Privacy Policy
eztz desk — Business Operations Platform
Last updated: May 14, 2026
Company responsible for the Platform: Ezituuz Company LTDA
Product: eztz desk — Business Operations Platform
Privacy contact: [email protected]
This Privacy Policy explains how Ezituuz Company LTDA ("Ezituuz", "we" or "our") handles personal data in the context of the eztz desk Platform, a business-operations technology solution used by companies to manage conversations, contacts, support tickets, automations, integrations and reports.
This Policy has been drafted in accordance with Brazil's General Data Protection Law — LGPD, Law No. 13,709/2018, and also takes into account good practices and requirements applicable to integrations with third-party platforms, including the WhatsApp Business Platform, Cloud API, Facebook, Instagram, Messenger and other Meta technologies, when enabled by the contracting customer. This document is provided for the international audience of our website; where discrepancies exist, the Portuguese-language version governed by Brazilian law shall prevail for customers operating under Brazilian jurisdiction.
1. Who we are
Ezituuz Company LTDA is a technology company that develops, licenses, maintains and supports the eztz desk Platform.
eztz desk allows contracting companies to organize support, receive and send messages, manage users, configure queues, track conversations, connect digital channels and, when applicable, integrate their operation with third-party APIs, such as the WhatsApp Business Platform, email, Telegram, Facebook, Instagram, Messenger and other compatible services.
2. Roles of Ezituuz and the customer under the LGPD
In the context of the eztz desk Platform, there are two main roles:
Contracting customer or company using the Platform: as a rule, is the Data Controller of the personal data of its end consumers, leads, contacts, customers, staff, agents and users. The customer decides which data is collected, for which purposes it is used, which messages are sent, which legal bases are adopted and which support channels are used.
Ezituuz: as a rule, acts as the Data Processor, processing data on behalf of the contracting customer in order to provide, operate, maintain, protect, update and support the eztz desk Platform.
Ezituuz does not determine which end consumers will be contacted by the customer, does not define the legal basis used by the customer, does not purchase contact lists, does not sell databases, does not trade personal data, does not perform advertising profiling of the customer's end consumers, and does not use the content of conversations for its own advertising or data resale.
Ezituuz may act as an independent Data Controller only with respect to data necessary for its own business relationship with the contracting customer, such as commercial registration, billing, collections, support, account security, fraud prevention, compliance with legal obligations and administrative management of the contract.
3. Who this Policy applies to
This Policy applies to:
- companies that contract or use eztz desk;
- administrators, agents and users registered by the customer on the Platform;
- end consumers, leads, contacts or customers who interact with a company using eztz desk via WhatsApp, email, Telegram, Messenger, Instagram, chat, forms or another integrated channel;
- visitors of websites, pages, forms or digital channels linked to Ezituuz or eztz desk.
When you talk to a company that uses eztz desk, that company is primarily responsible for explaining how it handles your personal data. Ezituuz acts as the technology provider of the platform used by that company.
4. Personal data that may be processed
Depending on how the contracting customer uses it, eztz desk may process the following categories of personal data:
- name;
- phone number;
- email;
- user identifiers on digital channels;
- profile picture, when made available by the integrated channel;
- messages sent and received;
- audio, images, videos, documents and media sent by the data subject or the customer;
- support history;
- tags, queues, status, internal notes and classifications made by the customer;
- interaction data, such as date, time, channel, responsible agent and conversation events;
- technical metadata, such as logs, IP address, access records, session identifiers, authentication events and device/browser information, when applicable;
- data freely entered by the customer, its users, or the end consumer themselves during support.
Ezituuz does not recommend that customers request or store sensitive data or high-risk information through the Platform, except when strictly necessary, permitted by law, supported by an adequate legal basis and accompanied by reinforced security measures.
5. Sensitive data, documents and restricted information
Sensitive personal data includes information about racial or ethnic origin, religious belief, political opinion, union membership, health data, sexual life, or genetic or biometric data linked to a natural person.
The contracting customer must avoid requesting, sending, storing or processing, through eztz desk or integrated channels, sensitive personal data, identification documents, full payment card numbers, complete financial data, health data, biometric data, data of children or teenagers, or other high-risk information, except where there is a legitimate need, an adequate legal basis and reinforced protection measures.
Ezituuz does not define which data is requested by the customer from end consumers and will not be responsible for sensitive data, documents, media or restricted information freely entered by the customer, its users, agents, administrators or end consumers without direct guidance or control from Ezituuz.
6. Purposes of data processing
Ezituuz, acting as a data processor, processes personal data for the following purposes:
- making the eztz desk Platform available and operating it;
- enabling the sending, receiving, routing, organization and storage of messages;
- enabling multichannel support;
- organizing contacts, conversations, queues, users, permissions, tags and reports;
- executing automations configured by the customer;
- integrating the Platform with third-party APIs and services enabled by the customer;
- authenticating users and controlling access;
- providing technical support;
- performing maintenance, updates, fixes and security improvements;
- maintaining technical logs and records necessary for operation, technical auditing and fraud prevention;
- performing backup, recovery and operational continuity, when applicable;
- complying with legal, regulatory, contractual obligations or orders from competent authorities.
Ezituuz does not use the customer's end consumers' data to sell databases, for its own behavioral advertising, data enrichment, creation of independent commercial profiles, or sharing with third parties for marketing purposes.
7. Legal bases
When Ezituuz acts as a data processor, the contracting customer is responsible for defining and documenting the legal basis applicable to the processing of personal data of its end consumers, leads, contacts, customers and users.
Legal bases may include, as applicable, consent, performance of a contract, legitimate interest, compliance with a legal or regulatory obligation, regular exercise of rights, or other grounds set forth in the LGPD.
When Ezituuz acts as an independent Data Controller with respect to data of its own corporate customers, it may process data based on performance of a contract, compliance with a legal obligation, legitimate interest, fraud prevention, regular exercise of rights and other bases provided for in the LGPD.
8. Integration with WhatsApp Business Platform, Meta and third-party channels
eztz desk may offer a technical integration with the WhatsApp Business Platform, Cloud API, Facebook, Instagram, Messenger and other Meta technologies, subject to technical availability, granted permissions, app approval, customer configuration and applicable Meta rules.
When operating the integration with the WhatsApp Business Platform, Ezituuz acts as a technical software provider, technology integrator or Tech Provider, as applicable, providing technical means for the customer to connect its business assets, numbers, accounts, permissions, webhooks, templates, support, automations and messages to the eztz desk Platform.
Ezituuz does not own WhatsApp, Facebook, Instagram or Messenger, does not represent Meta, does not speak on behalf of Meta, does not control Meta's decisions, and does not guarantee app approval, permissions, templates, numbers, accounts, number quality, sending limits, reversal of bans, pricing, permanent availability, API maintenance or indefinite continuity of the integrations.
The customer is solely responsible for maintaining a valid business account, Business Portfolio, WhatsApp Business Account, number, domain, documents, permissions, verifications, payment methods, business data and other assets required by Meta, correctly, up to date and in compliance with applicable terms, policies and guidelines.
9. Opt-in, opt-out and communications via WhatsApp
The contracting customer is solely responsible for obtaining, recording, evidencing and maintaining a valid legal basis, consent, opt-in or other applicable authorization for sending messages to end consumers.
For communications initiated by the customer via WhatsApp, the customer must ensure that the data subject:
- previously provided their phone number;
- authorized receiving communications via WhatsApp;
- was clearly informed about the nature of the messages they may receive;
- received a simple, effective and accessible means to revoke their authorization or request that messages stop.
The customer must keep adequate evidence of opt-in, including, where applicable, the source of the authorization, date and time, collection channel, stated purpose, authorized message category, identification of the data subject and revocation mechanism.
The customer must immediately honor opt-out, block, unsubscribe, consent-revocation or communication-stop requests, whether made within or outside WhatsApp.
Ezituuz will not be responsible for blocks, reports, quality loss, number suspension, account restriction, bans, template rejections, Meta sanctions, data-subject complaints, fines or damages arising from the absence of opt-in, failure to honor opt-out, spam, or misleading, abusive, unlawful or unsolicited messages sent by the customer.
10. Templates, messaging window and automations
The customer acknowledges that business-initiated messages via WhatsApp may depend on templates previously approved by Meta or the applicable provider, according to category, purpose and rules in force.
Ezituuz may provide technical resources for creating, sending, organizing or managing templates, but does not guarantee approval, maintenance, category, price, review timeframe, or Meta's interpretation of its policies.
The customer is responsible for respecting the messaging window applicable to the WhatsApp Business Platform, including the rule that free-form replies to user messages must observe the period permitted by Meta, requiring the use of approved templates when required.
If using automations, chatbots, artificial intelligence or automatic replies, the customer must maintain clear and effective means of escalation to human support or an alternative support channel.
The customer is fully responsible for the content, accuracy, legality, commercial promises, offers, information, automated replies, campaigns, flows and messages sent through the Platform.
11. Sub-processors, third parties and international transfer
To provide the services, Ezituuz may use sub-processors and technology suppliers, including hosting, VPS, cloud, storage, backup, monitoring, security, messaging, email, artificial intelligence, communication API, DNS, digital certificate and support-tool providers.
When the customer enables integrations with global platforms, such as Meta, WhatsApp, Facebook, Instagram, Telegram, Google, AI providers or other external services, personal data, messages, media, metadata and identifiers may be transmitted, stored or processed by such third parties, including outside Brazil.
Ezituuz will seek to use sub-processors with reasonable security standards compatible with the provision of the services, but does not fully control the policies, infrastructure, decisions, availability, pricing, rules or data-processing practices of independent third-party platforms.
12. Artificial intelligence and smart automations
eztz desk may allow integrations with artificial-intelligence services, chatbots, generative models, classifiers, assistants, summarizers or automation mechanisms, as contracted, configured and activated by the customer.
When the customer enables artificial-intelligence integrations, data, messages, conversation excerpts, metadata or content entered on the Platform may be sent to external AI providers for processing, according to the configurations adopted.
The customer is responsible for assessing the legal, regulatory, contractual and security adequacy of using AI, especially when it involves personal data, sensitive data, confidential information, regulated sectors or decisions with a relevant impact on individuals.
13. Information security
Ezituuz adopts technical and administrative measures that are reasonable and compatible with the nature of the Platform, its size, scope and the risks involved, which may include access control, environment segregation, authentication, encryption in transit, logs, backups, updates, restricted administrative access, technical monitoring and infrastructure best practices.
Security also depends on measures adopted by the customer, including the use of strong passwords, permission control, removal of offboarded users' access, device protection, phishing prevention, secure management of tokens and API keys, staff training and appropriate use of integrations.
No system connected to the internet, external APIs, user devices and third-party infrastructure can be considered absolutely secure, inviolable, uninterrupted or free of failures.
14. Technical access by Ezituuz
In environments managed by Ezituuz, the technical team may access administrative resources, infrastructure, logs, databases, files or configurations when necessary for deployment, maintenance, support, updates, bug fixes, security, technical monitoring, backup, recovery or compliance with legal obligations.
This technical access does not authorize commercial use of the customer's data, active reading of conversations for Ezituuz's own purposes, content monitoring for advertising, data sale, or exploitation of data for purposes unrelated to providing the services.
15. Data retention and deletion
Data processed on the Platform will be retained for as long as the contractual relationship with the customer lasts, or in accordance with Platform settings, legal obligations, operational needs, backup, security, fraud prevention, regular exercise of rights or applicable legitimate interests.
After the contract ends, the data may be exported by the customer, deleted, anonymized or made inaccessible, in accordance with the contract, the plan contracted, technical feasibility, good standing on payments, operational deadlines and applicable legal obligations.
16. Rights of data subjects
Under the LGPD, data subjects may request, as applicable:
- confirmation of the existence of processing;
- access to the data;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary, excessive or non-compliant data;
- portability, when applicable;
- information about sharing;
- revocation of consent;
- deletion of data processed on the basis of consent, when applicable;
- review of automated decisions, when applicable.
When the request relates to data processed by a customer company that uses eztz desk, the request should preferably be sent directly to that company, since it is the Data Controller and responsible for deciding how to handle the request.
Requests related to data for which Ezituuz itself acts as Data Controller may be sent to: [email protected].
17. Security incidents
If Ezituuz confirms a security incident involving personal data processed under its operation that may pose a relevant risk or damage, it will notify the contracting customer within a reasonable time, after confirmation and initial investigation, providing available information on the nature of the incident, categories of data affected, measures taken and mitigation recommendations.
It is the customer's responsibility, as Data Controller, to assess the need to notify Brazil's National Data Protection Authority — ANPD, data subjects, or third parties, except where Ezituuz has a direct legal obligation to do so.
Ezituuz is not responsible for incidents arising from failures solely attributable to the customer, such as improper password sharing, use of weak passwords, infected devices, exposed API keys, use of insecure networks, excessive permissions, negligence by internal users, or unlawful instructions given by the customer.
18. Acceptable use of the Platform
The customer must not use eztz desk for:
- sending spam or unsolicited messages;
- phishing, scams, fraud or malicious social engineering;
- unlawful data collection;
- privacy violations;
- harassment, discrimination, hate speech or abusive content;
- sending malware or malicious links;
- selling, offering or promoting products or services prohibited by law or by third-party policies;
- infringement of intellectual property rights;
- manipulation, deception or abuse of consumers;
- non-compliance with Meta, WhatsApp or other integrated platforms' policies;
- any unlawful purpose or purpose incompatible with this Policy, the Terms of Use or the applicable contract.
19. Children and teenagers
eztz desk is a business platform aimed at companies and professionals. Ezituuz does not direct its services to children.
If the customer processes data of children or teenagers through the Platform, it will be the customer's responsibility to ensure an adequate legal basis, specific consent when required, clear language, a legitimate purpose, reinforced protection and compliance with applicable rules.
20. Changes to this Policy
This Policy may be updated periodically to reflect legal, regulatory, technical, commercial, security, product or third-party policy changes.
When there are relevant changes, Ezituuz may notify its customers through a reasonable means, such as email, the Platform dashboard, the website, a contractual notice or another applicable channel.
21. Privacy contact
Ezituuz Company LTDA
Privacy Department / Data Protection Officer
Email: [email protected]
If your request relates to a conversation, support ticket, message, campaign or contact made by a company that uses eztz desk, we recommend that you also contact that company directly, since it is the Data Controller of the personal data in that context.
