Policy

Data Processing Agreement (DPA) & Compliance

Data Processing Agreement (DPA) & Compliance Framework

Includes

  • Data Processing Agreement (GDPR)

  • GDPR, UK GDPR & CCPA Compliance Statement

  • Security & Compliance Framework

  • International Data Transfers

Effective Date: 30th June 2026

Last Updated: 30th June 2026


DATA PROCESSING AGREEMENT (DPA)

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between InstaDM ("Processor", "we", "our", or "us") and the customer ("Controller", "you", or "your").

This DPA applies whenever InstaDM processes Personal Data on behalf of a customer subject to applicable privacy laws, including but not limited to:

  • EU General Data Protection Regulation (GDPR)

  • UK GDPR

  • California Consumer Privacy Act (CCPA), as amended by the CPRA

  • Other applicable privacy laws where relevant

If there is any conflict between this DPA and the Terms of Service regarding data processing, this DPA shall prevail.


2. Definitions

For purposes of this DPA:

Controller means the entity determining the purposes and means of processing Personal Data.

Processor means InstaDM, processing Personal Data on behalf of the Controller.

Personal Data means information relating to an identified or identifiable individual.

Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, deletion, or transfer.

Subprocessor means a third party engaged by InstaDM to process Personal Data on behalf of the Controller.


3. Scope of Processing

InstaDM processes Personal Data solely for the purpose of providing the Services described in the Terms of Service.

Processing activities may include:

  • User authentication

  • Account management

  • Social media automation

  • AI-assisted responses

  • Customer support

  • Analytics

  • Billing administration

  • Security monitoring

  • Backup and recovery


4. Categories of Personal Data

Depending on customer use, processing may include:

Customer Account Information

  • Name

  • Email address

  • Company information

  • Subscription details

Platform Usage Data

  • Login history

  • Device information

  • Browser information

  • IP address

  • Session activity

Connected Platform Data

  • Instagram account identifiers

  • Threads account identifiers

  • Public profile information

  • Comments

  • Messages

  • Engagement metrics

Customer Content

  • AI prompts

  • Uploaded documents

  • Workflow configurations

  • Knowledge base content

  • Automation rules


5. Categories of Data Subjects

Processing may relate to:

  • Customers

  • Customer employees

  • Customer administrators

  • End users

  • Social media followers

  • Prospective customers

  • Business contacts

  • Website visitors


6. Processor Obligations

InstaDM agrees to:

  • Process Personal Data only on documented customer instructions.

  • Maintain appropriate technical and organizational security measures.

  • Ensure confidentiality of personnel.

  • Limit access to authorized personnel.

  • Assist customers with applicable legal obligations where reasonably possible.

  • Notify customers of verified Personal Data breaches where required by law.

  • Delete or return Personal Data upon termination, unless legally required to retain it.


7. Customer Responsibilities

Customers are responsible for:

  • Determining the lawful basis for processing.

  • Providing required privacy notices.

  • Obtaining necessary consents.

  • Ensuring uploaded data is lawfully collected.

  • Configuring Services appropriately.

  • Responding to data subject requests unless otherwise agreed.


8. Security Measures

InstaDM maintains safeguards including:

  • TLS encryption

  • Encryption at rest where applicable

  • Role-based access controls

  • Multi-factor authentication for administrative systems where supported

  • Audit logging

  • Network security controls

  • Regular vulnerability management

  • Secure software development practices

  • Backup procedures

  • Incident response processes


9. Personal Data Breaches

Upon becoming aware of a confirmed Personal Data breach affecting customer information, InstaDM will:

  • Investigate promptly.

  • Contain the incident.

  • Assess impact.

  • Notify affected customers without undue delay where legally required.

  • Provide available information necessary to support customer compliance obligations.


10. Subprocessors

Customers authorize InstaDM to engage trusted Subprocessors for providing the Services.

All Subprocessors are contractually required to:

  • Maintain appropriate security controls.

  • Process Personal Data only as instructed.

  • Comply with applicable privacy obligations.

A current list of Subprocessors is maintained on our Trust Center.


11. International Transfers

Where Personal Data is transferred internationally, InstaDM implements appropriate safeguards, which may include:

  • Standard Contractual Clauses (SCCs), where applicable

  • Contractual protections

  • Technical safeguards

  • Organizational safeguards


12. Data Subject Rights

Where applicable, InstaDM will reasonably assist customers in responding to requests involving:

  • Access

  • Rectification

  • Erasure

  • Restriction

  • Portability

  • Objection

  • Withdrawal of consent


13. Audits

Upon reasonable written request and subject to confidentiality obligations, InstaDM may provide information demonstrating compliance with this DPA.

To protect the security of all customers, onsite audits may be limited or replaced by:

  • Independent audit reports

  • Security questionnaires

  • Compliance documentation

  • Policy reviews


14. Termination

Upon termination of the Services, Personal Data will be handled in accordance with our Data Retention Policy unless retention is required by law.


COMPLIANCE FRAMEWORK

Privacy Regulations

InstaDM is committed to operating in accordance with applicable privacy and data protection laws.

Our compliance program is designed to support customers subject to:

GDPR

We support GDPR principles including:

  • Lawfulness

  • Fairness

  • Transparency

  • Purpose limitation

  • Data minimization

  • Accuracy

  • Storage limitation

  • Integrity

  • Confidentiality

  • Accountability


UK GDPR

Where applicable, we support requirements under the UK General Data Protection Regulation.


CCPA / CPRA

For California residents, InstaDM is committed to supporting rights including:

  • Right to Know

  • Right to Delete

  • Right to Correct

  • Right to Opt-Out where applicable

  • Right to Non-Discrimination

InstaDM does not sell personal information as defined under the CCPA.


Other Privacy Laws

Our privacy program is designed to adapt to evolving regulations, including applicable regional and national privacy laws.


Security Compliance

Our security program includes controls aligned with recognized industry practices.

These include:

  • Encryption

  • Identity and access management

  • Logging and monitoring

  • Secure development lifecycle

  • Vulnerability management

  • Incident response

  • Backup and disaster recovery

  • Vendor risk management

  • Employee security awareness

  • Change management


SOC 2 Readiness

InstaDM's security program is designed with the SOC 2 Trust Services Criteria in mind.

Our controls support the following principles:

Security

Protection against unauthorized access.

Availability

Reliable and resilient service operations.

Confidentiality

Protection of sensitive information.

Processing Integrity

Accurate and authorized processing.

Privacy

Responsible handling of Personal Data.

Where applicable, customers may request additional compliance information through our Trust Center.


AI Governance

AI features are governed by our AI Usage & Data Handling Policy.

Our approach emphasizes:

  • Human oversight

  • Responsible AI

  • Privacy

  • Transparency

  • Data minimization

  • Customer control

  • Security


Vendor Management

All critical service providers undergo security and privacy review before being engaged.

Vendor evaluations may consider:

  • Security controls

  • Privacy commitments

  • Reliability

  • Business continuity

  • Regulatory compliance


Business Continuity

We maintain procedures supporting:

  • Disaster recovery

  • Backup management

  • Incident response

  • Infrastructure resilience

  • Operational continuity


Contact

Support support@instadm.us

Website https://instadm.us


Related Documents

  • Privacy Policy

  • Terms of Service

  • Security Policy

  • Cookie Policy

  • Service Level Agreement

  • Platform Usage & AI Governance Policy

  • Data Retention & Vulnerability Disclosure Policy

  • Trust Center


© 2026 InstaDM. All rights reserved.

We may use cookies or any other tracking technologies when you visit our website, including any other media form, mobile website, or mobile application related or connected to help customize the Site and improve your experience. learn more

Allow