Data deletion

Start a deletion request with the business you messaged.

SEP deletion is tenant-scoped. The business that received the conversation is the authority that can identify the correct customer record and begin the governed request.

1. Contact the business

Send the request to the business whose Facebook Page, Instagram account, widget, or other channel received your message. The same channel is the safest starting point because it identifies the responsible tenant without exposing another customer's data.

2. Identify the conversation

Provide the channel used, the Page or account name, and an approximate message date. Do not send a password, login code, payment secret, or government identifier merely to locate the conversation.

3. The business submits the request

An authorized SEP administrator for that business verifies the matching customer record and submits a tenant-scoped deletion governance request. SEP does not allow one organization to inspect or delete another organization's records.

4. Eligible data is removed or redacted

The governed process can purge attachments and derived customer context, redact conversation content, and pseudonymize the customer record. Explicit legal or audit holds remain visible to the authorized business instead of being disguised as deletion success.

If you authorized a business Meta account

1. Remove the Meta authorization

If you authorized a Facebook Page or Instagram account for a business, remove the app authorization from the corresponding Meta account settings. This stops future provider access; it does not by itself prove that tenant records have been deleted.

2. Deactivate the exact SEP asset

Ask an authorized SEP administrator for the same organization to deactivate the connected Page or Instagram asset and submit the applicable tenant-scoped deletion request. Another organization cannot perform this action for you.

3. Retain the recorded outcome

The administrator should retain the governed request status. SEP can redact eligible customer content and provider identity routes only when the deployed revision includes that verified Meta-specific redaction authority; data controlled solely by Meta remains subject to Meta's own settings and terms.