Data & PrivacyTerms of Service

Privacy Policy

Faceleadz LTDEffective: 27 August 2026UK GDPR Compliant
01

Who We Are

Follow to DM is operated by Faceleadz LTD, a company incorporated in England and Wales. We are the data controller responsible for your personal data under UK GDPR and the UK Data Protection Act 2018.

Faceleadz LTD

71–75 Shelton Street, Covent Garden, London, WC2H 9JQ

Privacy enquiries: contact@followtodm.com

02

Data We Collect

We collect the following categories of personal data:

  • Account data: your email address and password (stored in encrypted form) when you register for the Service.
  • Instagram session credentials: to connect your Instagram account to the Service, we collect and store your Instagram session cookies. These are used solely to operate the automation features on your behalf.
  • Message content: the direct message templates and content you configure within the Service.
  • Payment and billing data: payments are processed by Stripe, Inc. We do not store your full payment card details. We may receive limited billing information (such as name, billing address, and last four card digits) as provided by Stripe.
  • Usage data: technical information about your use of the Service, including login timestamps, feature usage, and error logs, used for security and service improvement.
03

How We Use Your Data

We use your personal data to:

  • Create, manage, and maintain your account;
  • Provide, operate, and improve the Service;
  • Process subscription payments and manage billing;
  • Communicate with you about your account, the Service, and any changes to our Terms or this Policy;
  • Detect, prevent, and respond to fraud, abuse, and security incidents;
  • Comply with our legal obligations.

We do not use your data for automated profiling or decisions that produce legal or similarly significant effects, and we do not sell your personal data to third parties.

04

Legal Basis for Processing

Under UK GDPR, we rely on the following legal bases to process your personal data:

  • Performance of a contract — processing necessary to provide the Service you have subscribed to (e.g. account management, operating automation features);
  • Legitimate interests — for fraud prevention, security monitoring, and improving the Service, where these interests are not overridden by your rights;
  • Legal obligation — where we are required to process your data by law;
  • Consent — where you have given us specific consent (e.g. marketing communications, where applicable). You may withdraw consent at any time.
05

Instagram Session Data

To operate the Service, we collect and store your Instagram session credentials (cookies). This data is processed exclusively to perform the automation functions of the Service on your behalf.

Important: We do not collect, store, or process personal data about your Instagram followers beyond what is technically necessary to deliver the automated DM feature (i.e. triggering a message to a new follower’s account). We do not build profiles on your followers, and we do not share this data with third parties.

Instagram session credentials are sensitive. We treat them as such, applying encryption and strict access controls. You may revoke access at any time by disconnecting your Instagram account within the Service settings or by deleting your account.

06

Data Sharing

We do not sell your personal data. We share your data only with the following categories of third parties, and only to the extent necessary:

  • Stripe, Inc. — for payment processing. Stripe acts as an independent data controller for payment data. Please refer to Stripe’s Privacy Policy for further information.
  • Hosting and infrastructure providers — cloud providers who store and process data on our behalf under data processing agreements and appropriate safeguards.
  • Law enforcement or regulatory authorities — where we are legally required or compelled to disclose data.

Any third-party processors we engage are bound by contractual obligations to handle your data securely and only in accordance with our instructions.

07

Data Retention

We retain your personal data for as long as your account is active and as necessary to provide the Service. Following cancellation or termination of your account, we will retain your data for a period of 90 days, after which it will be securely deleted, unless:

  • We are required by law to retain it for a longer period;
  • It is necessary to resolve disputes or enforce our agreements.

You may request deletion of your data at any time by contacting us (see Section 9 — Your Rights).

08

Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. This includes encryption of passwords and session credentials, access controls, and regular security reviews.

However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, and we encourage you to use a strong, unique password for your Follow to DM account.

09

Your Rights

As a data subject under UK GDPR, you have the following rights regarding your personal data:

Access

Request a copy of the personal data we hold about you.

Rectification

Request correction of inaccurate or incomplete data.

Erasure

Request deletion of your personal data ("right to be forgotten").

Restriction

Request that we limit how we process your data in certain circumstances.

Portability

Receive your data in a structured, machine-readable format.

Objection

Object to processing based on legitimate interests.

To exercise any of these rights, please contact us at contact@followtodm.com. We will respond within 30 days.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk if you believe we have not handled your data in accordance with UK GDPR.

10

International Data Transfers

Your personal data may be processed by our infrastructure or payment providers in countries outside the UK or European Economic Area. Where we transfer data internationally, we ensure that appropriate safeguards are in place — such as the UK International Data Transfer Agreement (IDTA), Standard Contractual Clauses, or adequacy decisions — in compliance with UK GDPR requirements.

11

Cookies

Our website uses essential cookies necessary for the operation of the Service — for example, to maintain your session when you are logged in. We do not use third-party advertising or tracking cookies.

You can manage or disable cookies through your browser settings. Please note that disabling essential cookies may prevent certain parts of the Service from functioning correctly.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. We will notify you of any material changes by email or by posting a prominent notice on the platform prior to the changes taking effect.

Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy. If you do not agree with any changes, you should discontinue use of the Service.

13

Contact & Complaints

For any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:

Faceleadz LTD

71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

Email: contact@followtodm.com

© 2026 Faceleadz LTD. All rights reserved.followtodm.com