Privacy

Customer data stays inside explicit business and channel boundaries.

This notice explains SEP's current technical handling of information during controlled early access. It does not claim a compliance certification or an externally verified Meta deployment.

Information handled by SEP

Information you provide

Account and business configuration, customer messages, contact details supplied in a conversation, and files deliberately attached to a supported channel.

Connected-channel information

Channel, Page or account routing details, provider event identifiers, delivery evidence, and the minimum provider identity needed to receive and reply to a message.

Business context

Approved services, products, policies, availability, and other tenant-controlled information used to answer a customer request.

Safety evidence

Bounded security, authorization, deduplication, audit, and failure evidence needed to prevent cross-tenant routing, replay, and false delivery claims.

Why the information is used

  • Route a message to the correct business and channel account.
  • Answer from business-approved context and carry out only an authorized action.
  • Preserve conversation continuity, delivery state, human takeover, and customer-request evidence.
  • Detect duplicates, reject unauthorized senders, investigate failures, and enforce tenant isolation.

Controlled Meta testing

Messenger and Instagram activation is restricted to explicitly paired tester identities. Other senders to a controlled-test account are acknowledged and discarded before SEP creates a contact, conversation, analytics record, or model request. Meta is not represented here as Live, reviewed, or externally certified.

Access, deletion, and questions

A customer should start an access or deletion request with the business whose Page, Instagram account, widget, or other channel received the message. That business can identify the correct tenant record and submit the request through its authorized SEP administration workflow. The exact deletion steps are described on the Data deletion page.

A business administrator who authorized a connected Meta account can remove that app authorization in Meta and ask the authorized SEP organization administrator to deactivate the exact asset and submit the applicable tenant-scoped deletion request. This is not a promise that provider-hosted data controlled by Meta is deleted by SEP.