Privacy Policy

Effective Date: August 18, 2026

1. Introduction

Venzallo ("we", "us", or "our") provides an automated booking assistant for Instagram and iOS. This Privacy Policy explains what information we collect, how we use it, who we share it with, and how you can exercise your privacy rights, including data deletion. This policy applies to our iOS app, our website, and our services interacting with Meta's Instagram Graph API.

2. Data Controller & Contact

VENZALLO
Privacy Contact: privacy@venzallo.com

3. Data We Collect

To provide our core booking functionality, we collect the minimum amount of data necessary. This directly maps to the privacy labels shown on the Apple App Store:

CategoryWhat We StorePurpose
Instagram Scoped User ID (PSID)A Meta-assigned identifier unique to your interaction with the businessLink your conversation to your bookings
Instagram UsernameYour public @handleDisplay your name in the salon's booking dashboard
User Content (Messages & Images)The text of direct messages you exchange with our AI booking assistant, and any images you choose to send in the chatProcess booking requests, check availability, and let the salon review anything you share
Contact Information & Client RecordsName and contact details (if voluntarily provided in chat) and appointment details (service type, date, time, assigned staff)Salon client management and booking history

What we DO NOT collect: We do not collect passwords, payment/financial information, exact location data, or any Instagram content outside of the direct messages sent to the booking assistant. We do not request data that is not directly relevant to our core functionality.

4. How and Why We Use Your Data

We process your data strictly to operate our service (Performance of a Contract under GDPR Art. 6(1)(b) and Legitimate Interest under Art. 6(1)(f)).

We use the following Meta permissions strictly to receive real-time webhook notifications, read incoming DMs to the connected business account, and reply with availability:

PermissionPurpose
instagram_basicRead the business's Instagram profile information (username, profile picture) to display in the Venzallo dashboard.
instagram_manage_messagesReceive and respond to Instagram DMs via our AI booking assistant to check availability and manage appointments.
pages_messagingSend booking responses back to customers via the Page's Instagram messaging API.
pages_show_listList the user's Facebook Pages during signup to identify the one connected to their Instagram Business account.
pages_manage_metadataSubscribe to Instagram webhook events to receive real-time DM notifications.
pages_read_engagementRequired by Meta's API to list Facebook Pages during signup and discover the connected Instagram Business account.

We only request the permissions necessary for the app's core functionality and do not use them for any other purpose.

5. Third-Party Sharing and Sub-Processors

We do not sell your personal data. We share data only with trusted sub-processors required to operate our service. Every third party listed below is contractually obligated to provide the same or equal protection of user data as stated in this Privacy Policy.

Sub-processorPurposeLocation
Meta PlatformsInfrastructure for receiving and sending Instagram messagesEU/US
OpenAINatural language processing to power the AI assistant. Configured with zero data retention; your messages are NOT used to train their AI models.US
Microsoft AzureBackend application and API hostingSwitzerland (EEA)
HetznerSecure database and web server hostingGermany (EEA)

6. Automated Decision-Making & AI Processing

Venzallo uses OpenAI's language models to parse your messages and generate contextual replies regarding salon availability.

7. Compliance with Meta Platform Terms

We strictly adhere to the Meta Platform Terms and Developer Policies. Regarding "Platform Data" (data obtained via Meta APIs):

Data transfer. We do not transfer Platform Data to third parties except as necessary to provide the service or as required by law.

Security. We maintain reasonable administrative, technical, and physical security measures to protect Platform Data from unauthorized access or use.

8. Data Retention

We hold data only for as long as necessary:

9. Your Rights & Data Deletion Instructions

Under the GDPR, you have the right to access, rectify, withdraw consent, or erase your personal data.

How to delete your data. You can request the complete removal of your data and conversation history at any time. We will process your deletion request within 7 business days.

Automated data deletion. When you remove Venzallo via Instagram (Method 2), our systems erase your data automatically and confirm the outcome on our Data Deletion page.

Data Export Request. You may request a copy of all data we hold about you by emailing privacy@venzallo.com with the subject "Data Export Request." We will provide a JSON file containing your stored data within 30 days.

Complaints. You have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).

10. Children's Privacy

Our service is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected such data, we will take immediate steps to delete it.

11. Changes to this Policy

We may update this Privacy Policy periodically. We will notify users of any significant changes by updating the "Effective Date" at the top of this document and providing notice within the app or via email.