PERSONAL DATA
This policy describes how PARADEYES processes personal data in connection with the IRIS for Instagram service, a conversational agent deployed on the Instagram messaging of PARADEYES client businesses to respond to their prospects and customers.
It supplements the general Privacy Policy of the Services, available from the footer, and applies to individuals who exchange messages with an Instagram account equipped with IRIS (the "end users") as well as to client businesses that connect their account.
It is drafted in accordance with Regulation (EU) 2016/679 of 27 April 2016, known as the General Data Protection Regulation or GDPR, and with French Law No. 78 17 of 6 January 1978 as amended.
The IRIS for Instagram service is published and operated by:
PARADEYES SASU with a share capital of €1,000 40 rue de Meudon, 92100 Boulogne Billancourt, France Nanterre Trade and Companies Register 994 727 154 Email: hello@paradeyesagency.com
Represented by Mr Basilide Baptiste Gonot, President.
When IRIS is deployed on the Instagram account of a client business, that business acts as the controller of its prospects' and customers' data, and PARADEYES acts as a processor within the meaning of Article 28 of the GDPR. The terms of this processing are described in the General Terms and Conditions of Sale.
The following categories of data are processed as part of the operation of IRIS on Instagram:
Conversation content: the messages exchanged between the end user and the client business's Instagram account, in order to generate responses.
Technical identifiers provided by Meta: the user account messaging identifier (IGSID) and the public username, in order to route conversations to the correct service instance.
Voluntarily submitted contact details: information the end user chooses to share during the conversation, such as their name, email address or phone number, for the purpose of a commercial follow up by the client business.
Technical access tokens: tokens issued by Meta allowing IRIS to operate the client business's account messaging. These tokens are stored encrypted (AES-256).
IRIS does not collect any browsing data or location data and does not access any information from the end user's Instagram profile other than what Meta transmits for message routing.
Responding to messages sent to the client business's Instagram account and ensuring conversation continuity. Legal basis: the client business's legitimate interest in responding to enquiries addressed to it (Article 6.1.f GDPR).
Forwarding contact requests made by the end user to the client business. Legal basis: performance of pre contractual measures at the request of the data subject (Article 6.1.b GDPR).
Ensuring the security, traceability and proper operation of the service. Legal basis: PARADEYES's legitimate interest (Article 6.1.f GDPR).
Responses are generated by an automated language model. IRIS does not make any decision producing legal effects concerning the end user or similarly significantly affecting them within the meaning of Article 22 of the GDPR. Conversations are not used to train artificial intelligence models.
Data is intended for the relevant client business and for authorised PARADEYES staff. It is processed by the following processors:
| Processor | Purpose | Data location | Safeguards |
|---|---|---|---|
| Meta Platforms Ireland Ltd. | Routing of Instagram messages via official Meta APIs | Ireland, United States | SCCs, Data Privacy Framework |
| Anthropic, PBC | Generation of conversational responses (Claude API) | United States | SCCs |
| Supabase Inc. | Hosting of service data | European Union (Frankfurt) | Native GDPR compliance |
| Vercel Inc. | Application hosting | United States | SCCs, Data Privacy Framework |
| Notion Labs, Inc. | Forwarding of contact requests to the client business | United States | SCCs, Data Privacy Framework |
| Resend (Plus Five Five, Inc.) | Email notification of contact requests | European Union (sending region), United States | SCCs |
Messages transmitted to Anthropic's API for response generation are retained by Anthropic for thirty days for abuse prevention purposes and are not used to train its models.
PARADEYES does not sell, rent or transfer personal data to third parties for commercial purposes.
Some of the processors listed above are located outside the European Union, mainly in the United States. Transfers are governed by the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914 of 4 June 2021), by the EU U.S. Data Privacy Framework for certified processors and, where applicable, by additional technical measures (encryption, pseudonymisation).
Instagram conversations and contact requests: 12 months from the last interaction on the PARADEYES side; 30 days on the Anthropic side.
Access tokens: for the duration of the contract between PARADEYES and the client business, then deleted upon termination together with all data of the relevant instance.
Technical security logs: 12 months.
Upon expiry of these periods, data is deleted or irreversibly anonymised.
Deletion of a message by the end user: when a user deletes a message in Instagram, the deletion is reflected in IRIS systems as soon as Meta sends the notification.
Deletion of conversations: any end user may request the deletion of their conversations and contact details by writing to hello@paradeyesagency.com. If the request concerns a conversation held with a client business's account, PARADEYES handles it in coordination with that business. Deletion is effective within 30 days.
Deletion of a client instance: any client business may request the complete deletion of its IRIS instance and associated data by writing to hello@paradeyesagency.com. Deletion is effective within 30 days.
The end user may stop automated responses at any time by writing STOP in the conversation. IRIS then stops responding and the conversation may be taken over by a human operator of the client business.
In accordance with Articles 15 to 22 of the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection over your data, as well as the right to set directives regarding the fate of your data after your death.
These rights may be exercised by email at hello@paradeyesagency.com or by post at PARADEYES, Référent RGPD, 40 rue de Meudon, 92100 Boulogne Billancourt, France, with proof of identity. PARADEYES undertakes to respond within one month of receiving the request, extendable by two months in complex cases.
PARADEYES implements appropriate technical and organisational measures, including encryption of data in transit (HTTPS/TLS), encryption of access tokens at rest (AES-256), isolation of data per client instance, profile based access control and logging of sensitive actions.
If, after contacting us, you consider that your rights have not been respected, you may lodge a complaint with the French data protection authority:
CNIL 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France Phone: +33 1 53 73 22 22 Website: https://www.cnil.fr
PARADEYES reserves the right to amend this policy to reflect regulatory, case law or technical developments of the service. The date of the last update appears at the top of this document.