Privacy Policy
This Privacy Policy explains how Automate Admits, Inc. (“Automate Admits,” “we,” “us,” or “our”) collects, uses, shares, retains, and deletes personal information in connection with the Automate Admits platform at automateadmits.com (the “Service”), including information we receive through Meta platforms such as Facebook Messenger and Instagram, through SMS and voice, and through web chat.
Contents
1. Who this policy covers
Automate Admits is a business messaging platform that helps organizations respond to, qualify, and manage leads who contact them through channels such as Facebook Messenger and Instagram. This policy applies to two groups of people:
- Customers — businesses and their team members who create an account and use the Service.
- End users — individuals who send messages to a Customer’s connected Facebook Page or Instagram account and whose messages are handled through the Service.
For end users, our Customer is the controller of the conversation and we act as a service provider/processor on the Customer’s behalf. If you messaged a business and have questions about your data, please contact that business directly; you may also contact us using the details below.
2. Information we collect
Information Customers provide
- Account information — name, email address, password (stored only as a salted hash), organization name, and team-member details.
- Billing information — subscription plan and payment status. Card payments are processed by our payment provider; we do not store full card numbers.
- Content you configure — AI agent persona, goals, guardrails, knowledge sources, and other settings.
Information about end users and conversations
- Message content sent to or from a connected channel — Facebook Messenger, Instagram, SMS, web chat, or email — including any images, files, or other media exchanged.
- Contact profile information such as the sender’s name or username, phone number, email address, and a platform-scoped identifier (for example a Messenger page-scoped ID or Instagram-scoped ID).
- Call recordings and transcripts where the Customer enables voice. Recordings and transcripts of calls handled through the Service are stored in the Customer’s account.
- Insurance and benefits information where the Customer uses eligibility verification, which includes the individual’s name, date of birth, and insurance member ID, and the benefits response returned by the payer.
- Lead details that the end user shares in conversation or that our Customer adds, which may include contact details, location, treatment history, and other information the parties choose to exchange.
Because our Customers are healthcare and treatment organizations, much of this information is likely to constitute protected health information. See Section 9.
Information collected automatically
- Log and device data — IP address, browser type, and timestamps, used for security and to operate the Service.
- Essential cookies — we use a session cookie to keep Customers signed in. We do not use advertising cookies.
3. Information from Meta platforms
When a Customer connects a Facebook Page or Instagram account, we use Facebook Login and the Meta Graph API to receive only the information needed to operate the Service, which may include:
- Page and Instagram account identifiers, names, and access tokens that allow us to receive and send messages on the Customer’s behalf.
- Messages exchanged between the end user and the connected Page or Instagram account, delivered to us through Meta webhooks.
- The public profile name (and, for Instagram, username) of an end user who messages the connected account, used to label the conversation.
We use information obtained through Meta platforms only to provide and improve the Service’s messaging features for the connecting Customer. We do not sell this information, use it for advertising, or transfer it to data brokers. Our use of information received from Meta platforms complies with the Meta Platform Terms and Developer Policies.
4. How we use information
- To deliver incoming messages into the Customer’s shared inbox and send the Customer’s replies back to the end user.
- To generate automated replies through the Customer’s configured AI agent (see Section 5).
- To organize contacts, conversations, lead status, and scheduling for the Customer.
- To authenticate users, provide support, process billing, and send service and transactional emails.
- To secure, maintain, troubleshoot, and improve the Service.
- To comply with legal obligations and enforce our terms.
5. AI processing of messages
To generate an automated reply, we send the following to our AI provider, Anthropic, PBC: the Customer’s configured agent instructions, the contact record for the person in the conversation, and the recent conversation transcript, including any images or media the contact sent. This happens on every turn of an automated conversation, because the model must read the conversation in order to draft a reply.
Anthropic does not use this data to train its models. We do not currently hold a business associate agreement with Anthropic. We publish the full status of every subprocessor, and how a Customer can limit what is shared, on our Trust page.
The Customer controls whether automated replies are enabled and can take over any conversation manually at any time. Because the AI agent must read message content to draft replies, the Service is not end-to-end encrypted.
6. How we share information
We do not sell personal information. We share information only as follows:
- With the Customer whose connected account received the conversation.
- With service providers (subprocessors) that help us run the Service, each under contractual confidentiality and security obligations. This is the complete list:
- Amazon Web Services, Inc. — application hosting, database, and object storage; the system of record, where all data including protected health information is stored and processed. Under a business associate agreement.
- Paubox, Inc. — delivery of transactional and service email to Customer teams. Under a business associate agreement.
- Stedi, Inc. — insurance eligibility and benefits verification. Receives the individual’s name, date of birth, and insurance member ID together with the Customer’s provider identifiers. Under a business associate agreement.
- Anthropic, PBC — AI processing of the contact record and conversation content to generate replies (see Section 5). No business associate agreement.
- Meta Platforms, Inc. — receiving and sending messages through the Facebook Pages and Instagram accounts a Customer connects. No business associate agreement.
- Telnyx LLC — transport of SMS and voice, phone numbers, call recording, and speech-to-text transcription. Transcription sends call audio to Telnyx’s speech-to-text service, which is powered by OpenAI Whisper. Recordings and transcripts are stored by us on AWS. No business associate agreement.
- Cloudflare, Inc. — public marketing site, static-asset delivery, DNS, and CDN/DDoS protection. No protected health information.
- Block, Inc. (Square) — payment processing for Customer subscriptions. Billing data only; no patient data.
- For legal reasons — to comply with applicable law, respond to lawful requests, or protect the rights, safety, and security of users, the public, or Automate Admits.
- In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to this policy.
7. Data retention
To be precise about what actually happens:
- Contacts, conversations, messages, call recordings, and transcripts are retained until they are deleted. There is no automatic expiry on this data — it is kept for the life of the Customer’s account. Customers can delete a contact or a conversation from the app at any time, and we delete or return account data on request following termination.
- Security activity logs are retained approximately 183 days and then purged automatically. Failed-login records and rate-limit counters are purged on a much shorter cycle.
- When a Customer disconnects a Page or Instagram account, we stop receiving new messages for that account. Messages already received remain in the Customer’s account until deleted.
- Copies of message content held by Meta, Telnyx, or Anthropic are subject to those providers’ own retention practices. Deleting a conversation in Automate Admits does not delete Meta’s copy of a Messenger or Instagram thread.
We retain other personal information for as long as needed to provide the Service and thereafter only as required for legitimate business or legal purposes such as security, dispute resolution, and compliance.
8. Data deletion & your rights
Depending on your location, you may have rights to access, correct, delete, or restrict the processing of your personal information, and to object to certain processing.
How to request deletion of your data
- End users: If you messaged a business that uses Automate Admits and want your conversation data deleted, email privacy@automateadmits.com with the connected Facebook Page or Instagram account name and the name/handle you used. We will delete the associated data, or forward your request to the relevant Customer where they are the controller, within 30 days.
- Customers: You can disconnect a channel at any time from within the app, and you can request deletion of your account and associated data by emailing privacy@automateadmits.com.
- Facebook/Instagram users: You may also remove the Automate Admits connection from your Facebook or Instagram settings under Business Integrations / Apps and Websites. Removing the connection stops further data collection; to also delete previously stored data, contact us at the address above.
We will verify requests before acting on them and will not discriminate against you for exercising your rights.
9. Security
We use technical and organizational measures designed to protect personal information, including encryption in transit and at rest, role-based access control, two-factor authentication, salted and iterated password hashing, per-organization audit logging, and signature verification of incoming platform webhooks. Full detail is on our Security page, which also lists what we have not yet done. No method of transmission or storage is completely secure, but we work to protect your information and to limit access to those who need it to operate the Service.
HIPAA & health information. Where a Customer uses the Service to handle protected health information, Automate Admits acts as the Customer’s Business Associate under HIPAA and offers a standing Business Associate Agreement that applies to every Customer. We describe the Service as HIPAA-eligible, not HIPAA-certified — no body certifies software as HIPAA compliant. Substance use disorder records are handled under our Qualified Service Organization Agreement, which also states plainly which Part 2 controls the Service does and does not provide. See our Trust & Compliance page for details and to request a copy of the BAA.
10. International data transfers
We and our service providers may process information in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
11. Children’s privacy
The Service is intended for businesses and is not directed to children under 13 (or the age required by your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.
13. Contact us
If you have questions or requests regarding this Privacy Policy or your personal information, contact us at:
- Automate Admits, Inc. (operators of Automate Admits)
- Email: privacy@automateadmits.com
- Web: https://automateadmits.com