Privacy Policy for DoNex

Effective Date: November 10, 2025

1. Introduction

Welcome to DoNex ("we," "our," or "us"). We provide an AI-powered Sales Assistant & Support CRM designed to help businesses automate interactions on Instagram, sync inventory, and manage customer support tickets (the "Service").

Your privacy and data sovereignty are paramount to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using DoNex, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

We adopt a principle of "least privilege," collecting only what is strictly necessary to function.

A. Information You Provide (Merchant Data)

  • Standard Users: Account details, product inventory, and pricing synced directly to our platform.

  • Enterprise/Organization Users: We typically interact with your existing databases strictly via secure APIs to retrieve the least necessary data required for a specific user interaction.

B. Information via Third-Party Platforms (Meta/Instagram Data)

To provide our core services, we require limited access via Meta's APIs:

  • Conversational Data: Incoming/outgoing DMs, comments, and mentions to enable automated replies.

  • End-User Public Data: Basic public info (e.g., username) to create CRM profiles.

C. Automatically Collected Data

  • Log Data & Cookies: IP address, browser type, and session cookies to maintain your language settings (e.g., EN, DE, ES, NL) and secure your login.

3. AI Processing & Data Sovereignty

Our unique architecture allows you to control where your data is processed by AI.

A. Standard AI Processing (Default)

By default, to provide the highest quality responses, we may route conversational data to the most capable AI models available. While we prioritize regional datacenters where possible, this default setting may involve processing data globally (e.g., in US-based datacenters) if required for superior model performance.

B. Strict Regional Locking (User Selected)

If you select a specific datacenter region in your settings (e.g., "EU Only"):

  • Strict Confinement: We will strictly process your data ONLY within that selected region.

  • No Egress: We will never route your data to models in other regions, even if it means foregoing more capable models available elsewhere.

C. Enterprise & Dedicated Models

For organization plan users, we support connecting to your own private/local LLMs hosted on your own infrastructure. We do not use your proprietary data to train generic, public-facing AI models.

4. Meta (Facebook & Instagram) Platform Data Compliance

DoNex adheres strictly to Meta’s Platform Terms:

  • No Sale of Data: We do not sell, license, or purchase any Platform Data obtained from Meta.

  • Limited Use: We only request permissions necessary to power specific features (e.g., DM automation).

  • Data Deletion: We will delete Platform Data if you request it, disconnect your account, or if we no longer have a legitimate business need for it.

5. How We Share Your Information

We do not sell your personal data. We share information only with:

  • Service Providers & Chosen AI Hosts: trusted vendors necessary to operate the Service. If you select strict regional locking, we only utilize vendors within that region.

  • Legal Compliance: If required by law, regulation, or valid legal process.

6. International Data Transfers

For users in the EEA, UK, or Switzerland: Your data may be transferred internationally unless you have enabled "Strict Regional Locking" in your dashboard. When transfers occur, we rely on approved mechanisms such as Standard Contractual Clauses (SCCs) to ensure adequate protection.

7. Data Security & Retention

We implement industry-standard security measures (SSL/TLS encryption). We retain Merchant and Platform Data only as long as necessary to provide the Service. You may request complete data deletion at any time.

8. Your Rights

You have the right to access, correct, or delete your data. You may revoke DoNex's access to your Instagram account at any time via Meta's settings. Contact us below to exercise these rights.

9. Contact Us

If you have any questions about this Privacy Policy or your data sovereignty options, please contact us at:

Email: [email protected]