Skip to content
Back to home page

Privacy Policy

Last updated: September 7, 2026

Anfitrione is a product of BGA TRAINING SOLUTIONS LTDA, Brazilian company registration (CNPJ) 57.660.473/0001-32.

Anfitrione ("we", "our" or "us") is committed to protecting privacy and handling personal data responsibly. This Privacy Policy explains how we collect, use, share, store and protect personal information in compliance with the Brazilian General Data Protection Law (LGPD - Law No. 13,709/2018).

This Policy applies to platform users (e.g., hosts and their teams) and also to third-party data (e.g., guests) that may be processed when you integrate and use Anfitrione.

Regarding guest and third-party data processed by the User through the platform, the User generally acts as the data controller and Anfitrione as the data processor, under the terms of the LGPD, processing data according to the User's instructions and to enable the service.

1. Data Collection

We collect the following types of data:

1.1 Identification Data

  • Full name
  • Email address
  • Phone number
  • CPF/CNPJ (for billing purposes)

1.2 Property Data

  • Registered property information (address, description)
  • Airbnb listing links
  • Automated service settings
  • Knowledge base (FAQs, property information)

1.3 Communication Data

  • Guest conversation history via WhatsApp
  • Automated messages sent by the system
  • Customer support interactions

Avoid entering sensitive data (e.g., health data) or excessive information on the platform. When this occurs at the initiative of the User or third parties, we will process such data only to the extent necessary to provide the service and protect platform security.

1.4 Technical Data

  • IP address
  • Browser and device information
  • Cookies and similar technologies
  • Platform access and usage logs

2. Purposes and Legal Bases

We use personal data, as a rule, to:

  • Operate the platform and its features (including automation and service management)
  • Enable integrations (e.g., WhatsApp Business Platform/Meta) and process service-related messages
  • Manage accounts, authentication, preferences and support
  • Process payments, billing and subscription management
  • Send transactional communications and relevant notices (e.g., security, charges and outages)
  • Monitor, audit and improve service quality (including performance evaluation and abuse prevention)
  • Comply with legal obligations and respond to requests from competent authorities
  • Produce statistics, reports and studies with aggregated and anonymized information

The main legal bases (LGPD) for processing include: (i) contract performance or preliminary procedures (service provision), (ii) compliance with legal/regulatory obligations (e.g., billing), (iii) legitimate interest (e.g., security, fraud prevention and service improvement), and (iv) consent when applicable (e.g., certain communications and cookies).

We do not use conversation content to create advertising profiles nor do we sell personal data. When we use AI providers, processing occurs to generate responses and assist service operation, under the terms of this Policy.

We may use and eventually share or commercialize aggregated and anonymized information for research, statistics, market intelligence and service improvement purposes, provided such information does not allow the identification of you, guests or any person.

3. Storage and Security

3.1 Where We Store

Your data is stored in cloud infrastructure and third-party services used to operate the platform. We adopt reasonable technical and organizational measures to protect data and select vendors that follow good security practices.

3.2 For How Long

  • Account data: while your account is active
  • Conversation history: 12 months after closure
  • Billing data: 5 years (legal requirement)
  • Technical logs: 6 months

3.3 Security Measures

  • Encryption in transit (TLS) and, when applicable, encryption/secrets at rest
  • Access controls and authentication measures
  • Monitoring, event logging and incident mitigation
  • Backups and continuity procedures
  • Data minimization and need-to-access practices

No system is completely secure. Although we adopt measures to reduce risks, it is not possible to guarantee absolute security.

4. Your Rights (LGPD)

Under the Brazilian General Data Protection Law (LGPD), you have the following rights:

Confirmation and Access

Confirm whether we process your data and obtain access to it

Correction

Request correction of incomplete or outdated data

Anonymization or Deletion

Request anonymization or deletion of unnecessary data

Portability

Request portability of your data to another provider

Deletion

Request deletion of data processed with consent

Consent Revocation

Revoke consent at any time

Opposition

Object to processing in case of LGPD non-compliance

Sharing Information

Know which entities we share your data with

5. Data Sharing

We may share your data with:

Authorized connectors and agents

When you connect an external agent (such as ChatGPT, Claude or Codex) through MCP, you authorize queries and operations on properties your account can access. Depending on the requested task, the connected client may receive guest and service provider names and contact details, reservation dates and details, messages, property information, knowledge content and identifiers needed to look up or change those records. Browser WebMCP uses your dashboard session for operations available on the page.

Connect only clients you trust and send only data needed for the task. You can disconnect the client and revoke authorization through the identity service. Revocation prevents new authorized access but does not delete copies already received by the client; those copies are handled under the respective provider’s policy. Agent changes are logged for review and accountability.

Technical MCP protocol records are retained for 30 days and do not store tool arguments. Operational records and queried data follow the applicable periods described in this policy. Do not send account passwords, access tokens, government identifiers, payment card data or health data through connectors.

  • WhatsApp/Meta: to enable integration with the WhatsApp Business Platform and message traffic
  • Authentication: Clerk (login and session management)
  • Infrastructure and database: Convex and hosting/execution services (e.g., Vercel)
  • Payment processing: Stripe (billing, payments and fraud prevention)
  • Email: Resend (transactional communications)
  • Monitoring/security: tools for error logging and metrics (e.g., Sentry)
  • AI providers: OpenAI (natural language processing for response generation)
  • Authorities and third parties by legal obligation: when required by law, court order or for the regular exercise of rights

We do not sell your personal data. We do not share personal data for third-party marketing purposes.

Some vendors may be located outside Brazil, which may involve international data transfer, subject to applicable legal bases and safeguards.

Aggregated and anonymized information (that does not identify individuals) may be shared or commercialized, as described in this Policy.

6. Cookies and Similar Technologies

We use cookies to:

  • Keep your session active
  • Remember your preferences
  • Analyze platform usage
  • Improve user experience

Audience measurement: we use PostHog (servers in the European Union) to measure site usage. By default, and even before you answer the cookie notice, this measurement is anonymous and cookieless: the identifier is derived from a hash that rotates and is discarded daily and cannot identify you. The legal basis is our legitimate interest in understanding and improving our content. If you allow it, we start using cookies and the ad pixel; if you decline, we stop the cookies and the pixel, while anonymous measurement may continue. You can object at any time through our Data Protection Officer (DPO) in the contact section below.

You can manage cookie preferences in your browser settings.

7. Contact

To exercise your rights or ask questions about this policy, contact us:

Data Protection Officer (DPO)

Email: privacidade@anfitrione.com.br

Response time: up to 15 business days

Data deletion request

To request account deletion and/or associated data, send an email to privacidade@anfitrione.com.br with the subject "Data deletion" and provide the account email, WhatsApp number (if applicable) and the scope of the request.

Some information may be retained for the time necessary to comply with legal obligations, fraud prevention and regular exercise of rights.

8. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you about significant changes by email or through a notice on our platform. We recommend reviewing this page regularly.