Skip to content
Cerebr-IA

Legal

Privacy policy

What data we process on this website and in MARKETIA, why, who we share it with and how to exercise your rights.

Last updated: September 28, 2026.

This policy covers this website (cerebria.co) and MARKETIA (marketia.cerebria.co and its API fapi.marketia.cerebria.co). It is consistent with the privacy policy published inside MARKETIA (in Spanish), which describes the same from the application itself.

Who is responsible

  • Controller: Cerebr-IA, a Clever company. Colombia. Cerebr-IA (also "Cerebria") is the Clever division that builds and operates MARKETIA.
  • Privacy and deletion contact: developer@cerebria.co. General contact: developer@cerebria.co.
  • We are the controller of this website's data and of MARKETIA user accounts. For the data of the customers of each business that uses MARKETIA, that business is the controller: MARKETIA processes it on the business's behalf, following its instructions and only to provide the service.

Data on this website

  • Contact form: when you submit it, our API (api.cerebria.co) stores your name, email, company (optional), topic, message, language, the date, your browser (User-Agent header) and a keyed hash (HMAC-SHA256 with a secret key) of your IP address that cannot be reversed: the IP is never stored in clear text. That hash is used to limit how many messages can be sent from the same IP and prevent abuse. If email notification is configured on the server, we also receive a copy of the message in our mailbox; otherwise the message is kept only in the API database. We use this data only to reply to you. The legal basis is your consent, given by ticking the box, which you can withdraw at any time.
  • Emails you send us: if you email us directly, we use your address and what you tell us only to reply to you.
  • Server logs: like any web server, the hosting keeps technical request data (IP, date, page, browser) for a limited time for security and troubleshooting.
  • No cookies or tracking: this website uses no cookies, third-party analytics or advertising pixels. See the cookie policy.

Data in MARKETIA

MARKETIA only accesses the accounts the business administrator explicitly connects, and only what the service needs.

SourceWhatWhy
Connected Facebook Pages and Instagram accountsComments and reactions on the business's posts, with the commenter's public name.Detect offensive messages and customer questions, and reply to or hide them according to the business's rules.
Messenger, Instagram and WhatsAppConversation messages, and name and profile picture when Meta provides them (the picture is copied to our storage because Meta's link expires). On Instagram, also username, follower count, whether they follow the business and whether they are verified.Show conversations in a single inbox and reply from it.
Meta ad accountsAggregated metrics: spend, impressions, clicks, conversions. No data about specific people.Show advertisers how their campaigns perform and help them manage them.
Click-to-message adsThe ID of the ad a conversation came from.Know which ad brought each customer.
The business's Meta instant forms (Lead Ads)What the person submits (usually name, phone and email, plus answers to the business's questions), with the source ad.Let the business contact whoever asked for information.
ThreadsProfile and posts of the connected account, and the replies and mentions it receives.Publish, moderate replies and measure.
TikTok (TikTok accounts, ad accounts and TikTok Business accounts the business connects)From ad accounts: name, currency, time zone, status, balance and aggregated metrics; from Business Centers, their name and company. From the TikTok account: username, display name, avatar, whether it is Business or verified, follower, video and like counts, and its video list with metrics. If the business enables those features, also: comments on its videos and ads (with the commenter's public name), the direct messages it receives and lead-form data from its ads.Show performance, publish the content the business decides, moderate comments, handle messages and let the business contact whoever asked for information.
Connected stores (Shopify, Dropi or built-in store)Orders: amount, products, city and the contact details needed for delivery.Measure results and manage deliveries.

Platform access tokens are stored encrypted and never returned through the interface or the API. Per-platform details are on the integration pages.

MARKETIA users

For people who use MARKETIA we process their name, email, organization, role and password (only as a bcrypt hash, never in clear text), and activity logs needed for security and support.

Who we share it with

Only with the providers needed for the service to work:

  • Hostinger: the server where the platform and its database run.
  • AI providers: when the business enables AI features, conversation and comment content is sent to draft replies and generate analyses, including voice-note audio (for transcription) and images sent by customers (for description). The default provider is OpenAI (United States). The platform can be configured to use one of these providers instead, which receive the same information: xAI, Google (Gemini), Anthropic (Claude) (United States), Mistral (European Union) and DeepSeek, Moonshot (Kimi) and Alibaba (Qwen), whose servers are in China: if one of these three is chosen, conversation data is transferred to China.
  • fal.ai: in the AI Studio, the instructions the business writes and its product images, to generate images and videos. No customer data is sent.
  • Apify: searches in public ad libraries for competitor analysis (brands or keywords). The encrypted connection to the Dropi panel may also go through its proxy; Apify cannot see its content.
  • ElevenLabs: only text generated by the platform, to turn it into a voice note.
  • File storage: the server itself or an S3-compatible service, depending on the installation.
  • Outgoing email provider: for notices and reports to the business and, if that notification is configured, to send us a copy of messages from this website's form.
  • Meta and TikTok: only what the features the business connects require (replies, moderation, messages, posts) and, if conversion measurement is enabled, purchase events with personal identifiers hashed with SHA-256, never in clear text.
  • Shopify: the order closed in chat, with name, phone, email and delivery address.
  • Dropi: the data needed for delivery (name, address, city, department, phone and email).
  • Payment gateways (Wompi, Bold): only for built-in stores that configure them, and only what is needed to charge.

None of them use this data for their own purposes. We do not sell data, use it for third-party advertising or to train AI models. Some providers (for example, AI providers) may process data outside Colombia; they only receive what the specific feature needs.

How long it is kept

  • For as long as the business keeps using the service.
  • Disconnecting an ad account deletes its metrics, campaigns and ads.
  • Disconnecting a Page stops new data; what was already received stays in the business's inbox until deletion is requested or the organization is deleted. That Page's Lead Ads data is deleted.
  • Disconnecting TikTok: removing an advertiser authorization revokes access on TikTok and deletes its ad accounts, metrics and Business Centers; disconnecting a TikTok account revokes its access and deletes its tokens and dependent data.
  • AI analyses are deleted after 90 days; technical logs of those calls after 30; error logs after 14.
  • Deleting an organization deletes everything it owns.
  • Messages from this website's form and emails you send us are kept as long as needed to handle your request, and deleted when you ask.

Removing access from TikTok

If you remove MARKETIA's permission from TikTok (in the app: Settings and privacy → Security → Manage app permissions; or in TikTok for Business), access stops working immediately: we stop reading and sending anything and the business is notified. You can also ask us to delete what was received from that account by emailing developer@cerebria.co.

Removing access from Facebook

If you remove MARKETIA in Facebook Settings → Apps and websites, Meta notifies us and we disconnect the Pages and ad accounts you connected. If you also request deletion, we delete the tokens, your Facebook ID and permission data, and give you a confirmation code to check the status. Full instructions on the data deletion page.

Your rights

Under Colombian data protection law (Law 1581 of 2012), you can access, update, correct and request deletion of your data, revoke the authorization you gave and file complaints with the Superintendence of Industry and Commerce (SIC). If you are a customer of a business that uses MARKETIA, you can contact that business or us directly, and we will handle it with them.

Email developer@cerebria.co stating what you want to do and which account or number you used. Deletion requests are completed within 30 days at most.

Security

Encryption in transit (TLS), tokens encrypted at rest, tenant isolation and roles. Details on the security page.

Minors

MARKETIA is a professional tool for businesses and is not directed at anyone under 18. Neither is this website.

Changes

If this policy changes, the date above is updated. Material changes are communicated to the businesses that use MARKETIA.