Who We Are
Follow to DM is operated by Faceleadz LTD, a company incorporated in England and Wales. We are the data controller responsible for your personal data under UK GDPR and the UK Data Protection Act 2018.
Faceleadz LTD
71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
Privacy enquiries: contact@followtodm.com
Data We Collect
We collect the following categories of personal data:
- Account data: your email address and password (stored in encrypted form) when you register for the Service.
- Instagram session credentials: to connect your Instagram account to the Service, we collect and store your Instagram session cookies. These are used solely to operate the automation features on your behalf.
- Message content: the direct message templates and content you configure within the Service.
- Payment and billing data: payments are processed by Stripe, Inc. We do not store your full payment card details. We may receive limited billing information (such as name, billing address, and last four card digits) as provided by Stripe.
- Usage data: technical information about your use of the Service, including login timestamps, feature usage, and error logs, used for security and service improvement.
How We Use Your Data
We use your personal data to:
- Create, manage, and maintain your account;
- Provide, operate, and improve the Service;
- Process subscription payments and manage billing;
- Communicate with you about your account, the Service, and any changes to our Terms or this Policy;
- Detect, prevent, and respond to fraud, abuse, and security incidents;
- Comply with our legal obligations.
We do not use your data for automated profiling or decisions that produce legal or similarly significant effects, and we do not sell your personal data to third parties.
Legal Basis for Processing
Under UK GDPR, we rely on the following legal bases to process your personal data:
- Performance of a contract — processing necessary to provide the Service you have subscribed to (e.g. account management, operating automation features);
- Legitimate interests — for fraud prevention, security monitoring, and improving the Service, where these interests are not overridden by your rights;
- Legal obligation — where we are required to process your data by law;
- Consent — where you have given us specific consent (e.g. marketing communications, where applicable). You may withdraw consent at any time.
Instagram Session Data
To operate the Service, we collect and store your Instagram session credentials (cookies). This data is processed exclusively to perform the automation functions of the Service on your behalf.
Instagram session credentials are sensitive. We treat them as such, applying encryption and strict access controls. You may revoke access at any time by disconnecting your Instagram account within the Service settings or by deleting your account.
Data Sharing
We do not sell your personal data. We share your data only with the following categories of third parties, and only to the extent necessary:
- Stripe, Inc. — for payment processing. Stripe acts as an independent data controller for payment data. Please refer to Stripe’s Privacy Policy for further information.
- Hosting and infrastructure providers — cloud providers who store and process data on our behalf under data processing agreements and appropriate safeguards.
- Law enforcement or regulatory authorities — where we are legally required or compelled to disclose data.
Any third-party processors we engage are bound by contractual obligations to handle your data securely and only in accordance with our instructions.
Data Retention
We retain your personal data for as long as your account is active and as necessary to provide the Service. Following cancellation or termination of your account, we will retain your data for a period of 90 days, after which it will be securely deleted, unless:
- We are required by law to retain it for a longer period;
- It is necessary to resolve disputes or enforce our agreements.
You may request deletion of your data at any time by contacting us (see Section 9 — Your Rights).
Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. This includes encryption of passwords and session credentials, access controls, and regular security reviews.
However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, and we encourage you to use a strong, unique password for your Follow to DM account.
Your Rights
As a data subject under UK GDPR, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your personal data ("right to be forgotten").
Request that we limit how we process your data in certain circumstances.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests.
To exercise any of these rights, please contact us at contact@followtodm.com. We will respond within 30 days.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk if you believe we have not handled your data in accordance with UK GDPR.
International Data Transfers
Your personal data may be processed by our infrastructure or payment providers in countries outside the UK or European Economic Area. Where we transfer data internationally, we ensure that appropriate safeguards are in place — such as the UK International Data Transfer Agreement (IDTA), Standard Contractual Clauses, or adequacy decisions — in compliance with UK GDPR requirements.
Cookies
Our website uses essential cookies necessary for the operation of the Service — for example, to maintain your session when you are logged in. We do not use third-party advertising or tracking cookies.
You can manage or disable cookies through your browser settings. Please note that disabling essential cookies may prevent certain parts of the Service from functioning correctly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. We will notify you of any material changes by email or by posting a prominent notice on the platform prior to the changes taking effect.
Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy. If you do not agree with any changes, you should discontinue use of the Service.
Contact & Complaints
For any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:
Faceleadz LTD
71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: contact@followtodm.com