Privacy Policy
Last updated: October 10, 2026
This policy explains how ROIVP Negócios Digitais Ltda. handles personal data on the virtuscopilot.com website and in the Virtus Copilot application, including data received from Meta platforms (WhatsApp, Instagram, Facebook and Lead Ads) when a customer connects their accounts to the application.
1. Who we are
Virtus Copilot is an AI-powered marketing, sales and customer success infrastructure developed and operated by ROIVP Negócios Digitais Ltda., Brazilian company registration (CNPJ) 41.471.542/0001-20, headquartered at R. Adelino Cardana, 293, Sala 603 Bloco C, Bethaville I/Centro, Barueri/SP, CEP 06.401-147, Brazil ("ROIVP", "we").
ROIVP is the controller of Virtus Copilot user account data and of visitors to this website. For the data of contacts and end customers that business customers serve through the application, the business customer is the controller and ROIVP acts as a processor, handling that data only according to the customer's instructions and this policy.
2. Data we collect
2.1 Account and website data
- Registration: name, email, phone, company and role of application users.
- Business contact: data sent through forms, WhatsApp or email.
- Browsing: IP address, browser, pages visited, traffic source, UTM parameters and click identifiers (fbclid, gclid), collected through cookies and pixels.
- Application usage: access logs, actions taken and technical data for security and support.
2.2 Data received from Meta platforms
When a customer connects their accounts to Virtus Copilot through Facebook Login and grants the requested permissions, we receive only the data needed for the functions below:
| Product | Data received | How we use it |
|---|---|---|
| Facebook Login | App-scoped user ID, name and email; list of Pages, Instagram accounts and WhatsApp Business accounts the user manages and chooses to connect. | Authenticate the user and let them select which assets to connect to Virtus Copilot. |
| WhatsApp Business Platform | Account phone number and display name, message templates, messages sent and received, contacts' profile name and phone number, delivery and read status. | Display and reply to conversations in the customer's inbox, send approved messages and templates and keep the service history. |
| Instagram (direct messages) | Professional account ID and username, direct messages sent and received, sender's username and profile picture. | Display and reply to Instagram direct messages in the customer's inbox. |
| Facebook Pages | ID, name and webhook settings of authorized Pages. | Link the Page to Instagram and Lead Ads and receive real-time events. |
| Lead Ads | Answers to the customer's ad lead forms (such as name, email and phone), form, ad and campaign IDs. | Create the contact in the customer's contact base and start the sales follow-up. |
We do not request permissions beyond those needed for these functions and we do not access content from Pages or accounts the user did not choose to connect.
3. How we use data
- Provide the contracted service: unified inbox, sales pipelines, contacts, automations and reports.
- Generate AI reply suggestions and summaries within the customer's own account.
- Authenticate users, prevent fraud and keep the platform secure.
- Provide support, send service notices and comply with legal obligations.
- Measure the performance of the website and of our campaigns, through cookies.
4. Commitments regarding Meta data
- We do not sell or rent data received from Meta platforms.
- We do not use that data for our own advertising, to build user profiles for third parties or for any purpose unrelated to the service provided to the customer who connected it.
- We do not train general-purpose AI models with customers' messages or contact data.
- Each business customer's data is isolated in its own account and is never shared with other customers.
- We comply with the Meta Platform Terms, the WhatsApp Business Policy and the applicable Developer Policies.
5. Sharing
We share data only with:
- Meta Platforms: to send and receive messages and events on the customer's behalf through the official APIs.
- Infrastructure providers: cloud, hosting, database, email and AI providers that process data on our behalf, under contract and confidentiality obligations.
- Authorities: when required by law, court order or a competent authority.
6. Cookies and tracking
The website uses first and third-party cookies (such as Meta Pixel and Google Tag Manager) to remember the chosen language, measure audience and evaluate campaigns. You can block or delete cookies in your browser settings. The application uses only cookies required for login and security.
7. Legal bases
We process data under Brazil's General Data Protection Law (LGPD, Law 13,709/2018) and, where applicable, the GDPR: performance of a contract, legitimate interests (security, improvement and measurement), compliance with legal obligations and consent where required, such as for marketing communications.
8. Retention
- Account and conversation data are stored while the contract is active or until the customer deletes them.
- When a Meta account is disconnected, we immediately stop receiving new data from it and its access tokens are deleted.
- After the contract ends or a deletion request is made, we delete the data within 30 days, except records we are legally required to keep (such as tax data and access logs, for the legal period).
9. Your rights and data deletion
You may request confirmation of processing, access, correction, portability, anonymization, deletion, information about sharing and withdrawal of consent by writing to admin@roivp.com.br. We reply within 15 days.
To remove Virtus Copilot's access to your Meta accounts and request data deletion, follow the instructions on the Data Deletion page. If you are a contact of a company that uses Virtus Copilot, you can also reach that company directly, as it is the controller of your data.
10. Security
We use encryption in transit (HTTPS/TLS) and at rest, role-based access control, secure authentication, protected storage of access tokens and continuous monitoring. In the event of a relevant incident, we will notify affected parties and the authorities as required by law.
11. International transfers
Some providers, including Meta and cloud providers, may process data outside Brazil. These transfers follow the LGPD and rely on contractual clauses and appropriate safeguards.
12. Children
Virtus Copilot is a business tool and is not intended for anyone under 18. We do not knowingly collect children's data.
13. Changes
We may update this policy. The current version is always available on this page with the date of the last update. Customers will be notified of material changes by email or in the application. Use of the service is also governed by the Terms of Service.
14. Contact and Data Protection Officer
Data Protection Officer: ROIVP Negócios Digitais Ltda.
Email: admin@roivp.com.br
Phone: +55 (61) 9844-8144
Address: R. Adelino Cardana, 293, Sala 603 Bloco C, Bethaville I/Centro, Barueri/SP, CEP 06.401-147, Brazil