Last updated: August 24, 2026
This Privacy Policy explains how HRK Media Khan ("DMSet AI", "we", "us") collects, uses, and protects information when you use our Instagram DM automation platform (the "Service"). By using the Service you agree to this policy.
This policy is provided as-is for general information and is not legal advice. Depending on your business and location, you should seek your own legal advice about your obligations.
We use trusted third parties to run the Service, and share only what each needs. These include, for example, payment processing (Stripe), AI model providers (such as Anthropic, OpenAI, and OpenRouter), Instagram messaging delivery (ManyChat), scheduling (Calendly), profile lookups (Apify), workflow automation (n8n), our application and database hosting (Base44 and Supabase), edge hosting and delivery of our demo and developer endpoints (Cloudflare), email delivery to you (Resend), and internal team notification and alerting (Discord). Where you configure your own alert webhook, we also send notifications to the destination you choose, which may be Discord or Slack. This list is representative rather than exhaustive and may change as the Service evolves. Each provider processes data under its own terms and security commitments. We do not sell personal information.
We email the address on your account for two reasons, and you control them separately.
You can change all of this at Settings, then Notifications, or from the "manage which emails you get" link in the footer of any email we send, which works without signing in.
We record which emails we sent you, when, and whether they were delivered, opened, bounced or reported as spam. We keep that for deliverability and support (working out whether an invoice or a ticket reply actually reached you), not to build a profile of you, and we do not use it for advertising. We do not sell or rent your email address and we do not send third-party advertising to it.
We retain account and configuration data while your account is active. Message and lead data is retained to provide your dashboard and bot memory, and is deleted on request or within a reasonable period after account closure, subject to legal and operational requirements.
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at dmsetai1@gmail.com. If you connect end-user data through your bot, you are responsible for having a lawful basis to do so and for honoring those individuals' rights.
If you are a California resident, the categories of personal information we collect include identifiers (such as name and email), commercial information (such as subscription and billing details), internet and other electronic network activity (such as usage and metering data), and inferences drawn to qualify leads on your behalf. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising. You have the right to know and access the personal information we hold about you, to delete it, to correct it, and to opt out of any sale or sharing (which we do not do). To exercise these rights, contact us at dmsetai1@gmail.com. We verify requests before acting on them, and we will not discriminate against you for exercising these rights.
HRK Media Khan is established in Norway, which is part of the European Economic Area, so the GDPR applies to our processing. We process personal data on the following lawful bases: performance of a contract with you, our legitimate interests in operating, securing and improving the Service, and your consent where required. You have the rights to access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to withdraw consent at any time. To exercise these rights, contact us at dmsetai1@gmail.com. You also have the right to lodge a complaint with a supervisory authority. Ours is the Norwegian Data Protection Authority (Datatilsynet), and if you are elsewhere in the EEA or in the United Kingdom you may complain to your own local authority instead. For end-user and lead data processed through your bot, you (the customer) are the controller and DMSet AI acts as the processor, handling that data only on your documented instructions.
We are established in Norway. Several of our sub-processors are based in the United States and elsewhere, so your data may be transferred outside the European Economic Area. For those transfers we rely on appropriate safeguards, such as the European Commission's standard contractual clauses or, where the provider is certified, the EU-US Data Privacy Framework.
We use strictly necessary cookies to keep you logged in, maintain your session, and protect the security of the Service. We do not use cookies to sell your data or for cross-context behavioral advertising.
We use industry-standard measures including encryption in transit, server-side secret storage, row-level access controls, and tenant isolation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
The Service is not directed to individuals under 18, and we do not knowingly collect their information.
We may update this policy from time to time. Material changes will be posted here with an updated date.
Questions about this policy: dmsetai1@gmail.com.