Privacy Policy

Version 1.0Effective: June 4, 2026

1. Introduction

This Privacy Policy explains how Codian Limited collects, uses, shares, and protects personal data when you use Postid (the "Service"). It applies to anyone who:

  • Registers an account with the Service.
  • Visits postid.app and provides information through forms (e.g., the contact form).
  • Joins a Workspace as an invited team member.
  • Connects a third-party social media account to the Service.

We are the data controller for the personal data described in this notice. If you are a member of a Workspace owned by someone else, that Workspace Owner may also act as a controller for content and metadata you produce inside their Workspace; we act as a processor of that content on their behalf.

This Policy is supplemented by:

If anything in this Policy conflicts with the KVKK Aydınlatma Metni for data subjects in Türkiye, the KVKK Aydınlatma Metni governs to the extent of the conflict.

2. Personal Data We Collect

The categories of personal data we process and the sources are summarised below.

2.1 Account and identity data

FieldSourcePurpose summary
Email addressYou, when you registerIdentifier, login, transactional emails, password reset, billing notices
Password (hashed)You, when you registerAuthentication
Display nameYou, when you register or update profileDisplay in dashboard, notifications
Preferred locale (tr, en)You, browser defaultUI language and email templates
Preferred timezone (IANA identifier)You, browser defaultScheduling correctness
Two-factor authentication secret + recovery codesYou, when you enable 2FAAuthentication
Email verification / password-reset / email-change tokensGenerated by usAccount-security flows
Last login timestampGenerated by usAccount-security display

2.2 Workspace and billing data

FieldSourcePurpose summary
Company name, tax number, tax office, address, city, country, postal code, phoneYou, in Workspace settingsInvoicing, tax compliance
Stripe Customer IDStripe, when you subscribeLinking your account to a Stripe customer record
Subscription state (plan, trial end, cancellation date, extra seats/workspaces/accounts)You and StripePlan enforcement, billing
Credit balance and transaction historyGenerated by usCredit-based features

We do not store full payment card numbers, CVV codes, or card expiry data. Stripe holds and processes that information under its own privacy notice.

2.3 Connected Account (Meta) data

When you connect a Facebook Page, Instagram Business profile, or Threads profile via OAuth:

FieldSourcePurpose summary
Platform user ID, Page ID, Instagram Business IDMeta (Graph API)Identifying the Connected Account
OAuth access tokenMetaAuthentication when posting on your behalf
OAuth refresh token (where issued)MetaLong-lived token renewal
Token expiry timestampMetaToken-refresh scheduling
Account name and profile image URLMetaDisplay in dashboard
Login method (Facebook / Instagram / Threads)Determined by youOAuth flow routing

OAuth tokens are stored encrypted at rest and are used only to perform actions you have authorised: publishing content to the Connected Account, refreshing tokens, fetching analytics for content published through the Service, and disconnecting the account on your request.

2.4 User-generated content

FieldSourcePurpose summary
Post text, scheduling timeYouStoring and publishing the post
Uploaded media (images, video)YouHosting in MinIO object storage; publishing to Connected Accounts
Approval workflow events (submit, approve, reject, comments)You and your collaboratorsApproval workflow audit trail
Saved replies and channel groupsYouComposer convenience features

2.5 Analytics data

For posts you publish through the Service, we collect from Meta:

  • Post-level metrics (impressions, engagement counts).
  • Aggregated demographics for the Connected Account audience.

This data is stored in our Elasticsearch index for the retention period described in Section 7.

2.6 Technical and security data

FieldSourcePurpose summary
IP addressBrowser / CloudflareAudit log, abuse prevention, geographic rate-limiting
User agent stringBrowserAudit log, troubleshooting
Correlation ID and request logGenerated by usOperational diagnostics
Rate-limit countersGenerated by usService-level enforcement
Activity log entries (e.g., PostCreated, PostPublished, AccountConnected)Generated by usTenant audit timeline
Audit log entries (entity changes, who changed what, when)Generated by usKVKK Article 11 compliance, internal compliance

2.7 Communications data

FieldSourcePurpose summary
Email messages sent to [email protected] (or other support addresses)YouResponding to and processing your requests
Notification preferences and read/unread stateYou and your activityNotification dispatch
Enterprise inquiry form submissionsYou, through the marketing siteSales follow-up

3. How We Use Your Personal Data and the Legal Basis

We process your personal data for the purposes below. The "legal basis" column refers to Article 6 of the GDPR and UK GDPR.

PurposeCategories of dataLegal basis
Provide the Service (account creation, authentication, content publishing, analytics, notifications)Account, Workspace, Connected Account, User Content, TechnicalPerformance of contract (Art 6(1)(b))
Bill you for paid Subscriptions and credit purchasesAccount, Workspace, Stripe Customer IDPerformance of contract (Art 6(1)(b)); compliance with tax law (Art 6(1)(c))
Send transactional emails (verification, password reset, billing notices, post-status alerts)Account, CommunicationsPerformance of contract (Art 6(1)(b))
Detect, prevent, and respond to abuse, fraud, and security incidentsTechnical, Audit logLegitimate interest (Art 6(1)(f)) — operating a secure service
Comply with legal obligations (tax records, court orders, regulatory inquiries)Workspace, billing, Audit logLegal obligation (Art 6(1)(c))
Improve and develop the Service (aggregate usage analysis)Aggregated and pseudonymisedLegitimate interest (Art 6(1)(f))
Respond to your support requestsCommunications, AccountPerformance of contract (Art 6(1)(b))
Marketing communications (only with your prior consent)Account, emailConsent (Art 6(1)(a))

We do not sell personal data, and we do not use Connected Account data or User Content to train artificial intelligence models that operate outside the Service you signed up for.

4. Who We Share Personal Data With (Sub-Processors)

We share personal data with the third parties listed below, each of whom acts as our processor or as an independent controller for limited purposes.

Sub-processorLocationData sharedPurposeSafeguards
Meta Platforms, Inc. (Facebook, Instagram, Threads)United StatesOAuth credentials, posted content, analytics requestsAuthentication, content publishing, analytics retrievalTheir own Privacy Policy; EU-US Data Privacy Framework where applicable
Stripe, Inc.United StatesBilling details (name, address, tax ID, email, payment card via Stripe Elements)Payment processing, invoice generation, tax calculation (Stripe Tax)Standard Contractual Clauses; Stripe's GDPR programme
Cloudflare, Inc.Global edge (data centres including EU)IP address, request metadataDDoS protection, content delivery, WAFStandard Contractual Clauses; Cloudflare DPA
OVH SAS (infrastructure host)EU data centreAll server-side data (encrypted at rest)Hosting the Service's compute and storageGDPR-compliant hosting agreement; data centre located in the EU

Transactional emails (account verification, password reset, billing notices, post-status alerts) are sent via our own self-hosted mail server (IredMail) running on a private network secured by Tailscale. The server is located in the European Union. No third-party email delivery provider receives recipient addresses or message contents for our transactional mail.

We do not share personal data with any party other than as described above, except:

  • When you direct us to (for example, by connecting an account or sharing a post link).
  • To comply with a binding legal request from a competent authority.
  • In connection with a merger, acquisition, or sale of assets — in which case we will notify affected data subjects in advance where possible.

We do not sell personal data to advertisers, data brokers, or any other third party.

5. International Data Transfers

Our primary infrastructure is hosted in an OVH data centre in the European Union. Some sub-processors (Meta, Stripe, Cloudflare) operate globally. When personal data is transferred outside the United Kingdom or the European Economic Area, we rely on the following safeguards:

  • The European Commission's Standard Contractual Clauses (Module 2 — controller-to-processor) and the UK International Data Transfer Addendum, included in our agreements with sub-processors.
  • The EU-US Data Privacy Framework for transfers to certified US sub-processors, where applicable.
  • For Türkiye-based data subjects, transfers comply with the requirements of KVKK Article 9 (transfers based on explicit consent, an adequacy decision, or other applicable lawful grounds).

You may request a copy of the safeguards by contacting [email protected]. [LEGAL REVIEW: confirm sub-processor agreements actually incorporate the SCCs / UK Addendum.]

6. Cookies and Similar Technologies

We use a minimal set of cookies necessary to operate the Service:

PurposeCategoryExpiry
Authentication session (so you stay signed in across pages)Strictly necessary~15 minutes (sliding renewal)
Long-lived session refresh (so you don't have to sign in repeatedly)Strictly necessary30 days
Cross-site request forgery (CSRF) protectionStrictly necessarySession
Language preference (tr/en)Functional1 year

All authentication-related cookies are set with the HttpOnly, Secure, and SameSite=Lax flags so they cannot be read by JavaScript, only travel over HTTPS, and are not sent on cross-site requests.

We currently do not use third-party analytics cookies (Google Analytics, Facebook Pixel, etc.). If we add such cookies in future we will deploy a consent banner and obtain your consent before setting them, in line with applicable ePrivacy law and KVKK guidance on online tracking.

You can disable cookies in your browser settings, but the Service will not work without the strictly-necessary cookies above.

7. How Long We Keep Your Personal Data

We retain personal data only for as long as necessary for the purposes for which it was collected, subject to applicable retention requirements.

CategoryRetention period
Account data (email, name, locale, timezone)For as long as the Account is active, plus 30 days after account closure. Backups containing this data are rotated out within 60 days.
Password hash and 2FA secretsFor as long as the Account is active. Permanently deleted on Account closure.
Workspace and billing data10 years after the end of the Subscription, to comply with UK and Turkish tax/accounting record-keeping obligations.
OAuth tokens for Connected AccountsUntil you disconnect the account or your Account is closed. Tokens are revoked promptly on disconnection.
User Content (posts, media)For as long as you keep them in the Service. Deleted within 30 days of deletion from the dashboard.
Analytics data24 months from collection (subject to your plan's analytics retention; lower tiers have shorter retention as described on the pricing page).
Activity log and audit log2 years from creation, subject to longer retention where required by law (e.g., security incident investigation).
Email communications with support3 years from the last message, then deleted unless required for a legal claim.
Backup snapshotsRotated out within 60 days.

When the retention period expires, we delete or irreversibly anonymise the data.

8. Your Rights

Under the UK GDPR, EU GDPR, and Turkish Personal Data Protection Law No. 6698 (KVKK), you have the following rights regarding your personal data:

  • Right of access — request a copy of the personal data we hold about you.
  • Right of rectification — request correction of inaccurate or incomplete data.
  • Right of erasure ("right to be forgotten") — request deletion of your personal data where the legal grounds for processing have ended.
  • Right of restriction — ask us to limit how we process your data while a complaint is investigated or in other limited circumstances.
  • Right of data portability — receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller, where technically feasible.
  • Right to object — object to processing based on our legitimate interests, including profiling.
  • Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting processing carried out before withdrawal.
  • Right to lodge a complaint — with a supervisory authority. For data subjects in the UK: the Information Commissioner's Office (ICO). For data subjects in the EU: your local data-protection authority. For data subjects in Türkiye: the Kişisel Verileri Koruma Kurumu (KVKK Kurumu) — see also our KVKK Aydınlatma Metni.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days, or sooner where required by law (KVKK requires response within 30 days; UK GDPR within one month).

You can also exercise some rights directly through the Service:

  • View and update your profile data in Settings → Profile.
  • Download an export of your Workspace data via Settings → Export (subject to plan).
  • Close your Account from Settings → Account → Close Account, which triggers deletion within 30 days.

If we cannot identify you with the information you provide, we may ask you for additional information to verify your identity before acting on a request.

9. Security

We protect personal data through technical and organisational measures, including:

  • In-transit encryption (TLS 1.2+) for all browser and API traffic.
  • At-rest encryption for OAuth tokens, 2FA secrets, and database backups.
  • Role-based access control for internal access to production systems, with the principle of least privilege.
  • Audit logging of administrative and data-access events.
  • Rate-limiting to mitigate brute-force and abusive traffic.
  • Two-factor authentication for user accounts (optional) and for staff accounts.
  • HashiCorp Vault for secret storage, with environment-segregated paths.
  • Regular dependency updates and automated security scanning in our CI pipeline.
  • Incident response procedures for personal data breaches.

No system can be guaranteed completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 48 hours of becoming aware of the breach, and affected data subjects without undue delay, in accordance with GDPR Article 33-34 and KVKK Article 12.

10. Children

The Service is not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected personal data from a child under 16, contact [email protected] and we will delete it without undue delay.

11. Automated Decision-Making and Profiling

We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing. We do not engage in profiling for advertising or marketing purposes.

Rate-limiting decisions (e.g., temporarily slowing requests from an IP showing abusive behaviour) are automated but do not produce legal effects and are reversible on appeal.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to you by email or by an in-Service notice at least 30 days before they take effect. Non-material changes (clarifications or typo fixes) may take effect immediately.

The current version of the Policy is always available at https://postid.app/legal/privacy.

13. Contact

For questions about this Privacy Policy, to exercise your data-subject rights, or for any data protection matter:

  • Data Protection Officer: Postid Privacy Team
  • DPO Email: [email protected]
  • General contact: [email protected]
  • Postal address: Codian Limited, Suite 8791, 5 Brayford Square, London, United Kingdom, E1 0SG
  • Company Number: 16333262

For data-subject rights requests under GDPR / UK GDPR / KVKK, please email the DPO at [email protected]. The DPO oversees compliance with applicable data protection law and is the primary contact for supervisory authorities (the ICO, EU DPAs, and the KVK Kurumu) where applicable.