Last updated: 22 May 2026
Privacy Policy
Insyte — GDPR & UK GDPR Compliant
1. Introduction
This Privacy Policy explains how Insyte (“we”, “us”) collects, uses, stores, and protects your personal data when you use our platform at https://insyte.cloud.
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR 2016/679), and the Data Protection Act 2018.
2. Who We Are
Data Controller: Insyte
Contact: legal@insyte.cloud
We process personal data of users located in the United Kingdom and the European Union.
3. Data We Collect
3.1 Account Data
- Name and surname
- Business email address
- Company name and role
- Billing information (processed by our payment provider — we do not store card details)
3.2 Usage Data
- Platform activity logs (features used, searches performed, pages visited)
- IP address and device/browser information
- Session duration and interaction data
3.3 Meta Integration Data
- OAuth tokens for Meta account connection (stored securely and encrypted)
- Meta Ad Account IDs and Page IDs you connect to Insyte
- Advertisement data you create or import through the platform
3.4 Communications Data
- Support requests and correspondence
- Email preferences and consent records
4. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract performance: to provide the Service you have subscribed to
- Legitimate interests: to improve our platform, prevent fraud, and ensure security
- Legal obligation: to comply with applicable laws and regulations
- Consent: for marketing communications (you may withdraw consent at any time)
5. How We Use Your Data
- To provide, maintain, and improve the Insyte platform
- To process payments and manage your subscription
- To send transactional emails (billing, product updates, security alerts)
- To provide customer support
- To detect and prevent fraud and abuse
- To comply with legal obligations
- With your consent, to send marketing and promotional communications
6. Data Sharing & Third Parties
6.1 Service Providers
We share data with trusted third-party service providers who assist us in operating the platform, including:
- Payment processors (e.g., Stripe) — for billing and subscription management
- Cloud infrastructure providers — for hosting and data storage
- Analytics providers — for platform performance monitoring
- Email service providers — for transactional and marketing emails
6.2 Meta Platforms
When you connect your Meta account, data is exchanged with Meta Platforms Inc. in accordance with Meta's own Privacy Policy and Platform Terms. We act as a data processor on your behalf for Meta API interactions.
6.3 Legal Disclosure
We may disclose your data if required by law, court order, or to protect our rights, property, or safety or that of our users.
7. Public Authority & Legal Requests
If we receive a request from a public authority, law enforcement agency, regulator, court, or other government body for user personal data, we review the legality and validity of the request before disclosing any data.
Where a request is unclear, excessive, invalid, or unlawful, we may reject, narrow, or challenge the request where legally permitted.
We apply data minimisation and disclose only the minimum personal data necessary to comply with a valid legal request.
We keep internal records of public authority requests, including the requesting authority, date, legal basis, data requested, data disclosed, our response, and the reasoning behind the decision.
9. International Data Transfers
Our primary operations are based in the United Kingdom. Some of our service providers may process data outside the UK and EU. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the UK ICO or European Commission.
10. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Upon account termination:
- Account data is retained for 12 months before deletion
- Billing records are retained for 7 years as required by UK tax law
- You may request earlier deletion subject to legal obligations
11. Your Rights
Under UK GDPR and EU GDPR, you have the following rights:
- Right of access — to request a copy of your personal data
- Right to rectification — to correct inaccurate or incomplete data
- Right to erasure— to request deletion of your data (‘right to be forgotten’)
- Right to restriction — to limit how we process your data
- Right to data portability — to receive your data in a structured, machine-readable format
- Right to object — to object to processing based on legitimate interests
- Right to withdraw consent — at any time, without affecting prior processing
To exercise any of these rights, contact us at legal@insyte.cloud. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or your local EU supervisory authority.
12. Security
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, and regular security assessments. However, no system is completely secure, and we cannot guarantee absolute security.
13. Children's Data
Insyte is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from minors.
14. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or in-platform notification. The latest version will always be available at https://insyte.cloud/privacy.
15. Contact Us
For any privacy-related queries or to exercise your rights:
Insyte — Data Controller
Email: legal@insyte.cloud
Website: https://insyte.cloud