Privacy Policy

Last updated 19 August 2026

1. Who we are

EMPEVO ("EMPEVO", "we", "us") provides appointment-setting software that helps businesses manage, prioritise and reply to conversations they receive on Instagram, Facebook Messenger and other messaging channels. EMPEVO is operated from the European Union and can be reached at privacy@empevo.eu.

Our customers are businesses. For the conversations processed inside a workspace, the business is the data controller and EMPEVO acts as its data processor. For our own account and billing records, EMPEVO is the controller.

2. Data we process

  • Account data — name, email address and profile picture from Google sign-in, plus the workspace and role assigned to you.
  • Platform Data from Meta — when a business connects an Instagram or Facebook account, we receive the account ID and name, conversation threads, message content, attachments metadata, timestamps and delivery status, and the sender's public username, display name and profile picture.
  • Contact data — notes, tags, deal values and outcomes added by the business team about the person they are talking to.
  • Sales outcome data — booked calls, show/no-show, closed deals and lost reasons entered by the business team.
  • Usage data — technical and security logs needed to operate the service.

We do not collect special category data, financial account data or precise location, and we do not ask users to provide them.

3. Why we process it and on what legal basis

  • Contract — to display a unified, ranked inbox, send replies on the business's behalf, and provide pipeline and reporting features.
  • Legitimate interests — to secure the service, prevent abuse, and improve reliability.
  • Legal obligation — to respond to lawful requests and keep required records.
  • Consent — where a specific feature requires it; you can withdraw consent at any time.

4. Use of Meta Platform Data

Platform Data obtained through the Meta APIs is used only to deliver the messaging, prioritisation, drafting and reporting features described above, for the business that authorised the connection. We comply with the Meta Platform Terms and Developer Policies. Specifically, we do not:

  • sell, licence or rent Platform Data, or share it with data brokers or ad networks;
  • use Platform Data for advertising, ad targeting, profiling for advertising, or building user profiles beyond the authorising business's own CRM records;
  • use Platform Data to make eligibility decisions about people (credit, insurance, employment, housing);
  • attempt to re-identify or combine Platform Data with data from other sources for purposes other than serving the authorising business.

A business can disconnect its Instagram or Facebook account at any time from the workspace settings or from Meta's Business Integrations settings. When access is revoked, we stop receiving new Platform Data and delete the stored Platform Data for that connection within 30 days.

5. AI processing

Message content may be sent to third-party large language model providers to generate reply drafts, lead scoring and coaching assessments. Content is sent for inference only, is not used to train third-party models, and is not retained by those providers beyond the short abuse-monitoring windows they operate. AI output is always reviewed by a human before anything is sent.

6. Sharing and subprocessors

We share data only with the providers needed to run the service:

  • Cloud hosting, database and authentication — to store workspace data and sign users in.
  • AI inference providers — to generate drafts, scoring and coaching feedback.
  • Messaging platform APIs — Meta (Instagram, Messenger) and, where a business uses it, its chat automation provider, to receive and send messages.

Each provider is bound by a data processing agreement and may only act on our documented instructions. We never sell personal data and never share it for cross-context behavioural advertising. We may disclose data where required by law.

7. International transfers

Some providers process data outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, together with technical safeguards such as encryption.

8. Retention

Conversation and contact data is retained while the workspace stays active and the connection remains authorised. It is deleted within 30 days of a verified deletion request, of the Meta connection being revoked, or of the workspace being closed. Backups roll off within a further 30 days. Aggregate, non-identifying statistics may be retained.

9. Your rights

You may request access, correction, export, restriction or deletion of your personal data, and object to processing. Instagram and Facebook users can request deletion at any time via our data deletion page, which also lets you check the status of a request, or by emailing privacy@empevo.eu. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

10. Security

Data is encrypted in transit and at rest, access is scoped per workspace through row-level security, team members only see the conversations assigned to their role, and administrative access is limited and logged. We notify affected customers and, where required, Meta and regulators without undue delay after a confirmed incident.

11. Children

EMPEVO is a business tool and is not directed to children under 16. We do not knowingly process data of children; if we learn we have, we delete it.

12. Cookies

We use only strictly necessary cookies and local storage to keep you signed in and to secure the session. We do not use advertising or cross-site tracking cookies.

13. Changes

We will update this page when our practices change and revise the "last updated" date. Material changes are communicated to workspace owners by email.

14. Contact

Privacy questions and rights requests: privacy@empevo.eu.