Home
Home Icon
/
Legal
/
Privacy Policy

Privacy Policy

Last updated on July 28th, 2026

This Privacy Policy describes how Edgar SAS (“Edgar”, “we”, “us”, or “our”) collects, uses, processes, and protects personal data in connection with the Inrō platform (the “Service”).

1. Identity of the Data Controller

Edgar SAS
RCS Compiègne 920 349 073
20 rue des Maraîchers, 60700 Pontpoint, France

Contact: privacy@inroapp.com

2. Scope and Roles

Depending on the context:

  • Edgar SAS acts as a data controller for personal data relating to its own users
  • Edgar SAS acts as a data processor when processing personal data on behalf of its customers

Customers are solely responsible for determining the purposes and legal basis of processing concerning their end users.

Where we process personal data in order to detect, investigate or act on a suspected breach of our Terms of Service — including reviewing automation configurations, Shared Content and message content, retaining evidence, reporting to platform providers or authorities, and preventing re-registration — we act as data controller for that processing, and not as a processor on behalf of a customer.

3. Categories of Personal Data

3.1 Data processed on behalf of customers

  • Instagram messages, comments, and related content
  • Media and attachments
  • Profile data and metadata
  • Interaction and behavioral data
  • Contact information collected by customers

3.2 Data relating to users of the Service

  • Identification and contact data
  • Account and organization data
  • Billing data
  • Support communications

3.3 Technical and usage data

  • Device and connection data
  • Usage data
  • Error and performance data

3.4 Abuse and enforcement records

  • The content giving rise to a suspected or established breach of our Terms of Service
  • Automation and Shared Content configurations associated with that breach
  • Account records, including identification, organisation and billing data
  • Connected Instagram business account identifiers
  • Signals used to prevent re-registration, including hashed email address, IP address and device identifiers

4. Purposes and Legal Bases

Data is processed for:

  • Provision and operation of the Service
  • Contract performance
  • Customer support and relationship management
  • Automation and analytics
  • Security and fraud prevention
  • Detection, investigation and enforcement of breaches of our Terms of Service

Legal bases:

  • Contract performance
  • Legitimate interests
  • Consent (where required)
  • Legal obligations

For the detection, investigation and enforcement of breaches of our Terms of Service, we rely on our legitimate interests in preventing fraudulent and deceptive use of the Service, protecting the recipients of messages sent through it, maintaining our access to the platforms on which the Service depends, and establishing, exercising or defending legal claims.

5. Artificial Intelligence

The Service uses artificial intelligence:

  • Processing may include message content and contextual data
  • Processing is performed via OpenAI
  • Data is not used to train AI models
  • Data is processed on a transient basis

6. Recipients and Subprocessors

Data is shared with service providers acting as processors.

A current list is available at:
www.inro.social/legal/subprocessors

We do not sell personal data.

Where we reasonably believe that use of the Service breaches our Terms of Service or applicable law, we may also disclose relevant account records and content to the following recipients, who act as independent controllers or in an official capacity:

  • Meta and other platform providers on which the Service depends
  • Payment providers
  • Competent regulatory, consumer protection and law enforcement authorities

7. International Transfers

Where data is transferred outside the EEA, appropriate safeguards are implemented, including:

  • Standard Contractual Clauses (SCCs)
  • EU–US Data Privacy Framework (DPF), where applicable

8. Data Retention

  • Messages and interactions: up to 24 months
  • Contacts: deleted after 24 months of inactivity
  • Logs: limited retention
  • Backups: up to 4 days
  • Abuse and enforcement records (section 3.4): 5 years from termination of the account
  • Re-registration prevention signals: 5 years from termination of the account

9. Data Deletion

Upon account deletion:

  • Data is permanently deleted, subject to the exception below
  • Residual data may persist temporarily in backups

By exception, where an account has been suspended or terminated for breach of our Terms of Service, we retain the abuse and enforcement records described in section 3.4 for the period set out in section 8. This exception is limited to the records and content connected to the breach; all other data is deleted as described above.

10. Cookies

Non-essential cookies are used only with prior consent.

Users can manage preferences through the consent interface.

11. Security

We implement appropriate measures including:

  • Encryption in transit
  • Encryption of sensitive data at rest
  • Access control
  • Monitoring

12. Data Subject Rights

Individuals may exercise rights including access, deletion, and objection.

Requests should be directed to the relevant data controller.

Rights of erasure and objection may be restricted where we retain data as necessary for the establishment, exercise or defence of legal claims, or for compliance with a legal obligation — in particular in relation to the abuse and enforcement records described in section 3.4.

Contact: privacy@inroapp.com

13. Children

The Service is not intended for individuals under 13.

14. Updates

This policy may be updated periodically.

15. Contact

privacy@inroapp.com