Legal & Security

Privacy Policy

Last Updated: August 2026 • Effective Date: August 21, 2026

This Privacy Policy governs the processing of personal data across the CLOZR platform, web applications, WhatsApp bot integrations, APIs, and AI coaching services (collectively, the "Services") operated by CLOZR, Lda. ("CLOZR", "we", "us", or "our"). We are committed to safeguarding corporate and individual privacy under the GDPR (EU), LGPD (Brazil), CCPA/CPRA (California), and international data protection standards.

1 Who We Are & Roles Under Data Protection Laws

CLOZR provides an AI-powered field sales intelligence platform that captures voice notes submitted via WhatsApp or web browsers, transcribes audio, extracts structured CRM deal parameters, audits sales methodology adherence, and provides real-time tactical auto-coaching to sales representatives and leadership.

Data Processor (Data Operator):

For audio recordings, transcripts, CRM fields, and customer account data submitted by your sales representatives, CLOZR acts as a Data Processor on behalf of your company (the Data Controller).

Data Controller:

For account registration data, billing records, direct customer support communications, and website telemetry, CLOZR acts as a Data Controller.

2 What Data We Collect

1. Voice Notes & Audio Submissions (Web & WhatsApp)

Audio voice notes (`.ogg`, `.opus`, `.m4a`, `.mp3`, `.wav`) recorded by sales reps directly via our Progressive Web App (PWA) or sent through the official CLOZR WhatsApp bot. Audio is transmitted via encrypted HTTPS/TLS 1.3 channels and processed for speech-to-text transcription.

2. WhatsApp Profile & Messaging Metadata

When reps interact via WhatsApp, we collect their authorized WhatsApp phone number, sender display name, message timestamps, and message IDs exclusively to authenticate rep identity, link debriefs to the correct company account, and deliver auto-coaching reply messages.

3. Structured Sales & Visit Intelligence

AI-extracted sales parameters (prospect company name, buyer personas, identified budget thresholds, competitors mentioned, objection notes, next steps, and deal scores). This data remains strictly isolated to your tenant organization.

4. User Account & Identity Data

Full names, business email addresses, company name, role (rep vs. manager), assigned territory, and secure cryptographically hashed authentication credentials.

5. Billing & Subscription Data

Payment information is processed directly by Stripe (PCI-DSS Level 1 Service Provider). CLOZR does not store raw credit card numbers or CVV codes.

6. Technical Telemetry & Cookies

Essential session tokens, IP addresses (anonymized), device types, and operating systems required for secure session management and fraud prevention.

3 Technology Stack & Sub-processors

We work exclusively with certified infrastructure providers bound by formal Data Processing Agreements (DPAs) and European Standard Contractual Clauses (SCCs):

OpenAI Inc.
AI transcription (Whisper API) & structured extraction (GPT-4o API). Zero Data Retention: Customer data is processed via enterprise API and is strictly NOT used to train public or foundational AI models.
Meta Platforms (WhatsApp Cloud API)
Secure transport of WhatsApp voice notes and delivery of real-time auto-coaching debrief messages. End-to-end encrypted in transit to WhatsApp infrastructure.
Supabase Inc. / AWS (Frankfurt, EU)
Primary encrypted PostgreSQL database, Row Level Security (RLS) tenant isolation, secure user authentication, and AES-256 object storage for audio files.
Vercel Inc.
Web application hosting, serverless edge compute, and CDN routing across secure EU edge networks.
Stripe Payments Europe Ltd.
PCI-DSS Level 1 compliant payment gateway and billing subscription lifecycle management.
Resend Inc.
Transactional email delivery for magic links, account invitations, and automated weekly sales performance summaries.

4 Artificial Intelligence & Model Training Safeguards

Strict No-Training Guarantee

We maintain a strict zero-data-training policy. Under our enterprise agreements with OpenAI and cloud AI sub-processors:

  • Your audio recordings and transcripts are NEVER used to train, retrain, or improve foundational AI models.
  • All AI inferences are performed in stateless, isolated memory contexts.
  • Extracted customer intelligence belongs 100% to your enterprise.

5 Data Storage, Encryption & Tenant Isolation

  • Encryption in Transit: All HTTP and WebSocket communications use TLS 1.3 encryption with strong cipher suites.
  • Encryption at Rest: Database records, transcripts, and audio storage volumes are encrypted using AES-256 encryption.
  • Tenant Isolation via Row Level Security (RLS): Every database query enforces strict tenant isolation at the database kernel level. No customer can ever view or access another customer's data.
  • Audio Lifecycle Management: Raw audio recordings are stored temporarily in encrypted storage for a maximum of 90 days (for playback and verification purposes) and are permanently purged thereafter.

6 Your Legal Rights (GDPR, LGPD & CCPA)

Depending on your jurisdiction, you and your sales representatives hold enforceable legal rights:

GDPR & LGPD Rights:
  • • Right of access & data portability
  • • Right to rectification of inaccurate data
  • • Right to erasure ("Right to be forgotten")
  • • Right to restriction or objection to processing
  • • Right to revoke consent at any time
CCPA / CPRA Rights:
  • • Right to know what personal info is collected
  • • Right to delete personal information
  • • Right to opt-out of data sales (CLOZR does not sell data)
  • • Right to non-discrimination

To exercise your rights, email our Data Protection team at hello@getclozr.app. Requests are fulfilled within 30 days free of charge.

7 Contact & Data Protection Officer

CLOZR, Lda. • Data Protection Office

Enterprise Privacy, Regulatory & Security Inquiries

Email: hello@getclozr.app

Supervisory Authority: Comissão Nacional de Proteção de Dados (CNPD) / ANPD (Brazil) / AEPD (Spain)