Gendaize

Privacy Policy

How Gendaize collects, uses, protects and shares personal data across portals, applications and integrations.

9/6/2026 · 2026-09-06

Data we process

We process data provided by users, organizations and end customers, including identity, contact details, credentials, organization relationships, services, appointments, forms, documents, commercial history and communication preferences.

We may also process technical usage, authentication, log, security-event and integration-token data needed to operate notifications, support and features connected to WhatsApp, email, storage, artificial intelligence and infrastructure providers.

Purposes and legal bases

We process data to authenticate users, perform contracts, provide online scheduling, CRM, forms, documents, notifications, support, billing, security, audit, product improvement and compliance with legal obligations.

Consent is used only where it is the appropriate legal basis and may be withdrawn under applicable law. Acceptance of the Terms is not blanket consent for every processing activity.

Controller and processor

When an organization uses Gendaize to serve its customers, it normally determines the purposes and required data and acts as controller, while Gendaize acts as its technology processor under its instructions.

Gendaize may also act as controller for account, subscription, security, support, billing and legal-compliance data processed for its own purposes.

Sharing and transfers

We share data only as needed to provide the service, including with hosting, database, messaging, storage, email, mapping, artificial intelligence, payment and support providers or where legally required.

We do not sell personal data. Some providers may process data in other countries, subject to the safeguards and lawful transfer mechanisms that apply.

Security and retention

We apply access control, authentication, organization segregation, monitoring and infrastructure practices to reduce risks of unauthorized access, loss or alteration. No environment is completely immune from incidents, failures or data loss.

Users and organizations must protect credentials and devices, restrict and revoke access, keep their systems updated and promptly report any suspected incident. Responsibility for unauthorized access will be assessed according to its cause and each party's participation, including the exclusive fault of the user, organization or a third party.

Where the organization acts as controller of its customers' data, it is responsible for assessing and making legally required notices to the ANPD and data subjects. When acting as processor, Gendaize will notify the organization without undue delay after confirming an incident related to the service and will provide available information and reasonably necessary cooperation.

Where Gendaize acts as controller, it will make legally required notices under its responsibility. The parties must cooperate in investigation, evidence preservation, containment, mitigation and responses to data subjects, without such cooperation changing the liability attributable to each party under law.

We retain data as needed to provide the service, comply with law, resolve disputes, prevent fraud and keep operational records. In the event of an incident, we will take containment, investigation, mitigation and notification measures required according to the risk and applicable law.

Rights and contact

Data subjects may request confirmation, access, correction, portability, sharing information, objection, review of automated decisions, anonymization, restriction or deletion as provided by applicable law.

Requests may require identity verification and may be referred to a customer organization where it controls the data. Use the Data Removal page or contact suporte@gendaize.com.br.

Move your operation into its own portal.

Create an account or talk to the team to understand the best path for your schedule, customers and automations.

Privacy Policy | Gendaize