Privacy policy
This policy describes what OxChannels does with personal data, including data received from the social platforms you connect. It describes how the service behaves today, not how we intend it to behave.
Who we are
OxChannels is a social publishing and automation service operated by CodeFormers. This policy explains what personal data the service processes, why, on what legal basis, and how long it is kept.
For data you place in the service as a customer, you are the controller and OxChannels acts as your processor. For account, billing and service-security data, OxChannels is the controller.
What data we process
- Account data
- Email address, display name, password hash, and the workspaces you belong to. Used to authenticate you and to decide what you may see and do.
- Connection data
- The social accounts and pages you connect, their provider identifiers, display names, and the health of each authorization. Used to publish on your behalf and to tell you when a connection needs attention.
- Provider credentials
- Access and refresh tokens issued by the platforms you connect. Held encrypted in a credential vault on the server. They are never sent to your browser and never shown in the interface.
- Content you publish
- Posts, media, schedules and their delivery results. Retained so the service can show what was published, when, where, and with what outcome.
- Engagement and analytics
- Aggregate counts and, where a platform exposes them, comments and reactions on your own posts. Used to produce the analytics you see in the product.
- Operational records
- An audit log of who changed what and when, plus technical logs, error traces and request identifiers. Used for security, billing accuracy and incident investigation.
Data from connected platforms
When you connect an account, the platform asks you to approve a specific list of permissions. The consent screen shown by the platform is authoritative: OxChannels can only receive what you approve there, and only for as long as the grant remains valid.
The authorization code returned by the platform is exchanged for a token by our server, not by your browser. The browser is told only that a connection succeeded and which account it belongs to.
Data received from a platform is used to operate the features you asked for. It is not sold, not used to build advertising profiles, and not used to train machine learning models.
Revoking access at the platform, or revoking the connection inside OxChannels, stops further collection. Data already received is deleted according to the retention rules below.
Why we are allowed to process it
- Contract
- Account, connection and publishing data are processed because they are necessary to provide the service you signed up for.
- Consent
- Access to each connected platform rests on the consent you give on that platform, which you can withdraw at any time.
- Legitimate interest
- Security logging, abuse prevention and service diagnostics, balanced against your interests and limited to what those purposes require.
- Legal obligation
- Billing records kept for the period tax law requires.
How long we keep it
- Provider tokens
- Deleted when a connection is revoked or when the platform invalidates the grant.
- Published content and delivery results
- Kept while the workspace exists, so the record of what was published stays accurate.
- Audit log
- Kept for the retention period configured for your workspace, because an audit record you can shorten at will is not an audit record.
- Technical logs
- Kept for a short operational window and then discarded.
- Account data
- Deleted within 30 days of account closure, except records that billing or tax law requires us to keep.
How it is protected
- Encryption in transit
- All traffic runs over TLS.
- Encrypted credentials
- Provider tokens are encrypted with a managed key and are readable only by the backend service that needs them.
- Least exposure in the browser
- The panel never receives provider tokens, so a compromised browser session cannot leak them.
- Workspace isolation
- Every read and every change is scoped to a workspace and checked against your role in it.
- Change records
- Actions that alter a connection, a publication or a permission are written to the audit log.
The local agent
OxChannels offers an optional agent that runs on your own machine. Data it holds locally stays on that machine unless you explicitly send it to the service. Using the agent is not required to use OxChannels, and declining it does not reduce the rest of the product.
Your rights
Under the GDPR you may request access to your personal data, correction, deletion, restriction of processing, portability, and you may object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it without affecting what was lawful before.
Write to the address below and we will respond within one month. You also have the right to complain to a supervisory authority; in Poland that is the President of the Personal Data Protection Office (UODO).
International transfers
Service infrastructure is operated in the European Union. Some connected platforms and processors operate outside the EEA; where data reaches them, the transfer relies on the European Commission standard contractual clauses or an adequacy decision.
Children
OxChannels is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will remove it.
Changes to this policy
When this policy changes, the date at the top of the page changes with it. Changes that materially affect how we handle your data are announced in the product before they take effect.
Contact
Questions about this policy, or a request to exercise your rights:[email protected].