⚠ Draft — not legal advice
This document is a technical draft prepared for legal review. It is under review with MisAbogados (attorney Ricardo Cantero, case 25762) and does not constitute legal advice nor a final version enforceable against third parties. Law 21.719 (Chile) takes effect around December 2026; this text is drafted to be operative by that date.
Registered address. The current address is Cochrane 639, Of. 54, Valparaíso, per the articles of incorporation and the compliance file. The Meta Business Manager record contains a typo (“630”); HERIHE DIGITAL LTDA. decided on 2026-09-06 not to correct it, to avoid reopening the already completed business verification. Separately, the legal pages currently live on herihe.digital still state Santiago, Chile and a different responsible entity — that remains open and is listed under pending decisions.
1. Provider identification
| Legal name | HERIHE DIGITAL LTDA. |
|---|---|
| Tax ID (RUT) | 78.389.881-0 |
| Registered address | Cochrane 639, of. 54, Valparaíso, 2361806, Chile Discrepancy — see notice above |
| Website | https://herihe.digital/ |
| Data protection contact | datos@herihe.digital |
| Phone | +56 9 4043 5095 |
| Business | Digital marketing and automation agency. Based in Chile, serving clients in CL, BR, US, ES, PE and MX. |
Hereinafter "HERIHE", "the Company" or "we". The party engaging or using the services is "the Client" or "you".
2. Acceptance and scope
By engaging a service, creating an account, requesting a free diagnostic or analysis, authorising access to an advertising or analytics account, or using any HERIHE digital product (together, "the Service"), you accept these Terms and Conditions. If you do not agree, do not use the Service.
These Terms are supplemented by: (a) the Privacy Policy; (b) the signed proposal, quotation or statement of work, where one exists; and (c) the Data Processing Agreement (DPA) where HERIHE processes personal data on the Client's behalf. In case of conflict, the signed contract prevails first, then the DPA, and lastly these Terms.
3. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Controller: the party that determines the purposes and means of processing.
- Processor: the party that processes personal data on behalf of and under the instructions of the controller.
- Data subject: the natural person to whom the data relates.
- Platform Data: information obtained from third-party platforms (Meta, Google, Apple and others) through application programming interfaces (APIs), federated login, or authorised integrations.
- Deliverables: assets, reports, campaigns, copy, images, automations and configurations produced for the Client.
4. Description of services
Depending on what is engaged in each case, HERIHE provides:
- Paid media: planning, execution and optimisation of campaigns on Google Ads and Meta Ads, among other networks.
- CRM and email marketing: deployment and operation of Mautic (self-hosted) and of the Client's equivalent platforms.
- Automation: n8n workflows, conversational support with Chatwoot, and integrations between the Client's systems.
- Landing pages and web assets: design, development, measurement and publication.
- B2B prospecting: list building, verification, and cold outreach campaigns in a professional context.
- Artificial intelligence agents: assistants and automations supported by language models.
- Self-serve tier: a subscription platform whose features and current pricing are published on the product's pricing page.
Diagnostics or analyses offered free of charge are commercial materials and create no contractual obligation for either party.
5. Account, eligibility and credentials
- You must be 18 or older and legally capable of entering into a contract.
- The information you provide must be truthful, current and complete.
- You are responsible for keeping your credentials confidential and must notify us immediately of any unauthorised use.
- When you grant us access to third-party accounts (Google Ads, Meta Business Manager, analytics, stores, CRM), you represent that you are authorised to do so and to authorise the processing of the data they contain.
- Tokens and credentials delegated to us are stored encrypted, with access restricted to the technical staff assigned to that account, and are revoked when the engagement ends.
6. Acceptable use
You may not use the Service to:
- Produce unlawful, deceptive or discriminatory content, or content infringing third-party rights.
- Reverse engineer, perform mass scraping, or gain unauthorised access to internal systems.
- Resell platform capacity, quotas or output without express authorisation.
- Generate spam, phishing or disinformation, or breach applicable law.
- Share credentials with third parties you have not authorised.
You further undertake to comply with the terms of the linked platforms (Google, Meta, Apple, payment providers and others) and with the acceptable use policies of the artificial intelligence providers involved in the Service.
7. Client obligations regarding its own data
Where HERIHE acts as a processor, the Client is the controller and accordingly:
- Warrants that it has a valid legal basis for the data it provides or gives us access to, and that it has informed data subjects as required by applicable law.
- Determines the purposes, targeting and content of communications.
- Must forward to us without delay any data subject requests it receives, so that we can assist.
- Is responsible for the lawfulness of any lists it supplies, including those obtained from third parties.
HERIHE may refuse or halt an instruction that, in its reasonable judgement, would breach applicable law or platform policies.
8. Intellectual property
8.1 What is ours
HERIHE's code, internal databases, proprietary prompts, automations, infrastructure, methodology and trade marks are the exclusive property of the Company. No licence is granted over these assets.
8.2 What is yours
Deliverables produced specifically for the Client belong to the Client once approved and once the corresponding period has been paid. The Client retains ownership of its brand, content, data and linked accounts.
8.3 Licence you grant us
You grant us a limited, non-exclusive licence to process your data and content for the sole purpose of providing the Service. This licence ends when the engagement is cancelled, except for what we must retain by legal obligation.
9. Plans, pricing and payment
- Billing: monthly, annually or per project, as set out in the proposal or on the product's current pricing page.
- Renewal: subscription plans renew automatically until you cancel.
- Plan changes: upgrades are prorated; downgrades take effect from the following cycle.
- Add-ons: charged per usage and do not renew automatically.
- Taxes: prices exclude VAT and other local taxes, which are added according to the Client's country.
- Failed payments: after three failed attempts the account is suspended; after 30 days without regularisation it is archived.
- Media spend: budget paid to Google, Meta or other networks is distinct from HERIHE's fees and is governed by the proposal. Upon request by the end advertiser, we will disclose the amount spent on advertising on their behalf, our fees, and the associated fee structure.
10. Cancellation, refunds and exit
- Cancellation: you may cancel at any time; access continues until the end of the paid period.
- Refunds: as a general rule there are no refunds for periods already started; exceptions are assessed case by case where the Service is defective through our fault.
- Grace period: the first 7 days of the first month are fully refundable, no questions asked.
- Orderly exit: when the engagement ends you have 30 days to export Deliverables and revoke credentials. After that we delete the data, except what we must retain by legal obligation (see section 15).
11. Availability
- Monthly uptime target: 99.5% on higher tiers. No formal service level is guaranteed on entry tiers.
- Maintenance windows: announced 48 hours in advance, typically overnight Chile time.
- If an incident attributable to HERIHE causes more than 24 continuous hours of unavailability, a proportional credit is applied in the following cycle.
12. Use of artificial intelligence
- Part of the Service generates content using artificial intelligence models. That content is a creative tool, not professional advice.
- Outputs require human review before publication. You are responsible for verifying accuracy, legality and suitability.
- We do not guarantee specific commercial results (leads, sales, return on ad spend).
- We do not use your data or your Deliverables to train third-party artificial intelligence models.
- Significant decisions — approving campaigns, changing prices, sending bulk communications — always require your human approval.
- We do not make automated decisions producing legal effects or similarly significantly affecting a data subject without human involvement. You may request review of any automated decision.
13. Personal data protection: dual role
HERIHE acts in two distinct capacities, and the law applies differently to each:
| Data set | HERIHE's role | Who determines purposes |
|---|---|---|
| B2B prospects in our own commercial database | Controller | HERIHE |
| HERIHE workers and collaborators | Controller | HERIHE |
| Visitors to our sites and our own analytics | Controller | HERIHE |
| Client databases, CRM, stores and audiences we operate | Processor | The Client |
| Client advertising campaign data | Processor | The Client |
13.1 Purposes and legal bases (controller role)
| Purpose | Legal basis | Data used |
|---|---|---|
| Delivery of contracted services | Performance of a contract | Name, email, phone, company |
| Commercial communications and B2B prospecting | Legitimate interest (*) | Name, corporate email, job title, company |
| Newsletter and content delivery | Consent | |
| Service analysis and improvement | Legitimate interest | Browsing and interaction data |
| Compliance with legal obligations | Legal obligation | As applicable |
(*) For B2B prospecting we maintain a documented balancing test under Article 16 quinquies of Law 21.719, available on request at datos@herihe.digital.
13.2 Retention periods
| Data type | Retention period |
|---|---|
| Active client data | Duration of the engagement + 5 years |
| Prospect data with no response | 12 months from last contact |
| Prospect data where an objection was raised | Deleted; only the minimum is kept on the suppression list |
| Browsing data | 12 months |
| Billing data | Statutory tax period (6 years) |
| Platform Data (Meta, Google and others) | For as long as the authorisation lasts; deleted within 30 days of revocation or end of contract |
13.3 Processors and sub-processors
We process data with the support of providers acting under our instructions or the Client's. The principal ones are:
| Provider | Function | Processing country |
|---|---|---|
| Google LLC (Ads, Analytics, Search Console, Tag Manager, Merchant Center, Workspace) | Advertising, analytics and email | United States |
| Meta Platforms, Inc. | Advertising, audiences and messaging | United States |
| DigitalOcean | Compute infrastructure | United States |
| cPanel hosting | Web hosting | United States |
| Mautic (self-hosted by HERIHE) | Email marketing and CRM | On the infrastructure above |
| Chatwoot (self-hosted by HERIHE) | Conversational support | On the infrastructure above |
| SendGrid | Transactional email delivery | United States |
| Anthropic · OpenAI | Language models and transcription | United States |
| Apify · Apollo · Hunter | B2B data collection, enrichment and verification | European Union / United States |
| Fathom | Meeting transcription | United States |
| Salesforce Marketing Cloud · Klaviyo | Email marketing for specific clients | United States |
| Transbank · MercadoPago · Flow · Bsale | Payments and invoicing | Chile and region |
We do not sell or transfer personal data to third parties for those parties' own purposes, nor do we use it for creditworthiness assessment. The current sub-processor list is available at datos@herihe.digital.
Full detail of what data we collect and how is set out in the Privacy Policy.
14. Third-party platforms
This section sets out, platform by platform, what data we receive, what we use it for, and how it is deleted. The structure is extensible: when a new platform is added, a card or a row is added to the table in 14.4 without rewriting the document.
14.1 Meta (Facebook, Instagram, WhatsApp Business) In use
What data we receive
- Client campaign metrics and configuration via the Marketing API: spend, impressions, clicks, conversions, audiences, and account and campaign identifiers.
- User identifiers scoped to an app or page (
app-scoped/page-scoped ID), public name, profile picture, and any contact details the user chooses to provide in a conversation. - Message content from Messenger, Instagram Direct and WhatsApp Business where the Client engages us to operate its conversational support.
- Data on pages and advertising assets managed by the Client.
What we use it for
- Auditing, optimising and reporting on the performance of the Client's campaigns.
- Responding to and following up on conversations the person initiates with the Client.
Limits we accept
- We do not sell, license or purchase Meta Platform Data, and we do not transfer it to data brokers.
- We process Platform Data only for the purposes described in this document and in the Privacy Policy. Platform data not described here is not processed.
- Data obtained from Messenger, Instagram Direct and WhatsApp conversations is not used for prospecting, list enrichment, or any purpose beyond supporting that conversation. Those people do not enter our B2B commercial database.
- One Client's advertising data is never combined with another's. It is used only on an aggregate and anonymous basis, and only to assess the performance of the campaigns of the advertiser it came from.
How it is deleted
Write to datos@herihe.digital with the subject "Data deletion", or follow the procedure in section 15. In addition, on Facebook you can go to Settings & Privacy → Settings → Apps and Websites, remove the application, open View Removed Apps and Websites, select it and click Send Request. When the integration is disconnected, we delete the associated Platform Data within the periods stated in section 15.
14.2 Google In use
What we receive and why
When a Client authorises us via Google OAuth, we access data from their Google account ("Google user data") for the sole purpose of delivering the contracted services:
| API and scope | Data accessed | Purpose |
|---|---|---|
Google Ads API (auth/adwords) | Campaign metrics, keywords, ads, budgets, conversions and account identifiers | Audit, optimisation and reporting |
Google Analytics (auth/analytics.readonly) | Aggregate reports on sessions, conversions and behaviour | Results measurement |
Search Console (auth/webmasters.readonly) | Queries, pages, impressions and organic positions | SEO/AEO diagnosis and planning |
Tag Manager (auth/tagmanager.readonly) | Inventory of tags, triggers and variables | Measurement audit |
Merchant Center (auth/content) | Feed and product status | Catalogue diagnosis |
Where it is stored and who it is shared with
OAuth tokens are stored encrypted on infrastructure under our control, with access restricted to the technical staff assigned to that account. Extracted data is retained for the duration of the contractual relationship. We do not share Google user data with third parties, other than with the infrastructure processors listed in 13.3, under a processing agreement and solely to host or process it on our behalf. We do not sell it, do not use it for targeted advertising, do not use it to train generalised artificial intelligence models, and do not use it for creditworthiness assessment.
Limited Use
Google Analytics and cookies
We use Google Analytics on our sites. You can review how Google collects and processes this data at "How Google uses information from sites or apps that use our services". The parties that may collect, receive or use data through cookies and similar identifiers on our sites are HERIHE DIGITAL LTDA., Google LLC and Meta Platforms, Inc. Except for strictly necessary cookies, they are set only with your consent, we keep a record of that consent, and you may withdraw it at any time by writing to datos@herihe.digital.
How to delete and how to revoke
You may revoke our access at any time at myaccount.google.com/permissions or by writing to datos@herihe.digital. On revocation we stop accessing immediately and delete extracted data within a maximum of 30 days.
Scope changes
If in future we need access to a type of data not described here, we will update this document and the Privacy Policy and request your consent before accessing it.
14.3 Apple Applies once an app exists
HERIHE does not currently publish any app of its own on the App Store. This section applies from the moment HERIHE publishes an app, or builds and operates one on a Client's behalf, and from then on we undertake to:
- Publish a link to the privacy policy both in the App Store Connect metadata field and within the app in an easily accessible manner, identifying what data is collected, how it is collected, and all uses of that data.
- Confirm that any third party with whom the app shares user data — analytics tools, advertising networks, third-party SDKs, and any related entities — provides the same or equal protection of user data as stated in the policy.
- Explain retention and deletion periods, and how a user can revoke consent or request deletion.
- Offer account deletion from within the app itself, not only by email, wherever the app supports account creation.
- Keep the App Privacy declarations on the store listing consistent with the app's actual behaviour.
- Offer Sign in with Apple where the app offers third-party federated login and the rule is applicable, and respect the private relay email address Apple generates.
Data received by mobile apps is governed by the same purpose, retention and deletion rules described in sections 13 and 15.
14.4 Other platforms
Extensible table. Each row states what data is received, for what purpose, and by what route it is deleted.
| Platform | Status | Data we receive | Purpose | How to delete |
|---|---|---|---|---|
| WhatsApp Business Platform | In use | Phone number, profile name, message content | Support and commercial follow-up on the Client's behalf | datos@herihe.digital or section 15; on disconnecting the integration |
| WooCommerce / Shopify | In use | Order, contact and address data of the Client's buyers | Synchronisation, automation and measurement of the Client's commerce | Request to the Client (controller) or to HERIHE as processor |
| Stripe · MercadoPago · Transbank · Flow | In use | Transaction status and minimum billing data. We do not store card numbers. | Payment collection and document issuance | Subject to tax retention periods; see 13.2 |
| Occasional use | Public professional data in a B2B context | Prospecting and segmentation in a professional context | Objection or erasure via datos@herihe.digital | |
| TikTok for Business | Planned | Campaign metrics and account identifiers | Advertising management on the Client's behalf | On revoking access; erasure within 30 days |
15. Data deletion — instructions
How to request deletion of your data. Write to datos@herihe.digital with the subject "Data deletion", stating: (1) your full name; (2) the email, phone number or social network identifier associated with your data; (3) the source platform, if you know it (Facebook, Instagram, WhatsApp, Google, website, form); and (4) whether you are requesting full deletion or only for a specific purpose, such as commercial communications.
15.1 What happens next
- Acknowledgement: we confirm receipt and give you a tracking code you can use to check the status of your request at any time by replying to the same email.
- Identity verification: we may request minimal additional information to confirm the request comes from the data subject. That information is used only for verification and is then deleted.
- Execution: we delete the data from our active databases, from the email and automation instances we operate, and from working copies.
- Response: we confirm in writing what was deleted, what was retained, and why.
15.2 Deadlines
Deadlines come from the law applicable to each data subject, not from the platforms. We always act as promptly as possible and, at the latest, within the periods set out in section 16. Objection to direct marketing is executed immediately and requires no justification.
15.3 What is retained and why
| What is retained | Why | For how long |
|---|---|---|
| The strict minimum on the suppression list (typically the email in reduced form) | So we can honour your objection and not contact you again | Indefinitely, for as long as the objection stands |
| Tax and billing documents | Statutory tax obligation | 6 years |
| Records needed to evidence compliance with a legal obligation or to defend legal claims | Legal obligation or overriding legitimate interest | The applicable limitation period |
Where retention rests on a legal obligation, we keep proof of the rule that requires it. If we refuse a request in whole or in part, we will explain the reason in writing and in plain language.
15.4 Deletion initiated from the platform
If you withdraw an integration's authorisation directly from Meta or Google, that withdrawal is treated as a request to delete the corresponding Platform Data and is executed within 30 days, with no need to write to us.
16. Rights by jurisdiction
A single text cannot satisfy every regime. The common rules are above; what follows is specific to each jurisdiction. The regime corresponding to your residence or to the place of processing applies.
16.1 Chile — Law 21.719
- Rights: access, rectification, cancellation (erasure), objection, portability and blocking.
- Response deadline: 15 business days from receipt of the request.
- Objection to direct marketing: immediate and requiring no justification. It is enough to reply "I DO NOT WISH TO RECEIVE COMMUNICATIONS" to any email, use the unsubscribe link, or write to the data contact.
- Complaints: to the Agencia de Protección de Datos Personales, once constituted.
- Law 21.719 takes effect around December 2026; until then we voluntarily apply this same standard alongside Law 19.628, currently in force.
16.2 Brazil — LGPD (Law 13.709/2018)
- Rights: confirmation that processing exists; access; correction; anonymisation, blocking or deletion of unnecessary or excessive data or data processed unlawfully; portability; deletion of data processed on consent; information about data sharing; information about the option not to consent; withdrawal of consent; and review of automated decisions.
- Deadlines: confirmation of existence and access are provided immediately in simplified format or, in full declaration, within 15 days. We apply the same 15-day period to the other rights.
- Channel: datos@herihe.digital.
- Complaints: to the Autoridade Nacional de Proteção de Dados (ANPD).
16.3 European Union and EEA — GDPR
- Rights: access, rectification, erasure, restriction of processing, portability, objection (including an absolute right to object to direct marketing), and not to be subject to automated decisions producing legal effects.
- Deadline: one month from receipt, extendable by a further two months where the request is complex or where there are multiple requests; in that case we will inform you within the first month.
- Withdrawal of consent: at any time, without retroactive effect on prior processing.
- Complaints: to the supervisory authority of your Member State.
16.4 California — CCPA / CPRA
- Rights: to know what personal information is collected and with whom it is shared; to delete it; to correct it; to opt out of its sale or sharing for cross-context behavioural advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
- Deadlines: we acknowledge receipt within 10 business days and respond within 45 calendar days, extendable by a further 45 days where reasonably necessary, with notice of the reason.
- No sale or sharing: HERIHE does not sell personal information and does not share it for cross-context behavioural advertising as those terms are defined. Should that change, an opt-out link will be published before it happens.
- Channel: datos@herihe.digital. You may act through an authorised agent on proof of authority.
17. International transfers
Part of our infrastructure and of the providers we use — compute, hosting, and marketing and analytics SaaS — has servers outside Chile, principally in the United States. In those cases we adopt the safeguards required by Law 21.719 (Arts. 27–28) and, where processing falls under the GDPR, the transfer mechanisms set out in its Chapter V. Details of providers and of the instrument applicable to each are available at datos@herihe.digital.
18. Confidentiality and security
Each party will keep confidential the other's non-public information accessed in connection with the Service and will use it only to perform the Service. The obligation survives the end of the engagement.
We apply technical and organisational measures: restricted-access storage, encryption in transit (TLS/SSH), encrypted backups of central databases, access control, traceability of data origin, and a centralised suppression list. In the event of a security breach affecting personal data, we will notify the Client without undue delay and, where applicable, the authority and the data subjects, as required by applicable law.
19. Limitation of liability
To the maximum extent permitted by law:
- HERIHE's total liability to the Client, on any ground, is limited to the amount actually paid by the Client in the 12 months preceding the event giving rise to the claim.
- We are not liable for indirect damages, loss of profit or loss of business opportunity, save in cases of wilful misconduct or gross negligence.
- We are not liable for interruptions, policy changes or decisions by third-party platforms (Google, Meta, Apple, payment providers, artificial intelligence providers) beyond our reasonable control, including advertising account suspensions decided by those platforms.
- Nothing in this clause limits liability that the law declares non-excludable, nor any non-waivable consumer rights.
20. Suspension and termination
We may suspend or terminate the Service if the Client materially breaches these Terms, uses the Service for unlawful or abusive activity, endangers the integrity of the platform, or is more than 30 days in arrears. In non-critical cases we give notice and 48 hours to remedy; in critical security or legality cases, suspension is immediate. On termination, the exit process in section 10 and the deletion process in section 15 apply.
21. Governing law, disputes and consumer rights
- Governing law: the laws of the Republic of Chile.
- Jurisdiction: the ordinary courts of Chile, in accordance with the venue clause to be fixed in the final version (see pending decisions).
- Prior resolution: before commencing proceedings, the parties will attempt direct resolution in writing for at least 30 days.
- Consumers: if you contract as a consumer in Chile, Brazil or the European Union, you retain in full the rights granted by the consumer protection laws of your country, which prevail over this contract wherever they are more favourable to you.
22. Changes
We may amend these Terms for legal, technical or business reasons. Material changes will be notified 30 days in advance by email and by prominent notice on the site. If you do not agree, you may cancel at no cost during that period. Continuing to use the Service after the effective date constitutes acceptance. Every published version states its last-updated date.
23. Contact
- Personal data, rights and deletion: datos@herihe.digital
- Phone: +56 9 4043 5095
- Address: Cochrane 639, of. 54, Valparaíso, 2361806, Chile
- Related documents: Privacy Policy · Data deletion instructions
24. Pending human decision
Points that cannot be settled in the draft and require a decision from HERIHE management, the accountant, or the reviewing attorney before the final version is published.
- Registered address — three versions in circulation.
Cochrane 639, of. 54(Meta Business Manager, verified) ·Cochrane 639, Of. 54(internal document A2) ·Santiago, Chile(legal pages published today). A single address must be settled and corrected everywhere: articles of incorporation, tax authority records, Business Manager, website and these documents. An address that is inconsistent between the public page and the verified record is direct friction in app review and business verification. - Responsible entity — resolved. The controller is HERIHE DIGITAL LTDA. (RUT 78.389.881-0, Valparaíso), confirmed by management on 2026-09-06. The earlier attribution to “Converclick, based in Santiago” is superseded.
- Data contact channel. This draft publishes
datos@herihe.digital; the current site publishesprivacy@herihe.digital,legal@,billing@andhola@. The internal inventory records thedatos@channel as a still-open operational gap. Publishing a mailbox creates the duty to answer it within the deadline: confirm it exists, has an assigned owner, and is monitored before publishing. - Phone number. This draft uses
+56 9 4043 5095; the site's WhatsApp button points to a different number. Decide which is the official contact number. - Venue clause. The conditions published today submit disputes to the courts of Santiago, while the registered office is in Valparaíso. Attorney's decision.
- Response deadline under Law 21.719. This draft keeps the 15 business days from document A2. Confirm against the final statutory text and its regulations.
- Prospect retention. Confirm whether 12 months is sufficient for prospects with no response (open point in A2).
- International transfers. Define the specific instrument per provider (Arts. 27–28 of Law 21.719 and GDPR Chapter V). This is currently a declared gap in the internal inventory.
- Data protection impact assessment. Determine whether the volume and the categories processed — including health and identity data held as a processor for clients — require an impact assessment.
- Meta: deletion route. Choose between a data deletion instructions URL (what this page implements today, in section 15) or a callback URL with a signed endpoint, deletion queue, and status page with a confirmation code. These are alternatives, not cumulative; the second requires development work.
- Google: hosting requirements. The privacy policy must be hosted on the same domain as the declared home page, linked from the site footer and from the OAuth consent screen; the domain must be verified in Search Console by an account holding owner or editor on the Google Cloud project. Confirm that the verifying account is the same as the project's. The Limited Use statement must also be reachable from the home page.
- OAuth scope classification. Verify in the Google Cloud console that the scopes in use are still classified as sensitive rather than restricted. A restricted scope would trigger an annual third-party security assessment and force a redesign of human access to the data.
- Operational conflict: messaging data and prospecting. Meta's policies prohibit using Messenger and Instagram conversation data for any purpose beyond supporting that conversation. The legitimate-interest balancing test for B2B prospecting must expressly exclude that source, and the system must prevent it structurally, not merely in text.
- Segregation of advertising data between clients. Confirm that no process combines one client's campaign data with another's, and document the control as evidence.
- Apple. Decide whether section 14.3 is published now, in anticipation of future apps, or activated only once an app exists. If an app with accounts is published, in-app account deletion stops being optional.
- Tags and cookies on legal pages. The legal pages published today load the tag container without collecting prior consent. Define prior consent for European Union visitors and replace the "browser settings" formulation with a banner that records and allows withdrawal of consent.
- Former-client instances with residual data. The inventory identifies deactivated databases with records still stored. Decide on secure erasure, return to the former client, or retention on an explicit legal basis, before publicly declaring the periods in section 13.2.
- Pricing and plans. Confirm whether the ranges and tiers published in version 1.0 of the site remain current; this draft points to the pricing page instead of restating figures.
- Publication. Define the final URLs — most likely
/terms.html,/pt/terms.htmland/en/terms.html— and adjust the canonical and alternate-language tags, which currently point at this draft's files. The pages must be public, indexable and not geo-blocked so that platforms can validate them. - Effective date and version. Fix the final version and its date, taking into account that Law 21.719 comes into force around December 2026.