Cloudorax UG (haftungsbeschränkt)
PrivacyTerms of ServiceData Deletion

Privacy Policy

Effective date: 2026-06-21 · Data controller: Cloudorax UG (haftungsbeschränkt), (HRB 286107 B, Amtsgericht Charlottenburg), Rosenthaler Straße 72A, 10119 Berlin, Germany

This Privacy Policy explains how Cloudorax UG (haftungsbeschränkt) ("we", "Einposty") collects, uses, stores and protects your personal data when you use our social media management and content-creation service (the "Service"), in accordance with the EU General Data Protection Regulation (GDPR) and Turkey's Personal Data Protection Law (KVKK No. 6698).

Cloudorax UG (haftungsbeschränkt) is a multi-tenant SaaS platform: each business or organization connects its own social accounts and can access only its own data. For messages and comments received by the accounts you connect (e.g. the Facebook, Instagram and WhatsApp inbox), Cloudorax UG (haftungsbeschränkt) acts as a data processor on your (the business's) behalf and instruction; the connecting business is the controller of those communications.

1. Categories of data we process

  • Account data: name, email address, hashed password, language/timezone preferences.
  • Connected social-account data: OAuth access/refresh tokens, page/channel identifiers and basic profile info needed to publish, obtained from the platforms you connect (Facebook, Instagram, X, LinkedIn, TikTok, YouTube, Pinterest, etc.). Tokens are stored encrypted and used only for actions you initiate.
  • Inbox and messaging data: direct messages (DMs), comments and conversations received by the accounts you connect, together with basic profile info of the people who initiate that contact (name, username, platform id). This is processed solely so you can view and reply to messages in the unified inbox. Data obtained from Meta platforms (Facebook, Instagram, WhatsApp) is used in compliance with the Meta Platform Terms, is never sold to third parties, and is not used for advertising.
  • Content data: posts, images, videos, drafts you create/upload and their publishing schedule.
  • Usage and log data: IP address, browser/device info, action timestamps, error logs — for security and diagnostics.
  • Payment data: billing identity details; card data is never stored by us and is handled by a PCI-DSS compliant payment processor.

2. Purposes and legal bases

  • Performance of a contract (GDPR Art. 6(1)(b)): operating your account, publishing your posts to connected platforms, running scheduled posts.
  • Legitimate interests (GDPR Art. 6(1)(f)): service security, abuse/spam prevention, diagnostics, product improvement.
  • Consent (GDPR Art. 6(1)(a)): optional marketing communications and non-essential analytics cookies.
  • Legal obligation (GDPR Art. 6(1)(c)): tax/invoicing and statutory retention duties.

3. Sharing and international transfers

We share data only with the sub-processors needed to deliver the Service (cloud hosting, email delivery, payments, error monitoring and the social/media providers you connect). Transfers to connected social accounts are limited to your own instructions (the content you publish). Where a sub-processor is located outside your jurisdiction, transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses) under GDPR Chapter V and KVKK Art. 9.

4. Retention

We retain your data while your account is active and afterwards for statutory retention periods. When you delete your account, your content and connected-account tokens are permanently deleted or irreversibly anonymised after a 14-day grace period. Records required by law (e.g. invoices) are kept for the applicable statutory period.

5. Your data-subject rights

Under GDPR Art. 15–22 and KVKK Art. 11 you may request access to and a portable machine-readable copy (export) of your data, rectification of inaccurate data, erasure ("right to be forgotten"), restriction of and objection to processing, and withdraw consent at any time.

Self-service data rights: export a copy of your data or request account deletion with one click.

Use Settings → Privacy after signing in, or email kvkk@einposty.com.

You also have the right to lodge a complaint with a data protection supervisory authority — for us that is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), or the authority of your own place of residence.

6. Security and abuse prevention

We protect data with TLS in transit, encryption of OAuth tokens at rest, tenant isolation and role-based access. To protect the Service against abuse we apply rate limiting and suspicious-activity detection to login, registration, password reset, email verification and data-export actions. See the Terms of Service for the full acceptable-use rules.

7. Cookies

We use strictly necessary cookies for session management and security (CSRF); these work without consent. Non-essential analytics cookies are enabled only with your explicit consent.

8. Changes and contact

We notify material changes by updating the effective date and, where appropriate, by email. For data-subject requests and questions: kvkk@einposty.com (general support: destek@einposty.com).

Questions: destek@einposty.com

Terms of Service · Data Deletion · Cloudorax UG (haftungsbeschränkt)