Privacy Policy
Effective Date: August 18, 2026
1. Introduction
Venzallo ("we", "us", or "our") provides an automated booking assistant for Instagram and iOS. This Privacy Policy explains what information we collect, how we use it, who we share it with, and how you can exercise your privacy rights, including data deletion. This policy applies to our iOS app, our website, and our services interacting with Meta's Instagram Graph API.
2. Data Controller & Contact
VENZALLO
Privacy Contact: privacy@venzallo.com
3. Data We Collect
To provide our core booking functionality, we collect the minimum amount of data necessary. This directly maps to the privacy labels shown on the Apple App Store:
| Category | What We Store | Purpose |
|---|---|---|
| Instagram Scoped User ID (PSID) | A Meta-assigned identifier unique to your interaction with the business | Link your conversation to your bookings |
| Instagram Username | Your public @handle | Display your name in the salon's booking dashboard |
| User Content (Messages & Images) | The text of direct messages you exchange with our AI booking assistant, and any images you choose to send in the chat | Process booking requests, check availability, and let the salon review anything you share |
| Contact Information & Client Records | Name and contact details (if voluntarily provided in chat) and appointment details (service type, date, time, assigned staff) | Salon client management and booking history |
What we DO NOT collect: We do not collect passwords, payment/financial information, exact location data, or any Instagram content outside of the direct messages sent to the booking assistant. We do not request data that is not directly relevant to our core functionality.
4. How and Why We Use Your Data
We process your data strictly to operate our service (Performance of a Contract under GDPR Art. 6(1)(b) and Legitimate Interest under Art. 6(1)(f)).
- To provide the service: Processing messages to understand booking requests, checking salon availability, and confirming appointments.
- To maintain your account: Linking your social identity to your booking history for salon management.
We use the following Meta permissions strictly to receive real-time webhook notifications, read incoming DMs to the connected business account, and reply with availability:
| Permission | Purpose |
|---|---|
instagram_basic | Read the business's Instagram profile information (username, profile picture) to display in the Venzallo dashboard. |
instagram_manage_messages | Receive and respond to Instagram DMs via our AI booking assistant to check availability and manage appointments. |
pages_messaging | Send booking responses back to customers via the Page's Instagram messaging API. |
pages_show_list | List the user's Facebook Pages during signup to identify the one connected to their Instagram Business account. |
pages_manage_metadata | Subscribe to Instagram webhook events to receive real-time DM notifications. |
pages_read_engagement | Required by Meta's API to list Facebook Pages during signup and discover the connected Instagram Business account. |
We only request the permissions necessary for the app's core functionality and do not use them for any other purpose.
5. Third-Party Sharing and Sub-Processors
We do not sell your personal data. We share data only with trusted sub-processors required to operate our service. Every third party listed below is contractually obligated to provide the same or equal protection of user data as stated in this Privacy Policy.
| Sub-processor | Purpose | Location |
|---|---|---|
| Meta Platforms | Infrastructure for receiving and sending Instagram messages | EU/US |
| OpenAI | Natural language processing to power the AI assistant. Configured with zero data retention; your messages are NOT used to train their AI models. | US |
| Microsoft Azure | Backend application and API hosting | Switzerland (EEA) |
| Hetzner | Secure database and web server hosting | Germany (EEA) |
6. Automated Decision-Making & AI Processing
Venzallo uses OpenAI's language models to parse your messages and generate contextual replies regarding salon availability.
- No model training: Data processed by our AI is explicitly opted out of being used to train or improve external AI models.
- No profiling: We do not build user profiles, conduct sentiment analysis, or perform automated decision-making that produces legal or similarly significant effects.
- Human oversight: Salon owners can view the conversation history and manually override, edit, or cancel any booking made by the AI.
7. Compliance with Meta Platform Terms
We strictly adhere to the Meta Platform Terms and Developer Policies. Regarding "Platform Data" (data obtained via Meta APIs):
- We do not sell Platform Data.
- We do not use Platform Data for advertising, marketing, or retargeting.
- We do not transfer Platform Data to any ad network, data broker, or advertising-related service.
- We do not use Platform Data to build, append to, or augment user profiles.
- We do not use Platform Data to train artificial intelligence or machine learning models outside of providing the immediate, core booking service to the authorizing business.
Data transfer. We do not transfer Platform Data to third parties except as necessary to provide the service or as required by law.
Security. We maintain reasonable administrative, technical, and physical security measures to protect Platform Data from unauthorized access or use.
8. Data Retention
We hold data only for as long as necessary:
- Chat Logs: Automatically and permanently deleted after 90 days.
- Booking Records / Identifiers: Retained only for the duration of the salon's operational needs to manage the appointment, or until a deletion request is received.
9. Your Rights & Data Deletion Instructions
Under the GDPR, you have the right to access, rectify, withdraw consent, or erase your personal data.
How to delete your data. You can request the complete removal of your data and conversation history at any time. We will process your deletion request within 7 business days.
- Method 1 (In-App / Email): Email privacy@venzallo.com with the subject "Data Deletion Request" and include your Instagram handle.
- Method 2 (Via Instagram): Navigate to your Instagram app > Settings > Website Permissions > Apps and Websites. Find Venzallo and click "Remove."
Automated data deletion. When you remove Venzallo via Instagram (Method 2), our systems erase your data automatically and confirm the outcome on our Data Deletion page.
Data Export Request. You may request a copy of all data we hold about you by emailing privacy@venzallo.com with the subject "Data Export Request." We will provide a JSON file containing your stored data within 30 days.
Complaints. You have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).
10. Children's Privacy
Our service is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected such data, we will take immediate steps to delete it.
11. Changes to this Policy
We may update this Privacy Policy periodically. We will notify users of any significant changes by updating the "Effective Date" at the top of this document and providing notice within the app or via email.