Vexum
Legal document

Privacy Policy

Version 5.0. Effective as of August 3, 2026.

Leia esta página em português

1. WHO WE ARE

Vexum is a trade name of IJA SOLUÇÕES LTDA, a private legal entity registered under CNPJ (Brazilian corporate taxpayer registry) No. 65.014.643/0001-30, headquartered at Rua Capitão José da Luz, 137, room 0203, Edifício Cervantes Cais 202, Coelhos district, Recife, Pernambuco, ZIP 50070-540, Brazil, hereinafter referred to as "Vexum".

Vexum provides law firms with a client communication and payment-reminder system operating over WhatsApp. The contracting law firms are the controllers of their own clients' data. Vexum, upon authorization and on behalf of each firm, sends due-date reminders and payment status notifications relating to pre-existing agreements between the firm and its own clients, receives the replies, and provides a dashboard so the firm's staff can handle those conversations. Each contracting firm owns its own WhatsApp Business account and may revoke Vexum's access to that account at any time.

This policy explains how we process personal data in the context of that system, and it applies to two categories of individuals, treated differently as detailed below:

2. OUR ROLE MAY CHANGE DEPENDING ON THE TYPE OF DATA

The Brazilian General Personal Data Protection Law (Law No. 13.709/2018, "LGPD") distinguishes two roles: the controller, who decides the purpose and the means of data processing, and the processor, who processes data following the controller's instructions. Vexum occupies both roles, depending on which data is at stake.

2.1. With respect to dashboard users' data (the people acting on behalf of the law firm, their registration data, system access data and billing data of the contract), Vexum is the controller. It is Vexum that decides the purpose and the means of that processing.

2.2. With respect to end data subjects' data (name, phone number, outstanding amount, due date and the content of the messages exchanged over WhatsApp), Vexum is the processor. The party that decides the purpose and the means of that processing is the law firm that contracted Vexum, which is the controller of that data. Vexum processes such data solely to perform the service contracted by the firm, following the firm's instructions.

If you are an end data subject (you received a payment reminder or account notification over WhatsApp from a law firm that uses the Vexum system) and want to better understand who is accountable for decisions about your data, see section 11 of this policy and the document "Data Deletion Instructions", published alongside this policy.

3. WHAT DATA WE COLLECT AND WHY

3.1. Dashboard users' data (Vexum as controller)

We collect: name, job title, corporate e-mail, contact phone number, access credentials, system usage records (login, actions performed in the dashboard) and billing data of the contracting firm (corporate name, CNPJ, address, payment data).

Purpose: to enable registration and access to the dashboard, provide support, invoice the service provided, comply with tax and accounting obligations, and safeguard system security through access logging.

3.2. End data subjects' data, that is, the contracting firm's clients with outstanding balances (Vexum as processor)

We process, following the contracting law firm's instructions:

Purpose, in specific terms: to send automated due-date reminders and payment status notifications on behalf of the contracting firm, to receive and record the replies sent by the data subject, to make those messages available in a dashboard so an employee of the contracting firm can view and reply to them, and to retain the history of that communication for the purposes of the communication service itself contracted by the firm from Vexum.

Vexum does not use end data subjects' data for its own purposes, does not sell it, does not use it to prospect other clients, and does not cross-reference it with other databases outside the system, save upon the contracting firm's express instruction and provided such instruction is compatible with the LGPD.

3.3. Categories of data Vexum does not process

Through this system, Vexum does not collect sensitive data as defined in article 5, II, of the LGPD (racial or ethnic origin, religious belief, political opinion, data concerning health or sex life, genetic or biometric data), unless such data appears incidentally in the content of an exchanged message — for example, a reference to child support proceedings, guardianship, a health condition or an employment relationship mentioned by the data subject or necessary to identify the contract or lawsuit the message refers to. In that case, Vexum processes such content with no additional purpose of analysis, classification or profiling, restricting itself to the minimum necessary to provide the contracted communication service, which falls within article 11, II, item 'd', of the LGPD (regular exercise of rights, including under a contract and in judicial or administrative proceedings). Vexum instructs contracting firms to limit, in the body of messages, detailed references to the subject matter of proceedings of a sensitive nature, restricting themselves to neutral identifiers such as the case number or the contract reference. The reinforced protections of section 9 below also apply.

4. LEGAL BASES FOR PROCESSING

4.1. For dashboard users' data (Vexum as controller), processing is grounded on:

4.2. For end data subjects' data (Vexum as processor), the applicable legal basis is defined by the contracting law firm, in its capacity as controller, and normally relies on article 7, V, of the LGPD (performance of a pre-existing contract between the data subject and the firm, or the firm's client, from which the outstanding obligation arises). Vexum processes such data exclusively to carry out that purpose defined by the controller, pursuant to article 39 of the LGPD.

5. WHO WE SHARE DATA WITH

To operate the system, the personal data processed passes through a single external agent, described below along with the role it occupies:

5.1. Meta Platforms, Inc. The company responsible for operating the WhatsApp Business Platform (also called the Cloud API), used to send and receive WhatsApp messages, and Vexum's contractual counterparty in that integration, by force of the very terms Meta applies to businesses located in Brazil. Vexum integrates directly with Meta's WhatsApp Business Platform for that integration, with no technical intermediary between Vexum's system and Meta's platform. According to Meta's own documentation, when providing the Cloud API service, Meta acts as processor of the personal data processed, on behalf of and upon instruction from the business using the platform, that is, on behalf of each contracting firm, and does not use the messages it processes for any different purpose, save upon instruction to the contrary.

5.2. We do not share data subjects' personal data with any third party other than Meta Platforms, Inc., except where required by law, by court order or by a competent authority, or upon specific authorization from the controller responsible for the data in question.

5.3. Sharing event data with Meta to optimize marketing messages. During the WhatsApp Business account onboarding process, Meta offers the option to share event activity data for the purpose of optimizing the performance of marketing messages. This sharing is a setting of the contracting firm's WhatsApp Business account, can be disabled in the account's own settings, and Vexum's guidance to contracting firms is to keep it disabled. Vexum neither controls nor directly benefits from that sharing, which occurs between the firm's account and Meta.

6. INTERNATIONAL DATA TRANSFERS

Use of the WhatsApp Business Platform inherently involves, by its own architecture, the processing of personal data by Meta Platforms, Inc., a US entity that acts as Vexum's contractual counterparty in that integration by force of the very terms Meta applies to businesses located in Brazil. This constitutes an international transfer of personal data under article 33 of the LGPD, and that transfer does in fact occur whenever a message is sent or received by the system.

Under the instruments Meta publishes and which govern that integration, including the WhatsApp Business Platform Cloud API Terms and the Meta Global Processor Terms, message content may be stored, during processing, in data centers owned by Meta and by sub-processors engaged by Meta, located in the United States, Ireland, Sweden and Denmark. There is therefore no single country of destination: Meta distributes that processing across those four countries, and Vexum does not determine which of them processes a specific piece of data at a given moment, a technical and operational decision that rests exclusively with Meta.

Legal basis for this transfer: Vexum relies on article 33, II, item "a", of the LGPD, taking the specific contractual clauses offered by Meta in the instruments referenced above as the formal vehicle of the transfer, combined with article 33, IX, together with article 7, V, of the LGPD, considering that the transfer is necessary for the performance of the very service agreement that grounds the processing described in section 4 of this policy. Vexum transparently records that it has assessed the contractual instruments published by Meta for that integration and identified that they offer safeguards materially equivalent to those required under the LGPD, including encryption in transit and at rest, contractual commitments of confidentiality and purpose limitation, and information security certifications held by Meta Platforms, Inc. Those instruments, however, are drafted by Meta primarily for compliance with the European data protection regime and do not textually correspond to the standard contractual clauses issued by the Brazilian National Data Protection Authority under Resolution CD/ANPD No. 19/2024, nor were they specifically approved by that Authority for this transfer. Vexum monitors regulatory developments on the matter and will adopt the Authority's standard clauses as soon as that becomes technically and contractually feasible with Meta Platforms, Inc. As of the date of this version, there is no decision by the National Data Protection Authority recognizing an adequate level of protection in the countries listed above, nor a specific authorization from the Authority for this transfer, and the transfer does not rely on specific, highlighted consent from the data subject for that international purpose.

Additional information about where and how Meta processes personal data globally, including the sub-processors it engages, is available in the instruments Meta itself publishes for the WhatsApp Business Platform Cloud API.

7. CONVERSATION HISTORY SYNCHRONIZATION (WHERE APPLICABLE)

Vexum's system can operate in two technical modes regarding the contracting firm's WhatsApp number: (i) the number operating exclusively through the official API, with no link to the WhatsApp Business app installed on a mobile phone; or (ii) the number operating simultaneously in the WhatsApp Business app and in the official API (the model known as coexistence).

If and only if the contracting firm opts for the coexistence model, the account onboarding process, conducted directly between the firm and Meta, may synchronize to Vexum's system a conversation history of up to 180 days prior to onboarding, as well as the list of contacts saved on the device linked to the number. That synchronization, when it occurs, is a decision and an action of the contracting firm during the onboarding process with Meta, not a collection of data initiated by Vexum, and its effects on personal data follow the same role rules (controller/processor) and legal bases described in sections 2 and 4 of this policy.

If the contracting firm opts for the model without coexistence (pure official API), that history synchronization does not occur.

8. REVOCATION OF ACCESS BY THE CONTRACTING FIRM

Each contracting firm owns the WhatsApp Business Account used in the system. The firm may, at any time, revoke Vexum's access to that account directly in the WhatsApp Manager settings or by requesting revocation from Vexum. Once access is revoked, Vexum can no longer send or receive messages on the firm's behalf, without prejudice to the retention of data already processed under section 10 of this policy.

9. DATA PROCESSING IN THE CONTEXT OF LEGAL PRACTICE AND PROFESSIONAL PRIVILEGE

Contracting law firms are subject to the professional privilege provided for in the Brazilian Bar Association Statute (Law No. 8.906/1994, article 7, items II and XIX, and article 34, item VII) and in article 154 of the Brazilian Criminal Code. The content of messages exchanged through the system may occasionally touch upon information protected by that privilege.

Vexum handles such content with the same standard of confidentiality, limits access to that data to the persons strictly necessary to operate the system, and does not use it for any purpose beyond performing the communication service contracted by the firm.

10. HOW LONG WE KEEP DATA, AND HOW TO REQUEST DELETION

We keep personal data for the period necessary to fulfill the purpose for which it was collected, observing the following terms:

Once the applicable retention period ends, data is deleted or anonymized, save a determination to the contrary from the responsible controller, within the limits of the law.

The terms above govern the data held by Vexum in its own systems, which are the operational basis of the communication service contracted by the firm. Independently, Meta Platforms, Inc. maintains, in its own infrastructure, distinct and shorter retention periods, applicable only to the processing it performs as operator of the WhatsApp Business Platform: message content, including attachments, is retained for up to 30 (thirty) days to enable the platform itself to function; technical identifiers and status metadata are deleted within 30 (thirty) days from the last recorded message status (sent, delivered or read); residual data from a closed account is deleted within 90 (ninety) days. Meta also offers an optional local storage feature (Cloud API Local Storage) which, when enabled, reduces the data-in-use period outside the selected region. This feature is disabled by default and is not enabled on the accounts operated by Vexum. These Meta terms do not replace or alter the retention periods applied by Vexum described in the preceding paragraphs of this section.

To learn how to request deletion of your data before those periods end, see the document "Data Deletion Instructions", published alongside this policy.

11. INFORMATION SECURITY

We adopt technical and administrative measures to protect the personal data processed, including: storage of credentials and access tokens in a secrets vault, with no exposure in code or in logs; least-privilege access control; data segregation between different contracting firms; encryption in transit; and system access logging.

No system is entirely free of risk. Should a security incident occur that may entail relevant risk or harm to data subjects, Vexum will follow the procedure set out in article 48 of the LGPD and in Resolution CD/ANPD No. 15/2024, notifying the National Data Protection Authority and, where applicable, the affected data subjects or the controller responsible for them, within the deadlines and in the manner prescribed by law.

12. DATA SUBJECT RIGHTS AND HOW TO EXERCISE THEM

Under article 18 of the LGPD, a personal data subject has the right, upon request, to: confirmation that processing exists; access to the data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary data or data processed in breach of the law; portability of the data to another service provider; deletion of data processed on the basis of consent; information about the entities with which the controller has shared data; information about the possibility of withholding consent and the consequences of that refusal; and withdrawal of consent, where consent is the applicable legal basis.

If you are a dashboard user of a contracting firm, your requests should be directed to Vexum, through the contact channel in section 14, and will be answered within the statutory period of up to 15 days.

If you are an end data subject (for example, you received a payment reminder from a law firm that uses the Vexum system), the controller responsible for your data is the law firm that sent the message, not Vexum. See the document "Data Deletion Instructions", published alongside this policy, to learn exactly how to proceed in that case. Vexum, in its capacity as processor, also receives and forwards end data subject requests that reach it, as detailed in that document.

13. CHILDREN AND ADOLESCENTS

Vexum's system is not directed at children or adolescents and is not used to knowingly process data of persons under 18 as end data subjects of communication. Should Vexum identify improper processing of a child's or adolescent's data without the legal basis required by article 14 of the LGPD, it will take appropriate measures to cease the processing and will inform the responsible controller.

14. HOW TO CONTACT VEXUM ABOUT PRIVACY, AND WHO IS ACCOUNTABLE FOR IT

To exercise the rights described in this policy, ask questions or report a security incident, contact us:

E-mail: privacidade@vexum.tech

Telephone: +55 81 99881-2909

Address: Rua Capitão José da Luz, 137, room 0203, Edifício Cervantes Cais 202, Coelhos, Recife, PE, ZIP 50070-540, Brazil

Given its current size, Vexum falls within the definition of a small-scale processing agent under Resolution CD/ANPD No. 2/2022, which exempts such agents from the obligation to formally and nominally appoint a data protection officer (DPO), while maintaining the requirement to provide, in an easily visible location, a direct communication channel with the data subject. That function is fulfilled by the channel indicated above.

All communication received through that channel is handled by Vexum's compliance team, which performs the duties described in article 41, paragraph 2, of the LGPD: receiving complaints and communications from data subjects, providing clarifications, taking action, receiving communications from the National Data Protection Authority, and providing internal guidance on data protection best practices.

15. CHANGES TO THIS POLICY

This policy may be updated to reflect changes in how we process personal data, changes in applicable legislation, or system architecture decisions. The version in force will always be publicly available at Vexum's web address, indicating the version number and effective date.

16. VERSION HISTORY

Version 1.0, published on August 2, 2026.

Version 2.0, published on August 2, 2026: update of the processing chain due to a change in technical architecture (Vexum began integrating directly with Meta's WhatsApp Business Platform, with no technical intermediary), inclusion of retention periods, confirmation of the privacy contact channel, and wording adjustments for greater specificity about the data obtained through the Meta platform.

Version 3.0, published on August 3, 2026: rewrite of section 6 (international transfers) to fully declare the transfer of data to Meta Platforms, Inc. and its legal grounds, without depending on confirmation of a specific storage territory; rewrite of section 14 to address the absence of a nominally appointed data protection officer based on Resolution CD/ANPD No. 2/2022 (small-scale processing agent), maintaining the direct communication channel already in place.

Version 4.0, published on August 3, 2026: update of section 6 identifying the countries where Meta and its sub-processors store data during processing (United States, Ireland, Sweden and Denmark), reassessment and adjustment of the legal grounds for the international transfer in light of the contractual instruments actually published by Meta, and inclusion, in section 10, of Meta's own retention periods on its infrastructure, distinct from those applied by Vexum.

Version 5.0, published on August 3, 2026: terminology review to describe the service as client communication and payment reminders; correction of the data-in-use period on Meta's infrastructure, clarifying that the local storage feature is optional and not enabled; detailing of the legal basis applicable to incidental sensitive data; and supplementation of the safeguards assessment for the international transfer.

Legal basis of this policy: Law No. 13.709/2018 (General Personal Data Protection Law), Law No. 12.965/2014 (Brazilian Internet Civil Framework), Decree No. 8.771/2016, Resolution CD/ANPD No. 15/2024, Resolution CD/ANPD No. 2/2022, Resolution CD/ANPD No. 19/2024, Law No. 8.078/1990 (Consumer Protection Code, where applicable), Law No. 8.906/1994 (Brazilian Bar Association Statute).

This English version is provided for accessibility. In the event of any divergence of interpretation, the Portuguese version prevails.