Privacy Policy

Last updated: July 26, 2026

1. Who we are

CRM de Performance is a customer relationship management system operated by Krit Web Ltda, registered under CNPJ (Brazilian company registration) 25.303.432/0001-00.

This policy explains which personal data is processed, for what purpose, with whom it is shared, and how to exercise your rights. It follows the LGPD (Brazil's General Data Protection Law), Law 13.709/2018.

2. Two different roles — read this section first

Data processing here is split into two situations, with distinct responsibilities:

2.1. Data of whoever hires the service

When you create an account, Krit Web Ltda is the controller of your registration and usage data. We decide the purposes and the means of that processing.

2.2. Data of the people served by the customer

The service stores conversations and information about third parties — the contacts, leads and clients of whoever hires the service. Regarding that data, Krit Web Ltda acts as processor: we process it on behalf of and under the instructions of the contracting customer, who is the controller.

This has a practical consequence: it is up to the contracting customer to have a legal basis to communicate with these people, to attend to their requests and to inform them about the processing. If you were served by a company that uses CRM de Performance and want to exercise rights over your data, contact that company first. If you do not know who to contact, write to admin@oficial.app.br and we will forward it to the responsible controller.

3. Data we process

3.1. Registration and usage data

  • Name, email address and password (stored encrypted, never in plain text).
  • Organization, role and permissions within the account.
  • Preferences such as language and theme.
  • Technical access records: date and time, IP address and browser identification, used for security and abuse limitation.

3.2. Conversation content

This is the most sensitive category and is therefore highlighted. The service connects to messaging channels — WhatsApp, Instagram Direct and Messenger — and stores:

  • The content of the messages exchanged, sent and received, including text and media files such as images, audio and documents.
  • Contact identifiers on the channel, such as phone number or profile identifier, and the displayed name.
  • Date, time and direction of each message, and the channel it came through.
  • Internal notes, tasks and the pipeline stage history recorded by the customer's team.

3.3. Origin and attribution data

When a contact arrives from an ad, the service records what the ads platform sends along with the first message, in order to identify which campaign originated it:

  • Click and ad identifiers provided by the platforms, such as Meta's and Google's origin parameters.
  • Identification of the source ad, ad set and campaign, when available.
  • Referring address, campaign parameters and landing page, when present.

4. What we use it for

PurposeLegal basis (LGPD)
Providing the contracted service and keeping the account runningContract performance (art. 7, V)
Storing and organizing conversations for the customer's supportContract performance, on behalf of the controller (art. 7, V)
Generating automatic suggestions and translations with artificial intelligenceLegitimate interest (art. 7, IX)
Measuring campaign results and reporting conversions to ad platformsController's legitimate interest (art. 7, IX)
Security, fraud prevention and abuse limitationLegitimate interest (art. 7, IX)
Complying with legal or regulatory obligationsLegal obligation (art. 7, II)

5. Use of artificial intelligence

The service uses artificial intelligence models for functions such as translating messages, suggesting replies, transcribing audio and summarizing conversations. To do this, the relevant conversation content is sent to contracted AI providers — currently Anthropic and OpenAI — which process the content and return the result.

These providers act as sub-processors, under a contract that restricts the use of the content to the provision of the service. We do not authorize the use of this content to train models.

AI-generated reply suggestions are shown to the customer's human operator. The decision to send is the customer's, not the system's.

6. Sending conversions to ad platforms

When a contact advances in the pipeline — for example, schedules, shows up or purchases — the service may report that result to the source ad platforms, such as Meta and Google, so that the customer can measure and optimize their campaigns.

This transmission includes the ad origin identifier, the event type and the date. Contact data occasionally used for matching is sent encrypted, as required by the platforms. We do not send conversation content to ad platforms.

7. Who we share data with

We do not sell personal data. We share it only with vendors necessary to operate the service:

VendorFunction
SupabaseDatabase, authentication and file storage
Anthropic, OpenAILanguage processing for the AI functions
Meta, GoogleReceiving conversion events from campaigns
Infrastructure and email delivery providerApplication hosting and transactional messages

We may also share data to comply with a court order or legal obligation, and to defend rights in administrative or judicial proceedings.

8. International transfer

Part of the vendors above are based outside Brazil, mainly in the United States. This means personal data may be processed abroad. These transfers rely on contractual protection clauses and occur only to the extent necessary to provide the service, in accordance with articles 33 and following of the LGPD.

9. How long we keep it

  • Registration data: for as long as the account exists and for up to 5 years after closure, a period tied to legal obligations and defense in any eventual proceeding.
  • Conversations and contact data: for as long as the contracting customer keeps the account, or until they request deletion. Control of this period belongs to the customer.
  • Access records: 6 months, in accordance with the Brazilian Internet Civil Framework (Marco Civil da Internet).

Once the purpose and the legal periods have ended, the data is deleted or anonymized. See the data deletion page to request removal.

10. Security

  • Encrypted traffic in transit and passwords stored with a hashing algorithm.
  • Channel integration credentials are stored encrypted, with a key separate from the database.
  • Isolation between organizations enforced at the database layer itself, so that one account cannot reach another's data.
  • Internal access restricted to the minimum necessary to operate and provide support.

No system is immune to incidents. If a security incident occurs with relevant risk to data subjects, we will notify those affected and the National Data Protection Authority within the applicable deadlines.

11. Your rights

The LGPD guarantees data subjects, among others, the right to:

  • confirmation that processing exists and access to your data;
  • correction of incomplete, inaccurate or outdated data;
  • request anonymization, blocking or deletion of unnecessary data;
  • request portability to another provider;
  • revoke consent, when the processing relies on it;
  • object to processing based on legitimate interest;
  • request review of decisions made solely through automated means.

To exercise any of them, write to admin@oficial.app.br. We reply within 15 days. We may ask for additional information to confirm your identity before responding — this is a protection against requests made by third parties in your name.

Recalling section 2: if your data is in the system because you talked to a company that uses CRM de Performance, the controller is that company. We forward your request to them.

12. Cookies

We only use cookies necessary for operation: keeping your session authenticated and storing your language preference. We do not use advertising or third-party tracking cookies in this application.

13. SMS messages

CRM de Performance may send text messages (SMS) on behalf of the subscribing customer — for example, appointment reminders or service notifications. For those messages, Krit Web Ltda acts as a processor: the phone number and the consent are collected by the subscribing customer, who is the controller of that data (see section 2.2).

Consent. The mobile number is provided by the person to the subscribing customer — when booking, during service, or through a form — together with agreement to receive messages about that service. The record of that consent is kept in the subscribing customer's account.

We do not sell and do not share mobile phone numbers or SMS consent data with third parties for marketing purposes. This data is used solely to deliver the subscribing customer's own messages, and is shared only with the telecommunications carrier required for delivery (see section 7).

How to stop receiving. Reply STOP to any message to stop receiving them. Reply HELP for assistance. The request takes effect on receipt and does not depend on a human reply.

Frequency and cost. Message volume varies with each person's own appointments — there is no automatic recurring promotional send. Message and data rates may apply, according to your mobile plan.

14. Changes to this policy

We may update this document to reflect changes in the service or in the law. The date at the top indicates the last revision. For relevant changes, we will notify you through the application or by email before the change takes effect.

15. Contact

Questions about privacy, data subject requests or matters related to this policy: admin@oficial.app.br.

Krit Web Ltda — CNPJ (Brazilian company registration) 25.303.432/0001-00.