Na WebToi, estamos comprometidos com a proteção das suas informações pessoais, em conformidade com a Lei 25 do Quebec, PIPEDA, GDPR e CCPA.
1. Informações que Coletamos
We collect personal information that you voluntarily provide when you contact us or use our services, including:
- Personal Details: Name, email address, phone number, and contact preferences.
- Business Information: Company name and project requirements shared through contact forms.
- Usage Data: Browser type, IP address, pages visited, and time spent on pages (via analytics cookies).
- Chatbot Interactions: Messages exchanged with our support chatbot, used to improve service quality.
- Google Account Data: When you connect a Google account via OAuth, we store encrypted access and refresh tokens, your Google email address, display name, and profile picture. We do not store the contents of your Gmail, Calendar events, or YouTube data beyond what is necessary to provide the requested service features.
2. Como Usamos Suas Informações
We use the information we collect to:
- Provide, operate, and improve our services.
- Send administrative communications and respond to inquiries.
- Send marketing communications (only with your explicit consent).
- Analyze website usage to improve user experience.
- Integrate with Google services (Calendar, Gmail, Meet, YouTube, Business Profile) on your behalf when you authorize this connection.
- Comply with legal obligations.
3. Serviços Google API
Nossa aplicação usa os Serviços Google API para conectar Agenda, Gmail, Google Meet, YouTube e Google Business Profile. Nosso uso de dados recebidos das APIs do Google está em conformidade com a Política de Dados de Usuário dos Serviços de API do Google, incluindo os requisitos de Uso Limitado.
Specifically regarding Google user data:
- We request only the minimum OAuth scopes necessary to provide the requested features.
- We do not use Google user data to develop, improve, or train generalized AI or ML models.
- We do not sell Google user data to third parties.
- We do not use Google user data for advertising purposes.
- Access tokens and refresh tokens are stored encrypted using AES-256-GCM in Google Cloud Firestore.
- You can revoke our access to your Google account at any time via Google Account Permissions.
Our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Compartilhamento de Informações
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
- Service Providers: Trusted third-party services that help us operate (e.g., Google Cloud, Firebase). These parties are contractually bound to protect your data.
- Legal Requirements: When required by law, court order, or governmental authority.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, with advance notice provided to users.
- With Your Consent: Any other sharing with your explicit prior consent.
5. Seus Direitos
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your personal data (right to be forgotten).
- Portability: Receive your data in a structured, machine-readable format.
- Restriction: Request restriction of how we process your data.
- Opt-Out: Withdraw consent for marketing communications at any time.
- Google Revocation: Revoke our access to your Google account at myaccount.google.com/permissions.
To exercise these rights, contact us at team@webtoi.com.
6. Retenção de Dados
We retain your personal information only as long as necessary to provide our services and comply with legal obligations:
- Account data: Retained while your account is active and for 30 days after deletion request.
- Google OAuth tokens: Deleted immediately upon account disconnection or upon your request.
- Analytics data: Retained for up to 26 months in anonymized form.
- Chatbot records: Retained for up to 12 months to improve service quality.
7. Segurança
We implement industry-standard technical and organizational measures to protect your personal data:
- OAuth tokens are encrypted at rest using AES-256-GCM.
- All data in transit is protected by TLS 1.2 or higher.
- Access to personal data is restricted to authorized personnel only.
- We use Google Cloud infrastructure, which complies with ISO 27001, SOC 2, and other certifications.
8. Cookies
We use cookies and similar technologies to improve your experience. Types of cookies we use:
- Essential: Required for the website to function. Cannot be disabled.
- Analytics: Help us understand how visitors interact with our website (anonymized).
- Chatbot Records: Enable our support chatbot to maintain conversation context.
9. Encarregado de Privacidade
In accordance with Quebec Law 25 and PIPEDA, we have designated a Privacy Officer:
Privacy Officer Contact:
Email: team@webtoi.com
Address: Montreal, Quebec, Canada
Website: https://webtoisitetemplate.web.app
10. Contato
If you have questions, complaints, or requests regarding this Privacy Policy or our data practices, please contact us at team@webtoi.com. We will respond within 30 days.