BdrGo
PTENES
Legal center Privacy Terms Sign in
Privacy and LGPD

Privacy Policy

Transparency for users, customers and people whose professional data is involved in a prospecting operation.

Last updated: August 30, 2026 ← Back to the website

BdrGo is the new name of NextWho. References to the former brand in the current documents identify the same platform.

This Policy explains personal data processing at nextwho. The legal entity responsible for each agreement is identified in the Order, proposal and tax document. To exercise your rights or contact the privacy channel, write to [email protected].

1. Scope

This Policy applies to the nextwho.com.br website, the authenticated platform, the official extension, APIs, integrations, transactional communications, demonstrations and support channels. It does not replace customers' privacy notices or the policies of connected third-party services.

The service is intended for the B2B context. We do not intentionally seek children's or adolescents' data or sensitive personal data for commercial prospecting.

Google and Gmail integration

Signing in with Google identifies your account on the platform. Connecting a Gmail mailbox is a separate authorization, requested when you choose to use that mailbox to send messages and track replies in the workspace. Sending uses the gmail.send permission; reading uses gmail.readonly. We do not request permission to delete messages or change your Gmail mailbox settings.

To locate replies, we query identifiers and headers of incoming messages, including sender, recipients and conversation references. On the initial synchronization, this query considers the recent inbox. We retrieve the content of messages associated with workspace conversations in order to display the history and apply the flows configured by the customer. We also store the mailbox address, message identifiers, operational metadata and encrypted credentials to keep the connection authorized.

This data is processed on our servers and by the infrastructure providers necessary for the service. When you enable AI features for these conversations, the required content may be sent to the configured AI provider to summarize, classify or draft replies. That use must be limited to the function requested by the customer, with no training of general-purpose models. We do not sell data obtained from Google, nor do we use it for advertising, ad targeting or building databases for resale. Human support access to content depends on specific authorization, except for applicable security exceptions and legal obligations.

The use and transfer of information received from Google APIs follow the Google API Services User Data Policy, including the Limited Use requirements, and the Google Workspace data policy. Campaigns through Gmail must respect the provider's rules, including recipient consent and unsubscribe.

You can disconnect the mailbox under Settings → Channels. This stops new synchronizations and removes the credentials stored at Nextwho; operations already started may still be completing. To revoke the authorization at Google, use your Google Account Connections. That revocation may affect other Nextwho features authorized on the same Google account.

Disconnecting does not automatically delete existing history. The history is retained according to the purposes and retention rules of this policy. To request its deletion, including data obtained from Gmail, follow the deletion instructions or write to [email protected]. The request covers the associated records, except for mandatory retention and the technical rotation of backups; the handling and applicable limits will be stated in the response.

2. Who decides on processing

nextwho as controller

Determines the data needed for the website, registration, authentication, security, billing, support and its own relationships.

nextwho as processor

Carries out customer instructions concerning lists, campaigns, messages, responses, workflows, calendar, CRM and workspace content.

The role depends on the decisions actually made in each operation, not just the name used in the contract. If nextwho determines the purpose and essential means of a database or its own enrichment service, it will act as controller for that operation and provide the corresponding transparency. The customer is normally the controller of the campaigns it creates, the selected audience, the offer and the communications sent on its behalf.

The obligations between the customer and nextwho are detailed in the Data Processing Agreement.

3. Personal data we may process

CategoryExamples
Account and identityName, email, photo, organization, job title, login and workspace identifiers.
Professional contact detailsName, job title, company, corporate email, professional phone number, professional profile and location.
Company and contextDomain, industry, size, CNPJ, location, technologies, public signals and corporate or commercial information.
Campaign and conversationLists, segmentation, messages, responses, intent, tasks, meetings, stages and contact history.
Usage and securityIP address, browser, device, access logs, auditing, failures, consents and usage events.
SubscriptionPlan, prospecting allowance, billing, tax data, payments and support.
IntegrationsIdentifiers, permissions, protected tokens, synchronized fields and CRM, calendar and channel metadata.

We do not request full card numbers; financial processing is performed by a specialized provider. The customer must not use the platform to infer or segment by health, religion, political opinion, racial or ethnic origin, sex life, genetic or biometric data, or other sensitive categories without a specific legal basis and contractual authorization.

4. Data sources

Data may come from:

  • users, administrators, forms, demonstrations and support;
  • lists and files uploaded by the customer;
  • CRMs, calendars, email providers and channels connected by the customer;
  • the official extension, only through authorized user actions and selections;
  • legitimate public sources, institutional websites and business registries;
  • contracted data, validation, enrichment and research providers;
  • platform use, technical logs and inferences generated by rules or AI.

Public data is not unprotected data. Before using public sources or legitimate interest, the purpose, necessity, the person's expectations, impact, safeguards and method of objection must be assessed.

5. Purposes and legal bases

PurposeBases that may apply
Creating an account, authenticating, providing and billing for the servicePerformance of a contract and preliminary procedures.
Security, fraud prevention, auditing and defenseLegitimate interest, legal obligation and the regular exercise of rights.
Executing lists, enrichment, workflows and integrationsInstructions from the customer acting as controller and the bases it defines; contract where applicable.
Providing support and product communicationsContract, legitimate interest or consent, as applicable.
Improving the product and measuring performanceLegitimate interest with minimization; consent for optional technologies when necessary.
Complying with obligations and responding to authoritiesLegal or regulatory obligation and the regular exercise of rights.

When processing depends on consent, it must be freely given, informed, unambiguous and specific, and may be revoked. Legitimate interest will not be used for sensitive data and requires a documented balancing assessment and safeguards.

6. Prospecting, objection and suppression lists

Customers use nextwho for B2B commercial communications. They must define a legal basis, respect contacts' expectations, identify the sender, limit frequency and provide a simple way to stop receiving further messages. When a person objects, contact must stop and a minimal record may be retained on a suppression list to prevent further outreach.

Requests relating to a campaign should first be directed to the company identified in the message, which normally controls the operation. nextwho may receive the request, technically block the contact and forward the request to the responsible customer.

7. AI, profiles and automated decisions

AI models may research authorized sources, personalize text, summarize conversations, classify fit or intent and recommend the next action. These inferences may be wrong. The customer defines rules, sources, channels and oversight and must review decisions with greater impact.

We do not authorize discriminatory decisions or profiles based on sensitive data. When a decision is made solely through automated processing and affects a person's interests, that person may request information and review under the LGPD, subject to commercial and industrial secrecy.

8. Sharing and subprocessors

We share only what is necessary with:

  • cloud, database, storage, observability, security and support services;
  • authentication, billing and payment processing services;
  • email, WhatsApp and other enabled channels;
  • AI, research, validation and data enrichment services;
  • CRMs, calendars and integrations enabled by the customer;
  • advisers and authorities when necessary by law or to protect rights.

Providers receive only data compatible with their function and are subject to protection commitments. The applicable list of providers and countries may vary according to the features enabled and will be made available during the contracting process or upon request.

9. International transfers

Some providers process data outside Brazil. When an international transfer takes place, we will adopt a valid mechanism provided for in the LGPD and ANPD regulations, including standard contractual clauses where applicable, as well as technical and contractual protection and transparency measures.

10. Retention, export and deletion

We retain data only for as long as necessary for the service, the stated purposes and legal obligations. The specific period depends on the category, contract, litigation, security and customer instructions.

  • account data and workspace content: during the relationship and the contracted export or retention window;
  • billing and tax documents: for the applicable statutory periods;
  • logs and auditing: for statutory periods and the period needed for security and investigation;
  • backups: until the applicable technical rotation, with restricted access and no restoration for ordinary use;
  • suppression lists: in a minimized form for as long as necessary to prevent improper contact;
  • acceptances and contractual evidence: for the period needed for proof and the exercise of rights.

At the end of the period, data is deleted, anonymized or retained with restrictions where there is a legal basis. The customer must export the content it wishes to preserve before the stated window closes.

11. Security and incidents

We adopt controls proportionate to the risk, including workspace separation, access control, credential protection, audit trails, backups, monitoring and secure development practices. No system is immune to incidents; users must also protect devices, accounts and integrations.

Incidents are assessed, contained, recorded and communicated according to the parties' roles, the risk and statutory timeframes. When acting as processor, nextwho will notify the customer acting as controller without undue delay and provide reasonably available information for its assessment and communication.

12. Cookies and local storage

The public website uses only technologies necessary for navigation, security and current operation. The authenticated platform uses a session cookie and temporary storage necessary for authentication, invitations and preferences. We will not enable optional analytics or advertising cookies without updating the Cookie Policy and offering appropriate controls before use.

13. Data subject rights

Under the LGPD and depending on the context, a person may request:

  • confirmation of the existence of processing and access;
  • correction of incomplete, inaccurate or outdated data;
  • information about sharing and relevant criteria;
  • anonymization, blocking or deletion of unnecessary or unlawfully processed data;
  • portability, where regulated and applicable;
  • deletion of data processed with consent, except where retention is permitted;
  • withdrawal of consent, objection and review of automated decisions.

Send your request to [email protected]. We may request proportionate information to confirm identity and locate the data. Requests concerning customer campaigns will be forwarded to the corresponding controller, without preventing a precautionary block of the contact.

You can also find out about the channels of the Brazilian National Data Protection Authority.

14. Changes and contact

This Policy may be updated due to legal, operational or provider changes. Significant changes will be communicated through appropriate means, and a new version will be published with the update date.

Privacy channel: [email protected]. General inquiries: [email protected].

© 2026 BdrGo Data deletion · Cookies · Acceptable use · Commercial terms Questions: [email protected]