Privacy Notice
Last updated: August 5, 2026
This is a convenience translation. The official version of this Privacy Notice is the Brazilian Portuguese version, which prevails in the event of any discrepancy.
What we do with your information
We have done our best to explain, in a clear and simple way, which personal data we will need from you and what we will do with each of them. That's why we have highlighted below the most important points, which can also be read in a complete and detailed way in our Privacy Notice.
In addition, we are always available to answer any questions you may have via our website https://www.groselia.com/pt, by phone (11) 95931-2868, and by email at pedro@groselia.com and danilo@groselia.com.
To talk specifically about the User's personal data, we have a specific channel: pedro@groselia.com
Who is responsible for the processing of data? We are controllers of the processing of personal data relating to our clients — that is, once the contracting company chooses to use our services, we will request certain information and make decisions in order to provide our service in the best and safest way possible. We are processors of the personal data of third parties entered into our solutions by the contracting company — that is, we process data based on the decisions of our clients, the controllers. The User is fully responsible for determining the purposes of the data to be processed through the platform, for defining the legal bases most appropriate to such processing, and for informing data subjects in advance about the sharing of data with Groselia. The User must not include on the platform any data or information without the knowledge and/or specific consent (when applicable) of the data subject and/or their legal representative. Likewise, the User will be responsible for deleting the personal data they enter on the platform while the account remains active, and must directly address data subjects' requests, with Groselia following their instructions. In addition, there are also some processors and/or sub-processors engaged by Groselia that may carry out the processing of personal data, such as legal counsel, developers, technology partners, servers, among others. Sub-processors may have access to Users' personal data only to enable the part of the Groselia solution provided by them, and following the same rules set out here.
How will we keep your data secure? Groselia cares deeply about the security of your personal data. That is why it implements the measures suggested by the National Data Protection Authority (ANPD) in its Guidance Manual for Small-Scale Data Processing Agents, which comprises a variety of security technologies and procedures to help protect your information.
What data do you need to provide us to use our platform? To register and use our services, you must provide: Client User: full name, email, phone number, CPF, billing data and billing address, access password, and the authorization credentials (access tokens) voluntarily granted when connecting your Instagram, Facebook, and Threads accounts via official Meta login. The content, images, texts, and brand information that the client enters on the platform are also collected. For Client Users that are legal entities, the company name and CNPJ will also be collected. Administrator User (Groselia team): full name, corporate email, and access credentials.
For what purposes do we use your personal data? All your data is processed for specific purposes and in accordance with the General Data Protection Law. We may process this information to: Provide our service; Provide support and customer service; Send sales- and marketing-related contacts; Offer our services or products. To better understand what we do with the information, we provide a table in our Privacy Notice.
With whom do we share your personal data? We will share your data with strictly necessary third parties, in the cases mentioned in the Privacy Notice, in cases of legal consent from the data subject, and pursuant to a court order or legal determination.
Will your access logs be collected? When you access our platform, we collect your access logs — that is, the set of information relating to the date, time of use, IP address, and logical access port of a given internet application from a given logical access port. This information will be kept by Groselia, under confidentiality, in a controlled and secure environment, for a minimum period of 6 (six) months, pursuant to Law No. 12.965/2014 and Article 7, II, of Law No. 13.709/18.
Will personal data be collected indirectly? In addition to access logs, we may also collect some information indirectly, in accordance with our Cookie Policy.
Will communication records be stored? We will also store the conversations you have with us through our communication channels, as this will improve your service, make it more efficient, and be used as evidence/proof of the service.
What are your rights? Even if you have already provided us with your personal data, you have the full right, at any time, to request from the controller: confirmation of the existence of processing of your data; access to your data; correction of your data; anonymization of data; blocking or elimination of unnecessary or excessive data, or data processed in noncompliance with the Law; portability of data to another provider; elimination of data, except that required by law; information about with whom the controller has shared data; information about the possibility of not giving consent and the consequences of refusal; and to withdraw and revoke your consent at any time.
What is the content of the Privacy Notice? The following Privacy Notice is divided as follows to make it easier for you to access information: Date the Text was Made Available; Explanation of Technical Terms or Foreign-Language Terms; Data Processing Agents; Information Security; Data Collection; Processing of Personal Data; Cancellation of the Platform, Access Accounts, and Data Deletion; Rights of the Data Subject; Changes to the Privacy Notice; Privacy Communication Channel; Contact for General Matters.
Groselia.
Before accessing the Groselia platform, it is important that you read, understand, and freely, unambiguously, and knowingly accept this Privacy Notice.
This platform, named Groselia, is owned and maintained by ARGIBEE COMÉRCIO E CONSULTORIA EM TI LTDA., a private legal entity registered with the CNPJ/ME under No. 65.129.849/0001-05, headquartered at Rua São Jerônimo dos Poções, nº 769, Vila Mirante, São Paulo/SP, CEP: 02.955-030.
This document aims to provide information about the collection, use, and storage ("processing") of the data provided by Users, and complies with Law No. 12.965/2014 (Brazilian Internet Civil Rights Framework) and Law No. 13.709/18 (General Data Protection Law).
1. DATE THE TEXT WAS MADE AVAILABLE
1.1. This document was drafted and made available on August 5, 2026.
2. EXPLANATION OF TECHNICAL OR FOREIGN-LANGUAGE TERMS
2.1. Below are the meanings of technical terms and terms in English:
API (Application Programming Interface): a set of protocols and tools that enables automated communication between different software systems. Groselia uses Meta's official APIs to publish content and collect metrics on behalf of Client Users.
Campaign: a set of publications planned and scheduled on the Groselia platform for distribution on the Client User's social media, which may include texts, images, videos, and other content formats.
Controller: a natural or legal person, governed by public or private law, who is responsible for decisions regarding the processing of personal data.
Cookies: small text files that are stored on the internet user's computer and can be retrieved by the website that sent them during browsing. They are mainly used to identify and store information about Users.
Encryption: a set of principles and techniques for encoding writing, making it unintelligible to those who do not have access to the agreed-upon conventions.
Personal data: information related to an identified or identifiable natural person.
Sensitive personal data: personal data concerning racial or ethnic origin, religious belief, political opinion, union or religious, philosophical, or political organization membership, data concerning health or sex life, genetic or biometric data, when linked to a natural person.
Data Protection Officer (Encarregado): a person appointed by the controller and processor to act as a communication channel between the controller, data subjects, and the National Data Protection Authority (ANPD).
Artificial Intelligence (AI): technology that enables machines to process information, identify patterns, make decisions, solve problems, and adapt to new situations based on large volumes of data, often without direct human intervention. AI seeks to replicate, expand, and improve human cognitive capabilities, using techniques such as machine learning, neural networks, and natural language processing.
IP (or Internet Protocol): a unique identifier for each computer connected to a network.
Processor: a natural or legal person, governed by public or private law, who processes personal data on behalf of the controller.
Logical access port: a number that complements the IP address and is used to identify which specific device or user made a connection at an exact moment, commonly used when multiple users share the same public IP.
Access Token: a temporary digital credential generated by Meta and voluntarily provided by the Client User when connecting their social media accounts to the Groselia platform, authorizing publications and the collection of performance data on their behalf.
Data processing: any operation carried out with personal data, such as those relating to collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, elimination, evaluation or control of information, modification, communication, transfer, dissemination, or extraction.
User(s): the person(s) who use(s) the platform's services.
2.2. Types of platform Users:
2.2.1. Client User: an individual or legal entity that hires Groselia to automate the creation and publication of content on their social media, approving campaigns, managing the publication calendar, and tracking performance metrics.
2.2.2. Administrator User: an employee or staff member of Groselia, responsible for managing client accounts, configuring the platform, providing support, and administering internal operations.
2.2.3. These Users, together, will be referred to simply as Users.
3. DATA PROCESSING AGENTS
3.1. We are controllers of the processing of personal data relating to Users — that is, once the User registers on our platform or uses our tools, we will collect certain information and make decisions in order to provide our service in the best and safest way possible.
3.2. We are processors of the personal data of third parties entered into our solutions by the contracting company — that is, we process data based on the decisions of our clients, the controllers.
3.2.1. The User is fully responsible for determining the purposes of the data to be processed through the platform and for defining the legal bases most appropriate to such processing.
3.2.2. The User is fully responsible for informing data subjects in advance about the sharing of data with Groselia, and must not include on the platform any data or information without the knowledge and/or specific consent (when applicable) of the data subject and/or their legal representative. Likewise, the User will be responsible for deleting the personal data they enter on the platform while the account remains active, and must directly address data subjects' requests, with Groselia only following their instructions, when applicable and necessary.
3.2.3. Furthermore, the Client User must establish data protection compliance processes, which include, but are not limited to, preparing the necessary documents and processing data in observance of the law, the rules published by the National Data Protection Authority (ANPD), and the rules relating to its activities.
3.2.4. Accordingly, the Parties undertake to respect and act in accordance with the duties imposed on data processing agents by Law No. 13.709/2018, being liable solely for their own actions, with the innocent Party entitled to a right of recourse in cases of noncompliance and penalties, including judicial penalties and those applied by the ANPD.
3.3. The platform may use third parties (sub-processors) to provide certain functionalities, who will have access only to the data strictly necessary to carry out such operations. Examples of these sub-processors, as well as the purposes for which the data will be processed, include:
3.3.1. Meta Platforms Inc. (Instagram, Facebook, Threads): responsible for receiving the content to be published on the Client User's accounts and for returning the performance metrics of the publications. Access to the User's accounts occurs exclusively through express authorization granted by the User themselves via official Meta login, and may be revoked at any time.
3.3.2. Artificial Intelligence Providers [Anthropic, PBC; OpenAI, LLC; Firecrawl (Mendable AI, Inc)]: responsible for processing texts and briefings provided by the User for the purpose of generating and optimizing content. The transfer of data to these providers is limited to what is strictly necessary for performing the content creation functionality.
3.3.3. Stripe: responsible for processing financial transactions, including subscription billing and invoice management. The transfer of data is restricted to the information necessary for billing.
3.4. Our engagements always prioritize the secure processing of User information. Therefore, from the moment these companies have access to this data, they become responsible for the security, processing, and proper sharing of this information, and may not disclose it for other purposes, in noncompliance with applicable law or this Privacy Notice, under penalty of being held liable for all sanctions, particularly civil and criminal sanctions and those applied by the National Data Protection Authority.
3.5. International transfer: The personal data processed by Groselia may be transferred to servers located outside Brazil, specifically to the United States, in order to ensure the proper provision of the services offered.
3.5.1. These transfers are carried out in accordance with Law No. 13.709/18 (LGPD) and CD/ANPD Resolution No. 19/2024, safeguarded by appropriate protection mechanisms for international data transfers, including the Standard Contractual Clauses approved by the ANPD. In addition, we adopt appropriate security measures whenever we carry out such transfers, ensuring compatible levels of protection for personal data.
4. INFORMATION SECURITY
4.1. Groselia cares deeply about the security of your personal data. That is why it implements the measures suggested by the National Data Protection Authority (ANPD) in its Guidance Manual for Small-Scale Data Processing Agents, which comprises a variety of security technologies and procedures to help protect your information.
4.1.1. In addition, we have effective measures and controls to prevent or reduce Information Security risks, with an approach focused on the Principles of the subject matter, in order to prevent, detect, respond to, and quickly recover from a threat to protect the confidentiality, integrity, and availability of technological assets and information — such as, for example, encryption of data in transit (HTTPS/TLS) and at rest, password storage with hashing, role-based access control and least-privilege principles, secure authentication, access log recording, periodic backups, and monitoring of suspicious activity.
4.2. All access logs — the set of information relating to the date, time, source IP address, and source logical port relating to the use of a given internet application from a given source logical port — will be kept by Groselia, under confidentiality, in a controlled and secure environment, for a minimum period of 6 (six) months, pursuant to Law No. 12.965/2014 and Article 7, II, of Law No. 13.709/18.
4.3. Groselia is committed to preserving the stability, security, and functionality of the platform through technical measures consistent with encouraging good practices. However, no service available on the internet has total protection against illegal intrusions. In cases where unauthorized third parties illegally breach the system, Groselia will make its best efforts to identify the party responsible for the unlawful act, but is not liable for the damages they cause.
5. DATA COLLECTION
5.1. To register and use Groselia's services, the following information will be required:
5.1.1. Client User: full name, email, phone number, CPF, billing data and billing address, access password, and the authorization credentials (access tokens) voluntarily granted when connecting your Instagram, Facebook, and Threads accounts via official Meta login. The content, images, texts, and brand information that the client enters on the platform are also collected. For Client Users that are legal entities, the company name and CNPJ will also be collected.
5.1.2. Administrator User (Groselia team): full name, corporate email, and access credentials.
5.2. Contact history: Groselia stores information about all interactions already carried out with Users, whether through the website, WhatsApp, or email platform, as this will improve your service, make it more efficient, and be used as evidence/proof of the service.
5.3. Information we collect indirectly: in addition to access logs, we may also collect some information indirectly, in accordance with our Cookie Policies, such as browsing and usage data, including IP address, device type, browser, operating system, pages accessed, date and time of access, and activity logs. With the Client User's express authorization, the Platform also receives, via Meta's official APIs, data regarding the connected accounts, such as account identifier, username, publications, and performance metrics (reach, impressions, and engagement).
6. PROCESSING OF PERSONAL DATA
6.1. By accepting this Privacy Notice, the User understands that the collection and processing of the personal data below is necessary for the performance of the contract with Groselia, as set out below.
Type of Personal Data: User's First and Last Name and/or Company Name. Legal Basis: Necessary for the performance of a contract or preliminary procedures related to a contract to which the data subject is a party, at the data subject's request (Art. 7, V, Law No. 13.709/2018). Purpose: Used for identification and verification of the User. This is essential personal data to enable contacting the User to address their requests and provide targeted responses.
Type of Personal Data: User's Email / Mobile Phone Number. Legal Basis: Necessary for the performance of a contract or preliminary procedures related to a contract to which the data subject is a party, at the data subject's request (Art. 7, V, Law No. 13.709/2018). Purpose: In the case of email, it is used for validating and logging into the platform. In addition, both are used as a means of communication with the User for contacts and interactions throughout the User's journey on the Platform.
Type of Personal Data: CPF or CNPJ (Brazilian tax ID). Legal Basis: Compliance with a legal or regulatory obligation by the controller (Art. 7, II, Law No. 13.709/2018). Purpose: Used for contractual qualification. This is essential personal data to clearly identify the contracting party, and is necessary for billing, issuing invoices and tax documents, payment management, and accounting/financial obligations.
Type of Personal Data: Billing address. Legal Basis: Compliance with a legal or regulatory obligation by the controller (Art. 7, II, Law No. 13.709/2018). Purpose: Necessary for billing, issuing invoices and tax documents, payment management, and accounting/financial obligations.
Type of Personal Data: Billing and payment data. Legal Basis: Necessary for the performance of a contract or preliminary procedures related to a contract to which the data subject is a party, at the data subject's request (Art. 7, V, Law No. 13.709/2018). Purpose: Processing subscription payments and financial management of the contract, through transfer to the authorized payment processor.
Type of Personal Data: Conversation history. Legal Basis: Necessary to serve the legitimate interests of the controller or a third party (Art. 7, IX, Law No. 13.709/2018). Purpose: Creating a history for the User, facilitating communication, increasing effectiveness in resolving inquiries, and improving the User's experience with the services provided by Groselia.
Type of Personal Data: Access log (IP address, date and time of access) and Source Logical Port. Legal Basis: Compliance with a legal or regulatory obligation by the controller (Art. 7, II, Law No. 13.709/2018). Purpose: Compliance with Article 15 of Law No. 12.965/2014, which imposes on Groselia the duty to keep the respective internet application access logs, under confidentiality, in a controlled and secure environment, for a period of 6 (six) months.
Type of Personal Data: Technical credentials and integration metadata (tokens and keys). Legal Basis: Necessary for the performance of a contract or preliminary procedures related to a contract to which the data subject is a party, at the data subject's request (Art. 7, V, Law No. 13.709/2018). Purpose: Configuring and maintaining the flow between Meta applications and Groselia, enabling the publication of content and reading of performance metrics on the User's Instagram, Facebook, and Threads accounts, exclusively as authorized by the User via official Meta login.
Type of Personal Data: Publication performance metrics (received via the Meta API). Legal Basis: Necessary for the performance of a contract or preliminary procedures related to a contract to which the data subject is a party, at the data subject's request (Art. 7, V, Law No. 13.709/2018). Purpose: Generating performance reports for the Client User (reach, impressions, engagement).
Type of Personal Data: Browsing data (device, browser, operating system, pages accessed). Legal Basis: Necessary to serve the legitimate interests of the controller or a third party (Art. 7, IX, Law No. 13.709/2018). Purpose: Used to improve the User's experience, optimize platform performance, and prevent fraud and ensure system security.
Type of Personal Data: Data that may be entered by the User (Content, images, texts, and brand information entered on the Platform). Legal Basis: In this case, Groselia is the data Processor and the legal bases must be defined by the Controller. Purpose: In this case, Groselia is the data Processor and the purposes for which the data will be used must be defined by the Controller.
6.2. Groselia provides on the platform a virtual assistant based on Artificial Intelligence to create, schedule, and publish content on the Instagram, Facebook, and Threads accounts of client companies.
6.3. Conversations are stored in the User's own logged-in account environment, encrypted at rest, and are not accessed by Groselia on a routine basis. Administrative access will only occur in specific, justified cases, recorded in an audit trail.
6.3.1. The conversations, data, and documents entered by the User are not used to train or improve third-party Artificial Intelligence models.
6.3.2. The information used by the assistant is exclusively that voluntarily provided by the User. This data is shared with partner technology providers solely for the purpose of processing the prompt (command) provided and returning the response requested by the User during the session.
6.4. The processing of interactions is carried out with the support of third-party large language models (LLMs), provided by [Anthropic, PBC; OpenAI, LLC; Firecrawl (Mendable AI, Inc)]. We recommend reading the Terms of Use and Privacy Notices of these systems before using the assistant.
6.5. By choosing to use the AI assistant, the User declares that they are aware of and agree that:
a) All of their actions and decisions are made freely and autonomously, and it is up to them to interpret the responses generated and decide on their use;
b) The responses are produced automatically by algorithms, without direct human intervention. They may vary depending on the context and are subject to technical limitations of understanding, and may present flaws, inaccuracies, or systemic hallucinations;
c) The use of the assistant for prohibited purposes, including the prohibited conduct defined in the Terms of Use, is the sole responsibility of the User;
d) The User may, at any time, request clarifications or a review of the information generated by the assistant through Groselia's official service channels.
6.6. Groselia acts merely as an integrator of the AI solution, responsible for configuring the tool within the platform. It has no technical control over the processing infrastructure, storage, or internal security mechanisms of the contracted technology providers, and is not liable for events beyond its sphere of control.
6.6.1. Groselia reserves the right to change, restrict, suspend, discontinue the AI assistant, or replace the underlying technology providers at any time. Any subsequent regulatory changes may result in the immediate adaptation or removal of the tool, without giving rise to any right of compensation for the User.
7. CANCELLATION OF THE PLATFORM, ACCESS ACCOUNTS, AND DATA DELETION
7.1. Cancellation of access accounts by Groselia: Groselia may, at its sole discretion, block, restrict, disable, or prevent any User's access to the platform whenever inappropriate conduct is detected.
7.2. Cancellation of access accounts by the User: to cancel the services and request deletion of the access account, the User must submit the request through one of the following channels: by email to pedro@groselia.com or danilo@groselia.com, by WhatsApp at +55 (11) 95931-2868, or through the cancellation option available in the account settings on the platform dashboard.
7.2.1. For more information about cancellation, see our Terms of Use.
7.2.2. The Client User may revoke the platform's access to their Meta accounts at any time, through the settings of the social network itself or through the Groselia dashboard, which immediately stops the collection of new data.
7.3. When the purpose of data processing ends, or upon a deletion request sent to pedro@groselia.com, the data will be subject to a prior review to verify whether there are legal or regulatory grounds authorizing or requiring their retention. Once this review is complete, the data will be permanently and irreversibly deleted, except for: (i) data whose retention is mandatory under applicable law or regulation; (ii) data necessary for the regular exercise of rights in judicial, administrative, or arbitration proceedings; and (iii) access logs, which will be kept under confidentiality, in a controlled and secure environment, pursuant to Law No. 12.965/2014 — in all cases, observing the minimum legally required retention period.
8. RIGHTS OF THE DATA SUBJECT
8.1. The data subject has the right to obtain from the controller, regarding the data processed about them, at any time and upon request:
8.1.1. Confirmation of the existence of data processing.
8.1.2. Access to the data.
8.1.3. Correction of incomplete, inaccurate, or outdated data.
8.1.4. Anonymization, blocking, or elimination of unnecessary or excessive data, or data processed in noncompliance with Law No. 13.709/2018.
8.1.5. Portability of data to another service or product provider, upon express request, in accordance with the regulations of the national authority, subject to trade and industrial secrets.
8.1.6. Elimination of data processed with the data subject's consent, except in the cases provided for in Law No. 13.709/2018.
8.1.7. Information about the public and private entities with which the controller has shared data.
8.1.8. Information about the possibility of not giving consent and the consequences of refusal.
8.1.9. Withdrawal of consent.
8.2. Should Groselia receive a request from data subjects to exercise their rights, it will be up to the Client User to address the data subject directly.
9. CHANGES TO THE PRIVACY NOTICE
9.1. Groselia may unilaterally add and/or modify any clause contained in this Privacy Notice. The updated version will apply to use of the platform from the date of its publication. Continued access to or use of the platform after such disclosure will confirm Users' acceptance of the new Privacy Notice.
9.2. If the change made requires the User's consent, the option to freely, unambiguously, and knowingly accept the new text or decline it will be presented.
9.3. If the User does not agree with the change, they may withhold consent for specific acts or may fully terminate their relationship with Groselia. Such termination will not, however, exempt the User from complying with all obligations assumed under previous versions of the Privacy Notice.
10. PRIVACY COMMUNICATION CHANNEL
10.1. Groselia informs that, being owned by a startup/small company, it is exempt from appointing a data protection officer, pursuant to CD/ANPD Resolution No. 2 of January 27, 2022.
10.2. Nevertheless, it emphasizes that your privacy remains our priority, and therefore provides the following channel for communication about any matter involving the User's personal data: pedro@groselia.com
10.3. If the communication concerns third-party data entered on the platform by the User, the User must themselves provide a communication channel for that purpose.
10.4. Groselia has a specific document to govern the license to use, rights, duties, guarantees, and general provisions: the Terms of Use. All of these documents are inseparably part of this Privacy Notice.
11. CONTACT FOR GENERAL MATTERS
11.1. Groselia provides the following channel to receive all communications that Users wish to make: website https://www.groselia.com/pt, by phone (11) 95931-2868, and by email at pedro@groselia.com and danilo@groselia.com