Privacy Policy
LKREBS DESENVOLVIMENTO DE SOFTWARE
Trading as Leal Labs
Last updated: December 9, 2025
Table of Contents
Introduction
This privacy policy ("Privacy Policy") applies to all visitors and users of the leallabs.ai hosted services and websites (collectively, the "Website" or "Websites"), which are offered by LKREBS DESENVOLVIMENTO DE SOFTWARE, CNPJ 43.461.024/0001-50, trading as Leal Labs, and/or any of its affiliates ("Leal Labs" or "we" or "us"). Please read this Privacy Policy carefully. By accessing or using any part of the Websites, you acknowledge you have been informed of and consent to our practices concerning your personal information and data.
This Privacy Policy is designed to comply with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados - LGPD, Law No. 13.709/2018), the European Union General Data Protection Regulation (GDPR), and other applicable data protection laws.
Data Protection
Oversight of Data Security is handled by Leal Labs' Data Protection Officer (Encarregado de Dados). Should you wish to make modifications, deletions, or additions to any personal data you believe to be captured by Leal Labs, or if you have any general security concerns, please contact us at admin@leallabs.ai.
Our Role as Controller and Processor
For information we collect about visitors to our Websites (for example, contact details submitted via forms, cookies, and usage data), Leal Labs generally acts as a data controller.
When a business customer uses Leal Labs to process data about its own customers (for example, WhatsApp conversations, uploaded documents, and CRM-style data), Leal Labs acts as a data processor (or "operator" under LGPD) on behalf of that business. In those cases, the business customer is responsible for providing appropriate privacy notices to its end users and for determining the lawful basis for processing.
What Information Leal Labs Collects and Why
Information from Website Visitors
Like most website operators, Leal Labs collects basic potentially personally identifying information from Website visitors of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request. We collect this information to better understand how visitors use the Website, to improve our Website and experience for visitors, and to monitor the security of the Website. From time to time, Leal Labs may publicly release potentially personally identifying information collected from Website visitors in the aggregate, e.g., by publishing a report on trends in the usage of the Website.
Leal Labs also collects potentially personally-identifying information like Internet Protocol (IP) addresses from visitors. Leal Labs does not use such information to identify or track individual visitors, however. We collect this information to understand how visitors use the Websites, to improve performance and content, and to monitor the security of the Websites.
Personally-Identifying Information
Users of the Websites may choose to interact with Leal Labs in ways that provide us with their personally-identifying information. In some instances, a User ID is generated for form and URL tracking, page views, page pings, and usage counts to ascertain product performance and development. The amount and type of information that Leal Labs gathers depends on the nature of your interaction with us, as well as the amount of information you choose to share. For example, we ask visitors who use our services to provide their full name and email address. We will also collect the information you provide to us in connection with creating an account on the Website.
Visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent them from engaging in certain Website-related activities or being able to access and use certain features and services.
Information Leal Labs Does Not Collect
Leal Labs does not intentionally collect sensitive personal information, such as social security numbers (CPF), genetic data, health information, or religious information. Although Leal Labs does not request or intentionally collect any sensitive personal information, we realize that users might store this kind of information in a Leal Labs instance by pushing it to us through our platform, our libraries, or API. If you store any sensitive personal information on Leal Labs servers, you are consenting to our storage of that information on our servers, which are located in the United States and Brazil.
Important: If you're a child under the age of 13 (or 18 in Brazil, per LGPD requirements for minors), you may not have an account on the Website. Leal Labs does not knowingly collect information from or direct any of our Website or content specifically to children. If we learn or have reason to suspect that a user is under the applicable minimum age, we will close the child's account.
Information from Connected WhatsApp Business Accounts
When a business customer connects their WhatsApp Business account to Leal Labs, we receive information from the WhatsApp Business Platform (Cloud API) operated by Meta. This information ("WhatsApp Data") may include:
- The business's WhatsApp phone number, display name, and account configuration.
- Messages sent to or from the business via WhatsApp, including text, media (such as images, audio, or documents), metadata (such as timestamps, message identifiers, and delivery status), and limited information about the sender (such as their phone number and display name).
- Technical and usage information relating to the WhatsApp Business account (such as templates used, message categories, and delivery metrics).
We process WhatsApp Data on behalf of the business customer, and only to provide our services, which include:
- Delivering and routing messages between the business and its customers;
- Providing automation, analytics, reporting, anomaly monitoring, and quality monitoring;
- Powering AI-assisted replies and "chat with your data" features, when enabled by the business; and
- Maintaining the security and reliability of our services.
We do not use WhatsApp Data to build profiles of individual end users for our own marketing purposes, nor do we sell WhatsApp Data.
Basis for Processing Your Information
Performance of a contract
The use of your information may be necessary to perform the contract that you have with us. For example, if you use our Websites to purchase Leal Labs product subscriptions or services, or request information through our Websites, we will use your information to carry out our obligation to complete and administer that contract or request.
Legitimate interests
We use your information for our legitimate interests, such as to provide you with the best content through our Websites and communications with users, to improve and promote our products and services, and for administrative, security, fraud prevention, and legal purposes.
Consent
We may rely on your consent to use your personal information for certain direct marketing purposes, such as sending you newsletter updates about Leal Labs products. You may withdraw your consent at any time through the unsubscribe feature provided with each marketing email or by contacting us at the addresses given at the end of this Privacy Policy.
Use of Artificial Intelligence
We, along with our service providers and third-party partners, may use artificial intelligence (AI) and machine learning technologies, including generative AI, to process the personal data described above to provide our services.
Leal Labs affirms that it does not use, develop, improve, or train generalized/non-personalized AI and/or ML models by using customer data, either uploaded by the users or pulled through third-party APIs available on the Leal Labs platform. Customer data is not transferred to any third-party AI/ML models or tools unless the customer has explicitly enabled an integration that uses such services. In such cases, the data is processed solely for the features enabled by the customer, and under terms consistent with applicable data protection laws.
How Leal Labs Uses and Protects Personally-Identifying Information
Sharing Your Information
Leal Labs only discloses potentially personally-identifying and personally-identifying information to those of its employees, contractors, and affiliated organizations that (i) need to know that information in order to process it on Leal Labs' behalf or to provide services available on the Website, and (ii) that have agreed not to disclose it to others.
In addition, we use third-party service providers (sub-processors) to help us operate our services. These may include:
- Cloud hosting and infrastructure providers;
- Database, backup, logging, and monitoring providers;
- Email delivery and customer support tools;
- Analytics tools; and
- AI/ML service providers used to deliver AI-assisted features, when enabled.
When you connect a WhatsApp Business account to Leal Labs, WhatsApp and Meta continue to process personal data as described in their own terms and privacy policies in order to deliver the WhatsApp Business Platform. We do not control how WhatsApp or Meta process that data, and you should refer to their privacy policies for more information.
Leal Labs will not rent or sell potentially personally-identifying or personally-identifying information to anyone. Other than to its employees, contractors, and affiliated organizations, as described above, Leal Labs discloses potentially personally-identifying and personally-identifying information only when required to do so by law, or when Leal Labs believes in good faith that disclosure is reasonably necessary to protect the property or rights of Leal Labs, third parties, or the public at large.
Leal Labs takes measures reasonably necessary to protect against the unauthorized access, use, alteration, or destruction of potentially personally-identifying and personally-identifying information. These measures include encryption of data in transit and at rest, access controls, regular security reviews, and monitoring of our systems for potential vulnerabilities and attacks.
International Transfer of Information
The Website is hosted in both the United States and Brazil, and information we collect will be stored and processed on our servers in these locations. Our employees, contractors, and affiliated organizations that process information for us as described above may be located in the United States, Brazil, or in other countries outside of your home country.
Where required under applicable data protection laws (such as the LGPD or GDPR), we will obtain your explicit consent through a clear affirmative action (such as checking a box) before transferring your data internationally. Merely using the Website does not constitute consent to such transfers.
Leal Labs Communications with You
If you are a registered user of the Websites and have supplied your email address, Leal Labs may occasionally send you an email to tell you about security, system information, new features, solicit your feedback, or just keep you up to date with what's going on with Leal Labs and our products. We primarily use our blog to communicate this type of information, so we expect to keep this type of email to a minimum. There's an unsubscribe link located at the bottom of each of the marketing emails we send you so you can stop receiving such emails at any time.
Global Privacy Practices
Information we collect will be stored and processed in the United States and Brazil following this Privacy Policy but we understand that users from other countries may have different expectations and rights about their privacy. For all Website visitors and users, no matter their country of location, we will: provide clear methods of unambiguous, informed consent when we do collect your personal information; only collect the minimum amount of personal data necessary for the purpose it is collected for, unless you choose to provide us more; offer you simple methods of accessing, correcting, or deleting your information that we have collected; and provide Website users notice, choice, accountability, security, and access, and we limit the purpose for processing.
Your Rights Under LGPD (Brazil)
If you are located in Brazil, you are entitled to the following rights under the Lei Geral de Proteção de Dados (LGPD): confirmation of the existence of processing of your personal data; access to your personal data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data; portability of your data to another service or product provider; deletion of personal data processed with your consent; information about public and private entities with which we have shared your data; information about the possibility of denying consent and the consequences of such denial; and revocation of consent.
To exercise your privacy rights under LGPD, you can email us at admin@leallabs.ai. We will respond within 15 days of receiving your request, as required by law.
Your Rights Under GDPR (European Union)
If you are located in the European Union, you are entitled to the following rights about your personal information and data: right of access to your personal data; right to correct any incorrect or incomplete personal data; right to restrict or suspend our processing of your personal data; right to complain to a supervisory authority; right of data portability; right to withdraw consent at any time; right to object to processing; right to object to direct marketing; and right of erasure ("right to be forgotten").
If you submit a Subject Access Request under the GDPR, we are obligated to respond within 30 days of receiving your request. If your request is particularly complex, we may extend this period and will inform you of the extension and the reasons for the delay within the initial 30-day period.
Data Subject Rights for Business Customer Data
If we receive a data subject request from an individual whose personal data we process on behalf of a business customer (for example, a WhatsApp user messaging that business), we will either respond on behalf of the business in accordance with our agreement or forward the request to that business so that it can respond, as required by applicable law and our obligations under Meta's Terms.
Data Retention and Deletion
If you already have an account on the Websites, you may access, update, alter, or delete your basic user profile information by logging into your account and updating profile settings.
Leal Labs will retain your information for as long as your account is active or as needed to perform our contractual obligations, provide you services through the Website, to comply with legal obligations, resolve disputes, preserve legal rights, or enforce our agreements.
User Data Deletion
Leal Labs provides users with the ability to request the deletion of their personal data and account at any time. You can submit a data deletion request through our platform's account settings or by contacting us at admin@leallabs.ai with the subject line "Data Deletion Request". Upon receiving and verifying your request, we will permanently delete your account and all associated personal data from our databases. Please note that once deleted, this action cannot be undone and your data cannot be recovered. We will process your deletion request within 15 days (for users in Brazil under LGPD) or 30 days (for users in the European Union under GDPR) of receiving your verified request.
Contacting Leal Labs About Your Privacy
If you have questions or concerns about the way we are handling your information, or would like to exercise your privacy rights, please email us with the subject line "Privacy Concern" at admin@leallabs.ai. We will respond within 15 days (for LGPD requests) or 30 days (for GDPR requests) of receiving your message at the latest.
Company Name
LKREBS DESENVOLVIMENTO DE SOFTWARE
Trading Name
Leal Labs
CNPJ
43.461.024/0001-50
Data Protection Officer
Luciano Krebs
Address
Av. Paulista, 1636, Conj. 4, CEP 01310-200, Bela Vista, São Paulo - SP, Brazil
Contact Email
admin@leallabs.aiPrivacy Policy Changes
Although most changes are likely to be minor, Leal Labs may change its privacy policy from time to time, and in Leal Labs' sole discretion. We may also provide notification to users who have provided us email addresses of material changes to this Privacy Policy through our Website. Leal Labs encourages visitors to frequently check this page for any minor changes to its Privacy Policy. Your continued use of this site after any change in this Privacy Policy will constitute your acceptance of such change.
Last edited: December 9, 2025
Your privacy is important to us
Have questions about your data? We're here to help.