ark

Privacy Policy

Last updated: September 17, 2026

KarkCRM is a CRM and WhatsApp customer-service platform used by organizations to manage their teams' conversations, contacts, leads, tasks and meetings. This policy explains what data we process, how we use it, who we share it with, and your rights. By using KarkCRM you agree to what is described here.

1. Data we collect

  • Account data: name, e-mail, password (stored as a cryptographic hash), role and profile picture of the organization's users.
  • Service data: WhatsApp conversations, contacts, leads, notes, tasks, call recordings and files exchanged in conversations — owned by the organization using the system and processed on its behalf.
  • Technical records: access and error logs, required for security and for operating the service.

2. Google user data we access

KarkCRM offers an optional integration with Google accounts — the organization's account and each user's individual account. We only access Google data after your explicit consent on Google's official consent screen, and only within the scopes below:

  • Account e-mail (email, openid): only to display which account is connected.
  • Google Calendar (calendar.events): create, read, update and delete events on your calendar to mirror CRM tasks and meetings (with a Google Meet link when applicable) and to display your events in the Calendar tab.
  • Google Sheets (spreadsheets.readonly — organization connection): read-only access to spreadsheets selected by the administrator (by URL or ID) to import contact lists into campaigns. KarkCRM never creates, edits or deletes spreadsheets or Drive files.

Regarding this Google data:

  • Use: exclusively for the features described above, visible in the CRM interface. We do not use Google data for advertising.
  • Storage: we store the connection's refresh token with restricted access, and only minimal references to created events (event ID and Meet link). We do not copy your calendar contents to our servers.
  • Sharing: we do not sell or share Google user data with third parties, except when required by law.
  • Artificial intelligence: data obtained from Google APIs is not used to develop, improve or train generalized or non-generalized AI and/or machine-learning models.
  • Revocation: you can disconnect your account at any time in the CRM (My Profile or Settings → Integrations) — the token is deleted immediately — and also revoke access at myaccount.google.com/permissions.

KarkCRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. How we use data

  • To provide the CRM service: customer support, lead management, tasks and meetings.
  • Productivity features such as audio transcription and AI reply suggestions — always in service of the organization and its customer conversations.
  • Security, abuse prevention and compliance with legal obligations.

We do not sell personal data and we do not display third-party advertising.

4. Sharing

Data is processed by providers strictly necessary to operate the service (hosting, media storage, WhatsApp and Google APIs, and AI providers for the features described), always limited to the minimum required. Beyond that, we only share data under legal obligation or by order of a competent authority.

5. Security and retention

We use encryption in transit (HTTPS), role- and permission-based access control, hashed passwords and the principle of least privilege. Data is kept while the organization's account is active; upon account deletion or a removal request, data is erased within a reasonable period, except where retention is required by law.

6. Your rights

Under the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018) and applicable law, you may request confirmation of processing, access, correction, anonymization, portability and deletion of your personal data, and withdraw consent. To exercise these rights, contact your organization's administrator or reach us at the contact below.

7. Data deletion

You can delete data directly in the CRM or request deletion by e-mail, free of charge. The steps, who may ask, the timelines and what is retained by legal obligation are on the Data deletion page.

8. Government and law-enforcement requests

Requests for data from public authorities are reviewed one by one, with legal advice when needed. We only comply with a valid, reasoned order addressed to us and within the requesting authority's jurisdiction; a generic or overbroad request is challenged or sent back to be narrowed. When we do comply, we disclose only the minimum the request requires, we log every request and what was disclosed, and we notify the organization that owns the data whenever the law allows it.

9. Changes to this policy

We may update this policy to reflect product or legal changes. The last-updated date is shown at the top; relevant changes will be announced in the platform.

10. Who processes the data, and contact

KarkCRM is the platform that hosts the data. In client companies' customer conversations, the client company is the controller of its contacts' data and KarkCRM acts as processor on its instructions.