Privacy Policy
Effective: [Owner to confirm: effective date of this version]
This policy explains what personal data [Owner to confirm: company legal name] ("Artify Solutions", "we") collects through artifysols.com and through our Control Center software, why, how long we keep it, who else handles it, and how you can ask us to delete it.
Registered address: [Owner to confirm: registered business address]. Contact for privacy questions and requests: [Owner to confirm: privacy contact email].
1. Who this covers
- People who visit artifysols.com or one of our landing pages.
- People who send us a message or fill in a form (enquiries, briefs, partner access requests).
- Customers and their staff who use the Control Center.
- People who write to, comment on, mention or message a Facebook Page or Instagram professional account that one of our customers (or we) manage through the Control Center.
2. What we collect
We do not sell personal data. We do not use data received from Meta to build advertising profiles, and we do not share it with data brokers.
| Data | Where it comes from | What we do with it |
|---|---|---|
| Page views: page path, referrer, campaign (UTM) tags and a random identifier that lives only in your browser tab | Our website | Count visits and measure which pages and campaigns work. No names or email addresses are stored with these events. |
| Form and landing page submissions: the answers you type (for example name, email, phone, company, message), the page you were on, your IP address and browser details, whether you ticked the consent box | You | Reply to you, create a lead in our CRM, keep proof of consent, protect forms from abuse. |
| Customer account data: name, work email, role, login history, security settings | You or your administrator | Run your account and keep it secure. Passwords are stored only as one-way hashes. |
| Facebook/Instagram messages, comments, mentions and visitor posts sent to a connected Page or professional account: the text, the sender's public name or handle and Meta's identifier for them, time stamps | Meta, through the permissions the connecting customer grants | Show them in the shared inbox, let the customer reply, and measure response times. |
| Facebook/Instagram account and Page information and performance numbers (followers, reach, engagement, post metrics) | Meta, with the connecting person's permission | Show analytics to the customer who connected the account. |
| Access tokens that let the Control Center act on a connected Page or Instagram account | Meta, when a person connects an account | Publish, read and reply on that account. Stored encrypted; never shown in the interface or logs. Deleted when the account is disconnected or Meta tells us access was removed. |
| Audit records: who did what and when inside the Control Center | Generated by the system | Security and accountability. They contain identifiers and counts, not message text. |
3. Why we use it (purposes)
Where the law requires a legal basis, we rely on: performing a contract with our customers; our legitimate interest in running and securing the service and measuring the website; your consent where we ask for it (for example the tick box on a form); and legal obligation. [Owner to confirm: confirm the legal bases and the regulations that apply to you, for example UAE PDPL and GDPR]
- To provide and secure the Control Center and the website.
- To answer enquiries and manage customer relationships.
- To let a customer manage their own Facebook Page and Instagram account: publish posts, read and answer messages and comments, and see analytics.
- To measure how the website performs.
- To meet legal obligations and to keep records of consent and of how privacy requests were handled.
4. Automated processing (AI)
The Control Center can use an AI model to classify incoming messages (topic, sentiment, priority) and to draft replies for a person to review. [Owner to confirm: confirm which AI provider is enabled in production and update this sentence] Draft replies are not sent automatically unless a workspace has explicitly switched automatic replies on, which is off by default. We do not use messages received through Meta to train AI models.
5. Who else handles the data
[Owner to confirm: confirm the hosting regions and any transfer mechanism you rely on for data stored outside your country]
- Hosting and delivery of the website and API: Vercel.
- Database: Supabase (PostgreSQL).
- Facebook and Instagram: Meta Platforms. When a customer connects an account, Meta's own privacy policy applies to the data on Meta's side.
- AI processing, if enabled: the provider named in section 4.
- Email delivery: [Owner to confirm: email provider, or "none: we do not currently send email from the platform"].
- Professional advisers, authorities and courts, where we are legally required to disclose.
6. How long we keep it
[Owner to confirm: confirm these retention periods, which are the platform's current defaults]
| Data | Kept for |
|---|---|
| Social inbox conversations and messages | 180 days by default (each workspace can set 7 to 3650 days), then deleted automatically |
| Website analytics events | 395 days (13 months), then deleted automatically |
| Login sessions after they end | 30 days |
| Encrypted backup exports | 30 days (the newest three are always kept) |
| Leads, contacts, clients and form submissions | While the enquiry or relationship is active; reviewed at least yearly; erased on a verified request |
| Consent register (source, status, time; no personal data) | Kept as proof of consent |
| Audit log and privacy-request records (identifiers and counts only) | Kept for security and accountability |
| Facebook/Instagram access tokens | Until the account is disconnected, access is removed on Meta's side, or you ask us to delete your data |
7. Your rights and how to use them
Depending on where you live you may have the right to ask for a copy of your data, to correct it, to have it deleted, to restrict or object to its use, and to withdraw consent. To use any of these, email [Owner to confirm: privacy contact email] from the address we hold for you, or use the steps on our Data Deletion page (/data-deletion). We may need to confirm it is you. We aim to answer within [Owner to confirm: response time you commit to, for example 30 days].
You can also complain to your data protection authority. [Owner to confirm: name the authority for your jurisdiction]
8. Deleting data that came from Facebook or Instagram
If you used Facebook or Instagram to sign in to a service of ours, or you want data that came from Meta removed, see /data-deletion. You can remove Artify Solutions from your Facebook settings at any time; Facebook then tells us, and we disconnect the account and delete the stored access tokens. You can also ask Facebook to send us a data deletion request: we confirm it with a code and a status page, a team member reviews it, and then we delete or anonymise the data we hold that is linked to your Facebook account.
9. Security
Access to the Control Center is controlled by roles and permissions; sensitive actions such as erasing personal data need a second person to approve; access tokens are stored encrypted; data is encrypted in transit; every privacy action is recorded in an audit log. No system is perfectly secure; if a breach affects you we will notify you and the authorities as the law requires.
10. Children
Our services are for businesses and are not directed at children. [Owner to confirm: confirm the minimum age you apply]
11. Changes
If we make a material change we will update the date at the top of this page and, where the change affects how we use data you gave us, tell you directly.