For consumers in Romania the Romanian version prevails.Versiunea in limba romana

Privacy Policy

This policy explains what personal data TRIIVON S.R.L. processes when you use GPTpostLLM, why, on what legal basis, who else sees it, how long we keep it and what you can require of us.

It is written under the GDPR (Regulation (EU) 2016/679) and Legea nr. 190/2018, the Romanian implementing law.

Controller: TRIIVON S.R.L., Limited liability company (societate cu răspundere limitată), registered office Bucharest, Sector 4, Sos. Giurgiului nr. 131, Bloc 1, Scara 2, Etaj 9, Apartament 65, postal code 040665, Romania, 53596703, registered at the Trade Register Office attached to the Bucharest Tribunal under J2026006019000. Contact: contact@oraglegpt.org and +40 753 980 299.

We have not appointed a Data Protection Officer. Legea nr. 190/2018 and Article 37 GDPR do not require one for an organisation of this size and activity, which does not carry out large-scale systematic monitoring or process special categories of data on a large scale. Data protection questions go to contact@oraglegpt.org and are handled by the company.


1. Read this first: whose data, and who is responsible

There are two different relationships and they have different answers. Getting this wrong is the usual reason a request goes to the wrong place.

We are the CONTROLLER for data about you as our customer: your account, your sign-in and security records, your correspondence with us, and our invoicing and accounting records. This policy governs that data.

We are the PROCESSOR for the content you put into the Service and any personal data inside it, including the audience data of the posts you publish. There, you are the controller, you decide what goes in, and we act on your instructions. The Article 28 terms are in Data Processing Addendum.

If you are an end user of somebody else's workspace, for example an employee of a company that uses GPTpostLLM, then that company is the controller of your data in it. Ask them first. If you come to us, we will tell you who the workspace belongs to and refer your request to them, and we will help them answer it.


2. What we collect

2.1 Data you give us

DataWhy
Email address and nameTo create and identify your account, and to correspond
PasswordTo authenticate you. Stored only as a PBKDF2-HMAC-SHA256 hash with 210,000 iterations and a random salt, never in plain text
Multi-factor secret, if you enable itTo verify time-based one-time codes
Workspace and organisation detailsTo set up your tenant
Your content: posts, captions, media, schedules, campaignsTo provide the Service
Correspondence you send to contact@oraglegpt.orgTo answer you and keep a record of what was agreed
Billing details you give us for an invoiceTo issue a lawful invoice. We collect no card or bank instrument, because the Service has no payment processing at all

2.2 Data we get when you connect a social account

When you connect an account we store the access credential for it and the identifiers needed to publish, such as the page or channel ID and the account name shown in the interface.

We request the narrowest scopes that will publish. We do not request, hold or use permissions to read your comments, mentions, messages or insights, because the connectors are publish-only and no code exists that would use such a permission.

Stored social credentials are encrypted at rest with AES-256-GCM and are never included in a data export.

2.3 Data generated by your use

DataWhy
Publication log: what was published, where, when, and the resultSo you and we can tell what happened, and resolve disputes
Audit log: which actor changed which recordIntegrity and accountability. Hash-chained and append-only
Security events: sign-ins, failures, suspicious activityTo detect and investigate abuse
Session recordsTo keep you signed in and to let you revoke sessions
Technical request data, including IP address and user agentSecurity, rate limiting and diagnosing faults

2.4 Analytics, which you supply and we do not gather

We fetch no analytics from any platform. The only route by which analytics data enters the Service is your own authenticated call to POST /api/v1/analytics/observations. The software actively refuses a collection_method of provider_api, webhook, scrape or crawl.

So any figures you see are figures you sent us. We did not collect them from Meta, TikTok or anyone else, and we cannot.

2.5 What we deliberately do not collect


PurposeLegal basis
Providing the Service under our agreement with youArt. 6(1)(b), performance of a contract
Authenticating you and keeping accounts secureArt. 6(1)(b) and Art. 6(1)(f), our legitimate interest in a secure service
Publishing to the accounts you connectedArt. 6(1)(b), and your authorisation at the platform
Security logging, abuse detection, rate limitingArt. 6(1)(f), legitimate interest in protecting the Service and its users
Keeping the audit logArt. 6(1)(f), and Art. 6(1)(c) where accountability under Art. 5(2) requires it
Invoicing and accounting recordsArt. 6(1)(c), a legal obligation under Romanian accounting and tax law
Answering your correspondenceArt. 6(1)(b) or Art. 6(1)(f)
Marketing messages, if anyArt. 6(1)(a), consent, which you may withdraw at any time. Required also by Legea nr. 365/2002 art. 6
Non-essential cookiesConsent, under Legea nr. 506/2004 art. 4 alin. (5). We set none. See Cookie and Local Storage Policy

Where we rely on legitimate interests we have considered your rights and interests and concluded they do not override ours for the narrow purposes above. You may object under Article 21, and we will tell you the outcome and why.


4. Who else sees your data

Our infrastructure vendor list is genuinely short. The full table, with locations and roles, is in Subprocessors.

Destination social platforms are not our subprocessors. When you publish to Facebook, TikTok or anywhere else, you are sending your content to an independent controller that decides for itself what it does with it, under its own privacy policy. We transmit what you told us to transmit.

We also disclose data where the law requires it, to establish or defend legal claims, and to a successor if the business is transferred, in which case we would tell you first.

We do not sell personal data, and we do not share it for advertising.


5. International transfers

Hosting involves no international transfer. The application, database, object storage, media processing and the mailbox are all on our own servers within the European Union, so Chapter V of the GDPR is not engaged for any of them.

One transfer does arise, and we would rather name it than bury it. Cloudflare sits in front of this site as a reverse proxy, and Cloudflare is established in the United States. Traffic to https://gptpostllm.oraglegpt.org therefore passes through a vendor outside the EEA, even though the edge serving European visitors is itself in Europe. The mechanism relied on is Cloudflare's published data processing addendum incorporating the EU Standard Contractual Clauses. The outstanding administrative point on that addendum is disclosed in section 3 of Subprocessors.

A transfer outside the EEA only arises if you choose it, by connecting a social platform outside the EEA, or by enabling an optional integration or an AI provider with your own credentials. That is your decision as controller. Where you need Standard Contractual Clauses for such a transfer, ask at contact@oraglegpt.org.


6. How long we keep it

DataRetention
Account and workspace dataWhile your account is open, then per Data Deletion Policy
Publication log24 months
Analytics observations you submitted25 months
AI run records, if an AI provider was enabled12 months
Security events12 months
Sessions24 hours
CorrespondenceWhile needed to handle the matter, and for any limitation period
Invoices and accounting recordsAs required by Romanian accounting and tax law
Audit logRetained, append-only, minimised on erasure so the chain survives

Deletion routes, the 30-day windows and the exact mechanics are in Data Deletion Policy.


7. How your data is protected

Full detail, and a frank list of the limitations, is in Security. In summary:


8. Our commitments to the social platforms and to you

These are the commitments platform reviewers ask about, and they are commitments to you as well.


9. Your rights

You have the rights in Articles 15 to 22: access, rectification, erasure, restriction, portability, objection, and not to be subject to solely automated decisions with legal or similarly significant effects. We take no such automated decisions.

How to exercise them, what to include, how we verify identity, our timescales and the complaint route to Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) are set out in Your Data Protection Rights.

In short: write to contact@oraglegpt.org. We answer within one month, extendable by two further months for genuinely complex requests under Article 12(3), and we charge nothing unless a request is manifestly unfounded or excessive.

You may complain to Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), https://www.dataprotection.ro, B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, cod poștal 010336, București, România, anspdcp@dataprotection.ro, and you have the right to a judicial remedy.


10. Children

The Service is not intended for children. You must be at least 16, or the age of digital consent where you live if that is higher. If we learn that we hold data about a child below that age we delete it. Tell us at contact@oraglegpt.org.


11. Cookies

We set one strictly necessary session cookie and no advertising or analytics cookies. The detail, and the position under Legea nr. 506/2004 art. 4 alin. (5) and alin. (6), is in Cookie and Local Storage Policy.


12. Changes

We may update this policy. The version in force is the one published here with its date. For a material change we publish the new version and, where we hold a means of contacting you, give reasonable notice. Superseded versions are available on request at contact@oraglegpt.org.


PageWhat it covers
Your Data Protection RightsExercising your rights, step by step
Data Deletion PolicyDeletion routes and exact timings
Data Processing AddendumThe Article 28 processor terms
SubprocessorsEvery vendor, and the categories we have not engaged
SecurityProtection measures and known limitations
Cookie and Local Storage PolicyCookies and local storage
Company IdentificationFull company identification data