Privacy Policy

How Workasso collects, uses and protects your data.

Last updated: October 5, 2026

1. Who we are

Workasso is operated by Gabriel Azambuja (sole proprietor, based in Brazil). We process the personal data described below on behalf of you as the customer (you are the "data controller"; we are the "data processor").

2. What we collect

Account data: name, email, locale, country, tax ID (when applicable for Brazilian invoicing). Usage data: agent actions, conversation messages, alerts processed, training chat history, document uploads. Billing data: Stripe customer + subscription IDs. We never see or store full payment card numbers. Integration data: OAuth tokens and API keys for connected services (Sentry, GitHub, Linear, Vercel, Slack, PostHog, Cal.com), and the read-only database connection string if you connect a database — all encrypted at rest with AES-256-GCM. WhatsApp data: when you connect WhatsApp, the messages your customers send to your number, the replies sent from it, contact names and phone numbers — see "WhatsApp (Meta) data" below. Technical data: IP address (geo-detection only, not retained), browser locale, signup source, UTM parameters.

3. How we use it

To provide the service: run your AI agents, send notifications, generate drafts, post to your connected channels. To bill you: pass Stripe customer/subscription IDs through to checkout + webhook reconciliation. To improve the service: anonymized aggregate metrics on usage patterns. We never train shared models on individual customer data. We do NOT sell your data, share it with advertisers, or use it to train third-party AI models.

4. Sub-processors

We use the following service providers to operate Workasso. Each handles a specific slice of your data under their own privacy commitments: • Anthropic (LLM inference — agent reasoning) • OpenAI (embeddings + audio transcription) • Resend (transactional email + inbound forwarding) • Stripe (payment processing) • Sentry (error monitoring) • PostHog (product analytics — only with consent) • Cloudflare (DNS + R2 file storage) • Neon (Postgres hosting) • Inngest (background job queue) • Upstash (Redis caching + rate limiting) • Meta Platforms (WhatsApp Business Cloud API — WhatsApp connectivity, when WhatsApp is connected) A full list with current data-processing terms is available on request.

5. WhatsApp (Meta) data

You connect your own WhatsApp Business number through Meta's official signup (WhatsApp Business Platform). Workasso then receives, through Meta, the messages your customers send to that number, the replies sent from it (including ones you send from the WhatsApp Business app), media they attach, their WhatsApp profile name and phone number, and — when your number stays on the WhatsApp Business app — your contacts and recent chat history, which Meta shares once at connection time. We use this data only to run your agents for you: read customer messages, draft and send the replies you approve (or that pass the auto-reply safety check), and show the conversation in your dashboard. We do not use it for advertising, sell it, or use it to train AI models. The access token Meta issues for your WhatsApp account is stored encrypted and is used only to send and receive messages for your account. You can disconnect WhatsApp in Workasso at any time, and remove Workasso's access in your Meta Business settings.

6. Data residency

Primary storage is in the EU (Neon Frankfurt), including the vector data used for agent knowledge. Email transit happens via Resend's US infrastructure. If you require strict EU-only or BR-only residency, contact us — this is currently negotiated on enterprise plans only.

7. Retention

Active accounts: data retained for as long as you keep the account active. Canceled accounts: 30-day grace period during which you can reactivate without data loss; after 30 days, all of your data is permanently deleted from primary storage. Backups roll off within 35 days (Neon backup policy). Logs: 90 days. Audit trail of agent actions: retained until account deletion, then purged with the rest.

8. Your rights

Under LGPD (Brazil) Art. 18 and GDPR (EU) Art. 15-21, you have the right to: • Access your data • Correct inaccuracies • Delete your account and all associated data • Export your data in a portable format • Object to processing for specific purposes • Lodge a complaint with your local data protection authority (ANPD in Brazil, the relevant DPA in the EU) To exercise any of these rights, email gabriel@workasso.com. We respond within 15 days.

9. Data deletion

You can delete your data at any time: • A single document, conversation or agent: delete it in the Workasso dashboard — its data and knowledge are removed. • WhatsApp: disconnect it on the agent's WhatsApp settings; then remove Workasso from Meta Business Settings → Integrations (or Business integrations) to revoke the token. • Your whole account: email gabriel@workasso.com from your account email with the subject "Delete my data". We delete your account and all associated data (agents, conversations, WhatsApp data, documents, integrations) within 30 days and confirm by email. Backups roll off within 35 days. If you are a customer of a business that uses Workasso and want your messages deleted, contact that business, or email us and we will route your request to them.

10. Cookies

We use a strictly-necessary session cookie for authentication. With your consent, we also use a PostHog analytics cookie to understand how features are used. You can decline analytics from the cookie banner shown on your first visit or change your choice anytime in account settings.

11. Security

OAuth tokens and other secrets are encrypted at rest using AES-256-GCM. Data in transit uses TLS 1.2+. Database backups are encrypted. We log access at the application layer and review unusual patterns. In the event of a personal data breach affecting your account, we notify you within 72 hours.

12. Changes to this policy

We'll update this page when our practices change. Material changes are also notified by email to active account holders. The "Last updated" date at the top reflects the most recent revision.

Questions about this policy or data requests? Email gabriel@workasso.com