Privacy Policy
Version 1.1 – Last updated: June 19, 2026
1. General Information
1.1 Controller Identification
Legal Name: The Siders AI LTDA
Address: 10a Avenida Paulista, 1106, Sala 01 Andar 16 - Bela Vista, São Paulo - SP, 01.310-914
E-mail: support@usepandle.com
1.2 Data Protection Officer (DPO)
Name: Leonardo Jacomussi E-mail: dpo@usepandle.com Role: Responsible for guiding employees and controlling personal data processing activities
1.3 Purpose of this Policy
This Privacy Policy describes how Pandle collects, uses, stores, and protects personal information from users of our AI-based conversation automation platform, in compliance with the General Data Protection Law (LGPD - Law 13.709/2018).
2. Data Collected
2.1 Personal Identification Data
- Full name
- E-mail address
- Phone number
- Account information (username and encrypted password)
2.2 Platform Usage Data
- Conversations and messages processed
- Engagement metrics
- Configuration preferences
- History of interactions with chatbots
2.3 Technical Data
- IP address
- Device and browser information
- Cookies and similar technologies
- Access and security logs
2.4 Third-Party Data
- Information from integrations with Meta (WhatsApp, Instagram, Facebook)
- Data from third-party APIs authorized by the user
2.5 Social Login Data (Facebook and other providers)
When you use social login, we may process:
email(Facebook): for account authentication, essential security communications, and access recovery.public_profile(Facebook): for basic account identification and minimal experience personalization (for example, name and avatar).- Social account identifiers and OAuth tokens: to maintain the session and the technical link with the provider.
3. Purposes and Legal Basis
3.1 Service Provision
- Legal Basis: Performance of a contract (Art. 7, V, LGPD)
- Purpose: Provide conversation automation features
- Data: Identification data, platform usage data, and technical data
3.2 Processing via Artificial Intelligence
- Legal Basis: Specific consent (Art. 7, I, LGPD)
- Purpose: Improve answer quality through natural language processing
- Justification: The user gives free, informed, and unequivocal consent for this specific processing
- Revocation: Available at any time through the settings panel
- Data: Conversation and message content for semantic analysis
3.3 Security and Fraud Prevention
- Legal Basis: Legitimate interest (Art. 7, IX, LGPD)
- Purpose: Protect the platform and users against malicious activities
- Data: Access logs, technical data, and behavioral data
3.4 Marketing Communications
- Legal Basis: Consent (Art. 7, I, LGPD)
- Purpose: Send newsletters, product updates, and relevant offers
- Data: Name, e-mail, and communication preferences
4. Data Sharing
4.1 Operators and Service Providers
We use operators/subprocessors to enable authentication, infrastructure, security, metrics, and transactional communications. The table below summarizes the main providers and purposes.
| Fornecedor | Finalidade principal | Categories of data involved |
|---|---|---|
| Meta Platforms | Social login and Meta integrations | email, public_profile, social identifiers and integration metadata |
| Google / Apple (OAuth, when enabled) | Social login | Account identifiers, e-mail, and basic profile |
| Vercel | Application hosting | Technical data, operational logs, and application traffic |
| Banco de dados PostgreSQL (provedor contratado) | Account, session, and product data persistence | Account data, session data, and functional platform data |
| Storage S3 compatível (provedor contratado) | File/image storage | Files uploaded by the user and technical metadata |
| Cloudflare (Turnstile) | Security, abuse prevention, and anti-bot validation | IP, verification token, and request technical data |
| Upstash (Redis) | Rate limiting, temporary flow states, and abuse protection | IP, e-mail, and temporary technical metadata |
| PostHog | Product metrics and analytics (with consent for non-essential categories) | Usage events and product identifiers |
| Sentry | Error monitoring and stability | Error telemetry, technical context, and pseudonymized identifiers |
| Resend | Sending transactional e-mails | E-mail, name, and minimal transactional content |
| Novu (when enabled) | Notifications | User identifier and notification payload |
| Typebot (when enabled) | Collection of requests in external forms | Data voluntarily submitted in forms |
| Stripe | Payment and subscription processing | Subscription data and billing identifiers |
| Serviço externo de workflow (when enabled) | Asynchronous processing of content generation tasks | Functional automation payload (without user credentials in plain text) |
4.2 International Transfers
4.2.1 Destinations and Adequacy
- Destinations: United States and/or European Union, depending on the provider used
- Status: Country without an adequacy decision by the ANPD
- Date of last assessment: June 19, 2026
4.2.2 Implemented Safeguards
- Standard Contractual Clauses (SCCs) - Version 2021 approved by the European Commission
- SOC 2 Type II certification of the recipients
- Suspension clauses in the event of unfavorable regulatory changes
- Semiannual assessment of country-specific risks
- Notification mechanisms in case of inappropriate government requests
5. Data Retention
5.1 Timeframes by Category
- Active account data: Throughout the contractual term
- Post-termination data: 24 months (for backup and auditing)
- Security logs: 12 months (to meet technical security requirements)
- Marketing data: 36 months or until consent is revoked, whichever occurs first
5.2 Review and Update
- Frequency: Annual assessment of necessity and proportionality
- Criteria: Original purpose, legal relevance, contractual requirements
- Deletion: Secure and irreversible deletion after the retention periods expire
6. Data Subject Rights
6.1 Rights Guaranteed by the LGPD
Users have the following rights regarding their personal data:
- Confirmation of the existence of processing
- Access to data
- Correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data
- Data portability to another service or product provider
- Deletion of data processed with the data subject’s consent
- Information about shared data use and purposes
- Information about the possibility of denying consent and the consequences of refusal
- Revocation of consent
6.2 How to Exercise Your Rights
- User portal: Privacy settings in the dashboard
- E-mail: dpo@usepandle.com
- Response time: Up to 15 calendar days
- Data deletion request: usepandle.com/legal/data-deletion
6.3 Revocation of Consent for AI
- Access: Settings panel → AI processing
- Effect: Immediate cessation of processing for AI purposes
- Impact: Possible reduction in the quality of automated responses
7. Data Security
7.1 Technical Measures
- End-to-end encryption for data in transit
- AES-256 encryption for data at rest
- Mandatory multi-factor authentication
- Role-based access controls (RBAC)
- Continuous monitoring of suspicious activities
7.2 Organizational Measures
- Regular training of the team in data protection
- Internal information security policies
- Periodic compliance audits
- Incident response plan for security incidents
7.3 Incident Notification
- To the ANPD: Up to 72 hours after becoming aware of a high-risk incident
- To data subjects: Immediate communication in the event of high risk to rights and freedoms
8. Cookies and Similar Technologies
8.1 Types of Cookies Used
- Essential: Necessary for platform operation
- Analytics: For improving the user experience
- Marketing: For content personalization (subject to consent)
8.2 Consent Management
- Cookie banner: Presented on the first visit
- Granular settings: Available in the user panel
- Withdrawal of consent: At any time through the settings
For detailed information about the cookies we use, their purposes, durations, and how to manage them, see our Cookie Policy.
9. Rights of Minors
9.1 Policy for Minors
- Minimum age: 16 years old to use the platform
- Parental consent: Mandatory for minors between 13 and 16 years old
- Verification: Age validation process implemented
9.2 Specific Protections
- Minimal collection of minors’ data
- Prohibition of direct marketing to minors under 16
- Regular review of privacy settings
10. Applicable Law and Venue
10.1 Applicable Law
This Policy is governed by Brazilian law, especially:
- Law 13.709/2018 (LGPD)
- Brazilian Civil Rights Framework for the Internet (Law 12.965/2014)
- Consumer Defense Code
10.2 Competent Venue
The venue of the District of São Paulo - SP is elected to resolve any disputes related to this Privacy Policy.
11. Updates to this Policy
11.1 Update Process
- Prior notice: 30 days before substantial changes
- Communication channels: E-mail, dashboard, and website
- Version history: Available at [link to history]
11.2 Effective Date
- Minor changes: Immediate effect with notice
- Substantial changes: After a 30-day notice period
12. Contact
12.1 Questions about this Policy
Data Protection Officer:
Leonardo Jacomussi
E-mail: dpo@usepandle.com
12.2 ANPD Ombudsman
If not satisfactorily resolved, you may contact the National Data Protection Authority:
Website: https://www.gov.br/anpd/pt-br
E-mail: atendimento@anpd.gov.br
Electronic document valid without the need for a physical signature
Pandle - All rights reserved © 2026