Legal

Privacy Policy

How CCX Digital Solutions handles personal data on the CCX Messages platform — what we collect from you, what we process on your instructions, and what we do to protect both.

Effective dateJuly 28, 2026
Version2.1
ScopeThe ccxmessages.com website and the CCX Messages platform
Data protection officer[email protected]
View technical controls
Honest summary

If you read only this part, you already have the essentials.

The summary does not replace the full text below, but it does not contradict any line of it. If in doubt, the full text prevails.

We are the controller of your account and browsing data; we are the processor of the content our customers send to their own customers.
No conversation on the platform trains an AI model — neither ours nor a third-party provider's.
Data, replicas, and backups stay in Brazil; international transfer happens only during delivery by a channel provider and during AI inference.
Content retention is configurable from 30 days to 5 years, and deletion is definitive at the end of the period.
We do not sell lists, we do not buy lists, and we do not use advertising cookies on the website.
01

Who processes your data

This policy is issued by CCX Digital Solutions LTDA, CNPJ 24.329.191/0001-06, which operates the CCX Messages platform. Whenever "we" appears here, it refers to that company.

The platform is a communications infrastructure used by other companies to talk to their own customers. This creates two distinct roles, and the difference between them determines almost everything that follows in this policy.

SituationOur roleWho decides
You use our website or have an account on the platformController: we decide the purposes of processingWe do
Messages a customer company sends to its own customersProcessor: we process on behalf of and by instruction of the customerThe customer company
Contacts imported by a customer into the platformProcessor, with purpose limited to the contractThe customer company
If your data is here because a company sent you a message, that company is the controller. We can forward your request to it, but we have no authority to decide about that data.
02

What we collect when we are the controller

As controller, we process only what is necessary to operate the service, bill for it, and comply with legal obligations. We do not buy databases, we do not enrich data with third parties, and we do not use advertising tracking on the website.

CategoryExamplesLegal basis
Account registrationName, business email, phone, company, and CNPJContract performance
Access dataIP address, login date and time, device, and browserLegitimate interest (security)
Platform usagePanel actions, keys created, volume sent per channelContract performance
BillingTop-ups, invoices, and consumption historyLegal and tax obligation
Sales contactData submitted in a demo or contact formLegitimate interest (pre-contract)
03

Cookies and measurement

On the public website we use only cookies strictly necessary for operation — such as keeping your session active and remembering display preferences. We do not use advertising cookies, we do not run remarketing, and we do not share identifiers with ad networks.

To understand page performance we use aggregate measurement, without building an individual profile and without cross-referencing registration data. You do not need to accept a banner to browse because there is nothing beyond the essential to consent to.

04

When we are the processor

Message content, contact lists, and conversation history belong to the customer that hired the platform. We process this data only to deliver the contracted service, following the instructions documented in the contract and in the data processing agreement.

We do not use message content for any purpose of our own: not for commercial analysis, not to train artificial intelligence models, and not for product improvement based on identifiable content.
We do not share, sell, or transfer one customer's contact list to another customer or to third parties.
Internal access to content is restricted, requires justification, and is recorded in an audit log — it normally happens only when the customer itself asks for help on a specific case.
It is the customer's responsibility to ensure the legal basis for contacting the data subject, including consent when the communication is marketing.
05

Artificial intelligence

When the customer enables the AI agent, its messages and knowledge base documents are sent to model providers to generate the response for that interaction. Our contracts with these providers prohibit retaining content for model training.

No conversation on the platform trains a model — neither ours nor a third party's. Knowledge base documents only serve to retrieve context for the customer's own responses, and the interaction record masks sensitive personal data while preserving the traceability of the decision.

If your internal policy requires it, we state in writing which model providers are in use at the time of contracting and in which region inference takes place.
06

Who we share with

We share data only with parties necessary for the service to exist, always under a data processing contract and with a limited purpose. The complete, up-to-date list of sub-processors is available on request, and relevant changes are communicated as set out in the contract.

Sub-processorWhat forRegion
Cloud providerApplication, database, and file hostingBrazil
Meta PlatformsDelivery on WhatsApp and InstagramPer Meta
Brazilian carriersSMS and RCS deliveryBrazil
AI model providersAgent inference, with no retentionBrazil and the United States
Payment providerTop-ups via Pix and boletoBrazil
We may also share data to comply with a court order or a request from a competent authority. When the law permits, we notify the affected customer before responding.
07

International transfers

Platform data is stored in Brazil, including replicas and backups. International transfer happens only in specific, defined situations: message delivery by a channel provider with global infrastructure, and AI inference when the chosen model operates outside the country. In these cases we apply contractual protection clauses equivalent to those required by the LGPD.

08

How long we keep data

The retention period depends on the nature of the data. Message content is retained on a schedule the customer configures, from 30 days to 5 years; tax records follow the statutory period, which cannot be negotiated by contract.

DataPeriodAfter that
Message content and attachmentsConfigurable: 30 days to 5 yearsDefinitive deletion
Delivery metadata and status24 monthsDefinitive deletion
Audit log24 monthsDefinitive deletion
Tax and financial records5 years (legal obligation)Retained for as long as the law requires
Account registration dataWhile the contract is activeDeleted after termination, unless a legal obligation applies
09

Your rights as a data subject

The LGPD grants you a set of rights, and we respond to all of them within 15 days — usually well before. We do not charge for the response and do not require justification for the request.

Confirm whether we process data about you and access that data.
Correct data that is incomplete, inaccurate, or out of date.
Request anonymization, blocking, or deletion of data that is unnecessary or processed in breach of the law.
Request portability to another provider, in accordance with the applicable regulations.
Withdraw consent, where processing relies on it, and be informed of the consequences of withdrawal.
Object to processing based on legitimate interest, stating the reason.
If the data is on the platform on behalf of a customer company, we forward your request to it within 2 business days and inform you of the forwarding.
10

Security and incidents

We apply encryption in transit and at rest, role-based access control, mandatory two-factor authentication for administrative profiles, and action audit logs. The technical details and the responsibility model are described on the security page.

In case of a security incident with material risk to data subjects, we notify the affected customers within the timeframe set in the contract, covering the scope of what happened, the data potentially involved, the containment measures taken, and the recommended action. This exists so the customer can meet its own obligations before the ANPD and the data subjects.

11

Changes to this policy

When we amend this policy, we update the effective date at the top and keep prior versions available on request. A change that reduces rights or expands purposes is communicated to customers by email at least 30 days in advance, so there is time to evaluate and, if appropriate, terminate the contract at no cost.

Exercise your rights

If you are a data subject and want to confirm, correct, port, or delete data, write to the Data Protection Officer. If your data is on the platform because a customer company sent it, we forward the request to that company — as controller, it decides, and we only execute.

Start today with R$ 50 in test credit.

Sandbox wallet released when you create the account, a WhatsApp test number and guided onboarding. No card, no contract.

Book a demoCreate free accountSales reply within 2 business hours
CCX
Brazilian CPaaS platform. WhatsApp, email, SMS, RCS, push and Instagram in a single integration.
All systems operational
© 2026 CCX Digital Solutions LTDA · CNPJ 24.329.191/0001-06 · BrazilTerms of usePrivacySecurityChangelog