This agreement is made under Article 28 of the GDPR between you (the Controller) and LINKPRO AI, S.L., CIF B93832897, of Plaza de la Iglesia, Edificio Plaza de San Pedro, N.º 3, Puerta A, 29670 Marbella (Málaga), Spain (the Processor).
It takes effect automatically when you accept the Terms of Service. There is nothing to sign and nothing to request. If your procurement process needs a countersigned copy, email privacy@dmhandled.com and we will sign one.
It covers personal data of the people who message your connected accounts, which we process only to run DM Handled for you.
It does not cover your own account and billing data — for that we are the controller and the Privacy Policy applies.
| Subject matter | Answering inbound direct messages on the Instagram, Facebook and WhatsApp accounts the Controller connects. |
|---|---|
| Duration | For as long as the subscription lasts, plus the deletion period in clause 9. |
| Nature and purpose | Receiving inbound messages; retrieving the Controller's own knowledge; generating a reply with a language model; sending it through Meta's official APIs; storing the conversation so the Controller can read it. |
| Types of personal data | The platform user ID and display name of the person messaging; the content of their messages and our replies; timestamps. Whatever else that person chooses to write — which the Controller cannot control and neither can we. |
| Categories of data subject | People who send a direct message to the Controller's connected accounts. |
| Special categories | Not requested and not required. A person may nonetheless volunteer health or similar data in a message. The service is built to detect medical, legal and financial subjects and hand them to a human rather than answer them, and that content is stored under the same protections as everything else. |
You give general authorisation for us to use the sub-processors listed at dmhandled.com/legal/subprocessors, which is the live list.
Before adding or replacing one we will email you at least 30 days beforehand. You may object on reasonable data-protection grounds within those 30 days; if we cannot resolve it, you may terminate and we will refund the unused part of any prepaid period.
Each sub-processor is bound by written terms no weaker than these, and we remain fully liable to you for what they do.
Storage by the Processor is entirely within the EU. Two flows reach outside it and both are set out squarely.
Meta is not one of our transfers. Instagram, Facebook and WhatsApp messages are on Meta's infrastructure under the Controller's own agreement with Meta, before and independently of anything we do. We access them through Meta's official APIs with the authorisation the Controller granted. Meta is not our sub-processor and this agreement does not purport to govern it.
One transfer is ours. Generating a reply sends the inbound message, the recent conversation and your knowledge and voice examples to Anthropic PBC (United States). The reply returns to the EU and is stored there.
The transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Three: processor to sub-processor), with a transfer impact assessment on file and available on request. Anthropic does not use the content to train models.
Stripe and Cloudflare involve US processing on the same clauses, for billing data and DNS respectively. Neither receives your customers' message content.
We will notify you without undue delay and in any event within 48 hours of becoming aware of a breach affecting your data, with what we know: what happened, which data and roughly how many people, the likely consequences and what we are doing. You make the call on notifying the supervisory authority and the individuals, because you are the controller; we will give you everything you need to do it.
We will make available the information needed to show we comply. You may audit once in any 12 months, on 30 days' written notice, during business hours, without disrupting the service and without access to other customers' data. You cover your own costs. If a supervisory authority requires more, we will do what it requires.
You can delete any conversation from the app at any time, and it is gone.
On termination we delete all personal data processed on your behalf within 30 days, backups included as they expire on their normal cycle, which is no longer than 35 days. Export what you need first. We will confirm deletion in writing if you ask.
This agreement is governed by Spanish law and forms part of the Terms of Service. Where they conflict on personal data, this agreement prevails. The liability cap in the Terms applies here too, except where the GDPR does not permit it.