Privacy Policy
How [to be filled in: legal entity] collects, uses and deletes personal data in the luv-social service. In force since [to be filled in: effective date].
In force since [to be filled in: effective date]
1. Who is responsible
The controller of your personal data is [to be filled in: legal entity], [to be filled in: registered address]. Write to [to be filled in: privacy address] about anything on this page.
2. What we hold
We hold six kinds of data, and no more than these:
- Account: your name, e-mail address, language and time zone, and — if you enable it — the fact that two-factor authentication is on.
- Workspace content: the posts you write, the media you upload, tags, brands, the names of your channels and the people you invited.
- Channel access: the tokens a platform issues so that we can publish for you. They are encrypted and never shown back to you or to us in readable form.
- Publication records: what we sent to a platform, what it answered, and when. This is how the service can tell you what happened to a post.
- Technical records: IP address and browser of a sign-in, and error reports if the operator has enabled error tracking.
- Payment: the plan, the period and the identifiers our payment provider gives us. We never see or store your card.
3. Why we may hold it
Account data, workspace content and channel access are processed to perform the contract with you — without them the service cannot do the one thing it exists for.
Publication and technical records are processed on our legitimate interest in a service that can explain itself, resist abuse and be debugged. Payment data is processed to comply with tax and accounting law.
We do not use your data for advertising, we do not sell it, and we do not use your content to train models.
4. What we send to the platforms
When you publish, the post text, its attachments and the settings you chose are sent to the platform you selected — that is the act you asked for. What the platform does with them afterwards is governed by the platform, not by us.
We read from a platform only what we need to show you the channel and the result: the account name and picture, the identifier of the published post, and the error text when something fails.
5. Who else touches the data
We use a small number of providers, each bound by a contract and each with access only to what their job needs:
We do not pass your data to anyone else, except where the law requires it of us.
- the hosting provider that runs the servers and the database;
- the object storage that holds uploaded media;
- the e-mail provider that delivers the letters we send you;
- the payment provider that processes charges;
- an error-tracking service, when the operator has enabled one.
6. How long we keep it
Account and workspace content are kept while the account exists. Everything else is on a schedule the software enforces by itself, every night:
A deleted workspace or account is removed for good after 30 days; until then the deletion can be undone by writing to us.
- The text and platform answers stored with a publication attempt: 90 days, then cleared — the attempt and its outcome remain, the content does not.
- The workspace timeline and in-app notifications: 180 days, then deleted.
- The IP address in an audit record: 365 days, then cleared; the record of the action itself remains.
- The IP address and browser of a session: cleared 365 days after the session was opened, and deleted 7 days after the session expired.
- The body of a payment event, which may carry your name and address: 90 days, then cleared.
- Backups: [to be filled in: backup retention] days.
7. How it is protected
Channel tokens are encrypted with a key of their own workspace, and the key itself is stored wrapped by a master key held outside the database.
Every workspace is isolated in the database itself, not only in application code: a query that does not name a workspace returns nothing. Operator access to a customer workspace requires two-factor authentication and is recorded in an audit log the customer can read.
8. Your rights
You may, at any time:
Write to [to be filled in: privacy address]. We answer within 30 days.
- ask what we hold about you and get a copy;
- correct anything that is wrong — most of it you can edit yourself;
- delete your account and your data (see the next section);
- object to processing based on our legitimate interest;
- complain to the data-protection authority of [to be filled in: jurisdiction].
9. Deleting your data
You can delete your account yourself, from the profile screen, without writing to anyone. What exactly happens then — and what is kept, because the law requires it — is described on the "Deleting your data" page.
10. Children
The service is not intended for children. We do not knowingly create accounts for people below the age of consent in their country; if we learn of one, we delete it.
11. Where the data is processed
The servers of the service are in the country the operator names at [to be filled in: privacy address] on request. The social platforms you connect are outside it, and publishing to them necessarily transfers the post to wherever they operate — that is the purpose of the act.
12. Changes to this policy
We may update this document. A change that materially affects you is announced by e-mail before it takes effect.
13. Contact
[to be filled in: legal entity], [to be filled in: registered address]. Privacy questions: [to be filled in: privacy address].