Legal
Data Deletion
Last updated: September 2026
1. Who This Page Is For
ImmiIQ is software used by Australian migration agencies and immigration lawyers. A firm can connect its own Facebook Page, its Instagram Business account or its LinkedIn organisation page so that posts it has written and approved inside ImmiIQ are published to those pages.
If you arrived here from Facebook or LinkedIn, this page tells you exactly what ImmiIQ holds because of that connection and how to have it deleted. If you are looking for how to delete an ImmiIQ account or a firm's client records, that is in our Privacy Policy.
2. What We Hold
A social connection in ImmiIQ belongs to the firm, not to the person who authorised it. When a firm's administrator connects Facebook, Instagram or LinkedIn, this is the complete list of what is stored:
- An access token, sealed with AES-256-GCM under a key derived per firm before it is written. It is never logged, never displayed and never returned by any part of the product.
- The id and name of the page being posted to - the Facebook Page id and name, the linked Instagram Business account id and handle when the Page has one. It holds the LinkedIn organisation id and name in the same way.
- The permissions granted, when the token expires and the timestamps of the connection, so the firm can see the state of it.
- The posts the firm chose to publish - the caption it wrote, the branded image it attached if there was one and, after publishing, the id the platform returned and the time it went out.
None of this is tied to a personal profile. There is no Facebook user id, no LinkedIn member id and no personal profile data anywhere in an ImmiIQ social connection, which is why a deletion request naming a Facebook account matches nothing here.
3. What We Never Receive
ImmiIQ publishes. It does not read an audience. We never request, receive or store:
- Followers, fans, connections or friend lists
- Messages, direct messages, comments or replies
- Audience, insights, demographic or advertising data
- Lead forms, contact lists or anything exported from a page's inbox
- Anyone's personal profile, email address or phone number
One permission does read a page back: after a post is sent, ImmiIQ can re-read that single post to confirm it published, because a publish that half-failed leaves a firm not knowing whether to send it again. Nothing from that read is stored beyond the post id already in the list above.
4. Option 1: Disconnect the Integration
This is the fastest route and it is entirely in the firm's hands. An administrator opens Settings › Integrations in ImmiIQ, chooses Facebook & Instagram or LinkedIn and selects Disconnect.
In the same moment, with no waiting period:
- The sealed access token is erased from our database
- The stored page id, page name and granted permissions are cleared
- ImmiIQ asks the platform to revoke the grant at its end, so the authorisation disappears from the account's app settings too
- Nothing further can be published to that page
What remains afterwards is a record that a connection once existed and was disconnected - the firm, the date and the reason, kept so an administrator can see who removed it. It contains no token and no page data. Section 5 is how that goes too.
5. Option 2: Email Us
To have everything else erased - the disconnection record, the posts ImmiIQ drafted or published on the firm's behalf and any branded images made for them - email support@immiiq.com with the subject "Data deletion request".
Tell us the firm name and the page the connection was for. If you are writing about a request that began on Facebook, quote the confirmation code you were given. We answer from a person, not an autoresponder.
6. How Long It Takes
Disconnecting: immediate. The credential is gone before the page finishes reloading.
By email: we reply and complete the deletion within 30 days, the same window our Privacy Policy commits to for every privacy request. We send one confirmation email when it is done.
Encrypted backups roll off on their own retention cycle, so a deleted record can survive in a backup for a short period after it has left the live system. It is never restored to serve a request and is overwritten when the cycle completes.
7. Posts Already Published
A post that has already gone out lives on the firm's own Facebook Page, Instagram account or LinkedIn page. It is the firm's content on the firm's page. Only the firm can take it down, from that platform, in the usual way.
Deleting the ImmiIQ record of a post removes our copy of the caption and the image. It does not and cannot remove the post itself. No request to us will change what is on a page we no longer have a token for.
8. Requests Sent From Facebook
Removing ImmiIQ from your Facebook account settings sends us a data deletion callback. We verify that it genuinely came from Facebook, record that it arrived and answer with a confirmation code and a link back to this page carrying that code.
We will not pretend that request deleted something. As section 2 explains, an ImmiIQ connection holds no Facebook user id, so there is no record on our side keyed to your account to erase - and we do not write your account id down in order to say otherwise. What the callback does is give you a reference. If a firm connected a Page you administer, the connection itself is removed by disconnecting it in ImmiIQ or by emailing us.
LinkedIn asks the same question in its own words and the answer is the same one.
9. A Firm's Client Records
Everything a firm keeps in ImmiIQ about its own clients - cases, documents, notes and correspondence - is the firm's, held by us on its behalf. It is governed by our Privacy Policy and by the firm's own agreement with its client. It is unrelated to any social connection.
If you are a client of a migration agency and want your records deleted, ask the firm - it decides what it must keep and for how long under its professional obligations. If you hold an ImmiIQ account of your own, the account deletion route is in the Privacy Policy under "Deleting Your Account".
10. Contact
Email: support@immiiq.com
ImmiIQ is a product of FastFlowUp (ABN 14 677 767 458), registered in Australia. You can also lodge a complaint with the Office of the Australian Information Commissioner.