back to site

Privacy — Penélope ChatBot

Product-specific annex for Penélope ChatBot, supplementing FTN's Privacy Policy.

Last updated: September 4, 2026

1. Scope

Penélope ChatBot is a service that lets a company (the "Subscriber") offer automated customer service to its own customers (the "Consumers") over WhatsApp, using Meta's WhatsApp Business Platform.

This annex details personal data processing in Penélope and supplements the Filipo Teixeira Negrão Consultoria em Tecnologia da Informação LTDA Privacy Policy. Where they diverge about Penélope, this annex prevails.

2. Roles of the parties

DataControllerProcessor
Subscriber's registration, account, plan and billingFTN
Messages and data of the Subscriber's ConsumersThe SubscriberFTN

This means FTN does not decide on its own what happens to Consumer data: it processes that data following the Subscriber's instructions, to deliver the contracted service. It is up to the Subscriber to inform its Consumers about the use of automated service and to hold a legal basis for the processing.

3. Subscriber data

To create and maintain the account we process: name, email, password (stored only as a hash), contact phone numbers, company or personal tax ID, legal name, state registration, address, website, profile image, plus plan and payment history data.

4. Consumer data

When a Consumer chats with the Subscriber's assistant, we process, on the Subscriber's behalf:

  • WhatsApp phone number (or equivalent identifier provided by Meta) and profile name;
  • content of the messages exchanged, including text and media files sent;
  • data the Consumer volunteers during the conversation — such as name, email, tax ID and address — when the service requires it, for instance to issue a charge or register a delivery;
  • records of appointments, orders and charges originating in the conversation.

This data is segregated per Subscriber: one Subscriber never accesses another's Consumers.

5. Data obtained from Meta's platform

Penélope is a technology provider integrated with the WhatsApp Business Platform. When the Subscriber connects their account through our setup wizard, they authorize — in a flow hosted by Meta itself — that we receive and process:

  • the WhatsApp Business Account identifier (WABA ID) and the phone number identifier (phone number ID);
  • the number's display name, its approval status and its quality rating;
  • a business access token, stored encrypted with AES-256-GCM and used only to operate the service on the Subscriber's behalf;
  • events sent by Meta over webhook, such as incoming messages, delivery receipts and number status updates.

This data is used exclusively to deliver the service contracted by the Subscriber. We do not sell it, do not use it for advertising, do not use it to train our own models and do not combine it with data from other sources to build profiles. Access is revocable by the Subscriber at any time, as described in section 9.

The WhatsApp Business Account belongs to the Subscriber, created in their company's name and under their own Meta business portfolio. FTN acts as a technology provider, never as the owner of a client's assets.

6. Purposes and legal bases

PurposeLegal basis (LGPD)
Create and maintain the Subscriber's account and deliver the servicePerformance of a contract (art. 7, V)
Process messages and reply to ConsumersPerformance of the Subscriber's contract with the Consumer, or the Subscriber's legitimate interest (art. 7, V and IX) — determined by the Subscriber as controller
Issue charges and record orders and appointmentsPerformance of a contract (art. 7, V)
Bill the plan and prevent fraud and abusePerformance of a contract and legitimate interest (art. 7, V and IX)
Comply with tax, accounting and regulatory obligationsLegal obligation (art. 7, II)

7. Who we share with

We do not sell personal data. We share only with suppliers necessary to operate the service, each limited to what its function requires:

SupplierPurposeData involved
Meta PlatformsSending and receiving WhatsApp messagesMessage content, Consumer's number, account identifiers
OpenAIInterpreting the conversation and generating the assistant's repliesMessage content and the context needed for the reply
GoogleCalendar, when the Subscriber connects Google CalendarAppointment data and Consumer identification
Pagar.mePIX charges issued by the Subscriber during the conversationName, tax ID and charge amount
StripeBilling the Subscriber's own subscription to FTNSubscriber billing data
Hosting providerServer and database infrastructureAll data at rest, encrypted where applicable

We may also share data when required by law, court order or request from a competent authority.

8. Retention

Consumer data is kept for the duration of the Subscriber's contract, because it is the source of the conversation history the assistant relies on. Once the contract ends, it is deleted within 90 days, except what must be retained by legal obligation.

The Subscriber's registration and tax records are kept for the applicable statutory periods, even if the account is closed.

Meta access tokens are deleted immediately when the Subscriber disconnects the account or terminates the service.

9. Revoking access and deleting data

The Subscriber may disconnect the WhatsApp account at any time from the Penélope panel, or remove the app directly in their own Meta business portfolio. In either case the token is invalidated and Penélope loses access to the account.

The full deletion procedure, including deadlines and what is retained by legal obligation, is on the data deletion page.

10. Consumers: who to contact

If you chatted with a company's assistant and want to access, correct or delete your data, address your request to that company — it is the controller. FTN handles such requests as a processor, on its instruction.

If you do not know how to reach them, write to filiponegrao@gmail.com with the number used in the conversation: we will identify the responsible Subscriber and forward your request.