Last updated: August 19, 2026
This Privacy Policy describes how SipCode Brasil (“SipCode”, “we”) collects, uses, stores, and protects personal data in the context of our institutional website (sipcode.com.br) and all solutions in the SipCode Ecosystem (Cloud PBX, Multiatendimento Flex, CCB Lite, ClickSIP, WhatsApp Dashboard, UnifySAC Prospecta, Mapper360, Zap360, Smart-SIP Softphone, and APIs), in compliance with Brazil’s General Data Protection Law (Law No. 13,709/2018 — LGPD) and the Brazilian Civil Rights Framework for the Internet (Law No. 12,965/2014).
By using our website or contracting any solution in the SipCode Ecosystem, you agree to the practices described in this Policy. If you do not agree, please do not use our services.
1. Who we are and how to reach us
SipCode Brasil is a business communication technology company, headquartered in Saquarema, RJ. For any request related to this Policy or your personal data, contact us at contato@sipcode.com.br.
2. What data we collect
We collect different categories of data, depending on how you interact with us:
- Website browsing data: pages visited, time spent, referral source, device and browser type — collected via cookies and analytics tools. Specific use of cookies is detailed in our Cookie Policy, in accordance with your consent.
- Form and contact data: name, email, phone, company, and job title, when you fill out a demo, quote, partnership, or support request form.
- Contracting data: company name, tax ID, billing data, and address, when you become a client of a SipCode solution.
- Usage data from contracted solutions: call records (metadata, not conversation content, except when recording is an expressly contracted feature), WhatsApp Business interactions, prospecting data, and other operational information generated by normal use of each solution.
- IP address and approximate geolocation: automatically collected during interactions with certain solutions — see section 3 below for specific details.
3. IP and geolocation collection by ClickSIP
ClickSIP, our WebRTC click-to-call solution, records the full IP address and approximate geographic location (city/region, estimated from the IP) of every visitor who clicks a ClickSIP button, link, or QR code — regardless of whether the call is actually completed. We also record the device, browser, and operating system used at the time of the click.
This collection also occurs when the link is accessed through our URL-shortening service, used to generate ClickSIP’s short links and QR codes. IP and geolocation are collected at the moment the link is accessed, even before redirection to the call screen.
Why we collect this data: this information is the functional core of the analytics report we deliver to our clients who contract ClickSIP — conversion funnel, click source, and service rate by channel. Without recording IP and approximate location, this feature — which is the product itself — cannot exist.
Legal basis: contract performance (art. 7, V, LGPD) in relation to the client company that contracted ClickSIP, and legitimate interest (art. 7, IX, LGPD) for security, fraud prevention, and service improvement purposes, always proportionally and with appropriate technical safeguards.
This same type of collection (IP and, when applicable, approximate geolocation) may also occur in other SipCode Ecosystem solutions that involve access-source tracking, such as WhatsApp Dashboard and UnifySAC Prospecta, always for the same purpose: providing the contracting client with the operational and analytical data of their own solution.
4. How we use the data collected
- Enable the technical operation of contracted solutions (e.g., routing a ClickSIP call to the correct phone system).
- Generate reports and analytics for our clients about the use of their own solutions.
- Respond to contact, demo, and support requests.
- Issue billing and manage the contractual relationship.
- Comply with legal and regulatory obligations.
- Prevent fraud, misuse, and protect the security of our systems.
- Improve our products based on aggregated and anonymized usage patterns whenever possible.
We do not use your personal data for purposes incompatible with those described in this Policy without first seeking your authorization, when required by law.
5. Who we share data with
We never sell personal data. We share data only in the following situations:
- With the contracting client company of a solution (e.g., a company that contracted ClickSIP has access to the analytics data generated by its own ClickSIP usage — not that of other clients).
- With service providers (data processors) who help us operate our infrastructure — hosting, transactional email providers, billing tools — always under contractual confidentiality obligations restricted to the contracted purpose.
- By legal obligation, when required by a competent authority, court order, or for the regular exercise of rights in administrative or judicial proceedings.
6. How long we retain data
We retain personal data for as long as necessary to fulfill the purposes described in this Policy, including compliance with legal, accounting, and tax obligations (generally 5 years after the end of the contractual relationship, subject to applicable statutes of limitation). Browsing and cookie data follow the retention periods described in our Cookie Policy. After this period, data is deleted or irreversibly anonymized.
7. Contractual relationship and service interruption
SipCode Ecosystem solutions are provided upon contracting and recurring payment. The processing of personal data linked to each solution is directly tied to the term of the corresponding contract.
In case of delinquency (late or missed payment), SipCode reserves the right to suspend or interrupt access to contracted solutions, without prior notice, until payment is regularized, without prejudice to the collection of amounts owed and other applicable measures provided for in the contract. Data stored during the suspension period is retained for a reasonable time to allow for regularization, after which it may be deleted according to this Policy’s retention periods.
This clause does not affect the data subject’s rights under the LGPD, which remain fully exercisable even during a service suspension period.
8. Information security
We adopt technical and administrative measures to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or any form of inadequate processing, including: encrypted connections (HTTPS/TLS) throughout the communication chain, user-profile-based access control, audit logging of sensitive administrative actions, and automatic code validation before any update goes into production. No system is 100% immune to incidents — should a security incident occur that could pose relevant risk to data subjects, we will notify as required by the LGPD.
9. Your rights as a data subject
Under articles 17 through 22 of the LGPD, you have the right to:
- Confirm the existence of processing of your data.
- Access the data we hold about you.
- Correct incomplete, inaccurate, or outdated data.
- Request anonymization, blocking, or deletion of unnecessary data or data processed in violation of the LGPD.
- Request data portability to another service provider.
- Request deletion of data processed based on your consent.
- Obtain information about who we share your data with.
- Revoke consent, when processing is based on it.
- Object to processing carried out based on another legal basis, when applicable.
To exercise any of these rights, contact us at privacidade@sipcode.com.br. We will respond within the timeframes established by the LGPD.
10. Cookies
The use of cookies on this website is detailed in our Cookie Policy, managed in compliance with the LGPD through our own consent banner.
11. Changes to this Policy
We may update this Policy periodically to reflect changes in our practices or as required by law/regulation. The date at the top of this page indicates the most recent version. Relevant changes will be communicated through this website or, when applicable, directly to contracting clients.
12. Contact
General questions can be sent to contato@sipcode.com.br. Requests or complaints specifically related to the processing of personal data can be sent to privacidade@sipcode.com.br. You also have the right to file a complaint with Brazil’s National Data Protection Authority (ANPD).