Privacy Policy

Last modified on August 21, 2026.

Coral Messaging, Inc., a company incorporated and headquartered in the United States of America, contact email privacy@coralmessaging.com and website www.coralmessaging.com ("Coral Messaging"), is a technology platform that allows companies to conduct and oversee commercial conversations on messaging platforms.

Law No. 13,709/2018 (LGPD) applies to the activities described in this Policy pursuant to its Article 3, since Coral Messaging offers services to clients located in the national territory and processes personal data of data subjects in Brazil. The General Data Protection Regulation of the European Union (GDPR) applies where relevant when Coral Messaging processes personal data of data subjects located in that territory, US federal and state laws (such as CCPA/CPRA), laws in force in Latin America, including LFPDPPP in Mexico, Law 1581 in Colombia, Law 25,326 in Argentina, Law 19,628 in Chile, and Law 29733 in Peru, as well as any other local data protection and privacy legislation applicable in other countries or territories where Coral Messaging has operations, infrastructure, or offers its services.

This Policy complements the Terms of Service published on Coral Messaging's website. 

1. Objective

This Policy establishes the guidelines that guide the personal data processing carried out by Coral Messaging, detailing which data are collected, for what purposes, on what legal grounds, for how long they are retained, with whom they may be shared, and what rights data subjects may exercise.

2. Scope

This Policy applies to the processing of personal data carried out by Coral Messaging within the scope of its platform, its institutional website, and its relationship with clients, employees, job candidates, and suppliers. It also applies to the personal data of representatives and commercial contacts of Coral Messaging's clients, as well as, where relevant to Coral Messaging's role as a processor, to the personal data of buyers and sellers whose commercial conversations traverse the platform.

3. Definitions

  • Authorization of the data subject (Consent): Free, informed, specific, and unequivocal manifestation of will by which the data subject agrees to the processing of their personal data for specified purposes.
  • Data Controller: Natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Data Processor: Natural or legal person, public authority, agency, or other body which processes personal data on behalf of and under the instructions of the Controller.
  • Personal Data: Any information relating to an identified or identifiable natural person ("Data Subject"); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier (such as a name, an identification number, location data, an online identifier, etc.).
  • Sensitive Personal Data / Special Category of Data: Personal data that requires a higher degree of protection due to its critical nature, including data revealing racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic data, biometric data, data concerning health, sex life or sexual orientation, as well as other data considered sensitive under applicable local laws.
  • Data Protection Officer / DPO: Person or team appointed by the Controller/Processor to act as a communication channel between the organization, data subjects, and competent Data Protection Authorities, ensuring compliance with applicable legislation.
  • Data Subject: Natural person to whom the personal data being processed refers.
  • Cross-Border Data Transfer: Transfer, transmission, sharing, or granting access to personal data to recipients located in a foreign country or to international organizations, subject to safeguards and legal mechanisms required by applicable data protection laws.
  • Data Processing: Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, modification, transfer, or destruction.
  • Data Protection Authority / Supervisory Authority (DPA): Independent entity, body, or public authority responsible for monitoring, ensuring, and enforcing compliance with personal data protection legislation in the applicable jurisdiction (such as ANPD in Brazil, DPAs in the European Union, and equivalent bodies in other territories).

4. Roles of Coral Messaging in Data Processing

Coral Messaging operates under two distinct roles, depending on the nature of the personal data involved:

  • As a Processor: regarding the content of commercial conversations conducted by sellers and buyers on the platform, including messages, attachments, and associated metadata, Coral Messaging processes data on behalf of and under instruction from the contracting client, who acts as the controller of this data. Data subject requests concerning these conversations are, whenever possible, directed or forwarded to the responsible controller, with Coral Messaging assisting in compliance as per the contract executed with the client. In Latin American jurisdictions and the United States, the Controller declares and warrants that it is solely responsible for obtaining the documented Consent of its employees and clients prior to using the platform, holding Coral Messaging harmless from any claim arising from the lack of Data Subject Authorization or breach of privacy expectations in electronic communications;
  • As a Controller: regarding the registration data of its own client base, such as name, title, phone, and email of representatives and commercial contacts of contracting companies, data collected on its institutional website, and data of its own employees, candidates, and suppliers, Coral Messaging decides the purposes and means of processing, being directly accountable to data subjects and competent Data Protection Authorities.

5. Personal Data Processed and Purposes

5.1. Commercial Conversation Data

Includes message content, files, and metadata of conversations conducted between sellers and buyers through messaging platforms, including date, time, and participants. This data is processed by Coral Messaging in its capacity as operator / processor, with the purpose of providing visibility and records of commercial conversations to the client controller. Retention periods and any archiving functionalities intended to comply with the client's regulatory obligations are defined in the applicable Client Agreement.

Under the Terms of Service, the client controller instructs Coral Messaging to access and analyze conversation data to the extent necessary to provide the Services, detect, investigate, and prevent security incidents, fraud, and platform misuse, respond to support requests, and verify compliance with the executed contract. Coral Messaging presumes that all Personal Data processed in this context serves strictly corporate purposes, with the Controller assuming that there is no expectation of personal privacy regarding communications stored on personal devices or accounts.

5.2. Registration and Account Data

Includes name, title, phone number, email, and other identification data of representatives and commercial contacts of client companies, collected to enable account creation, platform configuration, technical support, communication regarding service updates, and commercial and financial management of the contractual relationship.

5.3. Website Browsing Data

Includes IP address, browser and device type and version, pages visited, and other access log data collected when the data subject visits Coral Messaging's institutional website, for the purpose of ensuring platform security, complying with legal obligations regarding access log retention, and understanding site usage for continuous improvement.

5.4. Employee, Candidate, and Supplier Data

Includes personal data of employees, former employees, job applicants, and supplier representatives of Coral Messaging, processed for managing employment relationships, recruitment processes, payroll, and compliance with labor, social security, and tax obligations, as well as managing supplier contracts.

5.5. Usage Data, Aggregated Data, and Anonymized Data

Coral Messaging generates statistical data regarding the use of Services and may aggregate and anonymize data originating from the platform, using the result for the development and improvement of its products and services and for preparing reports and materials. Aggregated and anonymized data are not disclosed in a way that allows identifying the client, its sellers, or its buyers. Under applicable data protection laws, effectively anonymized or de-identified data are not considered personal data, ceasing to be subject to the provisions of this Policy as long as anonymization or non-re-identification is maintained.

Coral Messaging's platform is not intended for collecting or processing Sensitive Personal Data / special categories of data (as defined by local data protection laws), and the client controller must refrain from using the Services for this purpose, under Coral Messaging's Terms of Service.

5.6. Minors' Data

Coral Messaging's Services are intended for corporate use and are not directed to minors (such as children and adolescents, as defined by local laws). Coral does not knowingly collect personal data from minors. If a client company (Controller) uses the platform to process data of minors, it will be responsible for ensuring parental authorizations and observing legally required consent across applicable jurisdictions.

6. Legal Bases for Processing

Personal data processing by Coral Messaging is grounded on the following legal bases provided under applicable data protection laws, depending on the category of data and the purpose involved:

  • Performance of contract: for processing commercial conversation data and registration data necessary to perform the services contracted by the client;
  • Compliance with legal or regulatory obligation: for compliance with legal and regulatory obligations applicable to Coral Messaging and for data retention when required by regulations to which the client controller is subject, as set forth in the Customer Agreement;
  • Legitimate interest: for maintaining platform security, fraud prevention, and service improvement, always preceded by a proportionality assessment and without prejudice to the fundamental rights and freedoms of data subjects;
  • Consent: when applicable to specific communication and marketing purposes that do not arise directly from contract performance.

7. The Role of WhatsApp and Meta in the Data Chain and Use of Google APIs

Coral Messaging operates its platform on top of the WhatsApp Groups API, provided by Meta Platforms. When a message is sent, it travels encrypted between the WhatsApp user and Meta's infrastructure, which decrypts it and forwards it to the recipient company, including Coral Messaging, with Meta acting in this intermediation as an operator or service provider processing data on behalf of the controller. Meta retains messages for a limited period on its infrastructure solely to enable delivery and related API features, after which they are deleted from its environment, except for optional specific regional storage for regulated sector clients or local legal record-keeping requirements. Upon receipt by Coral Messaging, data is processed in accordance with the other provisions of this Policy.

The use and transfer by Coral Messaging of information received from Google APIs to any other app will adhere strictly to the Google API Services User Data Policy, including Limited Use requirements. Coral Messaging guarantees that Personal Data originating from Google Workspace (such as Gmail) will be used exclusively to provide or improve user-facing features. This data will not be used for advertising, nor will it be sold or transferred to third parties, except to comply with legal obligations or corporate transactions (such as mergers, acquisitions, or restructurings).

8. Use of Artificial Intelligence in Data Processing

Coral Messaging utilizes artificial intelligence technologies to generate summaries, flags, and suggestions that assist sellers in monitoring commercial conversations. This processing is performed through language model providers accessed via Coral Messaging's own contracted cloud infrastructure, so that conversation content is not transmitted to external environments for this purpose. Coral Messaging's AI features assist human decision-making and do not produce, by themselves, automated decisions affecting data subjects' interests without human intervention, complying with automated decision regulations in applicable jurisdictions. Coral Messaging expressly guarantees that it will not use commercial conversation data or Personal Data Processed on behalf of the Controller to train foundational AI models of third-party vendors (Zero Data Retention policy).

9. Data Sharing and Subprocessors

Coral Messaging shares personal data with third parties strictly to the extent necessary to provide its services:

  • Meta Platforms: as intermediary for the WhatsApp Groups API, as described in Section 7 of this Policy;
  • Cloud infrastructure provider: for platform hosting, data storage, and processing of AI functionalities under contractual security and confidentiality obligations;
  • Other service providers: tools supporting Coral Messaging's commercial, technical, and support operations may have limited access to certain categories of personal data, strictly for the purpose of delivering contracted services under confidentiality and security obligations equivalent to those in this Policy;
  • Integrations contracted by the client: when the client chooses to integrate the platform with third-party products, such as customer relationship management systems, Coral Messaging may access contact lists and other data in those products exclusively to enable contracted functionalities. Processing by third-party products is governed by their respective vendor terms and policies;
  • Competent authorities: when required by law, court order, or administrative authority request;
  • Corporate transactions: in case of merger, acquisition, or corporate restructuring, subject to the successor party's commitment to observe the terms of this Policy.

A complete and updated list of subprocessors can be requested by Coral Messaging clients through the channel indicated in Section 16 of this Policy.

10. Cross-Border Data Transfer

The cloud infrastructure utilized by Coral Messaging is located in the United States. Additionally, messages exchanged via the WhatsApp API may transit through Meta's infrastructure located outside the country of origin of the Data Subject or Controller. As such, data processing by Coral Messaging may involve international data transfers.

Coral Messaging ensures that these transfers strictly comply with legal mechanisms and safeguards established by applicable data protection laws, including mechanisms under Art. 33 of LGPD in Brazil, standard contractual clauses under Resolution CD/ANPD No. 19/2024 where applicable, Standard Contractual Clauses (SCCs) adopted in the European Union, Latin America, and Brazil, as well as frameworks like the EU-U.S. Data Privacy Framework or explicit consents, depending on the data's origin jurisdiction. Additionally, it requires infrastructure vendors to maintain equivalent protection levels and implement technical, administrative, and legal safeguards to ensure information security in transit and storage.

11. Data Retention and Deletion

Personal data is retained for the period necessary to fulfill the purposes of this Policy, per standard procedures adopted by Coral Messaging and in strict compliance with applicable local laws, based on the following criteria:

  • Contract duration: commercial conversation data and registration data are retained while the contractual relationship with the client persists, subject to applicable retention periods;
  • Access logs: site and platform access logs are retained for the period necessary for security purposes, service enhancement, and compliance with statutory record-keeping duties under local jurisdictions;
  • Contract termination: upon termination of the agreement with the client, related data is erased via secure methods, except where mandatory retention is required by law, regulation, or contractual archiving obligations, or returned per client controller instructions;
  • Employees and suppliers: data is retained for the period required by labor, social security, tax, and civil regulations applicable in each country of operation.

Notwithstanding the stated periods, Coral Messaging reserves the right to retain Personal Data beyond the agreed term if there is a legal or regulatory obligation, an ongoing legal investigation, or an order from a competent authority requiring information preservation.

12. Information Security

Coral Messaging adopts internationally recognized technical and administrative measures aimed at protecting personal data against unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination, including encryption in transit (TLS) and strict access controls and physical/logical security measures appropriate for protecting stored data, based on the principle of least privilege. The technical and organizational information security measures adopted by Coral Messaging are detailed in its Information Security Policy, available upon request. Coral Messaging requires technology vendors to maintain an equivalent level of protection.

As a Processor, should Coral Messaging identify any security incident affecting commercial conversation data, it commits to notifying the client company (Controller) in a timely manner according to contractual terms and applicable laws, offering necessary support for investigation and event mitigation as agreed in the contract.

13. Data Subjects' Rights

Under data protection laws across various jurisdictions, including LGPD in Brazil, GDPR in the EU, US state laws such as CCPA/CPRA, and Latin American laws like LFPDPPP in Mexico, Law 1,581 in Colombia, and Law 25,326 in Argentina, Data Subjects hold specific rights such as ARCO Rights (Access, Rectification, Cancellation, and Opposition), alongside other specific rights, which may be exercised upon request:

  • Confirmation and access: confirm the existence of processing and access personal data stored by Coral Messaging;
  • Correction: request correction of incomplete, inaccurate, or outdated data;
  • Anonymization, blocking, or deletion: request anonymization, blocking, restriction, or deletion of unnecessary, excessive, or non-compliant data under applicable laws;
  • Portability: request data transfer/portability to another service provider or directly to the data subject, per local technical and regulatory parameters;
  • Information on sharing: know which public or private entities Coral Messaging has shared data with;
  • Revocation of consent: revoke consent at any time or exercise opt-out rights where these serve as legal bases or mechanisms in applicable jurisdictions, understanding potential refusal consequences;
  • Objection: object to processing carried out based on consent waiver hypotheses or legitimate interest, in case of non-compliance with data protection rules;
  • Right against automated decision-making: request review or contest decisions made solely based on automated data processing that affect their interests;
  • Petition: file a complaint before the competent data protection authority, such as ANPD in Brazil, INAI in Mexico, SIC in Colombia, AAIP in Argentina, or the respective authority in their jurisdiction.

When the request involves commercial conversation data processed by Coral Messaging as a Processor, the request may be forwarded to the responsible client company acting as controller, with Coral Messaging supporting fulfillment per contract terms.

14. How to Exercise Your Rights

Data subjects can exercise their rights by sending a written request to the channel indicated in Section 16 of this Policy. The request must contain the full name of the data subject, contact details for response, identity verification document (when required by law or strictly necessary for security verification), and a clear description of the right to be exercised and the data involved. Coral Messaging will respond within a reasonable timeframe and within statutory deadlines established by applicable law in the subject's jurisdiction, and may request additional information to confirm identity or locate requested data.

15. Cookies and Browsing Data

Coral Messaging's institutional website uses cookies and similar technologies, including web beacons, to enable website functionality, authenticate sessions, remember language preferences, and understand browsing patterns for continuous improvement.

A portion of these cookies allows third parties, including Google and Meta, to display Coral Messaging ads on social media platforms and other online channels within ad retargeting campaigns. If the user provides personal data on the site, such data may be linked to information stored in cookies. Installing non-essential cookies (such as third-party advertising and analytics cookies) is subject to explicit prior user consent, which can be managed, granted, or revoked at any time via our cookie preference panel on the website. Users can also configure their browsers to block cookies, though this may affect certain features. This Policy does not cover nor make Coral Messaging responsible for third-party cookies or tracking technologies present on external links.

16. Privacy and Data Protection Channel

Coral Messaging provides the communication channel privacy@coralmessaging.com for data subjects, clients, and authorities regarding personal data protection matters, including exercising rights under this Policy and clarifying doubts about processing. Coral Messaging has a formally designated Data Protection Officer (DPO), who can be reached directly at privacy@coralmessaging.com for exercising rights, seeking clarification, or communicating with Data Protection Authorities across any jurisdiction.

17. Duties of Subprocessors

When Coral Messaging engages third parties to process personal data on its behalf (subprocessors/data subprocessors), the following minimum duties are contractually established:

  • Purpose limitation: process personal data strictly in accordance with Coral Messaging's instructions and principles of applicable data protection laws;
  • Security: adopt technical and administrative measures to prevent unauthorized access, alteration, or destruction, as well as security incidents or data leaks;
  • Confidentiality: maintain secrecy regarding personal data content and processing and ensure that employees and contractors are bound by formal confidentiality obligations;
  • Incident notification: promptly inform Coral Messaging of any security breach or identified risk in data administration;
  • Data subject support: assist Coral Messaging in responding to requests and complaints from data subjects, ensuring the full exercise of their rights.
  • Support and cooperation: assist Coral Messaging in addressing requests and complaints from competent Data Protection Authorities, ensuring compliance with applicable contractual and regulatory obligations.

18. Changes to This Policy

Coral Messaging may modify this Policy at any time to reflect changes in data processing practices or applicable legislation. Substantial changes, especially those impacting data subject rights or processing purposes, will be communicated via the website or email, with periodic review recommended. The revised version will indicate its last update date at the beginning or end of this document.

19. Specific Provisions for United States Users (US Privacy Laws) Minor Privacy (COPPA)

In compliance with the Children's Online Privacy Protection Act (COPPA), Coral Messaging Services are B2B in nature and are not directed to nor intentionally collect Personal Data from children under 13 (thirteen) years of age in the United States.

Notice to California Residents (CCPA/CPRA) and other state laws: Coral Messaging acts strictly as a "Service Provider" regarding commercial conversation data. We expressly declare that we do not "sell" or "share" Personal Data for cross-context behavioral advertising purposes. Over the past 12 (twelve) months, we collected the Personal Data categories described in Section 5 of this Policy exclusively for business purposes. Depending on the state of residence, data subjects may hold additional rights, such as the Right to Appeal, request corrections, or opt out, exercisable via email at privacy@coralmessaging.com.

20. Applicable Law and Forum

The Terms of Service of Coral Messaging elect the laws of the State of New York and the exclusive jurisdiction of the state and federal courts located in the Borough of Manhattan, City of New York, for disputes arising therefrom.

This choice of law does not preclude the application of mandatory local data protection laws, such as LGPD in Brazil pursuant to its Art. 3, GDPR in the European Union, and other regional laws, to the processing of personal data of data subjects located in their respective territories, nor does it prejudice the rights guaranteed to such subjects by applicable national laws or the jurisdiction of competent courts and Data Protection Authorities in each jurisdiction.