Lunaum produto da Helsen Ia Tecnologia LTDA

Version 1.3 · In force since 2026-08-02 Publication address: https://lunahia.com.br/en/data-deletion Portuguese version: https://lunahia.com.br/exclusao-de-dados

Language notice. This is a courtesy translation. The original and legally prevailing text is the Portuguese version. Should any divergence in meaning arise between the two texts, the Portuguese version prevails.

Document status. This page has been in force since 2026-08-02, the date it was published at this address, and it describes the procedure actually in use — the periods below are the ones implemented on the platform. External legal review by a lawyer has not been carried out as of that date: it is an open, tracked item, and it ceased to be a condition of entry into force on 2026-08-02.

This is the data deletion instructions page referenced in Helsen's app with Meta. It applies to anyone: an end user who exchanged messages with a company over WhatsApp, a company that is a Helsen customer, or a business that owns a connected number. The full policy is at https://lunahia.com.br/en/privacy.


Step by step

  1. Write to Helsen's privacy channel, the address ia.helsenservice@gmail.com, with the subject "Data deletion". It is the same channel published in section 10 of the privacy policy, at https://lunahia.com.br/en/privacy.
  2. Provide at least one identifier so that the records can be located:
    • the phone number in E.164 format (e.g. +5511999999999); or
    • the business-scoped user identifier — the value Meta delivers in the user_id or recipient_user_id fields, in the form US.13491208655302741918. This is the right identifier when the phone number is not available; or
    • if you are a corporate customer, the tax ID and the contact e-mail on the account.
  3. Say which company you talked to, if you know. Helsen is the messaging infrastructure; the one that decided to talk to you is the company that owns the number — and, for requests about the interaction itself, that company is the controller.
  4. Wait for the acknowledgement of receipt, sent through the same channel.
  5. Receive the answer within 15 calendar days of the complete request being received, stating what was deleted at each link of the chain and what the law required to be kept.

No request requires creating an account, installing anything or filling in an authenticated form.


What is deleted at each link of the chain

LinkWhat is deletedWho executes itNote
HelsenNormalized message content, raw webhook envelope, media files, status metadata and identifiers associated with the identifier providedHelsenExecuted directly, within the response deadline
The company you talked to (End Business)Whatever it keeps in its own system, which Helsen does not controlThe company itselfHelsen forwards the request and states whom to address
The software company that integrated the channel (Customer)Whatever it keeps in its own productThe company itselfSame as above
Contact repository hosted by Meta (Contact Book)The pair phone number ↔ business-scoped identifierMeta, at Helsen's requestSee the next section

Deletion in the repository hosted by Meta

The Contact Book is a repository hosted by Meta, not by Helsen. It automatically records the pair phone number ↔ business-scoped user identifier when the feature is enabled on the business portfolio.

Three practical consequences, stated without euphemism:

  • Deletion in that repository is done by business-scoped user identifier, through Meta's own Contact Book API. That is why step 2 asks for that value whenever it is available.
  • There is no API to list the contents of that repository. Helsen cannot enumerate what is there to check before or after.
  • Helsen does not control the execution time nor the retention in that repository. It forwards the request and reports whatever outcome it obtains.

What is not deleted, and why

What remainsPeriodLegal basis
API access logs6 months, implemented as 185 daysMandatory retention under article 15 of the Brazilian Internet Civil Framework for an application provider incorporated as a for-profit legal entity. Six months amount to 181 to 184 days depending on the start date, and 185 is the smallest whole number that never falls short of the statutory floor — see section 6 of the privacy policy
Tax documents and billing records5 yearsTax obligations and statutory limitation periods. They contain no message content

Outside those cases there is no discretionary retention: everything else follows the periods published in the privacy policy and is deleted automatically at the end of each one, regardless of any request.


Note on the format of this page

Meta accepts, in the app registration, a data deletion instructions URL as an alternative to the deletion callback. Helsen adopted the instructions URL: there is no end-user account in Helsen's console today, and a deletion callback presupposes an authenticated user to be removed. Migration to a callback will happen once a real user account exists in the console — and this page will then point to the new flow, without ceasing to exist.


Version history

VersionDateWhat changedStatus
1.02026-07-29Initial drafting, with the step-by-step, the links in the deletion chain and the Meta-hosted repositorySuperseded
1.22026-08-02Publication at this address and rewrite of the status note: the page is now in force as of the publication date, and external legal review is stated as an open, tracked item rather than a condition of entry into forceSuperseded
1.32026-08-02Two changes. (1) The access log period is no longer published as "6 months, that is, 180 days". The equality was false on every start date — six months amount to 181 to 184 days — so a 180-day parameter would erase the record before the floor of article 15 of the Internet Civil Framework. It is now published as 6 months, implemented as 185 days, in the same wording already adopted by the privacy policy. (2) Separation between the published text and the internal drafting support: the working version control and the method notes leave the page and remain in the source, and references to other published documents are now made by public address. No other period, procedure or obligation was changedIn force

Helsen's legal documents are published in Portuguese and in English. The Portuguese version is the legally prevailing one; the English version is a courtesy translation.