Privacy Policy — Postiz Application

Privacy Policy — Postiz Application

Effective date: 12 August 2026

This Privacy Policy explains how Postiz (the „Application”), operated by
Centrale Telefoniczne Paweł Matyja, ul. Warszawska 236/5, 43-155 Bieruń,
Poland, NIP 6462629132, REGON 240498089 (the „Operator”), collects, uses, shares, and
protects user data when a user connects their Facebook, Instagram, or other supported
social media accounts to the Application.

The Application is a social media management platform that allows users to connect
their own social media accounts, prepare and preview content, choose publication
settings, publish immediately or schedule publication, and review publication status
and analytics. Content is published only after an explicit action by the user.

1. Data Controller and Contact

The data controller is Centrale Telefoniczne Paweł Matyja. Privacy and data-deletion
requests may be sent to biuro@e-prolab.eu.

2. Data We Collect From Facebook and Instagram

When a user connects their Facebook or Instagram account to Postiz, we may collect and
process the following data from the user’s profile, subject to the permissions granted by
that user:

  • Basic profile information: name, username, and profile picture
  • Email address: the primary email address associated with the user’s Facebook account
  • Facebook User ID: the unique identifier assigned by Facebook to the user
  • Page information: the list of Facebook Pages the user manages, Page name, Page category, and Page metadata
  • Access tokens: OAuth access tokens required to maintain the authorized connection and perform actions on behalf of the user
  • Content and posts: posts, images, videos, captions, and publication settings created or selected by the user through the Application
  • Engagement metrics: likes, comments, shares, reach, impressions, and other analytics data for published content
  • Page engagement data: comments and messages received on the user’s connected Pages, when the user uses the Application’s inbox or engagement features
  • Technical logs: error information, publication status, and API call metadata needed for troubleshooting and security

3. Facebook Permissions Used

The Application requests the following Facebook permissions, each used only for the
purpose described:

  • pages_manage_posts — to create, edit, and delete posts on the user’s Pages
  • pages_manage_engagement — to create, edit, and delete comments on the user’s Pages
  • pages_read_engagement — to read posts, comments, and engagement on the user’s Pages
  • pages_read_user_content — to read user-generated content on the user’s Pages
  • pages_show_list — to display the list of Pages the user manages
  • pages_manage_metadata — to subscribe to and receive webhooks about Page activity
  • business_management — to access Business Manager API for managing business assets
  • public_profile — to read the default public profile fields
  • email — to read the user’s primary email address
  • read_insights — to read Insights data for the user’s Pages

4. How We Use Your Data

We use the data collected from Facebook and Instagram for the following purposes:

  • To authenticate the user and maintain the authorized connection to their social media accounts
  • To display the user’s connected accounts, Pages, and profile information within the Application
  • To publish and schedule posts, images, and videos on the user’s connected Pages and accounts
  • To retrieve and display analytics and performance metrics for the user’s published content
  • To manage comments, messages, and engagement on the user’s Pages from a single interface
  • To display publication results, investigate errors, prevent abuse, and ensure security

5. Legal Basis (GDPR)

The legal basis for processing user data is the user’s voluntary consent under Article
6(1)(a) of the General Data Protection Regulation (GDPR), given at the time the user
connects their Facebook account to Postiz. Users may withdraw consent at any time by
disconnecting their account.

6. Data Sharing and Third Parties

We do not sell, rent, or share user data with third parties for advertising purposes.
Data may be shared only:

  • With processing entities acting on behalf of the Operator (hosting providers, cloud infrastructure providers) under data processing agreements
  • When required by law, regulation, or legal process (upon request from public authorities)
  • To protect the rights, property, or safety of the Operator, users, or others

Facebook and Instagram receive data as part of the API calls made on behalf of the user.
Meta’s data practices are governed by Meta’s own policies and terms.

7. Data Retention

User data and access tokens are retained for as long as the user uses the Application.
When a user disconnects their Facebook or Instagram account:

  • Access tokens are immediately revoked
  • Personal data is deleted from our systems within 30 days
  • Anonymized, aggregated analytics data that cannot identify the user may be retained

8. Data Deletion

Users can request deletion of their data at any time. For detailed instructions, please
visit our Data Deletion Instructions page.

9. Your Rights Under GDPR

You have the right to:

  • Access your personal data
  • Rectify inaccurate or incomplete data
  • Erasure of your data („right to be forgotten”)
  • Restriction of processing
  • Withdraw consent at any time without affecting the lawfulness of processing before withdrawal
  • Data portability
  • Object to processing
  • Lodge a complaint with a supervisory authority (in Poland: Urząd Ochrony Danych Osobowych, uodo.gov.pl)

10. Security

We implement appropriate technical and organizational measures to protect user data
against unauthorized access, loss, alteration, or disclosure. All communication with
Facebook and other social platforms is encrypted using HTTPS/TLS. Access tokens are
stored securely and are never exposed in client-side code.

11. Children’s Privacy

The Application is not directed to children under 13. We do not knowingly collect data
from children. If we become aware that a child has provided data, we will delete it.

12. International Data Transfers

User data may be processed in the European Union and may be transferred to Meta
platforms located outside the EU. Such transfers are made in accordance with applicable
data protection laws, including Standard Contractual Clauses.

13. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to the Application’s functionality
or legal requirements. We will notify users of significant changes through the
Application or via email. The „Effective date” at the top indicates when the policy was
last updated.

14. Contact

For questions regarding this Privacy Policy or personal data, please contact:
Centrale Telefoniczne Paweł Matyja
ul. Warszawska 236/5, 43-155 Bieruń, Poland
NIP 6462629132, REGON 240498089
E-mail: biuro@e-prolab.eu

Koszyk