Privacy Policy
Last Updated: February 4, 2026
1. Introduction
SIA Digital Publisher ("we", "us", "our"), a company registered in Latvia (registration number: [YOUR_REG_NUMBER]), operates MarketingRoutine.ai (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
MarketingRoutine.ai is an AI-powered marketing platform that helps businesses manage customer communications across Facebook and Instagram. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
SIA Digital Publisher
Address: [YOUR_ADDRESS], Latvia
Email: privacy@marketingroutine.ai
Registration Number: [YOUR_REG_NUMBER]
3. Information We Collect
3.1 Information from Facebook and Instagram
When you connect your Facebook Page or Instagram Business Account to our Service, we may access:
- Direct Messages: Messages sent to your connected Facebook Pages and Instagram accounts
- Comments: Comments on your posts (organic and ad posts)
- Page Information: Page name, ID, and profile information
- User Information: Names and profile IDs of users who message or comment on your pages
- Message Metadata: Timestamps, message IDs, and attachment types
3.2 Account Information
When you create an account, we collect:
- Email address
- Name and organization name
- Password (encrypted)
- Billing information (processed by Stripe)
3.3 Usage Data
We automatically collect information about how you use the Service, including:
- Log data (IP address, browser type, pages visited)
- Device information
- Feature usage statistics
4. How We Use Your Information
We use the collected information for the following purposes:
4.1 Core Service Functions
- Message Processing: Receiving and displaying incoming messages and comments
- AI Response Generation: Using AI to suggest responses to customer inquiries
- Response Approval: Presenting AI-suggested responses for human review and approval
- Message Sending: Sending approved responses back through Facebook/Instagram
4.2 Service Improvement
- Analyzing usage patterns to improve the Service
- Training and improving AI response quality (anonymized data only)
- Troubleshooting and technical support
4.3 Communication
- Sending service notifications and updates
- Responding to support requests
- Marketing communications (with consent)
5. Legal Basis for Processing (GDPR)
We process your personal data based on:
- Contract Performance: Processing necessary to provide the Service you requested
- Legitimate Interests: Improving our Service and preventing fraud
- Consent: Marketing communications and optional features
- Legal Obligations: Compliance with applicable laws
6. Data Sharing and Disclosure
We may share your information with:
6.1 Service Providers
- OpenAI: For AI-powered response generation (message content is processed)
- Convex: Database hosting and storage
- Clerk: Authentication services
- Stripe: Payment processing
- Render: Application hosting
6.2 Legal Requirements
We may disclose information if required by law, court order, or government request.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.
7. Data Retention
We retain your data as follows:
- Messages and Comments: Retained for 90 days after processing, then automatically deleted
- Account Data: Retained while your account is active and for 30 days after deletion request
- AI-Generated Responses: Retained for 30 days for quality assurance
- Audit Logs: Retained for 1 year for security and compliance
You can request earlier deletion of your data at any time (see Your Rights section).
8. Data Security
We implement appropriate security measures including:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls and authentication
- Regular security audits
- Secure token storage for platform connections
- Webhook signature verification for incoming data
9. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (for OpenAI and other service providers). We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all service providers
- Adequacy decisions where applicable
10. Your Rights (GDPR)
Under GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time (where processing is based on consent)
To exercise these rights, contact us at privacy@marketingroutine.ai. We will respond within 30 days.
11. Cookies and Tracking
We use cookies and similar technologies for:
- Essential Cookies: Required for authentication and security
- Analytics Cookies: To understand how you use our Service (with consent)
- Preference Cookies: To remember your settings
You can manage cookie preferences through your browser settings.
12. Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date. For significant changes, we will provide additional notice via email.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
SIA Digital Publisher
Email: privacy@marketingroutine.ai
Address: [YOUR_ADDRESS], Latvia
You also have the right to lodge a complaint with the Latvian Data State Inspectorate (www.dvi.gov.lv) or another supervisory authority.
15. Facebook and Instagram Data
Our use of information received from Facebook and Instagram APIs adheres to the Meta Platform Terms and Developer Policies.
Specifically:
- We only access data necessary to provide our Service
- We do not sell Facebook or Instagram user data
- We do not use data for advertising purposes unrelated to your use of our Service
- We delete data upon your request or disconnection of your account
- Human review is required before any AI-generated response is sent