1. About this policy and the service
This policy applies to use of the service and explains what personal data is processed, why it is processed, who receives it, how long it is retained and the rights available to data subjects.
The service is designed for businesses and other professional customers. A customer can upload content once and publish it to connected pages and accounts across multiple social platforms. When enabled, the customer can also centralize messages and comments in one workspace.
If translations conflict, the Norwegian text prevails. Translations are provided to make the information easier to understand.
2. Who is responsible?
MDataService is the controller for customer-account, contact-person, billing, security, support and service-operation data.
When we process messages, comments, content or audience data for a customer, the customer is normally the controller and MDataService is the processor. Processing is governed by the customer's instructions and a data processing agreement under GDPR Article 28.
Connected social platforms also process data under their own terms and privacy policies. Customers must review platform settings and terms before connecting an account.
- Company details
- Mahmuod Data Service
- Organisation number
- 927978792
- Address
- Dragehodesvingen, 1360 Fornebu, Norway
- Privacy contact
- app@mdataservice.com
+4741138005 - Data protection officer
- No separate data protection officer has been stated. Privacy questions may be sent to the privacy contact.
3. Data we process
Depending on the features used, we may process these categories:
- Name, user ID, role and customer account
- Business name, email, phone and contact person
- Login events and authentication identifiers
- Connected pages, profiles, account IDs and selected permissions
- Encrypted access and refresh tokens
- Images, video, text, links, drafts and publishing schedule
- Messages, comments, replies, attachments and conversation status
- Sender name, public profile ID and page/account identifier
- IP address, browser, device, timestamps and feature use
- Security logs, errors, audit trail and abuse indicators
- Subscription, payment, invoice and required accounting data
- Email, support cases and feedback
The service is not intended for deliberate collection of special-category data. Customers must not upload health, biometric, political, religious or other sensitive data unless a valid legal basis, necessary safeguards and a written agreement are in place.
4. Sources of data
We receive data directly from the customer and authorised users, from devices and browsers using the service, from connected social platforms through approved APIs, and from people who contact the customer's pages through messages or comments. Where data is not obtained directly from the data subject, the customer as controller normally provides the required notice.
5. Purposes and legal bases
We use personal data only for specified purposes and under a valid legal basis:
Account identity, business contact and necessary authentication data must be provided to enter into and perform the service contract. Without them, we cannot create or secure the account. Connecting a social account and using publishing, inbox or comment features is optional, but a selected feature cannot operate without the corresponding platform data and permissions.
6. Social platforms and Meta data
The service requests only platform access needed for features the customer expressly enables. Authorisation codes and access tokens are used to identify connected pages, publish customer content, and retrieve or respond to messages and comments when those features are enabled.
Meta permissions that may be requested
The actual login dialog and Meta App Review submission must include only implemented and approved permissions. Remove unused permissions in the editor.
Data received through platform APIs is not used to sell personal data, for independent advertising, credit decisions, or profiling unrelated to the customer's selected feature.
7. Messages, comments and customer responsibility
When the customer centralizes inboxes or comments, the service may display sender name, public profile identifier, text, attachments, time, page/account and conversation status. The data is processed so the customer can answer and manage the request.
The customer must have a lawful basis, give its audience the required notice, honour objections and deletion requests, restrict user access, and not use the service for unlawful surveillance, spam or data it has no right to use.
9. Transfers outside the EEA
Some platform and operational providers may process data outside the EEA. Where GDPR requires it, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, assess transfer risks and use supplementary technical and organisational measures. Details of the relevant transfer mechanism can be requested from the privacy contact.
10. Retention and deletion
We do not retain personal data longer than necessary. These default periods apply unless the customer agrees a shorter period or law requires longer retention:
- Account and contact data
- For the customer relationship and up to 30 days after closure, unless law requires longer.
- Access tokens
- Until the integration is disconnected, permission is revoked, the token expires or the account is closed.
- Draft and published content
- Until the customer deletes it or closes the account; active-system deletion normally completes within 30 days.
- Messages and comments
- Under the customer's configured period or documented instructions, never longer than necessary for the feature.
- Security and audit logs
- Up to 12 months, with a possible extension for an incident or legal claim.
- Support cases
- Up to 24 months after the case closes.
- Accounting and payment data
- Normally 5 years, or the period required by Norwegian bookkeeping and tax law.
- Backups
- Remnants may remain in access-restricted backups for up to 90 days.
11. Information security
We use risk-based technical and organisational measures to protect confidentiality, integrity and availability. No solution can guarantee absolute security, but we review controls regularly and manage incidents through a documented response process.
- Encryption in transit (TLS)
- Encryption at rest
- Separate encryption of platform tokens
- Least privilege and limited API permissions
- Role-based access
- Multi-factor authentication for administrative access
- Audit and security logging
- Restricted backups and deletion cycle
- Incident response and notification procedures
- Security and privacy review of providers
12. Your rights
Where MDataService is the controller, subject to GDPR conditions you may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests, and withdraw consent without affecting prior lawful processing. Where the customer is the controller, contact the customer first; we assist the customer as processor.
We may request reasonable information to verify identity and prevent disclosure to the wrong person. Requests are normally free of charge.
13. Deleting app and Meta data
You can request deletion or disconnect a social account in these ways:
- Open service settings, choose Connected accounts, disconnect the relevant platform and confirm.
- Revoke the app's access in the social platform's privacy or integration settings.
- Send a deletion request to the email below. State the account email and connected page/account, but never send a password or access token.
- If the data concerns a business's customer dialogue, also contact that business because it is normally the controller.
After verification, we disable relevant integrations and delete data from active systems without undue delay, normally within the stated active-deletion period. Data lawfully retained is blocked from other use. Backup remnants are deleted through automatic overwrite.
13. Deleting app and Meta data14. This policy website
By default, this static policy site sets no cookies, uses no analytics and has no login. Netlify may process limited technical logs to deliver the site securely. If analytics or tracking is later enabled, this policy and any required consent mechanism must be updated first.
15. Children
The service is a business tool for authorised adult users and is not directed to children. We do not knowingly create customer accounts for anyone below the stated minimum age. Contact us if you believe a child supplied account data without necessary authorisation. 18+
16. Automated decisions and marketing
The service does not make automated decisions producing legal or similarly significant effects on individuals. We do not use customer audience data for our own direct marketing. Any optional marketing to customers is sent only with a valid basis and a clear opt-out.
17. Changes
We update this policy when processing, providers or law changes. Material changes are notified in the service or directly to customers before they take effect where practical and required. The date and version above identify the current edition.
18. Contact and complaints
Send questions or rights requests to the privacy contact. You may also complain to Datatilsynet or the supervisory authority where you live or work.
Official guidance sources
These links document the template's legal basis and guidance; they do not replace a specific legal review of the service's actual processing.