Privacy Policy
Effective: August 8, 2026
1. Introduction
Magnet Customer Software Ltda. ("Magnet Customer", "we" or "our"), a private legal entity registered under CNPJ 52.678.731/0001-94, headquartered at Avenida Afonso Pena, 2440, Suite 62, Centro, Campo Grande/MS, Brazil, ZIP 79.002-934, operates the CRM and IRM (Investor Relationship Management) platform for the Brazilian financial market. We are committed to protecting the privacy and personal data of our customers, users, and visitors. This Privacy Policy describes how we collect, use, store, and protect your personal information in compliance with the Brazilian General Data Protection Law (LGPD — Federal Law No. 13,709/2018) and other applicable legislation.
2. Data we collect
We collect different categories of data depending on your relationship with Magnet Customer:
- Personal identification data: full name, professional email address, phone number, job title, and company
- Platform usage data: access logs, pages visited, features used, session duration, actions performed in the interface
- Technical data: IP address, browser type and version, device, operating system, time zone
- Communication data: messages sent via contact forms, email, support chat, or demo requests
- Clients' customer financial data: when our clients use integrations with custodians (BTG Pactual, Safra, XP Investimentos, and others), investor portfolio information is processed under the exclusive control of the client — Magnet Customer acts as a data processor in this context, pursuant to art. 37 of the LGPD
- Cookie and analytics data: via Google Analytics (with consent) for behavioral analysis on the institutional website
3. Purpose of processing
We use your personal data for the following purposes:
- Service delivery: provisioning, operation, and maintenance of the SaaS platform
- Communication and support: answering inquiries, processing demo requests, sending technical and security notifications
- Product improvement: usage analysis, issue identification, development of new features
- Marketing communications (with consent): newsletters, educational materials, product updates — you can unsubscribe at any time
- Billing and invoicing: invoice issuance, payment control, fraud prevention
- Compliance with legal obligations: responding to judicial requests, regulatory authorities (CVM, BACEN, Receita Federal), and tax obligations
4. Legal basis (LGPD)
All data processing by Magnet Customer has an express legal basis under the LGPD (art. 7 and art. 11), including:
- Consent (art. 7, I): for marketing communications and non-essential cookies
- Contract performance (art. 7, V): for providing services contracted by the client
- Legitimate interest (art. 7, IX): for product usage analysis, security, fraud prevention, and continuous improvement
- Legal obligation (art. 7, II): for responding to competent authorities and fulfilling tax obligations
5. Data sharing
We do not sell, lease, or commercialize your personal data. We may share data in the following circumstances:
- Infrastructure sub-processors: Amazon Web Services (AWS) — hosting in the São Paulo region (sa-east-1) — and Google Cloud Platform for analytics and auxiliary storage
- Communication providers: SendGrid (transactional emails), with data protection contractual clauses
- Financial integrations authorized by the client: BTG Pactual, Safra, XP Investimentos, and other custodians are engaged exclusively under the instruction and authorization of the contracting client
- Legal requests: when required by law, court order, or competent regulatory authority, following prior legal analysis
- Corporate transactions: in the event of merger, acquisition, or asset sale, with prior notice to data subjects
6. Data security
We adopt robust technical and organizational measures to protect your data against unauthorized access, loss, alteration, or destruction:
- Encryption in transit: TLS 1.2+ on all communications between client and server
- Encryption at rest: data stored with AES-256 encryption in MongoDB and in AWS S3 backups
- Multi-tenant isolation: each client has an isolated database or segregated collections, ensuring data from different organizations never mixes
- Access control: authentication via Keycloak (OAuth 2.0 / OpenID Connect), granular RBAC, and audit trail of all operations
- Automated backups: daily backups with 30-day retention, periodically tested to ensure restorability
- Monitoring and alerts: anomaly detection, centralized logs, and 24/7 incident response
7. Data retention
We retain your personal data for as long as necessary to fulfill the purposes described in this policy and applicable legal obligations:
- Active account data: retained for the entire duration of the service contract
- Data after termination: retained for up to 90 days to enable export, then securely deleted, unless a longer retention is legally required
- Access logs: as required by the Brazilian Internet Civil Rights Framework (Law 12,965/2014), for a minimum of 6 months
- Fiscal and accounting data: as required by applicable tax legislation (generally 5 years)
8. Your rights (LGPD)
Under arts. 17 to 22 of the LGPD, you have the following rights regarding your personal data, which can be exercised at any time:
- Confirmation and access: know whether we process your data and obtain a copy
- Correction: update incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion: of unnecessary, excessive, or non-compliant data
- Portability: receive your data in a structured and interoperable format
- Information about sharing: know with whom we share your data
- Consent revocation: withdraw consent at any time without affecting the lawfulness of prior processing
- Right to object: if you disagree with processing based on legitimate interest
9. Cookies
Our website uses cookies and similar technologies. You can manage your preferences through the cookie banner displayed on first access:
- Essential cookies: necessary for the basic functioning of the site (authentication, security, language preferences) — cannot be disabled
- Analytics cookies: collected via Google Analytics to understand visitor behavior and improve the site — require your consent
- Preference cookies: store custom settings to improve your experience — require your consent
- To disable cookies, access your browser settings or click "Manage cookies" in the site footer
10. International data transfers
Some of our sub-processors (AWS, Google) may process data on servers located outside Brazil. In such cases, we ensure transfers occur with adequate safeguards as provided by the LGPD (art. 33), including standard contractual clauses that ensure a level of protection equivalent to that required by Brazilian legislation.
11. Google user data (Gmail and Google Calendar)
Magnet Customer offers an optional integration with the user's Google Account. The integration is only enabled when the user authorises it through Google's consent screen, and it can be revoked at any time. When authorised, we access the following data solely for the features described below:
- Gmail messages (gmail.readonly scope): we sync the user's mailbox to display the conversation history alongside the client record inside the CRM.
- Sending email (gmail.send scope): lets the user send email to their clients from the CRM, using their own address.
- Message management (gmail.modify scope): reflects in the mailbox the actions taken in the CRM — marking as read, applying a label, archiving and managing drafts.
- Calendars (calendar.readonly scope): lists the user's calendars and queries free/busy windows for meeting scheduling.
- Events (calendar.events scope): creates, updates and deletes in Google Calendar the events generated by the CRM, keeping both sides in sync.
12. Limited Use of Google user data
Magnet Customer's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. See Google's full policy. In practice this means that:
- We use the data only to provide and improve user-facing features within the platform — the CRM's email client and calendar.
- We do not transfer this data to third parties, except as necessary to provide the service, to comply with applicable law, or in a corporate transaction with prior notice.
- We do not allow humans to read the data, unless with the user's express consent, for security purposes, to comply with applicable law, or in aggregated and anonymised form for internal operations.
- We do not sell this data, and we do not use it for advertising, for credit assessment or lending purposes, or to train artificial intelligence models.
13. Retention and deletion of Google user data
Data obtained from Google APIs is subject to its own retention rules, independent of those described in section 7:
- Access and refresh tokens are stored encrypted and used only to renew the access authorised by the user.
- When the integration is disconnected in the CRM, or access is revoked in the Google Account, tokens are invalidated immediately and syncing stops.
- Messages and events already synced are removed from the CRM within 30 days of disconnection, or immediately upon request by the user or the account administrator.
- The user may revoke access at any time at https://myaccount.google.com/permissions, without depending on Magnet Customer.
14. Other email and calendar integrations
Besides Google, the platform lets users connect their mailbox and calendar through other providers. As with Google, the connection is always started by the user and can be undone at any time; the data accessed serves only the CRM's email client and calendar, and the retention rules described in section 13 apply to it as well.
- Microsoft 365 / Outlook (Microsoft Graph): we use User.Read to identify the connected account, Mail.ReadWrite to read and organise messages, Mail.Send to send email on the user's behalf, and Calendars.ReadWrite to sync meetings.
- Microsoft Exchange (EWS): same purpose, for organisations running their own Exchange server; authentication uses the credentials provided by the user.
- IMAP and SMTP: generic mailbox connection, authenticated with a password or app password provided by the user.
- iCloud: Apple mailbox connection, authenticated with an app password generated by the user.
- CalDAV: calendar synchronisation for providers compatible with the CalDAV standard.
15. Communication and data integrations
The platform also integrates with services that handle communication with end clients and data exchange with external systems. These integrations are enabled by the contracting account and process data only for the contracted purpose:
- WhatsApp: sending and receiving messages in customer service, through authorised providers. Messages exchanged are recorded in the client history within the CRM.
- SMS and voice (Twilio): messages and calls originated from the platform.
- Transactional email (Mailgun and SendGrid): delivery of notifications and automated communications from the platform.
- Migration from other CRMs (Pipedrive and Piperun): when the account requests a migration, we read data from the source system to bring it into Magnet Customer.
- Electronic signature (ClickSign): sending documents for signature and receiving the result.
- Custodians and financial institutions (BTG Pactual, Safra and XP Investimentos): as described in section 5, for accounts using the financial module.
16. WhatsApp Business data (Meta)
When the contracting account connects a WhatsApp Business number to the platform, Magnet Customer acts as a Tech Provider for Meta Platforms, Inc., processing data solely to enable service between the contracting company and its end customers. We receive from Meta:
- Account identifiers: the phone number ID and the WhatsApp Business account ID (WABA ID).
- An access token, used only to send and receive messages on behalf of the contracting account.
- The content of messages exchanged between the company and its customers: text, media, and delivery and read metadata.
- The phone number and profile name of whoever messages the contracting company.
- This data is used only to deliver the contracted service: displaying conversations in the Contact Center, sending replies, recording history, and linking messages to the corresponding CRM contact. We do not use it for advertising, we do not sell it, and we do not share it with third parties for their own purposes.
17. Limited Use of Meta data
Our use of information received from Meta APIs complies with the Meta Platform Policy and the WhatsApp Business Terms, including the Limited Use requirements. See the full Meta policy. Specifically, data obtained from these APIs:
- Is used only to provide and improve features visible in the platform interface.
- Is not transferred to data brokers, ad networks, or monetization services.
- Is not used to determine creditworthiness or eligibility for credit or insurance.
- Is not used to train artificial intelligence models.
- Is accessed by people only when necessary for support requested by the contracting account, for security reasons, or to comply with a legal obligation.
18. Retention and deletion of WhatsApp data
While the integration is active, conversations are stored in the contracting account's instance, under its control, and can be deleted at any time using the platform's tools. When the number is disconnected, the access token is removed immediately and we stop receiving new messages from that number — history already recorded remains in the instance until the account deletes it. When the contract ends, all instance data, including WhatsApp conversations, is deleted according to the term in section 7. See how to request deletion of your data.
19. Changes to this policy
We may update this Privacy Policy periodically. Significant changes will be communicated by email (to active clients) and through a prominent notice on our website, with a minimum of 15 days notice. The effective date at the top of this page will always reflect the most recent version. Continued use of the platform after the effective date of changes constitutes agreement to the updated terms.
20. Data Protection Officer (DPO) and Contact
To exercise your rights, clarify questions, or report incidents related to personal data processing, please contact our Data Protection Officer (DPO):
- Email: privacidade@magnetcustomer.com
- Company: Magnet Customer Software Ltda. — CNPJ: 52.678.731/0001-94
- Headquarters: Av. Afonso Pena, 2440, Suite 62, Centro, Campo Grande/MS, Brazil, ZIP 79.002-934
- Jurisdiction: Court of Campo Grande/MS, elected to resolve any disputes arising from this policy