Version: 4.0 | Effective Year: 2026

1. Introduction

These Terms of Use govern access to and use of the Positus Platform, a product made available by POSITUS TECNOLOGIA DA INFORMAÇÃO LTDA., a private legal entity registered under CNPJ No. 34.258.755/0001-02, headquartered at Avenida Angélica, No. 2530, 15th floor, Bela Vista district, in the city of São Paulo/SP, Brazil, ZIP code 01228-200, hereinafter referred to simply as “Positus“.

Positus is a company within the Robbu Group (https://robbu.global/home/) and acts as an official Business Service Provider (BSP), duly licensed by Meta Platforms, Inc. (“Meta”) for the commercialization and provision of the WhatsApp Business Solution (WBS).

The condition of authorized BSP can be verified in Meta’s Official Partner Directory, available at: https://www.facebook.com/business/partner-directory/details?id=225426795144832.

The service provided by Positus is characterized as Platform as a Service (PaaS), consisting of the provision of communication infrastructure through REST APIs and proprietary interfaces, which allow the Client company to integrate its systems into the WhatsApp Business Solution ecosystem.

These Terms of Use are intrinsically linked to the WhatsApp Business Licensing Agreement entered into between Positus and the Client company, which establishes in greater detail the contractual rules of the service provided, remuneration, and technical obligations.

These Terms are intended to define the rules to be specifically followed by users linked to the Client company for the use of the products and functionalities of the Positus Platform, without prejudice to the application of current legislation.

2. Acceptance of These Terms of Use

By accessing, using, or integrating with the Platform, the User expressly declares that they have read, understood, and fully agree with these Terms of Use, as well as all documents and policies incorporated by reference, including those established by Meta and the Positus Privacy Policy, available at: https://positus.com.br/politica-de-privacidade

Continued use of the Platform after any updates to these Terms or applicable external policies constitutes tacit acceptance of the changes.

It is important to note that the use of the Platform by persons under 18 (eighteen) years of age is prohibited, as its content is not intended for this audience, and those responsible for granting access shall be subject to liability for any damages caused to Positus or third parties.

Acceptance of this instrument is essential for access to and use of any services provided by Positus. If the User does not agree with the provisions of this instrument, they must not use the Platform.

3. Legal and Regulatory Framework

The legal and regulatory framework applicable to these Terms of Use, according to the product provided, includes:

4. Definitions

For the purposes of these Terms of Use, the following definitions apply:

5. Nature and Scope of the Service

The Positus Platform is a technological solution based on the Platform as a Service (PaaS) model, which provides digital communication infrastructure through REST APIs and proprietary interfaces, allowing the Client to integrate its systems with the WhatsApp Business Solution ecosystem.

Positus acts exclusively as a technical intermediary and infrastructure provider, with Meta being ultimately responsible for the operation of the WhatsApp Business Solution. The authority to approve accounts (WABA), phone numbers, and message templates is exclusive to Meta, and Positus has no decision-making power or interference over such processes.

Positus grants the Client company a limited, non-exclusive, non-transferable, and temporary license to use the Platform, exclusively for operational purposes and within the limits established in these Terms and in the Licensing Agreement.

The license does not imply the transfer of intellectual property rights, and any form of reproduction, modification, reverse engineering, sublicensing, or improper exploitation of the Platform, APIs, or any associated components is prohibited.

6. Incorporation of Third-Party Terms

The use of the Platform is conditioned upon the acceptance and full compliance with Meta’s terms and policies, which are incorporated into these Terms of Use by reference, as if fully transcribed herein.

By accepting these Terms, the User declares that they have read, understood, and agree with the following documents:

In the event of a conflict between these Terms of Use and Meta’s documents, the WhatsApp Business Solution Terms shall prevail.

The User and the Client acknowledge that such documents are an integral part of these Terms and that Meta may change them at any time, regardless of Positus’ consent. Continued use of the Platform after such changes constitutes tacit acceptance of the new rules.

Positus is exempt from any liability for defects or problems arising from non-compliance with the instructions and recommendations contained in Meta’s Terms of Use. If the User or the Client suffer penalties or have the service interrupted due to non-compliance with external rules, Positus cannot be held liable. On the contrary, if the non-compliance causes fines or penalties to be imposed on Positus by Meta, the Client shall be liable for such amounts and any losses and damages.

7. Platform Functionalities

The Positus Platform provides the Linked User, through its interfaces and APIs, with the following operational functionalities:

7.1. Positus Studio

Management interface accessible at http://studio.posit.us/, intended for the configuration and administration of the Platform’s resources, including:

7.2. Positus Messenger

Interface that allows end-user service, with the following capabilities:

7.3. APIs and Integrations

REST APIs that allow the Client to integrate its own systems and perform programmatic operations, including:

7.4. Sandbox Environment

Testing environment that allows:

7.5. Dashboards and Monitoring

Operational tracking and transparency tools:

7.6. Technical Support

Positus provides a technical support channel at https://studio.posit.us/suporte for opening tickets related to operational questions, technical incidents, and guidance on Platform use. Support is provided exclusively to the Client, who may, at their discretion, pass on instructions to their Linked Users.

8. Information Security, Access, and Communication

8.1. Authentication and Use of Bearer Tokens

Access to the Positus Platform APIs is carried out exclusively through Bearer Tokens, generated and managed by Positus Studio. The Client is solely responsible for the safekeeping, confidentiality, and proper use of their tokens.

It is recommended that the Client:

All requests made with the Client’s tokens will be considered their sole responsibility. Positus is not liable for damages arising from improper use, leakage, or compromise of these credentials.

8.2. Access Credentials for Positus Studio and Messenger

The User Linked to the Client is responsible for the confidentiality of their access credentials (login and password), and must use strong passwords, not reuse them in other services, avoid access in insecure environments, and immediately communicate any suspicion of improper use.

All actions taken with their credentials will be attributed to the respective User and will be the Client’s sole responsibility.

8.3. Webhooks and Communication Integrity

The Client must maintain an active and functional Webhook URL, capable of adequately processing notifications and returning an HTTP 200 OK response.

Failures in webhook reception resulting from unavailability or inadequacy of the Client’s infrastructure do not constitute a Platform failure. Positus is not liable for losses of messages, events, or notifications in such cases.

8.4. Positus Security Measures and Dependency Limitations

Positus adopts technical and organizational information security measures, including access controls, network protection, encryption in transit, monitoring, backups, incident management, and team training, in compliance with the LGPD.

Nevertheless, it is not possible to guarantee the total absence of vulnerabilities, due to the nature of the technology and dependence on third-party systems.

8.5. Access Logs

Positus maintains Platform access records for security, audit, and legal compliance purposes, containing information such as date, time, IP address, authenticated user, and actions performed. Logs are stored securely and used exclusively for legal and regulatory purposes.

8.6. Transparency and Availability

Positus provides a Status Page at https://status.positus.global, with updated information on Platform availability, incidents, maintenance, and operational history, constituting its official communication channel regarding service continuity.

9. Personal Data Protection

This section establishes the guidelines for processing personal data within the Positus Platform, in compliance with Law No. 13,709/2018 (General Personal Data Protection Law — LGPD), regulations of the National Data Protection Authority (ANPD), especially Resolution CD/ANPD No. 19/2024, and other applicable rules.

9.1. Roles in Data Processing

Pursuant to Article 5, items VI and VII, of Law No. 13,709/2018, the following roles are established:

The Client acts as the CONTROLLER of the personal data of linked users (consumers who interact with the Client via WhatsApp) and linked users (employees, collaborators, agents of the Client who access the Platform), being responsible for all decisions regarding processing, including:

Positus acts as the PROCESSOR of users’ personal data, processing exclusively under the Controller’s (Client’s) instructions and for the purpose of enabling the communication infrastructure. Positus does not make decisions about the purposes or forms of processing users’ data.

Meta (WhatsApp) acts as the entity providing access to the corporate service, and is also a recipient of operational data and metrics of the account (WABA) for the purposes of operating the WhatsApp Business Solution.

9.2. Obtaining Consent (Opt-in)

In cases where consent is the applicable legal basis, it is the sole responsibility of the Client, as Controller, to obtain prior and express consent from data subjects before sending messages via WhatsApp, pursuant to Article 7, I, of Law No. 13,709/2018.

Consent must be free, informed, unequivocal, and specific for determined purposes. The use of generic or presumed consent is prohibited.

The Client must maintain supporting records of the consent obtained, containing, at a minimum, date, time, form of collection, and purpose informed, which may be required by the ANPD or by judicial or administrative authorities.

The Client undertakes to hold Positus harmless from any sanctions, fines, or liabilities arising from the absence of consent or from the use of an inadequate legal basis.

Positus, as Processor, has no access, control, or interference over the consent-obtaining processes adopted by the Client.

9.3. Management of Blocks and Opt-out

Data subjects may revoke consent at any time, through express manifestation, pursuant to Article 18, §5, of Law No. 13,709/2018.

It is the Client’s sole responsibility to:

Non-compliance with these obligations may result in complaints to Meta, a reduction in account quality, or a ban, for which Positus is not liable.

9.4. Data Subjects’ Rights

Pursuant to Article 18 of Law No. 13,709/2018, data subjects have rights related to their personal data, including, among others: confirmation of processing, access, correction, anonymization, blocking, elimination, portability, information on sharing, and revocation of consent.

Requests must be directed to the Client, as Controller. If Positus receives a request directly from a data subject, it will be forwarded to the Client.

Positus, as Processor, will cooperate with the Client to enable the fulfillment of data subjects’ rights, through formal instructions, observing legal and technical deadlines, not exceeding 15 (fifteen) business days, except in case of technical impossibility duly justified.

9.5. Data Retention and Lifecycle

The history of conversations processed by the Platform is stored for up to 3 (three) months after the last interaction, being automatically deleted after this period, except for legal retention obligations.

In case of contract termination, the Client’s data will be deleted within 30 (thirty) days, except for:

After deletion, data recovery will not be possible.

9.6. Privacy Limitations and Sensitive Data

9.6.1. Positus does not provide the profile picture (avatar) of end users, in compliance with the principle of necessity and data minimization.

9.6.2. The sending, receiving, or processing, through the Platform, of sensitive financial data, including, among others, card numbers, security codes, banking passwords, complete account data, or crypto-asset keys, is expressly prohibited. Non-compliance with this prohibition is the sole responsibility of the Client and its Linked Users, and may constitute a violation of law and Meta’s policies.

9.7. International Data Transfer

The use of the Positus Platform implies an international transfer of personal data, due to Meta’s global infrastructure.

The transfer is based on the execution of the contract, adherence to Meta’s terms, and compliance with Resolution CD/ANPD No. 19/2024, through contractual guarantees and adequate security measures.

It is the Client’s responsibility to inform data subjects about the international transfer and to ensure a valid legal basis, keeping Positus harmless from any resulting liability.

Positus and Meta do not use data for profiling purposes beyond what is strictly necessary for the operation of the service.

9.8. Security Incidents

Positus will notify the Client of security incidents that may pose a relevant risk to data subjects, within 72 (seventy-two) hours of becoming aware of the event, containing the information required by the LGPD.

It will be up to the Client to assess the need for communication to the ANPD and to data subjects. Positus will cooperate in the investigation and mitigation of the incident.

9.9. Data Protection Impact Assessment (DPIA)

When required by legislation or by the ANPD, the preparation of the DPIA will be the Client’s responsibility, and it will be up to Positus to provide technical cooperation, by providing information about the processing carried out under its responsibility as Processor.

10. Guidelines on Rights and Responsibilities for Clients/Contracting Parties

10.1. Client’s Rights

The Client has the following rights within the scope of its contractual relationship with Positus:

10.2. Client’s Obligations

The Client assumes the following essential obligations for the proper functioning of the service:

The Client agrees to hold Positus harmless and to defend it against any complaints, lawsuits, administrative proceedings, sanctions, fines, or losses arising from:

10.3. Express Prohibitions to the Client

The Client is expressly prohibited from:

11. Guidelines on Rights and Responsibilities for Positus

11.1. Positus’ Rights

Positus, as a technological infrastructure provider and BSP authorized by Meta, has the following rights:

11.2. Positus’ Obligations

Positus undertakes to comply with the following obligations for the adequate provision of the service:

11.3. Limitations of Liability

Positus does not guarantee that the Platform will operate in an uninterrupted manner, free of errors, failures, or vulnerabilities, given:

In case of defects or inconsistencies in the operation of the Platform, Positus’ commitment is to undertake commercially reasonable efforts to remedy or remotely correct the failures with Facebook Inc., without guaranteeing resolution within a specified period.

Possible maintenance, updates, or instabilities may occur without prior notice, especially when determined by Meta or necessary for the emergency correction of security flaws.

Positus’ total liability for proven losses and damages, when applicable, is LIMITED to the equivalent of up to 3 (three) times the amount paid by the Client in the 12 (twelve) months prior to the damaging event, not covering loss of profits or indirect damages as provided for in the Licensing Agreement.

11.4. Liability Exclusions

Positus is exempt from any liability in the following cases:

Decisions and restrictions imposed by Meta:

Client infrastructure issues:

Improper use by the Client and linked users:

External events:

Data and history:

Third-party products and services:

12. Guidelines on Rights and Responsibilities for the Linked User

12.1. Nature of Access

The Linked User accesses the Positus Platform exclusively to carry out their professional activities related to the Client company. The use of the Platform must take place strictly within the operational purposes defined by the Client and in accordance with its internal policies.

Access does not grant the User any autonomous right over the Platform, the data shared by the Client, functionalities, or integrations. Usage rights are limited to the permissions assigned by the Client through Positus Studio.

The User’s relationship with the Platform is derived from and subordinate to the contractual relationship between Positus and the Client. Termination of the Licensing Agreement or the User’s departure from the Client company implies automatic cessation of the right of access to the Platform.

The use of the Positus Platform by minors is prohibited, even when accompanied by their legal guardians, under penalty of liability for any damages caused to Positus or third parties.

POSITUS has the right to verify the identity of those who use or register on the website, with the objective of protecting the organization itself from improper use by persons under 18 years of age. It is warned that, in case of verification of document falsification, provided for in the Criminal Code, POSITUS will take the appropriate legal measures.

12.2. Linked User’s Rights

The Linked User has the right to:

12.3. Linked User’s Responsibilities

The Linked User assumes the following obligations when using the Platform:

The User is directly responsible for:

12.4. Express Prohibitions to the Linked User

The User is expressly prohibited from:

12.5. Liability of the Linked User

Inappropriate, negligent, or willful use of the Platform may result in:

Positus may, at the Client’s request or by court order, provide logs and records of the User’s activities for the purposes of investigation, audit, or liability.

13. Final Provisions

13.1. Amendments to the Terms of Use

Positus reserves the right to amend these Terms of Use at any time, in order to adapt to new Platform functionalities, regulatory changes, changes in Meta’s policies, or compliance improvements.

The amendments will be published on the Platform and communicated to the Client and Linked Users through:

The updated version of the Terms of Use will enter into force 30 (thirty) days after publication, except for amendments arising from legal or regulatory requirements, which may have immediate effect.

Continued use of the Platform after the new Terms take effect constitutes tacit acceptance of the new Terms. If the Client or the Linked User does not agree with the amendments, they must immediately cease using the Platform and, in the case of the Client, exercise the right of contractual termination as per the Licensing Agreement.

The current version of these Terms of Use will always be available for consultation in Positus Studio and on the Positus institutional website https://positus.com.br.

13.2. Validity of Provisions

These Terms of Use have an indeterminate validity and may be amended at any time.

If any provision of these Terms of Use is considered invalid, illegal, or unenforceable by a competent judicial or administrative authority, such invalidity will not affect the other provisions, which will remain in full force and effect.

The parties undertake to replace the invalidated provision with another that, to the extent possible, produces equivalent economic and legal effects, respecting the parties’ original intent.

13.3. Data Subject Assistance

Positus, a company within the Robbu Group, has a designated team to handle inquiries on privacy, data protection, and the exercise of data subjects’ rights.

For matters related to personal data, the User or the Client may contact the Data Protection Officer (DPO) of Positus/Robbu through the following channels:

Considering that the Client is the Controller of the data relating to end users and linked users, data subject (user) requests must be directed primarily to the Client.

Positus, as Processor, will cooperate with the Client to the extent possible for compliance with legal obligations related to the rights of data subjects.

13.4. Applicable Law and Jurisdiction

These Terms of Use are governed and interpreted in accordance with the laws of the Federative Republic of Brazil.

The Court of the District of São Paulo/SP is hereby elected as the sole competent forum to resolve any disputes arising from these Terms of Use, with express waiver of any other, however privileged it may be.

13.5. Contact Information

For questions, suggestions, complaints, or requests related to these Terms of Use of the Positus Platform, the following channels are available:

RoleEmail
Compliance Officer (CO)compliance@robbu.com.br
Data Protection Officer (DPO)dpo@robbu.global
Chief Information Security Officer (CISO)dpo@robbu.global

São Paulo/SP, 2026.

POSITUS TECNOLOGIA DA INFORMAÇÃO LTDA. | CNPJ: 34.258.755/0001-02
Robbu Group © 2026 — All rights reserved