1. What we store when you connect an account
When you connect Instagram or Facebook to AIRON we never receive your password: Meta issues us an access permission instead. All that remains in our systems is:
- The access permission (token), always encrypted, never in plain text.
- Identifiers for the Instagram account and the linked Facebook Page, plus the public username.
- Events Meta sends us while the connection is active: comments, mentions and direct messages.
- Metrics we read on request (views, interactions). We do not build profiles or combine them with other sources.
We do not store your Instagram content: photos, videos and text stay with Meta. Full detail on purposes and legal bases is in our privacy policy.
2. Revoke immediately (no need to ask us)
This is the fastest route and it is entirely under your control. Access stops at once.
- Instagram: Settings → Security → Apps and websites → remove AIRON.
- Facebook: Settings & privacy → Settings → Apps and websites → select AIRON → Remove.
- Business Manager: Business settings → Accounts → remove AIRON’s access to the relevant asset.
From that moment AIRON can no longer read anything from your account. Data already stored does not disappear on its own — for that, see step 3.
3. How to request deletion
Email info@airon.team with the subject “Data deletion request - Instagram/Facebook”, telling us:
- Your Instagram username or the Facebook Page name.
- The company or practice it was connected for, if you remember it.
We will verify the account is yours before deleting anything. This is not red tape: without that check, anyone could have someone else’s data erased. Usually it is enough that the request comes from the address already linked to the account, or a confirmation from the profile itself.
4. What we delete, and how long it takes
Once the request is received and verified, we delete:
- The encrypted access permission and the connection record.
- Identifiers for the Instagram account and Page, and the username.
- Events received through the webhook: comments, mentions and messages.
- Any cached metrics.
Within 30 days of verification, as required by art. 12 GDPR, and usually much sooner. Our backups rotate: deletion propagates there within the same period, and in the meantime those copies are not used for any processing.
5. What we cannot delete
We would rather say this plainly than promise something that is not ours to give:
- Content that lives on Instagram or Facebook. Posts, comments and messages belong to your account on Meta; they are deleted there, not here.
- Records the law requires us to keep — invoices and tax documents, if you were a customer. They are kept for the legally required period and for that purpose only.
- Technical security logs (access, errors), kept for a limited period to detect abuse. They do not contain your account content.
6. Your rights
Beyond deletion you may exercise your rights of access, rectification, objection, restriction and portability, also at info@airon.team. If you believe we have not answered properly, you may lodge a complaint with your supervisory authority; in Spain that is the Agencia Española de Protección de Datos (aepd.es).
Controller: AIRON TEAM SL, Plaza Mayor 23, 1.º A, 47001 Valladolid, España.