How we handle personal data when providing technology services, including WhatsApp Business Platform integrations.
This Privacy Policy describes how SAWADEE TECH INOVA SIMPLES (I.S.), registered under Brazilian corporate taxpayer number (CNPJ) 67.720.990/0001-03, with offices at Avenida Roberto Camelier, 518, Casa 88 — Jurunas, Belém — PA · 66033-420, Brasil — “Sawadee Tech”, “we” — collects, uses, shares, stores and deletes personal data.
It applies to:
We are a Tech Provider. Our business is building and operating software that connects our customers to their own users. This means that most of the time we process end-user personal data on behalf of our customers and under their instructions — not for our own purposes.
Brazil’s General Data Protection Law (Law 13.709/2018, “LGPD”) distinguishes the controller, who decides how data is processed, from the processor (operador), who processes data on the controller’s behalf. Our role depends on the data, and it determines whom you should address.
| Context | Our role | Who decides |
|---|---|---|
| This corporate website | Controller | Sawadee Tech |
| Customer onboarding, billing and support | Controller | Sawadee Tech |
| End-user messages and data flowing through the integrations we operate | Processor | Our customer (the business serving that user) |
| Security, fraud prevention and legal records | Controller | Sawadee Tech |
If you are an end user who messaged a business on WhatsApp: the controller of your data is that business, not Sawadee Tech. We operate the infrastructure on its behalf.
We will not turn you away. If you contact us directly, we forward your request to the responsible controller and help fulfil it. See section 11.
This is a corporate website that uses no cookies, pixels, analytics tools or third-party tracking of any kind. There are no forms and no sign-up. Our hosting provider keeps transient technical records inherent to network operation: IP address, request timestamp, requested path, response code and user-agent. These serve security and availability only.
When operating messaging integrations for our customers we process the following. Content is determined by the customer and by the user — we do not choose what is sent:
We do not request sensitive personal data (LGPD art. 5, II) and our services are not designed to receive it. If a user volunteers such information in a message, it is treated with the same confidentiality as the rest of the conversation and subject to the retention periods in section 8.
| Purpose | Legal basis (LGPD) |
|---|---|
| Delivering the contracted service: transmitting, receiving and processing messages for the customer | Performance of a contract — art. 7, V (and legitimate interests of the controlling customer — art. 7, IX) |
| Customer onboarding, contracting, billing and collection | Performance of a contract — art. 7, V |
| Technical support, incident investigation and fixes | Performance of a contract — art. 7, V; legitimate interests — art. 7, IX |
| Platform security, integrity and availability; fraud and abuse prevention | Legitimate interests — art. 7, IX |
| Sending business-initiated messages (notifications, utility, marketing) to end users | Consent — art. 7, I, collected by the customer as described in section 5 |
| Complying with legal, regulatory and tax obligations and lawful orders | Legal obligation — art. 7, II; exercise of rights — art. 7, VI |
We do not sell personal data. We do not license or disclose it to third parties for those third parties’ own purposes, and we do not use it for targeted advertising.
We act as a Tech Provider on the WhatsApp Business Platform, integrating our customers’ systems with the WhatsApp Cloud API provided by Meta. In that chain:
Meta’s policies require that no business-initiated message be sent without the user’s prior, informed consent. The opt-in must clearly identify the sending business and the type of messages the user will receive, and may be collected through any verifiable means. Merely displaying a phone number does not constitute opt-in.
We contractually require our customers to obtain and retain this evidence, and we provide the technical means to record it and to process opt-out requests. Users may withdraw consent at any time, including by replying in the conversation itself; withdrawals are honoured and propagated to the customer’s systems.
In line with the WhatsApp Business Solution Terms and the Meta Platform Terms, we commit not to:
Messages travel encrypted between the user and the Cloud API using the Signal protocol, and Meta manages the encryption and decryption keys on behalf of the business. Per Meta’s documentation, message content is retained for up to 30 days to support core functionality such as retransmission, and user identifiers are deleted within 30 days after a message’s final status update unless otherwise directed. These periods are set by Meta and may be changed by Meta.
We share personal data only where necessary, always under contracts imposing confidentiality and security obligations equivalent to our own, and restricting the recipient to processing solely on our instructions.
| Recipient | Role | Purpose |
|---|---|---|
| Meta Platforms, Inc. / Meta Platforms Ireland Ltd. | Sub-processor | WhatsApp Business Platform (Cloud API) — message transit and delivery |
| Fly.io, Inc. | Sub-processor | Application hosting and compute |
| The contracting customer | Controller | Natural recipient of its own users’ data |
| Public authorities | — | Compliance with legal obligations or court orders, limited to the scope of the request |
The set of sub-processors varies with the architecture each customer contracts. The complete and current sub-processor list for a given contract is maintained by us and provided to the customer on request at contato@sawadee.lat, with advance notice of material changes.
Meta’s infrastructure and some of our providers are located outside Brazil, notably in the United States and the European Union. Processing may therefore involve international transfers of personal data under Chapter V of the LGPD.
These transfers rely on the grounds in LGPD art. 33 — in particular necessity for the performance of a contract (item VI) and contractual clauses and safeguards agreed with providers (item II) — complemented by each provider’s own transfer mechanisms, such as the standard contractual clauses adopted by Meta.
| Category | Period | Criterion |
|---|---|---|
| Website access logs | Up to 6 months | Security and diagnostics |
| End-user messages and data (as processor) | As instructed by the controlling customer; absent instruction, until the contract ends | Controller’s instruction; deletion or return at contract end |
| Consent records (opt-in / opt-out) | Duration of the relationship plus 5 years | Demonstrating compliance and handling rights requests |
| Customer account and contract data | 5 years after the relationship ends | General limitation period (Brazilian Civil Code art. 206, §5, I) |
| Tax and accounting records | 5 years | Applicable tax law |
Once the period and purpose are exhausted, data is securely deleted or irreversibly anonymised, save for the retention grounds in LGPD art. 16.
We maintain administrative, physical and technical safeguards appropriate to the sensitivity of the data and meeting the industry standards required by the Meta Platform Terms, including:
No system is entirely immune to incidents. We maintain an open vulnerability reporting channel at contato@sawadee.lat and commit to reviewing every good-faith report we receive.
LGPD art. 18 grants data subjects the following rights, exercisable at any time and free of charge:
Write to contato@sawadee.lat describing your request. We respond within 15 days of receipt, per LGPD art. 19, II. We may ask for additional information to verify your identity before acting — a safeguard in your favour.
Where the request concerns data we process as a processor, we forward it to the controlling customer and assist in fulfilling it, telling you that we have done so.
Detailed data deletion instructions: sawadee.lat/data-deletion
That page sets out exactly what is deleted, how long it takes, how you receive confirmation, and what we must retain by law. Deletion requests are completed within 30 days.
This website uses no cookies, tracking pixels, device fingerprinting or audience analytics. No third-party scripts are loaded on our pages and none of your data is sent to advertising networks. Should this change, we will update this policy and present the appropriate consent controls before any collection begins.
Our services are directed at businesses, not at people under 18. We do not knowingly collect children’s data. The WhatsApp Business Platform requires its users to meet the minimum age set in its terms. If we identify processing of a child’s data without the specific, prominent consent of at least one parent or legal guardian required by LGPD art. 14, §1, we delete the data and notify the controlling customer.
We maintain an incident response plan. On confirming a security incident that may pose relevant risk or harm to data subjects, we notify:
We may update this policy to reflect legal, regulatory, contractual or technical change. The version in force is always the one published on this page, identified by version number and date at the top. Material changes are communicated to customers through contractual channels with reasonable notice. Prior versions are available on request at contato@sawadee.lat.
The Data Protection Officer (Encarregado), appointed under LGPD art. 41, is the channel between Sawadee Tech, data subjects and the Brazilian data protection authority. Address requests to the email above with the subject Encarregado / LGPD.
If you believe your request was not adequately handled, you may complain to the Brazilian National Data Protection Authority (ANPD) at gov.br/anpd.