Privacy Policy — FlakeDesk
Last updated: July 2, 2026
This Privacy Policy describes how FlakeDesk ("we"), a customer operations and CRM platform operated by VentureCode, collects, uses, stores, shares, and protects personal data, in compliance with the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018) and other applicable legislation.
By using FlakeDesk (the application at flakedesk.com and subdomains) or interacting with channels operated by our customers through the platform, you agree to the practices described in this policy.
1. Who we are and our roles
FlakeDesk is a multi-tenant CRM software (SaaS) used by customer organizations to manage contacts, companies, sales pipelines, and customer service — including via WhatsApp.
- For platform user account data (name, email, access credentials), FlakeDesk acts as the controller.
- For data entered or received by customer organizations (contacts, companies, messages, attachments), FlakeDesk acts as the processor, handling data according to the instructions of the customer organization, which is the controller.
2. Data we collect
Account and platform usage data:
- Name, email, profile picture, and login method (Google, Microsoft, or email/password);
- Language, preferences, and access records (IP address, date/time, session identifiers);
- Audit logs of actions performed on the platform.
CRM data (processed on behalf of the customer organization):
- Registered contacts and companies: name, email, phone, role, company, notes, tags, and custom fields;
- Interaction history, follow-ups, pipelines, and attached documents.
WhatsApp message data (official Meta WhatsApp Business Platform integration):
- Phone number, profile name, message content, and media sent/received in conversations between you and the customer organization;
- Delivery metadata (sent, delivered, read).
Chat widget data on customer websites:
- Name, WhatsApp number, and message voluntarily provided by you in the chat form on the customer organization's website.
Technical data: strictly necessary cookies for authentication and session. We do not use advertising cookies or cross-site tracking.
3. How we use the data
- To provide, operate, maintain, and improve the platform;
- To authenticate users and protect accounts;
- To enable customer service via WhatsApp and other channels on behalf of customer organizations, including creating contact records (leads) from received messages;
- To send operational platform notifications;
- To offer artificial intelligence features (e.g., suggestions and assistant), processing only the data necessary for the requested functionality;
- To comply with legal and regulatory obligations and exercise rights in legal proceedings.
Legal bases (LGPD, art. 7): performance of a contract, legitimate interest (security, fraud prevention, and service improvement), compliance with legal obligations, and consent, where applicable.
4. Data sharing
We do not sell personal data. We share data only with:
- Meta Platforms (WhatsApp Business Platform): for sending and receiving WhatsApp messages; processing by Meta is governed by Meta's own policies;
- Infrastructure providers: Google Cloud Platform (hosting, database, and file storage), with data encrypted in transit and at rest;
- Login and calendar providers (when you connect them): Google and Microsoft, limited to the purposes you authorize;
- AI providers (when enabled by the customer organization): only the content necessary for the functionality, according to the organization's configuration;
- Public authorities, when required by law or court order.
5. International transfer
Data may be processed on servers located outside Brazil (currently the United States, via Google Cloud). We adopt appropriate contractual and technical safeguards, pursuant to articles 33 et seq. of the LGPD.
6. Security
- Encryption in transit (TLS) and at rest;
- Integration credentials (such as WhatsApp tokens) stored encrypted;
- Logical data isolation per organization (multi-tenant);
- Role-based access control, audit logging, and the principle of least privilege;
- Private file storage with authenticated and authorized access.
7. Retention and deletion
We keep personal data only for as long as necessary for the purposes of this policy, the customer organization's instructions, and legal obligations. Upon termination of the contract with the customer organization, data is deleted or anonymized within the agreed timeframes, except for retention required by law.
8. Your rights (LGPD, art. 18)
You may request: confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about sharing, and withdrawal of consent.
- If you are a platform user, contact us directly through the channels below.
- If you are a contact/customer of an organization that uses FlakeDesk (e.g., you talked to a company via WhatsApp or its website chat), please direct your request preferably to that organization, which is the controller of your data; we will support the handling of your request.
9. Children and adolescents
FlakeDesk is intended for professional use and is not directed at persons under 18 years of age.
10. Changes to this policy
We may update this policy periodically. The current version will always be publicly available, with the update date at the top. Relevant changes will be communicated through the platform's channels.
11. Contact
VentureCode — FlakeDesk
Data Protection Officer (DPO) email: admin@flakedesk.com
Website: https://flakedesk.com