Legal
Privacy Policy
1 Who controls your data
Notifiquei (CNPJ 59.859.848/0001-13) is the controller of the personal data processed by this platform, under Brazil's General Data Protection Law (Law 13.709/2018 β LGPD).
For questions, requests or to exercise your rights regarding personal data, write to: contato@notifiquei.com.br.
Data Protection Officer (DPO): Antonio Duarte
Email: dpa@notifiquei.com.br
This is the official channel for data subject rights requests, privacy questions and communications with Brazil's National Data Protection Authority (ANPD).
Dual role (controller and processor): Notifiquei is the controller of our own customers' data (account holders β name, email, phone, billing). For the personal data that you, as a customer, process through the platform about your own audience (for example, the content of messages and comments from people who interact with your Instagram), Notifiquei acts as a processor: you are the controller of that data and we process it on your instructions, under our Data Processing Agreement (DPA).
Users and data subjects in the European Union: when the platform is used to communicate with people located in the European Union or the European Economic Area, the General Data Protection Regulation (GDPR β Regulation (EU) 2016/679) also applies. See section 14 for the GDPR-specific details.
2 What data we collect
Registration data: full name, email address, phone number (when provided) and billing data (name, tax identification number and address).
Platform access and usage data: IP address, device/browser information, logs of actions performed on the platform, and the automation settings you create.
Data linked to the Instagram (Meta) API: the access token for your Instagram account, the account identifiers you yourself authorise, and logs of automated interactions carried out on your behalf, as permitted by Meta's policies.
We do not collect sensitive data such as health data, biometrics, religious beliefs or sexual orientation.
3 Why we use your data (purpose and legal basis)
We process your data for the following purposes and on the following legal bases, under Article 7 of the LGPD:
| Purpose | Legal basis (LGPD) |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 7, V) |
| Providing the automation features | Performance of a contract (Art. 7, V) |
| Processing payments | Performance of a contract (Art. 7, V) |
| Technical support and customer service | Performance of a contract (Art. 7, V) |
| Complying with tax and legal obligations | Legal obligation (Art. 7, II) |
| Improving and developing the platform | Legitimate interest (Art. 7, IX) |
| Marketing and product news | Consent (Art. 7, I) β opt-in |
| Fraud prevention and security | Legitimate interest (Art. 7, IX) |
If you are in the EU/EEA, the equivalent GDPR bases are Article 6(1)(b) for contract performance, Article 6(1)(c) for legal obligations, Article 6(1)(f) for legitimate interests and Article 6(1)(a) for marketing consent.
Your data will not be used for purposes incompatible with those listed above.
4 How long we keep your data
- Registration and usage data: kept for the duration of the contract and for up to 5 (five) years after the account is closed, to comply with legal and tax obligations.
- Access logs: kept for 6 (six) months, as required by Brazil's Internet Civil Framework (Law 12.965/2014).
- Payment data: kept for the period required by applicable tax and financial law.
- Meta API access tokens: kept only while the authorisation you granted remains valid. Once you revoke it or close your account, the tokens are removed.
- Instagram messages and conversations: the content of messages processed by the platform is retained while the account is active. After the account is closed, message content is deleted within 30 (thirty) days. Technical identifiers associated with conversations may be kept for up to 90 (ninety) additional days for audit and security purposes.
After those periods, data is irreversibly deleted or anonymised.
5 Who we share your data with
We do not sell personal data. We may share data with:
- Payment processors β Stripe for international subscriptions, and Abacatepay or similar for Brazilian ones β receiving only the data needed for the transaction.
- Infrastructure and hosting providers: our infrastructure runs on Amazon Web Services (AWS) and Google Cloud Platform, both with datacentres in Brazil and the United States, plus Turbocloud (a Brazilian provider) for the main API server. Auxiliary messaging, queue and cache services may process data outside Brazil, with appropriate safeguards under Article 33 of the LGPD.
- Email and communication providers for notifications and support.
- Meta Platforms, Inc. β data linked to Instagram is transmitted solely to operate the automations you authorised, under the Meta Platform Terms.
- Public authorities β when required by law, court order or regulatory demand.
6 International data transfers
Our infrastructure runs on Amazon Web Services (AWS) and Google Cloud Platform, both with datacentres in Brazil and the United States, plus Turbocloud (a Brazilian provider) for the main API server. Auxiliary services β such as message queues, cache and communications β may process data on servers outside Brazil. When that happens, we apply the safeguards set out in Article 33 of the LGPD, verifying that the destination country offers an adequate level of protection or that contractual clauses guarantee the protection of the transferred data.
Transfers between Brazil and the European Union: in 2026 the European Commission and the ANPD recognised the equivalence between the LGPD and the GDPR (mutual adequacy decision). As a result, personal data can flow directly between Brazil and the European Economic Area without additional contractual clauses. For transfers to providers located in countries without an adequacy decision (for example, technology or AI providers in the United States or elsewhere), we use appropriate contractual safeguards β such as the EU Standard Contractual Clauses β under Chapter V of the GDPR and Article 33 of the LGPD. The list of sub-processors is in our DPA.
7 Your rights as a data subject
Under Article 18 of the LGPD, you have the following rights over your personal data:
- Confirmation: to know whether we process your personal data;
- Access: to obtain a copy of the data we hold about you;
- Correction: to have incomplete, inaccurate or out-of-date data corrected;
- Anonymisation, blocking or deletion: to have unnecessary or excessive data anonymised, blocked or deleted;
- Portability: to receive your data in a structured format for use with another provider, where technically feasible;
- Erasure: to have data processed on the basis of consent deleted, except where retention is required by law;
- Information about sharing: to know which entities we share your data with;
- Information about refusing consent: to be told the consequences of not giving consent;
- Withdrawal of consent: to withdraw consent previously given, at any time and free of charge.
To exercise any of these rights, send a request to dpa@notifiquei.com.br. We respond within 15 (fifteen) business days, as required by the LGPD.
If our response is not satisfactory, you may complain to Brazil's National Data Protection Authority (ANPD), under Article 18, Β§1 of the LGPD, through the portal: gov.br/anpd.
If you are in the European Union or the EEA, the GDPR gives you the rights of access, rectification, erasure (βright to be forgottenβ), restriction of and objection to processing, portability, and the right not to be subject to solely automated decisions (Articles 15 to 22). Exercise them at dpa@notifiquei.com.br; we respond within one month, as required by Article 12(3) of the GDPR. You may also complain to the data protection authority in your country. Where your data is processed by a business that uses Notifiquei (for example, when you message a business's Instagram), that business is the controller β we will forward your request to it and assist in handling it, as described in section 14.
8 Cookies and tracking technologies
We use cookies and similar technologies to keep you signed in to the platform (essential cookies), to analyse usage and improve the experience (analytics cookies) and to remember your settings (functional cookies).
You can manage cookie preferences in your browser settings. Disabling essential cookies may prevent the platform from working correctly.
9 Data security
We apply technical and organisational measures to protect your data against unauthorised access, including encryption in transit (TLS/HTTPS), role-based access control, access monitoring and periodic security reviews.
In the event of a security incident that may create relevant risk or harm to data subjects, we will notify Brazil's National Data Protection Authority (ANPD) and the affected data subjects under Article 48 of the LGPD, within 72 (seventy-two) hours of becoming aware of the incident. For data subject to the GDPR, notification follows Articles 33 and 34 within the same 72-hour deadline.
10 Use of Artificial Intelligence
Notifiquei uses artificial intelligence models supplied by third parties β including OpenAI, Google and Anthropic β to provide features such as automated replies, purchase intent analysis and audio message transcription. To do so, the content of messages received by the Instagram accounts connected to the platform may be processed by those services.
Processing is automated, without human review by Notifiquei, and is subject to each provider's privacy policy. Data sent to the AI models is not used to train those models, under the agreements we hold with each provider.
11 Children's data
Our platform is intended exclusively for companies and individuals over 18 years of age. We do not knowingly collect data from minors. If we identify that a minor's data has been provided without proper consent, we will delete that information immediately.
12 Changes to this Policy
This Policy may be updated from time to time. When changes are material, we will notify you by email or by a visible notice on the platform at least 10 (ten) days before they take effect.
13 Contact and privacy channel
For questions, requests or complaints about privacy and data protection:
Email: contato@notifiquei.com.br
Notifiquei β CNPJ 59.859.848/0001-13
Response time: up to 15 (fifteen) business days.
14 Users and data subjects in the European Union (GDPR)
This section supplements the Policy for data subjects located in the European Union (EU) and the European Economic Area (EEA), to whom Regulation (EU) 2016/679 (GDPR) applies.
When the GDPR applies. The GDPR applies when data about people located in the EU/EEA is processed in the context of offering goods or services to them or monitoring their behaviour β for example, when a Notifiquei customer uses the platform to communicate with followers or customers located in the EU.
Roles. For end-customer data (the people who interact with our customer's account), the Notifiquei customer is the controller and Notifiquei is the processor, processing data only on the customer's instructions and under our Data Processing Agreement (DPA), which forms part of the Terms of Use and is accepted automatically by using the platform.
Legal basis (GDPR Article 6). Processing relies on performance of the contract (Art. 6(1)(b)), legitimate interest for security, fraud prevention and service improvement (Art. 6(1)(f)), and consent for marketing communications (Art. 6(1)(a)). It is for the customer-controller to ensure an appropriate legal basis for communicating with its own audience.
Sub-processors and international transfers. The list of sub-processors and the transfer safeguards are in our DPA. Transfers between Brazil and the EU are covered by the 2026 mutual adequacy decision; transfers to countries without adequacy rely on Standard Contractual Clauses.
Contact in the absence of an EU Representative (GDPR Article 27). Notifiquei is established in Brazil and has not, at this time, appointed a representative in the European Union under Article 27. EU/EEA data subjects and supervisory authorities may contact our Data Protection Officer directly at dpa@notifiquei.com.br, who will handle GDPR-related requests.
Rights and complaints. Data subjects in the EU/EEA may exercise the rights in Articles 15 to 22 of the GDPR and lodge a complaint with the supervisory authority of their Member State. In the event of a data breach, we will notify without undue delay under Articles 33 and 34.