Privacy Policy

Version 1.1 – Last updated: June 19, 2026


1. General Information

1.1 Controller Identification

Legal Name: The Siders AI LTDA Address: 10a Avenida Paulista, 1106, Sala 01 Andar 16 - Bela Vista, São Paulo - SP, 01.310-914
E-mail: support@usepandle.com

1.2 Data Protection Officer (DPO)

Name: Leonardo Jacomussi E-mail: dpo@usepandle.com Role: Responsible for guiding employees and controlling personal data processing activities

1.3 Purpose of this Policy

This Privacy Policy describes how Pandle collects, uses, stores, and protects personal information from users of our AI-based conversation automation platform, in compliance with the General Data Protection Law (LGPD - Law 13.709/2018).


2. Data Collected

2.1 Personal Identification Data

  • Full name
  • E-mail address
  • Phone number
  • Account information (username and encrypted password)

2.2 Platform Usage Data

  • Conversations and messages processed
  • Engagement metrics
  • Configuration preferences
  • History of interactions with chatbots

2.3 Technical Data

  • IP address
  • Device and browser information
  • Cookies and similar technologies
  • Access and security logs

2.4 Third-Party Data

  • Information from integrations with Meta (WhatsApp, Instagram, Facebook)
  • Data from third-party APIs authorized by the user

2.5 Social Login Data (Facebook and other providers)

When you use social login, we may process:

  • email (Facebook): for account authentication, essential security communications, and access recovery.
  • public_profile (Facebook): for basic account identification and minimal experience personalization (for example, name and avatar).
  • Social account identifiers and OAuth tokens: to maintain the session and the technical link with the provider.

3.1 Service Provision

  • Legal Basis: Performance of a contract (Art. 7, V, LGPD)
  • Purpose: Provide conversation automation features
  • Data: Identification data, platform usage data, and technical data

3.2 Processing via Artificial Intelligence

  • Legal Basis: Specific consent (Art. 7, I, LGPD)
  • Purpose: Improve answer quality through natural language processing
  • Justification: The user gives free, informed, and unequivocal consent for this specific processing
  • Revocation: Available at any time through the settings panel
  • Data: Conversation and message content for semantic analysis

3.3 Security and Fraud Prevention

  • Legal Basis: Legitimate interest (Art. 7, IX, LGPD)
  • Purpose: Protect the platform and users against malicious activities
  • Data: Access logs, technical data, and behavioral data

3.4 Marketing Communications

  • Legal Basis: Consent (Art. 7, I, LGPD)
  • Purpose: Send newsletters, product updates, and relevant offers
  • Data: Name, e-mail, and communication preferences

4. Data Sharing

4.1 Operators and Service Providers

We use operators/subprocessors to enable authentication, infrastructure, security, metrics, and transactional communications. The table below summarizes the main providers and purposes.

FornecedorFinalidade principalCategories of data involved
Meta PlatformsSocial login and Meta integrationsemail, public_profile, social identifiers and integration metadata
Google / Apple (OAuth, when enabled)Social loginAccount identifiers, e-mail, and basic profile
VercelApplication hostingTechnical data, operational logs, and application traffic
Banco de dados PostgreSQL (provedor contratado)Account, session, and product data persistenceAccount data, session data, and functional platform data
Storage S3 compatível (provedor contratado)File/image storageFiles uploaded by the user and technical metadata
Cloudflare (Turnstile)Security, abuse prevention, and anti-bot validationIP, verification token, and request technical data
Upstash (Redis)Rate limiting, temporary flow states, and abuse protectionIP, e-mail, and temporary technical metadata
PostHogProduct metrics and analytics (with consent for non-essential categories)Usage events and product identifiers
SentryError monitoring and stabilityError telemetry, technical context, and pseudonymized identifiers
ResendSending transactional e-mailsE-mail, name, and minimal transactional content
Novu (when enabled)NotificationsUser identifier and notification payload
Typebot (when enabled)Collection of requests in external formsData voluntarily submitted in forms
StripePayment and subscription processingSubscription data and billing identifiers
Serviço externo de workflow (when enabled)Asynchronous processing of content generation tasksFunctional automation payload (without user credentials in plain text)

4.2 International Transfers

4.2.1 Destinations and Adequacy

  • Destinations: United States and/or European Union, depending on the provider used
  • Status: Country without an adequacy decision by the ANPD
  • Date of last assessment: June 19, 2026

4.2.2 Implemented Safeguards

  • Standard Contractual Clauses (SCCs) - Version 2021 approved by the European Commission
  • SOC 2 Type II certification of the recipients
  • Suspension clauses in the event of unfavorable regulatory changes
  • Semiannual assessment of country-specific risks
  • Notification mechanisms in case of inappropriate government requests

5. Data Retention

5.1 Timeframes by Category

  • Active account data: Throughout the contractual term
  • Post-termination data: 24 months (for backup and auditing)
  • Security logs: 12 months (to meet technical security requirements)
  • Marketing data: 36 months or until consent is revoked, whichever occurs first

5.2 Review and Update

  • Frequency: Annual assessment of necessity and proportionality
  • Criteria: Original purpose, legal relevance, contractual requirements
  • Deletion: Secure and irreversible deletion after the retention periods expire

6. Data Subject Rights

6.1 Rights Guaranteed by the LGPD

Users have the following rights regarding their personal data:

  1. Confirmation of the existence of processing
  2. Access to data
  3. Correction of incomplete, inaccurate, or outdated data
  4. Anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data
  5. Data portability to another service or product provider
  6. Deletion of data processed with the data subject’s consent
  7. Information about shared data use and purposes
  8. Information about the possibility of denying consent and the consequences of refusal
  9. Revocation of consent

6.2 How to Exercise Your Rights

  • Access: Settings panel → AI processing
  • Effect: Immediate cessation of processing for AI purposes
  • Impact: Possible reduction in the quality of automated responses

7. Data Security

7.1 Technical Measures

  • End-to-end encryption for data in transit
  • AES-256 encryption for data at rest
  • Mandatory multi-factor authentication
  • Role-based access controls (RBAC)
  • Continuous monitoring of suspicious activities

7.2 Organizational Measures

  • Regular training of the team in data protection
  • Internal information security policies
  • Periodic compliance audits
  • Incident response plan for security incidents

7.3 Incident Notification

  • To the ANPD: Up to 72 hours after becoming aware of a high-risk incident
  • To data subjects: Immediate communication in the event of high risk to rights and freedoms

8. Cookies and Similar Technologies

8.1 Types of Cookies Used

  • Essential: Necessary for platform operation
  • Analytics: For improving the user experience
  • Marketing: For content personalization (subject to consent)
  • Cookie banner: Presented on the first visit
  • Granular settings: Available in the user panel
  • Withdrawal of consent: At any time through the settings

For detailed information about the cookies we use, their purposes, durations, and how to manage them, see our Cookie Policy.


9. Rights of Minors

9.1 Policy for Minors

  • Minimum age: 16 years old to use the platform
  • Parental consent: Mandatory for minors between 13 and 16 years old
  • Verification: Age validation process implemented

9.2 Specific Protections

  • Minimal collection of minors’ data
  • Prohibition of direct marketing to minors under 16
  • Regular review of privacy settings

10. Applicable Law and Venue

10.1 Applicable Law

This Policy is governed by Brazilian law, especially:

  • Law 13.709/2018 (LGPD)
  • Brazilian Civil Rights Framework for the Internet (Law 12.965/2014)
  • Consumer Defense Code

10.2 Competent Venue

The venue of the District of São Paulo - SP is elected to resolve any disputes related to this Privacy Policy.


11. Updates to this Policy

11.1 Update Process

  • Prior notice: 30 days before substantial changes
  • Communication channels: E-mail, dashboard, and website
  • Version history: Available at [link to history]

11.2 Effective Date

  • Minor changes: Immediate effect with notice
  • Substantial changes: After a 30-day notice period

12. Contact

12.1 Questions about this Policy

Data Protection Officer:

Leonardo Jacomussi
E-mail: dpo@usepandle.com

12.2 ANPD Ombudsman

If not satisfactorily resolved, you may contact the National Data Protection Authority:

Website: https://www.gov.br/anpd/pt-br
E-mail: atendimento@anpd.gov.br


Electronic document valid without the need for a physical signature

Pandle - All rights reserved © 2026