HomePricing Start free

Privacy Policy

Effective 13 September 2026 · LINKPRO AI, S.L. · CIF B93832897

PrivacyTermsData processingSub-processorsCookiesLegal notice

This policy explains what we do with personal data. It covers two different things, and it is worth being clear which is which from the outset.

Your data — your name, your email, your company, your billing details. We decide what happens to it, so for this we are the controller and this policy governs it.

Your customers' data — the people who message your Instagram, Facebook or WhatsApp account, and what they write. You decide what happens to it. We only act on your instructions, so for this we are the processor and the Data Processing Agreement governs it, not this policy.

1. Who we are

LINKPRO AI, S.L., CIF B93832897, registered at Plaza de la Iglesia, Edificio Plaza de San Pedro, N.º 3, Puerta A, 29670 Marbella (Málaga), Spain. Registered in the Registro Mercantil de Málaga, hoja MA-200123, inscripción 1.ª, 22 July 2026. We trade as DM Handled.

Write to privacy@dmhandled.com about anything on this page. We are not required to appoint a Data Protection Officer and have not appointed one; that address reaches the people who can actually answer.

2. What we collect about you, and why

WhatWhyLawful basisKept for
Name, email, password hashTo give you an account and let you log in Performance of the contractLife of the account, then 30 days
Company name, address, VAT numberTo invoice you correctly Legal obligation (Spanish tax law)6 years — we cannot delete these earlier, even on request
Card detailsTo take paymentPerformance of the contract We never see or store them — Stripe does
The knowledge and voice examples you give us So the agent can answer in your voicePerformance of the contract Life of the account, then 30 days
Login times, IP address, audit log of changes Security, and being able to tell you what happened Legitimate interest in keeping the service secure12 months
Support emails you send usTo answer you Legitimate interest in supporting customers24 months

3. Where it is stored, and where it goes

Everything we store is stored in the European Union — on our own servers at Hetzner, in Germany and Finland. That includes every conversation, all of your knowledge, your account record and our backups.

Two things sit outside the EU, and you should read them here rather than find them later. We would rather set them out plainly than let you infer that nothing ever leaves Europe, which would not be accurate.

Meta. Instagram, Facebook and WhatsApp messages are on Meta's infrastructure before we ever see them, under your own agreement with Meta. That is true whether or not you use us, and no tool can change it. We read and reply through Meta's official APIs using the access you granted.

Anthropic. To write a reply, the incoming message, the recent conversation and your knowledge and voice examples are sent to Anthropic PBC in the United States, which operates the Claude model that generates the text. The reply comes back and is stored in the EU. This transfer is made under the European Commission's Standard Contractual Clauses, and Anthropic does not use the content to train its models.

What is genuinely ours to promise is this: we are a Spanish company, our servers are in the EU, your contract and your data processing agreement are governed by Spanish law, and your supervisory authority is the AEPD. Everyone else who touches your data is named on the sub-processors page, with where they are.

The full list of everyone who processes data on our behalf, what they do and where they are, is at Sub-processors.

4. Who we do not sell to

We do not sell personal data. We do not share it for advertising. We do not build profiles of you or of the people who message you, and we do not use your conversations to train any model, ours or anyone else's.

5. Your rights

Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, hand it to you in a portable format, restrict what we do with it, or object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time.

Ask at privacy@dmhandled.com. We answer within one month. There is no charge unless a request is manifestly excessive, and we will say so before doing anything rather than afterwards.

If you are unhappy with how we have handled it, you can complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (www.aepd.es), or to the authority where you live. We would rather you told us first, but it is your right either way.

6. Deleting your data

This section is for the people who message our customers, as well as for customers themselves. Meta requires us to say plainly how deletion works, and it should be plain anyway.

If you messaged a business that uses DM Handled and want everything we hold about you gone, either route works and both are real:

1. Remove DM Handled in your Facebook or Instagram settings. Meta tells us automatically, we delete your data, and you get a confirmation code you can check at app.dmhandled.com/data-deletion. Nothing is manual and nobody has to be asked.

2. Email privacy@dmhandled.com. We answer within one month, usually the same week.

Deletion covers every business using DM Handled that you have messaged, not just one of them.

⚠️ Your messages also exist on Instagram, Facebook or WhatsApp themselves, under your own agreement with Meta. Removing them there is separate and is done in that app — we cannot do it for you and would not want the ability to.

If you are a customer, you can delete any conversation from inside the app at any time, and closing your account deletes everything within 30 days — except the billing records Spanish tax law requires us to keep for six years (section 2).

7. Security

Traffic is encrypted in transit with TLS. The database runs on a three-node cluster across three countries with automatic failover and encrypted backups. Access to production is limited to named people using key-based authentication; there are no shared passwords. Platform access tokens and API keys are held in root-owned files that the application can read and nobody else can.

No system is perfect. If personal data of yours is breached we will tell you without undue delay and, where the law requires it, the AEPD within 72 hours — with what happened, what data, and what we did about it.

8. Children

DM Handled is a business tool and is not offered to children. We do not knowingly collect data from anyone under 16.

9. Changes

If we change this policy in a way that affects you, we will email you at least 30 days before it takes effect. Small corrections get a new date at the top.

Every DM. Handled.
A service of LINKPRO AI, S.L.

Legal
Privacy
Terms
Data processing
Sub-processors
Cookies
Legal notice
Contact
privacy@dmhandled.com
hello@dmhandled.com