Privacy Policy | eesier
Last updated: May 20, 2026

Privacy Policy

How eesier handles your personal data and the data of leads approached through the platform.

1.

Who we are

eesier is a product of RSB Serviços em Software e Comunicação LTDA (CNPJ 46.402.039/0001-36), based in Brazil. We act as the controller of personal data we collect directly from our customers (account holders) and as a processor of personal data we handle on behalf of our customers (contact data of leads approached through the platform). For any questions about this policy or about how we handle your personal data, contact us at [email protected].

2.

Personal data we collect

We collect the following categories of personal data: (a) Account data: name, email, phone, tax ID, company name, and payment information (processed by partner payment gateways); (b) Usage data: conversation history with the agent, prospecting configurations, instructions, and knowledge-base content you provide; (c) MCP authentication tokens: opaque credentials generated to connect external agents to your account — we never expose tokens in logs or in administrative screens; (d) Lead data: name, business email, business phone, job title, company, and tax ID — collected from publicly available sources under applicable legal bases; (e) Technical data: IP address, browser, operating system, device identifiers, and access logs for security and audit purposes.

3.

How we collect this data

We collect data directly from you when you sign up, configure the platform, or interact with the agent. We collect lead data from publicly available sources, including public business registries, company websites, and professional directories. We do not buy email lists of natural persons. We do not scrape social networks or platforms that prohibit automated collection. When you import your own list, we act as processor of that data under your instructions.

4.

How we use the data

We use personal data exclusively to: (a) deliver and operate the autonomous prospecting service; (b) generate personalized outreach on your behalf; (c) process payments and issue invoices; (d) provide customer support; (e) comply with legal, regulatory, and tax obligations; (f) detect and prevent fraud, abuse, and illegal activity; (g) improve service quality based on anonymized or aggregated data. We do NOT use lead personal data for purposes unrelated to the service you have contracted.

5.

Legal basis under the LGPD

Data processing by eesier follows the legal bases set out in Brazil's General Data Protection Law (LGPD, Law nº 13.709/2018). We rely on the following bases depending on the processing type: (a) contract performance (Art. 7, V) — to operate the contracted service; (b) compliance with legal obligation (Art. 7, II) — for tax and regulatory obligations; (c) legitimate interest (Art. 7, IX) — for B2B commercial prospecting based on public data, information security, and fraud prevention, always observing the proportionality test and the data subject's right to object; (d) consent (Art. 7, I) — when expressly requested, for example for marketing communications directed at you. For customers and subjects outside Brazil, equivalent provisions of applicable data protection laws (such as the GDPR for European subjects) are observed in parallel.

6.

Sharing with third parties

We do not sell your personal data to third parties. We share data only with sub-processors strictly necessary to deliver the service, under data processing agreements: (a) cloud infrastructure providers for hosting and processing; (b) transactional email providers for sending messages on your behalf; (c) large language model (LLM) providers for generating personalized content; (d) payment processors for subscription billing; (e) operational analytics and telemetry providers. The current sub-processor list can be requested at [email protected].

7.

International data transfers

Some of our sub-processors are located outside Brazil. Whenever personal data is transferred internationally, we observe the safeguards required by Article 33 of the LGPD, including specific contractual clauses with each provider and verification that the destination country offers an adequate level of protection or that appropriate contractual safeguards are in place.

8.

Retention period

We retain your personal data for as long as necessary to fulfill the purposes described in this policy: (a) account data: while your account is active and for up to 5 (five) years after termination, for tax purposes; (b) conversation and lead data: while the account is active; after account termination, data is deleted within 90 (ninety) days, unless a legal obligation requires a longer period; (c) technical logs: retained for up to 30 (thirty) days for audit and security purposes; (d) tax data: retained for the period required by applicable tax legislation.

9.

Data subject rights

As a data subject, you have the following rights guaranteed by the LGPD (and equivalent rights under applicable laws such as the GDPR): confirmation that processing exists; access to your data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data; portability of data to another provider; deletion of data processed based on consent; information about public and private entities with which eesier has shared your data; information about the option not to provide consent and its consequences; consent withdrawal. To exercise any of these rights, contact us at [email protected]. We will respond within 15 (fifteen) days.

10.

Information security

We take technical and organizational measures to protect your personal data against unauthorized access, loss, alteration, disclosure, or destruction. These measures include: encryption in transit (TLS 1.2+) and at rest for sensitive data; role-based access control (RBAC); audit logs for access to personal data; environment segregation; periodic vulnerability reviews; and team training on information security and data protection. Despite these measures, no system is fully immune to incidents — in the event of an incident likely to cause significant risk or harm to data subjects, we will notify Brazil's National Data Protection Authority (ANPD) and affected subjects as required by Article 48 of the LGPD.

11.

Cookies and similar technologies

The eesier.com website uses strictly necessary cookies for platform functionality (session, language preferences) and analytics cookies to understand site usage (Google Analytics, with IP anonymization). You may disable cookies in your browser settings, but this may affect platform functionality. We do not use targeted advertising cookies.

12.

Children and minors

eesier is a B2B platform intended for companies and professionals. We do not knowingly process personal data of children or adolescents (under 18). If we identify inadvertent collection of such data, we will delete it immediately.

13.

Changes to this policy

This policy may be updated periodically to reflect changes in the service, applicable legislation, or operational practices. The updated version will be published on this page with the corresponding effective date. For material changes, we will notify active customers by email at least 15 (fifteen) days in advance.

14.

Contact

To exercise your rights as a data subject, clarify questions about this policy, or send any communication regarding personal data processing by eesier, use the email [email protected]. RSB Serviços em Software e Comunicação LTDA, CNPJ 46.402.039/0001-36.