Sitelab LLC, operator of the SociHunt application (the “Company,” “we,” “us,” or “our”)

Effective Date: 7/23/2026
Last Updated: 7/23/2026

1. Purpose and Scope

1.1 These Guidelines set out the requirements and procedures governing the Company’s receipt, review, and disposition of requests from Public Authorities for Personal Data or other information relating to users of the SociHunt application and any related products and services (the “Services”).

1.2 These Guidelines apply to every such request, whether domestic or foreign, and bind all directors, officers, employees, and agents of the Company who receive, review, or respond to such requests.

2. Definitions

2.1 “Personal Data” means any information relating to an identified or identifiable natural person that is processed by the Company in connection with the Services.

2.2 “Public Authority” means any law enforcement agency, court, tribunal, prosecutor, regulator, or other governmental or public authority, whether domestic or foreign, purporting to act under legal authority.

2.3 “Request” means any subpoena, warrant, court order, production order, summons, administrative demand, or other legal process, or any informal solicitation, issued or made by a Public Authority seeking the disclosure, preservation, restriction, or removal of Personal Data.

3. Requests Concerning Instagram Data; Redirection to Source

3.1 The authoritative record of a user’s Instagram account and content, including posts, media, captions, comments, followers, and direct messages, is maintained by Meta Platforms, Inc. and its affiliates (“Meta”) on the Instagram service, and not by the Company. A Public Authority seeking such data should direct its Request to Meta in accordance with Meta’s applicable procedures.

3.2 In connection with the Services, the Company processes and retains only a limited subset of Instagram-derived data, namely: encrypted access tokens authorizing the Services to act on a user’s behalf; aggregated or cached analytics and insights derived through the Instagram Graph API; content scheduled by a user for publication; and basic account profile information. These Guidelines govern any Request insofar as it seeks data actually held by the Company.

3.3 Upon receipt of a Request, the Company may inform the requesting Public Authority that it is not the original source of the user’s Instagram data, may direct the Request to Meta and to the affected user, and may provide such limited information as is reasonably necessary to facilitate that redirection, in each case to the extent permitted by law.

4. Review of Legality

4.1 The Company shall not disclose Personal Data in response to a Request except following review of the legality, validity, and enforceability of that Request.

4.2 Each Request shall be examined to confirm that it: (a) originates from a Public Authority of competent jurisdiction; (b) rests upon a valid legal basis and is served through proper legal process; (c) is sufficiently specific and is not vague, overbroad, or unduly burdensome; and (d) conforms to applicable law, including the law of the jurisdiction in which the Company and the relevant data are situated.

4.3 A Request that does not satisfy Section 4.2 shall be rejected, or its narrowing or correction shall be required, before any disclosure is considered.

5. Data Minimization

5.1 Where disclosure is legally required, the Company shall disclose only the minimum Personal Data necessary to comply with the specific and lawful terms of the Request.

5.2 The Company shall not disclose Personal Data beyond the precise scope compelled by valid legal process, and shall decline any Request seeking bulk, indiscriminate, or otherwise unnecessary access.

6. Right to Challenge

6.1 The Company reserves the right, and shall exercise that right where appropriate, to object to, seek to narrow, or challenge by lawful means any Request that it considers unlawful, invalid, overbroad, disproportionate, or otherwise improper, including before a court or other competent authority.

6.2 The Company shall not comply with a Request that it determines to be unlawful.

7. Documentation and Recordkeeping

7.1 The Company shall create and maintain a record of each Request received. Such record shall include, at a minimum: the identity of the requesting Public Authority; the date of receipt; the nature and scope of the Request; the legal basis asserted; the Company’s assessment; the response provided, together with the legal reasoning for that response; the Personal Data, if any, disclosed; and the personnel involved in the review and response.

7.2 Records maintained under this Section shall be retained in accordance with applicable law and the Company’s data retention practices.

8. Notice to Affected Users

8.1 Where permitted by applicable law and consistent with the integrity of any lawful investigation, the Company shall make reasonable efforts to notify an affected user prior to the disclosure of that user’s Personal Data, so as to afford the user an opportunity to seek protective relief.

8.2 The Company shall withhold such notice where prohibited by law or court order, or where notice would create a risk to the life or physical safety of any person.

9. Emergency Requests

9.1 Where a Request arises from circumstances involving an imminent risk of death or serious physical harm, the Company may disclose the Personal Data reasonably necessary to prevent that harm, subject to verification, to the extent practicable, of the emergency and of the requesting authority, and subject to documentation of the disclosure in accordance with Section 7.

10. No Voluntary or Excess Disclosure

10.1 The Company does not sell Personal Data. The Company does not voluntarily provide Personal Data to any Public Authority except as required by valid legal process or as permitted under Section 9.

11. European Data Protection

11.1 Where the Company processes Personal Data subject to Regulation (EU) 2016/679 (the “General Data Protection Regulation”) or other applicable European data protection law, the Company shall respond to Requests only in a manner consistent with those laws.

11.2 Where the Company is compelled to disclose Personal Data in a manner that it reasonably considers to conflict with applicable European data protection law, and is prohibited from notifying the affected user, the Company shall, to the extent lawful, inform the user of its inability to reconcile the Request with such law, so that the user may take such steps as the user considers appropriate, including the suspension of further processing or the termination of the user’s use of the Services.

12. Service and Contact

12.1 Requests shall be submitted in writing and directed to: [Legal Contact Name / Title], [Email Address], [Postal Address].

12.2 A Request that does not comply with these Guidelines and with applicable law may be rejected.

13. Governing Law

13.1 These Guidelines shall be construed in accordance with the laws of [Jurisdiction], without prejudice to any mandatory legal obligation applicable to a particular Request.

14. Amendment

14.1 The Company may amend these Guidelines from time to time. The version in effect is identified by the Effective Date stated above.