ChannelCockpit is intended for users in Germany. This translation helps you understand the German original. German original
Version:
Controller and privacy contact
Amed Bozo · ChannelCockpitMoritzstraße 43
65185 Wiesbaden
Germany
support@channelcockpit.app
+491773878629
Amed Bozo, trading as ChannelCockpit, is the controller for the processing carried out for our own purposes described here. Contact the operator directly at support@channelcockpit.app for privacy matters.
This policy covers the website, app, subscription and support. Where we manage content and data on a customer’s instructions, that customer determines the purposes and we assist as a processor under our Data Processing Addendum. Social platforms and payment providers also process certain data for their own purposes.
Data we receive
- Account: email address, internal user ID, optional display name, sign-in and security information, preferences, and the time and version of contract and adult declarations actually made.
- Connections: platform and account IDs, profile name and image, granted permissions, encrypted credentials and connection status. These come through the connection you authorise with the platform; you do not enter the platform password into ChannelCockpit.
- Analytics: available profile, post and video metrics, timestamps, titles, public display information and stored changes over time.
- Publishing: uploaded images and videos, drafts, text, format settings, target accounts, scheduled times and delivery or error status.
- Engagement: supported comments, replies and messages, including text, platform IDs, sender display details, timestamps and necessary conversation or attachment metadata. Meta message attachment files are not copied into a separate message archive.
- Payment: customer and subscription references, plan, payment and cancellation status, billing periods, usage and limited records preventing repeated trials. Stripe/Link collects payment and invoice details. We include the necessary customer name, billing address, amounts and contract dates in protected contract records when needed for required confirmations. We do not store full card numbers.
- Contact and operation: your message, contact address, contract reference and, where relevant, name; request and acknowledgement records; and technical connection, security and error data such as IP address, browser details and timestamps.
Content can include information about other people, such as commenters, conversation participants or people shown in media. Customers must only entrust data to us for lawful processing. The service is not designed for deliberate processing of particularly sensitive data such as health information. Do not include it in support requests unless necessary.
Purposes and legal bases
- Account and contract: sign-in, subscription, requested platform features, contract support and termination are processed as necessary to perform the contract or take steps at your request before it (GDPR Article 6(1)(b)).
- Security and reliable operation: abuse prevention, troubleshooting, limited technical logs and protection against repeated trials serve our legitimate interests in a secure, affordable and functioning service (Article 6(1)(f)). We limit content, access and retention to each purpose.
- Legal obligations: tax and accounting records, required consumer confirmations, privacy requests and binding official demands are processed to comply with law (Article 6(1)(c)). Establishing or defending legal claims may also rely on Article 6(1)(f).
- Voluntary consent: where consent is required, we obtain it separately (Article 6(1)(a)). A platform authorisation controls technical access; it does not automatically replace every required privacy-law basis.
- Customer-directed data: the customer determines the legal basis for their content processing. We process that data only to provide the agreed service and follow documented instructions.
Necessary account, contact and payment details are needed for the relevant service; without them we may be unable to provide it. Optional information remains optional. We do not make solely automated decisions with legal or similarly significant effects under GDPR Article 22. You can ask us to review a technical security or allowance restriction.
Website, browser storage and abuse protection
Technical connection data is processed to deliver and protect the website. The site stores display and language preferences locally in your browser. The app uses local preferences and the Firebase session data needed to keep you signed in. You can clear local data or sign out; doing so may remove preferences and your session.
Protected app requests use Firebase App Check and Google reCAPTCHA. Google receives technical device, browser and request information to detect abuse. Some profile and preview images may load directly from platform CDNs, which receive connection data. We do not use advertising trackers or create advertising profiles. Storage or access strictly necessary for the service you request relies on the applicable essential-service exception, including Section 25(2) TDDDG in Germany; this policy does not replace any further consent that is required.
When used, third-party services such as Google and directly loaded platform CDNs receive connection data and may associate it with other information under their own privacy notices. We do not enable our own cross-site advertising analytics. Those providers’ independent processing is governed by their terms and your settings with them; our lack of advertising trackers does not mean that no third party can associate activity across services.
Connected platforms
You choose the platforms and grant permissions there. We use the available data needed for the relevant feature. Publications, replies and messages are sent to the selected platform following your approval. Platform operators process data under their own terms and privacy notices:
- Google/YouTube: Google Privacy Policy and YouTube Terms of Service.
- TikTok: TikTok Privacy Policy.
- Instagram/Facebook: Meta Privacy Policy.
Google user data is used only for the app features you expect and authorise. We do not sell it or use it for advertising or AI model training. Transfers are limited to what is permitted for those features, your instructions, security or legal obligations. Human access occurs only where necessary and permitted, for example with your permission for a specific support case. Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect platforms in the app and revoke authorisations with the provider. See Data deletion for details.
Service providers and other recipients
We use the following providers for operation and communication. They receive only data needed for their role; where acting on our behalf, they are covered by data processing terms.
| Provider | Purpose | Processing locations | Privacy documents |
|---|---|---|---|
| Google Cloud EMEA Limited (Irland / Ireland); Google LLC (USA) | Google Cloud and Firebase: hosting, sign-in, database, server functions, export files, logging and abuse protection. Google Workspace: support mailbox and communication. | App database in Germany. Individual services, particularly Firebase Authentication, process data in the US; international support and subprocessor access are possible. | Cloud / Workspace DPA · Firebase DPA · Cloud subprocessors · Workspace subprocessors |
| Cloudflare, Inc. (USA) | Private media in R2, controlled media delivery, protection and forwarding of incoming support email through Email Routing. | R2 media in the EU jurisdiction; global network, security, email and support processing, including the US. | DPA · Subprocessors |
| Plus Five Five, Inc. (Resend, USA) | Delivery of contact enquiries and transactional acknowledgements. This contact route does not send newsletters. | Email delivery and processing of service, log and delivery data, including in the US. | DPA · Subprocessors |
Stripe and Sold through Link process payment, invoicing, fraud-prevention and, where relevant, tax data for their respective roles. They act independently for certain obligations and are not blanket subprocessors for all app content. See the Stripe Privacy Policy and Link Privacy Policy.
Recipients may also include social platforms you connect, necessary legal or tax advisers and competent authorities where a legal basis exists. We do not sell personal data or share it for third-party behavioural advertising.
International processing
The app database is in Germany and private R2 media uses the EU jurisdiction. This does not mean every item of data stays exclusively in the EU. Authentication, global networks, support, email and certain provider logs may involve the US and other countries.
Transfers from the EEA to another country require an applicable adequacy decision or appropriate safeguards, in particular EU Standard Contractual Clauses and any necessary supplementary measures. The EU-US Data Privacy Framework can only be used for a certified recipient and a transfer covered by that certification. The linked provider terms explain their transfer safeguards. You can request information and a copy of relevant safeguards from us, subject to protection of confidential business and third-party information. Lawful government access in the recipient country cannot be completely excluded despite safeguards.
Retention periods
We retain personal data only as long as needed for its purpose or required by law. The following periods and criteria apply:
- Account details, connections, drafts and private media are generally retained for active use; deletion or disconnection starts the relevant cleanup. Security and evidential records may be retained separately.
- TikTok history and related stored observations are retained for up to 90 days. A valid request requiring earlier deletion is not postponed until that period ends.
- Cached Meta message content is retained for up to 30 days, with only a limited excerpt per conversation. Comments are retained only as needed for the selected feature and connection.
- Temporary exports are short-lived: download links last two minutes and export files are scheduled for removal after ten minutes. Background cleanup and backup deletion can occur later.
- Technical Meta webhook intermediates have a 24-hour retention period; stripped completion status has a shorter period. Meta deletion-request receipts may remain for up to 90 days.
- Technical billing events are retained for up to 30 days. Limited pseudonymous records preventing repeated free trials may remain for up to 365 days.
- Contact-form retry and rate-limit states are short-lived, normally about 24 to 25 hours. Their technical storage does not contain the actual message body. Email and necessary case records in the mailbox have their own purpose and are removed after resolution unless a duty or specific evidential need requires retention.
- Tax-required invoices and accounting vouchers are generally retained for eight years; applicable business correspondence for six years and certain books and financial statements for ten years, under the statutory calculation rules. Not every support email falls into these categories.
- Necessary contract and rights records remain for applicable limitation or evidential periods, normally through the end of the third year after the relevant year ends; a specific dispute may require longer retention. Longer applicable statutory recordkeeping duties take precedence.
Deletion does not mean every backup held by every provider immediately disappears physically. Remaining copies are access-restricted, subject to the relevant deletion cycle and not used for new product purposes. Payment providers may have independent legal retention obligations.
Your rights
Subject to applicable conditions, you can request access, correction, deletion, restriction and portability. You may withdraw consent at any time for the future. You can object to processing based on legitimate interests for reasons relating to your particular situation, and to direct marketing at any time without giving a reason.
Contact support@channelcockpit.app. We handle your request without undue delay, normally within one month. If the complexity or number of requests requires an extension of up to two further months, we explain the reasons within the first month. We request only information needed to identify the data and verify your identity. Exercising your privacy rights is generally free. Exceptions apply only where legally permitted.
You can complain to a data protection supervisory authority, in particular where you live, work or believe an infringement occurred. The authority for our establishment is the Hessian Commissioner for Data Protection and Freedom of Information. See Data deletion for practical steps.