This policy covers inseeq.com and the inseeq Meta Ads App. It is written to be read, not to be survived.
This policy explains what personal data inseeq UG (haftungsbeschränkt) collects, why we collect it, who we share it with, how long we keep it and how you can have it deleted. It applies to our website at inseeq.com and to the inseeq Meta Ads App, our application on the Meta Platform.
If you are here from Facebook, Instagram, Threads or the Meta App Review process, section 2 is the one you want. To have data deleted, go straight to our data deletion page.
The controller responsible for the processing described in this policy is:
inseeq UG (haftungsbeschränkt)We are not required to appoint a Data Protection Officer under Art. 37 GDPR or § 38 BDSG and have not appointed one. All privacy enquiries reach us at legal@inseeq.com and we answer within 30 days.
Where a client of ours connects their own Meta assets to our app, that client is the controller for the data held in those assets and inseeq acts as their processor under Art. 28 GDPR. Section 2 explains this in detail.
The inseeq Meta Ads App is a business tool, not a consumer product. There is no public sign-up. Its users are authorised representatives of companies that have engaged inseeq to plan and run their marketing. A user signs in with Facebook Login and grants the app access to the ad accounts, Pages, Instagram accounts and Threads accounts that their own business controls, so that inseeq and the automated agents we operate on their behalf can manage advertising for them.
We only ever access assets a user has explicitly connected. We never access assets belonging to anyone who has not granted us access, and connecting one client’s assets gives us no visibility into another client’s.
Each permission we request maps to a specific function of the app. We request nothing beyond what these functions need.
| What the app does | Meta permission | Why we need it |
|---|---|---|
| Sign the user in and identify them | public_profile | Establish who is connecting and which business they act for. |
| List the ad accounts and business assets the user manages | business_management | Let the user pick which of their own assets inseeq should work on. |
| List campaigns and read performance figures | ads_read | Report on spend, reach and results, and decide what to optimise. |
| Create and adjust campaigns and ad creatives | ads_management | Run the advertising work the client has engaged us to do. |
| List the Pages the user manages | pages_show_list | Connect the correct Page to the correct ad account. |
| Read Page performance figures | pages_read_engagement, read_insights | Measure organic performance alongside paid performance. |
| Read Instagram media belonging to the connected account | instagram_basic | Reuse existing organic content as ad creative. |
| Publish posts to the connected Threads account | threads_basic, threads_content_publish | Publish content the client has approved. |
| Retrieve responses from the client’s own lead forms | leads_retrieval, pages_manage_ads | Deliver leads to the client who owns the form. See 2.3. |
Where a client runs Meta Lead Ads, the app retrieves the responses that people submitted through that client’s lead forms. Depending on how the client built the form, this can include name, email address, telephone number, job title, company name and the answers to the client’s own questions.
We retrieve this data for one purpose only: to deliver it to the client who owns the lead form, or to the CRM system that client nominates. The client is the controller for this data and inseeq acts as their processor under a data processing agreement pursuant to Art. 28 GDPR.
If you submitted a lead form on Facebook or Instagram and want to know what happened to your data, the advertiser whose form you filled in is your first point of contact. You can also write to legal@inseeq.com and we will identify the responsible client and forward your request to them.
The app runs on the superglue integration platform. The following processors and sub-processors are involved:
| Processor | Role | Location and safeguard |
|---|---|---|
| Index Commerce GmbH (superglue) Leopoldstraße 2-8, 32051 Herford, Germany | Runs the integration platform: executes the calls to the Meta API, stores the encrypted OAuth tokens, and keeps a record of workflow inputs, outputs and execution history. | Germany, EU |
| Amazon Web Services | Hosting, storage and backups for the superglue platform. | EU and US, EU Standard Contractual Clauses or EU-US Data Privacy Framework |
| Amazon Bedrock | AI model inference on the retrieved data. Data submitted for inference is not used to train the underlying models. | Operated by AWS, safeguards as above |
| Langfuse | Observability and tracing of the AI agent runs, for debugging and quality monitoring. | EU and US, Standard Contractual Clauses |
| PostHog | Product analytics for the superglue platform. | US, Standard Contractual Clauses |
Each of these is bound by a data processing agreement that obliges them to process the data only on instruction, to keep it confidential and to apply appropriate security measures. superglue’s own privacy policy is available at superglue.ai/privacy_policy.
Meta Platform Data retrieved through the app, including lead form data, is retained for a maximum of 90 days and then deleted. This matches the retention period of the workflow execution history on the superglue platform, so there is no copy that outlives the stated period.
OAuth access tokens are held in encrypted form for as long as the connection is active. When a user disconnects the app, or when the engagement between inseeq and the client ends, tokens are revoked and the associated data is deleted within 30 days. Encrypted backups roll off within a further 30 days.
You can disconnect the app yourself at any time, without contacting us, in Facebook Settings under Apps and Websites. Removing the app immediately revokes our access to your assets. It does not by itself delete data we have already retrieved, so if you also want that deleted, follow section 2.8.
Email legal@inseeq.com with the subject line Data deletion request, telling us the Facebook account, Page or ad account concerned. We delete the data and confirm in writing within 30 days. Deletion is free of charge. Step-by-step instructions are on our data deletion page.
When you visit inseeq.com, our hosting provider records your IP address, the page requested, the referring page, your browser and operating system, and the time of the request. We use this to deliver the site, keep it secure and diagnose faults. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a working and secure website. These logs are kept for a short period and then deleted or anonymised.
When you contact us or download a guide, we collect the details you enter, typically name, work email address, telephone number, company and your message. We use them to answer you and, where relevant, to discuss working together. Legal basis: Art. 6(1)(b) GDPR for steps taken at your request before entering a contract, and Art. 6(1)(f) GDPR for our legitimate interest in business communication.
These enquiries are stored in Attio, our CRM. Form submissions are checked by Cloudflare Turnstile to keep out automated spam. We keep enquiry records for as long as needed for the business relationship and thereafter in line with statutory retention duties.
We use Google Analytics 4 to understand how the site is used in aggregate. Where consent is required, we set these cookies only after you have given it, and you can withdraw consent at any time with effect for the future. Legal basis: Art. 6(1)(a) GDPR.
Site content is served through Contentful and hosted on Vercel. Typefaces are loaded from Google Fonts, which means your browser contacts a Google server and transmits your IP address in the process.
We process personal data only where one of the following applies under Art. 6(1) GDPR:
Where inseeq processes data on behalf of a client, the client determines the legal basis and inseeq acts on their documented instructions under Art. 28 GDPR.
Some of our processors are based outside the European Economic Area, or store data there. Where that happens, the transfer is covered by the European Commission’s Standard Contractual Clauses, or by the recipient’s certification under the EU-US Data Privacy Framework, together with supplementary technical measures such as encryption in transit and at rest. You can request a copy of the relevant safeguards from legal@inseeq.com.
| Data | Retention |
|---|---|
| Meta Platform Data, including lead form data | Maximum 90 days, then deleted |
| OAuth access tokens | For the life of the connection, revoked and deleted within 30 days of disconnection |
| Backups containing the above | Rolling 30 days, encrypted |
| Website enquiries and CRM records | Duration of the business relationship, then per statutory retention duties |
| Server logs | Short-term, then deleted or anonymised |
| Invoices and accounting records | 10 years, as required by German commercial and tax law |
Under the GDPR you have the right to:
To exercise any of these, write to legal@inseeq.com. We respond within 30 days and we do not charge for it. If your request concerns data we hold on behalf of a client, we will tell you which client is responsible and pass your request to them.
You also have the right to complain to a supervisory authority. Ours is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.
We apply technical and organisational measures appropriate to the risk. Data is encrypted in transit with TLS and at rest. API credentials and OAuth tokens are held in an encrypted vault, separately from the workflows that use them, and are never written to logs. Access is limited to the people who need it for the engagement, and every access is authenticated. We review these measures as our systems change.
Our services are directed at businesses. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact legal@inseeq.com and we will delete it.
We update this policy when our processing changes. The date at the top always reflects the current version. Where a change materially affects you, we notify affected users and clients directly rather than relying on you to check this page.
Questions about this policy, or about anything we do with your data: legal@inseeq.com, or by post to inseeq UG (haftungsbeschränkt), Linienstraße 115, 10115 Berlin, Germany.