Privacy Policy

Last updated: 11 July 2026 · Applies to Fluxo (app.fluxo.ltda)

This Privacy Policy explains how Fluxo Ltda. (“Fluxo”, “we”, “us”, or “our”) collects, uses, discloses, retains, and protects information in connection with the Fluxo application and related services made available at app.fluxo.ltda (collectively, the “Service”). By accessing or using the Service, or by connecting an Instagram or Meta account to it, you acknowledge that you have read and understood this Policy. If you do not agree, do not use the Service.

1. Who this Policy covers

This Policy addresses two groups:

For End-User data received from Meta (defined below), the Operator is the data controller and Fluxo acts as a data processor / service provider, processing that data only on the Operator’s documented instructions and as described here.

2. Information we collect

2.1 Information you provide (Operators)

2.2 Information obtained from Meta / Instagram (“Platform Data”)

When an Operator connects an Instagram professional account through Meta’s official APIs (using Facebook Login for Business and the permissions the Operator grants), we receive and process, strictly to provide the Service:

We access only the permissions (scopes) the Operator explicitly grants and only the data needed for the features in use.

2.3 Information collected automatically

3. How and why we use information

PurposeLegal basis (GDPR, where applicable)
Provide, operate, and secure the Service (authentication, dashboards, messaging, analytics, automation you configure)Performance of a contract; legitimate interests
Send transactional email (verification, password reset, service notices)Performance of a contract; legitimate interests
Deliver automated replies and lead capture that an Operator explicitly configuresThe Operator’s legitimate interests / consent obtained by the Operator from the End User
Maintain security, prevent abuse and fraud, and enforce our termsLegitimate interests; legal obligation
Comply with law and respond to lawful requestsLegal obligation

We do not sell personal information, and we do not use Platform Data to build advertising profiles, to train unrelated machine-learning models, or for any purpose incompatible with the reason it was collected. We use Platform Data solely to provide and improve the Service to the connecting Operator, in compliance with the Meta Platform Terms, Meta Developer Policies, and the Instagram Platform Policy.

4. How we share information

We share information only as follows, and never sell it:

5. Data retention

We retain personal information only as long as necessary for the purposes described here, to provide the Service, to comply with legal obligations, resolve disputes, and enforce agreements. Operators can configure retention windows for certain data (such as cached insights and captured leads). Encrypted access tokens are kept only while an account remains connected and are deleted when the connection is removed. When data is no longer needed, or upon a valid deletion request, we delete or de-identify it.

6. Your rights & how to delete your data

Depending on your jurisdiction, you may have rights to access, correct, export, restrict, object to, or delete your personal information, and to withdraw consent. To exercise these rights:

We honor valid deletion requests within 30 days (or sooner where required by law). We may retain limited information where necessary to comply with legal obligations or resolve disputes.

7. How we protect information

We apply technical and organizational safeguards designed to protect information, including: encryption in transit (HTTPS/TLS); encryption of access tokens at rest; strict tenant isolation so one Operator cannot access another’s data; least-privilege access controls; rate limiting; and security hardening of our infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. International data transfers

We and our sub-processors may store and process information in countries other than your own, including the United States. Where required, we rely on appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) for cross-border transfers of personal data.

9. Automated messaging & consent

The Service can send automated replies to inbound messages that an Operator configures. Operators are responsible for obtaining any consent required by law and by Meta’s policies before messaging End Users, for honoring opt-out requests, and for the content of their automations. The Service enforces Meta’s messaging guardrails (for example, inbound-initiated messaging within permitted windows and opt-out handling).

10. Children’s privacy

The Service is intended for businesses and users aged 18 or older and is not directed to children. We do not knowingly collect personal information from children under the age of 13 (or the minimum age in your jurisdiction). If you believe a child has provided us information, contact us and we will delete it.

11. Third-party services

The Service integrates with Meta’s platforms and may link to third-party sites. Their handling of your information is governed by their own privacy policies, including the Meta / Instagram Privacy Policy. We are not responsible for the practices of third parties.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be posted at this URL with an updated “Last updated” date, and where required we will provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance. We retain prior in-effect versions of this Policy.

13. Disclaimers & limitation of liability

To the fullest extent permitted by applicable law: the Service is provided on an “as is” and “as available” basis without warranties of any kind, whether express or implied, including merchantability, fitness for a particular purpose, and non-infringement. Fluxo does not warrant that the Service will be uninterrupted, secure, or error-free, or that data processed through Meta’s APIs will be accurate or complete. To the fullest extent permitted by law, Fluxo and its affiliates, officers, employees, and suppliers will not be liable for any indirect, incidental, special, consequential, punitive, or exemplary damages, or for any loss of profits, data, goodwill, or other intangible losses, arising out of or relating to your use of (or inability to use) the Service. Nothing in this Policy limits liability that cannot be limited or excluded under applicable law (including certain statutory data-protection rights). This Policy describes our data practices only and does not by itself grant any rights beyond those required by applicable law.

14. Region-specific disclosures

European Economic Area / United Kingdom (GDPR)

Where Fluxo acts as a controller, our legal bases are set out in Section 3. Where we act as a processor for an Operator, we process personal data only on that Operator’s instructions. You have the rights described in Section 6 and the right to lodge a complaint with your local supervisory authority. To exercise your rights or to reach our privacy contact, email support@fluxo.ltda.

California (CCPA/CPRA)

In the preceding 12 months we may have collected the categories of personal information described in Section 2 (identifiers, internet/network activity, commercial information, and content of communications) for the business purposes in Section 3. We do not sell or “share” personal information as those terms are defined under California law, and we do not use sensitive personal information for purposes requiring a right to limit. California residents may exercise rights to know, delete, correct, and non-discrimination by contacting us as described above.

Brazil (LGPD)

We process personal data in accordance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, Lei nº 13.709/2018, “LGPD”). Our legal bases (bases legais) for processing include the execution of a contract or preliminary procedures at your request, our legitimate interests, compliance with a legal or regulatory obligation, and your consent (consentimento) where required. As a data subject (titular) you have the rights set out in Article 18 of the LGPD, including: confirmation that we process your data; access to it; correction of incomplete, inaccurate, or out-of-date data; anonymization, blocking, or deletion of data that is unnecessary, excessive, or processed in non-compliance with the LGPD; data portability; deletion of personal data processed on the basis of your consent; information about the public and private entities with which we have shared your data; information about the possibility of refusing consent and the consequences of doing so; and revocation of consent. You may exercise these rights, or reach our data protection officer (Encarregado), by emailing support@fluxo.ltda. You also have the right to petition the National Data Protection Authority (Autoridade Nacional de Proteção de Dados — ANPD). Where we transfer personal data internationally, we do so in accordance with Article 33 of the LGPD.

15. Contact us

Questions, requests, or complaints about this Policy or your data: