Version 1.0 · Editorial review on October 1, 2026 · Central Carioli
1. Who we are and how to get in touch
THE E A DE F CARIOLI ENGENHARIA, commercially identified as Carioli Engenharia, is responsible for decisions regarding the processing of personal data carried out for its own activities in Central Carioli.
Central Carioli is the system for organizing services, contacts, companies, protocols and internal activities at Carioli. “Carioli Connect” identifies the functional evolution of this same solution.
For privacy issues and the exercise of rights, please contact us by email contato@carioliengenharia.com.br, with the subject Privacy — Central Carioli. This address is the service channel provided for in this policy; his appointment is not equivalent to the appointment of a person in charge.
2. Scope and stage of the solution
This policy covers personal data present in the Center's registrations, services, communications and operational records, including data from customer representatives, interested parties, suppliers, partners and internal users.
The solution is being implemented and approved. Production connection with the official WhatsApp platform and coexistence with the WhatsApp Business App still depend on configuration, validation and Meta requirements. The technical preparation of a connector does not mean that all WhatsApp conversations are already received by the system.
Advanced CRM, automation, expanded project management and MRP are expected developments. Reference to these functionalities does not declare their availability or automatically authorize new processing purposes. Relevant changes will have their notices and rules updated before the new treatment.
The navigation and forms of the institutional website are described in Website Privacy Policy. This notice specifically addresses the Center.
3. What data may be present
Depending on the interaction and resources actually used, the Center may contain:
- Identification and contact: name, email, telephone number, position and link to a company.
- Business context: corporate name, commercial name, segment and location of the represented organization.
- Service: content of messages and notes, summary of demand, responsible parties, priorities, dates, progress, protocol and activity history.
- Internal access: user name and email, department, access profile, protected authentication information and sessions.
- Traceability: authorship, date and type of operation, access changes and records necessary for security and diagnosis.
- Enabled integrations: account identifiers, number and message, profile name when provided, sender, processing or failure times and events made available by the integrated service.
Events received from an integration may contain additional metadata, even when certain functionality is not displayed in the interface. Receiving a media event does not mean that the file has been downloaded or that the system supports the media.
We ask that people only share what is necessary for the service. Complete personal documents and sensitive data should not be sent spontaneously when not necessary. If an activity requires this data, the need and the appropriate way to receive it must be clarified.
4. Source of data
The data can be provided directly by the person, by an authorized representative of a company, by internal users during the service or through integrated and enabled communication channels.
Registering a contact with a company does not automatically give you access to all of that organization's or other people's data. Imports and integrations must respect the stated purpose and permissions granted.
5. What we use the data for
The intended purposes are:
- Receive requests, identify contact and forward assistance.
- Continue negotiations, budgets, support and contractual relationships.
- Organize protocols, responsible parties and history necessary to carry out the work.
- Authenticate users and manage permissions.
- Investigate failures and protect accounts, records and the operation.
- Comply with applicable obligations and rights requests.
The legal basis depends on the transaction: pre-contractual measures or contract, legal obligation, exercise of rights, assessed legitimate interest or specific consent when necessary. We do not use simply reading this policy as general consent. Sensitive data requires its own hypothesis and specific analysis.
6. Who can access and who can we share with
Internal access is organized by functions, departments and concessions related to service. The board has broad access, including to records classified internally as confidential. This classification restricts operational access; does not mean secrecy against the responsible administration itself.
When necessary for the purposes described, data may be processed by infrastructure, storage, communication and technical support providers, under conditions compatible with their activity and responsibility. The effective list of providers must correspond to the implemented environment.
When a WhatsApp channel is enabled, Meta/WhatsApp participates in the transmission and operation of that channel, according to its own terms and notices. The role of each organization depends on the treatment carried out; It is not assumed that all external services are solely Carioli operators.
Data may also be presented to authorities or advisors when there is an applicable obligation or legitimate need to defend rights, limited to the necessary context.
The use of providers located abroad may involve international transfer. Before enabling this processing, Carioli must identify the recipients, the conditions and the applicable mechanism. Information on transfers actually carried out may be requested via the privacy channel.
7. WhatsApp, coexistence and history
The integration must use the resources officially available and authorized for the number. Enabling coexistence, when available, does not guarantee full synchronization of old conversations, groups, calls, media, or all devices.
Central permissions do not control existing access to the WhatsApp Business app and linked devices. Managing these accesses is a separate operational responsibility.
Requesting deletion in the Center does not automatically delete copies on another participant's phone, WhatsApp or external services.
8. Security and sessions
The Center has authentication mechanisms, access control and audit records. The operation must maintain protected credentials, access review and adequate configuration of the environments used.
No system offers absolute security. Suspicions of improper access or sending information to the wrong recipient must be reported to the contact channel.
The application uses mechanisms necessary to maintain the authenticated session. Cookies and measurement technologies on the institutional website need to be evaluated separately; This policy does not assert the absence of trackers on this site.
9. Conservation, archiving and disposal
The retention period depends on the purpose, the relationship with the person, applicable obligations and any substantiated need to defend rights. There is no unlimited retention authorization in this document.
Archiving a service or placing it in the trash does not mean deleting all personal data. Linked records, auditing, integration events and backups, when existing, also need to be considered in the analysis.
A technical exclusion restriction does not replace a justification for retaining data. If a request requires processing of linked records, an appropriate solution must be assessed, such as deletion, anonymization or access restriction, as appropriate.
When there are backup copies, the processing of the request must consider its effective replacement cycle and the necessary care not to reintroduce data deleted after a restoration. We do not promise instant deletion of all copies.
10. Your rights and how to request
You can request confirmation and access, correction, information about sharing, portability under the applicable terms, review of exclusively automated decisions when existing, revocation of consent and anonymization, blocking or deletion in the cases provided for by law.
Send the request to contato@carioliengenharia.com.br. Identity confirmation will be proportional to the request; do not send passwords, tokens or authentication codes. Rights assistance is free. When a measure cannot be adopted, the response must explain the reasons.
The procedure is in Data deletion request.
11. Updates
The published version will indicate its update date. Relevant changes in purpose, data categories, integrations or audiences served must be communicated appropriately. Expansion to CRM or MRP may require specific notices.
