Privacy Policy
Last updated: 2026-10-05
Instituto Bellas ("we", "the platform"), operated by Instituto Bellas (operador da plataforma), is a customer relationship management (CRM) software available at https://institubellas.tech. Businesses ("Customers") use it to talk to their own clients ("End Users") over WhatsApp — including the WhatsApp Business Platform (Cloud API) provided by Meta — and Instagram Direct. This policy explains what data we process, why, and the rights of everyone involved.
1. Roles
For the messages and contacts of End Users, the Customer business is the data controller and we act as data processor on its behalf. For account data of the people who log in to the platform (Customer staff), we are the controller.
2. Data we collect from WhatsApp and Instagram
- End User phone number (WhatsApp ID) and profile name, or Instagram-scoped user ID and username;
- content of messages exchanged with the Customer: text, images, audio, video, documents, stickers, locations and button replies;
- message metadata: timestamps, message IDs, delivery and read status (sent, delivered, read, failed) and error codes;
- when the conversation starts from a Click-to-WhatsApp ad, the ad reference data that Meta sends (ad ID, headline, click ID);
- business account data of the Customer: WhatsApp Business Account ID, phone number ID, display number, verified name, quality rating and an access token issued by Meta when the Customer connects through "Login with Facebook".
3. Purpose
- show conversations to the Customer's team and let them reply, send approved message templates and track delivery;
- organise contacts in sales pipelines, orders and follow-ups configured by the Customer;
- run automations and optional AI-assisted replies that the Customer enables;
- keep the service secure (signature checks, audit logs) and comply with legal obligations.
We do not sell personal data and we do not use End User data for our own advertising.
4. Sharing
- Meta Platforms (WhatsApp/Instagram) — messages are sent and received through Meta's APIs under Meta's terms;
- infrastructure providers — hosting, database and file storage (media files are stored in our object storage provider), only to run the service;
- providers enabled by the Customer — e.g. an AI model provider or webhooks the Customer configures;
- authorities, when required by law.
5. Retention
Conversations and contacts are kept while the Customer's account is active, or until the Customer deletes them. Access tokens are deleted as soon as a number is disconnected, the app is removed in Facebook settings, or a data deletion request is received. After an account is closed, data is deleted or anonymised within 90 days, except what the law requires us to keep.
6. Security
Traffic is encrypted with HTTPS. Meta access tokens are stored encrypted (AES-256-GCM). Webhooks from Meta are validated with HMAC signatures. Access inside each Customer workspace is restricted by roles.
7. Your rights (LGPD and GDPR)
You may request confirmation of processing, access, correction, portability, anonymisation or deletion of your data, information about sharing, and withdraw consent where applicable (Brazilian LGPD, art. 18; EU GDPR, arts. 15–22). End Users should preferably contact the business they talked to; you can also write to privacidade@exemplo.com and we will forward or handle the request. See also our data deletion instructions.
8. Contact
Instituto Bellas (operador da plataforma) — privacidade@exemplo.com