Chat Check-in Chat Check-in ← Back to Home

Privacy Policy

Last updated: May 2026 · Version 2026.05

MCMONT CONSULTORIA E TECNOLOGIA LTDA. CNPJ: 66.143.513/0001-60
Headquarters: Av. República do Líbano, 251, Sala 1112, Torre C, Pina, Recife/PE, CEP 51.110-160, Brazil
Trade name: Chat Check-in
Data Protection Officer (DPO): [email protected]

Important notice: The Portuguese version of this Policy, available at chatcheck.in/privacy, is the original and prevailing version. In case of any conflict or divergence between the Portuguese and the English versions, the Portuguese text shall prevail. This English version is provided for informational purposes only.

Mcmont Consultoria e Tecnologia Ltda., doing business as Chat Check-in ("Company," "we"), respects your privacy and is committed to protecting personal data, in compliance with Brazilian Law no. 13,709/2018 (General Personal Data Protection Law — LGPD), the Brazilian Civil Rights Framework for the Internet (Law no. 12,965/2014 — Marco Civil), and other applicable rules.

This Privacy Policy describes how we collect, use, store, share, and protect personal data related to the use of our SaaS platform for AI-powered automated WhatsApp customer service ("Platform" or "Service").

Processing observes the principles set forth in article 6 of the LGPD: purpose, adequacy, necessity, free access, quality of data, transparency, security, prevention, non-discrimination, and accountability. Where processing entails high risk to the rights and freedoms of data subjects (for example, intensive use of generative AI), we carry out a Data Protection Impact Assessment (DPIA / RIPD) in accordance with article 10 of the LGPD.

Table of Contents

  1. Who we are
  2. What data we collect
  3. How we collect
  4. How we use the data
  5. Legal bases
  6. Controller and Processor roles
  7. Data sharing
  8. International transfers
  9. Storage and retention
  10. Information security
  11. Data subject rights
  12. Cookies and similar technologies · Cookie Policy
  13. Children and adolescents
  14. Artificial Intelligence
  15. Limitations of liability
  16. Changes to this Policy
  17. Data Protection Officer and contact

1. Who we are

Mcmont Consultoria e Tecnologia Ltda. is a Brazilian limited liability company (sociedade empresária limitada), provider of the Chat Check-in service, an AI-powered WhatsApp automated customer service platform for inns, hotels, and businesses in the hospitality sector.

2. What data we collect

Depending on how the Service is used, we may collect and process the following categories of personal data:

2.1. Client registration data

  • Full name, email, phone number, password (stored in encrypted form);
  • Corporate name, trade name, CNPJ (Brazilian tax ID), address, and commercial contact information;
  • Establishment data (name of the inn/hotel, location, description, photos);
  • Payment data (processed directly by a third-party gateway — we do not store complete card data).

2.2. Usage and technical data

  • IP address, device identifiers, browser type, operating system;
  • Access and application logs (in compliance with the Marco Civil);
  • Pages accessed, actions performed, timestamps, durations;
  • Telemetry data, error and performance metrics.

2.3. Data of guests / end users (processed on behalf of the Client)

  • Phone number (WhatsApp);
  • Name (when provided by the guest themselves or by the WhatsApp provider);
  • Content of messages exchanged with the AI Bot;
  • Dates, timestamps, and metadata of interactions;
  • Any information voluntarily provided by the guest in the course of the conversation (check-in dates, number of people, preferences, etc.).

3. How we collect

We collect data (i) directly from the Client when they register and configure the Service; (ii) automatically through use of the Platform and similar technologies; (iii) through guests who send messages to the WhatsApp number configured by the Client, which will be processed by the Bot; and (iv) eventually from third parties, such as Meta/WhatsApp Business Platform, payment processors, and AI providers.

4. How we use the data

Personal data is used, where applicable, for the following purposes:

  • Create, authenticate, and manage user accounts;
  • Provide and operate the Service, including processing of messages by AI models;
  • Process payments and manage subscriptions;
  • Communicate operational notices, updates, security alerts, and modifications to these Terms;
  • Provide technical support and customer service;
  • Improve, monitor, and develop new features;
  • Prevent fraud, abuse, security breaches, and unlawful activities;
  • Comply with legal, regulatory, tax, and judicial obligations;
  • Regularly exercise rights in judicial, administrative, or arbitration proceedings;
  • Perform aggregated and anonymized statistical analyses.

5. Legal bases

We process personal data on the following legal bases set forth in the LGPD (articles 7 and 11), as applicable to each purpose:

  • Performance of contract (art. 7, V) — to provide the contracted Service;
  • Compliance with legal or regulatory obligation (art. 7, II) — for tax, accounting, Marco Civil records, etc.;
  • Legitimate interests (art. 7, IX) — for fraud prevention, security, analyses, and Platform improvements;
  • Regular exercise of rights (art. 7, VI) — in judicial, administrative, or arbitration proceedings;
  • Consent (art. 7, I) — when applicable, especially for marketing communications.

6. Controller and Processor roles

With respect to Client registration data and technical Platform data, Mcmont Consultoria e Tecnologia Ltda. acts as Controller.

With respect to data of guests/end users who interact with the Bot configured by a Client, Mcmont Consultoria e Tecnologia Ltda. acts as Processor (Operator), processing such data on behalf of and according to the instructions of the Client, who is the Controller. The Client is solely responsible for:

  • Defining the purposes and means of processing;
  • Obtaining the necessary legal bases;
  • Properly informing their guests about the processing;
  • Responding to data subject requests;
  • Complying with all other LGPD obligations.

We strongly recommend that the Client present this Policy and their own privacy policy to guests before initiating automated interactions.

7. Data sharing

We do not sell personal data. Where applicable, we share data with the following processors and partners, identified by name with the country in which they process the data and the purpose:

  • Amazon Web Services (AWS) — United States (selected regions): cloud hosting, computing, and storage of the Platform;
  • Stripe, Inc. — United States / Ireland: payment processing and recurring billing (we do not store complete card data; tokenization is performed by Stripe);
  • Meta Platforms / WhatsApp Business Platform — United States / global infrastructure: sending and receiving messages via WhatsApp, in accordance with the WhatsApp Business Platform policies;
  • Resend — United States: transactional email delivery (verification codes, operational notices);
  • Sentry — United States: error monitoring and application telemetry (loaded subject to consent for analytical cookies);
  • OpenAI, L.L.C. — United States: language models for response generation and audio transcription (Whisper);
  • DeepSeek — People's Republic of China: alternative language models for response generation (see section 8 and section 14 below);
  • Competent authorities: by court order, request from authority, or compliance with a legal obligation;
  • In corporate transactions: in case of merger, acquisition, corporate reorganization, or sale of assets, data may be transferred to the acquirer, with continued observance of this Policy;
  • With the data subject's consent, in cases not provided for above.

8. International transfers

Some of the processors listed in section 7 are headquartered or process data outside Brazil. We carry out international transfers based on article 33 of the LGPD, primarily under item V (necessity for performance of the contract with the Client) and, where applicable, items II (international cooperation) or IX (specific consent). We adopt standard contractual clauses and, when available, vendor compliance certifications.

United States. AWS, Stripe, Meta/WhatsApp, Resend, Sentry, and OpenAI process data on servers in the United States. We maintain Data Processing Agreements (DPAs) with these vendors and, where applicable, clauses that prohibit the use of data for model training.

People's Republic of China. Currently, part of message traffic may be processed by the AI provider DeepSeek, based in China, for the exclusive purpose of generating automated responses in the customer service flow. The transfer is based on LGPD art. 33, V (performance of contract), and Mcmont continuously evaluates applicable contractual clauses with this vendor. In a future version of the Platform, the Client will be able to choose among AI providers (including exclusively OpenAI/US); until then, Clients who prefer not to have data processed in China should request this configuration via [email protected].

9. Storage and retention

Data is stored for the time necessary to fulfill the purposes for which it was collected, observing the principles of necessity and minimization (LGPD, art. 6, III). The following retention periods apply:

  • Client registration data (name, email, phone, CPF/CNPJ, establishment data): throughout the term of the agreement and during the applicable civil, tax, and procedural statutes of limitations after termination;
  • Guest message history (chat_messages): up to 90 (ninety) days after exchange, automatically deleted thereafter. The Client and the data subject may request immediate deletion at any time through the channels described in section 11;
  • Application access logs: 6 (six) months, as required by article 15 of the Marco Civil da Internet;
  • Audit records of deletions and consents: up to 5 (five) years after the event, for defense in eventual ANPD oversight;
  • Tax and accounting records: for the applicable legal periods (minimum 5 years).

After the retention periods end, data will be deleted or anonymized, unless there is a legal duty of preservation.

10. Information security

We adopt reasonable technical and administrative measures to protect personal data against unauthorized access, loss, alteration, destruction, or any form of inadequate processing, including:

  • Encryption in transit (TLS) and at rest, where applicable;
  • Password hashing (bcrypt with 12 rounds);
  • Role-based access controls (RBAC);
  • Monitoring and audit logs of administrative actions;
  • Periodic backups;
  • Secure development practices and code review.

Non-discrimination principle. In compliance with LGPD art. 6, IX, we ensure that personal data will not be used for discriminatory, unlawful, or abusive purposes. We do not perform profiling that produces legal effects on or significantly affects the interests of data subjects.

Incident response. Despite our efforts, no system is completely impenetrable. In the event of a security incident that may pose risk or relevant harm to data subjects, we will adopt the following procedure, in compliance with article 48 of the LGPD and ANPD Resolution CD/ANPD nº 15/2024:

  • ANPD notification within a reasonable timeframe after becoming aware of the incident, containing: description of the nature, categories and approximate number of data/subjects affected, measures adopted and underway, related risks, and DPO contact details;
  • Communication to affected data subjects without undue delay, in clear and accessible language, whenever there is relevant risk;
  • Reporting channel: incidents may be reported to Mcmont at [email protected].

11. Data subject rights

Pursuant to article 18 of the LGPD, the data subject has the right to obtain:

  • Confirmation of the existence of processing;
  • Access to the data;
  • Correction of incomplete, inaccurate, or outdated data;
  • Anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in non-compliance with the LGPD;
  • Portability to another provider, observing trade and industrial secrets;
  • Deletion of data processed based on consent, except for legal retention hypotheses;
  • Information about sharing;
  • Information about the possibility of not providing consent and its consequences;
  • Withdrawal of consent.

You also have the right to object to processing based on legitimate interests, pursuant to LGPD art. 18, §2 in conjunction with art. 7, IX, except where there is an overriding legal basis (compliance with legal obligation, performance of contract, or regular exercise of rights).

Requests must be sent to [email protected]. We may request additional information to confirm the requester's identity. When we act as Processor (data of guests), we will forward the request to the corresponding Client Controller.

Direct channel for Clients. Clients with an active account have access to the Dashboard › My data area to exercise all of these rights in a facilitated manner: export a structured copy of their own data, correct registration information, manage granular consents (marketing and telemetry), consult the consent history, and register requests for deletion of specific guest data received directly by the Client.

12. Cookies and similar technologies

The Platform uses cookies, localStorage, sessionStorage, and third-party SDKs, organized into four categories: essential (authentication, session, and security — required and non-removable), functional (browsing preferences), analytical (error telemetry via Sentry, loaded only with consent), and marketing (currently not in use).

The details of each cookie/storage (name, provider, purpose, duration, and category) are described in the Cookie Policy. Consent is collected on first access through a banner with options to accept all, accept essential only, or customize by category, and can be revised at any time by clicking "Manage cookie preferences" in the website footer.

13. Children and adolescents

The Client area of the Platform (registration, dashboard, and panel) is not directed at individuals under 18. We do not intentionally collect data of Clients who are minors. If we identify such a scenario, the account will be terminated and the data deleted.

Underage end-user guests. As Processor, we may occasionally receive data of guests who are children or adolescents, depending on the type of establishment served by the Client. Pursuant to article 14 of the LGPD, the processing of data of children under 12 depends on specific and highlighted consent of at least one parent or legal guardian, and the processing of data of adolescents between 12 and 18 requires informed consent appropriate to the condition of adolescents. This obligation lies with the Client (Controller of guest data), who is responsible for verifying the age, obtaining parental consent where necessary, and providing clear information to the data subject and their guardians.

Parents, guardians, or the adolescent themselves may at any time request the deletion, correction, or clarification of data of a minor processed by the Platform by writing to [email protected]. We will forward the request to the corresponding Client Controller where applicable.

14. Artificial Intelligence

The Service uses generative AI models to process guest messages and generate automated responses. Message content is sent to the following providers, exclusively for this purpose:

  • OpenAI, L.L.C. (United States) — language models (response generation) and Whisper (audio transcription). Contractual prohibition on use of data for model training: confirmed under the contracted API plan;
  • DeepSeek (People's Republic of China) — alternative language models. Contractual prohibition on use of data for training: under evaluation. We maintain transparency on this point, and Clients who prefer not to use this provider may request a specific configuration via [email protected] (see section 8).

Responses generated by the AI are probabilistic and may contain errors, inaccuracies, or inappropriate content. The Client is responsible for monitoring the operation of the Bot and for any decision made based on its responses.

15. Limitations of liability

We shall not be liable for any damages arising from (i) inadequate, irregular, or unlawful use of the Service by the Client; (ii) decisions made by the Client, their agents, or guests based on content generated by the AI; (iii) incidents caused by third parties (including Meta/WhatsApp, AI providers, payment processors, and cloud providers); or (iv) the Client's non-compliance with the data protection obligations incumbent upon them as Controller.

All limitation of liability clauses set forth in the Terms and Conditions of Use apply on a subsidiary basis.

16. Changes to this Policy

This Policy may be modified at any time, at the Company's discretion, to reflect legal, regulatory, technological, or operational changes. Material changes will be communicated through the Platform dashboard or by email. Continued use of the Service after the new version becomes effective implies automatic and full acceptance.

17. Data Protection Officer and contact

For any questions, requests, or exercise of rights regarding this Policy and the processing of personal data, please contact our Data Protection Officer (DPO):

MCMONT CONSULTORIA E TECNOLOGIA LTDA. CNPJ: 66.143.513/0001-60
Headquarters: Av. República do Líbano, 251, Sala 1112, Torre C, Pina, Recife/PE, CEP 51.110-160, Brazil
Trade name: Chat Check-in
Data Protection Officer (DPO): [email protected]
Support: [email protected]
Contact: [email protected]