to the social account.
Users can revoke the social link under User > My Settings, in the linked accounts section. Public instructions are available at Social Data Exclusion.
5. WhatsApp, email, and external integrations
GeZap may integrate with external services to send messages, notifications, appointment confirmations, campaigns, reminders, location information, emails, and calendar events. These channels depend on the contracting company's settings and the respective providers' policies.
Message statuses, sending identifiers, webhook events, and technical metadata may be stored for audit, support, queue processing, and communication tracking.
6. Meta and WhatsApp Business Platform integration
GeZap may use Meta APIs, including the WhatsApp Business Platform, so contracting companies can connect WhatsApp Business accounts, send messages, create and manage templates, track delivery status, and process technical communication events.
The permissions whatsapp_business_messaging and whatsapp_business_management are used only to provide, operate, audit, protect, and support contracted features.
GeZap does not sell data obtained through Meta APIs and does not use that data for purposes independent from providing the contracted service.
7. Security and audit
- Passwords are stored using irreversible encryption.
- System access is controlled by authentication and permissions.
- Two-factor authentication (2FA) is available and, when enabled by the user, requires a temporary code from the authenticator app at each login, strengthening account protection.
- Relevant operations may be audited to track responsible users and timestamps.
- Each company's data is separated through logical multi-company controls.
- Backups and technical controls may be used for availability and recovery.
8. Data sharing
GeZap does not sell personal data. Data may be shared only when necessary for platform operation, legal compliance, technical support, integrations configured by the contracting company, or execution of contracted services.
When the contracting company uses external integrations, minimum necessary data may be sent to configured providers such as Meta, WhatsApp Business Platform, email, calendar, storage, authentication, infrastructure, and support services.
9. Retention and deletion
Data is retained while there is a relationship with the responsible company, operational need, legal obligation, security, audit, or another applicable legitimate basis.
Tokens, permissions, and technical integration identifiers may be revoked or removed when the company disconnects the integration, when the user unlinks a social account, or when deletion is requested through applicable channels.
10. Data subject rights
Under applicable law, data subjects may request information about data processing, correction, deletion, portability, restriction, or consent withdrawal when applicable.
When the request involves social login data, Meta/Facebook accounts, or other external providers connected to GeZap, the user may also follow the instructions at Social Data Exclusion or request support at support@gezap.com.br.
Requests related to data maintained by a specific company should be directed to the administrator responsible for that company's environment. For GeZap platform matters, use the contacts in the footer.
11. Changes to this policy
This Privacy Policy may be updated to reflect legal, operational, technical, or functional changes. The current version will always be publicly available on this page.