Policy

Data Retention & Vulnerability Disclosure Policy

Data Retention & Vulnerability Disclosure Policy

Includes

  • Data Retention Policy

  • Vulnerability Disclosure Policy

Effective Date: 30th June 2026

Last Updated: 30th June 2026


Introduction

At InstaDM ("InstaDM", "we", "our", or "us"), protecting customer data and maintaining a secure platform are fundamental to our operations.

This document describes:

  • How long we retain different categories of information.

  • How data is securely deleted or anonymized.

  • How security researchers can responsibly report vulnerabilities.

  • How we investigate and respond to reported security issues.

This Policy should be read together with our:

  • Privacy Policy

  • Security Policy

  • Terms of Service

  • Platform Usage & AI Governance Policy


PART I

Data Retention Policy

1. Purpose

We retain information only for legitimate business purposes, legal obligations, customer support, security, and service delivery.

We do not retain personal information longer than necessary.


2. Retention Principles

Our retention practices are based on the following principles:

  • Data minimization

  • Purpose limitation

  • Legal compliance

  • Customer privacy

  • Operational continuity

  • Security

  • Business continuity

  • Disaster recovery


3. Types of Data We Retain

Depending on your use of the Services, we may retain:

Account Information

Examples include:

  • Name

  • Email address

  • Company name

  • Subscription details

  • Authentication information

  • Billing profile

  • Connected accounts


Platform Activity

Examples include:

  • Login history

  • User settings

  • Connected social accounts

  • Automation workflows

  • Campaign configuration

  • API usage

  • Device information


Customer Content

Examples include:

  • Messages

  • Comments

  • AI prompts

  • AI-generated responses

  • Uploaded knowledge bases

  • Templates

  • Conversation history


Security Logs

Examples include:

  • Login attempts

  • IP addresses

  • Authentication events

  • Security alerts

  • Audit logs

  • Administrative actions


Billing Records

Examples include:

  • Subscription history

  • Invoices

  • Payment confirmations

  • Tax records

Payment card information is processed by our payment providers and is not stored on InstaDM servers.


4. Standard Retention Periods

Unless a longer period is required by law or contract, we generally retain data as follows.

Data CategoryTypical Retention
Account informationWhile account remains active
Subscription recordsDuration of subscription plus applicable legal period
Support ticketsUp to 3 years
Security logsUp to 24 months
Authentication logsUp to 12 months
AI prompts and responsesAs required to provide the service and according to customer settings
Analytics dataAggregated or anonymized where possible
Billing recordsAs required by applicable tax and accounting laws
Backup copiesAccording to backup rotation schedules

These periods may vary based on contractual obligations, legal requirements, or customer-specific agreements.


5. Account Deletion

Customers may request deletion of their account.

Following account closure:

  • Active services are terminated.

  • Customer access is removed.

  • Personal information is scheduled for deletion.

  • Connected platform credentials are revoked where applicable.

Certain information may be retained where required for:

  • Legal obligations

  • Fraud prevention

  • Security investigations

  • Tax compliance

  • Contract enforcement

  • Dispute resolution


6. Backup Retention

For business continuity, encrypted backups may temporarily contain deleted information until backup rotation cycles are completed.

Backups are:

  • Encrypted

  • Access restricted

  • Used only for disaster recovery

  • Deleted according to internal retention schedules


7. Data Anonymization

Where appropriate, information may be anonymized rather than deleted.

Anonymized information cannot reasonably identify an individual and may be used for:

  • Platform improvement

  • Performance analysis

  • Service planning

  • Product analytics

  • Capacity planning


8. Legal Holds

If required by law or during an active legal matter, deletion requests may be delayed until legal obligations have been satisfied.


9. Customer Responsibilities

Customers are responsible for:

  • Downloading information they wish to retain before closing an account.

  • Maintaining their own business records where required.

  • Managing exported data securely after download.


PART II

Vulnerability Disclosure Policy

10. Our Commitment

Security researchers play an important role in improving internet security.

We welcome responsible disclosure of legitimate security vulnerabilities affecting InstaDM.

We appreciate researchers who work with us to improve the security of our platform.


11. Scope

This Policy applies to vulnerabilities affecting:

  • instadm.us

  • Customer dashboard

  • Public APIs

  • Authentication systems

  • Web application

  • Mobile applications (if applicable)

  • Official integrations

  • Cloud-hosted services operated by InstaDM


12. Responsible Disclosure Guidelines

Researchers should:

  • Act in good faith.

  • Avoid privacy violations.

  • Avoid service disruption.

  • Avoid destroying or modifying data.

  • Report findings promptly.

  • Give us reasonable time to investigate before public disclosure.


13. Prohibited Testing

The following activities are not permitted:

  • Social engineering

  • Physical security testing

  • Denial-of-service attacks

  • Spam campaigns

  • Brute-force attacks

  • Malware deployment

  • Data destruction

  • Accessing customer data beyond what is necessary to demonstrate the issue

  • Attempting to extort payment


14. Safe Harbor

If you conduct security research in accordance with this Policy, we will generally consider your activities authorized and will not pursue legal action solely for compliant research.

This Safe Harbor does not apply to activities that:

  • Cause harm to users.

  • Violate applicable laws.

  • Access or disclose customer information unnecessarily.

  • Disrupt service availability.

  • Involve malicious intent.


15. How to Report a Vulnerability

Please include:

  • Description of the issue

  • Steps to reproduce

  • Affected URL or endpoint

  • Potential impact

  • Proof of concept where appropriate

  • Suggested remediation, if available

Send reports to:

Email: security@instadm.us

Subject:

Security Vulnerability Report


16. What to Expect

After receiving your report, we aim to:

  • Acknowledge receipt within a reasonable timeframe.

  • Review the submission.

  • Assess severity.

  • Prioritize remediation.

  • Keep you informed of significant progress where appropriate.

Response times may vary depending on the complexity and impact of the issue.


17. Severity Assessment

Reported vulnerabilities are evaluated based on factors including:

  • Ease of exploitation

  • Potential customer impact

  • Confidentiality risk

  • Integrity risk

  • Availability risk

  • Business impact

  • Exposure

Critical issues receive the highest priority.


18. Coordinated Disclosure

We request that researchers avoid public disclosure until:

  • The issue has been resolved,

  • Mitigations have been implemented, or

  • We mutually agree on an appropriate disclosure timeline.


19. Recognition

At our discretion, we may acknowledge researchers who responsibly disclose valid vulnerabilities.

Recognition may include:

  • Public thanks (with permission)

  • Hall of Fame listing

  • Appreciation certificates

  • Future bug bounty participation if offered

Recognition is not guaranteed and does not imply financial compensation.


20. Policy Updates

We may update this Policy periodically to reflect changes in our security practices, legal obligations, or operational requirements.

The latest version will always be available on our website.


Contact

For questions regarding this Policy or to report a security concern, contact:

Security Team

General Support: support@instadm.us

Website: https://instadm.us


Related Documents

This Policy should be read together with our:

  • Privacy Policy

  • Terms of Service

  • Security Policy

  • Cookie Policy

  • Platform Usage & AI Governance Policy

  • Service Level Agreement (SLA)

  • Data Processing Agreement (where applicable)


© 2026 InstaDM. All rights reserved.

We may use cookies or any other tracking technologies when you visit our website, including any other media form, mobile website, or mobile application related or connected to help customize the Site and improve your experience. learn more

Allow