Fieli Flow Privacy Policy
This English version is provided for convenience; the Portuguese version prevails.
Fieli Flow automates WhatsApp and e-mail communications, with artificial intelligence and a signed audit trail the customer can verify. The product is in Beta. This policy explains how we process personal data in Flow, under Brazil’s General Data Protection Law (LGPD, Law No. 13,709/2018).
Fieli Tecnologia LtdaCNPJ 67.265.180/0001-04
Rua Angelita Oliveira de Souza, 111 · Centro · Delmiro Gouveia/AL · CEP 57480-000, Brazil
(82) 99817-4910 · WhatsApp · contato@fieli.app
Our two roles
In Flow, Fieli acts in two ways, and this changes who is responsible for each piece of data (LGPD, art. 5, VI and VII):
- As controller, we decide about the customer account data: who the users are, how they sign in, how we provide support.
- As processor, we process the data of the customer’s contacts — the people the customer sends messages to — only on the customer’s instructions. In this case the customer is the controller: the customer defines the purpose, the legal basis and the retention period, and answers data subjects first.
Data we process as controller
| Operation | Data subjects | Data | Purpose | Legal basis | Fieli's role | Retention |
|---|---|---|---|---|---|---|
| Customer account | customer users | name, e-mail, credentials, session and security logs | create and maintain the account, authenticate and provide support | performance of a contract (art. 7, V) | controller | while the account exists; deleted or anonymized within 90 days after closure, except access logs (6 months) and a minimal record of the contract (5 years, to exercise legal rights) |
Data we process as processor
| Operation | Data subjects | Data | Purpose | Legal basis | Fieli's role | Retention |
|---|---|---|---|---|---|---|
| Customer contacts | contacts of Flow customers | name, phone, e-mail and, if provided by the customer, CPF or CNPJ | send the communications configured by the customer | defined by the customer, who is the controller | processor | while the customer keeps the contact; deletion upon data subject request |
| Consent log | contacts of Flow customers | date, source and content of consent or refusal | prove each send had consent and honor opt-outs | legal obligation and exercise of rights (art. 7, II and VI) | processor | kept even after the contact is deleted, as evidence, during the contract; handed over to the customer at closure |
| Messages | contacts of Flow customers | WhatsApp and e-mail message content | send, receive and record conversations | defined by the customer, who is the controller | processor | while the account is active, following the customer's instructions, who may delete them at any time; after closure, 30 days for export and deletion within 90 days, including backups |
| Link clicks | contacts of Flow customers | click and browser used, without IP address | measure the customer's campaign results | defined by the customer, who is the controller | processor | 12 months |
| Signed audit trail | contacts and users | chained record of each send and decision, with a signed root | let the customer prove what was done | exercise of rights (art. 7, VI) | processor | during the contract, handed over to the customer at closure; afterwards, only signed metadata (date, event type, pseudonymized identifiers and hashes, no message content) for 5 years, to exercise legal rights |
If you receive messages from a company that uses Flow, contact that company first: it decides about your data. If you contact us, we will forward the request to it and support it in handling the request (LGPD, art. 18, §6, and art. 39).
Artificial intelligence
- Providers
- Anthropic, OpenAI, Google (Gemini)
- What it does
- build journeys from text, answer from the customer's knowledge base and classify conversation intent
- Pseudonymization
- a personal-data redactor runs on our infrastructure before every call; if it fails, the model is not called
- Training
- prohibited: customer data is not used to train models
- Human review
- when it does not know the answer, the AI hands the conversation to a person
Data sent to AI providers is not used to train models, and providers are contracted without retention for training. The AI does not make decisions with legal effects on people: when it is not sure, it hands the conversation back to a person (LGPD, art. 20).
Signed audit trail
Every send goes through automatic checks — such as consent, opt-out requests and time windows — and each decision becomes a chained record with a digitally signed root. This record lets the customer prove, months later, that a message had consent (LGPD, arts. 8, §2, and 37).
Connected platforms
Flow connects to the platforms below only when the customer chooses to. Use of each one is also subject to that platform’s own terms.
Meta (Facebook, Instagram and WhatsApp Business Platform)
- What we access
- Page and professional account IDs and names, access tokens, content you choose to publish, comments and basic insights; for WhatsApp, the business phone number, message templates and messages exchanged through the WhatsApp Business Platform.
- What for
- Only to publish, send and show results of what you configured in the product.
- Sharing
- We do not sell this data, do not use it for advertising and do not share it without your consent.
- Retention
- While the account is connected; tokens and cached data are deleted when you disconnect or request deletion.
- How to revoke
- Remove the app in Facebook Settings > Apps and websites or Instagram Settings > Apps and websites, and see the Data Deletion page (/en/data-deletion).
Subprocessors and international transfers
| Provider | Role | Data | Country | Transfer basis | Status |
|---|---|---|---|---|---|
| Magalu Cloud Ltda. | hosting and database | all service data | Brazil | — | in use |
| Cloudflare, Inc. | network edge: TLS, caching and attack protection | connection metadata (IP, host, page address) | United States and others | LGPD art. 33: provider's contractual clauses; adoption of the ANPD standard contractual clauses (ANPD Resolution No. 19/2024) in progress | in use |
| netcup GmbH | e-mail server for the fieli.app domain | e-mail messages sent and received | Germany | art. 33, I: European Union recognized as adequate (ANPD Resolution No. 32/2026) | in use |
| Backblaze, Inc. (B2) | encrypted backups | encrypted database backups | United States | LGPD art. 33: provider's contractual clauses; adoption of the ANPD standard clauses in progress | in use |
| Anthropic, OpenAI, Google (Gemini) | artificial intelligence models | pseudonymized text only: personal data is replaced before sending | United States | the provider's contractual clauses, with adoption of the ANPD standard clauses in progress | in use |
| Meta Platforms (WhatsApp Business Platform) | sending and receiving WhatsApp messages through the official API | phone number, profile name and message content | United States and others (Meta infrastructure) | art. 33, II, b: standard contractual clauses, through the WhatsApp Business Data Transfer Addendum | in use |
Our main hosting is in Brazil. Personal data leaves the country only in the situations disclosedon this page: network edge, e-mail, channels chosen by the customer, artificial intelligence providers and providers still being migrated, always with the basis for each transfer.
In Flow this happens at the network edge, when sending e-mails and messages through the platforms chosen by the customer, in encrypted backups and when using AI with pseudonymized data. Each transfer relies on article 33 of the LGPD. The full text of the applicable clauses can be requested from the Data Protection Officer and will be sent within 15 days (ANPD Resolution No. 19/2024, art. 17).
Product cookies
The Flow dashboard uses essential cookies only:
| Name | Purpose | Essential |
|---|---|---|
sessão | keep you signed in to the dashboard | Yes |
idioma | remember the chosen language | Yes |
2FA | two-step verification | Yes |
Retention and deletion
The retention period for each type of data is in the tables above. In short, after the account is closed the customer has 30 days to export its data; after that, the data is deleted within 90 days, including backups. Consent records and the audit trail are handed over to the customer at closure; Fieli keeps only the signed metadata, without message content, for 5 years, solely to exercise legal rights.
- How to delete
- the customer deletes contacts in the dashboard; data subjects ask the customer or the DPO
- Deadline
- within 15 days
- What we keep by law
- access logs for 6 months (Brazilian Internet Civil Framework, art. 15) and data needed to comply with legal obligations or to exercise rights (LGPD, art. 16)
The full step-by-step is on the data deletion page.
Security
- encrypted connections (TLS) everywhere
- personal-data vault with AES-256-GCM encryption and per-customer keys
- per-customer data isolation in the database (row-level security)
- chained audit trail with a signed root
Incidents
If a security incident affects data processed on behalf of a customer, we notify the customer without undue delay, within 48 hours after becoming aware of it, so the customer can meet its own obligations. Where we are the controller, we notify the ANPD and the affected people within 3 business days (ANPD Resolution No. 15/2024).
Your rights
Data subjects have the rights of article 18 of the LGPD: confirmation, access, correction, anonymization, blocking or deletion, portability, information about sharing, information about consent and its withdrawal. We reply within 15 days (art. 19). You may also file a petition with Brazil’s National Data Protection Agency (ANPD). Details are in the Privacy Policy.
Data Protection Officer
José Tenório Abs Jr. · dpo@fieli.app
Channel for data subjects and for Brazil's National Data Protection Agency (ANPD).
Changes
Changes to this policy are published here, with a new version and effective date. Relevant changes are notified to customers 30 days in advance, except where required by law or for security reasons.