ArtHome CRM Privacy Policy
1. Who we are
ArtHome CRM is proprietary software developed, owned and operated by SMILING ATMOSPHERE – LDA, a company registered in Portugal under NIPC 517944596, with registered office at Rua Capitão Salgueiro Maia, nº 3, 2925-228 Azeitão, Setúbal, Portugal ("Smiling Atmosphere", "we", "us" or "our"). You can contact us at admin@smilingatmosphere.pt.
This Privacy Policy applies to ArtHome CRM and to the Instagram messaging integration operated through the Meta application ArtHome Inbox - Smiling (together, the "Service").
2. Scope
This Privacy Policy explains how personal data is processed in connection with the ArtHome CRM website, user accounts, support services, Meta and Instagram integrations, connected professional Instagram accounts, Instagram Direct conversations, comment-management functions where enabled, lead and customer workflows, booking and branch operations, technical logs and related server-side integrations.
The Policy also covers Meta Lead Ads and selected Meta Conversions API functions where a business customer has enabled those separate features. It does not govern the separate WorkTime product or unrelated websites and services.
3. Our roles under data protection law
Smiling Atmosphere is the controller for personal data used to operate user accounts, secure and administer the platform, provide support, maintain technical and audit logs, manage the Meta application and comply with legal obligations.
Where an ArtHome business customer determines why and how lead, prospect, student, parent, customer, Instagram correspondent, comment author or branch data is used, that business customer is the controller and Smiling Atmosphere processes the data on its documented instructions as a processor under a data processing agreement. The relevant business customer must provide its own privacy notice at the point where it collects personal data and remains responsible for its communications with individuals.
4. Categories of people
We may process data relating to authorized CRM users; employees, contractors and administrators of business customers; prospective and current customers; students and, where relevant, their parents or guardians; people who send Instagram Direct messages to a connected professional account; people who comment on connected Instagram content where comment functions are enabled; people who submit Meta Instant Forms; people who contact sales or support teams; and persons whose data is lawfully entered into ArtHome CRM by an authorized business customer.
5. Data we process
Depending on the enabled workflow and the information submitted, we may process the following categories of personal data.
- Account and access data, including name, business email, role, branch, language, authentication records, login events and permission settings.
- Connected Instagram account data, including the professional account identifier, username, account type, profile details, connection status, granted permissions and token-related technical metadata. Access tokens and application secrets are protected server-side and are not displayed to ordinary CRM users.
- Instagram correspondent data made available by Meta for an authorized messaging interaction, which may include an Instagram-scoped user identifier, username, profile name, profile image and other profile fields made available through the applicable API.
- Conversation data, including incoming and outgoing message text, timestamps, conversation and message identifiers, delivery or processing status, reactions, replies, story or post references and the identity of the authorized CRM user who handled a conversation.
- Attachments and media associated with a message, including images, videos, audio, files, media identifiers, temporary media URLs and related metadata made available by Meta. The Service processes only the media needed to display, route or respond to the conversation.
- Comment data where the feature is enabled, including comment text, identifiers, timestamps, author details made available by Meta, moderation status and replies sent by an authorized user.
- Meta lead data, including lead ID, form responses, name, contact details and information voluntarily supplied in an Instant Form where the separate Lead Ads integration is enabled.
- Attribution data, including Page, professional Instagram account, form, campaign, ad set, ad and creative identifiers where supplied by Meta and relevant to an enabled workflow.
- CRM activity, including lead or conversation status, assigned user, internal tasks, call notes, appointment, attendance, payment status, loss reason and customer history entered by authorized users.
- Support and communication records, including requests sent to our support channels and actions taken to resolve them.
- Technical and security data, including IP address, device and browser information, timestamps, webhook delivery information, API request logs, security events, error reports and audit logs.
- Selected conversion or outcome events sent to Meta where configured and lawfully permitted.
6. Sources of data
Data may be provided directly by an authorized user or data subject; received from Meta through Instagram APIs and Webhooks when a professional account is connected and a person interacts with it; received from Meta when a person submits an Instant Form; created during a conversation, call, appointment, attendance or service delivery; generated by the platform for security, delivery and audit purposes; or provided by an authorized business customer acting as controller.
7. Why we process data and legal bases
We process personal data to provide and administer the Service; authenticate users and manage permissions; connect authorized Instagram accounts; receive, display, route and respond to Instagram messages; support comment moderation and replies where enabled; maintain customer, scheduling and conversation history; receive and route leads; support sales and branch follow-up; measure lead outcomes; send selected conversion events to Meta; prevent fraud and secure the platform; provide support; maintain records; handle data subject requests; and comply with law.
Depending on the context, the legal basis may be performance of a contract, steps requested before entering a contract, compliance with a legal obligation, legitimate interests in operating and securing a business service and responding to communications, consent where legally required, or processing on behalf of a controller under its documented instructions. A business customer is responsible for selecting and documenting the lawful basis for its own marketing, messaging, comment-management and customer-management activities.
8. Instagram integration and permissions
An authorized business customer may connect a professional Instagram account to the Service through Meta's authorization process. The integration may request the permissions needed to identify the connected professional account, manage Instagram messages and manage comments where that function is enabled. The permissions currently relevant to the integration are instagram_business_basic, instagram_business_manage_messages and instagram_business_manage_comments.
We use these permissions only for the features shown to and authorized by the business customer. Connecting an account allows the Service to receive relevant webhook events, retrieve data needed for an authorized conversation or comment workflow and send replies from the connected professional account. The integration does not provide unrestricted access to a person's private Instagram account.
9. Meta Platform Data
When an authorized business connects Meta assets, ArtHome CRM may receive Platform Data through Meta APIs and Webhooks. We use that data only to provide the enabled integration: identify the connected asset; receive, display, route and respond to authorized Instagram conversations; manage comments and replies where enabled; retrieve and display leads and related advertising context; support legitimate follow-up; maintain required security and audit records; and report selected downstream lead outcomes through an applicable Meta Conversions API integration.
We do not sell Platform Data, use it for surveillance, use it to make prohibited eligibility decisions, combine it with unrelated data for undisclosed purposes or share it except with the relevant controller, authorized users and contracted service providers as permitted by law and Meta terms. We do not use Instagram message or comment content for unrelated advertising or to build independent profiles of individuals.
10. Instagram conversations and replies
Messages are processed when a person contacts a connected professional Instagram account or otherwise takes an action that Meta permits the account to answer through the API. Authorized users may read the conversation and respond through ArtHome CRM on behalf of the connected account. The business customer is responsible for the content, timing and lawfulness of its replies and for complying with Meta's messaging rules, including applicable response windows and restrictions on promotional messages.
Removing the app's Instagram access stops future access through that authorization, but it may not automatically delete records already stored in ArtHome CRM. A separate deletion request can be submitted as described in Section 18.
11. Comments and public interactions
Where comment management is enabled, ArtHome CRM may receive comments and related public interaction data from connected Instagram content, display them to authorized users and allow an authorized user to hide, moderate or reply where the applicable API and permissions allow. A public comment remains subject to the visibility and controls of Instagram. Deleting a CRM record does not necessarily delete the original comment from Instagram, and deleting a comment on Instagram does not necessarily remove a lawfully retained audit record from the CRM.
12. Branch routing and authorized access
ArtHome CRM may route a message, comment, lead or customer record to the appropriate organization, branch or authorized user based on the connected account, selected location, language, assignment rules or actions taken by authorized personnel. Access is limited by role and branch permissions. Business customers must assign access only to people who need it and promptly remove access when a person changes role or leaves.
13. Sharing and service providers
We may share personal data with the relevant ArtHome business customer and its authorized users; Meta Platforms Ireland Limited where the integration requires data exchange; hosting, database, email, communications, monitoring, backup and security providers acting under contract; professional advisers and authorities where legally required; and another party in a lawful corporate transaction subject to appropriate safeguards.
Service providers may process data only for contracted purposes and under appropriate confidentiality, security and data-protection obligations. We do not sell personal data or Meta Platform Data.
14. International transfers
Where personal data is transferred outside the European Economic Area, we use an applicable legal transfer mechanism, such as an adequacy decision or the European Commission Standard Contractual Clauses, together with supplementary safeguards where required. Details may be requested using the contact information below. Meta processes data under its own terms and privacy documentation for the relevant platform services.
15. Retention
We retain personal data only for as long as necessary for the relevant purpose, controller instructions, contractual obligations and applicable law. Unless a controller defines a shorter period or law requires a different period, the implementation baseline is as follows.
- Raw webhook payloads are retained for no more than 30 days after successful processing, except where a shorter technical retention period is used.
- Unconverted lead, contact, Instagram conversation, message, attachment reference and comment-management records are retained for up to 24 months after the last meaningful interaction.
- Customer, booking, attendance, payment and transaction records are retained for the service relationship and any legally required accounting, tax or claims period.
- Connected-account authorization records are retained while the integration is active and for the limited period needed to complete disconnection, security review and audit obligations. Revoked access tokens are deleted or rendered unusable.
- Account data is retained for the account relationship and for up to 90 days after closure, subject to security, contractual and legal requirements.
- Security and audit logs are retained for up to 12 months.
- Support records are retained for up to 24 months.
- Encrypted backups are retained for no more than 90 days before rotation. Deleted data may remain in protected backups until the applicable backup is overwritten and is not restored for ordinary business use.
- Data subject request and deletion records may be retained for as long as necessary to demonstrate compliance and resolve disputes.
16. Security
We use measures appropriate to the risk, including encrypted transport, access controls, role-based permissions, protected server-side secrets, audit logging, rate limiting, backups, monitoring, vulnerability handling and incident procedures. Access tokens, app secrets and passwords must not be stored in ordinary CRM notes or shared through unsecured channels. No method of storage or transmission is completely secure. Users must protect their credentials and promptly report suspected unauthorized access.
17. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and you may withdraw consent where processing relies on consent. Where Smiling Atmosphere processes data only for an ArtHome controller, we may forward the request to that controller and assist it. We may verify identity before acting and will respond within the period required by law.
You may also complain to the Portuguese supervisory authority, Comissão Nacional de Proteção de Dados (CNPD), at https://www.cnpd.pt/.
18. Access removal and data deletion
You can request deletion by following the instructions at https://smilingatmosphere.pt/arthome-crm/data-deletion/ or by emailing admin@smilingatmosphere.pt with the subject "ArtHome CRM Data Deletion Request". Do not send passwords, access tokens or payment-card details.
A person who authorized the Instagram connection may remove the application's access through the Instagram or Meta account settings where available. Access can also be revoked at https://www.instagram.com/accounts/manage_access/. Revoking access prevents future API access under that authorization but does not by itself guarantee deletion of records already stored in ArtHome CRM. Submit a deletion request if existing CRM records should also be deleted.
We handle deletion requests received through available Meta platform channels and the contact methods stated in this Policy. Some information may be retained where required by law, necessary to protect security, needed to establish or defend legal claims or required to demonstrate that a request was handled.
19. Children
ArtHome CRM is a business tool and is not offered directly to children. Business customers may use the platform in connection with services involving minors only where they have an appropriate lawful basis, provide required notices, obtain valid parental or guardian authorization where required, limit access and avoid collecting unnecessary information. Instagram users and connected professional accounts remain subject to Instagram's own age and account requirements.
20. Sensitive information
Users and business customers must not use free-text CRM fields, Instagram messages or internal notes to request or store passwords, access tokens, payment-card details, unnecessary health information or other unnecessary sensitive data. If a person voluntarily sends sensitive information, the business customer must assess whether it has a lawful reason to keep it and delete or restrict it when it is not necessary.
21. Automated processing
ArtHome CRM does not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. Workflow automation may route a message or lead, create a task, apply a status or report an outcome, but authorized personnel remain responsible for decisions and customer communications.
22. Cookies
The login service may use strictly necessary session, authentication, security and preference cookies. If analytics, advertising or other non-essential technologies are introduced, they must not be set before any legally required consent and this Policy and the cookie controls must be updated.
23. Changes
We may update this Policy when the Service, processing activities, Meta requirements or legal requirements change. We will publish the updated date and provide additional notice where a change materially affects individuals. Material changes to Meta data processing may also require an updated App Review submission or renewed authorization.
24. Contact
SMILING ATMOSPHERE – LDA
NIPC 517944596
Rua Capitão Salgueiro Maia, nº 3, 2925-228 Azeitão, Setúbal, Portugal
Email: admin@smilingatmosphere.pt
Website: https://smilingatmosphere.pt