Privacy
A comprehensive draft of how we handle prospect, lead and customer data.
1. What this covers and who we are
This notice describes, at a comprehensive draft level, how Gainer handles personal data across its website and platform. It is not finalized legal advice; the binding data-processing terms for a client engagement are set out in the signed service agreement and its data-processing addendum, which control in case of any conflict with this page.
Gainer is operated by [COUNSEL/ENTITY NAME: legal entity name, registration number/CNPJ, and registered address]. For EU/UK visitors, an EU representative may be required — [COUNSEL: confirm].
2. Controller vs. processor — the two roles Gainer plays
Gainer acts as CONTROLLER for: prospect and contact data submitted through the discovery, contact, and gap-audit forms on this website; the accounts and login credentials of client personnel who use the admin console/dashboard; and Gainer's own marketing and analytics data (e.g. Vercel Analytics on this site).
Gainer acts as PROCESSOR — processing data on the CLIENT's behalf and under the client's instructions — for: lead and customer personal data a client's own website visitors submit through the embeddable tracking snippet (track.js) or AI chat widget (chat.js) installed on the client's site; chat transcripts and knowledge-base content the client configures; and any data a client's connected integrations (WhatsApp, Stripe, CRM webhooks) send into the platform. The client is the controller for that data and is responsible for having a lawful basis and appropriate visitor-facing disclosures on its own site. The precise LGPD/GDPR framing and a formal data-processing addendum must be confirmed by counsel and referenced from the signed agreement.
3. Data we collect
Account & prospect data: name, email, phone, company/business details, and messages submitted via the discovery, contact, and audit forms, plus admin login sessions.
Lead & customer data (processed on a client's behalf): name, email, phone, the message/enquiry content, chat transcripts with the AI widget, UTM parameters and referrer, the landing page visited, consent status and timestamp, and derived attribution (e.g. organic-search / ai-search / google-ads / whatsapp / referral / direct).
Operational & analytics data: a tenant's frozen baseline metrics, lead outcome marks (qualified/won/lost) and deal value, SEO/Search-Console performance figures, install/heartbeat status, and aggregate usage of the admin tools.
We do not intentionally collect special-category data (health, biometric, precise geolocation beyond IP-derived region, etc.) through the standard lead-capture flow; a client should not configure the knowledge base or forms to solicit it without its own separate legal basis.
4. Lawful basis for processing
Where Gainer is controller (prospect/account data), processing relies on: consent (LGPD Art. 7, I / GDPR Art. 6(1)(a)) for marketing forms, which are consent-gated; and legitimate interest (LGPD Art. 7, IX / GDPR Art. 6(1)(f)) for operating the admin console securely and preventing abuse.
Where Gainer is processor (lead/customer data captured on a client's site), the lawful basis is determined by the client as controller — typically consent from the visitor at the point of capture (LGPD Art. 7, I / GDPR Art. 6(1)(a)) or the client's legitimate interest in responding to an enquiry (LGPD Art. 7, IX / GDPR Art. 6(1)(f)). The capture pipeline is built to require an explicit consent signal before personal data is stored (server-side gate, not just a UI checkbox), which a client can only relax by explicit configuration it is responsible for justifying.
5. How data is used
To operate the service: route and respond to leads, ground AI chat replies in a client's own knowledge base, generate follow-up messages, compute attribution/analytics, and produce the client dashboard and monthly impact report.
To measure results: run the randomized-holdout statistical test underlying the performance-fee model (Proof of Lift), using aggregated conversion outcomes — this does not require using any individual's personal data beyond what the lead record already contains.
To operate Gainer's own business: respond to prospect enquiries, secure the admin console, and — only with de-identified or aggregated data — improve the platform generally.
We do not sell personal data, and do not use a client's captured lead data to advertise to that client's leads on behalf of any other client.
6. Sub-processors
Providing the service relies on the following categories of sub-processor, engaged under their own data-protection terms: Vercel (application hosting); Upstash (Redis key-value data storage for leads, tenant settings, and rate limiting); Resend (transactional email delivery, including lead-reply and report emails); Google Gemini and/or Anthropic (the underlying large-language-model provider for AI chat replies, follow-up drafting, and SEO content — the specific provider is configurable per deployment); Google (Places autocomplete and Search Console data where a client connects it); Meta (WhatsApp Cloud API for WhatsApp messaging integrations); and PayPal (billing/payment processing). A current list of active sub-processors for a given deployment can be requested via the contact page. [COUNSEL: confirm whether a standing sub-processor notification/objection mechanism is required for EU clients.]
7. International data transfers
Because sub-processors operate global infrastructure (e.g. Vercel, Upstash, Google, Anthropic, Meta, PayPal), personal data may be transferred to and processed in countries outside the data subject's own country, including the United States. [COUNSEL: confirm the transfer mechanism relied on for LGPD (Art. 33) and GDPR (Chapter V) purposes — e.g. Standard Contractual Clauses / adequacy — for each sub-processor category, and add it here once confirmed.]
8. Data retention
Lead and customer data is retained for the period configured for that deployment (a configurable retention window, in days) before being eligible for automatic purge; where no window is configured, data is retained until deleted on request. Account/prospect data is retained for as long as reasonably needed to operate the relationship, plus any period required to meet legal, tax, or dispute-defense obligations. [COUNSEL: set the default retention window and confirm it against LGPD Art. 15-16 (data kept no longer than necessary for its purpose) and GDPR Art. 5(1)(e) storage limitation, and state it here as a fixed commitment rather than "configurable."]
9. Data-subject rights and how to exercise them
Subject to applicable law (LGPD Art. 18 / GDPR Art. 15-21), a data subject has rights to: confirm whether their data is processed; access a copy of it; correct inaccurate data; request deletion; request portability; object to processing based on legitimate interest; and withdraw consent at any time without affecting prior lawful processing.
For data captured through a client's site (Gainer as processor), the request should generally go to that client as controller, who can export a data subject's captured lead record (CSV export, admin-gated) or request deletion of a data subject's record by email — both currently supported via the admin data-subject tools. Gainer will assist the client in fulfilling a verified request. A data subject may also contact Gainer directly via the contact page and we will route the request to the relevant client controller or, where Gainer is controller, act on it directly. [COUNSEL/DPO: add the dedicated request channel and target response time — LGPD/GDPR both expect a prompt, defined turnaround (commonly 15-30 days).]
10. Security measures
Data in transit is encrypted (HTTPS/TLS) for the website, dashboard, and all outbound calls to sub-processors. Admin and per-tenant dashboard/report access is cookie-gated behind signed session tokens, with per-tenant isolation so one client's session cannot access another client's data. Application logs are structured and mask personal identifiers (email/phone) at the point of logging rather than storing them in the clear in log output. Payment-related webhooks (e.g. Stripe) and inbound messaging webhooks (WhatsApp) are signature-verified before being trusted. [COUNSEL: add any additional org-level measures (access review cadence, incident-response process, breach-notification commitment/timeline) once formalized.]
11. Cookies and tracking
This website uses Vercel Analytics (aggregate, privacy-respecting page-view analytics) and sets functional cookies necessary for the service to work — for example the admin session cookie and the per-tenant dashboard/report access cookie. It does not set third-party advertising cookies.
The embeddable tracking snippet (track.js) installed on a CLIENT's own site captures first-touch attribution (UTM parameters, referrer) client-side and sends it to Gainer only when a visitor takes an action that is captured under the consent gate described in Section 4 — it is not a passive, always-on cross-site tracker. [COUNSEL: confirm whether a cookie-consent banner is separately required on Gainer's own marketing site and on client sites under the applicable ePrivacy/LGPD cookie rules, and add a cookie table (name, purpose, duration) once finalized.]
12. AI processing and chat transcripts
Messages sent through the AI chat widget are sent to the configured LLM provider (Google Gemini and/or Anthropic — see Section 6) to generate a grounded reply, together with the relevant slice of the client's own knowledge base. Transcripts are stored so the client can review conversations and so the platform can compute chat/engagement statistics; they are subject to the same retention and deletion rights as other lead data (Sections 8-9). Visitors should not be encouraged to share sensitive personal data in chat that is not necessary to answer their question.
13. Children's privacy
The services are intended for business use and are not directed to children. We do not knowingly collect personal data from children through the discovery/contact forms. A client using the platform on a consumer-facing site is responsible for age-appropriate handling if its own visitors may include children. [COUNSEL: confirm the applicable age threshold (LGPD/ECA vs. GDPR/COPPA) if this changes.]
14. Changes to this notice
We may update this draft template to reflect the product accurately as it evolves; a live, signed data-processing addendum is amended per its own terms. The "last updated" reference for this page is the date of the most recent commit to this file in the product's source history.
15. Contact and DPO
For privacy questions or to exercise a data-subject right, use the contact page. [COUNSEL/ENTITY: add a named controller, postal address, and — where LGPD Art. 41 or GDPR Art. 37 require it — a designated DPO/data-protection contact, before publication.]