Privacy Policy
Last updated on July 30, 2026
This policy explains how Async Studio (CAETANO APOLLO DA SILVEIRA, CNPJ 68.009.930/0001-40) handles personal data on its institutional website and in its products, including Async Hub — our service desk that unifies WhatsApp and Instagram for small businesses.
What Async Hub does
Async Hub connects a business's WhatsApp and/or Instagram business account (our client, "the store") to our service desk tools, letting the store's team reply to their own customers from a single screen instead of switching between the WhatsApp and Instagram apps.
We do not sell access to this data, do not use it for targeted advertising, and do not use it for any purpose beyond providing the service desk the store contracted.
What data we process
To provide this service, Async Hub receives and stores, on behalf of the contracting store: the store's customer data (name, when available, WhatsApp phone number or Instagram profile identifier), the content of messages exchanged between the customer and the store, and conversation metadata (channel used, message timestamps, service stage).
This data reaches Async Hub through Meta's official APIs (WhatsApp Cloud API and Instagram Messaging API), via webhooks configured with the store's own authorization.
Legal basis and purpose
Processing this data serves the sole purpose of enabling the service requested by the store's own customer when they start a conversation via WhatsApp or Instagram — under Brazil's LGPD (Law 13,709/2018), the legal basis is contract performance requested by the data subject and the store's legitimate interest in serving someone who already reached out to it.
Data sharing
We do not share, sell or rent this data to third parties. We use cloud infrastructure providers (such as Supabase) as data processors under our responsibility, with technical isolation between each client store's data.
Security
Access tokens for Meta's APIs are stored with additional encryption, independent of database-level encryption. Each client store only has access to its own data, enforced at the database level. Internal access is role-based (admin/agent) within each client store.
Retention and deletion
Data is kept for as long as the store keeps Async Hub contracted. At any time, the data subject (the store's customer) or the store itself may request deletion or anonymization of a specific contact's data by writing to asyncstudio@outlook.com.
Your rights (LGPD)
Anyone whose data is processed through Async Hub may request, by contacting asyncstudio@outlook.com: confirmation of processing and access to the data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary data; portability to another provider; and deletion of data processed under consent, where applicable.
Changes to this policy
This policy may be updated to reflect changes in the service or in applicable law. The last update date is always shown at the top of this page.
Contact
Questions about this policy or how your data is handled: asyncstudio@outlook.com.