Skip to content

Your data rights

Last updated: 2026-04-14

This page describes the rights you have over the personal data Postato processes and how to exercise them. The rights described here are grounded in the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and the EU General Data Protection Regulation (GDPR, Regulation 2016/679).

1. Who is the controller

The controller of your personal data is Postato. For any request related to this page, write to privacy@postato.com.br.

2. Your rights

You can exercise the following rights at any time, free of charge:

  • Access. Confirm that Postato processes data about you and access that data (LGPD art. 18, II; GDPR art. 15).
  • Rectification. Correct incomplete, inaccurate or outdated data (LGPD art. 18, III; GDPR art. 16).
  • Erasure. Request deletion of personal data (LGPD art. 18, VI; GDPR art. 17). Detailed in section 3.
  • Portability. Receive your data in a structured, commonly used format (LGPD art. 18, V; GDPR art. 20).
  • Anonymization, blocking or deletion of unnecessary data. When processing is excessive or not compliant with the law (LGPD art. 18, IV).
  • Information about sharing. Learn which public and private entities Postato has shared your data with (LGPD art. 18, VII).
  • Withdrawal of consent. Withdraw consent at any time when it is the legal basis for processing (LGPD art. 8, §5; GDPR art. 7).
  • Objection and review of automated decisions. Object to processing and request human review of decisions made solely on automated processing (LGPD art. 20; GDPR art. 22).

3. Data deletion

If you connected a social network account (Instagram, LinkedIn, TikTok, X/Twitter, YouTube) to Postato and want to request deletion of your data, there are two paths.

Immediate disconnect from the dashboard. You can disconnect any network at any time under Integrations → Account → Disconnect. This revokes the authorization token immediately.

Formal request by email. Send an email to privacy@postato.com.br with subject [DATA DELETION] and include:

  • The email of your Postato account
  • The handle or identifier of the social network involved
  • Whether you want full deletion of the Postato account or only the unlinking of a specific network

What is deleted.

  • OAuth authorization tokens for the connected network (access and refresh)
  • The social account record, including external identifier and profile metadata
  • The link between posts published by that account and the network's identifier. Internal post metadata (status, delivery history, audit logs) is kept for the legal retention period, but the link to your network identifier is removed.
  • Webhooks configured specifically for that account

Deadline. We fulfill the request within 30 calendar days, in line with LGPD (art. 19) and GDPR (art. 12). We reply with confirmation when deletion is complete.

4. How to request

For any right listed in section 2, send an email to privacy@postato.com.br indicating:

  • Which right you want to exercise
  • The email of your Postato account
  • Enough detail to locate your data (for example, social network identifier, period, data type)

We may request additional information to confirm your identity before fulfilling the request, as permitted by LGPD (art. 18, §5) and GDPR (art. 12, §6).

5. Timelines

  • Acknowledgment: within 2 business days.
  • Final response: within 15 days for access and portability (LGPD art. 19, II) and within 30 calendar days for deletion and other rights. In complex cases we may extend by up to 60 additional days (GDPR art. 12, §3), informing you of the extension.

6. Justified refusal

We may refuse a request in limited cases, always with written justification:

  • When the requester's identity cannot be confirmed
  • When the data must be kept due to a legal or regulatory obligation, or for the exercise of rights in judicial, administrative or arbitration proceedings (LGPD art. 16)
  • When the request is manifestly unfounded or excessive (GDPR art. 12, §5)

7. Complaints

If you believe your rights have not been respected, you can file a complaint with the competent authority:

  • Brazil: National Data Protection Authority (ANPD) — www.gov.br/anpd
  • European Union: the data protection authority of your country of residence

Before that, we would be grateful if you wrote to privacy@postato.com.br so we can try to resolve the matter directly.

8. Changes to this page

This page may be updated. The "Last updated" date at the top reflects the most recent version.

9. Contact

For any matter related to data protection and the rights described here: privacy@postato.com.br