Data deletion
How to delete Facebook and Instagram data that 20X holds after a customer connects a Page or Instagram professional account.
Who can request deletion
Deletion is not limited to the business that connected the account. You can request deletion if you are:
- a 20X customer or workspace admin who connected a Facebook Page or Instagram professional account;
- an end customer — anyone who sent a message, left a public comment, or otherwise interacted with that Page or Instagram account, including people identified by a Facebook PSID or Instagram IGSID.
20X processes this data as a processor on the connecting business’s behalf. We will still action a valid request from the person whose data we hold.
How to request deletion
Email privacy@20x.business from a reachable address and include:
- that this is a data-deletion request for Facebook/Instagram data held by 20X;
- the Facebook Page name or Instagram username involved, if you know it;
- your Facebook/Instagram profile name and, if you have them, your PSID or IGSID;
- an approximate date of the conversation or comment.
Workspace admins can also disconnect the Page or Instagram account in 20X (Integrations). Disconnecting deletes stored access tokens immediately. Remaining messages, comments, and sender identifiers are deleted within 90 days, or sooner if you ask us to delete them.
If you connected the account through Facebook Login, you can also remove 20X from Facebook Settings → Apps and Websites. Meta then sends us a deauthorization callback; we delete tokens when we receive it.
What we delete
On a valid request (or on disconnect / Meta deauthorization, as applicable) we delete from 20X systems:
- access tokens (encrypted at rest with AES-256-GCM while stored);
- inbound messages and public comment text;
- conversation transcripts generated from those messages;
- sender IDs (PSID / IGSID) and profile names collected for those interactions;
- Page ID/name and Instagram account ID/username when the connection itself is removed.
We may retain a minimal record of the request (date, requester email, and that deletion was completed) for up to 90 days to demonstrate that we honoured it. Billing and security logs that do not contain your message content follow the retention rules in our Privacy Policy.
Meta signed deletion callbacks
When Meta sends a signed user-data deletion callback for this app, we process it and delete the associated tokens and social-account data. This page is the public instructions URL (/legal/data-deletion). If a separate callback endpoint is published for App Review, it will be listed here once the backend path is confirmed.
Timing
We acknowledge deletion requests within 2 business days and complete deletion within 30 days, unless a shorter period applies under GDPR or India’s DPDP Act. Messages and transcripts we have not already deleted are otherwise retained for 90 days from collection, then deleted automatically.