Iris · Legal document
Privacy policy
Draft — legal review pending
Draft — this policy is not yet in force. The waitlist is not open yet.
In short: Iris handles your messages and your contacts' messages to work on your behalf, and asks for your approval before spending and before calendar commitments outside the usual. Below, what that means in detail.
Version: rascunho-2026-10-02h (draft) · In force from: not yet in force
01Who we are
Iris is a personal assistant, a product of the EXECON brand, operated by CSVNET Consultoria, Negócios e Tecnologia LTDA, CNPJ (Brazilian National Registry of Legal Entities) 11.823.985/0001-71, with registered office at Av. Paulista, 171, andar 10, São Paulo/SP, Brasil, CEP 01311-000 ("we").
Data Protection Officer (encarregado pelo tratamento de dados): Daniel Barna — privacidade@execon.ai.
02Who this policy applies to, and our role
| who | who decides about the data (controller) | our role |
|---|---|---|
| Customer — holder of an Iris account | CSVnet | controller |
| Applicant — anyone who joins the waitlist | CSVnet | controller |
| Third party — anyone who talks to Iris on behalf of a customer | the customer | processor (operadora): we process this data on the customer's instructions, only to serve the customer |
03What data we process
From the applicant: name and e-mail of the Google account, Google account identifier, name provided, LinkedIn or Instagram profile address, the reason you wrote, the language, the version of these documents you accepted and the date of acceptance.
From the customer:
- registration: name, e-mail, Google account identifier;
- the version of the terms and of this policy you accepted, the date, time and IP of each acceptance, and the acceptance of the WhatsApp connection risk;
- usage credit: the credits issued to your account and the debits for measured usage;
- the messages exchanged with Iris through the channels you connect (WhatsApp, Telegram and e-mail);
- your Google Calendar and your e-mail, within the limits of the permissions you grant;
- the goals, tasks, commitments and reports that Iris records while working for you;
- personal data you ask Iris to keep in order to use on your behalf (for example, a document for a quote), stored encrypted;
- audio you send, transcribed within our own infrastructure;
- images and documents that you or your contacts send, whose content is read so that Iris can work with it;
- portal access logs (date, time, IP).
From the third party: name and phone number or e-mail address, and the content of the messages exchanged with Iris, including attachments (quotes, documents, images).
From people who visit the website or write to our contact e-mail addresses: the IP address and technical connection data (browser, date and time, network error reports), processed by the provider that hosts the website and forwards the e-mails, in order to deliver and protect the website; and the content of the message, if you write to us.
We do not ask for sensitive data (health, religion, biometrics, etc.). If such data appears in a conversation, it is processed only for the task in which it appeared.
04What we use it for, and on what legal basis
| purpose | whose | legal basis (LGPD — Lei Geral de Proteção de Dados, Brazil's General Data Protection Law) |
|---|---|---|
| review the waitlist and send the invitation | applicant | preliminary procedures relating to a contract, at the request of the data subject (art. 7º, V) |
| issue the usage credit, debit usage and pause when it runs out | customer | performance of a contract (art. 7º, V) |
| respond, schedule, get quotes, negotiate, follow up on deadlines and coordinate contacts on behalf of the customer | customer | performance of a contract (art. 7º, V) |
| same, as regards the third party's data | third party | defined by the customer, as controller; as a rule, the customer's legitimate interest (art. 7º, IX) or a contract to which the third party is a party (art. 7º, V) |
| keep access logs and proof of acceptance | customer | legal obligation (Marco Civil da Internet — Brazil's Internet Civil Rights Framework, art. 15) and regular exercise of rights (art. 7º, VI) |
| security, fraud prevention and backups | all | legitimate interest (art. 7º, IX) |
| deliver and protect the website; receive contact e-mails | visitors and people who write to us | legitimate interest (art. 7º, IX) |
| marketing communications | customer, applicant | consent (art. 7º, I), revocable at any time |
05Use of artificial intelligence
Messages are read and replies are written by an artificial intelligence system (Claude models, from Anthropic). Iris introduces itself to each third party as the customer's AI assistant, by the customer's name, at the start of the conversation, and never denies being an AI when asked.
Actions involving expenses and non-standard commitments are only carried out after the customer's approval. Anyone — customer or third party — may request human review of a decision made solely on the basis of automated processing (LGPD, art. 20) through the channel in item 12.
We do not use conversations to train AI models, and Anthropic's commercial terms prohibit it from training models on this content.
06Who we share with
Only with those necessary for the service to work:
| who | what for | where |
|---|---|---|
| Anthropic | process messages with AI; web search when Iris looks something up | USA |
| login, Gmail and Google Calendar, according to the permissions you grant | [to be confirmed] | |
| Meta (WhatsApp) | send and receive messages on the number you connect | [to be confirmed] |
| Telegram | send and receive messages through your bot | [to be confirmed] |
| Cloudflare | website hosting, DNS and forwarding of contact e-mails | [to be confirmed] |
| Oracle Cloud | server and backups | Brazil (São Paulo) — [region to be confirmed] |
We may also share data when required by law or by an order of a competent authority. We do not sell data. We do not use the content of your conversations for advertising.
Iris's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
07International transfer
Some providers are located outside Brazil. The main one is Anthropic, in the USA, which processes the messages with AI; under the contract with it, Anthropic may not train models on this content.
- Customer data: the transfer is necessary to perform the service the customer asked us for (LGPD, art. 33, IX, in conjunction with art. 7º, V).
- Third parties' data: we process this data on the instructions of the customer, who is its controller. Iris introduces itself as an AI at the start of each conversation, and this policy states that messages are processed outside Brazil.
- Google, WhatsApp and Telegram are services that the customer itself contracts and connects to Iris; what is stored in them is subject to each one's policies.
The data of those who join the waitlist is not sent to Anthropic.
08How long we keep it
| data | period |
|---|---|
| applicant not approved | deleted 90 days after the refusal or the expiry of the invitation; only dates, the accepted version and the status are kept |
| account data and conversations | for as long as the account exists |
| after termination | 30 days for you to export; after that, we delete within up to 30 days, including backups |
| backups | 30 days, on rotation |
| portal access logs | 6 months (Marco Civil, art. 15) |
| proof of acceptance (versions, date, time and IP) | up to 5 years after termination |
Third-party data follows the retention period of the account of the customer who brought it.
09Security
Each account's data is isolated from other accounts' data in the database, by rules of the database itself. Personal data stored at the customer's request is encrypted. Backups are private and are kept on infrastructure controlled by CSVnet. Access to the data by CSVnet personnel is restricted to what is necessary to operate and provide support.
10Security incidents
If there is an incident that may cause relevant risk or damage, we notify the ANPD (Autoridade Nacional de Proteção de Dados, Brazil's National Data Protection Authority) and the affected people within the deadlines of the ANPD's regulations. When the incident affects third-party data, we also notify the customer who is the controller.
11Children and adolescents
Iris is only for people 18 years of age or older (maiores de 18 anos). We do not knowingly collect data from minors; if we notice that this has happened outside a legitimate task of the customer, we delete it.
12Your rights
Under the LGPD (art. 18), you may request: confirmation that we process your data, access, correction, anonymization, blocking or deletion of what is unnecessary, portability, information about whom we share it with, information about the possibility of not consenting, and revocation of consent when it is the basis. You may also request review of an automated decision (art. 20) and file a complaint with the ANPD.
To make a request: privacidade@execon.ai. We respond within 15 days.
If you are a third party who talked to Iris on behalf of a customer, you may contact us through the same channel; since the controller is the customer, we forward the request to the customer and help them address it.
13Cookies
The website does not set cookies or use traffic analytics. The portal, once it exists, will use only essential cookies (keeping you logged in and protecting the login). We do not use advertising cookies.
14Changes to this policy
When this policy changes, the version and date at the top change. If the change is relevant, we notify the customer by e-mail and through the channel in which Iris talks to them 30 days in advance.
Translation of a draft (version rascunho-2026-10-02h). In case of any difference, the Portuguese version prevails.