You control the purpose of your customer conversations. BIGI processes the relevant records on your instructions. A public information page does not replace a binding data processing agreement.
Controller and processor roles
For your connected Instagram conversations and leads, your business normally decides why the data is used and is the controller. BIGI operates the tools on your behalf as processor. For BIGI account administration, security and its own business records, Stockholm IT Academi AB acts as controller.
Do not use BIGI to process data on behalf of another organisation unless you have the required authority and agreements. Meta and other services may have their own independent responsibilities under their terms.
Processing description
Subject matter: operation of your BIGI workspace and permitted Instagram conversation, campaign and content workflows. Duration: your use of the service followed by applicable deletion and restricted-retention periods.
Nature and purpose: collecting authorised events, storing workspace records, retrieving business context, preparing or transmitting authorised replies, recording outcomes, exporting and deleting records.
People concerned: workspace users, Instagram followers and other people interacting with the connected account, leads and people appearing in authorised uploaded content. Data types include account identifiers, usernames, messages, comments, timestamps, lead responses, business context and requested media. Sensitive categories are not required for the service and should not be submitted without a specific lawful need and appropriate safeguards.
Instructions and confidentiality
Processing must follow the controller’s documented lawful instructions, including workspace configuration, approved actions and deletion requests. Processing required by law must be handled under the applicable legal obligation, with notice where permitted.
Authorised personnel must be bound by appropriate confidentiality obligations. Access should be limited to people who need it for an authorised service purpose. If an instruction appears to infringe data protection law, the processor must inform the controller.
Security and assistance
Relevant measures include authenticated access, encrypted connection tokens, workspace isolation, signed-event verification, server-side action restrictions and controls to pause automation. See the security page for a practical description.
The processor must assist the controller, taking account of the processing and available information, with individual rights requests, breach assessment, impact assessments and supervisory-authority enquiries. An applicable personal data breach must be notified to the controller without undue delay.
Subprocessors and transfers
The subprocessor page lists the hosted configuration’s infrastructure and optional AI processing providers. The binding agreement must establish authorisation for subprocessors, obligations equivalent to the relevant processing duties, and a notice and objection process for changes.
Processing outside the EEA requires an applicable lawful transfer mechanism. Adequacy decisions or appropriate contractual safeguards and any necessary supplementary measures depend on the destination and provider. This page does not assert that every provider’s contract or transfer assessment has been independently verified.
Return, deletion and accountability
At the end of processing, the agreement must provide for return or deletion of personal data at the controller’s choice, subject to legal retention. BIGI provides an export route and deletion requests; live deletion and backup expiry are distinct.
The processor must make available the information necessary to demonstrate compliance with its processing obligations and allow appropriate audits, including inspections, under the binding agreement. Requests should protect other customers’ confidentiality and the security of the service.
Put the agreement in place
Before entrusting customer personal data to BIGI, obtain and accept a binding Article 28 data processing agreement with Stockholm IT Academi AB. Email gdpr@sita.dev with your legal business name and the planned processing scope to arrange it. No signature or acceptance is inferred from visiting this website.
The authoritative legal requirements are in the EU General Data Protection Regulation, including Articles 13–14, 28, 32–36 and Chapter V. The privacy notice explains BIGI’s own controller processing and the data deletion page gives actionable request steps.
Useful links
Contact the privacy team · Company details · Privacy notice · Request deletion · GDPR & processing · Data processing agreement · Subprocessors · Terms
Your rights: Swedish Authority for Privacy Protection · EU General Data Protection Regulation