Who we are
BossYou Manager is a social media management and agency delivery platform. The company responsible for the processing described here — the controller, in the language of Brazil's General Data Protection Law (LGPD, Law 13.709/2018) — is:
- Legal name
- BOSSYOU MEDIA AGENCIA DE MARKETING LTDA
- Trade name
- BOSSYOU MEDIA
- Company ID (CNPJ)
- 63.457.122/0001-21
- Address
- Est. Doutor Cícero Borges de Morais, 1850, Andar 1, Vila Universal, Barueri/SP, ZIP 06.407-000, Brazil
- Privacy email
- itacontabilidade@terra.com.br
- Phone
- +55 11 4688-1953
- Meta app
- BossYou Manager · App ID 1371849647985190
Wherever this policy says “we”, “BossYou” or “the platform”, it refers to the company above and to BossYou Manager.
The Portuguese version at bossyoumedia.com/privacidade is the canonical one. This English version is provided for convenience; in case of any discrepancy, the Portuguese text prevails.
The short version
A summary of what follows. Each point is detailed in its own section.
- What we collect. Account details of the people who use the platform, service usage data, and data from the Facebook and Instagram accounts you connect — posts, performance metrics and comments.
- Why we collect it. To deliver the service you hired us for: publishing, measuring results, responding to comments and producing reports. We do not sell personal data and we do not use it for advertising.
- What we do with comments. We automatically classify the sentiment and topic of public comments. This runs on a local model inside our own infrastructure: comment text is not sent to any third-party AI service.
- How to delete. Email itacontabilidade@terra.com.br. The step-by-step, what we erase and how long it takes are in How to request deletion of your data.
- Cookies. This page uses no cookies and carries no trackers. The platform uses only what is needed to keep you signed in and to remember your interface preferences.
Who this policy covers
Three different groups of people have data processed by us, for different reasons. It is worth knowing which one you belong to, because your rights and how you exercise them differ slightly in each case.
- 1. The BossYou team
- Employees and contractors who use the platform to produce client work.
- 2. Clients and their teams
- People from client companies invited into a workspace — to follow the work, comment and approve deliverables.
- 3. The public interacting with our clients' pages
- People who commented on or mentioned a Facebook Page or Instagram profile we manage. This group has no account with us and has likely never heard of BossYou — but their username and the text of their public comment reach us through Meta's APIs when the page is managed on the platform. We explain exactly what we store in What data we collect, on what legal basis in Why we process it, and how to request deletion in How to request deletion of your data.
What data we collect
a) Data you give us
- Account and sign-up: name, work email, password (stored only as a hash, never in readable form), job title or role, and the organization you belong to.
- Client company data: legal name, contacts, industry, notes and the relationship history recorded by the team.
- Work content: projects, tasks, internal comments, approval requests and attached files (design pieces, videos, documents).
- Content you publish: text, images and video you compose on the platform to be published to the connected networks.
- Billing data: what is needed to invoice your plan. Payment itself is processed by Asaas — see Who we share it with.
- What you write to us: support messages and requests sent by email or through our service channels.
b) Data collected automatically
- Application access logs: IP address, date and time of requests, and the action performed. Keeping these for six months is a legal obligation under Brazil's Internet Civil Framework (Law 12.965/2014, art. 15).
- Technical device data: browser type and version, operating system and language — sent by your own browser on every request on the internet.
- Interface preferences: stored in your browser's local storage, on your own device. They are not sent to our servers. See Cookies and local storage.
- Collection run records: date, time, outcome and row count of each sync with Meta, for troubleshooting.
We do not use third-party analytics tools, advertising pixels, tracking networks, or any profiling technology for advertising.
c) Data received from Meta (Facebook and Instagram)
When an authorized user connects a Facebook Page, an Instagram professional account or an ad account, we begin accessing data from those accounts through Meta's Graph API, within the permissions granted on the authorization screen. Specifically, we store:
| Category | What is stored |
|---|---|
| Connected account | Page or profile ID, name, username and follower count. |
| Posts | ID, date and time, permalink, caption, media type and post thumbnail. |
| Metrics | Reach, interactions, follower change, profile visits and contact-button taps — as daily series, and per post. |
| Comments and mentions | Comment ID, the commenter's ID and username, the comment text, date and time, like count, and whether the comment came from the account itself. |
| Comment classification | The sentiment label (positive, neutral or negative), topic, confidence score and the model version that produced the label. See the section on classification. |
| Competitors | Public follower, post and interaction counts of professional profiles nominated by the client for benchmarking. This is public data, obtained through Instagram's business discovery feature. |
| Access token | The credential authorizing our calls to Meta on behalf of the connected account. See Security. |
We do not collect anyone's friend or follower lists, profile data about people who interact with the pages beyond their public username, private messages outside the authorized scope, or any sensitive data as defined in art. 5, II of the LGPD (racial or ethnic origin, religious belief, political opinion, union membership, health data, sex life, genetic or biometric data).
Meta permissions, one by one
When you connect an account, Meta shows the permissions we are requesting. The table below translates each of them: what it lets us read or do, and what for. We only request what the contracted functionality requires.
| Permission | In plain language | Type |
|---|---|---|
pages_read_engagement |
Read your Facebook Page's content and engagement: posts, comments, reactions and Page information. This is what lets us build the performance report and show comments in the inbox. | Read |
pages_manage_posts |
Create, edit and delete posts on your Page. This is what lets us publish and schedule posts from the platform. | Write |
instagram_basic |
Read the linked Instagram professional account's profile — username, picture, follower and post counts — and the media published on it. | Read |
instagram_content_publish |
Publish photos, videos and reels to the Instagram professional account. | Write |
ads_read |
Read ad accounts, campaigns, ad sets and their results — spend, impressions, clicks and conversions — for paid media reporting. | Read |
ads_management |
Create and edit campaigns, ad sets and ads; pause and resume delivery; change budgets. | Write |
business_management |
See the assets in your Business Manager — Pages, Instagram accounts and ad accounts — so you can choose which ones to connect, and maintain those links. | Read and manage |
A write permission means the platform can act on your behalf within that scope — not that it acts on its own. Every publication, campaign change or deletion originates from an action by someone on your team or ours, and is recorded in the audit log with author and timestamp.
You can revoke these permissions at any time, directly with Meta, without going through us: on Facebook, under Settings & privacy → Settings → Apps and websites; on Instagram, under Settings → Apps and websites. Revoking stops our access immediately. It does not, by itself, erase data already collected — for that, see How to request deletion of your data.
Why we process it, and on what legal basis
The LGPD requires every processing activity to have a specific purpose and a legal basis (art. 7). One row per purpose, with the data involved and the basis that supports it.
| What for | Which data | Legal basis (LGPD) |
|---|---|---|
| Create and maintain your account and access to the platform | Sign-up details, credentials, organization and permissions | Performance of a contract — art. 7, V |
| Deliver the contracted work: publishing, scheduling, ad management | Post content, connected accounts, access tokens | Performance of a contract — art. 7, V |
| Measure performance and produce client reports | Page and post metrics, ad data | Performance of a contract — art. 7, V |
| Read, organize and respond to comments and mentions on managed pages | Comments, mentions, commenter username | Legitimate interest — art. 7, IX (managing the page's public communication, over content voluntarily posted in a public setting) |
| Classify comment sentiment and topic | Comment text | Legitimate interest — art. 7, IX |
| Benchmark performance against competitor profiles | Public metrics of professional profiles nominated by the client | Legitimate interest — art. 7, IX |
| Bill the contracted plan and issue tax documents | Billing and invoicing data | Performance of a contract — art. 7, V; and compliance with a legal or regulatory obligation — art. 7, II |
| Keep access and audit records; prevent fraud and abuse | Access logs, IP, date and time, action performed, author | Compliance with a legal obligation — art. 7, II (Internet Civil Framework, art. 15); and legitimate interest in security — art. 7, IX |
| Provide support and answer requests | Messages exchanged and contact details | Performance of a contract — art. 7, V |
| Defend our rights in judicial or administrative proceedings | Strictly what the case requires | Regular exercise of rights — art. 7, VI |
What we do not do. We do not sell, rent or trade personal data. We do not use client or public data for our own or anyone else's advertising. We do not build behavioural profiles of individuals for ad targeting. We do not use data collected through Meta's APIs to train general-purpose artificial intelligence models.
Automated classification of comments
So that reports show not just how many comments arrived but what the mood was, we automatically classify each public comment as positive, neutral or negative and assign it a topic (for example, price, delivery time or customer service).
Three things matter about how this works:
- It runs locally. Classification is performed by a language model running on our own infrastructure. Comment text is not sent to any third-party AI service, is not used to train models, and does not leave our environment for this purpose.
- It decides nothing about anyone. The label feeds an aggregate chart in a marketing report. It is not used to block, hide or moderate comments automatically, it does not set anyone's price or commercial terms, and it produces no legal effect or significant impact on the person who commented.
- It makes mistakes, and we know it. No classifier is perfect, especially with irony and with comments mixing praise and complaint. That is why the label is always treated as an aggregate estimate, never as a judgement about a specific person.
Even so, art. 20 of the LGPD gives you the right to request review of decisions made solely on the basis of automated processing. If a comment of yours was classified and you want to contest it, write to itacontabilidade@terra.com.br: we will review the case and, if you prefer, remove the classification.
Who we share it with
We do not sell personal data. We share only what is necessary, with parties who need it for the service to work, and always under a contractual duty of confidentiality and purpose limitation.
| Who | Role | What they receive, and why |
|---|---|---|
| Meta Platforms | Source of the data and independent controller | Receives the requests we make on behalf of the connected account — including the content you publish through the platform. Meta's own processing is governed by its privacy policy, not by this one. |
| Asaas | Processor | Handles billing and payment for contracted plans (Pix, bank slip and card). Receives the data needed to issue and settle the charge. |
| Google Fonts | Processor | Delivers the typefaces used on this page and in the platform. When loading the font, your browser tells Google your IP address and technical request data — as with any resource loaded from another domain. |
| The contracting client company | Recipient | The reports, metrics and comments relating to its own accounts. This is the point of the service: the work is delivered to the client. |
| Public authorities | Recipients | Only on a court order, a request from a competent authority, or another legal obligation. In those cases we require the request to be formal and reasoned, and we comply strictly within its limits. |
If BossYou ever goes through a merger, acquisition or corporate reorganization, data may be transferred as part of the business. In that case we will give prior notice, and the receiving party will be bound by the same commitments set out in this policy.
International transfers
Our operation and our data are in Brazil. There are, however, two unavoidable international transfers, both arising from third-party services:
- Meta Platforms — calls to the Facebook and Instagram APIs are processed on Meta's infrastructure, mostly in the United States. This transfer is necessary for the performance of the contract you entered into with us (LGPD, art. 33, VI): without it, there is no social network integration.
- Google Fonts — loading the typefaces sends technical request data to Google servers outside Brazil.
In both cases the transfer is limited to what is strictly necessary for the purpose. If we later start using cloud providers based abroad, we will update this section before the change takes effect and adopt the safeguards required by art. 33 of the LGPD.
How long we keep it
We keep each kind of data for as long as the purpose that justified it requires. After that it is deleted or anonymized — and anonymized data, which no longer identifies anyone, ceases to be personal data (LGPD, art. 12), so aggregate historical indicators may remain in reports.
| Category | Period | Why |
|---|---|---|
| Account and sign-up data | While the account exists, and up to 6 months after closure | To allow reactivation and settle outstanding matters |
| Meta access token | While the connection exists | Destroyed on disconnection, on revocation by Meta, or on a deletion request — whichever comes first |
| Collected posts and metrics | 24 months | To allow year-over-year comparison in reports |
| Comments, mentions and their classifications | 24 months | To track sentiment over time. The classification is deleted together with the comment |
| Projects, tasks, approvals and attachments | For the term of the contract, and up to 12 months after it ends | To evidence what was delivered and approved |
| Application access logs | 6 months | Legal obligation — Internet Civil Framework, art. 15 |
| Audit records | 5 years | Accountability and incident investigation |
| Tax, accounting and contractual documents | 5 years | Legal obligation and tax limitation periods. These documents are not deleted on request |
Security
No system is immune, and promising absolute security would be dishonest. What we can describe precisely are the measures we actually take:
- Encrypted traffic. All communication with the platform and with Meta's APIs happens exclusively over HTTPS.
- Credentials kept out of the codebase. Meta access tokens live in protected configuration files, outside the code repository and version control, readable only by the process that makes the calls.
- Tokens never appear in logs. The API client automatically strips any token from log text and error messages before writing them. When a token fails, the error identifies the affected client — never the credential.
- Per-client isolation. Every stored record mandatorily carries the identifier of the client it belongs to, and an automated check fails if any record is ownerless or points to a client that does not exist. Ownership of a record is never inferred from which credential fetched it.
- Comment text processed locally. Sentiment classification runs on our own infrastructure, with no transmission to external services.
- Restricted access. Only the team members who need to operate a client's account can access that client's data, and significant actions are recorded with author and timestamp.
- Passwords. Stored only as a cryptographic hash. Not even we can read them.
In the event of a security incident that may create relevant risk or harm to data subjects, we will notify Brazil's National Data Protection Authority (ANPD) and the affected people within a reasonable time, describing what happened, which data was involved and the measures taken — as required by art. 48 of the LGPD.
Found a vulnerability? Write to itacontabilidade@terra.com.br. We welcome responsible disclosure and take no action against anyone who reports in good faith.
Your rights
Art. 18 of the LGPD gives you the right, at any time and free of charge, to request:
- Confirmation that we process data about you;
- Access to the data we hold about you;
- Correction of incomplete, inaccurate or outdated data;
- Anonymization, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law;
- Portability to another provider, upon express request;
- Deletion of data processed on the basis of your consent;
- Information about who we share your data with;
- Information about the option not to give consent and what follows from that;
- Withdrawal of consent, where consent is the basis for the processing.
On top of that, you may object to processing grounded in legitimate interest (art. 18, § 2) and request review of automated decisions (art. 20) — see Automated classification of comments.
How to exercise them
Write to itacontabilidade@terra.com.br with the subject “LGPD — [the right you want to exercise]”. Say what you are asking for and include the information that lets us locate your data (same list as the next section).
We will acknowledge within 5 business days and respond within 15 days of the request. If the case is complex and needs more time, we will explain why and give a new deadline before the first one expires.
We may ask for additional information to confirm your identity before acting. This is not bureaucracy: it is what stops someone else from accessing or erasing your data by pretending to be you.
How to request deletion of your data
Anyone can request deletion of their data — with or without an account with us, including people who only commented on a page we manage.
Send an email to itacontabilidade@terra.com.br with the subject “Data deletion — BossYou Manager”.
What to include in the request
The more precise it is, the faster and more safely we can locate exactly your data.
- Always: your full name and an email address for our reply.
- If you use the platform: the email on your account and the name of the workspace or organization.
- If you connected Meta accounts: which Facebook Pages, Instagram profiles or ad accounts are involved.
- If you only commented on one of our pages: your Facebook or Instagram username and, if possible, the link to the post. Without it we cannot tell which comments are yours — it is the only key we hold.
- Optional: tell us whether you want everything deleted or only part of it (for example, just the comments).
Timeline
We acknowledge within 5 business days and complete the deletion within 30 calendar days of the request, or explain in writing, within that window, why we cannot delete something — and which legal basis requires us to keep it.
What we erase
- Your account, profile, credentials and workspace memberships;
- Meta access tokens: we revoke the credential with Meta and destroy the copy we hold;
- The asset connection: we disconnect the linked Pages, Instagram accounts and ad accounts, ending any future access;
- The posts, metrics and comments we collected through that connection, and the sentiment classifications derived from them;
- The comments and mentions attributed to your username, where the request comes from a member of the public who interacted with a page;
- Projects, tasks, internal comments and attachments you authored;
- Your support messages.
What we must keep, and why
The LGPD permits — and sometimes requires — retention of certain data even after a deletion request (art. 16). In our case:
- Tax, accounting and contractual documents, for 5 years, as a legal obligation (art. 16, I);
- Application access logs, for 6 months, as required by the Internet Civil Framework, art. 15 (art. 16, I);
- Audit records of what was done on the platform, for as long as needed for accountability and the regular exercise of rights (art. 16, II and III);
- Aggregate, anonymized indicators already incorporated into historical reports — figures that identify no one and therefore are no longer personal data (art. 12).
Outside those cases, deletion is permanent: data is removed from our active databases and from backup copies on the following backup rotation cycles.
You can remove BossYou Manager at any time under Settings & privacy → Settings → Apps and websites on Facebook. That immediately stops our access to your accounts — and we recommend doing it.
But that removal alone does not erase the data we have already collected. To have it actually deleted, also send the email described above. That is what this page is: our app's data deletion instructions.
Cookies and local storage
This policy page uses no cookies and loads no trackers. The only request to another domain is the typeface loading — see Who we share it with.
On the platform, usage is equally restricted:
- Strictly necessary cookies: keep you authenticated during the session and protect forms against forged requests. Without them, signing in is impossible. Because they are indispensable to the service you asked for, they do not depend on prior consent.
-
Local storage (
localStorage): holds interface preferences — visual theme, active workspace and display settings. It stays on your device and is not sent to our servers. Clearing site data in your browser erases all of it.
We do not use advertising cookies, cross-site tracking, or third-party analytics tools. There is therefore nothing to decline in a consent banner — which is also why this page does not show one.
Children and teenagers
BossYou Manager is a professional tool intended for companies and for people over 18. We do not direct the service at children or teenagers and do not knowingly collect their data.
Public comments collected from client pages may occasionally have been written by a minor, without any way for us to know. If we identify, or are informed by a guardian, that we hold data of a child or teenager without the legal grounds required by art. 14 of the LGPD, we will delete that data as soon as possible. Parents and guardians can request deletion through the same channel described in How to request deletion of your data.
Changes to this policy
This policy may change when we launch new features, switch a supplier, or when the law requires it. When that happens:
- We update the “Last updated” date and the version number at the top of this page;
- For material changes — a new purpose, a new category of data, a new recipient or a longer retention period — we give notice by email and in-app at least 15 days before it takes effect;
- Where a change requires consent, we will ask for fresh consent — earlier processing is not retroactively expanded.
The version in force is always the one published on this page, at
https://bossyoumedia.com/privacy.
Data Protection Officer and contact
The Data Protection Officer (in Brazilian law, the encarregado) is the channel of communication between you, BossYou and the National Data Protection Authority, under art. 41 of the LGPD.
- Data Protection Officer
- BOSSYOU MEDIA AGENCIA DE MARKETING LTDA
- itacontabilidade@terra.com.br
- Phone
- +55 11 4688-1953
- Address
- Est. Doutor Cícero Borges de Morais, 1850, Andar 1, Vila Universal, Barueri/SP, ZIP 06.407-000, Brazil
Use this same channel for questions about this policy, to exercise any right under art. 18, to request deletion of your data, or to report a security issue.
If you are not satisfied with our response, you may lodge a complaint with Brazil's National Data Protection Authority (ANPD) at gov.br/anpd.