Data processing addendum
Last updated 31 August 2026. Effective from 31 August 2026.
This addendum forms part of the terms of service and applies automatically. You do not need to ask for it, sign it, or email anyone.
1. Roles
For the personal data of people who comment on your Instagram posts, you are the controller and In Your DM (operating entity to be confirmed) is the processor. You decide which keywords trigger, what the messages say, and who receives them. We carry out those instructions.
For your own account data — your email, your password hash, your billing record — we are the controller, and our privacy policy governs it.
2. Scope of processing
- Subject matter: automated replies and direct messages on Instagram, and the contact records they produce.
- Duration: for as long as your account is open, plus the 30-day deletion grace window.
- Nature and purpose: receiving comment events, matching keywords, sending replies and messages, storing contacts and delivery history.
- Categories of data subject: people who comment on, or reply to, your Instagram content.
- Categories of personal data: Instagram user id, username, comment text, the keyword matched, timestamps, and any tags or fields you add.
- Special category data: none requested, none required. Do not configure automations that solicit it.
3. Our obligations
- Process personal data only on your documented instructions, which the product interface constitutes, unless law requires otherwise — in which case we tell you first unless the law forbids it.
- Ensure everyone with access is bound by confidentiality.
- Apply the technical and organisational measures in section 5.
- Engage sub-processors only under written terms no less protective than these, and give 14 days' notice before adding one.
- Assist you with data subject requests, with data protection impact assessments, and with regulator consultations.
- Notify you without undue delay, and within 48 hours, of any personal data breach affecting your data.
- Delete or return the data at the end of the relationship, at your choice.
- Make available the information needed to demonstrate compliance, and allow audits as described in section 7.
4. Your obligations
- Have a lawful basis for the messages you send, and honour opt-outs.
- Do not use automations to solicit special category data, or data from children.
- Give your own privacy notice to the people you message. They are your data subjects.
- Keep your credentials secure. Instructions issued through your account are treated as yours.
5. Technical and organisational measures
- Instagram access tokens encrypted at rest with AES-256-GCM; the key is held in the host environment and never in the database.
- Passwords hashed with bcrypt at cost 12.
- TLS on all traffic. Webhook authenticity verified by HMAC-SHA256 over the raw request body.
- Access tokens excluded from logs, error reports and data exports by column selection rather than by post-hoc filtering.
- Least-privilege access; production access limited to named administrators.
- Automated deletion of raw platform payloads after 7 days.
- Per-account send pacing beneath Meta's published limits, to protect the controller's own account.
- Separate database roles for the always-on worker and the dashboard.
6. International transfers
Where you are in the EEA, the UK or Switzerland and data is transferred to the United States, the parties adopt the European Commission’s Standard Contractual Clauses (Module 2, controller to processor) as incorporated into this addendum by reference, together with the UK International Data Transfer Addendum and the Swiss addendum as applicable.
Docking clause: an affiliate of yours may accede to these clauses on the same terms.
7. Audit
We will answer a reasonable written security questionnaire once per year at no charge, and provide any third-party audit reports we hold. On-site audits are available where a supervisory authority requires one, at your cost and on 30 days’ notice.
8. Liability and precedence
Liability under this addendum is subject to the limitations in the terms of service. Where this addendum conflicts with the terms, this addendum prevails for data protection matters. Where it conflicts with the Standard Contractual Clauses, the clauses prevail.
9. Signed copies
If your procurement process needs a countersigned PDF, email privacy@inyourdm.com and we will send one. The published version applies either way.