Privacy Policy
Last updated: August 21, 2026
KarkCRM is a CRM and WhatsApp customer-service platform used by organizations to manage their teams' conversations, contacts, leads, tasks and meetings. This policy explains what data we process, how we use it, who we share it with, and your rights. By using KarkCRM you agree to what is described here.
1. Data we collect
- Account data: name, e-mail, password (stored as a cryptographic hash), role and profile picture of the organization's users.
- Service data: WhatsApp conversations, contacts, leads, notes, tasks, call recordings and files exchanged in conversations — owned by the organization using the system and processed on its behalf.
- Technical records: access and error logs, required for security and for operating the service.
2. Google user data we access
KarkCRM offers an optional integration with Google accounts — the organization's account and each user's individual account. We only access Google data after your explicit consent on Google's official consent screen, and only within the scopes below:
- Account e-mail (email, openid): only to display which account is connected.
- Google Calendar (calendar.events): create, read, update and delete events on your calendar to mirror CRM tasks and meetings (with a Google Meet link when applicable) and to display your events in the Calendar tab.
- Google Sheets (spreadsheets.readonly — organization connection): read-only access to spreadsheets selected by the administrator (by URL or ID) to import contact lists into campaigns. KarkCRM never creates, edits or deletes spreadsheets or Drive files.
Regarding this Google data:
- Use: exclusively for the features described above, visible in the CRM interface. We do not use Google data for advertising.
- Storage: we store the connection's refresh token with restricted access, and only minimal references to created events (event ID and Meet link). We do not copy your calendar contents to our servers.
- Sharing: we do not sell or share Google user data with third parties, except when required by law.
- Artificial intelligence: data obtained from Google APIs is not used to develop, improve or train generalized or non-generalized AI and/or machine-learning models.
- Revocation: you can disconnect your account at any time in the CRM (My Profile or Settings → Integrations) — the token is deleted immediately — and also revoke access at myaccount.google.com/permissions.
KarkCRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use data
- To provide the CRM service: customer support, lead management, tasks and meetings.
- Productivity features such as audio transcription and AI reply suggestions — always in service of the organization and its customer conversations.
- Security, abuse prevention and compliance with legal obligations.
We do not sell personal data and we do not display third-party advertising.
4. Sharing
Data is processed by providers strictly necessary to operate the service (hosting, media storage, WhatsApp and Google APIs, and AI providers for the features described), always limited to the minimum required. Beyond that, we only share data under legal obligation or by order of a competent authority.
5. Security and retention
We use encryption in transit (HTTPS), role- and permission-based access control, hashed passwords and the principle of least privilege. Data is kept while the organization's account is active; upon account deletion or a removal request, data is erased within a reasonable period, except where retention is required by law.
6. Your rights
Under the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018) and applicable law, you may request confirmation of processing, access, correction, anonymization, portability and deletion of your personal data, and withdraw consent. To exercise these rights, contact your organization's administrator or reach us at the contact below.
7. Changes to this policy
We may update this policy to reflect product or legal changes. The last-updated date is shown at the top; relevant changes will be announced in the platform.
8. Contact
Privacy questions or requests: doutortopetejustus@gmail.com.