This Privacy Policy explains how Horizon Learning Solutions LLC, operating as Setpilot, handles personal data for its commercial service, currently available by invitation. It applies to invited customers and authorized users, people who contact us, and people who interact with an Instagram account connected to Setpilot.
1. Controller and contact
Horizon Learning Solutions LLC operates Setpilot from 1209 Mountain Rd Pl NE, Ste N, Albuquerque, New Mexico 87110, United States.
For privacy questions or requests, contact contact@setpilot.net.
2. Scope of this Policy
This Policy applies to personal data relating to:
- Visitors to Setpilot's public legal pages.
- Invited customers and their authorized users.
- People who contact Setpilot for support or information.
- People who send messages or comments to an Instagram account that a customer has connected to Setpilot.
A Setpilot customer must maintain its own privacy information for the people with whom it communicates. This Policy does not replace the customer's privacy policy.
3. Our data protection roles
Setpilot acts as a controller for data used to manage access, customer relationships, support, service security and compliance.
When a customer uses Setpilot to manage conversations from its Instagram account, the customer normally determines why those contact details and conversations are processed. In that context, the customer acts as controller and Setpilot acts as its processor or service provider, following the customer's documented instructions.
Requests about a specific business conversation should usually be directed first to the business that owns the relevant Instagram account. Setpilot will assist that business where appropriate.
4. Personal data we process
Depending on how Setpilot is used, we may process:
- Account and access data, such as name, email, invitation, profile, role, membership, permissions, preferences, authentication records and session information.
- Business and workspace data, including the business profile, offers, agents and versions, instructions, settings, simulations, editor content and authorized resources.
- Instagram data made available through an authorized Meta integration, including the connected professional account ID and username; account, media, comment, message and conversation IDs; usernames, messages, comments, replies, attachments, timestamps, entry triggers, source and related metadata.
- Integration and delivery records, including normalized and encrypted raw webhook payloads, receipts, processing boundaries, connection state, queues and delivery status.
- Lead, CRM and conversation data, including handles, original messages, internal or translated copies, summaries, notes, classifications, CRM status, follow-up instructions and information voluntarily provided to qualify a request or arrange a meeting.
- AI and runtime records needed to produce and deliver the service, including minimized prompts and context, generated outputs, validations, runs, checkpoints, caches, errors and operational state.
- Scheduling data, including email address, phone number, requested time, booking status, Calendly event and invitee links, cancellation and rescheduling links, attribution and encrypted attribution tokens.
- Usage, security and audit data, including metrics, quota usage, IP address, user agent, browser, device information, access logs, errors and limited Web Vitals.
- Privacy-request records and non-reversible keyed HMAC values used to prevent replay or honor a verified do-not-contact request.
Customers are responsible for ensuring that they have the rights and lawful basis needed for the information they provide to Setpilot.
5. Purposes and legal bases
We process personal data when necessary to:
- Provide, administer and improve the reliability of the contracted service.
- Authenticate users and manage permissions.
- Connect integrations selected by a customer.
- Process conversations, generate replies and support follow-up or scheduling workflows.
- Provide support and investigate service failures.
- Protect Setpilot, our customers and connected accounts from misuse, fraud and unauthorized access.
- Comply with legal obligations and defend legal claims.
Where European data protection law applies, the relevant legal bases may include performance of a contract, steps requested before entering a contract, legitimate interests in operating and securing the service, consent for optional activities, compliance with legal obligations, and a customer's documented instructions when Setpilot acts as processor.
6. Artificial intelligence
Setpilot uses contracted artificial intelligence services to understand conversation context and produce service outputs. Only information reasonably necessary for the requested function is sent to those providers.
Setpilot does not use identifiable customer, Instagram or conversation data to train general-purpose artificial intelligence models.
AI-generated output can be incomplete or inaccurate. Customers are responsible for configuring, testing and supervising their agents according to their business, legal obligations and risk profile. Setpilot is not intended to make fully automated high-impact decisions about employment, credit, housing, health, education, insurance or essential services.
7. Service providers and disclosures
We may share data when necessary with categories of providers that support hosting, databases, artificial intelligence, security, email, calendar connections, customer support and service operations. They receive only the data needed for their function and are subject to appropriate privacy and security obligations. Meta, Instagram and Calendly also process data under their own terms and privacy policies when their services are connected. Setpilot cannot delete independent copies controlled by those services.
We may disclose limited information to professional advisers, authorities or another organization involved in a corporate transaction when legally permitted or required. We do not sell personal data, share it for cross-context behavioral advertising or use it for targeted advertising.
8. International data transfers
Setpilot is operated by a United States company, and data may be processed in the United States or other countries where our service providers operate. Where applicable law requires it, we use recognized transfer safeguards, such as adequacy decisions, contractual protections or other valid transfer mechanisms.
9. Retention
Our standard retention rules are:
- Encrypted raw integration payloads: no more than 30 days, and sooner when required by a verified deletion.
- Used, rejected or expired OAuth state: no more than 24 hours after it becomes terminal or expires.
- Integration credentials: cryptographically destroyed locally when the integration is disconnected or its project is deleted.
- Active account and project data: while needed to provide the service and follow valid documented instructions.
- Explicit commercial cancellation without a deletion instruction: the project becomes inoperable and is scheduled for purge no later than 90 days from the date Setpilot records that cancellation.
- Personal data covered by a verified deletion request: deletion from active systems proceeds without undue delay, does not wait for the cancellation period and has a normal target of 30 days after sufficient verification.
- Minimal de-identified request-completion records and keyed replay-prevention HMAC values: up to 24 months.
- Keyed do-not-contact HMAC values: until the person withdraws the opt-out or the value is no longer needed to honor it.
Deletion in active systems does not immediately rewrite historical recovery copies. If a backup is restored, applicable deletion and suppression records must be reapplied before restored data resumes ordinary processing. Longer retention applies only to the categories, scope and period required by a concrete legal obligation, documented legal hold or narrow security need.
Logging out, inactivity, the end of a demonstration, disconnecting an integration, archiving or pausing work, and an unverified or failed request do not start the 90-day commercial-cancellation period.
10. Security
Setpilot uses measures designed to protect personal data, including encrypted transport, role- and tenant-scoped authorization, protected integration credentials and cryptographic destruction, signed webhook validation, rate limits, replay controls, audit records and restricted technical access. No system can guarantee absolute security.
11. Cookies and similar technologies
Setpilot uses essential session and workspace cookies, local preferences and limited performance telemetry needed to operate, secure and diagnose the service. Setpilot does not currently use advertising cookies or marketing pixels on these legal pages.
12. Privacy rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to complain to a competent data protection authority.
Send requests to contact@setpilot.net. We may request reasonable information to verify identity and prevent unauthorized disclosure or deletion. If the request concerns data controlled by a Setpilot customer, we may refer the request to that customer and assist with the response.
Detailed steps are available in the Setpilot User Data Deletion Instructions.
13. Minors
Registered Setpilot account holders and users must be at least 18years old. A person who interacts with a customer's Instagram account does not become a registered Setpilot user, and Setpilot does not assume every such contact is an adult. If you believe that personal data relating to a minor has been processed improperly, contact contact@setpilot.net to request review or deletion.
14. Changes to this Policy
We may update this Policy to reflect changes in Setpilot, our providers, our legal obligations or our privacy practices. We will publish the revised text with a new effective date and provide additional notice when required.
