Last updated: August 21, 2026
Serv, through its ServZap platform (available at servzap.eletrovia.com), values the privacy and security of the information of its clients and of the end users who interact with our WhatsApp automation solutions. This Privacy Policy describes how we collect, use, store and protect data in the context of the integration with the Official WhatsApp Business API (Meta), in compliance with the Brazilian General Data Protection Law (LGPD) and with the Meta Platform Policies.
Our Legal Role: We act strictly as technology Data Processors. The data processed by our infrastructure belongs exclusively to our clients (the Data Controllers), who are responsible for obtaining end-user consent (opt-in).
1. Data We Process
To provide the message automation and routing service, our system automatically processes the following data supplied through the official Meta API:
- Contact information: WhatsApp phone numbers of the end users who interact with our clients' numbers.
- Communication metadata: Date, time and delivery status of messages.
- Message content: Text, media and documents exchanged between the end user and the client, required for the automation flows to work.
- Profile information: The end user's public WhatsApp profile name, where they have made it public in their app.
2. How We Use the Data (Purpose)
Data use is strictly limited to technically enabling the contracted service. We do not use the data for any commercial purpose of our own.
- The phone numbers we process will under no circumstances be used by Serv for our own marketing campaigns, prospecting or any unsolicited communication.
- Message content is processed and stored securely for the sole purpose of keeping the support history of the contracting client within their ServZap account.
- We do not perform data mining on conversation content to build behavioural profiles.
- Consent (opt-in): campaign messages are only sent to users who have given prior consent to the Controller client, in accordance with Meta and LGPD rules.
3. Data Sharing and Disclosure
Serv keeps the data under strict commercial and technical confidentiality.
- Data sale: Under no circumstances do we sell, rent or trade contact lists, phone numbers or message content to third parties or partners.
- Infrastructure partners (sub-processors): Data may transit through high-security cloud hosting servers and through Meta Platforms, Inc. infrastructure itself, solely as required to deliver and keep the service stable.
- Legal requirements: Data will only be disclosed to competent authorities upon a prior and formal court order, in accordance with Brazilian law.
4. Data Retention and Deletion
Processed data is kept only for as long as our clients need it to manage their support conversations, or as required by law.
- Deletion on request: The client (Controller) may at any time request the purge of their end users' data from our databases.
- End of contract: When use of our services ends, all message and contact data linked to the client account will be deleted and/or anonymised from our infrastructure within 30 days.
5. How to Request Deletion of Your Data
In compliance with Meta and LGPD requirements, any person (end user or client) may request the deletion of their personal data processed by ServZap:
- Send an email to suporte@serv.eletrovia.com with the subject "Data Deletion", stating the associated WhatsApp phone number.
- Or make the request through the website servzap.eletrovia.com.
- We will complete the deletion within 30 days and confirm by email. Data that must be retained by legal obligation will be anonymised.
6. Your Rights (LGPD)
You have the right, at any time, to:
- Confirm that processing exists and access your data;
- Request the correction of incomplete, inaccurate or outdated data;
- Request the anonymisation, blocking or erasure of unnecessary data;
- Request data portability;
- Withdraw consent and request the deletion of data processed on that basis.
7. Information Security
We implement strict technical and organisational measures to protect data against unauthorised access, alteration, disclosure or destruction. We use encryption in transit (SSL/TLS), webhook signature validation and secure authentication methods to guarantee the full integrity of communication with the WhatsApp Business API.
8. Cookies
The ServZap panel uses only essential session cookies, required to keep the operator securely authenticated. We do not use advertising tracking cookies nor share browsing data with third parties.
9. Children's Privacy
ServZap is a business-to-business (B2B) tool intended for operators duly registered by our clients. We do not knowingly target, promote to, or collect data from children under 13. If we become aware that we have inadvertently processed personal data from a child under 13, we will take the necessary steps to delete it as soon as possible.
10. Changes to This Policy
This Policy may be updated from time to time. The date of the latest revision is always shown at the top of this page. Material changes will be communicated to clients through official channels.
11. Contact / Data Protection Officer (DPO)
For questions about this Policy, requests from Meta or to exercise rights under the LGPD, please get in touch: