Something went wrong.
FlitFlow
☰
Dashboard Build New Automation Your Automations Your Saved Links Your Defaults Best Practices

FlitFlow Privacy Notice

Last updated: September 1, 2026

Privacy at a glance

Who is responsible? CHICK 1, SLU, trading as FlitFlow, is responsible for personal data used for account administration, billing, security, support, legal compliance and operation of the Service. When FlitFlow processes Instagram interactions and Customer Content to run Customer-configured automations, FlitFlow generally acts on the Customer's instructions under the FlitFlow Data Processing Agreement.

What do we process? Depending on how FlitFlow is used, this includes Customer account and billing information; connected Instagram professional-account information; access tokens; publication metadata; comments, direct messages and Story interactions; automation settings; uploaded images; delivery records; follower-verification results; Saved Links; and link-click events.

Why? To connect Instagram accounts, run Customer-configured automations, deliver requested responses, prevent duplicate or abusive sends, operate subscriptions, secure and support the Service, satisfy legal obligations and improve reliability.

Who receives it? Meta and providers used for hosting, databases, private media storage, queues, payments, support, monitoring and scheduled operations. FlitFlow does not sell personal data.

Your rights: You may exercise applicable access, correction, deletion, restriction, objection and portability rights through Help & Requests or legal@flitflow.app. You may also complain to the Spanish Data Protection Agency or another competent supervisory authority.

1. Who we are

The controller for FlitFlow's own processing purposes is:

CHICK 1, SLU, trading as FlitFlow
Valverde 31, 1C, 28004, Madrid, Spain
Registry: Registro Mercantil de Madrid
Tax identification number: B88395652
Contact and Support form: Help & Requests

“FlitFlow”, “we”, “us” and “our” refer to this entity. “Customer” means the person or organization operating a FlitFlow account. “Instagram user” means a person who comments on, messages or otherwise interacts with an Instagram account connected by a Customer.

FlitFlow is an independent service and is not owned, sponsored or endorsed by Meta Platforms, Inc. or its affiliates (“Meta”).

2. When FlitFlow is controller or processor

FlitFlow acts as a controller when it determines why and how personal data is used for account administration, subscriptions and billing, security and abuse prevention, support, service communications, legal compliance and appropriately aggregated service analysis.

For Customer Content and Instagram interactions processed to execute a Customer's configured automations, the Customer generally determines the purpose and essential instructions. In that context, the Customer is normally the controller and FlitFlow acts as its processor under the FlitFlow Data Processing Agreement (“DPA”).

Customers are responsible for providing any notices and establishing any legal basis required for their campaigns and communications. An Instagram user seeking to exercise rights relating to a particular Customer's automation should normally contact that Customer first. The user may also contact FlitFlow, and we will assist or direct the request as appropriate.

3. Personal data we process

3.1 Customer and account information

  • name, organization and contact information provided to FlitFlow;
  • account identifiers, authentication and session information;
  • plan, subscription, allowance, invoice and payment-status information;
  • support communications; and
  • account-security, suspension and audit events.

FlitFlow does not require or store a Customer's Instagram or Meta password.

3.2 Connected Instagram-account information

  • Instagram account ID, username, professional-account and profile information;
  • access and refresh tokens, token-expiry information and granted permissions;
  • connection, removal, suspension and deauthorization state;
  • publication IDs, types, captions, dates, thumbnails and other metadata needed to select, display or match eligible Posts, Reels and Stories; and
  • account ownership and connection audit records.

3.3 Instagram interactions and automation data

  • comment, direct-message, Story-reply, quick-reply and other supported interaction identifiers;
  • usernames or platform-scoped user identifiers supplied by Meta where needed;
  • interaction text and context needed to match a keyword or determine eligibility;
  • automation configurations, trigger terms, response content, buttons, links, images, targeting and status;
  • follower-status results and verification activity where the Customer enables that feature;
  • event, cooldown, deduplication, capacity-reservation and queue records; and
  • delivery attempts, provider responses, outcomes and recovery information.

3.4 Saved Links, images and click information

  • Saved Link names, destination addresses, button labels and usage relationships;
  • Customer-uploaded images after validation and normalization; oversized originals are not retained after successful normalization;
  • private-storage object identifiers and short-lived signed delivery addresses;
  • link identifiers, frozen destinations and delivery attribution;
  • the date and time of a valid tracked-link request;
  • the request method;
  • whether the request matched FlitFlow's limited known-bot classification; and
  • whether it was the first counted click for that delivery.

FlitFlow's application database does not store the visitor's IP address or raw browser User-Agent as part of a click event. Infrastructure providers may process ordinary request information, including IP address, User-Agent and timestamps, in security or access logs. FlitFlow does not place a tracking cookie for link-click attribution or monitor activity on the destination website. The destination website may conduct its own processing under its own privacy notice.

3.5 Technical and usage information

  • request and event timestamps;
  • application, worker, queue and scheduler state;
  • error, security and diagnostic records;
  • browser, device and network information present in ordinary hosting or security logs; and
  • feature usage and service-performance information.

3.6 Sources

We obtain data directly from Customers; from Meta through Customer-granted permissions, webhooks and APIs; automatically when the Service or tracked links are used; from our service providers; and from authorized Customer administrators.

4. Purposes and legal bases

Where EU or EEA data-protection law applies, FlitFlow relies on the following legal bases for processing for which it acts as controller:

Purpose Legal basis
Create and administer accounts, connect Instagram, provide features and manage plans and billing Performance of a contract or requested pre-contract steps; legitimate interests where the Customer is an organization
Execute Customer-configured Instagram automations Contract and legitimate interests for FlitFlow's controller processing; the Customer determines the basis for processing for which FlitFlow acts as processor
Prevent duplicates, apply cooldowns and capacity controls, and recover delivery safely Contract; legitimate interests in reliable and non-abusive operation
Secure the Service and investigate fraud, spam, misuse and unauthorized access Legitimate interests in protecting Customers, Instagram users, FlitFlow and connected platforms; legal obligation where applicable
Provide support and service communications Contract; legitimate interests in administering and supporting the Service
Process payments, invoices, taxes, cancellations and disputes Contract; legal obligation; legitimate interests in accounting and claims management
Process Meta deauthorization and deletion notifications Contract; legitimate interests; legal obligation where applicable
Improve reliability and understand service performance Legitimate interests in maintaining and improving the Service, using minimization and aggregation where practicable
Send optional marketing communications Consent where required; otherwise legitimate interests where permitted, with an unsubscribe option

Where we rely on legitimate interests, we assess necessity and the effects on individuals' rights and freedoms. You may request information about the relevant assessment through [CONTACT FORM URL].

FlitFlow does not sell Instagram data, use it for unrelated advertising profiles, or permit its use for surveillance or sensitive profiling.

5. How the automation works

A Customer configures the keyword, eligible Instagram location, response, links, images, follower-verification setting and activation state. When Meta sends an eligible interaction, FlitFlow may automatically verify and match the event; apply duplicate, cooldown, capacity and platform-eligibility checks; optionally run follower verification; send the configured response; and record delivery state.

These operations may determine whether and when a response is sent, delayed, suppressed or retried. FlitFlow does not use this automation to make decisions that produce legal or similarly significant effects about Instagram users within the meaning of Article 22 GDPR.

6. Recipients and service providers

We disclose personal data only as necessary for the purposes described above, including to:

  • Meta, for account authorization, permitted information retrieval, receipt of interactions and delivery of Customer-configured responses;
  • providers of hosting, databases, private media storage, queues and caches;
  • payment and billing providers;
  • providers of support, email, monitoring and error management;
  • providers that invoke scheduled maintenance operations;
  • professional advisers, auditors and insurers; and
  • courts, regulators, law-enforcement bodies or other recipients where required by law or necessary to protect legal rights.

Service providers are subject to appropriate contractual and confidentiality obligations.

FlitFlow does not sell or rent personal data.

7. International transfers

Meta and some service providers may process personal data outside Spain, the European Economic Area or the country where the individual is located.

Where required, we rely on an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses. Information about applicable safeguards may be requested through Help & Requests.

8. Retention

We retain personal data only for as long as reasonably necessary for the relevant purpose, including providing the Service, safe retry and recovery, security, legal compliance and claims.

Current implementation-specific periods include:

  • cross-account access-denial audit events: 90 days;
  • other account security and ownership audit events: 12 months;
  • normalized uploaded images: while referenced by a live configuration or retryable delivery snapshot and during the historical-display period; the current default historical-display period is 30 days, after which unreferenced images become eligible for scheduled deletion; and
  • short-lived access addresses for private images: the current default expiry is 10 minutes.

Before publication, FlitFlow must finalize sufficiently precise periods or criteria for webhook and trigger history; delivery operations and recovery history; replay-cooldown and reservation history; click-event and token records; account and automation data after cancellation or disconnection; support and security logs; and billing, tax and dispute records. The implemented retention jobs and this Notice must match.

Disconnecting an Instagram account stops its automations and FlitFlow's collection of new data through that connection. It does not cancel the Customer's subscription or immediately delete all previously collected data. Billing, security, legal and permitted retention processing may continue.

Data may be retained longer where required by law or necessary for fraud prevention, security, dispute resolution or legal claims. Where feasible, it will be restricted, anonymized or separated from ordinary product use.

9. Disconnecting Instagram and deleting data

9.1 Disconnecting Instagram

A Customer may disconnect an Instagram account through FlitFlow, where available, or revoke FlitFlow's permissions through Meta. This stops the associated automations and collection of new data through that connection. It does not automatically cancel a subscription, delete the Customer's FlitFlow account or erase previously collected data.

9.2 Deleting a FlitFlow account

A Customer may request deletion of its FlitFlow account through the Contact and Support form at Help & Requests. We may take reasonable steps to verify the requester's identity and authority.

Following verification, we will delete or anonymize personal data associated with the account, except for information we must or are permitted to retain for legal, security, fraud-prevention or claims purposes.

Deleting a FlitFlow account is separate from an individual's exercise of data-protection rights under Section 11.

9.3 Meta deauthorization and data-deletion requests

Meta may notify FlitFlow through separate deauthorization and data-deletion callbacks. Under FlitFlow's current account-cleanup process, a valid callback of either type stops automation activity for the affected account and initiates deletion of its account-associated platform data. This behavior may change if Meta requirements or FlitFlow's account model changes; this Notice will be updated before any materially different processing begins.

FlitFlow verifies the callback and affected identity before deleting anything. It deletes account-associated media and relational account data, except for information that must or may lawfully be retained as described in Section 8. Retained audit records are disassociated from the deleted Instagram-account identifier.

Meta data-deletion requests receive a confirmation code that can be used to check status at:

https://flitflow.app/data-deletion-status/<confirmation_code>

The status page displays only whether the request is pending, completed, or could not be completed. If a request could not be completed, contact us through Help & Requests.

10. Security

FlitFlow uses technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss and destruction. These include access controls, encryption in transit, protected credentials and tokens, private storage, request verification, and controls intended to prevent duplicate or unauthorized processing.

No system is completely secure. Customers are responsible for protecting their own credentials and should promptly report suspected unauthorized access through Help & Requests.

11. Individual rights

Depending on applicable law, you may have the right to:

  • obtain information about and access your personal data;
  • correct inaccurate or incomplete personal data;
  • request deletion;
  • restrict or object to certain processing;
  • object to direct marketing;
  • receive personal data you provided in a structured, commonly used and machine-readable format where portability applies;
  • withdraw consent at any time, without affecting earlier lawful processing; and
  • complain to a competent supervisory authority.

To exercise a right, use Help & Requests or legal@flitflow.app. We may request information reasonably necessary to verify identity and authority.

In Spain, the supervisory authority is the Agencia Española de Protección de Datos (AEPD) (https://www.aepd.es).

Where FlitFlow acts only as processor, we may refer the request to the relevant Customer and assist it as required by the DPA.

12. Children

FlitFlow accounts are intended for persons aged 18 or older. Instagram interactions processed on behalf of Customers may nevertheless involve younger users. Customers are responsible for complying with applicable age, consent, privacy and marketing requirements when configuring and operating their automations.

If you believe a child's personal data has been processed unlawfully through FlitFlow, contact us through Help & Requests.

13. Cookies and similar technologies

FlitFlow uses cookies and similar technologies necessary to authenticate Customers, maintain sessions and protect the Service. These technologies do not require consent where they are strictly necessary to provide the Service requested by the user.

When someone opens a tracked Saved Link, FlitFlow records the link identifier, event date and time, request method, limited bot classification and first-counted-click state so that the Customer can measure link usage. The application does not store the visitor's IP address or raw User-Agent in the click-event record, does not place a tracking cookie for this purpose and does not monitor activity on the destination website. Hosting or security providers may process ordinary request information in their access or security logs as described in Sections 3.5 and 6.

14. Changes to this Notice

We may update this Notice when the Service, providers or legal requirements change. We will publish the revised version with a new “Last updated” date. Where a change materially affects individuals, we will provide additional notice or request consent where required.

15. Contact

Questions, requests and complaints concerning this Notice or FlitFlow's processing of personal data may be submitted through:

CHICK 1, SLU, trading as FlitFlow
Valverde 31, 1C, 28004, Madrid, Spain
Contact and Support form: Help & Requests
Email: legal@flitflow.app


Help & Requests Privacy Terms

© 2026 FlitFlow