N7 Social Media Connector

Privacy policy

This policy explains what data N7 Social Media Connector processes, why, how long it is kept and how you can have it deleted. It applies to the N7 Social Media Connector application operated by Netseven and to the pages published on this domain.

Last updated: Aug 15, 2026

1. Who is responsible for your data

The data controller is:

For questions about this policy, or to exercise any of the rights described in section 10, write to info@netseven.pl. Requests to delete data can also be submitted through the data deletion page.

2. What the application does

N7 Social Media Connector is a content aggregation tool. A website owner connects their own social media accounts (a Facebook Page, an X profile, a TikTok account) and the application periodically reads the public posts already published on those accounts and makes them available to that owner's own website through a read-only API, so the site can display a social media feed.

The application is read-only by design. It does not publish, comment, message or interact on your behalf.

3. What data is processed

3.1 Connected account data

3.2 Public content from connected accounts

Only content that is already public on the connected account is read.

3.3 Administrator accounts

For people who log in to the administration panel: name, email address, a hashed password and the roles and permissions assigned to them.

3.4 API clients

For each website allowed to read a feed: a client name, a hashed API token, an optional list of allowed origins and the date the token was last used.

3.5 Technical logs

Synchronisation logs recording when an account was read, how many posts were fetched, created or updated, and any error message returned by the platform. Standard server and application logs may record the time of a request, the URL and an IP address.

3.6 Data deletion requests

If you use the data deletion form: your email address, the platform and account you identify, your message, the IP address the form was submitted from and the date of submission. This is needed to find your data, act on the request and prove it was handled.

4. Where the data comes from

Data is obtained from the official platform APIs, and only with the account owner's authorisation:

Where a platform requires it, the connection is made through that platform's own OAuth login screen, so you grant access on the platform itself and can withdraw it there at any time.

5. Why the data is processed, and on what legal basis

Purpose Legal basis (GDPR)
Reading and displaying the public posts of the account you connected, on your own website. Performance of a contract, Art. 6(1)(b); your authorisation given on the platform.
Storing access tokens so the feed can refresh without a new login each time. Performance of a contract, Art. 6(1)(b).
Keeping synchronisation logs to detect and fix failures and abuse. Legitimate interest in a secure, working service, Art. 6(1)(f).
Handling and documenting data deletion and other rights requests. Legal obligation, Art. 6(1)(c), together with Art. 12 GDPR.
Administering panel accounts and API access. Legitimate interest in securing the service, Art. 6(1)(f).

6. What is never done with the data

7. Who the data is shared with

Data is not transferred to any other recipient unless required by law. Servers are located within the European Economic Area. Where a platform API involves a transfer outside the EEA, that transfer is carried out by the platform under its own safeguards, such as the European Commission's standard contractual clauses.

8. Cookies on these pages

The privacy policy page sets no cookies. The data deletion page sets two strictly necessary cookies — a session cookie and a CSRF token cookie — so the form can be submitted safely. There are no analytics, advertising or tracking cookies on these pages. Administrators who log in to the panel receive a session cookie and, optionally, a “remember me” cookie.

9. How long data is kept

10. How the data is protected

11. Your rights

Under the GDPR you have the right to:

Write to info@netseven.pl to exercise any of these rights. A reply follows within 30 days. You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland).

12. Deleting your data

Full, step-by-step instructions — including how to revoke the application's access on Facebook, X or TikTok, and a form for requesting deletion of everything already stored — are on the data deletion page. Requests are completed within 30 days.

13. Children

The application is a tool for website owners and is not directed at children. It is not knowingly used to process the data of anyone under 16. If such data reaches the application, it is deleted on notice.

14. Changes to this policy

This policy may be updated when the application changes. The date at the top always shows the current version, and the URL of this page stays the same, so the version registered with the platforms remains valid.

15. Contact

Netseven, info@netseven.pl