Back to ZildaChat

Privacy Policy

ZildaChat is committed to protecting your privacy and personal data. This policy explains how we collect, use, store, and protect your information in compliance with LGPD (Brazil), GDPR (EU), CCPA (California), and other applicable data protection laws.

LGPD CompliantGDPR CompliantCCPA CompliantISO 27001 Standards

Last updated: April 28, 2025 · Effective: April 28, 2025

11. Overview & Scope

Who we are

AZ Technology Soluções Digitais LTDA, CNPJ 27607249000116, operator of ZildaChat ("we", "our", "us"), is an AI-powered chat platform. This Privacy Policy applies to all users of our website, mobile applications, and services globally.

This Privacy Policy governs the collection, processing, storage, and transfer of personal data by ZildaChat. By using our services, you acknowledge that you have read and understood this policy.

This policy applies to:

  • All visitors to our website (zildachat.ai)
  • Registered users of the ZildaChat platform
  • Users of our API and developer tools
  • Business customers and their end users

22. Data We Collect

Account Data

  • Full name
  • Email address
  • Password (hashed, never stored in plain text)
  • Profile picture (optional)
  • Account creation date

Conversation Data

  • Chat messages and AI responses
  • Conversation history and metadata
  • Files and attachments you share
  • Feedback and ratings you provide

Technical Data

  • IP address (anonymized after 90 days)
  • Browser type and version
  • Operating system
  • Device identifiers
  • Session tokens (encrypted)

Usage Data

  • Features accessed and frequency
  • Error logs (anonymized)
  • Performance metrics
  • Referral source (anonymized)

⚠️ Sensitive Data

We do NOT intentionally collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, or financial information.

44. How We Use Your Data

We use your personal data strictly for the following purposes, applying the principle of data minimization:

Service Delivery: Providing AI chat responses, managing your account, and processing your requests
Security & Fraud Prevention: Detecting and preventing unauthorized access, abuse, and fraudulent activity
Service Improvement: Analyzing aggregated, anonymized usage patterns to improve AI quality and UX
Legal Compliance: Meeting our obligations under applicable laws and responding to lawful requests
Customer Support: Responding to your inquiries, bug reports, and support requests
Communications: Sending essential service notifications (never marketing without explicit consent)

🚫 We NEVER:

  • • Sell your personal data to third parties
  • • Use your conversations to train AI models without explicit opt-in consent
  • • Share your data with advertisers or data brokers
  • • Use your data for automated decision-making that produces legal effects without human review

55. Data Sharing & Third Parties

We share your data only in limited, controlled circumstances. All third-party processors are bound by Data Processing Agreements (DPAs):

Recipient

AI Infrastructure Providers

Purpose

Processing AI requests

Safeguard

DPA + encryption in transit and at rest

Recipient

Cloud Hosting (Supabase/AWS)

Purpose

Data storage and infrastructure

Safeguard

SOC 2 Type II certified, data encrypted at rest (AES-256)

Recipient

Analytics (anonymized only)

Purpose

Service improvement metrics

Safeguard

No PII transmitted, IP anonymization enabled

Recipient

Legal Authorities

Purpose

Compliance with court orders

Safeguard

Only when legally required; we notify users when permitted by law

66. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence. When transferring data internationally, we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where the destination country provides equivalent protection
  • Binding Corporate Rules (BCRs) for intra-group transfers
  • ANPD-approved mechanisms for transfers from Brazil under LGPD Art. 33

77. Data Retention

Account dataDuration of account + 30 days after deletion request
Conversation historyUntil you delete it, or 2 years of inactivity
Security logs12 months (legal obligation)
Anonymized analyticsUp to 36 months
IP addressesAnonymized after 90 days
Backup copiesDeleted within 90 days of original deletion

88. Your Rights

Under LGPD, GDPR, and other applicable laws, you have the following rights regarding your personal data:

Right of Access

Request a copy of all personal data we hold about you

Right to Rectification

Correct inaccurate or incomplete personal data

Right to Erasure

Request deletion of your personal data ("right to be forgotten")

Right to Restriction

Restrict processing of your data in certain circumstances

Right to Portability

Receive your data in a structured, machine-readable format

Right to Object

Object to processing based on legitimate interests or for direct marketing

Right vs. Automation

Not be subject to solely automated decisions with significant effects

Right to Withdraw Consent

Withdraw consent at any time without affecting prior processing

How to exercise your rights

Submit a request to privacy@zildachat.ai or through your account Settings → Privacy. We will respond within 15 days (LGPD) or 30 days (GDPR). Identity verification may be required.

99. Security Measures

We implement industry-leading security measures to protect your data:

Encryption

AES-256 at rest, TLS 1.3 in transit. All passwords hashed with bcrypt.

Access Control

Zero-trust architecture. Role-based access control (RBAC). MFA required for all staff.

Monitoring

24/7 intrusion detection, anomaly detection, and automated threat response.

Secure Development

OWASP Top 10 compliance, regular penetration testing, code security reviews.

Data Isolation

Strict tenant isolation. Your data is never mixed with other users' data.

Breach Response

Notification within 72h (GDPR) / 2 business days (LGPD) of confirmed breach.

1010. Children's Privacy

Age Restriction

ZildaChat is not directed to children under the age of 13 (or 16 in the EU/EEA under GDPR). We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us at privacy@zildachat.ai.

1111. California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have additional rights:

  • Right to Know: Request disclosure of personal information collected, used, disclosed, or sold
  • Right to Delete: Request deletion of personal information we have collected
  • Right to Opt-Out: Opt out of the "sale" or "sharing" of personal information (we do not sell data)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Limit: Limit use of sensitive personal information
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

To submit a CCPA request, contact us at privacy@zildachat.ai. We will verify your identity before processing requests.

1212. Brazilian Residents (LGPD)

Under the Lei Geral de Proteção de Dados (LGPD), data subjects in Brazil have the following rights (Art. 18):

Art. 18, IConfirmação da existência de tratamento de dados pessoais
Art. 18, IIAcesso aos dados pessoais tratados
Art. 18, IIICorreção de dados incompletos, inexatos ou desatualizados
Art. 18, IVAnonimização, bloqueio ou eliminação de dados desnecessários
Art. 18, VPortabilidade dos dados a outro fornecedor de serviço
Art. 18, VIEliminação dos dados pessoais tratados com consentimento
Art. 18, VIIInformação sobre compartilhamento com entidades públicas e privadas
Art. 18, VIIIInformação sobre a possibilidade de não fornecer consentimento
Art. 18, IXRevogação do consentimento
DPO (Encarregado de Dados): To exercise your rights, contact our Data Protection Officer at dpo@zildachat.ai. You may also file complaints with the ANPD at www.gov.br/anpd.

1313. Policy Changes

We may update this Privacy Policy periodically. When we make material changes, we will:

  • Notify you via email (if you have an account)
  • Display a prominent notice on our website
  • Update the "Last updated" date at the top of this policy
  • For significant changes, request renewed consent where required by law

Continued use of our services after the effective date constitutes acceptance of the updated policy.

1414. Contact & Data Protection Officer

Privacy Team

privacy@zildachat.ai

AZ Technology Soluções Digitais LTDA · CNPJ 27607249000116

Response within 15–30 days

Data Protection Officer (DPO)

dpo@zildachat.ai

LGPD Encarregado de Dados

GDPR Data Protection Officer

You also have the right to lodge a complaint with your local supervisory authority: ANPD (Brazil), ICO (UK), CNIL (France), or your national data protection authority.

© 2025–2026 AZ Technology Soluções Digitais LTDA · CNPJ 27607249000116. All rights reserved.

We value your privacy

We use cookies to enhance your experience, analyze site usage, and assist in our marketing efforts. By clicking "Accept All", you consent to our use of cookies. Cookie Policy · Privacy Policy

🇺🇸

We detected you're in United States. Use English?