Last Updated: March 10, 2026
Platform: SigmaAI is a multi-tenant WhatsApp AI automation platform for business communications.
Tenant: A customer (business, clinic, or organization) that uses SigmaAI to manage WhatsApp conversations.
End User: A customer of the Tenant who communicates with the Tenant's WhatsApp bot powered by SigmaAI.
Data Controller: The party that determines the purposes and means of data processing (typically the Tenant).
Data Processor: The party that processes data on behalf of the Controller (SigmaAI).
SigmaAI collects the following on behalf of Tenants:
Tenant Control: Tenants determine what data is collected and retain full ownership. SigmaAI does not sell or use this data for purposes other than providing the service.
Tenant as Controller, SigmaAI as Processor: Tenants are the Data Controller. SigmaAI acts as a Data Processor and processes data only as instructed by the Tenant through the Platform.
Data Ownership: All data belongs to the Tenant. SigmaAI does not claim ownership of Tenant data and does not use it for commercial purposes beyond service delivery.
Processing Activities: Data is processed to:
Legal Basis: Data processing is necessary for the performance of the contract between the Tenant and SigmaAI.
Data Subject Rights: Tenants must provide End Users with the ability to exercise their GDPR rights:
Data Protection Addendum: SigmaAI and Tenant agree to the EU Standard Contractual Clauses (SCCs) for lawful data transfers.
Data Transfers: Data may be transferred to non-EU countries only where SigmaAI has established adequate safeguards (SCCs, adequacy decisions).
Legal Basis: Data processing is lawful when:
Tenant as Data Controller: Tenants (the business/clinic) are the Data Controller under LGPD. SigmaAI is the Data Operator.
Data Subject Rights: Tenants facilitate End Users' rights under Law 13.709:
LGPD Officer Contact: For LGPD-related inquiries, Tenants should contact their local data protection officer or SigmaAI support.
SigmaAI retains data according to the following schedule:
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Conversation Messages | Per Tenant plan (default: 1-3 years) or upon Tenant request | Cryptographic deletion from database |
| Images & Media | Per Tenant request; default deleted after processing | Deleted from storage after triage completion |
| Contact Information | Until Tenant deletes contact or conversation | Deleted within 7 days of request |
| Backups & Archives | Up to 90 days (for disaster recovery) | Automatically purged after retention window |
Deletion on Termination: Upon account termination, all Tenant data is exported within 30 days and permanently deleted.
Encryption in Transit: All data transmitted to/from SigmaAI is encrypted using TLS 1.2+.
Encryption at Rest: Database records are encrypted using industry-standard AES-256 encryption.
Access Controls:
Security Audits: SigmaAI conducts regular security assessments and penetration testing. Results available upon request.
SigmaAI uses the following third-party services to deliver the Platform:
| Service | Purpose | Data Shared |
|---|---|---|
| Evolution API | WhatsApp messaging | Messages, contact info, media |
| OpenAI, Anthropic, Google, Groq | AI response generation | Conversation context, message text |
| Stripe | Payment processing | Billing data, subscription info |
| MCP Servers | Tenant-configured integrations (CRM, scheduling, EHR) | Varies by Tenant configuration |
| PostgreSQL & Redis | Data storage and caching | All Platform data |
Data Processor Agreements: SigmaAI has data processing agreements with all third-party providers.
AI Context: To generate AI responses, SigmaAI sends conversation context (recent messages, customer profile, business knowledge) to AI providers.
No Model Training: SigmaAI does not use Tenant conversation data to train or fine-tune AI models. Data is used only to generate responses in real-time.
Tenant Control: Tenants can:
AI Limitations: AI models may generate inaccurate, incomplete, or harmful responses. Tenants are responsible for reviewing AI output before delivery to End Users.
Portal Cookies: SigmaAI uses session cookies (JWT) to authenticate Tenant Portal access. These are essential for service operation and contain no tracking data.
Third-Party Analytics: The landing page does not use third-party analytics or tracking scripts. We do not track user behavior on appai.sigmaintel.io.
Server Logs: Web server access logs are retained for 90 days for security and debugging purposes only.
Support Contact: For privacy questions, data subject rights requests, or security concerns, contact: support@sigmaintel.io
Policy Changes: SigmaAI may update this Privacy Policy at any time. Significant changes will be notified to Tenants. Continued use of the Platform indicates acceptance of changes.
Effective Date: This policy is effective March 10, 2026.