5.5.1 LinkedIn (Profile & Company Pages)
Data Processed
- • Authorization tokens (OAuth access and refresh tokens), stored using AES-256-GCM encryption
- • Profile IDs and organization IDs, as well as display name, profile picture, or logo
- • Company pages you manage (ID, name, logo) for selecting the publication destination
- • Only to the extent necessary for the features you actively use and to the extent that the respective LinkedIn endpoints provide this data: LinkedIn posts, comments, reactions, and aggregated analytics data
Permissions (Scopes): r_basicprofile, w_member_social, w_member_social_feed, r_member_postAnalytics, r_member_profileAnalytics, r_1st_connections_size, rw_organization_admin, r_organization_social, r_organization_social_feed, w_organization_social, w_organization_social_feed, r_organization_followers
Purpose limitation: We use LinkedIn data solely to provide the requested social-media management services for the connected LinkedIn account or LinkedIn Page, including creating, scheduling and publishing posts, displaying and responding to comments, and providing analytics.
Not used for: We do not sell LinkedIn data, use it for advertising, sales, profiling, or enrichment purposes, or share one customer's LinkedIn data with other customers.
Deletion and withdrawal: LinkedIn credentials and retrieved LinkedIn data are deleted when you disconnect the integration or delete your account, unless statutory retention obligations apply. We will also delete relevant data where required by LinkedIn. We comply with LinkedIn's privacy, security, trust, and storage requirements.
5.5.2 Facebook Pages
Data Processed
- • Authorization tokens, page IDs, display name, and logo
- • Automatically detected links between Facebook Pages, Instagram Business accounts, and WhatsApp Business accounts (linked accounts are "carried over" when establishing a connection)
- • Only to the extent necessary for the actively used features: posts, comments, engagement statistics
- • Private messages are only available through the Community Manager feature you have enabled (Facebook Messenger)
Permissions (Scopes): pages_show_list, pages_read_engagement, pages_manage_posts, pages_messaging, business_management
Purpose limitation: Facebook data is used exclusively to manage the respective customer’s linked Facebook page, specifically to list pages, create, schedule, and publish posts, view engagement statistics, and—if enabled—respond to Messenger messages.
Not used for: We do not sell Facebook data, do not use it for advertising, sales, profiling, or data enrichment, and do not share a customer's Facebook data with other customers.
Deletion and withdrawal: Facebook login credentials and Facebook data that has been retrieved will be deleted when you disconnect, delete your account, or Meta requests that we do so, subject to any mandatory legal retention requirements.
5.5.3 Instagram Business
Data Processed
- • Authorization token, Instagram Business Account ID, display name, and profile picture
- • Only to the extent necessary for the actively used features: posts, comments, insights
- • Direct messages are only available if you have enabled the Community Manager feature (Instagram Direct)
Permissions (Scopes): instagram_basic, instagram_content_publish, instagram_manage_comments, instagram_manage_insights, instagram_manage_messages (+ Facebook Page scopes)
Purpose limitation: Instagram data is used exclusively to manage the respective customer’s linked Instagram Business account, specifically to create, schedule, and publish posts; manage comments; retrieve Insights; and—if enabled—respond to direct messages.
Not used for: We do not sell Instagram data, use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s Instagram data with other customers.
Deletion and withdrawal: Instagram login credentials and retrieved Instagram data will be deleted when you disconnect, delete your account, or Meta requests us to do so, subject to any mandatory legal retention requirements.
5.5.4 Threads
Data Processed
- • Authorization token, Threads account ID, display name, and profile picture
- • Only to the extent necessary for actively used features: Threads posts and aggregated statistics
Permissions (Scopes): threads_basic, threads_content_publish, threads_manage_insights
Purpose limitation: Threads data is used exclusively to manage the respective customer's Threads account, specifically to create, schedule, and publish posts, as well as to retrieve statistics.
Not used for: We do not sell Threads data, use it for advertising, sales, profiling, or data enrichment, and do not share a customer's Threads data with other customers.
Deletion and withdrawal: Threads login credentials and retrieved Threads data will be deleted when you log out, delete your account, or Meta requests that we do so, subject to any mandatory legal retention requirements.
5.5.5 WhatsApp Business
Data Processed
- • Authorization token, WhatsApp Business account ID, and display name
- • Message content is limited to the scope of the Community Manager feature you have enabled (sending and receiving WhatsApp messages)
Permissions (Scopes): whatsapp_business_management, whatsapp_business_messaging, business_management
Purpose limitation: WhatsApp data is used exclusively to link the associated WhatsApp Business account and—if enabled—to manage customer conversations in Community Manager.
Not used for: We do not sell WhatsApp data, do not use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s WhatsApp data with other customers.
Deletion and withdrawal: WhatsApp login credentials and retrieved WhatsApp data will be deleted when you disconnect, delete your account, or Meta requests that we do so, subject to any mandatory legal retention requirements.
5.5.6 X / Twitter
Data Processed
- • Authorization token, including expiration time for automatic renewal (offline.access)
- • Account ID, display name, and profile picture
- • Only to the extent necessary for the actively used features: Posts, including media
Permissions (Scopes): tweet.read, tweet.write, users.read, media.write, offline.access
Purpose limitation: X data is used exclusively to manage the respective customer's associated X presence, in particular to create, schedule, and publish posts, including media.
Not used for: We do not sell X data, use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s X data with other customers.
Deletion and withdrawal: X login credentials and X data you have accessed will be deleted when you log out, delete your account, or when X requests that we do so, subject to any mandatory legal retention requirements.
5.5.7 YouTube (Google)
Data Processed
- • Authorization token, channel ID, display name, and channel image
- • Only to the extent necessary for the actively used features: uploaded videos and associated channel data
Permissions (Scopes): youtube.upload, youtube.readonly, youtube.force-ssl
Purpose limitation: YouTube data is used exclusively to manage the respective customer's linked YouTube channel, in particular to upload videos and to read the channel data required for that purpose.
Not used for: We do not sell YouTube data, use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s YouTube data with other customers.
Deletion and withdrawal: YouTube login credentials and YouTube data you have accessed will be deleted when you log out, delete your account, or when Google requests that we do so, subject to any mandatory legal retention requirements.
5.5.8 TikTok
Data Processed
- • Authorization token, TikTok account ID, display name, and profile picture
- • Only to the extent necessary for the actively used features: videos, as well as profile and statistics data
Permissions (Scopes): user.info.basic, user.info.profile, user.info.stats, video.list, video.upload, video.publish
Purpose limitation: TikTok data is used exclusively to manage the respective customer's associated TikTok account, specifically to publish videos and view profile and statistics data.
Not used for: We do not sell TikTok data, use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s TikTok data with other customers.
Deletion and withdrawal: TikTok login credentials and retrieved TikTok data will be deleted when you log out, delete your account, or TikTok requests that we do so, subject to any mandatory legal retention requirements.
5.5.9 Wix
Data Processed
- • Authorization data via the Wix App Installer, including the expiration date for automatic renewal
- • Website/blog identifiers, to the extent necessary for publication
Permissions (Scopes): App Permissions via the Wix App Installer (not the traditional scope model)
Purpose limitation: Wix data is used exclusively for publishing blog posts on the respective customer's affiliated Wix website.
Not used for: We do not sell Wix data, do not use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s Wix data with other customers.
Deletion and withdrawal: Wix login credentials and retrieved Wix data will be deleted when you disconnect or delete your account, subject to any mandatory legal retention requirements.
5.5.10 WordPress
Data Processed
- • An application password you provided instead of an OAuth token
- • Website URL and, if necessary, username for publication
Permissions (Scopes): Application password created by you (not OAuth)
Purpose limitation: WordPress login credentials are used exclusively for publishing blog posts on your self-hosted WordPress website.
Not used for: We do not sell WordPress data, do not use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s WordPress data with other customers.
Deletion and withdrawal: WordPress login credentials are deleted when you log out or delete your account, subject to any mandatory legal retention requirements.
5.5.11 Own website
Data Processed
- • The webhook URL and secret you configured, instead of an OAuth token
Permissions (Scopes): The webhook URL and secret you configured (no OAuth)
Purpose limitation: The stored endpoint data is used exclusively to transfer data to your own system on your behalf.
Not used for: We do not sell this endpoint data, use it for advertising, sales, profiling, or data enrichment, or share it with other customers.
Deletion and withdrawal: The webhook URL and secret will be deleted when you disconnect or delete your account, subject to any mandatory legal retention requirements.
Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract)
Storage period: Retention period: Until the connection is terminated or the account is deleted. Expired, non-renewable tokens are automatically invalidated. Platform data is also deleted if the respective platform requests that we do so, subject to mandatory legal retention requirements.