Last updated: 11 June 2026
1. Data Controller Yuri Omelchenko NIF: 301711887 R. José Filipe Neto Rebelo 5, 2º Drt, 2500-222 Caldas da Rainha, Portugal Email: hello@flick-soft.tech
2. Data We Collect When you submit the contact form, we collect: name (optional), phone number, email address. We also collect standard server logs (IP address, browser type, access timestamps). When you use our platform, we process: • Conversation data: messages sent and received through connected channels (WhatsApp, Telegram, Instagram, Facebook Messenger, Email, Website chat, and other channels you choose to connect, such as VK, Avito, MAX, or LinkedIn), including text content, media files, timestamps, and read receipts • Contact data: lead/customer names, phone numbers, email addresses provided by you for CRM purposes • Business data: pipeline stages, proposals, appointments, notes, and other CRM records • Usage data: login timestamps, feature usage, browser type • Sign-in data: if you choose to sign in with Google or Apple, we receive your name, email address, and an authentication token from the provider. We do not receive your password, contacts, files, or any other account data • WhatsApp-specific data: phone numbers, message content, delivery/read status, media files shared through WhatsApp Business API • Instagram & Facebook data: usernames, message content, media files shared through Instagram Direct and Facebook Messenger via Meta Graph API • Instagram & Facebook profile metadata: Instagram Business account ID, username, profile picture URL, account type, and (where available) follower count. Facebook Page ID and name. Collected only when the business owner connects the account via OAuth, and displayed inside the CRM channel settings so the owner can confirm which account is linked. • Instagram & Facebook public comments: text content of public comments left on your business's posts, reels, and stories, plus commenter username and ID. Used to allow CRM operators to reply publicly or move the conversation to DM. We do NOT read comments on posts owned by anyone other than the connected business. • Outbound content metadata: when a CRM operator publishes a post, reel, or story through Flick AI to a connected Instagram Business account, we store the media file, caption, scheduled publish time, and the resulting media ID. We never publish content without an explicit operator action. • Aggregated insights: impressions, reach, profile views, post performance, and follower count for the connected Instagram Business account or Facebook Page. Used solely to display analytics in the business's CRM dashboard. No individual end-user identifiers are collected through Insights APIs. • Facebook Pages metadata: list of Facebook Pages the connecting user manages (shown during the OAuth flow so the user can choose which Page to connect), Page name, Page ID, and Page time zone (used to honor business hours when scheduling outbound messages).
3. Purpose & How We Use It Your data is used to: (a) respond to your inquiry; (b) provide the Flick AI platform service, including AI-powered customer communication; (c) improve our AI algorithms and response quality (we never use data obtained from Google APIs for this purpose); (d) send service-related communications and notifications; (e) facilitate business messaging through WhatsApp Business API, Instagram, Facebook Messenger, and other channels on your behalf. We do not use your data for marketing without your explicit consent.
4. Legal Basis (GDPR Art. 6) • Consent (Art. 6(1)(a)) — when you submit the contact form or agree to the trial • Contract performance (Art. 6(1)(b)) — to provide the subscribed service • Legitimate interest (Art. 6(1)(f)) — to respond to business inquiries. This is based on our reasonable expectation that responding to inquiries submitted through our website is within the reasonable expectations of the data subject. You may object to this processing at any time.
5. Automated Decision-Making (GDPR Art. 22) Our AI system automatically processes inquiries to: qualify interest level, generate personalized proposals, schedule appointments, and suggest follow-up actions. This processing is based on your consent and is necessary for the service you requested. You have the right to request human intervention, express your point of view, and contest automated decisions by contacting hello@flick-soft.tech.
6. Meta Platform Integration (WhatsApp, Instagram, Facebook & Messenger) Flick AI integrates with Meta Platforms, Inc. services through the following APIs and permissions:
• WhatsApp Business API (permissions `whatsapp_business_messaging`, `whatsapp_business_management`): Messages are sent and received through Meta's Cloud API infrastructure. We collect and store phone numbers, message content (text, images, documents, voice messages), delivery and read status, WhatsApp Business Account metadata, and message templates. The `whatsapp_business_management` permission is used solely to read and submit message templates to Meta for approval and to display the connected WhatsApp Business Account profile in the CRM settings.
• Instagram Direct Messages (permissions `instagram_business_basic`, `instagram_business_manage_messages`): We process direct messages sent to your Instagram Business account via Meta Graph API. We collect and store Instagram account ID, username, profile picture URL, message content, and media files. The `instagram_business_basic` permission is used to display the connected Instagram Business account inside the CRM channel settings; no posting or messaging activity is performed under this permission alone.
• Instagram Comments (permission `instagram_business_manage_comments`, and the legacy equivalent `instagram_manage_comments`): When a customer comments on a post or reel published by your connected Instagram Business account, our CRM ingests the comment text and commenter username so an operator can reply publicly or move the conversation to DM. We do not read or store comments on posts that are not owned by the connected business.
• Instagram Content Publishing (permission `instagram_business_content_publish`, and the legacy equivalent `instagram_content_publish`): Used only when a CRM operator explicitly creates a post, reel, or story through Flick AI. We upload the media file, caption, and any tagged users or locations to your connected Instagram Business account via Meta Graph API. We never auto-publish content without an explicit operator action.
• Instagram Insights (permission `instagram_business_manage_insights`, and the legacy equivalent `instagram_manage_insights`): Used to display aggregated analytics for the connected Instagram Business account (impressions, reach, profile views, post performance, follower count) inside the CRM dashboard. Insights data is read-only and aggregated; we do not access individual end-user metrics.
• Facebook Messenger (permissions `pages_messaging`, `pages_show_list`, `pages_read_engagement`, `pages_user_timezone`): We process messages from your Facebook Page via Meta Graph API. We collect and store user names, message content, and media files. The `pages_show_list` permission is used during the OAuth flow so the business can choose which Page to connect. `pages_read_engagement` is used to display aggregated Page metrics in the CRM dashboard. `pages_user_timezone` is used solely to honor the Page's business hours when scheduling outbound messages.
• Messenger Marketing Messages (permission `marketing_messages_messenger`): Used only when end users have explicitly opted in to receive marketing messages from your business via Facebook Messenger (for example, through a Send-to-Messenger checkbox on your website). We track opt-in records, message delivery status, and opt-out events. End users can opt out at any time by replying "STOP" or via the standard Messenger opt-out UI.
6a. Human Agent (24-Hour Messaging Window Extension) For Instagram Direct and Facebook Messenger, Meta enforces a standard 24-hour messaging window during which a business can reply freely to user-initiated conversations. Flick AI uses the `human_agent` message tag to allow a real human operator to send a single follow-up response up to 7 days after the user's last message. This is used only in the following cases: • The user's message arrived outside business hours (e.g., on a weekend) and the standard 24-hour window expired before an operator could respond. • The user's request requires human review, supplier coordination, or research that takes longer than 24 hours (e.g., custom solar quotes, multi-day tour bookings, technical specifications). Responses sent under the `human_agent` tag are always composed by a real authenticated CRM operator — never by automation or by AI without operator approval. The tag is never used for promotional, transactional, or unsolicited content.
For all Meta Platform integrations: • We act as a Technology Provider under Meta's Platform Terms of Service • We do NOT sell, share, or use Meta platform message data for advertising or marketing purposes • We do NOT use any Meta platform data to train AI models • Message templates (WhatsApp) and marketing message templates (Messenger) are submitted to Meta for approval before use in outbound communications • Meta Platforms processes data in accordance with its own privacy policy (facebook.com/privacy/policy) • We verify webhook signatures (X-Hub-Signature) for Instagram and Facebook to ensure data integrity • Access tokens for connected Meta accounts are stored encrypted at rest and used solely for the operations described above
7. Consent & Opt-in for Messaging Before sending messages to end users through WhatsApp or other channels: • End users must explicitly opt in to receive messages from your business • Opt-in may be collected through your website form, in-person interaction, or other compliant methods • End users can opt out at any time by replying "STOP" or contacting the business directly • We maintain opt-in records as required by Meta's WhatsApp Business Policy and GDPR
Facebook Messenger marketing messages (under the `marketing_messages_messenger` permission) require an explicit prior opt-in by the end user (for example, a Send-to-Messenger checkbox on your website or an in-Messenger opt-in flow) and comply with Meta's recurring notifications and marketing messages policies. We honor all "STOP" or opt-out signals immediately and prevent any further marketing message from being delivered through this channel.
8. Data Storage & Retention Your information is stored on secure servers exclusively within the European Economic Area (EEA): Latvia and Germany. We do not transfer personal data outside the EEA. We retain your data for up to 12 months after your last interaction, after which it is automatically deleted. Message data from Meta platforms (WhatsApp, Instagram, Facebook) is retained for the duration of your active subscription and deleted within 30 days of account termination. Aggregated insights data (Instagram and Facebook Page metrics) is cached for dashboard display and refreshed periodically; it is deleted together with the account or when the channel is disconnected. Access tokens for connected Meta accounts are encrypted at rest and revoked from our backend immediately when the business disconnects the channel or requests account deletion.
8a. Data Security & Protection Mechanisms We protect all personal and sensitive data (message content, contact details, OAuth access tokens, calendar and spreadsheet data) with the following technical and organizational measures: • Encryption in transit: all connections to our platform and all calls to third-party APIs use HTTPS/TLS 1.2+; incoming webhooks from messaging platforms are verified with cryptographic signatures (e.g., X-Hub-Signature) • Credential protection: account passwords are stored only as salted bcrypt hashes; sessions use short-lived signed JWT tokens; OAuth access tokens of connected accounts (Google, Meta and other channels) are stored encrypted at rest and are never exposed to the browser • Access control: role-based access control (RBAC) ensures staff members only see the data their role permits; tenant isolation is enforced at the database level with PostgreSQL Row-Level Security, so one business can never access another business's data; administrative access is limited to authorized personnel on a need-to-know basis • Infrastructure: all data is stored in EEA data centers (Germany and Latvia); databases are not exposed to the public internet; automated daily backups are kept on EU servers with limited retention • Incident response: suspected breaches are handled under the notification procedure described in §13
9. Sub-processors & Third Parties We use the following service providers: • Server hosting: Hetzner Online GmbH (Germany), SIA Nano IT (Latvia) — EU-based • AI processing: Google LLC (Google AI services) processes message text and conversation context to generate automated responses. Data may be processed outside the EEA under Standard Contractual Clauses (GDPR Art. 46) • AI fallback: DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) may process message text only when the primary AI provider is unavailable; data is processed outside the EEA • Voice transcription: Groq, Inc. (USA) transcribes voice messages received in connected channels; Deepgram, Inc. (USA) provides speech-to-text for the optional live-call feature. Audio is processed outside the EEA under the providers’ data processing terms • Sign-in providers: Google LLC (Sign in with Google) and Apple Inc. (Sign in with Apple) — used solely to authenticate you when you choose social sign-in • Maps & geocoding: Google Maps Platform (Google LLC) — used to display satellite imagery and geocode addresses for solar proposals • Calendar sync (optional): if you connect Google Calendar (Google LLC) or Apple iCloud Calendar (Apple Inc.), appointment data is synced between the platform and your calendar • Communication APIs: WhatsApp Business API (Meta Platforms, Inc.), Instagram Direct API (Meta), Facebook Messenger API (Meta), Telegram Bot API, Resend (email delivery) • Font delivery: Google Fonts (your IP address is transmitted to Google; policies.google.com/privacy) We do not sell, rent, or share your personal data with other third parties, except as required by applicable law or judicial order.
9a. Google User Data (Google API Services — Limited Use) If you connect Google features (Sign in with Google, Google Calendar sync, Google Sheets export, Google Drive file access), Flick AI receives only the data described in §2 and uses it exclusively to provide the user-facing features you have requested: authenticating you, creating and updating calendar events for your appointments, and reading/writing the spreadsheets and files you explicitly select. • We do NOT use Google user data for advertising or marketing purposes • We do NOT sell Google user data to any party • We do NOT use Google user data to develop, improve, or train AI or machine-learning models (neither generalized nor personalized) • We do NOT transfer Google user data to third parties, except as necessary to provide the features you requested, to comply with applicable law, or as part of a merger or acquisition with prior notice to you • Humans do not read Google user data, unless: we have your explicit permission for a support case; it is necessary for security purposes (e.g., investigating abuse); or the data is aggregated and anonymized for internal operations You can revoke Flick AI's access to your Google data at any time at https://myaccount.google.com/permissions or by disconnecting the integration in CRM Settings; stored Google data is then deleted under the rules in §8 and §12. Flick AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
10. International Data Transfers All primary data processing occurs within the EEA. AI processing (Google AI services) and Google Fonts may involve data transfer to Google outside the EEA; such transfers are covered by Google's Standard Contractual Clauses (SCCs) pursuant to GDPR Art. 46.
11. Your Rights (GDPR Art. 15–22) You have the right to: access your personal data (Art. 15), rectify inaccurate data (Art. 16), request erasure / "right to be forgotten" (Art. 17), restrict processing (Art. 18), data portability in a commonly used electronic format (Art. 20), and object to processing (Art. 21). To exercise any of these rights, contact hello@flick-soft.tech. We may verify your identity before processing your request. We will respond within 30 days.
12. Data Deletion You may request complete deletion of your account and all associated data at any time. To request deletion: • Send an email to hello@flick-soft.tech with subject "Data Deletion Request" • Include the email address associated with your account • We will process the deletion within 30 days and confirm completion via email Upon deletion, all personal data, conversation history, lead records, and files associated with your account will be permanently removed from our systems. Data that we are legally required to retain (e.g., billing records) will be kept for the minimum period required by law and then deleted.
Specifically for Meta Platform data: upon account deletion or channel disconnection, all message history, profile metadata, insights data, content metadata, and OAuth access tokens associated with the connected WhatsApp Business Account, Instagram Business account, or Facebook Page are deleted within 7 days. Webhook subscriptions are revoked immediately. You may also revoke our access at any time directly via Meta Business Suite → Business Settings → Integrations, which will immediately prevent any further data collection by Flick AI.
13. Data Breach Notification In the event of a personal data breach that poses a risk to your rights and freedoms, we will: notify the CNPD within 72 hours of becoming aware (GDPR Art. 33); notify affected individuals without undue delay if the breach poses a high risk (GDPR Art. 34).
14. Children's Data Our service is designed for businesses and is not directed at individuals under 16. We do not knowingly collect personal data from minors.
15. Policy Changes We may update this policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Continued use of the website after changes constitutes acceptance.
16. Supervisory Authority You have the right to lodge a complaint with the Portuguese Data Protection Authority: Comissão Nacional de Proteção de Dados (CNPD) www.cnpd.pt
17. Mobile Application (iOS) The Flick AI CRM iOS application (bundle identifier `tech.flick-soft.crm`) is a native client for the same Flick AI platform described above. It connects to the same EU-hosted backend and does not introduce any third-party tracking, advertising, or analytics SDKs.
17.1 Data Collected by the App • Account credentials: email and password entered at sign-in are transmitted over HTTPS/TLS to our authentication endpoint; the returned JWT authentication token is stored in the iOS Keychain (via Apple Secure Enclave where available) and never written to unencrypted storage. • Sign in with Google / Sign in with Apple: if you choose social sign-in, we receive your name, email address, and an identity token from Google or Apple to authenticate you. We never receive your password or any other account data from these providers. • Push notification token: when you enable notifications, an Expo push token (anonymous device identifier issued by Expo / Apple APNs) is sent to our backend and stored in the `mobile_push_tokens` table linked to your user account. This token is used solely to deliver push notifications (new message, new lead, task assigned, escalation). It is not shared with any third party for advertising. • Device metadata: device model and OS version are collected for diagnostics and compatibility (e.g., "iPhone15,2 · iOS 18.2"). No advertising identifier (IDFA) is requested or collected — the App Tracking Transparency prompt is not shown because we do not track. • Content you create or view: messages, leads, tasks and files you access in the app are transmitted between your device and our EU-hosted backend over HTTPS / secure WebSocket. They are not stored permanently on the device beyond standard OS-level caching of images you have opened. • Camera and photo library access: requested only when you explicitly tap the attachment button in a chat to send a picture. Images you select are uploaded to the same conversation on the backend and are not sent anywhere else.
17.2 Biometric Authentication (Face ID / Touch ID) If you enable biometric unlock, the biometric template (your face or fingerprint data) is processed exclusively on-device by Apple's Local Authentication framework and the Secure Enclave. It never leaves your device, is never transmitted to us or any third party, and we do not receive or store biometric data. The app only receives a binary success/failure signal from iOS.
17.3 Local Storage on the Device • Keychain (encrypted): JWT authentication token, optionally saved email for auto-fill. • App preferences (UserDefaults, not encrypted): language (en/pt/ru), push notifications on/off, biometric unlock on/off. • Image cache: images you have opened are cached by the OS and cleared by iOS when storage is low, or by you via Settings → General → iPhone Storage → Flick AI CRM → Offload App.
17.4 Third Parties Used by the Mobile App • Apple Push Notification service (APNs): required to deliver push notifications to iOS. Governed by Apple's Privacy Policy. • Expo Push API (Expo, Inc.): a relay that batches notifications from our backend to APNs. Expo receives only the push token and the message payload (title, short body, notification type, related record ID). Expo Privacy Policy: expo.dev/privacy. • Google Identity Services / Apple Sign In: contacted only if you choose social sign-in, solely for authentication. • Our own backend (Hetzner Germany, SIA Nano IT Latvia) — same EU infrastructure as the web platform. The mobile app does NOT use Google Analytics, Firebase Analytics, Meta SDK, Crashlytics, Mixpanel, Amplitude, Segment, or any other analytics/advertising SDK.
17.5 App Tracking Transparency (ATT) We do not track you across apps or websites owned by other companies. The ATT prompt is therefore not shown. No IDFA is collected.
17.6 Data Retention and Deletion (Mobile) • Push tokens are deleted from our backend immediately on logout (DELETE /api/mobile/push-tokens/:deviceId) and are automatically invalidated by Expo if you uninstall the app. • All server-side data retention rules from §8 apply identically to mobile users. • To request deletion of your account and all associated data, follow the procedure in §12 (email hello@flick-soft.tech with subject "Data Deletion Request"). This will remove your data regardless of whether it was accessed via web or iOS.
17.7 Children (Mobile) As with the web service, the iOS app is intended for business users aged 16 and above and is not directed at children. It is rated 4+ in the App Store (no objectionable content) but this rating reflects content, not the intended user base.
17.8 Contact for Mobile-specific Privacy Questions hello@flick-soft.tech — same contact as the web service.