| Legal name | Ricardo Wodianer de Mello LTDA |
|---|---|
| Trade name | Wodi Consultoria |
| CNPJ | 44.189.505/0001-11 |
| Data Protection Officer (DPO) | Ricardo Wodianer de Mello |
| Privacy contact | contato@tideseek.com |
In this policy, “we”, “our” and “Wodi Consultoria” refer to the company above. “Platform” means the artificial-intelligence agent system we operate for our corporate customers.
The Platform is sold to companies that use it to talk to their customers. That is why we process data in distinct positions, with different responsibilities (LGPD, art. 5):
We are CONTROLLERS — we decide how and why to process — in relation to:
We are PROCESSORS — we process under the contracting customer’s instructions, and that customer is the controller — in relation to:
When we approach companies at a customer’s request. Our customers use the Platform to approach companies that are not yet their customers. In those cases, the customer is the controller — they decide whom to approach and why — and Wodi Consultoria acts as a processor, executing the outreach under their instructions and with the safeguards described in section 8. If you received a message from us and want to know who determined the contact, reply to it: we identify the controller and forward your request.
If you are an end customer of a company that uses our Platform and want to exercise rights over your data, the controller is that company. Send the request to them; if you write to us, we will forward it to the controller and help them respond.
Email, password (stored only as a hash), access role and audit records of actions performed. Purpose: authenticate, control permissions and maintain an accountability trail. Legal basis: performance of a contract.
Name, email, phone, company, job title and the content of messages exchanged over WhatsApp and email. Purpose: allow the contracting company’s agent to serve, qualify and schedule meetings. Legal basis: performance of a contract (for the contracting customer) and legitimate interest or consent, as applicable, in the relationship between that company and its contacts.
Audio, images and documents. We do not keep the files. When a contact sends media over WhatsApp, we store only a reference to it at the provider; when the conversation is opened, the file is fetched from the source at that moment and displayed, without passing through our storage. Audio may be transcribed so the agent can understand the message, and in that case the text of the transcription is stored with the conversation — like any other message.
When someone fills in a contact form on a site that uses the Platform, we send a confirmation code to the email or WhatsApp provided. We store the address, phone number, timestamp, IP address and browser agent. Purpose: prove that the person owns the contact details provided before any automatic reply — this protects third parties from receiving messages because someone else entered their details. The code is stored only as a hash, never in readable form. Legal basis: legitimate interest in security and abuse prevention.
For the prospecting feature, we process data that appears in public sources: Brazil’s National Register of Legal Entities (CNPJ) from the Federal Revenue Service — legal name, CNAE, address, size, registration status and the email the company itself declared in the registry — and information published openly on the company’s website. We do not buy contact lists, do not use non-public sources, and do not collect data on individuals outside a professional context.
If you received a message from us, section 8 was written for you.
See section 4, which is dedicated to this because Google has specific requirements.
When a customer connects their email inbox, WhatsApp number or calendar, we store the credentials encrypted in our own vault. They are decrypted only at the moment of use, inside the process that runs the operation, and never appear in screens, API responses, system logs or in the context sent to language models.
This section describes, in detail, how we process data obtained through Google APIs.
We request two scopes, and nothing more:
| Scope | What it is for |
|---|---|
.../auth/calendar.freebusy | Query only busy/free intervals on the calendar, so the agent can offer real times to the contact. |
.../auth/calendar.events | Create the scheduled meeting event and cancel it when the meeting is unscheduled. |
We also request openid and email, used solely to show which account was connected (for example, name@company.com) on the administration screen.
We do not request the auth/calendar scope, which would give broad access to the calendar and its settings. We ask for the minimum needed for the feature.
We do not read the content of your events. Availability queries use the freeBusy endpoint, which returns only start and end intervals of busy periods. Titles, descriptions, attendees, attachments and locations of existing appointments are not accessed, not stored and not sent to language models. The only events whose content we know are those the Platform itself creates — meetings scheduled by the agent.
Our application’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
Authorization may be revoked at any time at myaccount.google.com/permissions or by removing the calendar on the Platform administration screen. Revocation immediately stops availability queries and creation of new events. Meetings already created remain on your calendar — they are your appointments, and deleting them without your request would alter your agenda.
The same treatment described in this section applies to the Microsoft Graph integration (Outlook / Microsoft 365), with equivalent scopes.
The Platform uses third-party language models to draft messages, qualify contacts and summarize conversations. That means the content of conversations and of the customer’s knowledge base is sent to those providers for processing, at the moment the agent acts.
We share data only with those necessary for the service to work:
| Third party | Role |
|---|---|
| Anthropic | language-model processing — by default, every conversation handled by an agent goes here |
| OpenAI | language-model processing when Anthropic fails or is unavailable, and transcription of audio received in conversations |
| Google (Gemini) | language-model processing only as last resort, if the two above are unavailable at the same time |
| Meta Platforms | sending and receiving WhatsApp messages (WhatsApp Business Cloud API) |
| Google / Microsoft | reading availability and creating calendar events |
| Cloudflare | form abuse protection and storage of encrypted backups (see sections 7 and 10) |
| Google (Analytics 4) | audience measurement for the institutional site, only with your consent |
| Hostinger | infrastructure hosting |
| Customer’s email provider | sending and receiving messages, via credentials the customer themselves connects |
The three model providers are on this list because they are the three the system can reach — and no others. The Platform chooses the model (it is not a customer option), and automatic failover for unavailability can only fall on a provider whose contractual chain has been verified. A subprocessor list that promises less than the system does is the defect this section exists to avoid.
About third-party model routers. The Platform has a ready integration with a router that resells models from other vendors, but no conversation is routed to it — neither by model choice nor by unavailability failover. If that changes, it and the destination provider become subprocessors and are added to this table before the first message goes out.
Our own audience measurement is intentionally omitted from this list: we run it on our own infrastructure (self-hosted), so site audience data is not sent to any third party. It remains under the same security regime as the rest of the Platform.
We do not sell personal data and do not share it for third-party advertising.
We may disclose data when required by law, court order or competent authority request, and in a corporate reorganization, in which case this policy will continue to be observed by the successor.
Isolation between customers. Each contracting company has data isolated in the database by a rule applied in the database server itself, not only by a filter in application code.
Secrets. Third-party credentials are encrypted at rest and decrypted only at the moment of use. Passwords are stored only as hashes, with an algorithm designed for that purpose.
Audit trail. Relevant actions are recorded with author, time and result.
Backups. They are generated daily, encrypted before leaving the server and stored off it. The decryption key does not live in the infrastructure that generates the backup.
| Data category | Period | Why |
|---|---|---|
| Application access records (date, time, IP) | 6 months | legal obligation — Brazilian Internet Civil Framework (Marco Civil), art. 15 |
| Audit trail of Platform actions | 12 months | accountability and incident investigation |
| Contracts, billing and tax records | 5 years after the relationship ends | tax and civil limitation periods |
| Contacts, conversations, knowledge base and collections portfolios (data processed as processor) | during the contract + up to 30 days after termination | the 30-day window exists for the customer to export what is theirs; afterwards, deletion or return per their instructions — and, at the data subject’s request, content is deleted earlier, under the procedure in section 9 |
| Data of a prospected company that did not interact | 24 months from the last send, if there is no interaction in that period | public data processed under legitimate interest; after that time without any reply, open, or deal, it is no longer necessary for the purpose that justified it |
| Identity confirmation code | 10 minutes, and only as a hash | the challenge lifetime; the readable value is never stored |
| Confirmation challenge record (identity, IP, time) | 6 months | defense against abusive form use, on the same timeline as access records |
| Audio, images and documents received in conversations | we do not store them | fetched from the source when the operator opens them |
| Calendar availability read | we do not store it | used only in memory while calculating times to offer |
| Calendar access token | until revocation or removal of the calendar | deleted from the vault in the same act |
| Do-not-contact request record | kept indefinitely | see the note below |
| Backups | up to 30 days (daily copies) and up to 200 days (monthly copies) | the window to notice and reverse corruption or loss |
Why a “do not contact me again” request is NOT deleted. When someone asks to stop receiving messages, we keep that request linked to the address or phone that made it. Deleting it together with other data would have the opposite effect: the person would become contactable again the first time that contact re-entered the Platform. Keeping the record is what honors the objection — and it holds only the minimum needed for that.
About backups and deletion. Once the periods expire — or a deletion request is fulfilled — the data is removed from production systems immediately. It may still exist in backups until the periods in the table above expire, when it disappears from those too. Backups are encrypted and used exclusively for restoration in case of an incident.
Where your address came from. From Brazil’s public CNPJ registry, where the company itself declared it, or from the company’s website. We use no other source, do not buy lists, and do not obtain addresses from third parties.
Legal basis. Legitimate interest (LGPD art. 7, IX) in offering products and services to companies whose profile matches what we serve, with the safeguards described below.
How to stop receiving messages now. Reply to the message with the word sair. Removal is immediate and lasting: the address enters a do-not-contact list checked on every send, across all channels, and does not depend on who asked us to approach you. You may also use the unsubscribe link or header that accompanies the message.
The safeguards we apply.
Your rights. You may at any time object to the processing (art. 18, §2), request confirmation and access to the data we hold about you, its correction and its erasure. Write to contato@tideseek.com.
What we keep after you opt out. Only the record that you asked not to be contacted, linked to the address — and for an indefinite period, for the reason explained in section 7.
Under Brazil’s LGPD (Law 13.709/2018), you may request: confirmation that we process your data; access to the data; correction of incomplete or outdated data; anonymization, blocking or deletion of unnecessary data or data processed in non-compliance; portability; information about sharing; withdrawal of consent; and opposition to processing based on legitimate interest.
To exercise any of them, write to contato@tideseek.com. We will respond as soon as possible and, in any case, within the timelines provided by law. We may ask for additional information to confirm your identity — which prevents a third party’s request from exposing your data.
If you are an end customer of a company that uses the Platform, see section 2: that company is the controller.
Once the controller has granted the request, we delete: conversation history on both channels, including the team’s internal notes; received messages, with the original content and the media reference; content of forms filled on the site; pending reply drafts and the context in use by the agent; the service text in the search index; and your name from within meeting records.
We retain, and the reason for each:
What erasure does not reach. Data that lives outside the Platform: the contracting company’s own management system, its email inbox, the conversation history on the device of whoever spoke with you, and meeting events already created on the calendar of the professional who served you — those are appointments between two people, and we do not alter them on our own. A meeting still to happen is flagged to the contracting company at the moment of erasure, so they can decide whether to cancel and notify you.
Timeline: we respond within 15 days (art. 19, §1).
Data Protection Officer (LGPD, art. 41): Ricardo Wodianer de Mello, reachable at contato@tideseek.com.
The Platform is operated on infrastructure located in Brazil (Campinas/SP). Production data — contacts, conversations, knowledge base and collections portfolios — is processed on national territory.
There are two exceptions, and they are international transfers:
These transfers occur under the hypotheses of LGPD art. 33, through contractual clauses that ensure an adequate level of protection.
In the case of Google Analytics, the transfer only happens after your consent on the site banner (section 11). If you refuse, no data is sent.
Our own audience measurement does not create a transfer to a third party, because the tool runs on our infrastructure — the data does not leave our environment.
Inside the Platform (authenticated area) we use only browser local storage, to keep your session and theme preference. There are no advertising cookies or third-party trackers in the authenticated area.
On the institutional site we use two measurement tools, with different treatments:
| Tool | What it does | Cookies | Consent |
|---|---|---|---|
| Own measurement, self-hosted on our infrastructure | counts visits, pages and traffic sources in an aggregated way, without identifying people | none | not required — no cookie or persistent identifier |
| Google Analytics 4 | measures audience and navigation behavior, with a visitor identifier | uses | prior consent required — loaded only after you accept |
You choose. The banner shown on the first visit lets you accept or refuse measurement by cookies. While you do not accept, Google Analytics is not loaded and no data is sent to it. Refusal does not limit access to the site or any functionality. The choice can be changed at any time via the same banner.
Google Analytics processes data in the United States (see section 10) and operates with anonymized IP. We do not enable Google Analytics advertising features: site audience data is not used to create advertising audiences, remarketing or ad profiles.
The Platform is intended for corporate use by people 18 or older. We do not knowingly collect data from children or adolescents.
We may update this policy. The date at the top shows the latest revision; material changes will be communicated to contracting customers through usual channels.
Wodi Consultoria — Ricardo Wodianer de Mello LTDA · CNPJ 44.189.505/0001-11
contato@tideseek.com