1. Who processes data
The “Operator” is the provider named on your invoice or payment statement (a payment intermediary may collect fees under its own notice). Contact: site form or pre-contract email.
End-user Direct data: you (the Customer) are the controller; the Operator is the processor on your instructions.
Your account data: the Operator is an independent controller (contract, security, support, billing reconciliation).
2. What we process
Access requests / contacts — name, email, notes you submit.
Paid cabinet — email, Instagram Business identifiers, assistant settings, Direct messages, optional memory artefacts, delivery metadata, encrypted access credentials.
Public demo — short-lived chat (no permanent account).
Technical — IP for demo limits, session cookies, security logs.
3. Why
Qualify requests, invoice manually, run the assistant, demo the product, secure the Service, and support you. End-user message content is used to generate replies and keep context—not to market to those end users for the Operator’s own benefit.
4. Infrastructure and subprocessors
Primary application servers and databases run on rented VPS infrastructure in Germany (EU). Additional subprocessors are used only as needed, in categories such as: hosting; messaging / social API intermediaries; AI model providers; optional advanced memory (if your plan enables it); email; and payment / invoicing intermediaries. Specific vendor brands may change.
Where transfer rules apply (e.g. EEA/UK customers), the Operator relies on available mechanisms such as adequacy decisions, standard contractual clauses, or equivalent safeguards.
5. Your rights and deletion
Update business settings in the cabinet. Delete your account from Legal at any time—immediate and permanent for application data (Instagram connection via the messaging provider, Direct logs, settings, notes, prompts, memory cards and tenant memory facts), subject to backup rotation.
Operator-initiated: unpaid, abandoned, or abusive accounts may be deactivated; app data kept up to 30 days, then deleted the same way.
May remain: aggregated anonymized metrics without identifiers or message text.
End users should contact you (the Customer) first; the Operator assists where technically feasible.
6. Security and incidents
HTTPS, access controls, encrypted tokens at rest, logging, and backups as infrastructure allows. No system is perfectly secure. Personal-data breaches affecting end-user data: Operator notifies you without undue delay with information reasonably available; regulator/end-user notices remain your duty unless law assigns them to the Operator.
7. Contact
Use the access form or site chat. This notice is informational and does not certify a formal GDPR/CCPA programme. Enterprise addenda (e.g. detailed SCCs) can be discussed before onboarding.