Last modified on August 21, 2026.
Coral Messaging, Inc., a company incorporated and headquartered in the United States of America, contact email privacy@coralmessaging.com and website www.coralmessaging.com ("Coral Messaging"), is a technology platform that allows companies to conduct and oversee commercial conversations on messaging platforms.
Law No. 13,709/2018 (LGPD) applies to the activities described in this Policy pursuant to its Article 3, since Coral Messaging offers services to clients located in the national territory and processes personal data of data subjects in Brazil. The General Data Protection Regulation of the European Union (GDPR) applies where relevant when Coral Messaging processes personal data of data subjects located in that territory, US federal and state laws (such as CCPA/CPRA), laws in force in Latin America, including LFPDPPP in Mexico, Law 1581 in Colombia, Law 25,326 in Argentina, Law 19,628 in Chile, and Law 29733 in Peru, as well as any other local data protection and privacy legislation applicable in other countries or territories where Coral Messaging has operations, infrastructure, or offers its services.
This Policy complements the Terms of Service published on Coral Messaging's website.
This Policy establishes the guidelines that guide the personal data processing carried out by Coral Messaging, detailing which data are collected, for what purposes, on what legal grounds, for how long they are retained, with whom they may be shared, and what rights data subjects may exercise.
This Policy applies to the processing of personal data carried out by Coral Messaging within the scope of its platform, its institutional website, and its relationship with clients, employees, job candidates, and suppliers. It also applies to the personal data of representatives and commercial contacts of Coral Messaging's clients, as well as, where relevant to Coral Messaging's role as a processor, to the personal data of buyers and sellers whose commercial conversations traverse the platform.
Coral Messaging operates under two distinct roles, depending on the nature of the personal data involved:
Includes message content, files, and metadata of conversations conducted between sellers and buyers through messaging platforms, including date, time, and participants. This data is processed by Coral Messaging in its capacity as operator / processor, with the purpose of providing visibility and records of commercial conversations to the client controller. Retention periods and any archiving functionalities intended to comply with the client's regulatory obligations are defined in the applicable Client Agreement.
Under the Terms of Service, the client controller instructs Coral Messaging to access and analyze conversation data to the extent necessary to provide the Services, detect, investigate, and prevent security incidents, fraud, and platform misuse, respond to support requests, and verify compliance with the executed contract. Coral Messaging presumes that all Personal Data processed in this context serves strictly corporate purposes, with the Controller assuming that there is no expectation of personal privacy regarding communications stored on personal devices or accounts.
Includes name, title, phone number, email, and other identification data of representatives and commercial contacts of client companies, collected to enable account creation, platform configuration, technical support, communication regarding service updates, and commercial and financial management of the contractual relationship.
Includes IP address, browser and device type and version, pages visited, and other access log data collected when the data subject visits Coral Messaging's institutional website, for the purpose of ensuring platform security, complying with legal obligations regarding access log retention, and understanding site usage for continuous improvement.
Includes personal data of employees, former employees, job applicants, and supplier representatives of Coral Messaging, processed for managing employment relationships, recruitment processes, payroll, and compliance with labor, social security, and tax obligations, as well as managing supplier contracts.
Coral Messaging generates statistical data regarding the use of Services and may aggregate and anonymize data originating from the platform, using the result for the development and improvement of its products and services and for preparing reports and materials. Aggregated and anonymized data are not disclosed in a way that allows identifying the client, its sellers, or its buyers. Under applicable data protection laws, effectively anonymized or de-identified data are not considered personal data, ceasing to be subject to the provisions of this Policy as long as anonymization or non-re-identification is maintained.
Coral Messaging's platform is not intended for collecting or processing Sensitive Personal Data / special categories of data (as defined by local data protection laws), and the client controller must refrain from using the Services for this purpose, under Coral Messaging's Terms of Service.
Coral Messaging's Services are intended for corporate use and are not directed to minors (such as children and adolescents, as defined by local laws). Coral does not knowingly collect personal data from minors. If a client company (Controller) uses the platform to process data of minors, it will be responsible for ensuring parental authorizations and observing legally required consent across applicable jurisdictions.
Personal data processing by Coral Messaging is grounded on the following legal bases provided under applicable data protection laws, depending on the category of data and the purpose involved:
Coral Messaging operates its platform on top of the WhatsApp Groups API, provided by Meta Platforms. When a message is sent, it travels encrypted between the WhatsApp user and Meta's infrastructure, which decrypts it and forwards it to the recipient company, including Coral Messaging, with Meta acting in this intermediation as an operator or service provider processing data on behalf of the controller. Meta retains messages for a limited period on its infrastructure solely to enable delivery and related API features, after which they are deleted from its environment, except for optional specific regional storage for regulated sector clients or local legal record-keeping requirements. Upon receipt by Coral Messaging, data is processed in accordance with the other provisions of this Policy.
The use and transfer by Coral Messaging of information received from Google APIs to any other app will adhere strictly to the Google API Services User Data Policy, including Limited Use requirements. Coral Messaging guarantees that Personal Data originating from Google Workspace (such as Gmail) will be used exclusively to provide or improve user-facing features. This data will not be used for advertising, nor will it be sold or transferred to third parties, except to comply with legal obligations or corporate transactions (such as mergers, acquisitions, or restructurings).
Coral Messaging utilizes artificial intelligence technologies to generate summaries, flags, and suggestions that assist sellers in monitoring commercial conversations. This processing is performed through language model providers accessed via Coral Messaging's own contracted cloud infrastructure, so that conversation content is not transmitted to external environments for this purpose. Coral Messaging's AI features assist human decision-making and do not produce, by themselves, automated decisions affecting data subjects' interests without human intervention, complying with automated decision regulations in applicable jurisdictions. Coral Messaging expressly guarantees that it will not use commercial conversation data or Personal Data Processed on behalf of the Controller to train foundational AI models of third-party vendors (Zero Data Retention policy).
Coral Messaging shares personal data with third parties strictly to the extent necessary to provide its services:
A complete and updated list of subprocessors can be requested by Coral Messaging clients through the channel indicated in Section 16 of this Policy.
The cloud infrastructure utilized by Coral Messaging is located in the United States. Additionally, messages exchanged via the WhatsApp API may transit through Meta's infrastructure located outside the country of origin of the Data Subject or Controller. As such, data processing by Coral Messaging may involve international data transfers.
Coral Messaging ensures that these transfers strictly comply with legal mechanisms and safeguards established by applicable data protection laws, including mechanisms under Art. 33 of LGPD in Brazil, standard contractual clauses under Resolution CD/ANPD No. 19/2024 where applicable, Standard Contractual Clauses (SCCs) adopted in the European Union, Latin America, and Brazil, as well as frameworks like the EU-U.S. Data Privacy Framework or explicit consents, depending on the data's origin jurisdiction. Additionally, it requires infrastructure vendors to maintain equivalent protection levels and implement technical, administrative, and legal safeguards to ensure information security in transit and storage.
Personal data is retained for the period necessary to fulfill the purposes of this Policy, per standard procedures adopted by Coral Messaging and in strict compliance with applicable local laws, based on the following criteria:
Notwithstanding the stated periods, Coral Messaging reserves the right to retain Personal Data beyond the agreed term if there is a legal or regulatory obligation, an ongoing legal investigation, or an order from a competent authority requiring information preservation.
Coral Messaging adopts internationally recognized technical and administrative measures aimed at protecting personal data against unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination, including encryption in transit (TLS) and strict access controls and physical/logical security measures appropriate for protecting stored data, based on the principle of least privilege. The technical and organizational information security measures adopted by Coral Messaging are detailed in its Information Security Policy, available upon request. Coral Messaging requires technology vendors to maintain an equivalent level of protection.
As a Processor, should Coral Messaging identify any security incident affecting commercial conversation data, it commits to notifying the client company (Controller) in a timely manner according to contractual terms and applicable laws, offering necessary support for investigation and event mitigation as agreed in the contract.
Under data protection laws across various jurisdictions, including LGPD in Brazil, GDPR in the EU, US state laws such as CCPA/CPRA, and Latin American laws like LFPDPPP in Mexico, Law 1,581 in Colombia, and Law 25,326 in Argentina, Data Subjects hold specific rights such as ARCO Rights (Access, Rectification, Cancellation, and Opposition), alongside other specific rights, which may be exercised upon request:
When the request involves commercial conversation data processed by Coral Messaging as a Processor, the request may be forwarded to the responsible client company acting as controller, with Coral Messaging supporting fulfillment per contract terms.
Data subjects can exercise their rights by sending a written request to the channel indicated in Section 16 of this Policy. The request must contain the full name of the data subject, contact details for response, identity verification document (when required by law or strictly necessary for security verification), and a clear description of the right to be exercised and the data involved. Coral Messaging will respond within a reasonable timeframe and within statutory deadlines established by applicable law in the subject's jurisdiction, and may request additional information to confirm identity or locate requested data.
Coral Messaging's institutional website uses cookies and similar technologies, including web beacons, to enable website functionality, authenticate sessions, remember language preferences, and understand browsing patterns for continuous improvement.
A portion of these cookies allows third parties, including Google and Meta, to display Coral Messaging ads on social media platforms and other online channels within ad retargeting campaigns. If the user provides personal data on the site, such data may be linked to information stored in cookies. Installing non-essential cookies (such as third-party advertising and analytics cookies) is subject to explicit prior user consent, which can be managed, granted, or revoked at any time via our cookie preference panel on the website. Users can also configure their browsers to block cookies, though this may affect certain features. This Policy does not cover nor make Coral Messaging responsible for third-party cookies or tracking technologies present on external links.
Coral Messaging provides the communication channel privacy@coralmessaging.com for data subjects, clients, and authorities regarding personal data protection matters, including exercising rights under this Policy and clarifying doubts about processing. Coral Messaging has a formally designated Data Protection Officer (DPO), who can be reached directly at privacy@coralmessaging.com for exercising rights, seeking clarification, or communicating with Data Protection Authorities across any jurisdiction.
When Coral Messaging engages third parties to process personal data on its behalf (subprocessors/data subprocessors), the following minimum duties are contractually established:
Coral Messaging may modify this Policy at any time to reflect changes in data processing practices or applicable legislation. Substantial changes, especially those impacting data subject rights or processing purposes, will be communicated via the website or email, with periodic review recommended. The revised version will indicate its last update date at the beginning or end of this document.
In compliance with the Children's Online Privacy Protection Act (COPPA), Coral Messaging Services are B2B in nature and are not directed to nor intentionally collect Personal Data from children under 13 (thirteen) years of age in the United States.
Notice to California Residents (CCPA/CPRA) and other state laws: Coral Messaging acts strictly as a "Service Provider" regarding commercial conversation data. We expressly declare that we do not "sell" or "share" Personal Data for cross-context behavioral advertising purposes. Over the past 12 (twelve) months, we collected the Personal Data categories described in Section 5 of this Policy exclusively for business purposes. Depending on the state of residence, data subjects may hold additional rights, such as the Right to Appeal, request corrections, or opt out, exercisable via email at privacy@coralmessaging.com.
The Terms of Service of Coral Messaging elect the laws of the State of New York and the exclusive jurisdiction of the state and federal courts located in the Borough of Manhattan, City of New York, for disputes arising therefrom.
This choice of law does not preclude the application of mandatory local data protection laws, such as LGPD in Brazil pursuant to its Art. 3, GDPR in the European Union, and other regional laws, to the processing of personal data of data subjects located in their respective territories, nor does it prejudice the rights guaranteed to such subjects by applicable national laws or the jurisdiction of competent courts and Data Protection Authorities in each jurisdiction.