Last updated · October 3, 2026
Privacy, in plain language.
This notice covers the FlyingDM website and early-access request form. It does not yet cover a live Instagram integration.
Who is responsible
FlyingDM is operated by Saasland Ltd, the controller for the processing described here. Saasland Ltd is registered in England and Wales (company number 15793509). Its registered office is 124 City Road, London EC1V 2NX, United Kingdom. Privacy contact: saasland.company@gmail.com (UK GDPR Article 13(1)(a)).
Information we receive
When you request early access, you give us:
- Your email address and Instagram handle.
- A range for your monthly Instagram conversation volume.
- Your primary goal value, which defaults to “all of the above” unless you change it.
To limit abusive submissions, the application briefly reads your IP address and browser user-agent and stores a hash derived from them with a request count. The hash is pseudonymous personal information, not anonymous information (UK GDPR Articles 4(1) and 5(1)(c)). The hosting and access providers may also process technical request and sign-in information to deliver and protect this website.
Why we use it
- We use the email and the information you submit to consider your request and contact you about FlyingDM access. Our legitimate interest is responding to the request you chose to send; we use these details only for that purpose (UK GDPR Article 6(1)(f)).
- We use the business details to assess demand and improve the prospective service. Our legitimate interest is product planning; we limit collection to short form fields (Article 6(1)(f)).
- We use the anti-abuse hash and request count to protect the form. Our legitimate interest is site security and preventing misuse (Article 6(1)(f)).
Requesting access does not sign you up for unrelated promotional emails. If we later offer an optional marketing subscription, we will explain it separately and provide the choice required by applicable direct-marketing rules.
How long we keep it
The application is configured to remove early-access requests older than 12 months and anti-abuse records older than 24 hours. Cleanup runs at server startup, hourly while the server is running, and when a valid form request arrives. An outage can delay removal until service resumes. We may retain a limited record for longer where needed for a legal obligation or claim (Article 5(1)(e)). Heroku retains its recent application log buffer for up to one week or 1,500 lines, whichever limit is reached first. We do not log form bodies. Scheduled database backups retain seven daily copies and one weekly copy on our current plan. Deleted information can remain in these restricted recovery copies until they expire; if a backup is restored, we reapply deletion and retention rules. Provider-managed disaster-recovery copies follow Heroku’s own data-safety policy.
Who processes the information
Heroku (Salesforce) hosts this production website and stores form submissions in Heroku Postgres on our behalf under Salesforce’s applicable data-processing terms. Our authorised team reviews requests; Google provides the Gmail service used for our published contact address and replies. Namecheap manages our domain and DNS, not the form database. We do not sell form data or send it to Meta through this form. Provider personnel and subprocessors may process information as necessary to operate, support and secure their services.
International transfers
The website and database use Heroku’s Europe region. This is not a guarantee that all provider processing stays in Europe or the United Kingdom: support, subprocessors and email services may involve other countries, including the United States. Where a restricted transfer requires safeguards, Salesforce’s data-processing terms provide applicable Standard Contractual Clauses and the UK International Data Transfer Addendum. You can consult the Salesforce agreements or contact us for information about the safeguards. Email sent to our Gmail contact is also subject to Google’s applicable privacy and international-transfer terms; see Google’s Privacy Policy.
Cookies and similar technologies
The FlyingDM landing code does not set analytics or advertising cookies and the public website does not require a ChatGPT sign-in. If non-essential tracking is added, we will provide the information and choice required by the UK Privacy and Electronic Communications Regulations before it runs.
Your rights and complaints
Depending on the circumstances, you can ask to access, correct, erase or restrict your information (UK GDPR Articles 15–18). Data portability is generally unavailable for this form because we rely on legitimate interests rather than consent or a contract (Article 20). We normally respond to a rights request within one month (Article 12(3)).
You may object at any time to processing based on our legitimate interests, including product planning and anti-abuse processing (Article 21). Contact saasland.company@gmail.com to exercise a right or make a data-protection complaint. We will acknowledge a complaint within 30 days, investigate it and explain the outcome. You may also complain to the UK Information Commissioner’s Office through its complaints service.
Required fields and automated decisions
The form requires an email address, Instagram handle and conversation volume. The primary goal has a default selection that you can change. These fields are not required by law. Without the required fields we cannot review the access request. The application does not use the form to make decisions with legal or similarly significant effects solely by automated means (Article 13(2)(e)–(f)).
Future Instagram integration
This notice does not cover customer messages or other Instagram platform data. Before offering a live integration, we will describe the data categories, purposes, controller and processor roles, permissions, providers, retention, deletion and international transfers, and assess whether a data-protection impact assessment is needed (Articles 13–14, 28 and 35).
Questions
Contact saasland.company@gmail.com. This notice is based on the UK GDPR and Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025.