This Data Processing Addendum (DPA) forms part of the Setpilot Terms or another agreement between the customer and Horizon Learning Solutions LLC when Setpilot processes customer-controlled personal data as a processor.
1. Scope and roles
The customer is the controller or processor that determines the permitted business purpose. Horizon Learning Solutions LLC is the processor or subprocessor for customer-controlled Instagram conversations, connected scheduling data and related service records. Each party remains responsible for its separate controller activities.
2. Documented instructions
Setpilot will process personal data only to provide, secure, support and improve the reliability of the contracted service; follow the customer's product configuration and documented instructions; and comply with law. We will notify the customer if an instruction appears unlawful unless prohibited from doing so.
3. Confidentiality and security
Personnel authorized to process customer data are bound by confidentiality. Setpilot maintains risk-appropriate technical and organizational measures, including transport encryption, protected integration credentials, tenant authorization, auditability, access restriction, deletion workflows, recovery controls and incident procedures.
4. External provider categories
The customer gives general authorization to use subprocessors needed for hosting, databases, artificial intelligence, email and service delivery, security, support and operations. Setpilot will impose data-protection duties appropriate to their functions and remains responsible to the extent required by applicable law.
A specific provider, region or public register is not represented as verified by this page. Notice or additional information will be provided where the parties' contract or applicable law requires it.
5. Assistance and requests
Taking into account the nature of processing, Setpilot will reasonably assist with data-subject requests, security obligations, breach notifications, impact assessments and regulator consultations. If a request is received directly for customer-controlled data, Setpilot will refer it to the customer unless legally required to respond.
6. Personal data incidents
Setpilot will notify the customer without undue delay after confirming a personal data breach affecting customer-controlled data and will provide available information reasonably needed for the customer's legal assessment. Notification is not an admission of fault.
7. Return and deletion
During the service, authorized users can export project data and use the product deletion controls. A verified deletion instruction starts the deletion lifecycle without waiting for a commercial-cancellation period. An explicit commercial cancellation without a deletion instruction makes the project inoperable and schedules purge no later than 90 days after Setpilot records it. Setpilot retains only data required by a concrete legal obligation or documented legal hold. Active-system deletion does not immediately rewrite historical recovery copies, and applicable deletion and suppression records must be reapplied before restored data resumes ordinary processing.
8. International transfers and audits
Where restricted data is transferred internationally, the parties will use a valid transfer mechanism and cooperate to complete additional documentation when legally required. This page does not certify that a specific transfer, provider, region, EU Standard Contractual Clauses module or UK addendum has already been verified or completed.
On reasonable written request, Setpilot will provide information necessary to demonstrate compliance. Audits must protect other customers, security and confidentiality, avoid unreasonable disruption, and use existing independent materials first.
9. Annex A — Processing details
- Subject: AI-assisted commercial conversation, CRM and scheduling service.
- Duration: the active service term, a verified deletion lifecycle or, after explicit commercial cancellation without deletion, no more than 90 days before scheduled purge, subject only to concrete legal retention and historical recovery-copy limits.
- Data subjects: customer users and people who message, comment or schedule with a connected business account.
- Data: account identifiers; Instagram identifiers, messages, comments, media and metadata; CRM notes and classifications; scheduling contact details and URLs; technical, delivery and security records.
- Special data: not intentionally required; customers must not submit it unless lawful and necessary.
- Operations: collection, organization, storage, analysis, generation, transmission, retrieval, restriction, export and deletion.
10. Annex B — Security measures
- Role- and tenant-scoped authorization and authenticated administrative actions.
- TLS in transit and encryption or cryptographic protection for sensitive integration material.
- Credential cryptoshredding on disconnect or project deletion.
- Logging, monitoring, rate limits, webhook validation and replay controls.
- Data minimization, limited raw-payload retention and verified deletion workflows.
- Restoration controls that reapply deletion and suppression records before ordinary processing resumes, together with vulnerability management and incident response.
11. Annex C — Meta/Instagram processing
Setpilot requests only these Instagram permissions:
- instagram_business_basic
- instagram_business_manage_messages
- instagram_business_manage_comments
They support professional-account connection; supported messages, replies and messaging interactions; comments and supported comment-triggered direct messages. They do not authorize advertising access or uses unrelated to those functions. Customers remain responsible for notices, lawful instructions and Meta policy compliance.
12. Contact and precedence
Contact contact@setpilot.net about this DPA. If this DPA conflicts with the Terms on processing customer-controlled personal data, this DPA controls for that conflict. All other Terms remain unchanged.
