Fieli Tickets Privacy Policy
This English version is provided for convenience; the Portuguese version prevails.
Fieli Tickets is a customer support system: it brings e-mail and WhatsApp conversations into one inbox, organizes tickets with deadlines and owners, and uses artificial intelligence to prepare summaries and drafts — always with human review. The product is in Beta.
Fieli Tecnologia LtdaCNPJ 67.265.180/0001-04
Rua Angelita Oliveira de Souza, 111 · Centro · Delmiro Gouveia/AL · CEP 57480-000, Brazil
(82) 99817-4910 · WhatsApp · contato@fieli.app
Our two roles
- As controller, we process the customer’s account data and its support agents’ data.
- As processor, we process conversations, attachments and the data of the people the customer serves, only on the customer’s instructions; the customer is the controller of this data.
Data we process as controller
| Operation | Data subjects | Data | Purpose | Legal basis | Fieli's role | Retention |
|---|---|---|---|---|---|---|
| Customer account | customer users | name, e-mail, credentials, session and security logs | create and maintain the account, authenticate and provide support | performance of a contract (art. 7, V) | controller | while the account exists; deleted or anonymized within 90 days after closure, except access logs (6 months) and a minimal record of the contract (5 years, to exercise legal rights) |
Data we process as processor
| Operation | Data subjects | Data | Purpose | Legal basis | Fieli's role | Retention |
|---|---|---|---|---|---|---|
| Conversations and tickets | customers of Tickets customers | name, e-mail, WhatsApp, messages, attachments and satisfaction rating | handle and resolve requests | defined by the customer, who is the controller | processor | while the account is active, following the customer's instructions; after closure, 30 days for export and deletion within 90 days, including backups |
If you were served by a company that uses Tickets, contact that company first. If you contact us, we will forward the request to it and support it in handling the request (LGPD, art. 18, §6, and art. 39).
Artificial intelligence
- Providers
- OpenAI, Anthropic
- What it does
- summarize conversations, suggest reply drafts and classify tickets
- Pseudonymization
- today the text is sent to the providers without pseudonymization; pseudonymization will be implemented before the beta opens
- Training
- prohibited: customer data is not used to train models
- Human review
- every suggested reply is reviewed and sent by a person
Tickets’ AI summarizes conversations, suggests drafts and proposes a classification. No reply is sent without human review: the agent reads, edits or discards every suggestion. For that reason the AI makes no automated decisions about the people served (LGPD, art. 20). Data sent to AI providers is not used to train models.
Attachments
Files sent in conversations are stored in isolation per customer and are scanned by antivirus before becoming available.
Connected platforms
Meta (Facebook, Instagram and WhatsApp Business Platform)
- What we access
- Page and professional account IDs and names, access tokens, content you choose to publish, comments and basic insights; for WhatsApp, the business phone number, message templates and messages exchanged through the WhatsApp Business Platform.
- What for
- Only to publish, send and show results of what you configured in the product.
- Sharing
- We do not sell this data, do not use it for advertising and do not share it without your consent.
- Retention
- While the account is connected; tokens and cached data are deleted when you disconnect or request deletion.
- How to revoke
- Remove the app in Facebook Settings > Apps and websites or Instagram Settings > Apps and websites, and see the Data Deletion page (/en/data-deletion).
Subprocessors and international transfers
| Provider | Role | Data | Country | Transfer basis | Status |
|---|---|---|---|---|---|
| Magalu Cloud Ltda. | hosting, database and attachments | all service data | Brazil | — | being onboarded |
| Cloudflare, Inc. | network edge: TLS, caching and attack protection | connection metadata (IP, host, page address) | United States and others | LGPD art. 33: provider's contractual clauses; adoption of the ANPD standard contractual clauses (ANPD Resolution No. 19/2024) in progress | in use |
| Resend | e-mail delivery | addresses and e-mail content | United States | LGPD art. 33: provider's contractual clauses; adoption of the ANPD standard clauses in progress | in use |
| OpenAI, Anthropic | artificial intelligence models | conversation text, currently without pseudonymization | United States | the provider's contractual clauses, with adoption of the ANPD standard clauses in progress | in use |
| Meta Platforms (WhatsApp Business Platform) | sending and receiving WhatsApp messages through the official API | phone number, profile name and message content | United States and others (Meta infrastructure) | art. 33, II, b: standard contractual clauses, through the WhatsApp Business Data Transfer Addendum | in use |
Our main hosting is in Brazil. Personal data leaves the country only in the situations disclosedon this page: network edge, e-mail, channels chosen by the customer, artificial intelligence providers and providers still being migrated, always with the basis for each transfer.
The full text of the applicable clauses can be requested from the Data Protection Officer and will be sent within 15 days (ANPD Resolution No. 19/2024, art. 17).
Product cookies
| Name | Purpose | Essential |
|---|---|---|
sessão | keep the agent signed in | Yes |
Retention and deletion
- How to delete
- the customer deletes conversations in the dashboard; data subjects ask the customer or the DPO
- Deadline
- within 15 days
- What we keep by law
- access logs for 6 months (Brazilian Internet Civil Framework, art. 15) and data needed to comply with legal obligations or to exercise rights (LGPD, art. 16)
After the account is closed, the customer has 30 days to export conversations; they are then deleted within 90 days, including backups. See the data deletion page.
Security
- encrypted connections (TLS) everywhere
- per-customer data isolation in the database (row-level security)
- passwords with argon2id and attachments scanned by antivirus
If an incident affects data processed on behalf of a customer, we notify the customer within 48 hours after becoming aware of it. Where we are the controller, we notify the ANPD and the affected people within 3 business days (ANPD Resolution No. 15/2024).
Your rights
Data subjects have the rights of article 18 of the LGPD, with a reply within 15 days, and may petition Brazil’s National Data Protection Agency (ANPD). See the Privacy Policy.
Data Protection Officer
José Tenório Abs Jr. · dpo@fieli.app
Channel for data subjects and for Brazil's National Data Protection Agency (ANPD).
Changes
Changes to this policy are published here with a new version and effective date, and relevant changes are notified to customers 30 days in advance.