Privacy Policy
Last updated 4 October 2026
Who is responsible
OmniMed Global B.V. (trading as Postmodel), Krom Boomssloot 5, 1011 GP Amsterdam, Netherlands, registered under Dutch Chamber of Commerce (KvK) 98643908. Contact: info@postmodel.ai.
What we process
- Connected TikTok account: the account's open ID, display name and profile picture, and the access and refresh tokens TikTok issues when the account is connected. Permissions requested:
user.info.basicandvideo.publish. - Content: the videos, photos and captions the brand has approved for publishing, and the settings chosen for each TikTok post (visibility, comments, Duet, Stitch, branded content).
- Approvals: the Telegram user ID of the approver, the decision and its time.
- Results: TikTok's publish ID, status and post ID.
Why
Only to publish content the brand has approved to the account the brand connected, to show the approver which account a post goes to, and to report the result. Legal basis: performance of our contract with the brand (Art. 6(1)(b) GDPR) and our legitimate interest in running the service securely (Art. 6(1)(f) GDPR).
Who receives data
- TikTok receives the content and settings an approver confirmed.
- Hetzner Online GmbH hosts our servers in the EU (Helsinki, Finland) under a data processing agreement.
- Telegram delivers approval messages to the brand's approvers.
We do not sell data, do not use it for advertising and do not share it with anyone else. Our web server keeps no access logs.
How long
Tokens are kept until the account is disconnected; we then revoke them with TikTok and delete them within 7 days. Approval and publishing records are kept for the duration of our work for the brand and deleted within 90 days after it ends, unless law requires longer.
Disconnecting and deletion
Remove Postmodel Social in the TikTok app under Settings → Security → Manage app permissions, or write to info@postmodel.ai. We then revoke the tokens and delete the account data.
Your rights
You may request access, correction, deletion, restriction, data portability, and object to processing. You may complain to the Autoriteit Persoonsgegevens (Netherlands) or your local data protection authority.
Security
Tokens and keys travel only over HTTPS and are stored on our server so that only the publishing service can read them. Every post needs a human confirmation.