Privacy Policy
Last updated: June 2025
1. Introduction to our Privacy Policy
Z-API TECNOLOGIA DA INFORMACAO LTDA. ("Z-API" and/or the "Company"), registered under Brazilian CNPJ no. 29.249.718/0001-06, headquartered at Av. Bento Munhoz da Rocha Netto, nº 632, Sala 201-204 Torre Norte, CEP 87030-010, in the city of Maringá-PR, Brazil, is the largest WhatsApp integration API in Brazil, compatible with multiple devices.
In this sense, and in order to demonstrate our concern for matters related to Privacy and Data Protection, we hereby establish this: Privacy Policy (the "Policy").
2. Purpose
This Policy aims to clarify, in a simple and accessible way, how Z-API processes personal data — that is, its collection, sharing, storage, etc. — in compliance with applicable data protection laws.
Our commitment is to protect the privacy and security of the information provided by data subjects when using our services, ensuring a reliable and secure experience. This Policy details the types of data collected, the purposes of its use, the rights of data subjects and the measures implemented to ensure the confidentiality and integrity of this information.
This Policy may be updated from time to time to align its wording with internal procedures or legal requirements.
3. Definitions
As we value transparency and communication, below is a glossary of technical terms and concepts that may be used throughout this Policy, related to privacy and data protection:
- Processing
- Any operation carried out with personal data, such as those referring to collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation or control of information, modification, communication, transfer, dissemination or extraction.
- Cookies
- Small files sent by websites and saved on your devices, which store preferences and a small amount of other information, in order to personalize your browsing according to your profile.
- Data Subject / User
- A natural person to whom the personal data being processed refers, such as customers, visitors and other people who interact with the website.
- Personal data
- Any information related to an identified or identifiable natural person.
- Anonymization
- The use of reasonable technical means available at the time of processing, through which a piece of data loses the possibility of being associated, directly or indirectly, with an individual.
- Purpose
- The reason why personal data will be processed. The purpose must be legitimate, specific, explicit and communicated to the data subject.
- Controller
- A natural or legal person, of public or private law, responsible for decisions regarding the processing of personal data.
- Processor
- A natural or legal person, of public or private law, that processes personal data on behalf of the controller.
- Data Protection Officer
- The person appointed by the controller and processor to act as a communication channel between the controller, data subjects and Brazil's National Data Protection Authority (ANPD).
- LGPD
- Law No. 13,709 of August 14, 2018, also known as Brazil's General Data Protection Law, which legally governs the processing of personal data in Brazil, both digitally and physically, with the aim of protecting the fundamental rights of freedom and privacy and the free development of the personality of the natural person.
4. About the personal data provided
Any personal data provided to Z-API is handled with the highest levels of security and care, and is used only for the purposes specified in this Policy. The data provided to the Company will depend on the process the data subject is undergoing.
| Data Collected | Purpose of Processing | Legal Basis |
|---|---|---|
| Name; Company name; Tax ID; Phone number; Email; Address. | Registration to use the Platform; Identification of the User/Data Subject; Company communication with the User; Invoicing and/or correspondence. | Performance of a contract or preliminary procedures related to a contract, art. 7, V, of the LGPD. |
| Data Collected | Purpose of Processing | Legal Basis |
|---|---|---|
| Full name; Tax ID; Contracted plan; Bank details. | Identification and payment management of the User/Data Subject; Issuance of invoices; Subscription management. | Performance of a contract or preliminary procedures related to a contract, art. 7, V, of the LGPD. |
| Data Collected | Purpose of Processing | Legal Basis |
|---|---|---|
| Full name; Email. | Sending Z-API news and updates to the email registered for the newsletter. | Legitimate interests of the controller or third parties, art. 7, IX of the LGPD. |
| Data Collected | Purpose of Processing | Legal Basis |
|---|---|---|
| Name of the person in charge; Company name; Email; Phone; State and city. | Providing a contact channel on the Company's website for the general public regarding plans and custom options for the User's business. Customer support. | Performance of a contract or preliminary procedures related to a contract, art. 7, V, of the LGPD. Legitimate interests of the controller or third parties, art. 7, IX of the LGPD. |
5. Data collected by Z-API
The data listed in the previous table refer to data provided directly by the data subject to the Company. However, some other personal data may be processed by the Company:
- Mobile device data from access to the digital platform and other information, such as the type and version of the browser used.
- Log data.
- IP address.
- Email and instant messaging systems — used to maintain communication between the data subject and the Company, such as social networks, website chat, email and WhatsApp.
- Cookie data — described in section 6.
In addition to the purposes defined above, the Company may process personal data to achieve any of the following purposes:
- Satisfactory performance of its business, such as providing and maintaining API services as contracted, account management and authentication, improvements to enhance the API's functionality and performance, development of new features based on the data subject's behavior, and improving the algorithms and efficiency of the service provided.
- Detecting and preventing fraud or unauthorized use of the service, in order to protect the integrity of the Platform.
- Diagnosing and resolving technical issues.
- Generating internal reports on Platform performance.
- Compliance with legal obligations or applicable law requirements, whether in response to legal proceedings, a request from a competent legal authority — such as the Judiciary — or to protect the rights of data subjects, their privacy, their physical or material integrity, to comply with the terms of any necessary agreement or contract, or with our own terms.
6. Z-API's use of Cookies
Cookies are small files sent by websites and saved on your devices, which store preferences and a small amount of other information, in order to personalize your browsing according to your profile. By accepting the Cookie banner or using the features of the Z-API website, you allow the Company to use cookies to monitor your use of the website or online platform.
The Company uses cookies on its website for different purposes:
7. Sharing of personal data
Z-API may share Data Subjects' Personal Data to provide and operate its services and achieve a legitimate and specific purpose. We will take the measures available in the market and within our reach so that all information security standards are observed and processing is carried out in strict accordance with the purposes described herein. As such, we may share your personal data with:
- Judicial, administrative or governmental authorities: upon request, requisition or court order, Z-API may share personal data with the competent authorities. Sharing will only include the data necessary to comply with the request, or when necessary for us to present a defense or exercise a legal right.
- Professional consultants: Z-API may rely on outsourced help for certain specific activities, such as accounting services for tax filings.
It should be noted that sharing Personal Data with third parties will only occur to achieve a legitimate, specific purpose previously disclosed to the data subject in our System or in this Policy.
8. Personal data retention period
Your personal data and other information will be stored only for as long as strictly necessary to fulfill the purpose for which it was obtained or for the periods provided for by legal and contractual provisions. Therefore, in addition to constant observance and updating of these regulations, regardless of consent or a deletion request, the General Data Protection Law allows the Company to retain the personal data of customers, service providers and the general public in order to accomplish one of the following:
- Compliance with a legal or regulatory obligation, such as, for example, tax documents for a period of five years.
- Transfer to a third party, respecting your rights and the provisions of data protection and privacy laws.
- For exclusive use, with third-party access prohibited, provided the data has been anonymized.
9. Storage of personal data
Z-API guarantees that all information or personal data provided will be handled with the highest security standards, in order to ensure that none of this information is subject to destruction, loss, alteration or improper disclosure. To this end, Z-API adopts several information security measures:
- Encryption in Transit: All data transmitted between the client and Z-API's servers is protected by encryption protocols, such as TLS (Transport Layer Security), ensuring that information is encoded and secure against interception during transmission.
- Encryption at Rest: Data stored on Z-API's servers is encrypted using techniques such as AES (Advanced Encryption Standard), ensuring that, even in the event of unauthorized access, the data remains unreadable without the appropriate keys.
- Protection against unauthorized access: Z-API implements strict access controls to its systems and internal directories, with granular permissions. Only authorized employees have access to the information necessary to perform their duties, following the principles of least privilege and segregation of duties. Two-factor authentication (2FA) is also used.
- Protection against intrusions: Firewalls are used to filter network traffic and prevent unauthorized access, in addition to intrusion detection and prevention systems (IDS/IPS) that monitor and respond to malicious activity.
- Environment isolation: Z-API uses containers and/or virtual machines to isolate different services, preventing failures or attacks on one part of the infrastructure from affecting others.
- Backups and disaster recovery: Z-API performs regular backups, enabling fast data restoration and service recovery in the event of disasters or critical failures.
- Awareness programs: Educational programs are implemented for customers and employees, addressing the risks of phishing and other forms of social engineering.
- LGPD compliance: Z-API requires partner companies, service providers and suppliers that process personal data to comply with Brazil's General Data Protection Law (LGPD), ensuring absolute confidentiality of the information and personal data they have access to.
10. The rights you have over your personal data
In compliance with applicable regulations regarding the processing of personal data, the User may request, at any time, by contacting our Data Protection Officer, the following rights:
- Confirm the existence of processing.
- Access your personal data.
- Correct incomplete, inaccurate or outdated personal data.
- Request the anonymization, blocking or deletion of unnecessary, excessive personal data or data processed in violation of the LGPD.
- Request the portability of personal data to another service or product provider, through express request, in accordance with the regulations of the national authority, and subject to trade and industrial secrets.
- Delete or anonymize personal data processed based on your consent, except where the law authorizes retention on another legal basis.
- Obtain information about the public and private entities with which the controller has shared data.
- Obtain information about the possibility of not giving consent and the consequences of refusal.
- Withdraw your consent, as applicable.
11. Data Protection Officer (DPO)
If you would like to clarify questions, make requests or exercise any of your rights related to the processing of personal data, please contact our Data Protection Officer:
Data Protection Officer: Wagner Mendes Voltz
Email: wagner.fusca@grupoirrah.com
If you prefer to contact us by mail, please send your correspondence to: Avenida João Paulino Vieira Filho, nº 672, Sala 101, Zona 01, CEP 87020-015, Maringá–PR, Brazil.