Otto Privacy Policy
Summary in English · version 1 · in force from September 22, 2026
In a few lines
- The store decides about its customers’ data. Tenet stores and processes that data on the store’s behalf, following its instructions.
- Tenet decides about the data of panel accounts and of people who write to us.
- Data is stored in Brazil, in São Paulo. To travel, messages pass through Meta, the owner of WhatsApp, and through other services outside the country (see which).
- We do not sell data. We do not use conversations to train artificial intelligence, and the suppliers that receive excerpts of them do not either. The assistive AI ships switched off.
- To see, correct or delete your data, talk to the store or write to privacidade@tenet.ia.br. See how.
1. Who we are
Tenet Tecnologia (being incorporated), under the responsibility of André Luiz Bastos Arruda, contact privacidade@tenet.ia.br, develops and operates Otto: a WhatsApp customer service hub used by stores.
The policy covers Otto (the panel at otto.tenet.ia.br or at a store’s own address) and this site, tenet.ia.br. It follows Brazil’s General Data Protection Law, the LGPD (Law No. 13,709/2018).
- Store
- The company that hires Otto to serve its customers over WhatsApp.
- Customer
- The person who talks to the store over WhatsApp.
- Team
- The people the store invites to answer through the Otto panel.
2. Who decides about your data
If you are a store’s customer
The store is the controller of your data. Tenet is the processor: it handles the data on the store’s behalf and only under its instructions (LGPD art. 39). The store should have its own privacy policy.
If you are on a store’s team
Tenet is the controller of your account data: email, name, sign-ins and device notifications. What you do in the service (conversations taken, availability, response time) is recorded for the store, which controls those records.
If you visit this site or write to us
Tenet is the controller.
3. What data we handle
About store customers
- Identification: WhatsApp number, WhatsApp profile name and any name the team notes down.
- Conversations: texts, photos, voice messages, videos and documents exchanged with the store; the transcript of voice messages, when switched on; quoted messages; sent, delivered and read times.
- Service: conversation stage, labels, reminders, who answered and when, and internal team notes the customer does not see.
- Profile: sizes, favourite brands, notes, birthday (day and month only) and the salesperson who usually answers.
- Origin: whether the conversation came from a store ad on Facebook or Instagram (Meta reports the ad and a click code) or from a page on the store’s site (the item, the size and the page address).
- Items: item holds and “let me know when it’s back” requests.
- Contact preferences: requests not to be contacted, with date, channel and who recorded them; reactivation by the store, with who and why; opting out of promotions.
- Technical log: a copy of each notice Meta sends Otto about a store’s number, including the number, profile name and message, used to check deliveries and fix failures. For numbers that belong to no store, only the size and the number’s code are kept. The Portuguese version lists a pending change here.
About panel users
- Account: email, profile name, store and role (owner, supervisor, agent, counter), and the invitation (who invited, and when).
- Sign-ins: date, time, IP address and browser of each sign-in.
- Device notifications: if switched on, the browser push endpoint and the device type.
- Work in the service: messages and notes written, conversations taken, passed on or closed, availability and quick replies. The store controls these records.
About visitors to this site and people who write to us
The site uses no scripts and no audience measurement. It receives only what every web server receives (IP address, browser and page requested), handled by Cloudflare to deliver and protect the site. The only possible cookie is a technical one: when Cloudflare’s bot protection is on, it may set __cf_bm or cf_clearance to tell people from bots. If you write to us, we keep your email, your name and what you wrote.
What Otto does not ask for
Otto does not ask for CPF, address, card data or location, nor for sensitive data such as health, religion or sexual orientation. If a customer sends such data in a conversation, it is stored as part of the message, with the same protection. Stores should not note sensitive data in profiles or notes. Photos sent by the team leave without the location data the camera records.
4. What we use it for
Customer data, on the store’s behalf
To send and receive messages on the store’s WhatsApp number; show each conversation to the right team member and distribute service; show the item, size and stock, and hold items; remember preferences; know whether a conversation came from an ad or the store’s site; honor opt-outs; measure waiting and response times; and keep the service running, investigate failures and prevent abuse.
Team and site data, by Tenet
To give access by invitation and email the sign-in code; notify devices of new messages; protect accounts; answer people who write to us; and comply with the law.
What we do not do
- We do not sell or rent data.
- We do not use customer data for Tenet’s own advertising.
- We do not combine data across stores: the same person talking to two stores is two separate records, and one store cannot see the other’s.
- We do not use conversations to train artificial intelligence models.
- We make no automated decisions about customers. Automatic assignment only chooses which salesperson answers.
5. Legal bases
For customer data, the store, as controller, chooses the legal basis. The most common are preliminary procedures and contract performance (LGPD art. 7, V), legitimate interest (art. 7, IX), consent for WhatsApp promotions (art. 7, I) and the regular exercise of rights (art. 7, VI).
Where Tenet is the controller: legitimate interest for team accounts and access (and contract performance with the person who signs for the store); legal obligation for panel sign-in records (art. 7, II, under art. 15 of Brazil’s Internet Civil Framework); and legitimate interest and the regular exercise of rights for emails and data subject requests.
6. Who we share it with
Each supplier receives only what its part requires.
Always
- Supabase
- Database, media files, panel sign-in and server functions. Database and files in São Paulo, Brazil (AWS region sa-east-1); the server functions that receive and send messages may run in another region, including the United States.
- Meta (WhatsApp Business Platform)
- Carries messages between the customer and the store’s number, and reports which ad a conversation came from. Meta also processes this data on its own account. United States and other countries.
- Cloudflare
- Hosts this site and the panel, protects against attacks and forwards email sent to @tenet.ia.br addresses. Global network, including Brazil.
- Supabase (sign-in email service)
- Sends the panel’s emails (sign-in code and invitation). Country: United States.
Only when switched on
- ElevenLabs
- Transcribes customers’ voice messages; receives only the audio file. It ships switched off, and is turned on only at the store’s request. United States. The Portuguese version lists a pending confirmation about the training setting.
- Anthropic (assistive AI)
- Will suggest replies for the team to review, receiving the excerpt of conversation needed. Not available yet; it will ship switched off, and only the store turns it on. Under Anthropic’s commercial terms, this data does not train its models. United States.
Also
Browser push services (Apple, Google or Mozilla), which deliver a “New message” notice without the customer’s name, number or text; the coding assistant Tenet uses to build Otto and investigate failures (Claude, by Anthropic, United States), through which database excerpts may pass during an investigation, with a pending confirmation noted in Portuguese; Tenet’s mailbox provider (Gmail, by Google, in the United States); the store’s own sales system, from which Otto only reads the catalog (such as Shopify or Bling), never customers or orders; authorities, when the law or a court requires; and, in a sale or merger of Tenet, the data follows with the same protections, and stores are told first.
7. Transfers outside Brazil
The database and files stay in Brazil. Meta, Supabase’s server functions, Cloudflare, the SMTP provider, ElevenLabs and Anthropic process data outside the country, each for the purpose above. For Meta, the transfer is needed to do what the customer asked by writing on WhatsApp (LGPD art. 33, IX). For the others, the intended route is the ANPD standard contractual clauses (Resolution CD/ANPD No. 19/2024); the review of each supplier’s contract is still in progress. Where a contract already includes the clauses, you can ask for them at privacidade@tenet.ia.br, and we send them within 15 days.
8. How long we keep it
- Conversations, media, profile, labels, holds: while the store uses Otto, unless the store or customer asks to delete earlier. After the contract ends, the store has 30 days to ask for a copy, and everything is deleted within 90 days of the end.
- Requests not to be contacted: kept while the store uses Otto, even if everything else is deleted; only the number and the request, so it keeps working.
- Technical logs: copies of Meta’s notices, up to 30 days; the record that prevents duplicate sends, up to 7 days; an automatic cleanup runs every night.
- Team accounts: while the person is active at a store. Once removed, access ends at once and the account (email and profile name) is deleted within 90 days; messages and notes stay in the store’s history. The Portuguese version lists a pending routine here.
- Panel sign-in records: 6 months, as required by art. 15 of the Internet Civil Framework. The Portuguese version lists a pending change here.
- Emails to Tenet and data subject requests: up to 5 years.
- Backups: what is deleted also leaves the automatic backups within 30 days.
9. How we protect it
- Each store sees only its own data: the database checks, on every read, that the requester belongs to that store’s team.
- Column-level permissions: no team member changes a customer’s phone number in the panel; only the store’s admin can undo an opt-out, with a written reason, after the customer writes again.
- Protected phone numbers: the full number shows to the store’s admin, and to the rest of the team only when the conversation must continue outside Otto after WhatsApp’s 24-hour window; never for customers who opted out.
- Private media: photos, voice messages and documents are kept private and opened through temporary links valid for one hour.
- Secrets in a vault: WhatsApp and catalog access keys sit in an encrypted vault, never as plain text in the database.
- Verified messages: every message from Meta has its signature checked before it enters.
- Passwordless, invitation-only sign-in with a one-time code sent by email. The Portuguese version lists a pending change here.
- Encrypted connections (HTTPS) all the way.
- Tenet’s access: only authorized people, for support at the store’s request or to fix failures, with the help of an AI coding assistant (see section 6).
10. Your rights
Under LGPD art. 18 you can ask for confirmation that we process your data; access; correction; anonymization, blocking or deletion of unnecessary, excessive or unlawful data; portability; deletion of data processed with your consent; information about sharing; information about not consenting and its consequences; and withdrawal of consent. You can also object to processing without consent that breaks the law, ask for review of decisions made solely by automated means (art. 20), and complain to Brazil’s data protection authority, the ANPD, at gov.br/anpd, or to a consumer protection body.
11. How to ask, and how to delete your data
If you are a store’s customer
- Ask the store in the WhatsApp conversation itself, for example: “please delete my data”. The store decides about your data and answers for the request.
- Or write to us at privacidade@tenet.ia.br, with the WhatsApp number you used and the store’s name. We forward it to the store within 2 business days and help carry it out.
- What is deleted: conversations with internal notes, media files, transcripts, profile, labels, holds, back-in-stock requests and the technical log linked to your number at that store. Only your number and an opt-out, if you made one, remain, so it keeps working. If the store must keep something by law, it explains what and why.
- Deadline: as soon as possible, and within 15 days of the request. Backups leave the cycle within 30 days.
Otto deletes what is with the store and with Tenet. Messages on your phone and what Meta keeps follow WhatsApp’s rules. To stop receiving messages, ask in the conversation; if you only want to stop promotions, say so.
If you are on a store’s team
Ask the store’s admin to remove your access, and write to privacidade@tenet.ia.br asking for the account to be deleted.
How we respond
We may ask you to confirm the number or email is yours. We answer simply right away when possible, and in full within 15 days (LGPD art. 19). It is free.
12. Security incidents
If an incident affects personal data, we tell the affected store within 48 hours of confirming it, so it can notify the ANPD and its customers within the deadline of Resolution CD/ANPD No. 15/2024. When Tenet is the controller, we give those notices ourselves.
13. Data protection officer
Tenet’s data protection officer is André Luiz Bastos Arruda, at privacidade@tenet.ia.br.
14. Cookies and on-device storage
This site uses no scripts and no measurement tools. The only cookie is Cloudflare’s technical anti-bot cookie, when that protection is on (see section 3).
The Otto panel sets no cookies of its own and may receive the same Cloudflare cookie. It keeps a few things in the browser’s local storage only to work: the session, the email the code was sent to (for up to 1 hour), theme and store color, the chosen store, and screen layout. It also installs a service worker to work as an app and receive notifications. None of this is used for tracking or advertising.
15. Children and teenagers
Otto is a work tool for stores and is not made for children. A store that serves children or teenagers must follow LGPD art. 14 and act in their best interest.
16. Changes to this policy
When the policy changes, the date and version change too. Relevant changes are emailed to stores at least 30 days in advance. Questions: privacidade@tenet.ia.br.