Skip to content
IGP oneIntelligent
Growth Partner
ProductSolutionsPricingResourcesCompany
EN
  • English
  • עברית
  • العربية
  • Español
  • Français
  • Deutsch
  • Português
  • Русский
Log inStart 7-day trial
  1. Home
  2. Legal
  3. Privacy policy

Privacy policy

Last updated September 29, 2026

In short

We collect what we need to run IGP one on the web and in our apps, use it only to provide and protect the service, and store it in the European Union. We don't sell or share your personal data for advertising, we don't keep recordings of your voice, and our AI providers don't train on your data. You can access, correct, export or delete your data at any time.

Contents

  1. Who we are and what this notice covers
  2. What we collect
  3. How we use data, and our lawful bases
  4. How AI is used with your data
  5. Who we share data with
  6. Instagram data (Meta Platform Data)
  7. Where data is stored and international transfers
  8. How long we keep data
  9. How we protect data
  10. Your rights
  11. European Union and United Kingdom
  12. United States, including California
  13. United Arab Emirates
  14. Israel
  15. Children
  16. Marketing emails
  17. Changes to this notice
  18. Contact

Who we are and what this notice covers

IGP one (igpone.com, app.igpone.com and the IGP one apps for iOS and Android) is operated by IGP Global Solutions FZ-LLC, a free zone company licensed by the Ras Al Khaimah Economic Zone (RAKEZ), FDRK7851, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. In this notice, 'we', 'us' and 'our' mean IGP Global Solutions FZ-LLC.

This notice explains how we handle personal data when you visit our website, use our apps, create an account, use IGP one, buy a subscription or contact us.

We act in two roles. For your account, billing, website visits and support, we decide how data is used, so we are the controller. For the personal data of your own customers that IGP one processes for you, such as Instagram comments, direct messages and leads, your business is the controller and we are your processor. That second role is governed by our Data Processing Agreement.

If you contacted a business that uses IGP one and you want to exercise your rights, please contact that business first. We will help them respond, and you can also write to us at [email protected].

What we collect

Account and contact details: your name, email address, business name, role, language, time zone and sign-in method. If you sign in with Google or Apple, we receive the name and email address that provider shares with us.

Your workspace: brand kit and brand memory (such as your business facts, products, prices, tone of voice and approved claims), media you upload, content drafts, captions, approvals, schedules, notes and settings.

Conversations with the AI agent: the messages you send to IGP one in chat, the files you share there and the answers it gives, including transcripts of voice conversations.

Voice mode (mobile apps): when you use voice mode or dictation, your audio is streamed to OpenAI and processed in real time. We save the text transcript in your chat history, like a typed chat. We do not store audio recordings, and we don't use your voice to identify you.

Connected Instagram account: your Instagram professional account ID, username, profile details, the access token (stored encrypted), your posts and media, comments, direct messages and replies to your stories, and account insights, within the permissions you grant.

Your customers' data (as your processor): the usernames, profile names, profile pictures and message or comment content of people who interact with your Instagram account, and any contact details or requests they choose to share, which may be saved as leads.

Billing information: your plan, billing address, VAT or tax number, invoices and payment status. Card payments are handled by Stripe. We receive only limited card details such as the card brand, last four digits and expiry date, never the full card number. If you subscribe in our iOS or Android app, Apple or Google handles the payment and tells us the subscription status and a transaction ID; we never receive your store payment details.

Support and communications: messages you send us, feedback, and your email preferences.

Technical and usage data: IP address, device and browser type, approximate location derived from the IP address, pages and features used, error reports, security logs and audit logs of actions in your workspace. We avoid putting message content or unnecessary personal data in logs.

Mobile app and device data: device model, operating system and app version, language, a push notification token if you allow notifications, and crash reports. The app asks for microphone access only when you first use voice mode or dictation, and uses the microphone only while you are using them. You can turn off microphone access and notifications at any time in your device settings.

Cookies and similar technologies: see our Cookie Policy.

Please don't upload health records, card numbers, passwords, government ID numbers or other sensitive data to a marketing workspace. IGP one is not designed for it.

Where data comes from: from you, from the Instagram account you connect (through Meta), from the people who comment on or message that account, from Stripe, Apple and Google about payments, subscriptions and sign-in, and from your browser or device.

Is it required? You are not legally required to give us personal data, but we need your account details, and for paid plans your billing details, to provide the service. Without them we cannot open an account or take payment.

How we use data, and our lawful bases

To provide IGP one under our contract with you: create and secure your account, run the AI agent, create and schedule content you approve, publish to Instagram, handle comments and messages, capture leads, send notifications and weekly reports, and provide support. Lawful basis: performance of a contract.

To run our mobile apps: send the push notifications you allow, process your voice when you use voice mode or dictation, and find and fix crashes. Lawful basis: performance of a contract; for crash reports, legitimate interests (for UAE residents, contract). Notifications and microphone access also need your permission on the device, which you can withdraw in your device settings.

To bill you and meet legal duties: process payments, issue invoices, calculate and report taxes, keep accounting records and respond to lawful requests. Lawful basis: contract and legal obligation.

To keep the service safe: prevent fraud and abuse, enforce our Acceptable Use Policy, investigate incidents and protect our users. Lawful basis: legitimate interests (for UAE residents, contract and legal obligation).

To prevent misuse of the free first result: to give each business one free first result, we keep a one-way cryptographic fingerprint (a SHA-256 hash) of the email address and of the IP address used, together with the business's website domain or Instagram handle. We use this record only to stop the same person or business from claiming the free result more than once. We don't keep the email or IP address itself in this record, we don't share it, and we don't use it for marketing. Lawful basis: legitimate interest in preventing abuse.

To improve IGP one: understand which features are used, fix errors and measure performance, using aggregated or de-identified data where possible. We do not use your content or your customers' messages to train AI models. Lawful basis: legitimate interests (for UAE residents, contract or consent).

To send product news and offers: only if you opt in, and you can unsubscribe or object to direct marketing at any time. Service messages, such as the trial reminder, receipts and security notices, are sent as part of the contract. Lawful basis: consent.

Optional cookies: only with your consent. Lawful basis: consent.

We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.

How AI is used with your data

To write drafts, suggest replies and answer you in chat, IGP one sends the relevant parts of your workspace and conversations to our AI model providers, Anthropic and OpenAI, through their business APIs. They process the data on our behalf under their API terms and do not use it to train their models. They may keep it for a short period for abuse and safety monitoring under those terms.

In voice mode, your audio is streamed over an encrypted connection to OpenAI's realtime service, which recognises your speech and produces the spoken reply. The voice you hear is AI-generated. We keep the text transcript in your chat history, not the audio. OpenAI's API terms, including any short retention for abuse monitoring, also apply to voice requests.

More detail is in our AI Policy.

Who we share data with

Service providers (subprocessors) that host, store, process payments, run AI models, send email and monitor the service, under contracts that limit their use of the data. The current list is on our Subprocessors page.

Stripe, which processes web payments for us. Stripe also uses payment data as an independent controller to prevent fraud and meet its own legal duties, under the Stripe Privacy Policy.

Meta (Instagram), when you tell IGP one to publish content or send replies on your connected account. Meta handles that data under its own terms and privacy policy.

Apple or Google, when you use their sign-in, buy through the App Store or Google Play, or receive push notifications from our apps (delivered through Apple Push Notification service or Firebase Cloud Messaging). They act under their own terms.

Professional advisers, such as lawyers, auditors and accountants, under confidentiality.

Authorities, courts or regulators, when the law requires it or to protect rights and safety. We push back on requests that are unclear or too broad.

A buyer or successor, if our business is reorganised, merged or sold, with this notice continuing to apply.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

Instagram data (Meta Platform Data)

Data we receive from Instagram through Meta's APIs ('Platform Data') is used only to provide IGP one to the business that connected the account: to publish, show and answer comments, messages and story replies, capture leads and report results.

We do not sell, license or buy Platform Data. We do not use it for advertising, to build profiles of people, or to make decisions about anyone's eligibility for jobs, housing, credit, insurance or similar, and we do not share it with data brokers. We follow Meta's Platform Terms and Developer Policies.

We delete Platform Data when the account is disconnected, when Meta or the account owner asks us to, or when we no longer need it, as described in 'How long we keep data' and on our Delete your data page.

Where data is stored and international transfers

Your workspace data is stored in the European Union: our database runs on Supabase in Frankfurt, Germany, and files are stored in Cloudflare R2 in the EU. Some servers run with Hetzner in Germany or Finland.

Some processing happens outside the EU. AI requests are processed in the United States by Anthropic and OpenAI, and our service logs, which contain no message content, are kept by Better Stack in the United States. Some service providers, such as Stripe, operate globally. Our team works from the United Arab Emirates and may access data from there to provide support and run the service.

When personal data from the EU, the UK or Switzerland is transferred to a country without an adequacy decision, we use the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum for UK data and the Swiss adaptations for Swiss data), or the EU-U.S. Data Privacy Framework, its UK Extension or the Swiss-U.S. framework where the recipient is certified. We add safeguards such as encryption and access control.

For data from the UAE, we transfer data abroad only where the UAE Personal Data Protection Law allows it, for example to countries with adequate protection or under contractual safeguards. For data from Israel, we follow the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, including written commitments from recipients.

You can ask us for a copy of the relevant safeguards at [email protected].

How long we keep data

Account and workspace data: while your account exists. Cancelling a subscription does not delete your account. If you delete your account, we delete workspace data within 30 days, and it leaves our rolling backups within a further 35 days.

Chat history, including transcripts of voice conversations: while your account exists. Voice audio: not stored by us.

Accounts without an active subscription: if an account has had no active subscription and no sign-in for 24 months, we email the owner at least 30 days before deleting it.

Instagram data: while Instagram is connected, messages and comments are kept for 12 months after the last activity in that conversation, and lead cards (the person's Instagram username and name, a short summary, tags and your notes) are kept while your account exists and Instagram stays connected. You can delete them earlier. When you disconnect Instagram, we delete the access token immediately and stop collecting. Comments, messages, insights and leads received or captured through that connection are deleted within 30 days, unless you reconnect the same account within that time. You can export your leads before you disconnect.

Push notification tokens: until you sign out of the app, turn off notifications, or the token stops working.

Invoices and tax records: for the period required by tax and accounting law, generally up to 7 years.

Security, audit and error logs, including crash reports: up to 12 months, unless needed longer to investigate an incident or defend a claim.

Free first result abuse-prevention record (hashed email and IP address, website domain or Instagram handle): 24 months after the free result was created, even if you delete your account earlier. Bot-check (verification) fingerprints: 30 days.

Support messages: up to 24 months after the request is closed.

Consent records and records of privacy requests: for as long as we need to show we complied, generally up to 5 years.

How we protect data

Data is encrypted in transit and at rest, each business's data is isolated, social access tokens are kept in an encrypted vault, and sensitive actions are logged. Our Security page describes the measures we use.

If a personal data breach is likely to affect you, we will tell you and the relevant authorities as the law requires.

Your rights

Depending on where you live, you can ask to access your personal data, correct it, delete it, receive it in a portable format, restrict or object to certain processing, and withdraw consent at any time without affecting earlier processing.

You can do most of this yourself in Settings: edit your details, export your data, and delete your account. For anything else, write to [email protected]. We may ask you to verify your identity. Requests are free. We respond within one month (45 days for US state law requests), and tell you if we need more time as the law allows.

You can complain to us at [email protected]. We acknowledge complaints within 30 days and tell you the outcome without undue delay. You also have the right to complain to a data protection authority.

European Union and United Kingdom

For EU and UK residents, the GDPR and UK GDPR apply. Our lawful bases are listed above. Where we rely on legitimate interests, you can object, and we will stop unless we have compelling grounds.

Privacy contact for people in the European Union and the United Kingdom: [email protected].

We have not appointed a Data Protection Officer; see 'Contact' below for why, and how to reach us about privacy.

You can complain to the supervisory authority in the EU country where you live or work, or to the UK Information Commissioner's Office.

United States, including California

This section is our notice at collection and privacy policy for residents of California and other US states with consumer privacy laws, to the extent those laws apply to us.

Categories we collect (last 12 months): identifiers (name, email, IP address, account IDs); customer records and commercial information (business details, plan, purchase history); internet or network activity (usage and log data); approximate geolocation from IP address; professional information (business name and role); the content of messages and files you or your customers send through the service; audio information (voice input in our apps, processed in real time and not stored by us); and device identifiers such as push notification tokens. Sources: you, your connected accounts, your customers' interactions, our payment and sign-in providers, and your device.

Purposes: the business purposes described in 'How we use data'. We disclose each category to service providers and contractors for those purposes only.

Sensitive personal information: account sign-in data is used only to authenticate you. We do not use or disclose sensitive personal information to infer characteristics about you.

Sale and sharing: we do not sell personal information and do not share it for cross-context behavioural advertising, and we have not done so in the last 12 months. IGP one is not intended for anyone under 18, and we do not knowingly collect personal information from minors. We honour Global Privacy Control (GPC) signals as an opt-out.

Your rights: to know and access, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising them. You can use an authorised agent, and we may ask the agent for proof of authority and ask you to verify your identity. We confirm receipt within 10 business days and respond within 45 days. If we decline a request, you can appeal by replying to our decision; we answer appeals within 45 days.

Retention: as set out in 'How long we keep data'.

United Arab Emirates

For residents of the UAE, we process personal data under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), as it applies to us and as its implementing regulations take effect.

We rely on your consent, the performance of our contract with you, or our legal obligations. We do not rely on legitimate interests for UAE residents.

You can ask to access, correct, delete or restrict your data, receive a copy of it, object to its processing (including for direct marketing), and object to decisions based only on automated processing. We report data breaches to the UAE Data Office and affected people as the law requires.

Israel

For residents of Israel, we process personal data under the Protection of Privacy Law, 5741-1981, including Amendment 13 (in force since 14 August 2025), and its regulations.

Notice at collection: you are not legally required to give us your personal data, but without the details marked as required we cannot open an account or provide the service. The purposes, the recipients and your rights are set out in this notice.

You can ask to see the personal data we hold about you and ask us to correct or delete data that is inaccurate, incomplete, unclear or outdated. We secure data under the Privacy Protection (Data Security) Regulations and report serious security incidents to the Privacy Protection Authority as required.

Privacy protection officer: we have not appointed a privacy protection officer under Amendment 13, because our current activities do not require one (see 'Contact'). For privacy questions, contact [email protected]. You can also complain to the Israeli Privacy Protection Authority.

Children

IGP one, including our apps, is a business service for people aged 18 and over and is not directed to children. We don't knowingly collect personal data from anyone under 18. If you believe a child has given us data, contact [email protected] and we will delete it.

Marketing emails

We send marketing emails only if you opt in. Every marketing email has a one-click unsubscribe link, identifies us as the sender and, where the law requires (for example, under Israel's anti-spam rules), is labelled as advertising. Service emails, such as receipts, trial and renewal reminders and security notices, are part of the service and cannot be switched off while you have an account.

Push notifications from our apps are about your workspace, such as a new lead or a draft waiting for approval. You can turn them off in your device settings.

Changes to this notice

We update this notice when our practices change. For material changes, we notify account owners by email or in the app at least 30 days before they take effect. The date at the top shows the latest version.

Contact

Privacy questions and requests: [email protected]. Postal address: IGP Global Solutions FZ-LLC, FDRK7851, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates.

Data protection officer: we have not appointed a Data Protection Officer under the GDPR or a privacy protection officer under Israel's Amendment 13, because our current activities do not require one: we do not carry out large-scale processing of special categories of data or large-scale systematic monitoring as a core activity, and we are not a data broker or a public body. We will review this if our activities change. For all privacy matters, contact [email protected].

  • Privacy policy
  • Terms of service
  • Cancellation and refund policy
  • Cookie policy
  • Acceptable use policy
  • Data processing agreement
  • Subprocessors
  • How IGP one uses AI
  • Accessibility statement
  • Delete your data
  • Company details
  • Security and data protection
IGP one

An intelligent growth partner. A little more room to run your business.

Product

The AI agentContent studioInbox & repliesBusiness intelligence

Solutions

Cafés & restaurantsRetailClinics & healthcareBeauty salons & spasGyms & studiosReal estateE-commerce brandsAgencies

Resources

ResourcesIntegrationsPricingService statusDesign release notes

Company

About IGP oneContactSecurity and data protectionCompany details
EnglishעבריתالعربيةEspañolFrançaisDeutschPortuguêsРусский
© 2026 IGP Global Solutions FZ-LLCRAK Economic Zone · United Arab Emirates[email protected]All rights reserved.
Privacy policyTerms of serviceCancellation and refund policyCookie policyAcceptable use policyData processing agreementSubprocessorsHow IGP one uses AIAccessibility statementDelete your data