Privacy Policy
Last updated: October 1, 2026
This Privacy Policy describes how FlakeDesk ("we"), a customer operations and CRM platform operated by VentureCode, collects, uses, stores, shares, and protects personal data, in compliance with the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018) and other applicable legislation.
By using FlakeDesk (the application at flakedesk.com and subdomains) or interacting with channels operated by our customers through the platform, you agree to the practices described in this policy.
1. Who we are and our roles
FlakeDesk is a multi-tenant CRM software (SaaS) used by customer organizations to manage contacts, companies, sales pipelines, and customer service, including via WhatsApp.
- For platform user account data (name, email, access credentials), FlakeDesk acts as the controller.
- For data entered or received by customer organizations (contacts, companies, messages, attachments), FlakeDesk acts as the processor, handling data according to the instructions of the customer organization, which is the controller.
2. Data we collect
Account and platform usage data:
- Name, email, profile picture, and login method (Google, Microsoft, or email/password);
- Language, preferences, and access records (IP address, date/time, session identifiers);
- Audit logs of actions performed on the platform.
CRM data (processed on behalf of the customer organization):
- Registered contacts and companies: name, email, phone, role, company, notes, tags, and custom fields;
- Interaction history, follow-ups, pipelines, and attached documents.
WhatsApp message data (official Meta WhatsApp Business Platform integration):
- Phone number, profile name, message content, and media sent/received in conversations between you and the customer organization;
- Delivery metadata (sent, delivered, read).
Chat widget data on customer websites:
- Name, WhatsApp number, and message voluntarily provided by you in the chat form on the customer organization's website.
Technical data: strictly necessary cookies for authentication and session.
Product usage measurement: inside the application we use Google Analytics to understand which screens are used and where the product fails, on the basis of our legitimate interest in improving the service you subscribed to (LGPD, art. 7, IX). We record the screen path with record identifiers already stripped (for example, /contacts/:id instead of the contact number), plus technical browser data. We also record which actions were taken, from a closed list declared in code (for example, "contact created", "reply sent in the inbox"), along with labels that identify no one, such as the channel used or the signup source, and the organization's subscription plan, so we can compare adoption across plans. We do not send your organization's or your user's identifier. We donot send the content of your data, customer names, messages or files. You can turn this measurement off at any time under Profile → Account → Usage measurement; the choice applies to the device where it was made.
Measuring our ads (public website only, and only if you allow it): when you reach flakedesk.com through a Google ad, the page address carries a click identifier (gclid, gbraid or wbraid). If, and only if, you choose Accept all in the cookie banner, we keep that identifier for up to 90 days in your browser (cookie flakedesk_ads_click) and carry it through to the creation of your account. When an organization subscribes to a paid plan, we tell Google Ads, from our servers, that the click led to a purchase, sending only the amount, currency and time of the purchase and a verification code derived from the subscription (no name, email, organization or plain subscription identifier). The purpose is to measure how our ads perform, based on your consent (LGPD, art. 7, I), which you can withdraw at any time through Manage cookies in the site footer: withdrawing deletes the identifier stored on the site. Once the purchase has been sent, or if the subscription is not completed, we delete the identifier from our records. If you have already created an account, the identifier also stops being used when you turn off measurement under Profile → Account → Usage measurement. We do not run remarketing and we do not allow ad personalization: Google's ad_personalization category stays disabled at all times. Inside the authenticated application we do not use advertising cookies.
3. How we use the data
- To provide, operate, maintain, and improve the platform;
- To authenticate users and protect accounts;
- To enable customer service via WhatsApp and other channels on behalf of customer organizations, including creating contact records (leads) from received messages;
- To send operational platform notifications;
- To offer artificial intelligence features (team assistant, insights, summaries and support chatbot), processing only the data necessary for the requested functionality. The organization administrator can disable the assistant at any time in the settings;
- To comply with legal and regulatory obligations and exercise rights in legal proceedings.
Legal bases (LGPD, art. 7): performance of a contract, legitimate interest (security, fraud prevention, and service improvement), compliance with legal obligations, and consent, where applicable.
4. Data sharing
We do not sell personal data. We share data only with:
- Meta Platforms (WhatsApp Business Platform): for sending and receiving WhatsApp messages; processing by Meta is governed by Meta's own policies;
- Infrastructure providers: Google Cloud Platform (hosting, database, and file storage), with data encrypted in transit and at rest;
- Artificial intelligence provider: Google Cloud (Vertex AI), under FlakeDesk's account, for the AI features included in the plans. The data sent (excerpts of contacts, companies, interactions and messages needed for the question) is not used to train models. If the organization chooses to connect its own AI provider (OpenAI, Anthropic or a compatible endpoint), processing by that provider is governed by the agreement between the organization and the provider;
- Login and calendar providers (when you connect them): Google and Microsoft, limited to the purposes you authorize;
- AI providers (when enabled by the customer organization): only the content necessary for the functionality, according to the organization's configuration;
- Public authorities, when required by law or court order.
5. Google Workspace data (Limited Use)
When you connect your calendar, FlakeDesk requests a single scope — https://www.googleapis.com/auth/calendar.events — required to create, update and display the events tied to your follow-ups. We do not request access to other calendars, we do not list your calendars and we do not query your availability.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
- No calendar data reaches any AI model. We do not use, transfer or sell this data to create, train or improve foundational or generalized AI or machine learning models, our own or third-party. The FlakeDesk assistant's tools read only contacts, companies, interactions and the organization's own knowledge base;
- Your events are not stored. They are read live from your account for display on the calendar screen and are never persisted in our databases;
- The authorization is revocable. The token is stored encrypted and bound to your user; you can disconnect at any time from your Profile, which also removes the connection.
6. International transfer
Data may be processed on servers located outside Brazil (currently the United States, via Google Cloud). We adopt appropriate contractual and technical safeguards, pursuant to articles 33 et seq. of the LGPD.
7. Security
- Encryption in transit (TLS) and at rest;
- Integration credentials (such as WhatsApp tokens) stored encrypted;
- Logical data isolation per organization (multi-tenant);
- Role-based access control, audit logging, and the principle of least privilege;
- Private file storage with authenticated and authorized access;
- Antivirus scanning of every uploaded document, performed on our own infrastructure (the file is not shared with third parties); files with threats are refused and never stored.
8. Retention and deletion
We keep personal data only for as long as necessary for the purposes of this policy, the customer organization's instructions, and legal obligations. Upon termination of the contract with the customer organization, data is deleted or anonymized within the agreed timeframes, except for retention required by law.
Documents uploaded by the organization (proposals, contracts, receipts, and other files) are kept in FlakeDesk's storage (Google Cloud, us-east1 region), accessible only to authorized people within the same organization. A deleted document stays in the trash for 30 days before permanent deletion. Deleting a user's account does not delete the organization's documents: they are the organization's data, not the individual user's.
9. Your rights (LGPD, art. 18)
You may request: confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about sharing, and withdrawal of consent.
- If you are a platform user, contact us directly through the channels below.
- If you are a contact/customer of an organization that uses FlakeDesk (e.g., you talked to a company via WhatsApp or its website chat), please direct your request preferably to that organization, which is the controller of your data; we will support the handling of your request.
10. How to delete your data
You can request deletion of your account and personal data at any time, through two paths:
- Without needing the app: through the page Delete my data. Enter your account email and we send a confirmation link.
- Inside FlakeDesk: under Profile → Account → Delete account.
What is deleted
Your account, profile (including your profile picture and the files you attached to feedback), access credentials, sessions, calendar connections (Google/Outlook), your conversations with the AI assistant, the assistant's memory, notifications, feedback and personal preferences. Where your e-mail address appeared in records that remain (invitations, access requests, the history of e-mails sent to you), it is removed or replaced by an anonymous marker.
What remains, and why
- Contacts, companies, interactions and customer conversations belong to theorganization using FlakeDesk. It is the controller of that data, and you operated it as its representative. Those records stay with the organization, unlinked from your account(without identifying you as the owner). To request their deletion, the request must go to the organization itself.
- Audit records and tax/accounting obligations are retained for the legal periods (LGPD art. 16) and then erased. The personal identifier is removed at deletion time.
Timelines
Deletion happens 15 days after confirmation. During that period you can cancel through the emailed link or in the app. Once completed, we email you a record of it. Backup copies are overwritten in the normal retention cycles, within 30 days.
One exception
If you are the only admin of an organization that has other members, deletion stays pending until another person is promoted to admin. Otherwise, your colleagues would lose access to the company account's administration. We email you when this happens. Your deletion right stands: this is only sequencing.
11. Children and adolescents
FlakeDesk is intended for professional use and is not directed at persons under 18 years of age.
12. Changes to this policy
We may update this policy periodically. The current version will always be publicly available, with the update date at the top. Relevant changes will be communicated through the platform's channels.
13. Contact
VentureCode · FlakeDesk
Data Protection Officer (DPO) email: info@flakedesk.com
Website: https://flakedesk.com