Privacy Policy
Last updated: July 26, 2026
1. Privacy commitment
Your privacy matters to us. This policy describes what data we collect, how we use it, with whom we share it and your rights as a data subject, in compliance with the Brazilian LGPD (Law 13.709/2018).
2. Data we collect
To operate the platform, we collect:
- Sign-up data: name, email, agency/organization name and password (stored as a hash).
- Usage data: actions performed on the platform, scheduled posts, uploaded media, technical logs.
- Connected account data: OAuth tokens for Instagram, Facebook, Google and other integrated platforms — stored encrypted.
- Billing data: minimum information needed to process payments via our payment provider.
3. Purpose of processing
We use your data to:
- Provide the contracted service and enable your integrations.
- Process payments and manage your subscription.
- Send operational communications (alerts, invoices, updates).
- Investigate and prevent misuse, fraud or security violations.
4. Legal bases
We process data based on the performance of our contract with you (LGPD art. 7, V), legal or regulatory obligations (art. 7, II) and our legitimate interest for security and service improvement (art. 7, IX), respecting your fundamental rights.
5. Isolation between agencies
The platform is multi-tenant. Each client agency accesses only its own data, clients, media, connected accounts and reports. No agency has visibility into another agency’s data.
6. Your rights as a data subject
You may exercise the rights provided in LGPD art. 18 at any time, including:
- Confirmation of the existence of and access to your data.
- Correction of incomplete or outdated data.
- Anonymization, blocking or deletion of unnecessary data.
- Portability of your data to another provider.
- Deletion of data processed with your consent, subject to legal retention periods.
7. Sharing with third parties
We share data only with (i) platforms you ask us to integrate with (Meta, Google, etc.), (ii) essential infrastructure providers (hosting, database, transactional email) under contracts with data protection clauses, and (iii) public authorities pursuant to a legal order.
8. Information security
We adopt reasonable technical and organizational measures — encryption in transit (TLS) and at rest for sensitive credentials, role-based access control (RBAC), organization isolation and monitoring — to protect your data from unauthorized access.
9. Retention and deletion
We retain your data for as long as necessary to provide the service and meet legal obligations. After account cancellation, data is retained for up to 90 days for potential recovery and then deleted, unless a longer legal retention period applies.
Contacting the controller
The data controller is Agência Mais Conteúdo. To exercise your rights or clarify questions, write to fernando@agenciamaisconteudo.com.br.