Legal
Privacy Policy
Last updated: 27 July 2026
Welcome to InstaMessage Ltd (“InstaMessage,” “we,” “us,” or “our”). We provide AI-enabled messaging services for businesses and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and safeguard your information when you use our application or services (“Service”). By accessing or using InstaMessage, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use our Service.
1. Scope & Applicability
Geographic reach. InstaMessage is available worldwide. However, our primary focus is on users in the United Kingdom and European Union. We therefore abide by applicable data protection laws, including the UK Data Protection Act 2018 and the General Data Protection Regulation (GDPR).
Business use. Our Service is intended for businesses and not for personal or household use. Children under the age of 16 (or a higher age required by local law) are not permitted to use InstaMessage.
Controller vs processor. For your account and billing information, InstaMessage Ltd acts as the data controller. For message and contact data that you upload and process through our platform, your business is the data controller and InstaMessage Ltd acts as your data processor. We only process such data on your documented instructions, as required to provide the Service.
2. Information We Collect
Account information
- Company name, address, Tax ID, website.
- Contact details (name, email, phone number).
- Login credentials (email and password).
Financial information
- We use third-party providers (e.g. Stripe) to process payments securely.
- We do not store full payment card details ourselves.
Messages & attachments
- Message content (WhatsApp, SMS, RCS, Messenger, live chat) and associated metadata (timestamps, sender/recipient).
- Voice interactions, where enabled: call audio is processed to provide the service and a transcript is stored in the conversation thread. Call audio itself is not retained beyond processing.
- Attachments (e.g. images, documents).
- Customers may store contact data (e.g. recipient phone numbers) in the platform for as long as they maintain an account.
AI processing
- Some data may be processed by third-party AI providers (e.g. OpenAI) in order to deliver features such as sentiment analysis, automated responses, or natural language processing.
- We only send the minimum necessary data for processing.
Cookies & analytics
- We use cookies and similar technologies to operate the Service and analyse usage.
- Our marketing site (instamessage.co.uk) uses Plausible Analytics for traffic measurement. Plausible does not use cookies and does not collect personal data; reporting is aggregate-only.
- Our marketing site also uses Microsoft Clarity for session recordings and heatmaps. Clarity uses cookies and may capture interaction data on pages you visit. Sensitive form fields are masked so they are not recorded.
- Third-party analytics providers may collect device and usage data (e.g. IP address, browser type, time on page).
- You can control cookies through your browser settings. You can opt out of Clarity recordings using Microsoft's opt-out tools.
No sensitive data. We do not request or intentionally collect sensitive personal data (e.g. health, biometric). If you send such information through the Service, you are responsible for ensuring it is lawful to do so.
3. How We Use Your Information
- To create, manage, and verify accounts.
- To process and deliver your messages and campaigns.
- To provide customer support and technical assistance.
- To improve Service performance and troubleshoot issues.
- To send service-related notifications (e.g. billing, system updates).
- To comply with legal and regulatory obligations.
- For AI-based automation features where enabled.
We do not use your data for advertising or sell it to third parties.
4. Legal Bases (UK/EU Users)
We process personal data under GDPR/UK GDPR on the following bases:
- Contract - to deliver the services you request.
- Legitimate interests - to maintain security, prevent abuse, and improve performance.
- Consent - for optional features (e.g. marketing emails, cookies where required). You may withdraw consent at any time.
5. How We Share Your Information
Service providers. We use third-party service providers to operate the Service, including hosting, payment processing, message routing, and analytics. We only share the minimum necessary personal data required for them to perform their duties on our behalf. We do not share data with these providers for their marketing or promotional use.
Key sub-processors. Our principal sub-processors are: Google Cloud (hosting and infrastructure), OpenAI (AI language processing), and Stripe (payment processing), together with the telecommunications carriers that deliver messages and calls. Website analytics providers are listed in Section 9. We will update this list when our sub-processors change.
International transfers. Some sub-processors process data outside the UK/EEA (for example in the United States). Where they do, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses, together with each provider’s own certifications.
Legal obligations. We may disclose your information if required to do so by law or in response to valid requests from governmental authorities or public agencies.
Business transfers. If we undergo a merger, acquisition, or sale of assets, your data may be transferred as part of the business.
With your consent. We may share your information for other purposes not listed here but will seek your consent before doing so.
6. Data Retention
Account data. Retained for as long as you maintain an active account.
Message & contact data. Retained for as long as your account is active (so you may re-use your contacts). If your account is closed, we delete or anonymise this data after 30 days.
Attachments. May be stored for a shorter period (e.g. 7 days) due to storage and security considerations.
Financial/payment records. Retained for six years under UK law.
Support interactions. Typically two years.
7. Security
We implement technical and organisational measures to protect your information, including:
- Encryption in transit and at rest.
- Role-based access controls.
- Logging and monitoring.
- Regular vulnerability assessments.
You are responsible for maintaining the confidentiality of your login credentials.
8. Your Rights
If you are in the UK/EU, you have the right to:
- Access your personal data.
- Correct inaccurate data.
- Request deletion of your data.
- Restrict or object to processing.
- Data portability (obtain a copy in a portable format).
- Lodge a complaint with the Information Commissioner’s Office (ICO) in the UK or your local regulator in the EU.
You can manage much of your data directly via your account settings.
9. Cookies & Tracking
We use cookies to:
- Keep you signed in.
- Remember preferences.
- Measure performance.
You may disable cookies in your browser, but some features of the Service may not function properly. You can manage much of your data directly via your account settings.
10. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by the “Last updated” date above.
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our privacy practices, please contact us.