Fintalk

Privacy Policy

Updated October 2025

1. Purpose and Scope

FINTALK is committed to the privacy and confidentiality of the information provided by everyone it does business with.

This Privacy Notice describes how we collect, use, store and share personal data in our activities and digital platforms, in compliance with Brazilian Law No. 13,709/2018 (LGPD) and complementary regulations issued by the Brazilian National Data Protection Authority (ANPD).

It applies to all visitors, customers, suppliers, partners and users who interact with the website https://fintalk.ai or use our services.

2. Definitions

  • Personal data: any information relating to an identified or identifiable natural person.
  • Data subject: the natural person to whom the personal data relates.
  • Controller: the legal entity that makes decisions regarding the processing of personal data (FINTALK).
  • Processor: the legal entity that processes personal data on behalf of the controller.
  • Data Protection Officer (DPO): the person appointed by the controller to act as a communication channel between the controller, data subjects and the ANPD.
  • ANPD: Brazilian National Data Protection Authority.
  • Cookies: files or technologies that store information about the user's browsing.

3. Who We Are and Controller Identification

FINTALK S.A. provides technology for companies to communicate with their consumers through conversational artificial intelligence, via voice and text.

Our company is registered under CNPJ No. 33.143.233/0001-00, headquartered at Rua Butantã, 194 - 4º andar - Pinheiros, São Paulo/SP, CEP 05.424-000, Brazil, and is the controller of the personal data processed on this website and its platforms.

The company operates in compliance with Brazilian law, including Resolution No. 3,954/2011 of the National Monetary Council (CMN), and maintains governance practices aligned with the LGPD and ANPD resolutions.

4. Support Channels and Data Protection Officer (DPO) Contact

If you have questions about this Notice or wish to exercise any of your rights as a data subject, you can contact us through the following official channels:

  • Data Protection Officer (DPO): Bruno Souza Pinto
  • Deputy DPO: Eduardo Calazans
  • Email: [email protected]
  • Address: R. Butantã, 194 - 4º andar - Pinheiros, São Paulo - SP, 05424-000, Brazil

We are committed to responding to your requests within an appropriate timeframe, in compliance with the Brazilian General Data Protection Law.

5. Personal Data Collected

We collect only the data strictly necessary to deliver our services and support activities, including:

Data is collected directly (via forms, website, chatbots) or indirectly (through authorized processors).

  • Cookies
  • Full name, email address, phone number and company
  • Digital identification data (IP address, online identifiers, access logs)
  • Information required to execute proposals and contracts with financial institutions, such as account opening, credit applications and registration updates

6. Legal Bases for Data Processing

We process personal data under the following circumstances:

  • Compliance with a legal or regulatory obligation (Art. 7, II): when processing is necessary to meet requirements imposed by Brazilian law or regulatory authorities (e.g. Central Bank, COAF, CMN).
  • Performance of a contract or preliminary procedures (Art. 7, V): when personal data is processed to perform contracts entered into with data subjects or to carry out pre-contractual steps.
  • Legitimate interest of the controller (Art. 7, IX): use of personal data for promotion, prospecting and offering of financial products and services, always respecting the data subject's right to object (opt-out).
  • Consent of the data subject (Art. 7, I): use of personal data for digital marketing, non-essential cookies, newsletters or personalized communications, based on a free, informed and unambiguous statement by the data subject, which may be revoked at any time.

FINTALK ensures that all processing based on legitimate interest is preceded by an impact assessment and allows opt-out at any time.

7. Sharing and International Transfer

Personal data may be stored on servers located abroad. In such cases, specific contractual clauses and security measures compatible with the level of protection required by the LGPD (art. 33 et seq.) are adopted.

  • Compliance with legal or regulatory obligations (Art. 7, II): disclosure to public bodies or regulators (e.g. Central Bank, COAF, Federal Revenue), when required by law.
  • Service providers and technology processors (Art. 7, V): involvement of infrastructure, hosting, security, data analytics and technical support providers (such as AWS, Google Cloud, Microsoft Azure), acting under a processor agreement.
  • Judicial or administrative authorities (Art. 7, VI): provision of data under court order, administrative proceedings or the regular exercise of rights.
  • International transfer to cloud providers (Art. 33): storage on servers located outside Brazil, in accordance with art. 33 of the LGPD and contractual clauses ensuring an adequate level of protection.

8. Security Measures and Data Retention

We adopt technical and administrative security controls aligned with standards such as ISO/IEC 27001, ISO/IEC 27002 and the NIST Cybersecurity Framework, including:

Data is kept only for as long as necessary to fulfil its purposes or legal obligations, pursuant to arts. 15 and 16 of the LGPD and Resolution CD/ANPD No. 15/2024. After that period, it is securely and auditably deleted.

  • Encryption of data at rest and in transit
  • Role-based access control (RBAC)
  • Multi-factor authentication
  • Logging and log monitoring
  • Periodic vulnerability testing

9. Use of Cookies and Tracking Technologies

We use cookies in our online environments to improve your browsing experience, ensuring performance, security and personalization according to your preferences and recurring visits.

Two types of cookies may be used: session cookies (temporary, automatically deleted when you close the browser) and persistent cookies (remain on the device for the period defined for each cookie or according to browser settings).

If you prefer, you can manage your cookie preferences directly in your browser.

Categories and purposes:

  • Necessary cookies: ensure the basic functioning of the website and security features.
  • Functional cookies: enable additional features, such as social sharing, feedback and third-party integrations.
  • Performance cookies: analyze website usage to optimize speed and usability, mapping improvement points in the user experience.
  • Analytics cookies: provide access and interaction metrics, such as number of visitors and most visited pages.
  • Advertising cookies: display personalized ads according to your interests and browsing behavior.

Third-party tools used: Google Ads (conversion measurement and advertising), Hotjar (behavior and performance analytics) and LinkedIn Insight Tag (campaign measurement, retargeting and audience analytics on LinkedIn). These tools may set cookies and collect browsing identifiers, IP address, pages visited and device data, processed according to each vendor's privacy policy.

10. Data Subject Rights and How to Exercise Them

Data subjects have the rights set out in arts. 18 to 20 of the LGPD, including:

  • Confirmation of the existence of processing and access to data
  • Correction of incomplete or outdated data
  • Anonymization, blocking or deletion of unnecessary data
  • Data portability
  • Deletion of data processed under consent
  • Information about sharing carried out
  • Revocation of consent
  • Review of automated decisions

Requests must be sent to our support channel, by email to [email protected], as indicated in Section 4 of this Privacy Notice.

Responses will be provided within a reasonable timeframe and within the limits established by applicable law, ensuring transparency and respect for data subjects' rights.

11. Changes to this Notice

This Notice may be amended to reflect legal, regulatory or technological changes.

The new version will be published on FINTALK's website with the update date indicated. We recommend that data subjects review this document periodically.

12. Legal and Regulatory References

  • Law No. 13,709/2018 – Brazilian General Data Protection Law (LGPD)
  • Resolution CD/ANPD No. 2/2022 – Processing Agents and Data Protection Officer
  • Resolution CD/ANPD No. 3/2022 – Dosimetry and Sanctions
  • Resolution CD/ANPD No. 4/2023 – Administrative Sanctioning Procedure
  • Resolution CD/ANPD No. 15/2024 – Incident Reporting and Processing Records
  • Cookies and Tracking Technologies Guide (ANPD, 2024)
  • Information Security and Best Practices Guide (ANPD, 2023)