Legal

Privacy policy

This policy explains which data MARIA FLORENCIA GONZALEZ processes when operating Wogensy, how it is used, with whom it may be shared and how to request access, correction or deletion.

Effective from: September 28, 2026Version 1.3

1. Scope and controller

MARIA FLORENCIA GONZALEZ operates Wogensy, a platform for managing agencies and their clients. This policy applies to the website, application and connected integrations, including Instagram organic reports, Meta Ads reports and publishing or scheduling content on Instagram and Facebook Pages where that feature is enabled.

When an agency uploads or manages its clients' data, that agency determines the operational use of the information and Wogensy processes it to provide the service. If your inquiry concerns information managed by an agency, we may coordinate our response with it while continuing to handle your request.

Controller's contact address: FELIX DE AZARA 100, LOMAS DE ZAMORA, BUENOS AIRES, ARGENTINA.

2. Data we process

Depending on how you use the platform, we may process the following categories:

  • Account and identity data, such as name, email, avatar, login method, memberships, roles and account status.
  • Agency, client and operational data, such as contacts, responsible staff, services, contracts, communications, calendars, content, approvals and files added by authorized people.
  • Business inquiry data, including an address supplied by a person, and coordinates and coverage areas obtained when locating it.
  • Administrative and billing data, such as legal name, tax identification, address, currency and billing contacts. We do not request banking credentials through the Meta integration.
  • Support and communication data, including messages and background information needed to answer an inquiry or resolve an incident.
  • Technical and security data, such as IP address, browser, device, access dates, session identifiers, audit events, errors and activity needed to prevent abuse.

We obtain this data directly from users, from agencies managing their workspaces, from voluntarily connected services and from technical records generated while using the platform.

3. Instagram and Meta data

An authorized person can connect a professional Instagram account directly for reports, or use Facebook Login for Business to select accessible business assets, such as Pages, linked professional Instagram accounts and ad accounts. The connection is voluntary and authorized through Meta. It is used for enabled organic or advertising reports and, if publishing is authorized and the accounts are associated with the business, to deliver calendar content to Instagram and Facebook Pages.

Data we may receive and retain

  • Identifier and name of the person authorizing through Facebook, accessible business portfolios and Pages, their identifiers and names, and their relationship to professional Instagram accounts or ad accounts. They are used to identify the connection and allow explicit asset selection.
  • Professional account identifier, username, display name, account type, granted permissions and connection validity dates.
  • An encrypted access token and technical authorization data. The token is used on the server and is not shown in reports or to other agencies.
  • For organic reports: identifiers, type, date, permanent link and an excerpt of the text of posts, reels and active stories. We do not download or retain the binary photo or video file to prepare these reports.
  • Metrics Meta makes available for each content or account type, such as reach, views, interactions, likes, comments, saves, shares, replies, watch time, profile visits and follower count.
  • Synchronization results, metric availability and timestamps needed to build weekly or monthly reports and explain partial data.
  • Ad account identifier, name, currency, time zone and status; campaign, ad set and ad identifiers and names; objectives and aggregated metrics, such as spend, reach, impressions, clicks, results, attributed values and costs. This data is retained in read-only Meta Ads report snapshots.
  • For requested calendar deliveries: text, images or videos of the selected version, destination accounts, date and time zone, approval or exception reason, person confirming delivery and each network's results, including identifiers and links of confirmed publications. We retain this data to execute delivery, communicate its outcome and maintain the history.

What this integration does not do

We do not request your Instagram or Facebook password. These integrations do not access direct messages, contact lists or personal profile content. The calendar feature sends only content an authorized person requests to publish or schedule; it does not edit or delete publications already on the social network. Meta Ads reports do not create, modify or pause campaigns, budgets or ads, or import individual identities of people who viewed or interacted with ads.

Instagram provides stories while they are available. To maintain report traceability, we may retain their identifiers and historical metrics after they stop being visible on Instagram.

4. How we use data

We process data to:

  • create and protect accounts, authenticate access and apply permissions by role and agency;
  • provide the agreed features and maintain operational history;
  • locate a business inquiry's address and determine whether it falls within configured coverage areas;
  • connect professional Instagram accounts, synchronize content and metrics, generate reports and deliver them to configured recipients;
  • discover authorized business assets, associate ad accounts with selected businesses and retrieve their structure and metrics to prepare read-only advertising reports;
  • publish or schedule the selected content version on authorized Instagram accounts and Facebook Pages associated with the business, check results and maintain traceability of approval or exception and each delivery;
  • provide support, diagnose errors, prevent fraud or abuse and maintain security;
  • measure product operation and improve its stability and user experience;
  • comply with legal obligations, respond to valid requests and protect our own or third-party rights.

Depending on the context, processing is based on providing the requested service, granted authorization or consent, legitimate security and improvement interests, and compliance with legal obligations. Meta authorizations can be revoked through its application and integration controls.

Data received from Meta is used to provide requested connection, reporting and delivery features. We do not sell that data or use it to create advertising profiles or target advertising unrelated to this service.

5. With whom we share data

We may share data only when necessary with:

  • authorized agency staff and report recipients configured by the agency itself;
  • infrastructure, database, storage, email, authentication, security, monitoring and analytics providers delivering services under confidentiality and protection obligations;
  • Google Geocoding and, when Google cannot find a location, Georef Argentina and OpenStreetMap's Nominatim, solely to convert a business inquiry's address into coordinates;
  • Meta, when a person starts, maintains or revokes a connection, consults reports or requests publishing or scheduling. To publish, we send the text and allow Meta to retrieve the selected images or videos through temporary authorized links. A confirmed publication remains on the social network under its terms and policies;
  • authorities or third parties where there is a legal obligation, a valid order or a need to protect rights and security.

Some providers may process information in other countries. In those cases, we seek to use reasonable contracts, controls and safeguards to protect data in accordance with applicable law.

6. Retention and security

We retain data for as long as necessary to provide the service, maintain requested reports and history, comply with legal obligations, resolve disputes and protect the platform. When no longer needed, we delete or anonymize it in a reasonable manner.

Meta connection data is retained while the integration remains active or is necessary for authorized reports and deliveries. Following a valid deletion request, we stop access and delete or anonymize the relevant data without undue delay, unless a legal obligation or third-party right requires limited information to be retained.

We apply access controls, isolation between agencies, encryption of Meta access tokens, action traceability and technical and organizational measures intended to prevent unauthorized access, alteration, disclosure or loss. No system can guarantee absolute security.

Backup copies may retain data during their limited technical lifecycle; they remain protected and are not reused for operational purposes after a valid deletion request.

7. Your rights

You may request information, access, correction, updating, confidentiality or deletion of your data, and withdraw authorization where applicable. Requests are free of charge and available regardless of your country.

Where Argentine Law 25,326 applies, access requests must be answered within 10 calendar days and correction, updating or deletion requests within 5 business days, unless a legal exception applies. You may also lodge a complaint with the Argentine Agency for Access to Public Information (AAIP).

We may request reasonable information to verify your identity, your relationship to the account and the scope of the request. This prevents disclosure or deletion of another person's, client's or agency's data.

Learn about your rights with the AAIP

8. How to request data deletion

To request deletion of your account data or data obtained from Instagram, Facebook or Meta Ads, follow these steps:

  1. Send an email from an address associated with your account to privacy@wogensy.com, with the subject “Privacy or data deletion request”.
  2. Provide your name, the related agency and the information you want deleted. Where applicable, include the Instagram username, the name or identifier of the Facebook Page or the related ad account.
  3. Do not send passwords, tokens, access codes or sensitive documents we have not requested.
  4. We will verify your identity or authorization, acknowledge receipt and communicate the result and scope of deletion.

A valid request may include stopping access, deleting stored credentials, unlinking professional accounts, Pages or ad accounts, and deleting or anonymizing identifiers, imported content, metrics and derived reports. If we must retain limited information due to a legal obligation, security, fraud prevention or third-party rights, we will explain the reason and restrict its use.

You can also withdraw authorization through Facebook's or Instagram's application and integration controls, depending on how you connected the account. This stops the connection's authorized access but does not by itself delete stored copies or publications or campaigns remaining on Meta. To delete data stored on the platform, follow the request procedure.

9. Cookies and measurement

We use technologies needed to sign in, maintain security, remember preferences and operate the platform. We may also collect technical or aggregated measurements to understand performance and correct errors.

You can configure your browser to limit cookies, although blocking strictly necessary cookies may prevent access or the operation of some features.

10. Changes, minors and contact

The service is intended for organizations and people acting in a professional context; it is not intentionally designed for people under 18 years of age.

We may update this policy when the product, providers or applicable obligations change. We will publish the new version at this URL and state its effective date. We retain previous versions in accordance with our obligations.

Privacy contact

For questions or to exercise your rights, contact privacy@wogensy.com.