Privacy Policy
Effective Date: March 30, 2025
1. Introduction
This Privacy Policy describes how PAN STUDIOS, LLC ("we," "us," or "our") collects, uses, and protects information in connection with our website (dukepan.com), AI automation services, and any automated messaging integrations we operate on behalf of our clients (collectively, the "Services").
By using our Services, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use of our Services.
2. Information We Collect
2.1 Website Visitors
When you visit dukepan.com, we may collect:
- Standard server log data (IP address, browser type, referring URLs, pages visited, timestamps)
- Information you voluntarily submit through contact forms, community email signup forms, or by booking a call
2.2 Instagram DM Automation (Meta Graph API)
As part of our AI automation services, we may operate automated messaging agents connected to our clients' Instagram accounts via the Meta Graph API. In this context, we may process the following data on behalf of the account owner (our client):
- Instagram User IDs: The unique numeric identifier assigned by Meta to any Instagram user who sends a message to the connected account.
- Instagram Usernames: The public username associated with a message sender, when made available by the API.
- Message Content: The text content of direct messages received by the connected Instagram account, used solely to generate automated AI-powered replies.
- Message Timestamps: The date and time a message was sent, used for operational purposes.
Important: We act as a data processor on behalf of our clients (the Instagram account owners), not as an independent data controller. Data processed through the Meta Graph API is subject to Meta's Privacy Policy as well as this policy.
2.3 Other Automation Services
For other workflow automation services (customer support bots, email automation, CRM integrations, etc.), we process only the data necessary to provide the agreed service. Specific data handling terms are outlined in the client service agreement.
3. How We Use Your Information
We use collected information for the following purposes:
- To provide the Services: Processing Instagram DMs and other messages to generate AI-powered automated replies on behalf of our clients.
- To improve the Services: Analyzing aggregate, anonymized patterns to improve automation accuracy and response quality.
- To communicate with you: Responding to inquiries, sending service-related notices, and fulfilling booking requests.
- To comply with legal obligations: Retaining records as required by applicable law or in response to legal process.
We do not use personal data collected through the Instagram integration for advertising, marketing, training AI models for third parties, or any purpose beyond directly operating the automation service for the account owner.
4. Data Retention
We retain data only as long as necessary to provide the Services:
- Message data (Instagram DMs and other processed messages): Retained for up to 90 days after the end of the service relationship, then securely deleted.
- Client account data: Retained for the duration of the client engagement and for up to 3 years afterward for legal and accounting purposes.
- Website logs: Retained for up to 12 months.
Clients may request earlier deletion of message data by contacting us at duke@dukepan.com.
5. Third-Party Sharing
We do not sell, rent, or trade personal data to third parties. We share data only in the following limited circumstances:
- Service providers: We use trusted third-party tools to operate the Services (e.g., cloud hosting, AI model APIs). These providers are contractually bound to process data only on our behalf and in accordance with this policy.
- Meta (Instagram): Data is exchanged with Meta's platform as a necessary part of operating the Instagram DM integration. See Meta's Privacy Policy for their practices.
- Legal requirements: We may disclose data if required to do so by law, court order, or governmental authority.
- Business transfers: In the event of a merger, acquisition, or asset sale, data may be transferred as part of that transaction, subject to equivalent privacy protections.
6. Data Security
We implement reasonable technical and organizational measures to protect personal data from unauthorized access, loss, or disclosure. These include encrypted data transmission (TLS), access controls, and secure credential management. However, no system is completely secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that inaccurate data be corrected.
- Deletion: Request that your personal data be deleted, subject to any legal retention requirements.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Portability: Request a portable copy of your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
To exercise any of these rights, please contact us at duke@dukepan.com. We will respond within 30 days.
Note: For data processed through the Instagram integration, the account owner (our client) is the primary data controller. End users wishing to exercise their rights should first contact the Instagram account owner, or contact us and we will assist in coordinating the request.
8. Children's Privacy
Our Services are not directed to individuals under the age of 13 (or 16 in the EU/EEA). We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" at the top of this page. Continued use of the Services after any changes constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us: