AgenteBoltly ← Back to the site

Privacy Policy

How MW TI handles personal data on boltly.com.br and on the Boltly platform (AgenteBoltly).

Last updated: 7 September 2026 · This document supplements the General Terms and Conditions of Use.

This is a translation provided for convenience. The legally binding version of this document is the one written in Brazilian Portuguese; in the event of any discrepancy, the Brazilian Portuguese text prevails. Português (BR)

1. Who is responsible

This policy describes how M DE S WANDERLEY JUNIOR TECNOLOGIA DA INFORMAÇÃO (trading as MW TI), corporate taxpayer number (CNPJ) 17.799.356/0001-30, collects, uses, shares and protects personal data, in accordance with Brazilian Law 13.709/2018 (LGPD) and with the Internet Civil Framework.

Corporate site: mwti.com.br · Product: boltly.com.br.

2. Who this policy applies to

3. Our roles: controller and processor

The same company can play different roles depending on the data processed. At Boltly:

DataWho the controller isOur role
Registration data of the Client and of panel Users (name, email, telephone, tax number, billing, access logs) MW TI Controller
Conversations, contacts, media and records of the leads who talk to the contracting company's agent The contracting company (our Client) Processor, processing only in accordance with the Client's instructions
Browsing on boltly.com.br and commercial contact forms MW TI Controller

In practice: it is the company that contracted Boltly that decides what happens to the leads' data. We supply the technology and process that data on their behalf. Access or deletion requests made by a lead are forwarded to the company responsible for the conversation.

4. Data we collect

4.1. Data you give us

4.2. Data collected automatically

4.3. Data processed on the Client's behalf (conversation content)

In running the conversations, the platform processes and stores, under the contracting company's responsibility:

A word about sending documents. Photos of identity documents, receipts and contracts may contain sensitive data. It is the contracting company that decides whether these features stay enabled, and that is answerable for the legal basis and the necessity of that processing.

5. What we use the data for

We do not sell personal data and we do not pass it to third parties for their own advertising.

6. Legal bases

ProcessingLegal basis (LGPD)
Operating the platform, billing and supportPerformance of a contract — art. 7, V
Security, fraud prevention, product metricsLegitimate interests — art. 7, IX
Tax documents and retention of access logsLegal or regulatory obligation — art. 7, II
Optional cookies and marketing communicationsConsent — art. 7, I
Defence in judicial, administrative or arbitral proceedingsRegular exercise of rights — art. 7, VI
End contacts' data processed on the Client's behalfDefined by the Client, in its capacity as controller

7. Artificial intelligence and conversation content

7.1. To generate the agent's replies, the necessary conversation content is sent to language model providers contracted by MW TI. That transfer happens solely to produce the reply for that conversation.

7.2. Depending on the Client's configuration, the following may also be sent to specialised providers: audio, for transcription; images and PDFs, for reading; and the text of the reply, for conversion into speech.

7.3. We contract these providers on terms that prohibit the use of the content to train their models. Even so, the Client can disable document reading, audio transcription, voice and media archiving in the panel, if it prefers that data not to be processed.

7.4. Replies are generated automatically and may contain errors. The platform offers handover to a human, and reviewing the conversation is the contracting company's responsibility.

7.5. We do not use end contacts' personal data to train models of our own.

8. Sharing and sub-processors

We share data only as far as necessary to provide the service, with suppliers acting under contract and on MW TI's instructions:

CategoryWhat for
Cloud and hosting providersServers, database and running the application
AI model providers and model routersGenerating replies, transcribing audio, reading documents and speech synthesis
File storageKeeping the media sent in conversations
WhatsApp / Meta PlatformsSending and receiving messages — processing governed by Meta's own policies
Payment methods and tax documentsCollecting subscription fees and issuing invoices
Email, analytics and support toolsCommunicating with clients and measuring the site

We may also share data: (i) under a court order or a request from a competent authority; (ii) to defend rights in proceedings; (iii) in the event of a corporate reorganisation, merger or acquisition, in which case this policy will continue to be observed; and (iv) with integrations enabled by the Client itself, in which case the third party acts under its own terms and responsibility.

An up-to-date list of the sub-processors in use can be requested at privacidade@boltly.com.br. We may replace one supplier with another of equivalent function, maintaining the same level of protection.

9. International transfers

Some of the suppliers above are based outside Brazil, notably AI model providers, cloud providers and WhatsApp/Meta. In those cases the transfer complies with art. 33 of the LGPD, supported by appropriate contractual clauses, equivalent security guarantees or the other legal grounds that apply.

10. How long we keep it

DataRetention period
Registration data of the Client and UsersFor the duration of the contract and for up to 5 years afterwards, to defend rights
Conversations, media and conversation memoryFor as long as the Client's contract lasts; after it ends, up to 30 days for export and then deletion
Application access logsAt least 6 months, as required by the Internet Civil Framework
Tax and accounting documentsFor the periods required by law
Opt-out recordsKept for as long as needed to honour the request not to be contacted

Once the periods and purposes have ended, the data is securely deleted or anonymised.

11. Information security

We adopt technical and administrative measures consistent with the state of the art, among them: encryption in transit (TLS), passwords stored only as a hash, role-based access control with revocable sessions, data isolation between clients, media files kept in a private store behind temporary links, an audit trail of sensitive actions, failure monitoring and periodic supplier assessment.

No system is entirely immune. The Client is also responsible for protecting its team's credentials, revoking access for people who leave and keeping devices secure.

Vulnerabilities can be reported at privacidade@boltly.com.br.

12. Data subject rights

Under art. 18 of the LGPD, you may request:

Send your request to privacidade@boltly.com.br. We may ask for extra information to confirm your identity, and we will reply within the periods set by the LGPD. Some data may be kept where there is a legal obligation or a need to defend rights — in that case we will explain why.

You may also lodge a complaint with the Brazilian National Data Protection Authority (ANPD).

13. If you talked to a Boltly agent

If you received or sent messages to a company that uses Boltly, the decisions about your data are made by that company, not by MW TI. We merely operate the technology on their behalf.

14. Cookies

On boltly.com.br we use the following categories:

The optional categories are only enabled with your consent, collected in the banner shown on your first visit. You can review your choice at any time through the “Cookie preferences” link in the site footer, or delete the cookies in your browser settings. Refusing the optional ones does not prevent you from using the site.

15. Children and young people

The platform is intended for professional use by people over 18 and is not directed at children or young people. We do not knowingly collect data from minors. If improper processing is identified, the data will be deleted. It is for the Client, as controller, to observe the rules of art. 14 of the LGPD should its audience include minors.

16. Security incidents

In the event of a security incident that may bring relevant risk or harm, we will notify the affected Client without undue delay and, where applicable, the ANPD and the data subjects, with the information available and the measures taken.

17. Changes to this policy

This policy may be updated because of changes to the product, to suppliers or to the law. The date of the last update is at the top of the page, and material changes will be communicated by email or by notice in the panel. The version in force is always at boltly.com.br/privacidade.html.

18. Contact the data protection officer

Officer responsible for personal data processing (DPO): privacidade@boltly.com.br

Commercial matters and support: contato@boltly.com.br

WhatsApp: +55 (81) 99542-5862

M DE S WANDERLEY JUNIOR TECNOLOGIA DA INFORMAÇÃO — MW TI · CNPJ 17.799.356/0001-30 · mwti.com.br