Last updated: August 23, 2026
This Data Processing Agreement ("DPA") applies whenever we process personal data on your behalf through Nousify.ai (the "Service"). It forms part of our Terms of Service, and you accept it by creating an account or using the Service. If you need a countersigned copy, email johnny@nousify.ai.
You are the controller of the personal data we process for you. We are the processor. We process it only to provide and support the Service, and only on your instructions - your use of the Service and this DPA are those instructions.
If you are an agency using the Service for your own clients, you are their processor and we are your sub-processor. You confirm you have your clients' authority to appoint us, and you remain responsible to them for our performance.
The data subjects are your team, your agency clients, and the Instagram users you contact or who contact you. We process the following categories of personal data for as long as your agreement runs, plus the deletion period in section 7.
| Category | Fields |
|---|---|
| Account users | Name, email, password hash, billing details, product usage |
| Instagram accounts | Username, display name, profile picture, Instagram user ID, access tokens |
| Leads and contacts | Instagram username, display name, profile picture, biography, public profile data, plus any notes, custom fields and pipeline data you add |
| Conversations | Message content sent and received, timestamps, attachments, delivery status |
We do not ask for special category data. Please do not record it in free-text fields.
Outreach messages are sent from your own browser, using your own logged-in Instagram session, by a browser extension running on your device. We never receive or store Instagram passwords, and outreach is not sent from our servers.
Where Meta's official Instagram API is available - inbox sync, reading and sending replies - we use it under your own authorization, which you can revoke at any time directly with Meta.
The browser extension is not a sub-processor. It is software you run on your own machine, not a third party we send your data to.
We keep appropriate technical and organizational measures in place and review them periodically. We may change them, provided protection is not reduced. Currently:
Everyone we authorize to process your data is bound by confidentiality.
You authorize us to use the sub-processors below.
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Supabase | Database, authentication, storage | All customer data | EU |
| Vercel | Hosting and delivery | All customer data | US |
| Meta Platforms | Official Instagram messaging API | Conversations, profile data | US / IE |
| OpenRouter | AI-suggested message drafts | Conversation and lead data | US |
| Serper | Lead finder search | Search queries, public results | US |
| Stripe | Payments | Account billing data only | US / IE |
| Loops | Product email | Account contact data only | US |
| PostHog | Product analytics | Account usage data | US |
| Crisp | Support chat | Account contact and support data | EU |
We will give you reasonable notice before adding or replacing a sub-processor, by email or by updating this page. If you object on reasonable data protection grounds, we will discuss it with you in good faith and look for a workable alternative. If there is not one, either of us may terminate the affected part of the Service. We bind every sub-processor to obligations no less protective than these, and remain responsible to you for their performance.
You are responsible for having a lawful basis for the outreach you send, for honoring opt-outs, and for complying with Instagram's own terms.
We will help you, so far as is reasonable and possible given the nature of the Service, with data subject requests, impact assessments, and consultations with a supervisory authority. If a data subject contacts us directly, we will point them to you and pass the request on.
When your agreement ends we will delete your data, or return it if you ask, within 90 days. Backups age out on our ordinary cycle. We may keep data where the law requires it, and will keep it confidential and use it for nothing else. You can export or delete your data yourself at any time while your account is active - see Data Deletion.
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and give you what we know: what happened, roughly who and what is affected, the likely consequences, and what we are doing about it. Where we cannot give you everything at once, we will follow up as we learn more.
As the table in section 5 shows, some of our sub-processors operate outside the UK and EEA. Those transfers are made under the European Commission's Standard Contractual Clauses and, where the UK GDPR applies, the UK International Data Transfer Addendum. Both are incorporated into this DPA by reference.
We will give you the information you reasonably need to demonstrate compliance, including our security documentation. Where that answers your questions, it satisfies this section.
If a supervisory authority requires an on-site audit, or you reasonably need one, we will cooperate: no more than once a year, on 30 days' notice, during business hours, subject to confidentiality, and at your cost unless the audit finds a material breach.
This DPA forms part of your agreement with us and prevails over it on anything concerning personal data. Liability under this DPA is subject to the limits in that agreement. Questions can be sent to johnny@nousify.ai.