Skip to content
A1 QuoteQuote
PricingDocsFor suppliers
Sign inRequest my next purchase quote

A1 Quote. Quotations on your behalf, form replies in one place.

PrivacyTermsDocsSupplier portal

Privacy policy

Updated on 06/09/2026

On this page
  1. 1. Who we are and our role
  2. 2. Buyer data (account holders)
  3. 3. Supplier data (recipients of requests)
  4. 4. Legal basis for first contact
  5. 5. How to opt out
  6. 6. Sharing and processors
  7. 7. Retention
  8. 8. Your rights (Article 18)
  9. 9. Security
  10. 10. Changes

Draft for review before the service is made available. The commitments described must be confirmed in operations. This translation follows the Portuguese source.

This policy explains what data A1 Quote stores, why, for how long, and how you can exercise your rights. It applies to two different groups: buyers (who create an account and send requests for quotation) and suppliers (who receive a request by email or WhatsApp, with or without an account). Applicable law: Brazil's General Data Protection Law (Law 13,709/2018, LGPD).

1. Who we are and our role#

A1 Quote is a platform that sends requests for quotation on behalf of the buyer to the suppliers they select, receives responses, and organizes them for comparison.

  • For data about the buying business and its users, A1 Quote is the controller: it determines how accounts, billing, and history are processed.
  • For supplier data registered by the buyer (name, email, phone), the buyer is the controller who decides to contact that person, and A1 Quote is the processor, acting on their instructions. A1 Quote is a controller only for what it needs to protect the supplier: the global opt-out list and delivery records.

Contact channel for privacy and personal data: contato@a1solutions.ia.br.

2. Buyer data (account holders)#

Data Purpose Legal basis (Article 7)
Name, email, business, sector Create the account, identify who sends each request, sign messages on their behalf Performance of a contract (item V)
Requests, items, registered suppliers, responses, orders Provide the service: send, collect, compare, generate orders, and keep history Performance of a contract (item V)
Billing data (plan, credits, payment status) Charge subscriptions and credits; card numbers stay with the payment provider, never with us Performance of a contract (item V); legal obligation for tax invoices (item II)
Access logs (IP, date, browser) Account security and compliance with Brazil's Civil Rights Framework for the Internet Legal obligation (item II)
API keys and MCP usage Allow agents to operate the account; measure usage for billing Performance of a contract (item V)

3. Supplier data (recipients of requests)#

Suppliers do not need an account. We store the following data about them:

Data Source Purpose
Name, contact name, email, phone, CNPJ Registered by the buyer, imported from their spreadsheet, or suggested by searches of public sources (business contact details published by the business itself) and approved by the buyer before any message is sent Deliver requests and orders
Responses (prices, deadlines, terms, attachments, free text) Sent by the supplier through the link, email, or WhatsApp Show them to the requesting buyer; they remain within that buyer's account
Delivery, opening, and response records Generated by the platform Measure whether messages arrived; avoid sending again to suppliers who have responded
Opt-out request (opt-out) Made by the supplier through the link Never contact that email or phone again, on behalf of any buyer

A supplier's responses are visible only to the buyer who made that request. Prices are never shared between different buyers.

4. Legal basis for first contact#

  • Email (first contact): the buyer's legitimate interest (Article 7, item IX) in requesting a price from a supplier whose business contact is public or who already supplies them. Every message identifies the requester and purpose and includes an opt-out link. The proposed balancing assessment considers: the contact is commercial, expected in this market, limited to one request and one reminder, and the supplier can opt out with one click.
  • WhatsApp: consent (Article 7, item I). Suppliers receive WhatsApp messages only when the channel is authorized; the buyer records the source. An email response does not authorize WhatsApp or open its customer service window. Messages use the official WhatsApp Business API with an approved template.
  • Sensitive data (Article 11): the platform does not request or need any. If a buyer includes sensitive data in a request, they are responsible for it and must remove it.

5. How to opt out#

Any supplier can request to stop receiving requests in three ways:

  1. Through the “unsubscribe” link included in every message sent by the platform (an address such as /u/<código>).
  2. By replying to the request email with that request.
  3. By writing to contato@a1solutions.ia.br.

The request applies to the entire platform: no buyer can send again to that contact. Suppliers can reverse their decision only by requesting it in writing.

You can request deletion of your data through the quotation link or at contato@a1solutions.ia.br.

6. Sharing and processors#

We do not sell data. We use processors to provide the service, each receiving only what they need:

Processor Purpose
Transactional email provider Deliver messages and record delivery, bounces, and opens
Meta (WhatsApp Business Platform) Deliver WhatsApp messages when the buyer connects their business number
Database and hosting provider Store and serve account data
Payment provider Charge subscriptions; it stores the card, we do not
Automated text-reading provider Extract prices and quantities from free-text or PDF responses; the source passage is stored as evidence for the buyer to check

Some processors are outside Brazil. Transfers follow Article 33 of the LGPD, with contractual clauses providing equivalent protection.

7. Retention#

  • Buyer account: for as long as the account exists. On closure, data is deleted within 30 days, except what the law requires us to retain (tax records for 5 years; access logs for 6 months).
  • Supplier data within an account: follows the buyer's account. Suppliers can request deletion at any time; we keep only the email or phone on the do-not-contact list to respect the request.
  • Opt-out list: retained for as long as the platform exists. This is the only way to ensure the request is respected.
  • Backups: overwritten within 35 days.

8. Your rights (Article 18)#

Buyers and suppliers can request at any time: confirmation that we process their data, access, correction, anonymization, portability, deletion, information about parties with whom we share data, and withdrawal of consent. We respond within 15 days. If you disagree with the response, you can complain to Brazil's National Data Protection Authority (ANPD).

Requests: contato@a1solutions.ia.br.

9. Security#

Data is encrypted in transit and at rest. Each business is isolated by rules in the database itself; users cannot see another business's data. API keys are stored as hashes. Incidents involving significant risk are reported to the ANPD and affected individuals, as required by Article 48.

10. Changes#

When this policy changes, the date at the top is updated and buyers with accounts are notified by email. Changes that expand data use take effect only after that notice.