Privacy Policy
1. Data Controller
In compliance with the General Data Protection Regulation (GDPR EU 2016/679) and applicable privacy regulations, the data controller responsible for personal data processed through this website and service is:
- Controller Name: [RESPONSABLE LEGAL]
- Tax ID / CIF: [NIF/CIF]
- Registered Address: [DOMICILIO]
- Privacy & Legal Contact: [EMAIL PRIVACIDAD]
- Data Subject Rights Portal: Privacy Request Center
2. Role Distinction: Data Controller vs. Data Processor
To provide full legal clarity under GDPR:
- We act as Data Controller: With respect to our waitlist subscribers, our registered customer account credentials, billing records, direct telemetry, and platform security audit logs.
- We act as Data Processor: When a business connects its professional Instagram account to our platform and our system processes comments, direct messages (DMs), or interactions from third-party end users on the customer's behalf and under their instructions. In that context, the customer is the primary Data Controller, and our relationship is governed by our Data Processing Addendum (DPA) under GDPR Article 28.
3. Purposes and Legal Bases for Processing
| Purpose | Data Categories | Legal Basis (GDPR) | Retention Period |
|---|---|---|---|
| Waitlist Management: Confirmation, launch notification, and delivery of early adopter 50% discount. | Email address, timestamp of consent, registration IP hash. | Explicit Consent (Art. 6.1.a GDPR). | Until the user unsubscribes or 12 months after public launch without engagement. |
| Connected Service Provision: Assisted carousel publishing, analytics reading, and authorized automations. | Instagram account ID, encrypted OAuth access tokens, post metadata. | Performance of Contract (Art. 6.1.b GDPR). | For the duration of active service or until Instagram disconnection / deauthorization. |
| Security & Fraud Prevention: Abuse prevention, rate limiting, and technical infrastructure audit logs. | IP address (hashed/normalized), User-Agent, event logs, timestamps. | Legitimate Interests (Art. 6.1.f GDPR). | Maximum 90 days in active security logs; automatic purging thereafter. |
4. Meta Platforms and Instagram Data Handling
Regarding our integration with the official Instagram API via Instagram Login:
- Least Privilege: We strictly request only the scopes necessary to provide features authorized by the user.
- Token Security: Access tokens provided by Meta are encrypted at rest using strong application-level encryption and are never exposed to browser clients, frontend logs, or telemetry.
- No Data Sales: We never sell, lease, transfer, or commercialize Meta platform data to data brokers, ad networks, or third parties.
- No Password Storage: We never ask for or store Instagram account passwords; authentication is handled solely through Meta's OAuth 2.0 flow.
- Disconnection & Deletion: Users can disconnect the integration at any time from their Instagram account settings or via our User Data Deletion page. Upon disconnection or callback, tokens and cached platform data are permanently purged.
5. Subprocessors & Service Providers
We do not share personal data except as strictly necessary to operate our service under Article 28 GDPR contracts:
- Cloudflare, Inc.: Global CDN, edge compute (Workers), security protection, and transactional email routing (Standard Contractual Clauses).
- Neon Database, Inc. / Serverless PostgreSQL: Managed database storage encrypted at rest and in transit.
- Meta Platforms Ireland Ltd.: Platform integration provider under Meta Platform Terms.
Review the full list at our Subprocessors Directory.
6. Data Subject Rights
Under the GDPR, you have the right to request access to, rectification, erasure (right to be forgotten), restriction of processing, data portability, and objection to processing of your personal data, as well as the right to withdraw consent at any time.
To exercise your rights, submit a request through our Privacy Request Center or email [EMAIL PRIVACIDAD]. We respond to all verified requests within one month of receipt, extendable by two further months where necessary pursuant to GDPR Article 12.3.
You also hold the right to lodge a complaint with a supervisory authority, including the Spanish Data Protection Agency (AEPD) at www.aepd.es.