Log in See plans →
Back to home

LGPD Art. 39 · GDPR Art. 28

Data Processing Agreement (DPA)

Last updated: June 5, 2026  ·  Version 2.0

🌐

Courtesy translation. Notifiquei is a Brazilian company, and the Portuguese version of this Agreement is the legally binding one. If the two versions ever disagree, the Portuguese text governs — except that nothing here reduces a right that mandatory data protection law grants you. Section 14 contains the clauses required by Article 28 of the GDPR.

📋

Automatic acceptance on subscribing. By creating an account and subscribing to any Notifiquei plan, the Controller declares that it has read, understood and fully agreed to this Data Processing Agreement, which forms an integral part of the Terms of Use. Acceptance is recorded with date, time and IP address at the moment of registration.

1 Parties and definitions

This Agreement is entered into between:

Processor (LGPD, Art. 5, VII)
Notifiquei
CNPJ 59.859.848/0001-13
contato@notifiquei.com.br
Controller (LGPD, Art. 5, VI)
The Customer
The individual or company that subscribes to Notifiquei and determines the purposes and means of processing the data of its own Instagram followers and contacts.

For the purposes of this Agreement, the definitions of Brazil's General Data Protection Law (Law 13.709/2018 — LGPD) apply: Personal Data (any information relating to an identified or identifiable natural person), Processing (any operation performed on personal data), Data Subject (the natural person the data relates to), Sub-processor (a third party that processes data on the Processor's instructions). Where the data is subject to the GDPR, the equivalent definitions in Article 4 of Regulation (EU) 2016/679 apply, and “Processor” and “Controller” have the meanings given there.

2 Subject matter and nature of the processing

Notifiquei acts as Processor for the personal data of third parties (followers, commenters and senders of direct messages on Instagram) who interact with the automations configured by the Controller (the Customer).

The processing carried out by Notifiquei includes:

  • Receiving and processing direct messages (DMs) received by the Controller's profile;
  • Reading and automatically replying to comments on the Controller's posts;
  • Processing story interactions, according to the flows configured by the Controller;
  • Temporarily storing the Instagram user identifiers needed to run the automations;
  • Generating usage reports and statistics for the Controller.

Notifiquei does not determine the purposes of the processing — those are defined exclusively by the Controller when configuring the automation flows.

3 Types of data and categories of data subjects

Type of dataCategory of data subjectSource
Instagram usernameFollowers / visitors to the Controller's profileOfficial Meta API
Unique user identifier (PSID/IGSID)Users who sent a DM or commentedOfficial Meta API
Content of received messagesUsers who started a conversationOfficial Meta API
Content of public commentsUsers who commented on postsOfficial Meta API
Interaction timestampsAll of the aboveOfficial Meta API

No sensitive data (Art. 5, II of the LGPD; Art. 9 of the GDPR) is processed by Notifiquei under this Agreement.

4 Purpose and legal basis

The processing carried out by Notifiquei has as its sole purpose the performance of the service contract entered into with the Controller (Art. 7, V of the LGPD; Art. 6(1)(b) of the GDPR). Notifiquei will not use the data for any other purpose, including its own advertising, AI model training or sharing with unauthorised third parties.

It is the Controller's responsibility to ensure it has an adequate legal basis to collect and process data subjects' data through the Notifiquei platform, including compliance with the Meta Platform policies and the applicable guidance of the ANPD or the relevant European supervisory authority.

5 Duration of the processing

Processing of third-party data (the Controller's followers/contacts) takes place for the duration of the service contract. After the account is closed:

  • Interaction data (message and comment content) is deleted within 30 (thirty) days;
  • Technical identifiers needed for audit purposes are retained for up to 90 (ninety) additional days;
  • Security logs are kept for 6 (six) months, as required by Brazil's Internet Civil Framework.

6 Notifiquei's obligations (Processor)

Notifiquei undertakes to:

  • Process personal data exclusively in accordance with the Controller's documented instructions;
  • Ensure that the persons authorised to process the data are bound by confidentiality obligations;
  • Implement appropriate technical and organisational measures to ensure data security (TLS encryption in transit, role-based access control, audit logs);
  • Notify the Controller within 72 (seventy-two) hours of becoming aware of a security incident involving data processed under this Agreement;
  • Assist the Controller in responding to data subject requests (Art. 18 of the LGPD; Articles 15 to 22 of the GDPR), to the extent technically possible;
  • Assist the Controller in complying with obligations relating to security, breach notification and impact assessments;
  • Delete or return the data to the Controller at the end of the services, in accordance with the periods in section 5;
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this Agreement.

7 The Controller's obligations (Customer)

The Controller undertakes to:

  • Ensure it has an adequate legal basis to use data subjects' data (followers/contacts) through the Notifiquei platform;
  • Use the platform in compliance with the Meta Platform Terms and with the applicable data protection law;
  • Not configure automation flows for unlawful or discriminatory purposes, or in ways that violate data subjects' rights;
  • Respond directly to requests from data subjects exercising their rights in relation to interactions that took place through the platform;
  • Inform Notifiquei immediately of any data subject or authority request affecting data processed under this Agreement;
  • Keep its platform access credentials secure.

8 Sub-processors

Notifiquei uses the following sub-processors for the processing carried out under this Agreement:

Sub-processorPurposeCountry
TurbocloudMain API server (dedicated VPS)Brazil
Amazon Web Services (AWS)Cloud infrastructure, data storage and auxiliary servicesBrazil / USA
Meta Platforms, Inc.Official Instagram API (source of the data)USA
AbacatepayPayment processing (Controller's data)Brazil
StripePayment processing for international subscriptions (Controller's data)USA / Ireland
OpenAI (openai.com)Natural language processing (AI), audio transcription via Whisper, message analysisUSA
Google Cloud / Google LLCMedia storage (images/videos), language models (Gemini)USA
AnthropicLanguage models (Claude) for reply automationsUSA
ResendTransactional email delivery (invitations, password resets, alerts)USA
SupabaseAuthentication, database and media storage (São Paulo datacentre, sa-east-1)Brazil
CaktoPayment processing (Controller's data)Brazil
SentryApplication error and performance monitoringUSA
Apple (APNs) / Google (FCM)Push notification delivery for the mobile appsUSA

General authorisation and liability (GDPR Art. 28(2) and (4)). The Controller grants general written authorisation for the engagement of the sub-processors listed above. Notifiquei imposes on each sub-processor, by contract, the same data protection obligations set out in this Agreement, and remains fully liable to the Controller for those sub-processors' performance of them. Notifiquei will inform the Controller of any material change to the list at least 15 (fifteen) days in advance, save in cases of force majeure; the Controller may object on reasonable grounds in writing to dpa@notifiquei.com.br.

9 Security and incidents

Notifiquei applies the following technical and organisational security measures:

  • Encryption of data in transit (TLS 1.2+);
  • Role-based access control (RBAC) following the principle of least privilege;
  • Access and audit logs retained for 90 days;
  • Periodic security testing;
  • An internal incident response policy.

In the event of a security incident involving data processed under this Agreement, Notifiquei will notify the Controller within 72 (seventy-two) hours, describing the nature of the incident, the categories and estimated number of affected data subjects, and the measures taken or proposed to remedy it.

10 International data transfers

Notifiquei's main API server runs on infrastructure located in Brazil (Turbocloud), and the database, authentication and media storage sit in a Brazilian datacentre (Supabase, São Paulo). Processing may involve transfers to the United States (Meta integration, monitoring, push notifications and AI providers) and, occasionally, to other countries in the case of AI providers and gateways. Those transfers rely on appropriate safeguards (Art. 33 of the LGPD).

Transfers under the GDPR (Chapter V). In 2026 the European Commission and the ANPD recognised the equivalence between the LGPD and the GDPR (mutual adequacy), so data can flow directly between the European Economic Area and Brazil without additional safeguards. For transfers to sub-processors located in countries without an EU adequacy decision (for example, the United States), Notifiquei uses the EU Standard Contractual Clauses (SCCs) or another valid Chapter V mechanism, and the Controller may request the deactivation of the artificial intelligence features that depend on providers located outside an adequate country.

11 Data subject rights

Where a data subject (a follower/contact of the Controller) exercises their rights under Art. 18 of the LGPD or Articles 15 to 22 of the GDPR directly with Notifiquei, we will redirect the request to the Controller within 5 (five) business days, since the Controller is primarily responsible for handling it.

Notifiquei will provide the Controller with technical assistance in handling those requests as far as possible, at no additional cost for up to 5 (five) requests per month.

12 Term, termination and deletion of data

This Agreement remains in force for the entire period of the service subscription. Closure of the account by the Controller or by Notifiquei automatically terminates this Agreement, without prejudice to the confidentiality obligations and the retention periods set out in section 5.

On written request to dpa@notifiquei.com.br, the Controller may ask for the early deletion of third-party data processed under this Agreement, provided there is no legal impediment.

13 Data Protection Officer contact

For matters relating to this Agreement, including data subject rights requests and incident notifications:
Data Protection Officer (DPO): Antonio Duarte
Email: dpa@notifiquei.com.br
Notifiquei — CNPJ 59.859.848/0001-13

14 GDPR-specific clauses (Article 28)

Where the Controller uses the platform to process the personal data of data subjects located in the European Union or the European Economic Area, this Agreement also serves as the processor contract required by Article 28 of Regulation (EU) 2016/679 (GDPR). For that purpose, the Controller is the controller and Notifiquei is the processor, and the following provisions apply, prevailing over the other clauses in case of conflict as regards data subject to the GDPR:

  • Documented instructions (Art. 28(3)(a)): Notifiquei processes the data only on the Controller's documented instructions — which include these Terms, this DPA, and the automations and settings the Controller defines on the platform — including as regards international transfers, unless required by law.
  • Confidentiality (Art. 28(3)(b)): the persons authorised to process the data are bound by a duty of confidentiality.
  • Security (Art. 28(3)(c) and Art. 32): appropriate technical and organisational measures, as set out in section 9.
  • Sub-processors (Art. 28(2) and (4)): general authorisation, imposition of the same obligations and Notifiquei's liability, as set out in section 8.
  • Assistance with data subject rights (Art. 28(3)(e)): Notifiquei assists the Controller in responding to requests to exercise the rights in Articles 15 to 22 of the GDPR (access, rectification, erasure, restriction, objection, portability), as far as technically possible.
  • Support with security, breaches and DPIAs (Art. 28(3)(f), Arts. 33–34 and Art. 35): Notifiquei notifies the Controller without undue delay (and within 72 hours) on becoming aware of a breach, and assists with impact assessments and prior consultations.
  • Deletion or return (Art. 28(3)(g)): at the end of the services, data is deleted or returned in accordance with section 5.
  • Audit (Art. 28(3)(h)): Notifiquei makes available to the Controller the information necessary to demonstrate compliance and allows reasonable audits and inspections, subject to prior notice and confidentiality.
  • International transfers (Chapter V): as set out in section 10 (Brazil–EU adequacy; SCCs for countries without adequacy).

Note: Notifiquei is a company established in Brazil and has not appointed a representative in the EU under Article 27 of the GDPR. EU data subjects and authorities may contact the Data Protection Officer directly at dpa@notifiquei.com.br.

Instagram sales automation on Meta's official API. Built in Brazil, running worldwide.

Product

  • How it works
  • Features
  • Pricing
  • FAQ

Legal

  • Terms of use
  • Privacy
  • Data agreement (DPA)

Contact

  • contato@notifiquei.com.br
  • dpa@notifiquei.com.br
Notifiquei — Meta Business Partner Notifiquei — TikTok Marketing Partner
© 2026 Notifiquei. All rights reserved.  ·  CNPJ 59.859.848/0001-13
All systems operational Official Meta Partner