GDPR Compliance


Last Updated: March 20, 2026


1. Our Commitment to Data Protection

ChatBits, operated by M D LABS CONSULTORIA E TREINAMENTOS LTDA, is committed to protecting the personal data of all users, including those in the European Union (EU) and European Economic Area (EEA). This page explains how we comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Brazilian General Data Protection Law (LGPD - Law 13.709/2018), and the California Consumer Privacy Act ("CCPA").

2. What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union that governs how personal data of EU/EEA residents is collected, stored, processed, and shared. It grants individuals significant rights over their personal data and imposes strict obligations on organizations that handle that data.

3. Data We Collect and Why

We collect and process personal data only when we have a lawful basis to do so. The following table summarizes our data processing activities:

Data Type Purpose Legal Basis (GDPR)
Name, Email Account creation and management Contractual Necessity (Art. 6(1)(b))
Payment Information Process subscriptions and billing Contractual Necessity (Art. 6(1)(b))
Meta/Facebook Data Chatbot functionality, messaging automation Consent (Art. 6(1)(a))
Messenger Subscriber Data Deliver chatbot responses, subscriber management Legitimate Interest (Art. 6(1)(f))
IP Address, Device Info Security, fraud prevention, analytics Legitimate Interest (Art. 6(1)(f))
Cookies Authentication, preferences, analytics Consent (Art. 6(1)(a))
Log Data Error tracking, security monitoring Legitimate Interest (Art. 6(1)(f))

4. Your Rights Under GDPR

If you are located in the EU/EEA, you have the following rights under GDPR. You can exercise any of these rights by contacting us at [email protected].

  • Right of Access (Art. 15): Request a copy of all personal data we hold about you. We will provide this within 30 days.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure / Right to be Forgotten (Art. 17): Request deletion of your personal data. See our Data Deletion Policy for the complete process.
  • Right to Restriction of Processing (Art. 18): Request that we limit how we process your data in certain circumstances.
  • Right to Data Portability (Art. 20): Request your data in a structured, machine-readable format (JSON or CSV).
  • Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent (Art. 7(3)): Withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint (Art. 77): File a complaint with your local Data Protection Authority if you believe your rights have been violated.

5. Your Rights Under LGPD (Brazil)

As a Brazilian company, we fully comply with the LGPD. Brazilian users have the following rights under Articles 17-22:

  • Confirmation of the existence of processing of personal data
  • Access to your personal data
  • Correction of incomplete, inaccurate, or outdated data
  • Anonymization, blocking, or deletion of unnecessary or excessive data
  • Portability of data to another service provider
  • Deletion of personal data processed with consent
  • Information about public and private entities with which we share data
  • Information about the possibility of denying consent and the consequences
  • Revocation of consent

Our Data Protection Officer (DPO) can be reached at [email protected].

6. Your Rights Under CCPA (California)

California residents have additional rights under the CCPA:

  • Right to Know: What personal information is collected, used, shared, or sold
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: Opt out of the sale of personal information (we do NOT sell personal data)
  • Right to Non-Discrimination: Equal service and pricing regardless of exercising privacy rights

7. International Data Transfers

As a company based in Brazil, your data may be processed in Brazil. For EU/EEA users, we ensure adequate protection for international data transfers through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with all service providers
  • Technical and organizational measures to protect data during transfer
  • Compliance with Chapter V of the GDPR regarding international transfers

A Data Processing Addendum (DPA) is available upon request for enterprise customers.

8. Data Security Measures

We implement appropriate technical and organizational measures as required by GDPR Article 32:

  • TLS/SSL encryption for all data in transit (HTTPS enforced)
  • Encryption of sensitive data at rest
  • Passwords hashed using bcrypt (never stored in plain text)
  • Access controls with role-based permissions
  • Regular security audits and vulnerability assessments
  • Intrusion detection and monitoring systems
  • Employee training on data protection
  • Incident response procedures (see Section 9)

9. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the relevant Data Protection Authority within 72 hours of becoming aware of the breach (GDPR Art. 33)
  • Notify Meta within 48 hours if the breach involves Meta Platform data (as required by Meta Platform Terms Section 6)
  • Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34)
  • Document all breaches, including facts, effects, and remedial actions taken

10. Data Retention and Deletion

We retain personal data only for as long as necessary for the purposes described in our Privacy Policy:

  • Account Data: Duration of account + 30 days after deletion
  • Meta Integration Data: Deleted within 30 days of disconnection or account cancellation
  • Log/Security Data: 30 days
  • Backups: 30 days

You can request complete data deletion at any time. See our Data Deletion Policy for details.

All cookies and sessions are destroyed upon logout. We do not track user activity for commercial purposes.

11. Facebook Messenger and GDPR

Regarding the use of ChatBits for Facebook Messenger automation:

  • Users who initiate a conversation with your Facebook Page via Messenger provide implicit consent (opt-in) for receiving messages
  • All automated messages include an unsubscribe/opt-out mechanism
  • Subscriber data is stored securely and can be deleted upon request
  • We comply with Meta's 24-hour messaging window policy
  • We use proper message categorization (Message Tags) as required by Meta
  • Users can manage their subscription status at any time

12. Sub-Processors

We use the following categories of service providers (sub-processors) to deliver the Service:

  • Cloud Hosting: Secure data center infrastructure for application hosting
  • Payment Processing: Secure payment gateway for subscription billing
  • Email Delivery: Transactional email service for account notifications
  • Meta Platform APIs: Facebook and Instagram integration for chatbot functionality

All sub-processors are bound by data processing agreements that are at least as protective as our commitments to you.

13. Privacy by Design

In accordance with GDPR Article 25, we implement Privacy by Design and by Default:

  • We collect only the minimum data necessary for the Service (data minimization)
  • Privacy settings are configured to the most protective option by default
  • Data protection is integrated into our development process
  • We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing

14. How to Exercise Your Rights

To exercise any of your data protection rights:

  • Email: [email protected] with subject "Data Rights Request - [Your Right]"
  • Self-Service: Use your account settings to update profile information, manage connected pages, or delete your account
  • Data Deletion: Use our Data Deletion Request Form

We will respond to all requests within 30 days. If we need more time (up to 60 additional days for complex requests), we will inform you of the reason for the extension.

15. Contact Our Data Protection Team

  • Data Protection Officer (DPO): [email protected]
  • Company: M D LABS CONSULTORIA E TREINAMENTOS LTDA
  • Location: Cabo Frio, RJ, Brazil
  • CNPJ: 32.174.043/0001-80

For EU users: You also have the right to lodge a complaint with your local Supervisory Authority (Data Protection Authority).

16. Related Documents