Skip to content
couryo

Draft pending legal review

Privacy policy

Updated 2026-10-07

Draft pending legal review. This text is not yet a published policy. Items in brackets must be filled in before publishing. If this English version and the Portuguese version differ, the Portuguese version prevails.

1. Who processes the data#

Couryo is a service of [WUNKA LEGAL NAME], CNPJ [CNPJ] ("Wunka", "we"), a company based in Brazil and subject to Brazil's data protection law (LGPD).

2. What data we process#

Category Examples Source
Account name, email, Google profile picture, company, tax ID you and Google sign-in
Billing plan, invoices, tax details you and the payment processor
Usage and security IP address, browser, dashboard and API access logs collected automatically
Email sent sender, recipients, subject, content, attachments, metadata and delivery events sent by you through the API or SMTP
Support messages and review requests you

Card details are handled directly by the payment processor; Couryo does not store them.

Purpose Legal basis
Providing the service: sending, logging events, calling webhooks performance of a contract
Billing and invoicing performance of a contract and legal obligation
Preventing abuse, fraud and account takeover, and protecting sending reputation legitimate interest
Support and account communication performance of a contract
Improving the product with aggregated data legitimate interest

4. Automated decisions#

To prevent abuse, automated systems, including AI models, analyze email content and links (all of it at level 1, by sampling at level 2) and bounce and complaint rates. These analyses may limit or pause sending. You have the right to request a review of any automated decision: requests are analyzed right away and, if there is still doubt, by a person within 1 business day.

We do not use the content of your email to train AI models. [CONFIRM IN AI VENDOR CONTRACTS.]

5. Who we share it with#

Only with subprocessors needed to run the service, by category:

The named list of subprocessors is available to customers on request and in the DPA. We give notice before adding a new subprocessor. We also share data when required by law or court order.

6. International transfers#

Couryo's infrastructure is currently in the United States, and some subprocessors process data outside Brazil. Transfers follow article 33 of the LGPD, using standard contractual clauses approved by Brazil's data protection authority (ANPD) or another valid mechanism. [CONFIRM THE MECHANISM IN EACH CONTRACT.]

7. How long we keep it#

Data Period
Send logs and events your plan's log retention: 7 days (Free), 30 days (Pro), 90 days (Scale), custom (Enterprise)
Suppression list while the account exists, so we never email someone who asked to stop
Account data while the account exists and for the legal period after closure
Tax and billing data for the period required by tax law
Access logs 6 months, as required by Brazilian law

8. Security#

We use encryption in transit, API keys stored only as hashes, 2FA, role-based access control and monitoring. If a relevant security incident occurs, we notify affected users and the authorities within the legal deadlines.

9. Your rights#

You can request: confirmation of and access to your data, correction, anonymization, blocking or deletion of unnecessary data, portability, information about sharing, withdrawal of consent and review of automated decisions.

If you are the recipient of an email sent by a Couryo customer, the controller is the company that sent it. Contact them first. If you cannot, write to our data protection officer and we will help route your request.

10. Data protection officer#

Data protection officer: [DPO NAME]. Contact: privacidade@couryo.com.

11. Cookies and local storage#

This site does not use advertising or tracking cookies. It only stores your theme preference (light or dark) in your browser. The dashboard uses a session cookie, needed to keep you signed in.

12. Changes to this policy#

Material changes are announced by email and on this page, with the update date.