Privacy Policy

Last updated: 17 August 2026

Who we are

Hermayon is operated by Sealambda GmbH, Sulzerstrasse 1, 4528 Zuchwil, Switzerland (company no. CHE-267.359.056) ("Sealambda", "we", "us"). This policy explains how personal data is handled through the Hermayon website and application.

Our direct customers are organizations ("Customers") that connect an Instagram professional account and manage its direct-message conversations. For the contacts and conversation content a Customer stores, the Customer is the data controller and we act as its processor. We process that data on the Customer's instructions and assist it with data-subject requests.

Data we collect

  • Account and organization data — name, email address, hashed sign-in credentials, organization details, membership, and permissions.
  • Instagram connection data — an encrypted access token, the connected professional account ID, display name, token expiry, and basic connection metadata.
  • Inbox data — Instagram-scoped contact identifiers, contact display names, direct-message content, attachments, delivery state, and conversation activity timestamps received from or sent through the connected account.
  • Technical data — security, diagnostic, and application logs and the browser and network information required to operate and protect the Service.

How we use data

  • Provide and secure accounts, organizations, and the shared Instagram inbox.
  • Receive, display, send, and reconcile Instagram direct messages.
  • Send transactional account and organization email.
  • Diagnose failures, prevent abuse, and meet legal obligations.

We do not sell personal data. We do not use Customer conversations or contacts to train our own or a third party's artificial-intelligence models.

Instagram and Meta data

Hermayon uses Meta's Instagram Platform so a Customer can connect an Instagram professional account and work with its direct messages in a shared inbox. We use data received from Meta only to provide this service to the Customer that connected the account. We do not combine it across Customers or make it available to other Customers.

A Customer must own or be authorized to operate every Instagram account it connects and remains responsible for its own notices, lawful basis, replies, and compliance with Meta's terms and policies.

Disconnection and data deletion

When a Customer disconnects an Instagram account, or Meta deauthorizes it, we first mark the connection as disconnected and immediately erase its access token, display name, and profile metadata. We retain its conversations and messages for a 30-day reconnection grace period. Reconnecting the same account to the same organization during that period clears the disconnection date and preserves the inbox.

If the account is not reconnected, after 30 days we permanently erase the channel-account record, its conversations and messages, the Instagram contact identifiers associated with those conversations, and contacts left with no other identity. A contact that still has another identity is preserved.

An explicit Meta Data Deletion Request has no grace period. We immediately perform the same permanent erasure, including for a channel the Customer previously removed from its active account list, and return Meta a confirmation URL and code.

A person may also request access, correction, or deletion by contacting the Customer whose Instagram account they messaged or by emailing [email protected]. When the Customer is the controller, we will work with it to respond.

Service providers

We use providers only as needed to operate the Service, including:

  • cloud hosting, database, backup, and infrastructure providers;
  • Meta Platforms, Inc., for the Instagram Platform;
  • transactional email delivery providers; and
  • security, error-monitoring, and operational support providers.

Providers process data under contractual restrictions appropriate to their role. We do not allow them to use Customer Data for their own advertising.

Cookies

We use only cookies and browser storage needed for sign-in, security, preferences, and application operation. We do not currently use advertising cookies.

Other retention

We retain active account and organization data while the Customer uses the Service and for only as long afterwards as needed for closure, security, disputes, and legal obligations. Short-lived operational logs and backups follow controlled retention schedules and age out rather than becoming a second active copy of Customer Data.

The 30-day channel grace period is deliberately limited: it lets a Customer recover from an accidental disconnect without making disconnected platform content permanent. An explicit deletion request always overrides that recovery period.

International transfers

Sealambda GmbH is based in Switzerland. Where data is transferred outside Switzerland or the European Economic Area, we use an applicable adequacy decision or safeguards such as the European Commission's Standard Contractual Clauses.

Your rights

Subject to applicable law, including the GDPR and Swiss Federal Act on Data Protection, you may have rights to access, correct, delete, restrict, or object to processing; obtain a portable copy; and complain to a data-protection authority. Contact the relevant Customer first for data it controls, or contact us at [email protected].

Security

We use measures including encryption in transit, encryption at rest for Instagram tokens and message text, access controls, tenant isolation, and hashed sign-in credentials. No system is completely secure, but we maintain safeguards proportionate to the Service and the data it handles.

Changes and contact

We may update this policy and will change the date above and notify Customers when a change is material.

Sealambda GmbH
Sulzerstrasse 1
4528 Zuchwil, Switzerland
[email protected]