Fieli Posts Privacy Policy
This English version is provided for convenience; the Portuguese version prevails.
Fieli Posts helps agencies and businesses keep their social media up to date: the weekly content plan is suggested with artificial intelligence in each brand’s voice, the client approves it on WhatsApp and Posts publishes to the connected networks, only through each platform’s official APIs and always after a person has reviewed it. The product is in Beta.
Fieli Tecnologia LtdaCNPJ 67.265.180/0001-04
Rua Angelita Oliveira de Souza, 111 · Centro · Delmiro Gouveia/AL · CEP 57480-000, Brazil
(82) 99817-4910 · WhatsApp · contato@fieli.app
Our two roles
- As controller, we process the agency’s or business’s account data: users, sign-in and support.
- As processor, we process connected social accounts, brand content and approver data only on the customer’s instructions; the customer is the controller of this data.
Data we process as controller
| Operation | Data subjects | Data | Purpose | Legal basis | Fieli's role | Retention |
|---|---|---|---|---|---|---|
| Customer account | customer users | name, e-mail, credentials, session and security logs | create and maintain the account, authenticate and provide support | performance of a contract (art. 7, V) | controller | while the account exists; deleted or anonymized within 90 days after closure, except access logs (6 months) and a minimal record of the contract (5 years, to exercise legal rights) |
Data we process as processor
| Operation | Data subjects | Data | Purpose | Legal basis | Fieli's role | Retention |
|---|---|---|---|---|---|---|
| Connected social accounts | connected brands and profiles | identifiers, profile name and image, access tokens, pages and channels | publish approved content and show results | defined by the customer, who is the controller | processor | while the account is connected; YouTube: refreshed or deleted within 30 days; LinkedIn: deleted within 10 days after disconnection |
| Content and metrics | client brands | posts, media, captions and engagement metrics | plan, publish and report | defined by the customer, who is the controller | processor | while the account is active; after closure, 30 days for export and deletion within 90 days |
| WhatsApp approvals | approvers named by the customer | name, phone, decision and comment | collect approval before publishing | defined by the customer, who is the controller | processor | while the customer account exists |
Data from third-party platforms
Posts only accesses a social network when the customer connects the account, and only requests the permissions needed to publish approved content and show results. We do not sell platform data, do not use it for advertising, do not share it with third parties without consent and do not use it to train artificial intelligence models. Each platform has its own rules, described below.
Google and YouTube
Fieli Posts's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is not used to develop, improve, or train generalized or foundation AI/ML models.
Fieli Posts uses YouTube API Services. By connecting a YouTube channel you agree to the YouTube Terms of Service (https://www.youtube.com/t/terms); Google's handling of your data is described in the Google Privacy Policy (https://policies.google.com/privacy).
- What we access
- Channel ID and name, profile image, videos you choose to publish and their metadata, and basic analytics for published videos.
- What for
- Only to publish the content you or your client approved and to show you its results.
- Sharing
- We do not sell this data, do not use it for advertising and do not share it without your consent.
- Retention
- YouTube data is refreshed or deleted within 30 days; a deletion request is completed within 7 days.
- How to revoke
- Disconnect the channel in the product, or revoke access at https://myaccount.google.com/permissions.
Meta (Facebook, Instagram and WhatsApp Business Platform)
- What we access
- Page and professional account IDs and names, access tokens, content you choose to publish, comments and basic insights; for WhatsApp, the business phone number, message templates and messages exchanged through the WhatsApp Business Platform.
- What for
- Only to publish, send and show results of what you configured in the product.
- Sharing
- We do not sell this data, do not use it for advertising and do not share it without your consent.
- Retention
- While the account is connected; tokens and cached data are deleted when you disconnect or request deletion.
- How to revoke
- Remove the app in Facebook Settings > Apps and websites or Instagram Settings > Apps and websites, and see the Data Deletion page (/en/data-deletion).
TikTok
- What we access
- Open ID, display name and avatar, access tokens and videos you choose to publish, with their status.
- What for
- Only to publish content you or your client approved.
- Sharing
- We do not sell this data, do not use it for advertising and do not share it without your consent.
- Retention
- While the account is connected; deleted when you disconnect or the relationship ends.
- How to revoke
- Disconnect in the product or remove the app in TikTok Settings and privacy > Security > Manage app permissions.
- What we access
- Organization page ID and name, access tokens, posts you choose to publish and their comments and basic analytics.
- What for
- Only to publish content and show results. Fieli is not a LinkedIn partner.
- Sharing
- We do not sell this data, do not use it for advertising and do not share it without your consent.
- Retention
- Deleted within 10 days after you disconnect, the relationship ends or you request deletion.
- How to revoke
- Disconnect in the product or remove the app in LinkedIn Settings > Data privacy > Permitted services.
Available networks depend on each platform’s approval. A network is only offered in the product after Fieli’s app has been approved by it.
Approval via WhatsApp
Drafts are sent to the approver named by the customer through the WhatsApp Business Platform, Meta’s official API. We process the approver’s name, phone number, decision and comment only to record the approval before publishing. Nothing is published without that approval.
Artificial intelligence
- Providers
- OpenAI, Anthropic, Google (Gemini)
- What it does
- suggest the content plan and draft posts in each brand's voice
- Pseudonymization
- personal data is removed or replaced before being sent to the model
- Training
- prohibited: customer data is not used to train models
- Human review
- nothing is published without a person's approval
Content suggested by the AI is always reviewed and approved by a person before publication. Data received from platforms is not used to train models.
Subprocessors and international transfers
| Provider | Role | Data | Country | Transfer basis | Status |
|---|---|---|---|---|---|
| Magalu Cloud Ltda. | hosting and database | all service data | Brazil | — | being onboarded |
| Cloudflare, Inc. | network edge: TLS, caching and attack protection | connection metadata (IP, host, page address) | United States and others | LGPD art. 33: provider's contractual clauses; adoption of the ANPD standard contractual clauses (ANPD Resolution No. 19/2024) in progress | in use |
| Meta Platforms (WhatsApp Business Platform) | sending and receiving WhatsApp messages through the official API | phone number, profile name and message content | United States and others (Meta infrastructure) | art. 33, II, b: standard contractual clauses, through the WhatsApp Business Data Transfer Addendum | being onboarded |
| Meta Platforms (Facebook e Instagram) | publishing through the official APIs | published content and metrics | United States and others | art. 33, inherent to the channel chosen by the customer | being onboarded |
| Google LLC (YouTube) | publishing through the YouTube Data API | published videos, metadata and metrics | United States and others | art. 33, inherent to the channel chosen by the customer | being onboarded |
| TikTok (ByteDance) | publishing through the Content Posting API | published videos and status | United States and others | art. 33, inherent to the channel chosen by the customer | being onboarded |
| LinkedIn Corporation | publishing through the Community Management API | published posts, comments and metrics | United States and others | art. 33, inherent to the channel chosen by the customer | being onboarded |
| Provedores de IA generativa / Generative AI providers | artificial intelligence models | pseudonymized text only: personal data is replaced before sending | United States | the provider's contractual clauses, with adoption of the ANPD standard clauses in progress | in use |
Our main hosting is in Brazil. Personal data leaves the country only in the situations disclosedon this page: network edge, e-mail, channels chosen by the customer, artificial intelligence providers and providers still being migrated, always with the basis for each transfer.
Publishing on a social network, by definition, delivers the content to that network’s infrastructure outside Brazil, under its terms. The full text of the applicable clauses can be requested from the Data Protection Officer and will be sent within 15 days (ANPD Resolution No. 19/2024, art. 17).
Retention and deletion
- How to delete
- disconnect the social account in the product or ask the DPO
- Deadline
- within 15 days; YouTube within 7 days; LinkedIn within 10 days
- What we keep by law
- access logs for 6 months (Brazilian Internet Civil Framework, art. 15) and data needed to comply with legal obligations or to exercise rights (LGPD, art. 16)
When you disconnect a social account, its access tokens are revoked and deleted. After the customer account is closed, the customer has 30 days to export the data; it is then deleted within 90 days. The step-by-step for each platform is on the data deletion page.
Cookies
| Name | Purpose | Essential |
|---|---|---|
sessão | keep you signed in | Yes |
Posts uses no advertising cookies and does not allow third parties to serve content or ads inside the product.
Security
- encrypted connections (TLS) everywhere
- access tokens encrypted with managed keys and per-customer isolation
If an incident affects data processed on behalf of a customer, we notify the customer within 48 hours after becoming aware of it. Where we are the controller, we notify the ANPD and the affected people within 3 business days (ANPD Resolution No. 15/2024).
Your rights
Data subjects have the rights of article 18 of the LGPD and may exercise them through the Data Protection Officer, with a reply within 15 days, and may also petition Brazil’s National Data Protection Agency (ANPD). Questions or complaints about the use of platform data can also be sent to the Data Protection Officer. See the Privacy Policy.
Data Protection Officer
José Tenório Abs Jr. · dpo@fieli.app
Channel for data subjects and for Brazil's National Data Protection Agency (ANPD).
Changes
Changes to this policy are published here with a new version and effective date, and relevant changes are notified to customers 30 days in advance.