Data Processing Agreement (DPA) & Compliance
Data Processing Agreement (DPA) & Compliance Framework
Includes
Data Processing Agreement (GDPR)
GDPR, UK GDPR & CCPA Compliance Statement
Security & Compliance Framework
International Data Transfers
Effective Date: 30th June 2026
Last Updated: 30th June 2026
DATA PROCESSING AGREEMENT (DPA)
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between InstaDM ("Processor", "we", "our", or "us") and the customer ("Controller", "you", or "your").
This DPA applies whenever InstaDM processes Personal Data on behalf of a customer subject to applicable privacy laws, including but not limited to:
EU General Data Protection Regulation (GDPR)
UK GDPR
California Consumer Privacy Act (CCPA), as amended by the CPRA
Other applicable privacy laws where relevant
If there is any conflict between this DPA and the Terms of Service regarding data processing, this DPA shall prevail.
2. Definitions
For purposes of this DPA:
Controller means the entity determining the purposes and means of processing Personal Data.
Processor means InstaDM, processing Personal Data on behalf of the Controller.
Personal Data means information relating to an identified or identifiable individual.
Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, deletion, or transfer.
Subprocessor means a third party engaged by InstaDM to process Personal Data on behalf of the Controller.
3. Scope of Processing
InstaDM processes Personal Data solely for the purpose of providing the Services described in the Terms of Service.
Processing activities may include:
User authentication
Account management
Social media automation
AI-assisted responses
Customer support
Analytics
Billing administration
Security monitoring
Backup and recovery
4. Categories of Personal Data
Depending on customer use, processing may include:
Customer Account Information
Name
Email address
Company information
Subscription details
Platform Usage Data
Login history
Device information
Browser information
IP address
Session activity
Connected Platform Data
Instagram account identifiers
Threads account identifiers
Public profile information
Comments
Messages
Engagement metrics
Customer Content
AI prompts
Uploaded documents
Workflow configurations
Knowledge base content
Automation rules
5. Categories of Data Subjects
Processing may relate to:
Customers
Customer employees
Customer administrators
End users
Social media followers
Prospective customers
Business contacts
Website visitors
6. Processor Obligations
InstaDM agrees to:
Process Personal Data only on documented customer instructions.
Maintain appropriate technical and organizational security measures.
Ensure confidentiality of personnel.
Limit access to authorized personnel.
Assist customers with applicable legal obligations where reasonably possible.
Notify customers of verified Personal Data breaches where required by law.
Delete or return Personal Data upon termination, unless legally required to retain it.
7. Customer Responsibilities
Customers are responsible for:
Determining the lawful basis for processing.
Providing required privacy notices.
Obtaining necessary consents.
Ensuring uploaded data is lawfully collected.
Configuring Services appropriately.
Responding to data subject requests unless otherwise agreed.
8. Security Measures
InstaDM maintains safeguards including:
TLS encryption
Encryption at rest where applicable
Role-based access controls
Multi-factor authentication for administrative systems where supported
Audit logging
Network security controls
Regular vulnerability management
Secure software development practices
Backup procedures
Incident response processes
9. Personal Data Breaches
Upon becoming aware of a confirmed Personal Data breach affecting customer information, InstaDM will:
Investigate promptly.
Contain the incident.
Assess impact.
Notify affected customers without undue delay where legally required.
Provide available information necessary to support customer compliance obligations.
10. Subprocessors
Customers authorize InstaDM to engage trusted Subprocessors for providing the Services.
All Subprocessors are contractually required to:
Maintain appropriate security controls.
Process Personal Data only as instructed.
Comply with applicable privacy obligations.
A current list of Subprocessors is maintained on our Trust Center.
11. International Transfers
Where Personal Data is transferred internationally, InstaDM implements appropriate safeguards, which may include:
Standard Contractual Clauses (SCCs), where applicable
Contractual protections
Technical safeguards
Organizational safeguards
12. Data Subject Rights
Where applicable, InstaDM will reasonably assist customers in responding to requests involving:
Access
Rectification
Erasure
Restriction
Portability
Objection
Withdrawal of consent
13. Audits
Upon reasonable written request and subject to confidentiality obligations, InstaDM may provide information demonstrating compliance with this DPA.
To protect the security of all customers, onsite audits may be limited or replaced by:
Independent audit reports
Security questionnaires
Compliance documentation
Policy reviews
14. Termination
Upon termination of the Services, Personal Data will be handled in accordance with our Data Retention Policy unless retention is required by law.
COMPLIANCE FRAMEWORK
Privacy Regulations
InstaDM is committed to operating in accordance with applicable privacy and data protection laws.
Our compliance program is designed to support customers subject to:
GDPR
We support GDPR principles including:
Lawfulness
Fairness
Transparency
Purpose limitation
Data minimization
Accuracy
Storage limitation
Integrity
Confidentiality
Accountability
UK GDPR
Where applicable, we support requirements under the UK General Data Protection Regulation.
CCPA / CPRA
For California residents, InstaDM is committed to supporting rights including:
Right to Know
Right to Delete
Right to Correct
Right to Opt-Out where applicable
Right to Non-Discrimination
InstaDM does not sell personal information as defined under the CCPA.
Other Privacy Laws
Our privacy program is designed to adapt to evolving regulations, including applicable regional and national privacy laws.
Security Compliance
Our security program includes controls aligned with recognized industry practices.
These include:
Encryption
Identity and access management
Logging and monitoring
Secure development lifecycle
Vulnerability management
Incident response
Backup and disaster recovery
Vendor risk management
Employee security awareness
Change management
SOC 2 Readiness
InstaDM's security program is designed with the SOC 2 Trust Services Criteria in mind.
Our controls support the following principles:
Security
Protection against unauthorized access.
Availability
Reliable and resilient service operations.
Confidentiality
Protection of sensitive information.
Processing Integrity
Accurate and authorized processing.
Privacy
Responsible handling of Personal Data.
Where applicable, customers may request additional compliance information through our Trust Center.
AI Governance
AI features are governed by our AI Usage & Data Handling Policy.
Our approach emphasizes:
Human oversight
Responsible AI
Privacy
Transparency
Data minimization
Customer control
Security
Vendor Management
All critical service providers undergo security and privacy review before being engaged.
Vendor evaluations may consider:
Security controls
Privacy commitments
Reliability
Business continuity
Regulatory compliance
Business Continuity
We maintain procedures supporting:
Disaster recovery
Backup management
Incident response
Infrastructure resilience
Operational continuity
Contact
Support support@instadm.us
Website https://instadm.us
Related Documents
Privacy Policy
Terms of Service
Security Policy
Cookie Policy
Service Level Agreement
Platform Usage & AI Governance Policy
Data Retention & Vulnerability Disclosure Policy
Trust Center
© 2026 InstaDM. All rights reserved.