Privacy Policy
Beo — Instagram CRM. Last updated: 12 August 2026.
Beo ("Beo", "we", "us") is an Instagram customer-relationship management tool operated under the GrowBeyond brand by Štěpán Kakeš, a sole trader registered in the Czech Trade Licensing Register under company number (IČO) 24411523, with a registered address at Konopná 636/7, Liberec XIV-Ruprechtice, 460 14 Liberec, Czech Republic. This policy explains what data we process when an Instagram professional account is connected to Beo, how we use it, and the choices and rights you have. Štěpán Kakeš is the data controller; you can reach us at the contact below.
1. Data we process
When you connect an Instagram professional account, and on an ongoing basis while it is connected, we process:
- Account & profile data — your Instagram account id and username, and the public name, username and profile picture of people who message or comment on your account.
- Messages & comments — the content of direct messages and comments exchanged through your connected account, including attachments and reactions, so we can show them in your inbox and let you reply.
- Media insights — metrics for your own posts, reels and stories (e.g. reach, views, saves).
- Access tokens — a long-lived Instagram access token, stored encrypted, used only to call the official Instagram API on your behalf.
- Account & usage data — the email and name of users you grant access to, and basic operational logs.
We obtain this data through the official Instagram API with your explicit authorization. We do not scrape Instagram.
2. How we use it
- To provide the CRM: a unified inbox, lead profiles, replying to DMs and comments, and analytics.
- To provide optional AI assistance (e.g. summaries, reply suggestions, lead qualification).
- To operate, secure and improve the service.
We do not sell your data and we do not use it for advertising.
3. Multi-tenant isolation
Beo serves multiple organizations. Each organization's data is isolated at the database level and is only accessible to members of that organization (and the platform operator for support and administration). One client cannot access another client's data.
4. Sharing & processors
We share data only with infrastructure providers ("processors") needed to run the service:
- Supabase — database, authentication and file storage (hosting in the EU).
- OpenAI / LLM providers — only the conversation content needed to generate the AI output you request.
- Meta / Instagram — to send and receive messages and comments on your behalf.
- Optional notification channels you enable (e.g. Telegram, Discord, email).
We do not share your data with any other third parties.
5. Retention
We keep data for as long as the Instagram account is connected and your organization is active. When you disconnect the account, remove your organization, or request deletion, the data is removed as described below. Access tokens are deleted immediately on disconnect or deauthorization.
6. Deleting your data
You can have your data deleted in any of these ways:
- Disconnect / remove the app in your Instagram settings — Instagram notifies our deauthorization endpoint and we revoke and delete the stored access token.
- Send a data deletion request — this is handled automatically at
https://app.growbeyond.cz/api/integrations/instagram/data-deletion; you receive a confirmation code and a status link. - Email us at the address below and we will delete your data.
7. Security
Data is hosted on EU infrastructure, access tokens are encrypted at rest, transport is over HTTPS, and access is restricted by row-level security per organization.
8. Your rights (GDPR)
As we serve users in the EU, you have the right to access, correct, export, restrict or delete your personal data, and to object to processing. To exercise any of these, contact us below.
9. Contact
Štěpán Kakeš, IČO 24411523
Konopná 636/7, Liberec XIV-Ruprechtice, 460 14 Liberec, Czech Republic
stepankakes47@gmail.com · growbeyond.cz