Calead Privacy Policy
Last updated: 08/19/2026
Effective date: 08/19/2026
This Policy describes how Calead collects, uses, stores, shares, and deletes personal data. It applies to the calead.ai website, the application at app.calead.ai, the scheduling widget embedded on customer websites, and every integration offered by the platform.
1. Who we are
Calead is the trade name of the platform operated by 59.247.164 HUMBERTO TEIXEIRA DA SILVA, a sole proprietorship registered under Brazilian taxpayer number (CNPJ) 59.247.164/0001-60, with its registered office at Rua Clara Simões Speck, 163, Barra da Lagoa, Florianópolis, SC, 88.061-255, Brazil.
Privacy contact: ola@calead.ai
Data Protection Officer, under article 41 of the Brazilian General Data Protection Law (LGPD): Humberto Teixeira da Silva, ola@calead.ai.
2. Summary of what we do with Google data
If you connect your Google account to Calead, this is what happens:
- We read the busy periods on your calendar to calculate and display your available slots to people booking with you.
- We create, update, and cancel events on your calendar when a meeting is booked, rescheduled, or cancelled through Calead.
- We do not sell, rent, or trade data obtained from Google APIs.
- We do not use this data for advertising, nor to train generalized artificial intelligence models.
- You can revoke access at any time at myaccount.google.com/permissions, and disconnect the integration inside Calead itself.
Full detail, including the scopes we request and Google's Limited Use policy, is in section 6.
3. Our role: controller and processor
Calead handles data in two distinct capacities, and this changes who is accountable for what.
Controller. When we process data belonging to our own customers: account details, billing data, platform usage, support requests. Here the purpose is determined by us.
Processor. When we process data our customer collects through the platform: leads captured by the widget, meeting participants, contacts synced to the CRM, WhatsApp conversations. In these cases the customer is the controller, defines the purpose, and is accountable for the lawful basis of the collection. Calead processes this data following the customer's instructions and this document.
If you filled in a scheduling form on a website that uses Calead, the controller of your data is the company that owns that website. Direct access or deletion requests to them. If you prefer to contact us, we will forward the request to the responsible customer within 5 business days.
4. Data we collect
4.1 Account data (you are our customer)
Name, email address, hashed password or provider identifier, profile picture when you sign in with Google, phone number, company, job title, time zone, language, the organization you belong to, and your role within it.
Source: provided by you at signup, or by Google when you use Google sign-in.
4.2 Data obtained from Google APIs
- Identification of the calendars you select for use in Calead.
- Busy periods (free/busy) used to calculate availability.
- Events created, modified, or cancelled by Calead, including title, description, time, video call link, and attendee list.
- Access and refresh tokens for the integration.
4.3 Lead and booking data
Name, email address, phone or WhatsApp number, company, free-text message, answers to the questions the customer configured in the widget, chosen time slot, booking status, notes, and interaction history.
Source: filled in by the lead in the scheduling widget or the capture assistant.
4.4 Recorded and transcribed meeting data
When the customer enables the meeting assistant, an automated participant joins the video call and performs recording and transcription. In this flow we process: meeting audio and video, a text transcript with speaker identification, summaries, topics, action items, and classifications generated by artificial intelligence.
This feature only operates when the customer explicitly enables it. The automated participant is visible in the participant list throughout the call.
Customer responsibility. It is the meeting organizer's duty to inform participants and obtain any required consent before recording begins. Laws in several countries and states require consent from everyone present. Calead provides the tool; the duty to inform belongs to whoever uses it.
4.5 WhatsApp data
When the customer connects a WhatsApp number: the connected account number, recipient numbers, the content of messages sent and received in the context of bookings and automations, delivery and read status, and connection session data.
4.6 CRM data
When the customer connects Kommo, HubSpot, or Pipedrive: integration access credentials and the contact, deal, and activity fields synced in either direction.
4.7 Data from visitors to websites running the widget
Anonymous session identifier, pages visited on the customer's website, traffic source and campaign parameters (UTM), steps taken in the booking flow, date and time, device and browser type, IP address, and language.
Purpose: attributing the source of a booking, measuring widget conversion, and detecting misuse.
4.8 Payment data
Subscription plan, subscription status, billing history, credit consumption, and the last four digits and brand of the card.
Calead never receives or stores the full card number, CVV, or password. Processing is handled by Stripe, entirely within its own environment.
4.9 Technical and security data
IP address, device identifiers, access logs, error logs, audit records of administrative actions, and alerts for unauthorized widget origins. Retention of application access logs follows article 15 of the Brazilian Internet Civil Rights Framework.
5. Purposes and lawful bases
| Purpose | Data | Lawful basis (LGPD) |
|---|---|---|
| Create and maintain your account, authenticate access | 4.1 | Performance of a contract (art. 7, V) |
| Display availability and create calendar events | 4.2 | Performance of a contract |
| Receive, organize, and route leads | 4.3 | Performance of a contract with the customer; legitimate interest of the customer as controller (art. 7, IX) |
| Record, transcribe, and summarize meetings | 4.4 | Consent of participants, obtained by the customer (art. 7, I) |
| Send confirmations, reminders, and automations via WhatsApp and email | 4.3, 4.5 | Performance of a contract; consent where the message is promotional |
| Sync data with the customer's CRM | 4.6 | Performance of a contract |
| Measure conversion and attribute booking source | 4.7 | Legitimate interest (art. 7, IX) |
| Charge subscriptions and manage credits | 4.8 | Performance of a contract; legal and tax obligation (art. 7, II) |
| Prevent fraud, abuse, and security incidents | 4.9 | Legitimate interest; legal obligation |
| Send product communications | 4.1 | Legitimate interest, with an unsubscribe option in every message |
6. Use of data obtained from Google APIs
6.1 Scopes requested and why
| Scope | Concrete use in the product |
|---|---|
https://www.googleapis.com/auth/calendar.events.freebusy | Read only the busy intervals of the selected calendars, to calculate which slots to display in the scheduling widget. This scope gives no access to event content, only to free and busy periods |
https://www.googleapis.com/auth/calendar.events | Manage scheduling events: create the event when a lead books, add attendees and the video call link, update the time when a meeting is rescheduled, and cancel the event when a booking is called off |
We request the minimum scope necessary for each feature. Calead does not request full calendar access: we do not create or delete calendars, do not change account settings, and do not manage sharing permissions. When a feature is disabled, we stop using the corresponding data.
6.2 Limited Use policy
Calead's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice:
- We use the data only to provide and improve features that are visible to you in the product.
- We do not transfer the data to third parties, except as necessary to provide the service to you, to comply with applicable law, or as part of a merger or acquisition with prior notice and consent.
- We do not use the data for advertising, including personalized, targeted, or interest-based advertising.
- We do not allow humans to read this data, except with your explicit consent for specific cases, when necessary for security purposes, to comply with applicable law, or where the data is aggregated and anonymized.
- We do not use data obtained from Google APIs to develop, train, or improve generalized artificial intelligence or machine learning models.
6.3 Artificial intelligence and Google data
Calead uses Google's Gemini models to generate meeting summaries, suggest replies, and classify leads. When the customer enables these features, calendar or meeting content may be sent to the model to produce the result shown on screen.
In those cases:
- The transfer happens only after the customer explicitly enables the feature.
- The content is used to produce that specific result, never to train models.
- Calead performs no human review of the content, except in the cases listed in item 4 above.
If you do not want calendar or meeting content processed by AI, keep these features disabled in your organization settings.
6.4 Revoking access
You can disconnect the integration inside Calead, under Settings, or revoke access at myaccount.google.com/permissions. Once revoked, we delete the tokens within 7 days and stop accessing your calendar. Events already created remain on your calendar, under your control.
7. Who we share data with
We do not sell personal data. We share only what is necessary, with the following processors:
| Processor | Purpose | Data involved | Location |
|---|---|---|---|
| Google Cloud / Firebase | Hosting, database, authentication, file storage, function execution | All | United States (Firestore in the nam5 multi-region; Storage and Cloud Functions in us-central1) |
| Google Calendar API | Reading availability and managing events | 4.2 | United States |
| Google Gemini API | Generating summaries, classifications, and replies | 4.3, 4.4 when the feature is enabled | United States |
| Recall.ai | Automated participant joining the meeting, recording, and transcription | 4.4 | United States |
| Stripe | Payment and subscription processing | 4.8 | United States |
| Evolution API (Calead-operated instance) | WhatsApp connection and message delivery | 4.5 | United States |
| Kommo, HubSpot, Pipedrive | Syncing with the CRM chosen by the customer | 4.6 | Per the provider chosen by the customer |
| Resend | Sending confirmation and reminder emails | Name and email address | United States |
We may also share data to comply with a court order or a request from a competent authority, and in the event of a corporate reorganization, with prior notice to data subjects.
The list above is the current list of subprocessors and can be requested at any time at ola@calead.ai. Material changes are communicated to customers with 30 days notice.
8. International transfers
Data processed by Calead is stored and processed in the United States. The database runs in the Cloud Firestore nam5 multi-region, and file storage and function execution run in the us-central1 region. The other processors listed in section 7 also process data outside Brazil.
Transfers rely on article 33, items II and IX, of the LGPD, supported by contractual clauses that impose on the processor a standard of protection equivalent to Brazilian law. Material changes of location will be communicated under section 15.
9. How long we keep data
| Category | Period |
|---|---|
| Account data | For as long as the account exists, plus 6 months after closure |
| Google tokens | Until disconnection or revocation, deleted within 7 days |
| Leads and bookings | For as long as the account exists, or until the customer deletes them |
| Meeting recordings | 30 days, unless the customer configures a different period |
| Transcripts and summaries | For as long as the account exists, or until the customer deletes them |
| WhatsApp messages | 12 months |
| Visitor sessions and analytics events | 13 months |
| Tax and billing records | 5 years, by legal obligation |
| Application access logs | 6 months, under article 15 of the Internet Civil Rights Framework |
| Security audit records | 12 months |
Once an account is closed, we delete or anonymize data within the periods above, except where the law requires retention.
10. Security
Measures in place:
- Encryption in transit (TLS) and at rest on Google Cloud infrastructure.
- Per-document access rules in Firestore, with isolation by organization.
- Authentication managed by Firebase Authentication.
- App Check on the widget and on public endpoints, with alerts for unauthorized origins.
- Rate limiting on public endpoints.
- Audit logging of administrative actions.
- Internal access restricted to staff who need it to operate the service.
No system is immune to incidents. In the event of a security incident posing material risk to data subjects, we notify the Brazilian data protection authority (ANPD) and the affected subjects within the periods set by article 48 of the LGPD.
11. Your rights
The LGPD grants you: confirmation that processing exists, access to your data, correction, anonymization, blocking or deletion of unnecessary data, portability, deletion of data processed on the basis of consent, information about data sharing, information about the option to withhold consent, withdrawal of consent, and review of automated decisions.
How to exercise them:
- Inside the product: customers can export all organization data and request full deletion from the dashboard, under Settings, without contacting support.
- By email: ola@calead.ai. We respond within 15 days.
If you are not our customer and your data was collected through one of our customers, contact that company first. Section 3 explains why.
Complaints may also be directed to the Brazilian National Data Protection Authority (ANPD).
12. Automated decisions
Calead scores and classifies leads and meetings with the support of artificial intelligence. These classifications are suggestions shown to the customer, with no automatic legal effect on the data subject. The decision to contact, prioritize, or discard a lead is human and belongs to the customer. You can request a review of these classifications through the channels in section 11.
13. Cookies and similar technologies
We use:
- Necessary: maintaining an authenticated session and protecting against abuse. These cannot be disabled.
- Functional: language, theme, and time zone preferences.
- Analytics: measuring application usage and widget conversion.
The scheduling widget stores a session identifier in the visitor's browser to attribute the source of a booking. Cookie consent management on the website where the widget is installed is the responsibility of the customer who installed it.
14. Children and adolescents
Calead is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children or adolescents. If we identify such collection, we delete the data.
15. Changes
We may change this Policy. Material changes will be communicated by email and by notice in the application with 15 days notice. The last updated date appears at the top of this document.
16. Contact
59.247.164 HUMBERTO TEIXEIRA DA SILVA (Calead)
CNPJ 59.247.164/0001-60
Rua Clara Simões Speck, 163, Barra da Lagoa, Florianópolis, SC, 88.061-255, Brazil
Privacy: ola@calead.ai
Data Protection Officer: Humberto Teixeira da Silva, ola@calead.ai