LGPD Art. 39 · GDPR Art. 28
Data Processing Agreement (DPA)
1 Parties and definitions
This Agreement is entered into between:
contato@notifiquei.com.br
For the purposes of this Agreement, the definitions of Brazil's General Data Protection Law (Law 13.709/2018 — LGPD) apply: Personal Data (any information relating to an identified or identifiable natural person), Processing (any operation performed on personal data), Data Subject (the natural person the data relates to), Sub-processor (a third party that processes data on the Processor's instructions). Where the data is subject to the GDPR, the equivalent definitions in Article 4 of Regulation (EU) 2016/679 apply, and “Processor” and “Controller” have the meanings given there.
2 Subject matter and nature of the processing
Notifiquei acts as Processor for the personal data of third parties (followers, commenters and senders of direct messages on Instagram) who interact with the automations configured by the Controller (the Customer).
The processing carried out by Notifiquei includes:
- Receiving and processing direct messages (DMs) received by the Controller's profile;
- Reading and automatically replying to comments on the Controller's posts;
- Processing story interactions, according to the flows configured by the Controller;
- Temporarily storing the Instagram user identifiers needed to run the automations;
- Generating usage reports and statistics for the Controller.
Notifiquei does not determine the purposes of the processing — those are defined exclusively by the Controller when configuring the automation flows.
3 Types of data and categories of data subjects
| Type of data | Category of data subject | Source |
|---|---|---|
| Instagram username | Followers / visitors to the Controller's profile | Official Meta API |
| Unique user identifier (PSID/IGSID) | Users who sent a DM or commented | Official Meta API |
| Content of received messages | Users who started a conversation | Official Meta API |
| Content of public comments | Users who commented on posts | Official Meta API |
| Interaction timestamps | All of the above | Official Meta API |
No sensitive data (Art. 5, II of the LGPD; Art. 9 of the GDPR) is processed by Notifiquei under this Agreement.
4 Purpose and legal basis
The processing carried out by Notifiquei has as its sole purpose the performance of the service contract entered into with the Controller (Art. 7, V of the LGPD; Art. 6(1)(b) of the GDPR). Notifiquei will not use the data for any other purpose, including its own advertising, AI model training or sharing with unauthorised third parties.
It is the Controller's responsibility to ensure it has an adequate legal basis to collect and process data subjects' data through the Notifiquei platform, including compliance with the Meta Platform policies and the applicable guidance of the ANPD or the relevant European supervisory authority.
5 Duration of the processing
Processing of third-party data (the Controller's followers/contacts) takes place for the duration of the service contract. After the account is closed:
- Interaction data (message and comment content) is deleted within 30 (thirty) days;
- Technical identifiers needed for audit purposes are retained for up to 90 (ninety) additional days;
- Security logs are kept for 6 (six) months, as required by Brazil's Internet Civil Framework.
6 Notifiquei's obligations (Processor)
Notifiquei undertakes to:
- Process personal data exclusively in accordance with the Controller's documented instructions;
- Ensure that the persons authorised to process the data are bound by confidentiality obligations;
- Implement appropriate technical and organisational measures to ensure data security (TLS encryption in transit, role-based access control, audit logs);
- Notify the Controller within 72 (seventy-two) hours of becoming aware of a security incident involving data processed under this Agreement;
- Assist the Controller in responding to data subject requests (Art. 18 of the LGPD; Articles 15 to 22 of the GDPR), to the extent technically possible;
- Assist the Controller in complying with obligations relating to security, breach notification and impact assessments;
- Delete or return the data to the Controller at the end of the services, in accordance with the periods in section 5;
- Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this Agreement.
7 The Controller's obligations (Customer)
The Controller undertakes to:
- Ensure it has an adequate legal basis to use data subjects' data (followers/contacts) through the Notifiquei platform;
- Use the platform in compliance with the Meta Platform Terms and with the applicable data protection law;
- Not configure automation flows for unlawful or discriminatory purposes, or in ways that violate data subjects' rights;
- Respond directly to requests from data subjects exercising their rights in relation to interactions that took place through the platform;
- Inform Notifiquei immediately of any data subject or authority request affecting data processed under this Agreement;
- Keep its platform access credentials secure.
8 Sub-processors
Notifiquei uses the following sub-processors for the processing carried out under this Agreement:
| Sub-processor | Purpose | Country |
|---|---|---|
| Turbocloud | Main API server (dedicated VPS) | Brazil |
| Amazon Web Services (AWS) | Cloud infrastructure, data storage and auxiliary services | Brazil / USA |
| Meta Platforms, Inc. | Official Instagram API (source of the data) | USA |
| Abacatepay | Payment processing (Controller's data) | Brazil |
| Stripe | Payment processing for international subscriptions (Controller's data) | USA / Ireland |
| OpenAI (openai.com) | Natural language processing (AI), audio transcription via Whisper, message analysis | USA |
| Google Cloud / Google LLC | Media storage (images/videos), language models (Gemini) | USA |
| Anthropic | Language models (Claude) for reply automations | USA |
| Resend | Transactional email delivery (invitations, password resets, alerts) | USA |
| Supabase | Authentication, database and media storage (São Paulo datacentre, sa-east-1) | Brazil |
| Cakto | Payment processing (Controller's data) | Brazil |
| Sentry | Application error and performance monitoring | USA |
| Apple (APNs) / Google (FCM) | Push notification delivery for the mobile apps | USA |
General authorisation and liability (GDPR Art. 28(2) and (4)). The Controller grants general written authorisation for the engagement of the sub-processors listed above. Notifiquei imposes on each sub-processor, by contract, the same data protection obligations set out in this Agreement, and remains fully liable to the Controller for those sub-processors' performance of them. Notifiquei will inform the Controller of any material change to the list at least 15 (fifteen) days in advance, save in cases of force majeure; the Controller may object on reasonable grounds in writing to dpa@notifiquei.com.br.
9 Security and incidents
Notifiquei applies the following technical and organisational security measures:
- Encryption of data in transit (TLS 1.2+);
- Role-based access control (RBAC) following the principle of least privilege;
- Access and audit logs retained for 90 days;
- Periodic security testing;
- An internal incident response policy.
In the event of a security incident involving data processed under this Agreement, Notifiquei will notify the Controller within 72 (seventy-two) hours, describing the nature of the incident, the categories and estimated number of affected data subjects, and the measures taken or proposed to remedy it.
10 International data transfers
Notifiquei's main API server runs on infrastructure located in Brazil (Turbocloud), and the database, authentication and media storage sit in a Brazilian datacentre (Supabase, São Paulo). Processing may involve transfers to the United States (Meta integration, monitoring, push notifications and AI providers) and, occasionally, to other countries in the case of AI providers and gateways. Those transfers rely on appropriate safeguards (Art. 33 of the LGPD).
Transfers under the GDPR (Chapter V). In 2026 the European Commission and the ANPD recognised the equivalence between the LGPD and the GDPR (mutual adequacy), so data can flow directly between the European Economic Area and Brazil without additional safeguards. For transfers to sub-processors located in countries without an EU adequacy decision (for example, the United States), Notifiquei uses the EU Standard Contractual Clauses (SCCs) or another valid Chapter V mechanism, and the Controller may request the deactivation of the artificial intelligence features that depend on providers located outside an adequate country.
11 Data subject rights
Where a data subject (a follower/contact of the Controller) exercises their rights under Art. 18 of the LGPD or Articles 15 to 22 of the GDPR directly with Notifiquei, we will redirect the request to the Controller within 5 (five) business days, since the Controller is primarily responsible for handling it.
Notifiquei will provide the Controller with technical assistance in handling those requests as far as possible, at no additional cost for up to 5 (five) requests per month.
12 Term, termination and deletion of data
This Agreement remains in force for the entire period of the service subscription. Closure of the account by the Controller or by Notifiquei automatically terminates this Agreement, without prejudice to the confidentiality obligations and the retention periods set out in section 5.
On written request to dpa@notifiquei.com.br, the Controller may ask for the early deletion of third-party data processed under this Agreement, provided there is no legal impediment.
13 Data Protection Officer contact
For matters relating to this Agreement, including data subject rights requests and incident notifications:
Data Protection Officer (DPO): Antonio Duarte
Email: dpa@notifiquei.com.br
Notifiquei — CNPJ 59.859.848/0001-13
14 GDPR-specific clauses (Article 28)
Where the Controller uses the platform to process the personal data of data subjects located in the European Union or the European Economic Area, this Agreement also serves as the processor contract required by Article 28 of Regulation (EU) 2016/679 (GDPR). For that purpose, the Controller is the controller and Notifiquei is the processor, and the following provisions apply, prevailing over the other clauses in case of conflict as regards data subject to the GDPR:
- Documented instructions (Art. 28(3)(a)): Notifiquei processes the data only on the Controller's documented instructions — which include these Terms, this DPA, and the automations and settings the Controller defines on the platform — including as regards international transfers, unless required by law.
- Confidentiality (Art. 28(3)(b)): the persons authorised to process the data are bound by a duty of confidentiality.
- Security (Art. 28(3)(c) and Art. 32): appropriate technical and organisational measures, as set out in section 9.
- Sub-processors (Art. 28(2) and (4)): general authorisation, imposition of the same obligations and Notifiquei's liability, as set out in section 8.
- Assistance with data subject rights (Art. 28(3)(e)): Notifiquei assists the Controller in responding to requests to exercise the rights in Articles 15 to 22 of the GDPR (access, rectification, erasure, restriction, objection, portability), as far as technically possible.
- Support with security, breaches and DPIAs (Art. 28(3)(f), Arts. 33–34 and Art. 35): Notifiquei notifies the Controller without undue delay (and within 72 hours) on becoming aware of a breach, and assists with impact assessments and prior consultations.
- Deletion or return (Art. 28(3)(g)): at the end of the services, data is deleted or returned in accordance with section 5.
- Audit (Art. 28(3)(h)): Notifiquei makes available to the Controller the information necessary to demonstrate compliance and allows reasonable audits and inspections, subject to prior notice and confidentiality.
- International transfers (Chapter V): as set out in section 10 (Brazil–EU adequacy; SCCs for countries without adequacy).
Note: Notifiquei is a company established in Brazil and has not appointed a representative in the EU under Article 27 of the GDPR. EU data subjects and authorities may contact the Data Protection Officer directly at dpa@notifiquei.com.br.