AzendyAzendy

Privacy Policy

Last updated: June 17, 2026

This is a courtesy translation. In case of any discrepancy, the Portuguese version of this Policy prevails.

This Privacy Policy describes how Azendy Tecnologia LTDA - ME (Brazilian company registry CNPJ 62.492.990/0001-80), hereinafter "Azendy", collects, uses, shares and protects personal data when providing its management platform for clinics, salons and beauty and wellness businesses ("Platform"), including WhatsApp customer service. We are committed to the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018).

1. Who we are and our role

Azendy acts in two ways: as controller of the registration and usage data of the businesses that contract the Platform; and as processor of the data those businesses handle about their own customers (appointments, customer service, history), following the instructions of each business, which is the controller of that data.

2. Data we collect

We collect the data needed to operate the Platform:

  • Account data: name, email, phone and credentials of the professionals and administrators of the businesses.
  • Data of the business's customers: name, phone, email, appointments, services, amounts and service history — processed on behalf of the business.
  • WhatsApp communication data: phone number, profile name and the content of messages (text and media) exchanged between the customer and the business through the service channel, used exclusively to enable and record that service.
  • Payment data: information needed to process deposits and charges, processed by payment providers (we do not store full card data).
  • Technical data: access logs, device data and measurement cookies/pixels, as described in section 8.

3. What we use the data for

  • Providing and operating the Platform (scheduling, service, orders, billing).
  • Enabling WhatsApp communication between the business and its customers (confirmations, reminders and requested service).
  • Processing payments and issuing tax documents.
  • Preventing fraud, ensuring security and complying with legal obligations.
  • Improving the Platform and providing support.

4. Legal bases (LGPD)

We process personal data on the basis of:

  • performance of a contract and pre-contractual procedures (art. 7, V);
  • compliance with a legal or regulatory obligation (art. 7, II);
  • legitimate interest, where applicable and without overriding the data subject's rights (art. 7, IX);
  • consent, where required — for example, for marketing communications (art. 7, I).

5. Data sharing

We do not sell personal data. We share data only when necessary to operate the Platform, with:

  • Meta Platforms (WhatsApp Business / Cloud API): for delivering and receiving the messages of the service channel, as a processor.
  • Payment providers (e.g. Asaas, Mercado Pago) and tax document providers, to process transactions and tax obligations.
  • Cloud infrastructure providers (e.g. Amazon Web Services), for secure hosting and processing.
  • Authorities, when required by law or court order.

These partners process the data according to our instructions and their own privacy policies.

6. International transfer

Part of the processing and storage may take place on servers located outside Brazil (for example, cloud infrastructure in the United States). In those cases, we adopt appropriate safeguards in accordance with the LGPD.

7. Retention and deletion

We keep data for as long as necessary for the purposes above and to comply with legal obligations. Once processing ends, data is deleted or anonymized, except where retention is permitted by the LGPD.

8. Cookies and measurement

The Platform and the booking pages may use cookies and measurement pixels (e.g. Meta, Google, TikTok) for operation, security and conversion measurement, according to each business's configuration. You can manage cookies in your browser settings.

9. Your rights

As a data subject, under the LGPD (art. 18) you may request:

  • confirmation that processing takes place and access to the data;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion of unnecessary data;
  • portability and information about sharing;
  • withdrawal of consent, where that is the legal basis.

For data processed on behalf of a business (customers of a clinic/salon), we will forward the request to the respective controller where applicable.

10. Security

We adopt technical and organizational measures to protect data against unauthorized access, loss or alteration — including access control, encryption in transit and isolation between businesses (multi-tenant).

11. Changes to this Policy

We may update this Policy from time to time. The date of the last update is shown at the top. Relevant changes will be communicated through the appropriate channels.

12. Contact and Data Protection Officer (DPO)

To exercise your rights or ask questions about privacy, contact our Data Protection Officer:

privacidade@azendy.com.br

Azendy Tecnologia LTDA - ME — CNPJ 62.492.990/0001-80.