Last Updated: March 17, 2026
Platform: SigmaAI is a multi-tenant WhatsApp AI automation platform for business communications.
Tenant: A customer (business, clinic, or organization) that uses SigmaAI to manage WhatsApp conversations.
End User: A customer of the Tenant who communicates with the Tenant's WhatsApp bot powered by SigmaAI.
Data Controller: The party that determines the purposes and means of data processing (typically the Tenant).
Data Processor: The party that processes data on behalf of the Controller (SigmaAI).
SigmaAI collects the following on behalf of Tenants:
Tenant Control: Tenants determine what data is collected and retain full ownership. SigmaAI does not sell or use this data for purposes other than providing the service.
Tenant as Controller, SigmaAI as Processor: Tenants are the Data Controller. SigmaAI acts as a Data Processor and processes data only as instructed by the Tenant through the Platform.
Data Ownership: All data belongs to the Tenant. SigmaAI does not claim ownership of Tenant data and does not use it for commercial purposes beyond service delivery.
Processing Activities: Data is processed to:
Legal Basis for Processing (Art. 6):
Data Subject Rights: If you are located in the EU, EEA, or UK, you have the following rights under GDPR:
To exercise your rights, contact dpo@sigmaintel.io. We will respond within 30 days (extendable by 60 days for complex requests).
Right to Lodge a Complaint (Art. 77): You have the right to lodge a complaint with a supervisory authority in your EU/EEA member state of residence, place of work, or where the alleged infringement occurred.
Data Protection Officer: For GDPR-related inquiries, contact our DPO at dpo@sigmaintel.io.
Data Processing Location: Platform data is stored on servers located in Germany (EU). Conversation data may be transferred to the United States for AI processing (OpenAI, Anthropic, Google).
International Data Transfers: Transfers to the United States are governed by EU Standard Contractual Clauses (SCCs) and supplementary technical measures (TLS 1.2+ in transit, AES-256 at rest). We rely on the EU-US Data Privacy Framework where applicable.
Data Breach Notification: In the event of a personal data breach, SigmaAI will notify the relevant supervisory authority within 72 hours of becoming aware (Art. 33) and affected data subjects without undue delay when the breach poses a high risk to their rights (Art. 34).
Legal Basis: Data processing is lawful when:
Tenant as Data Controller: Tenants (the business) are the Data Controller (Controlador) under LGPD. SigmaAI is the Data Operator (Operador) and processes data only as instructed by the Tenant.
Data Subject Rights: End Users may exercise their rights under Law 13.709/2018 by contacting the Tenant or SigmaAI directly:
International Data Transfers: Conversation data may be processed by AI providers (OpenAI, Anthropic, Google) headquartered in the United States. These transfers are conducted under contractual clauses that ensure an adequate level of data protection as required by LGPD Art. 33.
Encarregado de Protecao de Dados (DPO): For LGPD-related inquiries, data subject rights requests, or complaints, contact our Data Protection Officer at: dpo@sigmaintel.io
CCPA / CPRA (California): If you are a California resident, you have the following rights under the California Consumer Privacy Act (as amended by the California Privacy Rights Act):
Response Timeframe: We will acknowledge your request within 10 business days and respond within 45 calendar days (extendable by an additional 45 days with notice).
Sale and Sharing of Personal Information: SigmaAI does not sell personal information for monetary consideration. When cookie consent is granted, the Meta (Facebook) Pixel on our landing page may constitute "sharing" of personal information for cross-context behavioral advertising as defined by CPRA. You may opt out of this sharing by rejecting cookies via our consent banner or by clicking the "Do Not Sell or Share My Personal Information" link.
Categories of PI Collected (past 12 months):
| Category | Examples | Source | Business Purpose |
|---|---|---|---|
| Identifiers | Phone number, name, email | WhatsApp messages, Tenant input | Service delivery, communication |
| Commercial information | Subscription tier, payment history | Stripe, Tenant Portal | Billing, service provisioning |
| Internet activity | Page views, checkout events (when consent given) | Meta Pixel (consent-gated) | Advertising conversion tracking |
| Communications content | Message text, images | WhatsApp via Evolution API | AI response generation |
| Inferences | Conversation intent, language, sentiment | AI processing | Automated response routing |
Other US State Laws: SigmaAI respects the data privacy rights granted by state privacy laws including the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, and similar legislation. Residents of these states may exercise equivalent data rights by contacting support@sigmaintel.io.
Children's Privacy: SigmaAI is not directed at individuals under 16 years of age. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.
SigmaAI retains data according to the following schedule:
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Conversation Messages | Per Tenant plan (default: 1-3 years) or upon Tenant request | Cryptographic deletion from database |
| Images & Media | Per Tenant request; default deleted after processing | Deleted from storage after triage completion |
| Contact Information | Until Tenant deletes contact or conversation | Deleted within 7 days of request |
| Backups & Archives | Up to 90 days (for disaster recovery) | Automatically purged after retention window |
Deletion on Termination: Upon account termination, all Tenant data is exported within 30 days and permanently deleted.
Encryption in Transit: All data transmitted to/from SigmaAI is encrypted using TLS 1.2+.
Encryption at Rest: Database records are encrypted using industry-standard AES-256 encryption.
Access Controls:
Security Audits: SigmaAI conducts regular security assessments and penetration testing. Results available upon request.
SigmaAI uses the following third-party services to deliver the Platform:
| Service | Purpose | Data Shared |
|---|---|---|
| Evolution API | WhatsApp messaging | Messages, contact info, media |
| OpenAI, Anthropic, Google, Groq | AI response generation | Conversation context, message text |
| Stripe | Payment processing | Billing data, subscription info |
| MCP Servers | Tenant-configured integrations (CRM, scheduling, EHR) | Varies by Tenant configuration |
| PostgreSQL & Redis | Data storage and caching | All Platform data |
Data Processor Agreements: SigmaAI has data processing agreements with all third-party providers.
AI Context: To generate AI responses, SigmaAI sends conversation context (recent messages, customer profile, business knowledge) to AI providers.
No Model Training: SigmaAI does not use Tenant conversation data to train or fine-tune AI models. Data is used only to generate responses in real-time.
Automated Decision-Making (GDPR Art. 22): SigmaAI uses AI to automatically generate responses to End User messages. This constitutes automated processing. Important safeguards:
Tenant Control: Tenants can:
AI Limitations: AI models may generate inaccurate, incomplete, or harmful responses. Tenants are responsible for reviewing AI output before delivery to End Users.
Portal Cookies: SigmaAI uses session cookies (JWT) to authenticate Tenant Portal access. These are essential for service operation and contain no tracking data.
Cookie Consent: Non-essential tracking cookies are loaded only after you provide explicit consent via the cookie banner on our website, in compliance with LGPD Art. 7, I and GDPR Art. 6(1)(a).
Third-Party Analytics: When consent is given, the landing page uses the following tracking tools:
| Service | Purpose | Data Collected |
|---|---|---|
| Meta (Facebook) Pixel | Advertising conversion tracking | Page views, checkout events, purchase confirmations |
You can withdraw consent at any time by clearing your browser cookies or local storage and revisiting the site.
Server Logs: Web server access logs are retained for 90 days for security and debugging purposes only.
Contact Information:
Policy Changes: SigmaAI may update this Privacy Policy. For material changes that affect how your personal data is processed, we will notify Tenants via email at least 30 days before the changes take effect. Where required by applicable law (GDPR, LGPD), we will obtain your consent before implementing material changes. Minor clarifications or corrections may be made without prior notice.
Effective Date: This policy is effective March 17, 2026.