VB Agent Builder

Privacy Policy

Last updated: July 3, 2026

This Privacy Policy describes how VB Agent Builder, a product of Virtual Boost ("we", "us", or "the platform"), collects, uses, shares, and protects information while providing our service for building and operating AI customer-service agents integrated with messaging channels (WhatsApp, Instagram Direct, Facebook Messenger, Telegram, and a website widget).

By using the platform, available at vbagentbuilder.com, you agree to the practices described here. We process personal data in accordance with applicable data protection laws, including Brazil's General Data Protection Law (LGPD — Law No. 13.709/2018), and with the policies of the integrated platforms, including the Meta Platform Policies.

1. Who we are and our roles

The platform is a tool that our customers ("Subscribers") use to serve their own end customers. Regarding end-customer data that flows through conversations, we act as a processor, while the Subscriber is the controller. Regarding the Subscriber's account data, we act as controller.

2. Data we collect

2.1. Data you provide

2.2. Data from connected channels (Meta and others)

When you connect a Facebook, Instagram, or WhatsApp account, we receive, through Meta's official APIs and with your explicit authorization:

2.3. Automatically collected data

3. How we use the data

We do not sell personal data. We do not use end-customer message content for advertising, nor to train third-party AI models.

4. Legal basis

We process data based on: performance of a contract (providing the service), consent (when connecting channels and authorizing access), legitimate interest (security and service improvement), and compliance with legal obligations.

5. Sharing and subprocessors

We share data only with providers essential to the operation, under confidentiality obligations:

We may also disclose data when required by law or by a competent authority.

6. Use of third-party platform data

6.1. Meta (Facebook, Instagram, WhatsApp)

Our use of information received from Meta's APIs follows the Meta Platform Policies. We use Facebook, Instagram, and Messenger data solely to operate the automated support you configured — receiving the customer's message and sending the agent's reply. We do not transfer this data to data brokers, nor use it for unauthorized purposes.

6.2. Google (Google Calendar)

When you connect a Google account for the scheduling feature, we access — with your authorization via Google OAuth — the Google Calendar API to: (a) check your availability (free/busy) and (b) create and read events on the selected calendar, so the agent can book appointments during the conversation. We store, encrypted, only the refresh token needed to maintain the connection; we do not copy or store your full calendar content beyond what the feature requires.

VB Agent Builder's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google data for advertising, do not sell it, and do not use it to train generalized AI models — we use this information solely to provide and improve the scheduling feature you enabled.

6.3. TikTok (Business Messaging)

When a business connects their TikTok Business Account, we access — with the account holder's explicit authorization via TikTok OAuth and under the Business Messaging permission — the TikTok Business Messaging API solely to: (a) receive the direct messages (DMs) that TikTok users send to that business account and (b) send the business's reply within the same conversation. We do not access ad, video, follower, or analytics data beyond what is needed to operate messaging, and we do not message users proactively — we only reply within conversations a user has started. Our use of information received from TikTok APIs complies with the TikTok Developer Terms and Data Protection requirements: we do not sell this data, do not use it for advertising, and do not use it to train generalized AI models. Businesses can disconnect their account at any time, which stops all further access.

7. Retention

We keep data while your account is active and for as long as necessary for the purposes of this Policy or as required by law. Once the account is closed, data is deleted or anonymized within a reasonable period, except where legal retention applies.

8. Security

We adopt technical and organizational measures to protect data, including encryption of credentials and tokens, access control, and transmission over HTTPS. No system is 100% infallible, but we work continuously to mitigate risks.

9. Your rights

Under applicable law, you may request: confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing, and withdrawal of consent. To exercise these, contact us (section 15).

10. Data deletion

You can request deletion of your data at any time:

11. Cookies

We use only cookies and local storage essential to operation (for example, keeping your session and chosen language). We do not use advertising cookies.

12. Minors

The platform is intended for businesses and people over 18. We do not knowingly collect data from minors.

13. International transfer

Some providers may process data outside Brazil. In such cases, we adopt appropriate safeguards in line with the LGPD.

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be communicated through our usual channels, and the "Last updated" date at the top will be revised.

15. Contact

Questions, requests, or exercising your rights: