Privacy Policy
Last updated: 10 October 2026
This English translation is provided for convenience. If it differs from the Greek text, the Greek version prevails.
The application “Social Planner” is an internal tool of the social media agency identified in section 1 (“the agency”, “we”). The agency’s staff use it to schedule and publish content on the professional Instagram accounts of the agency’s clients and to prepare statistics and monthly reports for them.
The application is not open to the public: there is no public sign-up and only staff accounts created by the agency’s administrator can use it. Below we explain which personal data it processes, for what purpose, how long it keeps them and which rights you have under the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Data controller
The controller of the data described in this policy is:
- Legal name
- (not provided yet)
- Address
- (not provided yet)
- Privacy contact e-mail
- (not provided yet)
2. What data we process
2.1 Data received from Instagram
The application connects to Instagram only through Meta’s official API (Instagram API with Instagram Login), and only after the owner of the professional account has logged in on Instagram’s own page and explicitly approved access. It requests only the permissions instagram_business_basic, instagram_business_content_publish, instagram_business_manage_insights. We receive:
- Account details: the Instagram account ID, username, account type (Business or Creator) and the permissions granted.
- Profile details: the number of followers, followed accounts and posts. The display name and profile picture are not stored.
- Media metadata: the ID of each of the account’s posts, its type (photo, video, carousel, reel, story), date, permalink, number of likes and comments, the first 120 characters of the caption and the address of the thumbnail on Instagram’s servers (which expires after a short time).
- Insights: aggregate daily figures for the account (reach, views, accounts engaged, total interactions, profile link taps, followers) and per post (views, reach, likes, comments, saves, shares, replies, follows, profile visits, average watch time of reels).
- Access token: stored encrypted in the database, used only by the application’s server for the purposes in section 3 and refreshed automatically before it expires.
- Image fingerprints: after the first connection, the application reads up to the 200 most recent photos of the account and keeps only a digital fingerprint (hash) of each image together with its link, so that staff are warned before publishing the same photo again. The images themselves are not stored.
We do not receive messages, the content of comments, follower lists or information about who liked or commented, and we have no access to the Instagram account’s password.
2.2 Content uploaded by the agency
Agency staff upload photos and videos and enter captions, hashtags, mentions, collaborators, user tags, alternative text and the publishing time. This content may include data about other people (e.g. people in photos or tagged accounts) and is used only to publish it on the client’s instructions.
Files are kept in a non-public area of the server. Shortly before publishing, a copy is placed temporarily at a public address with a random, unguessable name so that Instagram can download it; it is removed as soon as the publication is completed or cancelled. When the files are deleted is described in section 6; for posts already published, staff see the thumbnail directly from Instagram and it is not stored again.
For each photo we also keep digital fingerprints (hashes), so that duplicate posts can be detected even after the file has been deleted. An image cannot be reconstructed from a fingerprint.
2.3 Staff accounts
For agency staff who use the application we keep name, e-mail, password (hashed only), role, two-factor authentication settings and passkeys, and a history of actions on posts (e.g. who scheduled or changed a post). For each login session we also keep the IP address and browser details (user agent).
2.4 Technical logs
The server logs technical events, such as errors and calls to the Instagram API, with account and media IDs but never with access tokens, so that problems can be found and fixed.
3. Purposes and legal basis
- Publishing content: scheduling and publishing posts, carousels, reels and stories on the client’s Instagram account, on the client’s behalf and according to the client’s instructions. Legal basis for the client’s own data: performance of the contract between the agency and its client (Article 6(1)(b) GDPR).
- Other people’s data in the content: people shown in photos and videos, tagged accounts, mentions and collaborators, published on the client’s behalf. Legal basis: the legitimate interest of the client in promoting its business and of the agency in carrying out the client’s instructions (Article 6(1)(f)). The client makes sure that, where required, it has the permission or consent of the people shown or mentioned.
- Statistics and reports: showing the performance of the account and its posts to agency staff and monthly PDF reports for the client. Legal basis: performance of the contract (Article 6(1)(b)).
- Preventing duplicate posts: comparing each new photo with the fingerprints of photos already published. Legal basis: performance of the contract and the legitimate interest of the agency and the client in not publishing the same content by mistake (Article 6(1)(b) and (f)).
- Security and reliability: staff accounts and roles, action history, technical logs and internal notifications about problems. Legal basis: the agency’s legitimate interest in providing the service securely and reliably (Article 6(1)(f)).
Access to an Instagram account is granted only with the explicit approval of its owner on Instagram’s login page and can be revoked at any time (section 8). Data received from Instagram are used only for the purposes above and in accordance with the Meta Platform Terms.
Providing the data is not a legal requirement. Connecting the Instagram account is, however, necessary to perform the contract with the client: without it the application can neither publish nor prepare statistics and reports for the account. Without staff account details, a staff member cannot log in to the application.
4. Recipients and processors
The data are accessible only to the agency’s authorised staff. We share them only with:
- Meta Platforms Ireland Limited (Instagram): through the official API we send the content to be published and receive the data in section 2.1. Meta’s own processing is governed by Meta’s privacy policy.
- Hosting provider: the application, its database and files are hosted on a server within the European Union, by a provider acting as a processor on behalf of the agency.
- Authorities: public or judicial authorities, only where required by law.
5. No sale, no advertising
We do not sell, rent or trade personal data. We do not use data from Instagram or from the application for advertising, profiling or automated decision-making, and we do not share them with advertising networks or data brokers.
6. How long we keep data
- Photos and videos: all files of a post (original, edited versions, thumbnails, public copy) are deleted as soon as its publication on Instagram is confirmed. If the post is cancelled, they are deleted 7 days after the cancellation; if publishing fails or misses its time and is not resolved, they are deleted 7 days later. Drafts without any activity are deleted after 3 days, and files never added to a post after one day. Posts waiting for review or for their publishing time keep their files until they are published, cancelled or deleted.
- Post records and fingerprints: the record of each post (caption, time, Instagram link, action history) and the fingerprints of its photos are kept as a record of our work for the client and to prevent duplicate posts for as long as the cooperation lasts, and are deleted on request.
- Data from Instagram: the follower count, insights, media metadata and fingerprints taken from the account are kept as the history behind the client’s statistics and reports until their deletion is requested, also after access is revoked or the account is disconnected. A deletion request through Instagram deletes them immediately, together with the access token; the account ID, username, account type and granted permissions stay on the client’s record until their deletion is also requested by e-mail (section 8). The access token is replaced on every refresh and stops working as soon as access is revoked.
- Monthly PDF reports: deleted automatically 24 months after the month they cover.
- Technical logs: deleted automatically after 14 days.
- Staff accounts: kept while the staff member works for the agency. When they leave, their account is disabled (the application does not delete accounts) and kept, with its action history, as a record of the work for clients for as long as the posts it refers to are kept, unless its deletion is requested earlier.
- Session details: the IP address and browser details of a session are deleted on logout, or automatically shortly after the session expires (480 minutes of inactivity).
- Deletion requests: for each request we keep the confirmation code, the account ID and the date, so that you can check its status and we can show that it was carried out.
- Backups: the database and files are included in the server’s backups, which are overwritten in rotation; deleted data are gone for good once the backups have rotated.
7. Security
- Communication with the application and with Instagram is encrypted (HTTPS).
- Access tokens are stored encrypted and staff passwords only as hashes.
- Only authorised staff have access, with roles that limit what each person can do; two-factor authentication and passkeys are available.
- Files are kept outside the public area of the server and can be viewed only by logged-in users; the temporary public copies have random names and are removed after publishing.
- Requests from Meta to the application (access revocation, data deletion) are accepted only with a valid cryptographic signature.
- Logs never contain access tokens or passwords.
8. Revoking access and deleting data
The owner of the Instagram account can revoke access at any time in Instagram: Settings → Website permissions → Apps and websites → remove the app. Meta notifies us automatically and the application immediately stops all publishing and data reading for the account. Data already received stay until their deletion is requested (section 6).
From the same screen the owner can also send a data deletion request. Meta forwards it to the application, which immediately deletes the access token, the follower count, the insights and media metadata, the monthly reports and the fingerprints taken from the account, and returns a confirmation code with a link to a page showing the status of the request. Only the account’s username, ID, account type and granted permissions on the client’s record (without access) and the records of the posts prepared by the agency itself remain.
You can also ask for all of your data to be deleted, including what remains, by e-mail to (not provided yet). We will reply within one month at the latest.
9. Your rights
Under Articles 15 to 21 GDPR you have the right to:
- access your data and obtain a copy;
- rectification of inaccurate or incomplete data;
- erasure;
- restriction of processing;
- data portability, i.e. to receive your data in a structured, commonly used format;
- object to processing based on legitimate interest.
To exercise your rights, send an e-mail to (not provided yet). We may ask for information confirming that you own the account. We reply without undue delay and within one month at the latest. If you are a client of the agency, erasure or restriction means the application will no longer be able to publish on your behalf.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).
10. Cookies
The application uses only the strictly necessary cookies for staff login: a session cookie that expires after 480 minutes of inactivity, a cookie that protects against CSRF attacks and, only if “Remember me” is ticked at login, a cookie that keeps the user logged in. No analytics, advertising or third-party cookies are used. This page sets no cookies; the light or dark theme preference stays only in your browser.
11. Changes to this policy
We update this policy when the application’s functionality or the legal framework changes. The current version is always on this page, with the “Last updated” date at the top. We inform our clients directly of material changes.
12. Contact
For any question about this policy or your data, e-mail us at (not provided yet) or write to us at (not provided yet).