This policy explains what data the application Nanopower Social Automation (“the App”) processes, why, and how a business or an individual can have that data deleted. It covers only the App. It does not cover any website, product or service operated separately by the businesses that use the App.
1. Who is responsible
| Who is responsible for the data | The business that connected the App. Where NanoPower runs the App for its own accounts, NanoPower is responsible. Where the App is connected for another business under a technology partnership, that business is responsible for its own customers’ data. |
|---|---|
| App owner | Registered under the Meta business portfolio nanopower_global
(Meta ID 992958768578700) |
| Role of the App | The App is a processor. It acts only on the instruction of the business that connected it, and only on the accounts that business selected. It is never the owner of that business’s customer data. |
| Contact for requests about the App | info@nanopowerhpl.com |
2. What the App is for
The App is a marketing-operations tool used by a business to manage its own Meta presence: reading and answering comments and messages on its Instagram and Facebook Page, publishing and moderating its own content, reading the performance of its own advertising, and collecting the leads submitted through its own lead-ad forms.
A business connects the App by granting permissions through Meta’s official login flow. Access covers only the assets that business explicitly selects, and only for as long as the grant stands.
3. What data is processed
| Category | Examples | Why |
|---|---|---|
| Connected asset metadata | Page ID and name, Instagram account ID and username, ad account ID | To know which assets the business authorised and to route requests to them |
| Public interactions | Comment text, comment ID, the commenter’s public username and Meta-scoped user ID, timestamps | To read a question and publish an answer under it on the business’s behalf |
| Messages | Direct messages and Page messages sent to the business, and the replies it sends | To let the business answer its own customers |
| Lead form submissions | The fields the person chose to submit on the business’s own lead ad | To deliver the lead to the business that paid for the ad |
| Advertising performance | Aggregated spend, impressions, clicks, results by campaign | Reporting. This is statistical data and is not linked to individual people |
| Access credentials | The access token issued by Meta when the business grants permission | To make authorised API calls. Stored encrypted, never displayed, never logged |
4. Automated replies and AI processing
Where a business enables automatic answering, the text of a public comment or an incoming message is sent to a large language model in order to draft a reply in the business’s own words and knowledge base. The provider processes the text only to return that draft, under business API terms that do not permit using it to train models. No profile building or automated decision-making with legal effect is performed on any person.
5. Where data is stored and who can see it
Data is stored on a dedicated server operated for the App in Germany (Hetzner Online GmbH). Access is limited to the operator of the App and to the client business that owns the data. Each client business is isolated: one client’s data is never exposed to another.
Sub-processors: Meta Platforms (the source of the data), Hetzner Online GmbH (hosting), and the language-model provider described in section 4.
6. How long it is kept
Data is kept for as long as the client business keeps the App connected, because the business uses that history to answer its own customers. It is deleted when the business ends the connection and asks for deletion, or on the request of the person the data is about — in either case within 30 days of the request. See section 7.
| Access tokens | Stop working the moment a business revokes access, and are removed from storage when the connection ends |
|---|---|
| Aggregated advertising statistics | Kept for historical reporting. These are totals — spend, impressions, clicks — and contain no personal data |
7. Your rights and how to delete your data
Anyone whose data the App has processed may request access to it, its correction, or its deletion. Write to info@nanopowerhpl.com with enough detail to identify the record (for example the Instagram username and the business whose account you interacted with). Requests are answered within 30 days.
A business that connected the App can cut off all future processing itself at any time, by removing the App under Settings → Business integrations in its Meta account. Instructions for deleting data already held are published at the data-deletion page linked from the App’s settings.
8. Children
The App is a business tool and is not directed at children. It does not knowingly process the data of anyone under 13.
9. Changes
If this policy changes materially, the connected businesses are notified by email before the change takes effect, and the date at the top of this page is updated.