Privacy Policy
This policy explains what personal data TRIIVON S.R.L. processes when you use GPTpostLLM, why, on what legal basis, who else sees it, how long we keep it and what you can require of us.
It is written under the GDPR (Regulation (EU) 2016/679) and Legea nr. 190/2018, the Romanian implementing law.
Controller: TRIIVON S.R.L., Limited liability company (societate cu răspundere limitată), registered office Bucharest, Sector 4, Sos. Giurgiului nr. 131, Bloc 1, Scara 2, Etaj 9, Apartament 65, postal code 040665, Romania, 53596703, registered at the Trade Register Office attached to the Bucharest Tribunal under J2026006019000. Contact: contact@oraglegpt.org and +40 753 980 299.
We have not appointed a Data Protection Officer. Legea nr. 190/2018 and Article 37 GDPR do not require one for an organisation of this size and activity, which does not carry out large-scale systematic monitoring or process special categories of data on a large scale. Data protection questions go to contact@oraglegpt.org and are handled by the company.
1. Read this first: whose data, and who is responsible
There are two different relationships and they have different answers. Getting this wrong is the usual reason a request goes to the wrong place.
We are the CONTROLLER for data about you as our customer: your account, your sign-in and security records, your correspondence with us, and our invoicing and accounting records. This policy governs that data.
We are the PROCESSOR for the content you put into the Service and any personal data inside it, including the audience data of the posts you publish. There, you are the controller, you decide what goes in, and we act on your instructions. The Article 28 terms are in Data Processing Addendum.
If you are an end user of somebody else's workspace, for example an employee of a company that uses GPTpostLLM, then that company is the controller of your data in it. Ask them first. If you come to us, we will tell you who the workspace belongs to and refer your request to them, and we will help them answer it.
2. What we collect
2.1 Data you give us
| Data | Why |
|---|---|
| Email address and name | To create and identify your account, and to correspond |
| Password | To authenticate you. Stored only as a PBKDF2-HMAC-SHA256 hash with 210,000 iterations and a random salt, never in plain text |
| Multi-factor secret, if you enable it | To verify time-based one-time codes |
| Workspace and organisation details | To set up your tenant |
| Your content: posts, captions, media, schedules, campaigns | To provide the Service |
| Correspondence you send to contact@oraglegpt.org | To answer you and keep a record of what was agreed |
| Billing details you give us for an invoice | To issue a lawful invoice. We collect no card or bank instrument, because the Service has no payment processing at all |
2.2 Data we get when you connect a social account
When you connect an account we store the access credential for it and the identifiers needed to publish, such as the page or channel ID and the account name shown in the interface.
We request the narrowest scopes that will publish. We do not request, hold or use permissions to read your comments, mentions, messages or insights, because the connectors are publish-only and no code exists that would use such a permission.
Stored social credentials are encrypted at rest with AES-256-GCM and are never included in a data export.
2.3 Data generated by your use
| Data | Why |
|---|---|
| Publication log: what was published, where, when, and the result | So you and we can tell what happened, and resolve disputes |
| Audit log: which actor changed which record | Integrity and accountability. Hash-chained and append-only |
| Security events: sign-ins, failures, suspicious activity | To detect and investigate abuse |
| Session records | To keep you signed in and to let you revoke sessions |
| Technical request data, including IP address and user agent | Security, rate limiting and diagnosing faults |
2.4 Analytics, which you supply and we do not gather
We fetch no analytics from any platform. The only route by which analytics data enters the Service is your own authenticated call to POST /api/v1/analytics/observations. The software actively refuses a collection_method of provider_api, webhook, scrape or crawl.
So any figures you see are figures you sent us. We did not collect them from Meta, TikTok or anyone else, and we cannot.
2.5 What we deliberately do not collect
- No special category data under Article 9. Do not put it into the Service.
- No card or bank details. There is no payment processor.
- No advertising identifiers, no cross-site tracking, no data brokers, no enrichment vendors.
- No third-party web analytics and no tag manager. See Cookie and Local Storage Policy.
- No inbox content, because no connector can read one.
3. Legal bases
| Purpose | Legal basis |
|---|---|
| Providing the Service under our agreement with you | Art. 6(1)(b), performance of a contract |
| Authenticating you and keeping accounts secure | Art. 6(1)(b) and Art. 6(1)(f), our legitimate interest in a secure service |
| Publishing to the accounts you connected | Art. 6(1)(b), and your authorisation at the platform |
| Security logging, abuse detection, rate limiting | Art. 6(1)(f), legitimate interest in protecting the Service and its users |
| Keeping the audit log | Art. 6(1)(f), and Art. 6(1)(c) where accountability under Art. 5(2) requires it |
| Invoicing and accounting records | Art. 6(1)(c), a legal obligation under Romanian accounting and tax law |
| Answering your correspondence | Art. 6(1)(b) or Art. 6(1)(f) |
| Marketing messages, if any | Art. 6(1)(a), consent, which you may withdraw at any time. Required also by Legea nr. 365/2002 art. 6 |
| Non-essential cookies | Consent, under Legea nr. 506/2004 art. 4 alin. (5). We set none. See Cookie and Local Storage Policy |
Where we rely on legitimate interests we have considered your rights and interests and concluded they do not override ours for the narrow purposes above. You may object under Article 21, and we will tell you the outcome and why.
4. Who else sees your data
Our infrastructure vendor list is genuinely short. The full table, with locations and roles, is in Subprocessors.
- Contabo GmbH, hosting. The application, database, object storage and media processing run on our own server; this site and our mailbox run on a second one. Both servers are in the European Union.
- Cloudflare, authoritative DNS for the domain and reverse proxy in front of this site. Because this hostname is proxied, Cloudflare terminates TLS and processes your IP address, the URL you requested, your user agent and the content in transit.
- Let's Encrypt, TLS certificate issuance. Sees a domain name and no personal data.
Destination social platforms are not our subprocessors. When you publish to Facebook, TikTok or anywhere else, you are sending your content to an independent controller that decides for itself what it does with it, under its own privacy policy. We transmit what you told us to transmit.
We also disclose data where the law requires it, to establish or defend legal claims, and to a successor if the business is transferred, in which case we would tell you first.
We do not sell personal data, and we do not share it for advertising.
5. International transfers
Hosting involves no international transfer. The application, database, object storage, media processing and the mailbox are all on our own servers within the European Union, so Chapter V of the GDPR is not engaged for any of them.
One transfer does arise, and we would rather name it than bury it. Cloudflare sits in front of this site as a reverse proxy, and Cloudflare is established in the United States. Traffic to https://gptpostllm.oraglegpt.org therefore passes through a vendor outside the EEA, even though the edge serving European visitors is itself in Europe. The mechanism relied on is Cloudflare's published data processing addendum incorporating the EU Standard Contractual Clauses. The outstanding administrative point on that addendum is disclosed in section 3 of Subprocessors.
A transfer outside the EEA only arises if you choose it, by connecting a social platform outside the EEA, or by enabling an optional integration or an AI provider with your own credentials. That is your decision as controller. Where you need Standard Contractual Clauses for such a transfer, ask at contact@oraglegpt.org.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and workspace data | While your account is open, then per Data Deletion Policy |
| Publication log | 24 months |
| Analytics observations you submitted | 25 months |
| AI run records, if an AI provider was enabled | 12 months |
| Security events | 12 months |
| Sessions | 24 hours |
| Correspondence | While needed to handle the matter, and for any limitation period |
| Invoices and accounting records | As required by Romanian accounting and tax law |
| Audit log | Retained, append-only, minimised on erasure so the chain survives |
Deletion routes, the 30-day windows and the exact mechanics are in Data Deletion Policy.
7. How your data is protected
Full detail, and a frank list of the limitations, is in Security. In summary:
- Passwords hashed with PBKDF2-HMAC-SHA256, 210,000 iterations.
- Multi-factor authentication available, optional for customer accounts.
- Credential fields encrypted at rest with AES-256-GCM: social tokens, pasted provider secrets, API keys, integration and webhook secrets and similar. Bulk business content is not application-encrypted, and we say so rather than claim blanket encryption.
- Tenant isolation enforced by PostgreSQL row-level security, forced at the database, with tenant identity taken from the server-side session and never from the request.
- Hash-chained, append-only audit log covering every change. Reads are not audited.
- Sessions are opaque bearer tokens, 12 hours absolute and 2 hours idle, with a
HttpOnly,Secure,SameSite=Laxcookie and a CSRF origin check.
8. Our commitments to the social platforms and to you
These are the commitments platform reviewers ask about, and they are commitments to you as well.
- We do not use your content or your platform data to train any machine learning model, ours or anyone else's.
- We do not use platform data for advertising, ad targeting or audience building, and we run no advertising technology.
- We do not sell, rent or broker platform data.
- We request the minimum scopes needed to publish, and nothing that would let us read your audience, messages or insights.
- We delete platform data on request and on deauthorisation, immediately and with no grace period when a platform tells us by signed callback. See Data Deletion Policy.
- We do not attempt to circumvent any platform's rate limits, review process or automation rules.
- Any AI feature is off unless a workspace administrator turns it on with their own provider key. No AI provider is configured on this deployment by default, and content is never sent to a model provider unless that administrator enabled it. Text embeddings are computed locally and are never sent anywhere.
9. Your rights
You have the rights in Articles 15 to 22: access, rectification, erasure, restriction, portability, objection, and not to be subject to solely automated decisions with legal or similarly significant effects. We take no such automated decisions.
How to exercise them, what to include, how we verify identity, our timescales and the complaint route to Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) are set out in Your Data Protection Rights.
In short: write to contact@oraglegpt.org. We answer within one month, extendable by two further months for genuinely complex requests under Article 12(3), and we charge nothing unless a request is manifestly unfounded or excessive.
You may complain to Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), https://www.dataprotection.ro, B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, cod poștal 010336, București, România, anspdcp@dataprotection.ro, and you have the right to a judicial remedy.
10. Children
The Service is not intended for children. You must be at least 16, or the age of digital consent where you live if that is higher. If we learn that we hold data about a child below that age we delete it. Tell us at contact@oraglegpt.org.
11. Cookies
We set one strictly necessary session cookie and no advertising or analytics cookies. The detail, and the position under Legea nr. 506/2004 art. 4 alin. (5) and alin. (6), is in Cookie and Local Storage Policy.
12. Changes
We may update this policy. The version in force is the one published here with its date. For a material change we publish the new version and, where we hold a means of contacting you, give reasonable notice. Superseded versions are available on request at contact@oraglegpt.org.
13. Related pages
| Page | What it covers |
|---|---|
| Your Data Protection Rights | Exercising your rights, step by step |
| Data Deletion Policy | Deletion routes and exact timings |
| Data Processing Addendum | The Article 28 processor terms |
| Subprocessors | Every vendor, and the categories we have not engaged |
| Security | Protection measures and known limitations |
| Cookie and Local Storage Policy | Cookies and local storage |
| Company Identification | Full company identification data |