Privacy Policy
Last updated: 19 August 2026
In short. We process conversations only to make the service work: deliver automated replies, display conversations in a shared inbox, and maintain a contact database. We do not sell data, we do not use it to train artificial intelligence models, and we delete uploaded chat archives right after processing.
1. Who we are
The dmhive service (dmhive.io) is provided by Individual Entrepreneur Valentin Nazarenko, registered at Georgia, Tbilisi, Nadzaladevi district, Ts. Dadiani Street, N34, Block N7, Building N10, commercial space, registration number 300421933 ("we", "us", "the service").
Data protection enquiries: privacy@dmhive.io.
2. Two roles: our customers and their subscribers
- Customer: a business that signed up for dmhive and connected its messaging accounts. For customer data we act as the data controller.
- Subscriber: a person who messages the customer. For subscriber data we act as a data processor, processing it on the customer's documented instructions under a data processing agreement. The customer is the controller of that data.
3. Data we process
3.1. Customer account data
- email address, name, password (stored hashed);
- subscription and payment history (card details are handled by our payment provider Paddle, see section 6, and never reach our servers);
- technical data: IP address, browser type, activity logs.
3.2. Data received from Meta platforms
When a customer connects an Instagram account or Facebook Page, we receive the following through official Meta APIs:
| Data | Purpose |
|---|---|
| Connected account ID, name and profile picture | Show the customer which account is connected; send messages on its behalf |
| Direct messages: text, attachments, sender ID, timestamps | Deliver automated replies, display conversations in the inbox, let operators reply |
| Comments on posts and story replies | Trigger keyword-based automations, including replying to a comment via direct message |
| Subscriber public profile: name and picture | Identify the person in the inbox and personalise replies |
| Access tokens | Technical ability to send and receive messages; stored encrypted |
We receive equivalent data from Telegram, MAX and WhatsApp, limited to what the bot needs to operate in that channel.
3.3. Chat archives uploaded by the customer
A customer may upload an export of their own chats so that the service can assemble a bot scenario automatically. Such archives receive our strictest handling:
- media files are discarded during extraction and never enter processing;
- personal data (phone numbers, addresses, names) is stripped from the text and replaced with anonymised placeholders before any analysis;
- the source archive is deleted automatically: no later than 72 hours after processing inside a customer account, and immediately at the end of the session for the no-signup demo;
- third-party language models (see section 6) receive only an anonymised distilled excerpt, never the full archive.
4. Why we process data
- providing the service: receiving and sending messages, running scenarios, inbox, contacts;
- automatically assembling a bot scenario from material the customer provided;
- billing and plan usage accounting;
- customer support;
- security: preventing abuse, spam and unauthorised access;
- compliance with legal obligations.
GDPR legal bases: performance of a contract (Art. 6(1)(b)); legitimate interests in operating and securing the service (Art. 6(1)(f)); consent where required (Art. 6(1)(a)); legal obligation (Art. 6(1)(c)).
5. What we do not do
- we do not sell data or share it for advertising purposes;
- we do not use message content to train artificial intelligence models, neither our own nor third-party ones; our model providers are contractually barred from training on data we send them;
- we do not read customer conversations manually, except when the customer asks for help, or when required by a security investigation or by law.
6. Who we share data with (subprocessors)
- infrastructure and hosting: Hetzner Online GmbH, Germany;
- content delivery, site protection and storage of early-access requests: Cloudflare, Inc.;
- language model provider for conversation analysis and AI replies: OpenAI.
Payments are handled by Paddle.com Market Limited (United Kingdom), acting as our reseller (merchant of record) and an independent controller of payment data. Paddle receives the buyer's name, email address, country and payment details; full card details never reach our servers. See the Paddle privacy policy for details.
An up-to-date subprocessor list is available to customers on request and forms part of our data processing agreement (DPA).
7. Data location and international transfers
Primary storage is located in the European Union, in Germany. Some subprocessors process data outside the EU: an anonymised summary of conversations is sent to OpenAI (USA) for analysis. Such transfers rely on the European Commission's Standard Contractual Clauses or other safeguards permitted by law.
8. Retention
| Category | Retention |
|---|---|
| Uploaded chat archives | up to 72 hours after processing; for the no-signup demo, until the session ends |
| Inbox conversations and contact records | while the customer account is active; deleted within 30 days of closure |
| Customer account data | while the account is active; 30 days after closure |
| Payment and accounting records | as required by law |
| Technical logs | up to 90 days |
| Backups | up to 35 days, then overwritten |
9. Your rights
You may request access to your data, its correction, deletion or portability, restrict or object to processing, and withdraw consent previously given. Write to privacy@dmhive.io; we respond within 30 days.
If you are a subscriber who messaged a business using dmhive, please contact that business first: it decides how your data is used. We will assist it in fulfilling your request. See Data Deletion for the deletion procedure.
You also have the right to lodge a complaint with your local data protection authority.
10. Security
Data is transmitted over encrypted connections; access tokens and passwords are stored encrypted; staff access follows the principle of least privilege. Customer workspaces are isolated from one another. In the event of a personal data breach we notify affected customers and the supervisory authority within the deadlines set by applicable law (72 hours under the GDPR).
11. Cookies
dmhive.io uses strictly necessary cookies only: login session and interface preferences. There are no advertising or third-party tracking cookies on this site.
12. Children
The service is intended for businesses and is not directed at persons under 16. We do not knowingly collect their data.
13. Changes to this policy
We may update this policy. We notify customers of material changes by email and in the product interface at least 14 days before they take effect. The date of the current version is shown at the top of this page.
Terms of Use · Refunds · Privacy Policy · Data deletion
Individual Entrepreneur Valentin Nazarenko · ID 300421933
Georgia, Tbilisi, Nadzaladevi district, Ts. Dadiani Street, N34, Block N7,
Building N10, commercial space
support@dmhive.io ·
founder@dmhive.io