Data Retention & Vulnerability Disclosure Policy
Data Retention & Vulnerability Disclosure Policy
Includes
Data Retention Policy
Vulnerability Disclosure Policy
Effective Date: 30th June 2026
Last Updated: 30th June 2026
Introduction
At InstaDM ("InstaDM", "we", "our", or "us"), protecting customer data and maintaining a secure platform are fundamental to our operations.
This document describes:
How long we retain different categories of information.
How data is securely deleted or anonymized.
How security researchers can responsibly report vulnerabilities.
How we investigate and respond to reported security issues.
This Policy should be read together with our:
Privacy Policy
Security Policy
Terms of Service
Platform Usage & AI Governance Policy
PART I
Data Retention Policy
1. Purpose
We retain information only for legitimate business purposes, legal obligations, customer support, security, and service delivery.
We do not retain personal information longer than necessary.
2. Retention Principles
Our retention practices are based on the following principles:
Data minimization
Purpose limitation
Legal compliance
Customer privacy
Operational continuity
Security
Business continuity
Disaster recovery
3. Types of Data We Retain
Depending on your use of the Services, we may retain:
Account Information
Examples include:
Name
Email address
Company name
Subscription details
Authentication information
Billing profile
Connected accounts
Platform Activity
Examples include:
Login history
User settings
Connected social accounts
Automation workflows
Campaign configuration
API usage
Device information
Customer Content
Examples include:
Messages
Comments
AI prompts
AI-generated responses
Uploaded knowledge bases
Templates
Conversation history
Security Logs
Examples include:
Login attempts
IP addresses
Authentication events
Security alerts
Audit logs
Administrative actions
Billing Records
Examples include:
Subscription history
Invoices
Payment confirmations
Tax records
Payment card information is processed by our payment providers and is not stored on InstaDM servers.
4. Standard Retention Periods
Unless a longer period is required by law or contract, we generally retain data as follows.
| Data Category | Typical Retention |
|---|---|
| Account information | While account remains active |
| Subscription records | Duration of subscription plus applicable legal period |
| Support tickets | Up to 3 years |
| Security logs | Up to 24 months |
| Authentication logs | Up to 12 months |
| AI prompts and responses | As required to provide the service and according to customer settings |
| Analytics data | Aggregated or anonymized where possible |
| Billing records | As required by applicable tax and accounting laws |
| Backup copies | According to backup rotation schedules |
These periods may vary based on contractual obligations, legal requirements, or customer-specific agreements.
5. Account Deletion
Customers may request deletion of their account.
Following account closure:
Active services are terminated.
Customer access is removed.
Personal information is scheduled for deletion.
Connected platform credentials are revoked where applicable.
Certain information may be retained where required for:
Legal obligations
Fraud prevention
Security investigations
Tax compliance
Contract enforcement
Dispute resolution
6. Backup Retention
For business continuity, encrypted backups may temporarily contain deleted information until backup rotation cycles are completed.
Backups are:
Encrypted
Access restricted
Used only for disaster recovery
Deleted according to internal retention schedules
7. Data Anonymization
Where appropriate, information may be anonymized rather than deleted.
Anonymized information cannot reasonably identify an individual and may be used for:
Platform improvement
Performance analysis
Service planning
Product analytics
Capacity planning
8. Legal Holds
If required by law or during an active legal matter, deletion requests may be delayed until legal obligations have been satisfied.
9. Customer Responsibilities
Customers are responsible for:
Downloading information they wish to retain before closing an account.
Maintaining their own business records where required.
Managing exported data securely after download.
PART II
Vulnerability Disclosure Policy
10. Our Commitment
Security researchers play an important role in improving internet security.
We welcome responsible disclosure of legitimate security vulnerabilities affecting InstaDM.
We appreciate researchers who work with us to improve the security of our platform.
11. Scope
This Policy applies to vulnerabilities affecting:
instadm.us
Customer dashboard
Public APIs
Authentication systems
Web application
Mobile applications (if applicable)
Official integrations
Cloud-hosted services operated by InstaDM
12. Responsible Disclosure Guidelines
Researchers should:
Act in good faith.
Avoid privacy violations.
Avoid service disruption.
Avoid destroying or modifying data.
Report findings promptly.
Give us reasonable time to investigate before public disclosure.
13. Prohibited Testing
The following activities are not permitted:
Social engineering
Physical security testing
Denial-of-service attacks
Spam campaigns
Brute-force attacks
Malware deployment
Data destruction
Accessing customer data beyond what is necessary to demonstrate the issue
Attempting to extort payment
14. Safe Harbor
If you conduct security research in accordance with this Policy, we will generally consider your activities authorized and will not pursue legal action solely for compliant research.
This Safe Harbor does not apply to activities that:
Cause harm to users.
Violate applicable laws.
Access or disclose customer information unnecessarily.
Disrupt service availability.
Involve malicious intent.
15. How to Report a Vulnerability
Please include:
Description of the issue
Steps to reproduce
Affected URL or endpoint
Potential impact
Proof of concept where appropriate
Suggested remediation, if available
Send reports to:
Email: security@instadm.us
Subject:
Security Vulnerability Report
16. What to Expect
After receiving your report, we aim to:
Acknowledge receipt within a reasonable timeframe.
Review the submission.
Assess severity.
Prioritize remediation.
Keep you informed of significant progress where appropriate.
Response times may vary depending on the complexity and impact of the issue.
17. Severity Assessment
Reported vulnerabilities are evaluated based on factors including:
Ease of exploitation
Potential customer impact
Confidentiality risk
Integrity risk
Availability risk
Business impact
Exposure
Critical issues receive the highest priority.
18. Coordinated Disclosure
We request that researchers avoid public disclosure until:
The issue has been resolved,
Mitigations have been implemented, or
We mutually agree on an appropriate disclosure timeline.
19. Recognition
At our discretion, we may acknowledge researchers who responsibly disclose valid vulnerabilities.
Recognition may include:
Public thanks (with permission)
Hall of Fame listing
Appreciation certificates
Future bug bounty participation if offered
Recognition is not guaranteed and does not imply financial compensation.
20. Policy Updates
We may update this Policy periodically to reflect changes in our security practices, legal obligations, or operational requirements.
The latest version will always be available on our website.
Contact
For questions regarding this Policy or to report a security concern, contact:
Security Team
General Support: support@instadm.us
Website: https://instadm.us
Related Documents
This Policy should be read together with our:
Privacy Policy
Terms of Service
Security Policy
Cookie Policy
Platform Usage & AI Governance Policy
Service Level Agreement (SLA)
Data Processing Agreement (where applicable)
© 2026 InstaDM. All rights reserved.