GDPR · EEA · Meta Platform

Privacy Policy

How MDataService processes personal data in our social publishing and customer-engagement platform.

Last updated: 19 July 2026Effective: 19 July 2026Version: 1.0

1. About this policy and the service

This policy applies to use of the service and explains what personal data is processed, why it is processed, who receives it, how long it is retained and the rights available to data subjects.

The service is designed for businesses and other professional customers. A customer can upload content once and publish it to connected pages and accounts across multiple social platforms. When enabled, the customer can also centralize messages and comments in one workspace.

If translations conflict, the Norwegian text prevails. Translations are provided to make the information easier to understand.

2. Who is responsible?

MDataService is the controller for customer-account, contact-person, billing, security, support and service-operation data.

When we process messages, comments, content or audience data for a customer, the customer is normally the controller and MDataService is the processor. Processing is governed by the customer's instructions and a data processing agreement under GDPR Article 28.

Connected social platforms also process data under their own terms and privacy policies. Customers must review platform settings and terms before connecting an account.

Company details
Mahmuod Data Service
Organisation number
927978792
Address
Dragehodesvingen, 1360 Fornebu, Norway
Privacy contact
kontakt@mdataservice.com
+4741138005
Data protection officer
No separate data protection officer has been stated. Privacy questions may be sent to the privacy contact.

3. Data we process

Depending on the features used, we may process these categories:

  • Images, video, text, links, drafts and publishing schedule
  • Security logs, errors, audit trail and abuse indicators
  • Subscription, payment, invoice and required accounting data
  • Email, support cases and feedback

The service is not intended for deliberate collection of special-category data. Customers must not upload health, biometric, political, religious or other sensitive data unless a valid legal basis, necessary safeguards and a written agreement are in place.

4. Sources of data

We receive data directly from the customer and authorised users, from devices and browsers using the service, from connected social platforms through approved APIs, and from people who contact the customer's pages through messages or comments. Where data is not obtained directly from the data subject, the customer as controller normally provides the required notice.

5. Purposes and legal bases

We use personal data only for specified purposes and under a valid legal basis:

Create and manage the customer account and provide the serviceContract, GDPR Art. 6(1)(b)
Billing, payment, accounting and taxContract and legal obligation, Art. 6(1)(b), (c)
Support and service communicationContract and legitimate interests, Art. 6(1)(b), (f)
Secure accounts, prevent misuse and handle incidentsLegitimate interests and legal obligations, Art. 6(1)(f), (c)
Troubleshoot and improve stability and usabilityLegitimate interests, Art. 6(1)(f); aggregated data where possible
Meet law and establish or defend legal claimsLegal obligation and legitimate interests, Art. 6(1)(c), (f)

Account identity, business contact and necessary authentication data must be provided to enter into and perform the service contract. Without them, we cannot create or secure the account. Connecting a social account and using publishing, inbox or comment features is optional, but a selected feature cannot operate without the corresponding platform data and permissions.

6. Social platforms and Meta data

The service requests only platform access needed for features the customer expressly enables. Authorisation codes and access tokens are used to identify connected pages, publish customer content, and retrieve or respond to messages and comments when those features are enabled.

Enabled platformsThreadsTikTokXSnapchat

Meta permissions that may be requested

The actual login dialog and Meta App Review submission must include only implemented and approved permissions. Remove unused permissions in the editor.

Data received through platform APIs is not used to sell personal data, for independent advertising, credit decisions, or profiling unrelated to the customer's selected feature.

8. Sharing and processors

We share data only where needed to provide the service, follow customer instructions, meet legal requirements, or protect rights and security. We do not sell personal data. Providers are bound by contracts, confidentiality, security requirements and documented instructions where they act as processors.

ProviderPurposeProcessing regionPrivacy
NetlifyHosting this public privacy-policy siteGlobal infrastructurePrivacy

9. Transfers outside the EEA

Some platform and operational providers may process data outside the EEA. Where GDPR requires it, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, assess transfer risks and use supplementary technical and organisational measures. Details of the relevant transfer mechanism can be requested from the privacy contact.

10. Retention and deletion

We do not retain personal data longer than necessary. These default periods apply unless the customer agrees a shorter period or law requires longer retention:

Account and contact data
For the customer relationship and up to 30 days after closure, unless law requires longer.
Draft and published content
Until the customer deletes it or closes the account; active-system deletion normally completes within 30 days.
Security and audit logs
Up to 12 months, with a possible extension for an incident or legal claim.
Support cases
Up to 24 months after the case closes.
Accounting and payment data
Normally 5 years, or the period required by Norwegian bookkeeping and tax law.
Backups
Remnants may remain in access-restricted backups for up to 90 days.

11. Information security

We use risk-based technical and organisational measures to protect confidentiality, integrity and availability. No solution can guarantee absolute security, but we review controls regularly and manage incidents through a documented response process.

  • Encryption in transit (TLS)
  • Encryption at rest
  • Separate encryption of platform tokens
  • Least privilege and limited API permissions
  • Role-based access
  • Multi-factor authentication for administrative access
  • Audit and security logging
  • Restricted backups and deletion cycle
  • Incident response and notification procedures
  • Security and privacy review of providers

12. Your rights

Where MDataService is the controller, subject to GDPR conditions you may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests, and withdraw consent without affecting prior lawful processing. Where the customer is the controller, contact the customer first; we assist the customer as processor.

We may request reasonable information to verify identity and prevent disclosure to the wrong person. Requests are normally free of charge.

kontakt@mdataservice.comWe normally respond within one month and use an internal target of 30 days after identity verification. For complex or numerous requests, GDPR permits an extension of up to 2 months; we will notify you within the first month.

13. Deleting app and Meta data

You can request deletion or disconnect a social account in these ways:

  1. Open service settings, choose Connected accounts, disconnect the relevant platform and confirm.
  2. Revoke the app's access in the social platform's privacy or integration settings.
  3. Send a deletion request to the email below. State the account email and connected page/account, but never send a password or access token.
  4. If the data concerns a business's customer dialogue, also contact that business because it is normally the controller.

After verification, we disable relevant integrations and delete data from active systems without undue delay, normally within the stated active-deletion period. Data lawfully retained is blocked from other use. Backup remnants are deleted through automatic overwrite.

13. Deleting app and Meta data

14. This policy website

By default, this static policy site sets no cookies, uses no analytics and has no login. Netlify may process limited technical logs to deliver the site securely. If analytics or tracking is later enabled, this policy and any required consent mechanism must be updated first.

15. Children

The service is a business tool for authorised adult users and is not directed to children. We do not knowingly create customer accounts for anyone below the stated minimum age. Contact us if you believe a child supplied account data without necessary authorisation. 18+

16. Automated decisions and marketing

The service does not make automated decisions producing legal or similarly significant effects on individuals. We do not use customer audience data for our own direct marketing. Any optional marketing to customers is sent only with a valid basis and a clear opt-out.

17. Changes

We update this policy when processing, providers or law changes. Material changes are notified in the service or directly to customers before they take effect where practical and required. The date and version above identify the current edition.

18. Contact and complaints

Send questions or rights requests to the privacy contact. You may also complain to Datatilsynet or the supervisory authority where you live or work.

Mahmuod Data ServiceDragehodesvingen, 1360 Fornebu, Norwaykontakt@mdataservice.com
Datatilsynet (Norwegian Data Protection Authority)Complaint / Klage

Official guidance sources

These links document the template's legal basis and guidance; they do not replace a specific legal review of the service's actual processing.