Skip to content

1. Who we are

Collektivs is a social-media management platform for music collectives, labels, associations, and independent artists. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our website at https://collektivs.com and our related services (collectively, the "Service").

The data controller is:

Throughout this policy, "we", "our", and "us" refer to Drouvin Consulting, and "you" refers to the user of the Service.

2. What data we collect

2.1 Data you provide directly

  • Account data: name, email address, password (stored as a salted hash, never in plaintext), profile picture.
  • Organization data: organization name, address, website, member roles, billing contact.
  • Content you create: posts, captions, scheduled-post metadata, uploaded images and videos, AI-generation prompts, calendar events, campaign briefs.
  • Payment data: collected and processed by our payment provider (Mollie) — we store only the last 4 digits of the card and the billing address. We never see or store full card numbers or CVCs.

2.2 Data we collect from connected social-media accounts

When you connect a Facebook Page, Instagram Professional account, TikTok account, or other supported platform (Google, YouTube, Twitch, SoundCloud, Discord, Slack, Apple, Shotgun) we receive and store:

  • Identifiers: account ID (e.g. Facebook Page ID, Instagram user ID, TikTok open_id / union_id), username, display name.
  • Public profile information: profile picture, account category, link, follower count if exposed by the platform.
  • Email address: if returned by the OAuth scope (e.g. Facebook email).
  • Access and refresh tokens: stored encrypted at rest, used only to perform the actions you explicitly requested.
  • Content metadata: IDs of posts our app published on your behalf, plus aggregated engagement data (views, reach, likes count, comments count, shares) returned by each platform's analytics endpoints.

We do not read or store the content of comments left on your posts by other users, the content of direct messages received by your accounts, or the personal data of other end-users who interact with your posts.

2.3 Data we collect automatically

  • Usage data: pages visited, features used, timestamps, action logs (creating, editing, deleting posts).
  • Technical data: IP address (truncated and used only for security and rate-limiting), browser type, operating system, device type, language preference.
  • Cookies and similar technologies: see Section 9.
  • Error and performance data: collected via Sentry to diagnose crashes and via Grafana Cloud / Better Stack for system observability. These tools may receive a reduced fingerprint of your session (user ID, route, browser).

3. How we use your data

We use your personal data for the following purposes and on the following legal bases under the GDPR (Articles 6 and 9 where relevant):

PurposeLegal basis
Provide the core publishing, scheduling, and analytics features you signed up forPerformance of a contract (Art. 6(1)(b))
Authenticate you and secure your accountPerformance of a contract + Legitimate interest in security (Art. 6(1)(b), (f))
Make a limited subset of your authentication activity visible to the owners and admins of organizations you are a member of, so they can oversee the security of the workspace they are responsible for (see Section 3.2)Legitimate interest (Art. 6(1)(f)) — documented in our Legitimate Interests Assessment, available on request
Process payments and manage your subscriptionPerformance of a contract; Legal obligation for accounting (Art. 6(1)(b), (c))
Send transactional emails (login links, scheduled-post failure alerts, billing receipts)Performance of a contract (Art. 6(1)(b))
Send marketing or product-update emailsConsent (Art. 6(1)(a)) — opt-out at any time via the unsubscribe link
Improve the Service, debug issues, and analyze usage trends in aggregateLegitimate interest (Art. 6(1)(f))
Comply with legal obligations (tax, accounting, lawful requests)Legal obligation (Art. 6(1)(c))
Defend our legal rights and prevent abuseLegitimate interest (Art. 6(1)(f))

We do not sell or rent your personal data, ever. We do not use your content to train machine-learning models without your explicit, separate consent.

3.1 AI features

If you use the AI content-assist features (powered by Google Gemini), the prompt you submit is sent to Google's API. Google processes it under its own Generative AI Terms. We do not retain prompts or generated outputs beyond the active session unless you explicitly save them in your dashboard.

3.2 Visibility of your activity to your organization

When you join an organization on Collektivs (as something other than a GUEST), a limited subset of your authentication activity becomes visible to the owners and admins of that organization, so they can oversee the security of the workspace they are responsible for.

Who can see it. Only the roles OWNER and ADMIN of the same organization. Other members (including other EDITORs and GUESTs) cannot see this data. A separate permission flag controls this access — being an admin alone is not enough; the permission must also be granted.

What is shown by default — aggregate views only. The default security view in the organization dashboard shows counts and anomaly badges, not individual sign-in rows. For example: total successful sign-ins this week, count of failed attempts, count of new-device sign-ins, count of members who have not enrolled in MFA, and badges for any open security anomaly.

What is shown on drill-down — per-member detail, gated. An owner or admin can click into a specific anomaly or into a member's row to view the last 30 days of that member's authentication events. The drill-down view shows:

  • Sign-in timestamps and outcome (success / failed / MFA challenge).
  • A truncated IP address — IPv4 to /24, IPv6 to /64. We never expose the full address.
  • Device family (e.g. "Chrome on macOS") — never a unique device identifier.
  • Approximate location at country + region level, derived offline. We never expose street-level geolocation.
  • Your MFA enrolment status (on / off) — never the secret or recovery codes.

Every drill-down is audited and visible to you. Whenever an owner or admin opens the drill-down view of your activity, a record is created with their identity, the time, and (optionally) the reason they provided. You can see this record at Settings → Security → Who viewed my activity in your own dashboard. The record is retained for 12 months.

Excluded from this visibility:

  • The content of any communication.
  • Activity outside authentication events (we do not surface in-app browsing or feature usage to admins).
  • Your sessions outside the organization (we never expose your sign-in to a different organization to this organization's admins).
  • Members whose role is GUEST — their activity is not surfaced to admins at all.

How long this data is retained. Routine authentication events for 6 months. Events tied to an open security signal for up to 12 months. The "who viewed my activity" audit records for 12 months. After these periods the data is deleted by an automated daily process.

Your right to object (Art. 21 GDPR). You may object to this processing on grounds relating to your particular situation. To object, email privacy@collektivs.com or use Settings → Privacy → Object to processing in the dashboard. On a substantiated objection we restrict drill-down access to your data — admins will only see aggregate counts and an "objection on file" indicator. We will continue to ingest the events for strictly security purposes (Art. 21(1) "compelling legitimate grounds"), unless your objection demonstrates an overriding interest.

No automated decisions. This data may drive UI badges and notifications but is never used to automatically suspend, restrict, or remove your access. Any such action requires a deliberate decision by an admin.

If you are an employee of the organization. Where the organization that admitted you is your employer and you are based in Belgium, additional national rules apply (Belgian National Labour Council CCT 81 on the monitoring of electronic communications). Your employer is responsible for fulfilling its CCT 81 obligations (worker information, works-council notice, proportionality) before activating member-activity visibility in their Collektivs workspace; we provide them with the controls and attestation flow needed to do so.

The full balancing test we performed under Art. 6(1)(f) — including the safeguards listed above — is documented in our Legitimate Interests Assessment, available on request to privacy@collektivs.com.

4. Platform-specific data handling

4.1 Meta Platforms (Facebook + Instagram)

We use the Meta Graph API and Meta's official OAuth flows. The Facebook permissions we request are:

  • public_profile, email — to identify you and create your account.
  • pages_show_list, business_management — to list the Pages you manage so you can choose which to connect.
  • pages_manage_posts, publish_video — to publish, edit, and delete posts you compose in our editor.
  • pages_read_engagement, read_insights — to display engagement metrics for posts our app created.

The Instagram permissions we request (via Instagram Login) are:

  • instagram_business_basic — to display your account info and existing media list inside our dashboard.
  • instagram_business_content_publish — to publish Reels, photos, and carousels you compose in our editor.

We comply with the Meta Platform Terms and Meta Developer Policies, including the requirement to delete platform data within 30 days of you disconnecting your account or our access being revoked. We do not store user data we obtained from Meta beyond what is strictly necessary for the features you use.

4.2 TikTok

We use TikTok Login Kit, the Display API, and the Content Posting API. The scopes we request are: user.info.basic, user.info.profile, video.list, video.upload, video.publish. We comply with the TikTok Developer Terms of Service.

4.3 Other platforms

When you connect Google, YouTube, Twitch, SoundCloud, Discord, Slack, Apple, or Shotgun accounts, we collect only the data needed for the specific feature you use. Each platform's own privacy policy applies in addition to ours.

5. Subprocessors

We share your personal data with the following service providers ("subprocessors"). Each of them is bound by a Data Processing Agreement requiring them to process data only on our instructions and to maintain appropriate security.

SubprocessorPurposeLocation
ScalewayApplication hosting (API, worker, database)Frankfurt, Germany (EU)
ImageKitImage and video storage + CDNFrankfurt, Germany (EU)
MolliePayment processingThe Netherlands (EU)
Scaleway (Transactional Email)Transactional email deliveryParis, France (EU)
InfomaniakNewsletter email deliverySwitzerland (adequacy decision)
InfisicalSecrets management (no end-user data)Frankfurt, Germany (EU)
SentryError monitoringFrankfurt, Germany (EU)
Better Stack / Grafana CloudLogging and observabilityEU
OllamaAI content generationUnited States (with EU model option)
Meta Platforms, Inc.Facebook + Instagram OAuth and APIsUnited States
TikTok / ByteDanceTikTok OAuth and APIsUnited States / Singapore

A current list of subprocessors is maintained at /legal/subprocessors and we will notify Customers of material changes by email at least 30 days before the change takes effect.

6. International data transfers

Some subprocessors are located outside the European Economic Area (EEA), notably the United States and Switzerland. When personal data is transferred outside the EEA, we rely on:

  • The European Commission's Standard Contractual Clauses (2021 version), or
  • An applicable adequacy decision (e.g. the EU–US Data Privacy Framework where the recipient is certified), or
  • Your explicit consent for specific transfers where required.

You can request a copy of the safeguards we apply by writing to privacy@collektivs.com.

7. How long we keep your data

Data categoryRetention period
Account dataWhile your account is active, plus up to 30 days after deletion (then deleted)
Social-media access tokensWhile the connection is active; deleted within 24 hours of disconnection
Posts, captions, uploaded mediaWhile stored in your workspace; deleted on account deletion (30-day grace)
Cached engagement metrics13 months, then aggregated to anonymous statistics
Authentication events visible to organization admins (sign-in, MFA challenge)6 months — or 12 months if tied to an open security signal
"Who viewed my activity" audit records12 months
Billing and accounting records10 years (French Code de commerce Art. L123-22)
Server logs12 months
Sentry error events90 days
Email logs (Scaleway Transactional Email, Infomaniak)90 days

When a retention period ends, we either delete the data or irreversibly anonymize it.

8. Your rights

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the GDPR (and equivalent UK / Swiss laws):

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — correct inaccurate data.
  • Right to erasure ("right to be forgotten") — see Section 10 and our separate Data Deletion Instructions.
  • Right to restrict processing — limit how we use your data in certain cases.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interest, including any direct marketing.
  • Right to withdraw consent — for any processing based on consent, at any time, without affecting the lawfulness of past processing.
  • Right to lodge a complaint with your local supervisory authority. In France this is the CNIL.

If you are in California, the CCPA / CPRA grants you similar rights, including the right to know, the right to delete, and the right to opt out of "sale" or "sharing" of personal data. We do not sell or share personal data as those terms are defined under the CCPA.

To exercise any of these rights, email privacy@collektivs.com from the email address associated with your account, or use the in-app Settings → Privacy controls. We will respond within 30 days.

9. Cookies

We use a small number of cookies and similar technologies:

  • Strictly necessary cookies: session, CSRF token, authentication cookie. Without these the Service cannot function.
  • Functional cookies: remember your dashboard preferences (language, sidebar state).
  • Analytics cookies: [DESCRIBE — only if you actually deploy analytics; remove this row if you do not].

We do not use advertising or cross-site tracking cookies. You can review and adjust your cookie preferences at any time via the cookie banner shown on your first visit and the Cookies link in our footer.

10. Account and data deletion

You can delete your account and all associated data at any time from Settings → Account → Delete account in the dashboard, or by following the instructions on our Data Deletion page. On deletion:

  • All access tokens for connected social-media accounts are revoked and deleted within 24 hours.
  • Personal account data, content, and metadata are deleted within 30 days.
  • Billing records are retained for the legally required period (see Section 7).

Disconnecting a single social-media account (without deleting your Collektivs account) deletes the access tokens and account-specific data within 24 hours.

11. Security

We protect your data with industry-standard measures:

  • All traffic is encrypted in transit using TLS 1.2+.
  • Access tokens and other credentials are encrypted at rest.
  • Database backups are encrypted.
  • Access to production systems is limited to a small number of authenticated engineers and audited.
  • We run automated security scans on our codebase and dependencies.

No system is perfectly secure. If you discover a vulnerability, please email security@collektivs.com — we operate a responsible disclosure program.

12. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@collektivs.com and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and post the updated version on this page with a new "Last updated" date at least 30 days before it takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact

For any privacy question or to exercise your rights:

For complaints, you may also contact your local data protection authority (CNIL in France).