Data processing agreement
Last updated
Parties and scope
This Data Processing Agreement ('DPA') is between the customer that accepted our Terms of Service ('Customer', the controller) and IGP Global Solutions FZ-LLC ('IGP one', the processor). It applies when IGP one processes personal data on the Customer's behalf in providing the Service ('Customer Personal Data').
It forms part of the Terms of Service and is accepted when the Customer accepts those Terms. If this DPA and the Terms conflict on data protection, this DPA prevails. For a countersigned copy, email [email protected].
Details of processing (Annex I)
Subject matter and purpose: providing the IGP one Service, including the AI agent (in chat and in voice mode), content creation, publishing, handling of comments, messages and story replies, comment-to-DM flows, story-reply automation, lead capture, notifications and reporting.
Nature of processing: collection through connected accounts, storage, organisation, analysis by AI models, generation of replies and content, transmission to connected platforms, and deletion.
Duration: the term of the Customer's subscription and the deletion period below.
Data subjects: people who interact with the Customer's connected Instagram account (such as commenters, message senders, people who reply to its stories, and leads), and the Customer's team members.
Categories of data: usernames, profile names and pictures, platform IDs, message, comment and story-reply content, contact details and requests people share, lead notes and tags, team member names and emails, and workspace chat history (including transcripts of voice conversations; voice audio is processed in real time and not stored).
Special categories: not intended. The Customer must not use the Service to collect special category data, health data, payment card data or government ID numbers.
Frequency of transfer: continuous, while the Service is used. Retention: as set out in 'Deletion and return'. Competent supervisory authority for the SCCs: as determined under Clause 13 for the Customer. Subprocessors (Annex III): as listed on our Subprocessors page.
Customer instructions
IGP one processes Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless the law requires otherwise; in that case IGP one tells the Customer before processing, unless the law prohibits it. The Terms, this DPA and the Customer's configuration and use of the Service are those instructions. IGP one will tell the Customer if it believes an instruction breaks data protection law.
The Customer is responsible for having a lawful basis and giving the required notices to data subjects, including that automated and AI-assisted replies are used.
Confidentiality
IGP one ensures that everyone authorised to process Customer Personal Data is bound by confidentiality and accesses it only as needed to provide and support the Service.
Security (Annex II)
IGP one implements appropriate technical and organisational measures, including: encryption in transit and at rest; primary storage of Customer Personal Data in the European Union; logical tenant isolation with row-level security; field-level encryption of social access tokens in a vault; role-based access; single sign-on and access controls for internal tools; audit logs; daily backups with tested restores; and continuous error and uptime monitoring. Service logs, which contain no message content, are kept by Better Stack in the United States. Our Security page describes these measures and may be updated, provided the overall level of protection is not reduced.
Subprocessors
The Customer gives general authorisation for IGP one to use the subprocessors listed on our Subprocessors page.
IGP one gives at least 30 days' notice before adding or replacing a subprocessor that processes Customer Personal Data, by updating that page and emailing account owners. The Customer may object on reasonable data protection grounds within that period. If we cannot reasonably address the objection, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for it.
IGP one imposes data protection obligations on each subprocessor that are no less protective than this DPA and remains responsible for its subprocessors.
International transfers
Customer Personal Data is stored in the EU. It may be accessed from the United Arab Emirates by IGP one and processed in the United States by AI and other subprocessors.
For transfers of personal data subject to the GDPR to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914: Module Two (controller to processor) between the Customer and IGP one, and Module Three (processor to processor) between IGP one and its subprocessors where needed. Clause 7 (docking) applies; the option in Clause 9(a) is general authorisation with the notice period above; Clause 11 optional language does not apply; Clauses 17 and 18 are governed by and heard in the courts of Ireland. Annexes I and II are the sections above.
For UK data, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner applies, with Tables 1 to 3 completed from this DPA and the SCCs. For Swiss data, the SCCs apply with references read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is a competent authority.
Where a subprocessor is certified under the EU-U.S. Data Privacy Framework, that framework may be used instead.
Transfers subject to the UAE PDPL or Israeli law are made under the transfer rules of those laws, including contractual safeguards.
If IGP one receives a legally binding request from a public authority for Customer Personal Data, it notifies the Customer where the law allows, challenges the request where there are reasonable grounds, and discloses only the minimum required.
Assistance to the Customer
IGP one helps the Customer respond to data subject requests, mainly through self-service tools for access, export, correction and deletion. If IGP one receives a request directly, it forwards it to the Customer without undue delay and does not respond except as instructed or required by law.
IGP one provides reasonable help with the Customer's obligations on security, breach notification, data protection impact assessments and prior consultation with authorities (GDPR Articles 32 to 36), based on the information available to it, and keeps a record of the processing it carries out for the Customer.
Personal data breaches
IGP one notifies the Customer without undue delay, and in any case within 48 hours after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes what happened, the data and people affected, likely consequences, and the measures taken or proposed, and is updated as more becomes known.
IGP one does not notify authorities or data subjects on the Customer's behalf unless the Customer asks or the law requires it.
Deletion and return
The Customer can export Customer Personal Data at any time during the subscription and for 30 days after it ends. At the Customer's choice, data is returned through export or deleted: after the Customer deletes its account, or 30 days after termination, IGP one deletes Customer Personal Data, and it leaves rolling backups within a further 35 days, unless the law requires longer retention.
While Instagram is connected, messages and comments are kept for 12 months after the last activity in the conversation, and lead records while the Customer's account exists and Instagram stays connected. When the Customer disconnects Instagram, the access token is deleted immediately and data received through that connection is deleted within 30 days, unless the account is reconnected within that time.
Audits
IGP one makes available the information reasonably needed to show compliance with this DPA, including written answers to security questionnaires once a year. If that is not enough, or if an authority requires it, the Customer may carry out an audit, once a year, with 30 days' notice, during business hours, by an independent auditor under confidentiality, at the Customer's cost.
US state privacy laws
For the CCPA/CPRA and similar US state laws, IGP one acts as a service provider or processor. It will not sell or share Customer Personal Data, will not retain, use or disclose it outside the direct business relationship or for any purpose other than providing the Service, will not combine it with other data except as those laws allow, and will notify the Customer if it can no longer meet these obligations. IGP one certifies that it understands and will comply with these restrictions.
UAE and Israel
For Customer Personal Data subject to the UAE PDPL, IGP one processes it only on instructions, keeps it confidential and secure, notifies breaches as above, and deletes it at the end of processing. For data subject to Israel's Protection of Privacy Law and its Data Security Regulations, IGP one meets the obligations of a holder that processes for the Customer, including security measures, confidentiality, breach reporting to the Customer and return or deletion at the end of the engagement.
Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms, except where the law or the SCCs do not allow it. This DPA lasts as long as IGP one processes Customer Personal Data.
Contact
Data protection questions: [email protected]. Signed copies and legal notices: [email protected].