1. Data controller
WMST — W.M Soluções Tecnológicas, based in Lorena/SP, Brazil, is the controller of the personal data processed through this website and the platforms it builds and operates. Data protection contact: contato@wmst.com.br.
2. Data we collect and why
- Identification and contact data (name, email, phone, company): answering quote requests, enabling trials, providing support and sending operational messages.
- Usage and browsing data (IP address, pages visited, referral source, device identifiers): security, fraud prevention, aggregate analytics and site improvement.
- Conversation content exchanged with our AI agents: delivering the requested service, keeping history and improving answer quality.
- Data processed on behalf of customers: when we operate platforms contracted by companies, we act as processors and handle data solely under the controlling customer instructions.
3. Legal bases
Processing relies on contract performance or pre-contractual steps, compliance with legal or regulatory duties, legitimate interest (security and service improvement) and, where required, consent — which can always be withdrawn.
4. Your rights
You may request confirmation of processing, access, correction, anonymisation, blocking or deletion, portability, information about sharing and withdrawal of consent. We reply within 15 calendar days at contato@wmst.com.br.
5. Sharing
We share data only with vendors that support our operation (cloud hosting, email and messaging delivery, AI model providers, analytics and payment processors), always under contract and WMST instructions, or when required by law or a competent authority.
6. International transfers
Part of the infrastructure and AI providers we use is located outside Brazil. In those cases we apply contractual safeguards compatible with the LGPD to keep the same level of protection.
7. Retention and deletion
We keep data for as long as the stated purposes require or for the applicable legal periods (for example, access logs for 6 months and tax records for 5 years). Once the period ends, data is securely deleted or anonymised.
8. Information security
We use encryption in transit (HTTPS), role-based access control, environment segregation, event logging, backups and periodic dependency reviews. No system is fully immune, but material incidents are reported to data subjects and to the Brazilian authority (ANPD) as required by law.
9. Cookies and analytics
We use essential cookies (session and security) and aggregate measurement cookies such as Google Analytics and Search Console to understand site usage. You may block or clear cookies in your browser; session-dependent features may stop working.
10. Updates to this policy
We may update this policy to reflect legal, technical or operational changes. The current version always lives on this page, with the update date at the top. Material changes are announced by email or in-app notice.