PRIVACY POLICY
MULTIAGENTS
Updated: January 2026
Multiagents values the privacy of users and customers. This Privacy Policy aims to clearly explain how we process personal data within the scope of the website https://www.multiagents.inc and the Multiagents platform, in compliance with Law No. 13,709/2018 (Brazilian General Data Protection Law - LGPD).
1. PERSONAL DATA COLLECTED
1.1. Information provided by the data subject
When registering, contracting, or using the platform, the data subject may voluntarily provide:
- Full name;
- Corporate or personal email address;
- Contact phone number (mobile or landline);
- Company name, tax ID, and position;
- Payment information (credit card data, bank slip, or PIX, processed by certified gateways);
- Information entered in forms, support chats, or contact channels;
- Conversation data managed by AI agents (when the client configures agents to interact with their own end customers).
1.2. Automatically collected information
During platform use, we automatically collect:
- IP address and approximate geolocation information;
- Technical browsing data: browser type, operating system, screen resolution, preferred language;
- Access logs: date, time, pages visited, actions taken on the platform;
- Cookies and unique identifiers: used for authentication, security, and platform functionality (see section 8 for more details).
This information is used exclusively to:
- Ensure platform security;
- Prevent fraud and unauthorized access;
- Improve user experience;
- Analyze platform performance.
1.3. Third-party data
Multiagents does not collect or use personal data from third parties without the express consent of the data subject or without an appropriate legal basis.
When the client uses prospecting, lead qualification, or data enrichment features, the data is:
- Provided directly by the client; or
- Obtained from public and legitimate sources (e.g., professional social networks, corporate websites); or
- From certified partner databases, always with consent or appropriate legal basis.
1.4. Use of Data from Google Services Integrations
Multiagents may integrate with Google services (Gmail, Google Calendar, Google Drive, Google Sheets, among others) to offer advanced features to users.
1.4.1. Authorization and Consent
Integration is performed upon express user authorization through Google's official consent mechanisms (OAuth 2.0). The user grants specific permissions and can revoke them at any time.
1.4.2. Data Accessed
During use of these integrations, Multiagents may access, exclusively for authorized purposes:
Gmail:
- Message headers (sender, recipient, subject, date);
- Message content (email body);
- Attachments (when necessary for the requested functionality);
- Labels and categories.
Google Calendar:
- Event titles, descriptions, and locations;
- Dates, times, and time zones;
- Guest list and participation status;
- Configured reminders and notifications.
Google Drive, Documents, Sheets, and Presentations:
- File and folder names;
- Unique IDs and file URLs;
- Metadata (creation date, modification, owner);
- File content (when necessary for functionality, e.g., reading spreadsheets for data processing).
1.4.3. Purposes of Use
Data from Google integrations is used exclusively to:
- Synchronize information between Multiagents and the user's Google account;
- Create, edit, update, or delete records (emails, events, files) according to actions explicitly authorized by the user;
- Execute functionalities requested by the user within the platform (e.g., automatic meeting scheduling, email sending via AI agents, calendar availability check);
- Process and analyze data to provide insights or automations configured by the user.
1.4.4. Express Prohibitions
Multiagents WILL NOT use data from Google integrations for:
- Advertising, marketing, or retargeting purposes without express consent;
- Sale, sharing, or disclosure to unauthorized third parties;
- Access or manipulation of data outside the scope of permissions granted by the user;
- Training third-party AI models or for purposes unrelated to the contracted service.
1.4.5. Storage and Security
When temporary storage of data from these integrations is necessary, Multiagents:
- Stores only for the time necessary to fulfill the stated purpose;
- Applies appropriate technical and administrative measures for protection against unauthorized access, loss, or improper alteration (encryption, access control, audit logs);
- Deletes the data when no longer necessary or upon user request.
1.4.6. Access Revocation
The user may, at any time, revoke Multiagents' access to their Google account through:
After revocation, Multiagents will immediately cease access and delete stored data related to the integration, except when there is a legal retention obligation.
1.4.7. Compliance with Google Policies
Multiagents is in full compliance with:
2. PURPOSES OF PROCESSING
Personal data collected is used for the following legitimate purposes:
2.1. Service provision
- Enable registration, authentication, and regular use of the Multiagents platform;
- Execute contracted functionalities (AI agent creation and management, lead qualification, automated customer service, CRM integrations, etc.);
- Process payments and issue invoices.
2.2. Communication with the user
- Send notifications about platform use (e.g., agent alerts, reports, updates);
- Respond to technical support requests;
- Send communications about contractual, policy, or feature changes.
2.3. Compliance with legal obligations
- Comply with determinations from competent authorities;
- Fulfill tax, labor, and regulatory obligations.
2.4. Security and fraud prevention
- Monitor and prevent unauthorized access, fraud, and cyberattacks;
- Ensure platform integrity and availability.
2.5. Platform improvement
- Analyze usage patterns to enhance functionalities;
- Develop new features based on feedback and aggregated usage data.
2.6. Marketing and communication (only with consent)
- Send newsletters, product updates, and educational content (users can opt out at any time).
3. LEGAL BASIS FOR PROCESSING
Personal data processing by Multiagents is based on the following legal bases provided by LGPD:
- Consent of the data subject, when applicable (e.g., newsletters, marketing);
- Contract execution or preliminary procedures related to a contract to which the data subject is a party (e.g., service provision);
- Compliance with legal or regulatory obligation (e.g., invoice issuance, tax obligations);
- Regular exercise of rights in judicial, administrative, or arbitration proceedings;
- Legitimate interest of the controller (e.g., platform security, fraud prevention, service improvement).
4. DATA SHARING
Multiagents does not share personal data with third parties for commercial, advertising, or data resale purposes.
Sharing occurs exclusively in the following cases:
4.1. Service providers (processors)
With companies contracted for operational purposes, always under confidentiality clauses and LGPD compliance:
- Cloud infrastructure providers (e.g., AWS, Google Cloud, Azure);
- Payment gateways (e.g., Stripe, PagSeguro, Mercado Pago);
- Communication tools (e.g., Twilio for SMS, SendGrid for transactional emails);
- Monitoring and security services (e.g., Cloudflare, Sentry);
- Support tools (e.g., Intercom, Zendesk).
4.2. Public authorities
Upon court order, request from competent authority, or compliance with legal obligation.
4.3. Client-configured integrations
When the client connects Multiagents to CRMs, communication tools, or proprietary systems (via API, webhooks, or custom MCPs), data is shared under the client's responsibility, who acts as controller of that data.
4.4. Mergers, acquisitions, or restructurings
In case of sale, merger, acquisition, or corporate restructuring, data may be transferred to the successor, maintaining the same protection obligations.
5. INFORMATION SECURITY
Multiagents adopts rigorous technical and administrative measures to protect personal data against unauthorized access, destruction, loss, alteration, communication, or any form of inadequate or illicit processing.
5.1. Implemented security measures:
- Encryption: data in transit (TLS 1.3) and at rest (AES-256);
- Access control: multi-factor authentication (MFA), role-based permission profiles (RBAC);
- Continuous monitoring: access logs, anomaly detection, automatic alerts;
- Firewall and DDoS protection: prevention of cyberattacks;
- Automatic backup: configurable retention with periodic recovery tests;
- Environment segregation: isolated production, staging, and development;
- Team training: information security and LGPD best practices;
- Regular audits: security assessments by independent third parties.
6. DATA SUBJECT RIGHTS
Under LGPD, data subjects may exercise the following rights at any time:
- Confirmation of processing of personal data;
- Access to personal data being processed;
- Correction of incomplete, inaccurate, or outdated data;
- Anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data;
- Data portability to another service or product provider, upon express request, in structured and interoperable format;
- Deletion of data processed with the data subject's consent;
- Information about data sharing with public and private entities;
- Information about the possibility of not providing consent and the consequences of refusal;
- Consent revocation, at any time, through express manifestation.
6.1. How to exercise your rights
To exercise any of the above rights, contact us through:
- Email: contact@multiagents.inc
- Platform form: "Privacy and Data" section
Response time: up to 15 business days, according to deadlines established by ANPD.
7. DATA RETENTION AND DELETION
7.1. Retention period
Personal data is stored for the time strictly necessary to fulfill the stated purpose, respecting:
- During the contract term and active platform use;
- Legal and regulatory deadlines (e.g., tax obligations: 5 years; labor: up to 30 years);
- Deadline for exercising rights in judicial or administrative proceedings;
- Data subject consent, when applicable.
7.2. Deletion
After the retention period ends, data will be:
- Anonymized irreversibly; or
- Securely deleted, using techniques that prevent recovery.
7.3. Account cancellation
Data subjects may request account cancellation at any time. In this case:
- Registration and usage data will be deleted within 30 days;
- Data subject to legal obligation (e.g., invoices) will be kept for the legal period;
- Backups will be deleted in the next rotation cycle (up to 90 days).
8. COOKIES AND TRACKING TECHNOLOGIES
8.1. What are cookies?
Cookies are small text files stored in the user's browser to recognize devices, improve experience, and ensure proper platform operation.
8.2. Types of cookies used
Multiagents uses the following cookie categories:
8.2.1. Strictly necessary cookies
Essential for platform operation (e.g., authentication, security, session). Cannot be disabled.
8.2.2. Performance and functionality cookies
Improve user experience by remembering preferences and settings.
8.2.3. Analytics cookies
Collect aggregated information about platform use (e.g., most visited pages, session time) for improvement purposes. We use:
- Google Analytics (anonymized, without individual identification).
8.2.4. Marketing cookies (only with consent)
Used to display personalized content and measure campaign effectiveness. Only activated with explicit consent.
8.3. Cookie management
Users can manage or disable cookies through:
Note: Disabling strictly necessary cookies may affect platform operation.
9. INTERNATIONAL DATA TRANSFER
Multiagents does not perform international transfer of personal data, except when essential for:
- Contract execution or legal obligation;
- Use of cloud infrastructure services with data centers outside Brazil.
When transfer occurs, it will always be with:
- Standard Contractual Clauses (SCCs) approved by the European Commission or ANPD;
- Guarantee of adequate level of protection, according to LGPD and GDPR;
- Express consent of the data subject, when applicable.
Currently, Multiagents' main infrastructure operates on servers located in Brazil.
10. MINORS
The Multiagents platform is not intended for individuals under 18 years of age.
If we become aware that we have collected data from minors without appropriate parental consent, we will take immediate action to delete this information.
Parents or guardians who identify improper use by minors should contact: contact@multiagents.inc
11. CHANGES TO THE PRIVACY POLICY
This Privacy Policy may be modified at any time to reflect:
- Legislative or regulatory changes;
- Operational changes to the platform;
- Privacy and security best practices.
11.1. Change notification
When there are relevant changes, Multiagents will notify users through:
- Email registered on the platform;
- Prominent notice on the platform interface;
- Publication on the official website.
Continued use of the platform after notification implies acceptance of the new conditions.
We recommend reviewing this Policy periodically.
12. DATA PROTECTION OFFICER (DPO)
Multiagents designates a Data Protection Officer (DPO), responsible for:
- Accepting complaints and communications from data subjects;
- Providing clarifications about data processing;
- Receiving communications from ANPD and taking appropriate measures;
- Guiding employees and contractors on data protection practices.
DPO Contact:
- Email: contact@multiagents.inc
13. CONTACT
For questions, requests, or exercise of rights related to privacy and data protection, please contact:
Email: contact@multiagents.inc
Website: https://www.multiagents.inc
Multiagents
Vertical AI Multi-Agent Platform
https://www.multiagents.inc
Last updated: January 2026