Privacy Policy
Last updated: August 5, 2026
1. Who we are and what this policy covers
FLUXIUM INOVA SIMPLES (I.S.), registered under Brazilian company number (CNPJ) 60.123.373/0001-81, headquartered in São Paulo, SP — Brazil, with its corporate website at https://www.fluxium.pro (“Fluxium”, “we”, “us”), is a technology provider that builds and operates customer messaging, automation and artificial intelligence solutions for businesses across different industries.
Our solutions share the same codebase and the same infrastructure, and are delivered under industry-specific brands. This Privacy Policy is a single document covering all of them:
- OticaPro — otica.pro (integrates Meta platforms)
- TaskPro — task-pro.pro
- EducaPro — educa-br.pro
- CRM Fluxium — crm.fluxium.pro
- Affiliates Fluxium — affiliates.fluxium.pro
- Mails Fluxium — mails.fluxium.pro
- Genial IA — genialia.vercel.app
- Precedent IA — precedent.fluxium.pro
- AdvocaciaPro — sistemajuridico.vercel.app
- OnboardingPro — onboardingpro.vercel.app
This list is kept up to date as new solutions go live. Any new Fluxium solution is governed by this same Policy from launch.
This document describes how we process personal data in compliance with the Brazilian General Data Protection Law (Law No. 13,709/2018 — LGPD) and with the terms of the platforms we integrate with, including Meta Platform Terms and Developer Policies.
By using our solutions — whether as a representative of a Business Customer or as an end customer served through one of the integrated channels — you agree to the practices described here.
2. Definitions
- Personal data: any information relating to an identified or identifiable natural person, such as name, national ID, email address, phone number, social network identifiers and IP address.
- Sensitive personal data: data on racial or ethnic origin, religious belief, political opinion, union membership, health or sex life, genetic or biometric data linked to a natural person.
- Controller: the party that decides the purposes and means of processing.
- Processor: the party that processes data on behalf of and under the instructions of the controller.
- Data subject: the natural person the data refers to.
- Business Customer: the company that subscribes to a Fluxium solution to run its own customer service — the optical store, the clinic, the practice or the retail network.
- End customer: the person who talks to the Business Customer through one of the integrated channels (WhatsApp, Instagram Direct, Instagram comments, among others).
3. Who is controller and who is processor
Our solutions run on a multi-tenant model in which each Business Customer has its own isolated environment. Roles are distributed as follows:
3.1 The Business Customer is the controller of its customers’ data
The store, clinic or practice that subscribes to the solution decides why and how it talks to its own customers. It is responsible for having a legal basis for that communication and for responding to its data subjects’ requests.
3.2 Fluxium is the processor of that data
Regarding end customer data — messages, comments, contacts, service history — Fluxium processes data on behalf of and under the instructions of the Business Customer. We do not use that data for our own purposes.
3.3 Fluxium is the controller of account data
Regarding data about Business Customer representatives — registration, authentication, billing and platform usage — Fluxium is the controller and is accountable for those processing decisions.
4. Data we collect
4.1 Provided by you
- Full name, email address and phone number
- Login credentials (email and password, managed by our authentication provider; passwords are never stored in plain text)
- Organization data (legal name, company number, address, billing details)
- National ID, when required for registration or scheduling in integrated systems
- Content you send through the service channels: text, audio, images, video and documents
- Scheduling information: dates, times, services, professionals
- Service settings, including the instructions you define for the AI assistant
4.2 Collected automatically
- IP address, browser type and operating system
- Pages visited, clicks, and date and time of access
- Device and session identifiers
- Audit records of sensitive operations performed in the dashboard
- Approximate location derived from the IP address
4.3 Payment data
Card data is processed directly by our payment provider (Stripe) and neither transits through nor is stored on our servers. We keep only transaction records: amount, date, status and charge identifier.
4.4 Sensitive data
In healthcare-oriented solutions, and where the Business Customer integrates its practice management system, clinical scheduling data may be processed — procedure, responsible professional and appointment history. This is sensitive personal data under article 5, II of the LGPD and receives the reinforced protections described in this Policy.
5. Data obtained through Meta platforms
Integration with Meta’s official APIs exists in Fluxium’s messaging solutions — currently OticaPro — and in versions of those same solutions operated under the customer’s own brand, which is why our application declares different domains. In every case the codebase is the same and the practices described here apply equally.
The integration only happens after an authorized representative of the Business Customer explicitly connects the account and grants the permissions.
5.1 WhatsApp Business Platform
Through the official WhatsApp Business API we receive and process:
- Phone number and profile name of the person sending the message
- Message content exchanged: text, audio, image, video, document and location
- Technical identifiers: message ID, phone number ID, WhatsApp Business Account (WABA) identifier
- Delivery and read status of sent messages
- Message template and campaign metadata for messages sent by the Business Customer
5.2 Instagram
Through the official Instagram API, with Business Login, we receive and process:
- The user identifier scoped to the connected account (IGSID), username, display name and profile picture
- Content of direct messages exchanged with the connected professional account, including attachments
- Public comments made on the connected account’s posts and the identifier of the commented media
- Referral events generated when someone starts a conversation through an Instagram link
- Basic data of the connected professional account: identifier, username and picture
When the Business Customer enables comment replies, we may publish a public reply in the comment thread and send a private message to the person who commented — a capability provided and authorized by the platform, limited to one message and to the seven-day window counted from the comment.
Our commitments regarding Meta data
- We use this data exclusively to provide the messaging service to the Business Customer that connected the account.
- We do not sell, rent or transfer this data to third parties.
- We do not use it for advertising, ad targeting, building advertising profiles or enriching data brokerage databases.
- We do not use it to train artificial intelligence models, our own or third parties’.
- Each Business Customer can access only the data of its own connected account. Isolation is enforced at the database level, not merely in the interface.
- We delete this data when the account is disconnected, when the contract ends, or upon the data subject’s request, as described in section 13.
6. What we use data for
- Providing the service: receiving and replying to messages and comments, organizing service history, managing contacts and appointments.
- Automating support: generating replies with artificial intelligence, transcribing audio, interpreting images received and handing the conversation over to a human agent when needed.
- Communicating: sending confirmations, appointment reminders and service notifications.
- Billing: processing subscriptions, payments and tax documents.
- Protecting: preventing fraud and abuse, rate limiting, validating webhook signatures and keeping audit records.
- Improving: analyzing usage in an aggregated and anonymized way to improve features and performance.
- Complying with the law: meeting legal and regulatory obligations and requests from competent authorities.
7. Legal bases
7.1 Regular personal data (LGPD, article 7)
- Performance of a contract (item V): processing necessary to deliver the service subscribed by the Business Customer
- Consent (item I): when the data subject voluntarily provides their data, such as by starting a conversation or signing up
- Legitimate interest (item IX): platform security, fraud prevention and service improvement
- Compliance with a legal or regulatory obligation (item II)
- Regular exercise of rights in judicial, administrative or arbitration proceedings (item VI)
7.2 Sensitive personal data (LGPD, article 11)
- Specific and highlighted consent (item I)
- Health protection, in procedures carried out by health professionals or health services (item II, “f”)
8. Use of artificial intelligence
Artificial intelligence is a core component of our messaging solutions. We use Google’s Gemini models, and we disclose transparently:
- Messages received through the integrated channels are sent to the model so it can generate the service reply.
- Processing happens in real time and is scoped to that conversation and that Business Customer.
- Audio messages may be transcribed and images may be analyzed so the assistant understands what was sent.
- The assistant may perform actions in the system — checking availability, scheduling, rescheduling, cancelling, recording information — always within the Business Customer’s environment.
- Data sent to the model is handled under Google’s API terms, which do not use API content to train models.
- The end customer can request a human agent at any time, and the Business Customer can take over the conversation whenever it wants.
- The Business Customer configures the assistant’s behavior: instructions, tone, services offered and business hours.
You have the right to request human review of decisions made solely by automated processing, under article 20 of the LGPD.
9. Who we share data with
We share personal data only with the providers necessary to operate the service, and strictly for the purposes described in this Policy:
| Provider | Purpose | Where it operates |
|---|---|---|
| Amazon Web Services (AWS) | application hosting and server infrastructure | Brazil (São Paulo) |
| Supabase Inc. | database, authentication and file storage | Brazil (São Paulo) |
| Meta Platforms, Inc. | sending and receiving messages and comments through the official WhatsApp Business and Instagram APIs | United States |
| Google LLC | artificial intelligence (Gemini) for reply generation, audio transcription and image analysis; calendar sync (Google Calendar) when enabled | United States |
| Stripe, Inc. | payment processing and subscription management | United States |
| Vercel Inc. | hosting of institutional websites and part of the web applications | United States |
When a Business Customer enables an integration with its own management system, the data required by that integration is exchanged with the system it chose — including OptFacil (Dataweb), Clinix, Dental Office, Clinicorp. That configuration is the Business Customer’s decision.
All providers are contractually bound to process data securely and in compliance with applicable law. We do not sell, rent or share personal data for third-party marketing.
We may also share data to comply with a legal obligation, court order or request from a competent authority, and in the context of a corporate reorganization — in which case this Policy continues to apply to the transferred data.
10. Where data lives and how it is protected
The primary infrastructure for our solutions — application servers and database — operates in Brazil, in the São Paulo region. Some providers listed in section 9 operate outside the country, as indicated in the table.
Technical and administrative measures we apply:
- Encryption in transit (TLS/HTTPS) and at rest
- Isolation between Business Customers enforced in the database itself, through row-level security policies
- Role-based access control with hierarchical permission levels
- Cryptographic signature validation of webhooks received from integrated platforms
- Third-party credentials stored encrypted, never in plain text
- Rate limiting, input validation and protections against the most common vulnerabilities
- Audit logging of authentication, access and sensitive operations
- Periodic review of security practices and internal access
No system is immune to incidents. Should a security incident occur with relevant risk to data subjects, we will notify those affected and the Brazilian Data Protection Authority (ANPD) within the legal deadlines.
11. International transfers
Some providers keep infrastructure outside Brazil, which constitutes an international transfer of personal data. In those cases, the transfer complies with article 33 of the LGPD and relies on engaging providers that offer an adequate level of protection, standard contractual clauses and adherence to recognized data protection frameworks.
12. How long we keep data
- Business Customer account data: while the account is active and for up to 90 days after cancellation, to allow reactivation.
- Messages, comments and service history: for the duration of the contract, or for the period defined by the Business Customer, whichever comes first.
- Data obtained from Meta platforms: deleted when the account is disconnected, when the contract ends, or upon the data subject’s request.
- Financial and tax records: for the period required by tax law, at least 5 years.
- Audit and security logs: at least 6 months, under the Brazilian Internet Act and applicable law.
- Health data: for the periods required by the sector regulation applicable to the Business Customer.
Once the retention period ends, data is securely deleted or irreversibly anonymized.
13. How to request deletion of your data
You may request deletion of your personal data at any time, free of charge, through one of these paths:
13.1 If you are an end customer of a Business Customer
Ask the business you talked to directly — it is the controller of your data. If you prefer, write to contato@fluxium.pro stating the channel used (WhatsApp or Instagram), the corresponding identifier (phone number or username) and the name of the business you talked to. We will forward the request to the controller and assist with deletion in our capacity as processor.
13.2 If you are a Business Customer
You can disconnect integrated accounts from the dashboard at any time, which immediately stops the collection of new data from that channel. To permanently delete data already stored, write to contato@fluxium.pro from your registered email address.
13.3 What happens after the request
- We acknowledge receipt and provide a confirmation number.
- We complete deletion within 15 business days, except where law requires retention of a specific record — in which case we will tell you which data was kept and on what legal ground.
- You can check the status of your request using the confirmation number by writing to the same address.
- Backups are overwritten in the normal retention cycle; in the meantime, the data remains inaccessible for use.
14. Your rights as a data subject
Under articles 17 to 22 of the LGPD, you may:
- Confirm the existence of processing and access your data
- Correct incomplete, inaccurate or outdated data
- Request anonymization, blocking or deletion of unnecessary data or data processed in breach of the law
- Request portability of your data to another provider
- Request deletion of data processed on the basis of consent
- Learn who we share your data with
- Withdraw consent at any time
- Object to processing carried out on a basis other than consent, in case of breach of the law
- Request review of decisions made solely by automated processing
Write to contato@fluxium.pro. We respond within 15 business days, under article 18, §5 of the LGPD. We may ask for additional information to verify your identity before fulfilling the request — a safeguard against fraudulent requests.
15. Cookies
We use strictly necessary cookies only: keeping the authenticated session, interface preferences and cross-site request forgery protection. We do not use advertising tracking cookies, third-party pixels for behavioral advertising, or fingerprinting techniques.
16. Minors
Our solutions are intended for businesses and their representatives over 18 years old. We do not knowingly collect data from minors for registration or platform access.
When minors are served through the integrated channels — in clinical scheduling, for example — processing takes place in the minor’s best interest and with the specific consent of at least one parent or legal guardian, under article 14 of the LGPD, which the Business Customer, as controller, is responsible for obtaining. If we identify improper collection, we will delete the data.
17. Changes to this Policy
This Policy may be updated to reflect changes in our services, new integrations or legal requirements. Relevant changes are communicated through the dashboard or by email, and the last updated date at the top of this page is always revised.
18. Contact
For questions, requests or complaints about this Policy or about your data:
- Data Protection Officer (DPO): contato@fluxium.pro
- General contact: contato@fluxium.pro
- Phone: +55 (11) 97196-3841
- FLUXIUM INOVA SIMPLES (I.S.) — CNPJ 60.123.373/0001-81 — São Paulo, SP — Brazil
If you are not satisfied with our response, you may file a complaint with the Brazilian Data Protection Authority (ANPD) at www.gov.br/anpd.
