Legal
Data Processing Addendum
Last updated: August 26, 2026 · v2026-08-26
Engineer draft for transparency — not legal advice. A qualified lawyer should review before you treat this as final compliance guidance.
Engineer draft for transparency — not legal advice. Counsel should replace this with a signed DPA before you rely on it in an enterprise deal. This is not a certification.
DPA version: 2026-08-26 · Last updated: August 26, 2026
This Data Processing Addendum (DPA) applies when you use Insta24 to process personal data of Instagram users, customers, or other end people (DMs, comments, CRM contacts, appointments, shop orders, lottery entries, uploaded media) in a workspace.
1. Parties and roles
- You (the workspace owner / organization) are the controller of that audience data.
- Insta24 is the processor (and may use sub-processors listed at Subprocessors).
- For your Insta24 login, SaaS billing, and website cookies, Insta24 is a controller — that is covered by the Privacy Policy, not this DPA.
Accepting Terms and Privacy in the product also records acceptance of this DPA version for your account.
2. Instructions
Insta24 processes audience data only to provide the product features you enable (inbox, automations, CRM, booking, shop, lotteries, analytics you configure) and to secure the service. You warrant that you have a lawful basis and any required consents (including Meta Platform rules) for the automations and messages you run.
3. Customer responsibilities (audience / children)
You are responsible for your Instagram audience. Do not use Insta24 to collect or target children’s data in violation of applicable law or Meta policies. Instagram’s age floor is not a substitute for your own compliance.
4. Security and staff
Insta24 applies technical and organizational measures appropriate to the risk (encryption in transit, access control, encrypted tokens, tenant isolation). Access is limited to personnel who need it to operate the service.
5. Sub-processors
You authorize Insta24 to use the sub-processors listed on Subprocessors. We will keep that list updated. Transfers outside the EEA use appropriate safeguards (such as standard contractual clauses) where required.
6. Assistance with rights and breaches
Insta24 will reasonably help you respond to data-subject requests that concern audience data stored in the product (for example Contacts export). Insta24 will notify you without undue delay if we become aware of a personal-data breach affecting your workspace, with enough information for you to meet controller duties where applicable.
7. Deletion and return
When you disconnect an Instagram account without purge, audience rows may remain. When you Disconnect and delete Meta-sourced data, delete the workspace via account deletion, or Meta sends a deletion callback, we delete or irreversibly scrub that Meta-sourced audience data we hold, except as required by law. You can export contacts and appointments from the app before deletion.
SaaS invoices for your Insta24 subscription may be retained in anonymized form (see Privacy Policy).
8. International processing
Audience data may be processed on our VPS, Cloudflare, and other sub-processors. If you are in the EEA/UK/CH, you are responsible for assessing whether this tool is appropriate for your processing, including transfers.
9. Term
This DPA lasts for as long as Insta24 processes audience data for your workspace. Surviving duties (deletion, confidentiality) continue as required by law.