Privacy Policy

Last updated: January 1, 2025

1. Introduction

InstaBCM ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our business continuity management platform and related services.

By using InstaBCM, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

We collect information you provide directly to us, including:

  • Account Information: Name, email address, company name, job title, and password when you create an account.
  • Business Continuity Data: Information about your organization's business functions, risks, recovery objectives, and continuity plans that you enter into our platform.
  • Payment Information: Billing address and payment method details when you subscribe to paid plans. Payment processing is handled by Stripe, and we do not store full credit card numbers.
  • Communications: Information you provide when contacting our support team or responding to surveys.

2.2 Information Collected Automatically

When you use our service, we automatically collect:

  • Usage Data: Pages visited, features used, time spent, and actions taken within the platform.
  • Device Information: Browser type, operating system, device type, and screen resolution.
  • Log Data: IP address, access times, and referring URLs.
  • Cookies: We use cookies and similar technologies to maintain sessions and understand usage patterns.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Send technical notices, updates, security alerts, and support messages
  • Respond to your comments, questions, and customer service requests
  • Monitor and analyze trends, usage, and activities
  • Detect, investigate, and prevent fraudulent or unauthorized activity
  • Personalize and improve your experience
  • Comply with legal obligations

4. AI and Data Processing

InstaBCM uses artificial intelligence to provide features like plan generation, risk analysis, and recommendations. When you use AI-powered features:

  • Your data is processed by our AI systems to generate outputs specific to your organization
  • We do not use your business continuity data to train AI models
  • AI processing is performed on secure infrastructure with appropriate safeguards

5. Data Sharing and Disclosure

We do not sell your personal information. We may share information in the following circumstances:

  • Service Providers: With vendors who perform services on our behalf (hosting, payment processing, analytics)
  • Legal Requirements: When required by law, regulation, or legal process
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you direct us to share information with third parties

6. Data Security

We implement appropriate technical and organizational measures to protect your information, including:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Regular security assessments and penetration testing
  • Access controls and authentication requirements
  • Employee training on data protection
  • Incident response procedures

7. Data Retention

We retain your information for as long as your account is active or as needed to provide services. After account deletion, we retain certain information as required by law or for legitimate business purposes (such as resolving disputes) for up to 7 years.

8. Your Rights

Depending on your location, you may have rights including:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data
  • Portability: Request export of your data in a machine-readable format
  • Objection: Object to certain processing activities

To exercise these rights, contact us at privacy@instabcm.com.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including standard contractual clauses where required.

10. Children's Privacy

InstaBCM is not intended for use by children under 16. We do not knowingly collect personal information from children under 16.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date.

12. Contact Us

If you have questions about this Privacy Policy, please contact us at:

Email: privacy@instabcm.com
Address: InstaBCM, Privacy Team