1. Who we are
This platform is operated by Lucas Nhimi Longuinhos (data controller), an individual registered in Brazil, under the brand PropAgents AI / PropDash ("PropAgents", "we", "our"). This Privacy Policy describes how we collect, use, store, and protect your personal information in compliance with Brazilian General Data Protection Law (LGPD - Law No. 13,709/2018) and Meta Platform Terms.
Contact: privacidade@propagents.ai
2. Data we collect
- Registration data: name, email, phone, and company information.
- WhatsApp integration data: phone number, messages sent and received through the platform, Meta API access tokens, WhatsApp Business Account (WABA) identifiers and Phone Number IDs, templates, and webhook subscriptions.
- Meta Platform data: as authorized by the user through Embedded Signup / Login for Business, including public profile data (name), Business Manager information, and WhatsApp Business assets the user chooses to connect.
- Usage data: access logs, platform interactions, and usage metrics.
- Real estate data: property listings registered by the user, including descriptions, prices, and images.
3. Purpose of processing
We use your data to:
- Provide and maintain the PropDash platform services.
- Process and deliver WhatsApp messages via WhatsApp Business API in compliance with Meta policies.
- Generate AI-powered analytics and suggestions to optimize your customer service.
- Send service-related communications (updates, security alerts).
- Improve our products and services.
4. Data sharing and processors
We only share data with the following service providers / data processors, strictly necessary for the operation of the service:
- Meta Platforms, Inc. — recipient (not processor): sending and receiving WhatsApp messages via Cloud API, OAuth authentication, messaging metrics.
- Supabase, Inc. — PostgreSQL database and authentication provider (United States / European Union).
- Vercel, Inc. — web application hosting and CDN (United States).
- Anthropic PBC — AI processing (Claude API), United States.
- OpenAI, Inc. — AI processing, United States.
- Pinecone Systems, Inc. — vector database for semantic search, United States.
- Resend, Inc. — transactional email delivery.
- Trigger.dev, Inc. — background job execution.
- Upstash, Inc. — cache (Redis).
We do not sell, rent, or trade your personal data. All providers above operate under data processing agreements that limit the use of data to the purposes described in this policy.
5. Meta Platform data (WhatsApp)
When you connect a WhatsApp Business account to PropAgents, the following Meta Platform data is stored:
- Access tokens: stored securely and never exposed in the user interface. Used exclusively to send/receive messages on your behalf.
- WABA ID and Phone Number ID: identifiers required to route webhooks and Cloud API calls.
- Messages: message content is stored to be displayed in the agent history. You may request deletion at any time.
You may revoke PropAgents' access to your WhatsApp account at any time through Meta Business Manager (Settings → Apps → remove access) or by disconnecting the integration in the PropAgents panel.
6. Data retention
Your data is retained while your account is active or as needed to provide the services. Upon account closure, personal data is deleted within 30 days, unless there is a legal retention obligation. Meta API access tokens are revoked immediately upon integration disconnection.
7. Security
We employ technical and organizational measures to protect your data, including encryption in transit (TLS 1.2+), role-based access control, least privilege principle, and continuous security monitoring.
8. Your rights (LGPD)
Under Brazilian LGPD, you have the right to:
- Access your personal data.
- Correct incomplete or outdated data.
- Request the deletion of your data.
- Revoke consent for data processing.
- Request the portability of your data.
- Know with whom we share your data (full list in section 4 above).
To exercise your rights, contact: privacidade@propagents.ai.
9. Data deletion
You may request data deletion at any time via the email above or by visiting the data deletion instructions page. Once requested, your data will be removed within 30 business days.