Last updated: 2 December 2025
Owner: David Burn Photography
Website: https://davidburnphotography.co.uk
Contact: david@burnt.media
1. Introduction
This privacy policy explains how David Burn Photography (“we”, “us”, “our”) processes information when using our Instagram automation tool (“the App”).
The App is used only for managing comments and messages on Instagram and is currently in private developer testing.
We are committed to protecting your privacy and handling data responsibly.
2. Information We Collect
2.1 Information Provided by Instagram
When authorised, the App may access:
- Your Instagram Business Account ID
- Comments made on your posts
- Messages sent to your Instagram Business Account
- Public usernames and profile pictures of users who interact with your account
- Media IDs related to comments or messages
No additional personal information is collected.
2.2 Technical Data
When Meta delivers webhook notifications, we may receive:
- Event type (comment, message, mention)
- Timestamp
- IDs required to process the event
This data is only used automatically by the App to reply to comments or messages.
3. How We Use Information
We use Instagram-provided data exclusively to:
- Detect keywords in comments
- Automatically reply to comments or direct messages
- Deliver requested resources or information
- Log actions for debugging and improving the tool
The App does not sell, share, or transfer data to third parties.
Data is never used for advertising or external profiling.
4. Legal Basis for Processing (GDPR)
As a UK-based business, we process Instagram data under:
- Legitimate Interests – to respond to interactions on our Instagram account
- Consent – granted when connecting an Instagram Business Account to the App during setup
5. Data Storage and Retention
- The App does not store long-term copies of comments, messages, or Instagram user data.
- Temporary logs may be held to ensure the system works properly and are automatically deleted or overwritten.
- No data is stored in external databases during development testing.
6. Sharing Your Information
We do not share Instagram data with:
- Other users
- Third-party vendors
- Advertising platforms
The only data processing occurs within the Instagram Graph API and Meta’s systems.
7. Data Security
We take reasonable steps to protect all processed data, including:
- Secure HTTPS communication
- API tokens stored in protected environment variables
- No public exposure of personal data
8. Your Rights (GDPR & UK GDPR)
You have the right to:
- Access your personal data
- Request correction or deletion
- Object to or limit processing
- Withdraw Instagram authorisation at any time
To revoke access, visit:
Instagram app settings → Accounts Centre → Apps and Websites → Active → Remove App
Or contact us directly at david@burnt.media
9. Children’s Data
The App is not intended for use by children under the age of 13 and does not knowingly process their data.
10. Updates to this Policy
We may update this privacy policy as needed for legal or operational reasons.
The most recent version will always be available on our website or by request.
11. Contact Us
For questions, requests, or concerns, contact:
David Burn Photography
Email: david@burnt.media
Website: https://davidburnphotography.co.uk