Privacy policy
This policy explains what data N7 Social Media Connector processes, why, how long it is kept and how you can have it deleted. It applies to the N7 Social Media Connector application operated by Netseven and to the pages published on this domain.
Last updated: Aug 15, 2026
1. Who is responsible for your data
The data controller is:
- Netseven
- ul. Lipowa 1, 42-690 Tworóg
- KRS: 0000571964, NIP: 6452543340
- Email: info@netseven.pl
For questions about this policy, or to exercise any of the rights described in section 10, write to info@netseven.pl. Requests to delete data can also be submitted through the data deletion page.
2. What the application does
N7 Social Media Connector is a content aggregation tool. A website owner connects their own social media accounts (a Facebook Page, an X profile, a TikTok account) and the application periodically reads the public posts already published on those accounts and makes them available to that owner's own website through a read-only API, so the site can display a social media feed.
The application is read-only by design. It does not publish, comment, message or interact on your behalf.
3. What data is processed
3.1 Connected account data
- Public account identifiers: page or profile ID, name, username or handle.
- Public profile picture URL and public profile link.
- Access and refresh tokens issued by the platform when you authorise the connection.
- Technical settings you choose: how often the account is synchronised, content filters.
3.2 Public content from connected accounts
- Post text, publication date and the permanent link to the original post.
- Attached media (images, video thumbnails and video URLs) and the post type.
- The author name and author avatar shown publicly on the post.
- Public engagement counters, such as the number of reactions, comments or views.
- The raw API response for the post, kept so a synchronisation problem can be diagnosed.
Only content that is already public on the connected account is read.
3.3 Administrator accounts
For people who log in to the administration panel: name, email address, a hashed password and the roles and permissions assigned to them.
3.4 API clients
For each website allowed to read a feed: a client name, a hashed API token, an optional list of allowed origins and the date the token was last used.
3.5 Technical logs
Synchronisation logs recording when an account was read, how many posts were fetched, created or updated, and any error message returned by the platform. Standard server and application logs may record the time of a request, the URL and an IP address.
3.6 Data deletion requests
If you use the data deletion form: your email address, the platform and account you identify, your message, the IP address the form was submitted from and the date of submission. This is needed to find your data, act on the request and prove it was handled.
4. Where the data comes from
Data is obtained from the official platform APIs, and only with the account owner's authorisation:
- Meta / Facebook Graph API — public posts and public page details of a connected Facebook Page, read with the
pages_read_engagementandpages_read_user_contentpermissions. - X (Twitter) API v2 — public posts of a connected profile, read with an application-only token.
- TikTok Display API — basic public profile data and the public video list of a connected account, read with the
user.info.basicandvideo.listscopes.
Where a platform requires it, the connection is made through that platform's own OAuth login screen, so you grant access on the platform itself and can withdraw it there at any time.
5. Why the data is processed, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Reading and displaying the public posts of the account you connected, on your own website. | Performance of a contract, Art. 6(1)(b); your authorisation given on the platform. |
| Storing access tokens so the feed can refresh without a new login each time. | Performance of a contract, Art. 6(1)(b). |
| Keeping synchronisation logs to detect and fix failures and abuse. | Legitimate interest in a secure, working service, Art. 6(1)(f). |
| Handling and documenting data deletion and other rights requests. | Legal obligation, Art. 6(1)(c), together with Art. 12 GDPR. |
| Administering panel accounts and API access. | Legitimate interest in securing the service, Art. 6(1)(f). |
6. What is never done with the data
- No selling, renting or brokering of data to anyone.
- No advertising, ad targeting, profiling or automated decision-making.
- No reading of private messages, direct messages, friend lists or non-public content.
- No posting, commenting, liking, following or any other action on your behalf.
- No use of platform data for any purpose other than displaying your own public feed on your own website, as required by the Meta Platform Terms, the X Developer Agreement and the TikTok Developer Terms.
7. Who the data is shared with
- The website operator who connected the account — public feed content is delivered to their site, which is the entire purpose of the connection.
- The hosting provider that runs the servers and databases for this application, acting as a processor under a data processing agreement.
- The source platforms (Meta, X, TikTok), where the data originates and which process it under their own privacy policies.
Data is not transferred to any other recipient unless required by law. Servers are located within the European Economic Area. Where a platform API involves a transfer outside the EEA, that transfer is carried out by the platform under its own safeguards, such as the European Commission's standard contractual clauses.
8. Cookies on these pages
The privacy policy page sets no cookies. The data deletion page sets two strictly necessary cookies — a session cookie and a CSRF token cookie — so the form can be submitted safely. There are no analytics, advertising or tracking cookies on these pages. Administrators who log in to the panel receive a session cookie and, optionally, a “remember me” cookie.
9. How long data is kept
- Connected account data and access tokens — until the account is disconnected, the token is revoked on the platform, or you ask for deletion.
- Public posts and media — for as long as the account stays connected. Deleting the account in the panel deletes its stored posts and media.
- Synchronisation logs — automatically pruned after 30 days.
- Administrator and API client records — for as long as the access is needed, then deleted.
- Data deletion requests — 365 days after the request is completed, as proof that it was handled, then deleted.
10. How the data is protected
- Access tokens and other credentials are encrypted at rest in the database.
- API tokens are stored only as hashes and are shown once, at creation.
- All traffic to the application and to the platform APIs runs over HTTPS.
- Panel access is restricted by roles and permissions, and every account needs its own login.
11. Your rights
Under the GDPR you have the right to:
- access your data and receive a copy of it;
- have inaccurate data corrected;
- have your data erased (see the data deletion page);
- restrict or object to processing based on legitimate interest;
- receive your data in a portable format;
- withdraw an authorisation you gave on a platform, at any time, in that platform's settings.
Write to info@netseven.pl to exercise any of these rights. A reply follows within 30 days. You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland).
12. Deleting your data
Full, step-by-step instructions — including how to revoke the application's access on Facebook, X or TikTok, and a form for requesting deletion of everything already stored — are on the data deletion page. Requests are completed within 30 days.
13. Children
The application is a tool for website owners and is not directed at children. It is not knowingly used to process the data of anyone under 16. If such data reaches the application, it is deleted on notice.
14. Changes to this policy
This policy may be updated when the application changes. The date at the top always shows the current version, and the URL of this page stays the same, so the version registered with the platforms remains valid.
15. Contact
Netseven, info@netseven.pl