Privacy Policy
1. Information for users
FX FOR A LIVING, S.L.N.E., hereinafter the DATA CONTROLLER, is the controller of users' personal data and informs you that such data will be processed in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. The following information on processing is provided:
Purpose of processing
Maintaining an educational and/or commercial relationship with the User.
Processing operations
- Sending educational and/or commercial promotional communications by email, fax, SMS, MMS, social communities or any other electronic or physical medium, present or future, that enables such communications. These communications will be sent by the DATA CONTROLLER and will relate to its products and services, or those of its collaborators or suppliers with whom it has entered into a promotional agreement.
- Carrying out statistical studies.
- Processing orders, requests or any type of query submitted by the user through any of the available contact channels.
- Sending the website newsletter.
Data retention criteria
Data will be retained for as long as there is a mutual interest in maintaining the purpose of processing. Once no longer necessary for that purpose, data will be deleted using appropriate security measures to ensure pseudonymisation or complete destruction.
Data sharing
We will not share your personal data with third parties unless we are legally required to do so or have previously agreed to it.
In order to provide you with an adequate service and manage our relationship with you as a client, the categories of companies that process your data on behalf of FX FOR A LIVING, S.L.N.E. — as part of the services we have contracted from them — are tax and accounting advisory and management companies, and information technology services companies.
We also inform you that, for the same purpose stated above, certain companies providing services to FX FOR A LIVING, S.L.N.E. may access your personal data (international data transfers). Such transfers are made to countries with a level of protection equivalent to that of the European Union (European Commission adequacy decisions).
For more information, please contact us at: support@contentflow365.com.
User rights
- Right to withdraw consent at any time.
- Right to access, rectification, portability and erasure of your data, and to restriction of or objection to its processing.
- Right to lodge a complaint with the supervisory authority (aepd.es) if you consider that the processing does not comply with applicable regulations.
Contact details to exercise your rights
Postal address: FX FOR A LIVING, S.L.N.E. C/La Añaza, 29 1º Dcha, 35500 Arrecife (Las Palmas).
Email: support@contentflow365.com
2. Mandatory or optional nature of information provided by the User
By ticking the relevant boxes and entering data in fields marked with an asterisk (*) in the contact form or download forms, users expressly, freely and unambiguously accept that their data is necessary for the provider to handle their request, while the inclusion of data in the remaining fields is voluntary. The User warrants that the personal data provided to the DATA CONTROLLER is accurate and undertakes to notify any changes to that data.
The DATA CONTROLLER informs users that, whenever it intends to transfer personal data, it will first request the express, informed and unambiguous consent of the Users.
All data requested through the website is mandatory, as it is necessary for the provision of an optimal service to the User. If not all data is provided, we cannot guarantee that the information and services provided will be fully suited to your needs.
3. Security measures
In accordance with the provisions of current data protection regulations, the DATA CONTROLLER is complying with all GDPR requirements for the processing of personal data under its responsibility, and in particular with the principles set out in Article 5 of the GDPR, under which data is processed lawfully, fairly and transparently in relation to the data subject and is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
The DATA CONTROLLER warrants that it has implemented appropriate technical and organisational policies to apply the security measures required by the GDPR in order to protect users' rights and freedoms, and has provided users with the information necessary to exercise those rights.
4. YouTube API Services integration
ContentFlow365 uses Google's YouTube API Services (YouTube Data API v3 and YouTube Analytics API) to provide the following features to the User once they have explicitly connected their YouTube channel through Google's OAuth 2.0 flow:
- Publishing videos created by the User to their YouTube channel (
youtube.upload). - Setting a custom thumbnail on the uploaded video (
youtube). - Publishing a pinned comment on the uploaded video (
youtube). - Changing the video privacy status (from unlisted to public) on the date scheduled by the User (
youtube). - Displaying the User's public and private channel and video statistics in their internal dashboard (
youtube.readonly,yt-analytics.readonly).
4.1 Acceptance of Google and YouTube terms
By using ContentFlow365's YouTube integration, the User expressly agrees to be bound by the YouTube Terms of Service and Google's Privacy Policy.
4.2 What data we obtain from YouTube and how we use it
ContentFlow365 only obtains and stores from YouTube API Services the data strictly necessary to provide the User with the features described above:
- OAuth tokens (access token and refresh token) — stored encrypted in our database and used exclusively by our backend services to execute the operations authorised by the User. They are not shared with third parties or used for any other purpose.
- YouTube channel ID and name connected to the account, as well as the email address associated with the Google account — displayed in the User's internal dashboard so they can identify which channel is connected and disconnect it if they wish.
- Video metadata published by the User through the platform (title, description, tags, publication date, YouTube video ID) — stored in our database to display publication status, link to analytics, and allow the User to manage their published video history.
- Aggregated channel statistics (views, subscribers, interactions, watch time) — shown to the User in their internal analytics dashboard. This data is temporary and periodically refreshed from the YouTube Analytics API.
ContentFlow365 does NOT transfer, sell, share or disclose to any third party the data obtained from YouTube API Services under any circumstances. Data is used exclusively within the private scope of the User who connected it.
4.3 YouTube data storage and retention
OAuth tokens are stored encrypted in databases hosted in the European Union (Supabase, Frankfurt) and remain active until the User explicitly revokes the integration. Published video metadata is retained for the lifetime of the User's account on the platform. Upon account cancellation, this data is deleted within a maximum of 30 days.
Aggregated channel statistics are periodically refreshed and may be cached for up to 24 hours to reduce calls to the YouTube Analytics API. This data never leaves ContentFlow365's servers.
4.4 How to revoke ContentFlow365's access to your YouTube account
The User can revoke ContentFlow365's access to their YouTube data at any time using either of these two methods:
- From ContentFlow365: go to Social Hub → Accounts, find the "YouTube Direct connected" card and click "Disconnect". Revocation is immediate: the access token is invalidated, the refresh token is marked as inactive in our database, and ContentFlow365 can no longer make YouTube API calls on behalf of the User.
- From Google security settings: go to https://myaccount.google.com/permissions, find "ContentFlow365" in the list of authorised third-party apps and click "Remove access". This action revokes access on Google's side and propagates the invalidation to our servers on the next token use attempt.
4.5 Limited Use — compliance with YouTube API policies
ContentFlow365's use of information received from Google APIs, including the transfer of that information to any other application, adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Meta and Instagram integration
ContentFlow365 allows customer businesses to voluntarily connect their Facebook Pages and professional Instagram accounts through Meta's authorisation process. Each business chooses which assets to connect and which automations to enable.
5.1 Data we receive
Depending on the permissions granted and features used, we may process:
- OAuth tokens and granted permissions, stored only in access-restricted server-side infrastructure.
- Asset identifiers and metadata, such as Facebook Pages, professional Instagram accounts, usernames and selected media.
- Comment and webhook data, such as comment ID, text, date, related media and the app-scoped Instagram identifier.
- Delivery identifiers and statuses required to record a public or private reply and prevent duplicate sends.
5.2 How we use this data
We use this data only to provide features configured by the customer business: display and select its own assets, detect keywords in comments on supported posts, Reels, Stories or Live broadcasts, publish a reply under the comment, send one private reply with the requested resource, and display automation status and errors. We do not sell this data or use it to build our own advertising profiles.
5.3 People who comment or reply
A person does not need to be a ContentFlow365 customer for Meta to send us the minimum data from their interaction with a professional account managed by a customer. That data is processed on behalf of the business that configured the automation, solely to respond to the requested interaction, prevent duplicates and maintain an operational and security record.
5.4 Retention, disconnection and deletion
Connection data is retained while the integration remains active and for as long as needed to maintain the operational history requested by the customer. When Meta is disconnected, we stop using the token. The account owner or a person who interacted with it may request deletion of associated data; we will complete the request within 30 days, except where legal or security obligations apply.
See the public Meta and Instagram data-deletion instructions.
6. Google Ads, Data Manager and Google Analytics integration
ContentFlow365 lets each customer business voluntarily connect its own Google user and select the Google Ads Customer it wants to manage. The authorisation is bound to the corresponding ContentFlow account and does not grant access to other customer businesses.
6.1 Data we receive
Depending on the features enabled by the business, we may process only:
- Encrypted OAuth token, authorising-user email and granted scopes, stored in access-restricted server-side infrastructure.
- Google Ads identifiers, configuration and metrics for the selected Customer: campaigns, ad groups, ads, assets, targeting, comments, conversions and statistics required to display and manage them.
- First-party data intended for Customer Match. Identifiers are normalised and hashed before transmission; ContentFlow365 requires confirmation of a valid consent basis and does not retain unhashed identifiers in the upload record.
- Read-only Google Analytics 4 metadata, such as accounts, properties and audiences, so the business can select the correct measurement source. ContentFlow365 cannot modify Analytics data with this permission.
6.2 How we use this data
We use it only to display real information from the accounts selected by the User and to execute advertising actions the User previews and expressly confirms. Campaigns, ad groups and ads created by ContentFlow365 are paused by default. We do not activate spend automatically, use this data for our own advertising, or use it to train artificial-intelligence models.
6.3 Security, retention and disconnection
Tokens are encrypted before storage and bound to one ContentFlow account and its selected Customers. They are retained while the integration remains active or until Google revokes them. Operational history is retained for the life of the account and deleted within 30 days after cancellation, except where legal or security obligations apply.
The User can withdraw authorisation from Google Ads → Connection & setup → Disconnect, or from their Google Account permissions. On disconnection, ContentFlow365 removes the stored authorisation and stops making calls on the User's behalf; it does not delete existing Google accounts, campaigns or videos.
6.4 Limited use and no disclosure
ContentFlow365 does not sell, rent or disclose data received from Google APIs. Its use and any permitted transfer adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Google Calendar integration
ContentFlow365 lets an authorised account member voluntarily connect their own Google Calendar from the private Sales & CRM workspace. The authorisation is isolated to the matching ContentFlow account.
7.1 Data we receive
- Encrypted OAuth access and refresh tokens, authorising-user email and granted scopes, stored only in access-restricted server-side infrastructure.
- Calendar identifiers, names, access roles and time zones so the user can select the correct calendar.
- Free/busy time ranges required to display availability without disclosing unrelated event content.
- Event identifiers, titles, start/end times and links needed to display and manage the events selected or created by the user.
7.2 How we use this data
We use Google Calendar data only to list the connected user's calendars, show availability and upcoming events, and create, edit or delete an event after an explicit user action. We do not use Calendar data for advertising, sell it, disclose it to unrelated third parties, or use it to train general-purpose artificial-intelligence models.
7.3 Security, retention and revocation
OAuth tokens are encrypted before storage and never exposed to the browser. Connection metadata is retained while the integration remains active. Calendar responses are limited to the active account and are not retained beyond what is necessary to provide the requested feature. Disconnecting immediately removes the stored OAuth credentials; minimal audit metadata is retained only where required for security, fraud prevention or legal compliance.
The user can disconnect Google Calendar from Sales & CRM → Calendar → Connections, or remove ContentFlow365 from Google Account connections. ContentFlow365 then stops making Calendar API calls on the user's behalf.
7.4 Limited Use and no disclosure
ContentFlow365's use and any permitted transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Native publishing to Pinterest, Threads and Bluesky
ContentFlow365 may offer integrations that let the User voluntarily connect their own Pinterest, Threads or Bluesky accounts and publish content from their private workspace. Each integration is enabled only after the User completes the relevant provider's authorisation flow.
8.1 Authorisation and permissions
ContentFlow365 does not request or retain passwords for these networks. When the User enables an integration, we use the provider's or AT Protocol's OAuth flow to request only the permissions required:
- Pinterest:
user_accounts:read,boards:read,boards:write,pins:readandpins:writeto identify the authorised account, query available boards and create or check requested Pins. ContentFlow365 does not provide general board management;boards:writeis requested because it is part of the permissions required by Pinterest's Pin-creation operation. - Threads:
threads_basicandthreads_content_publishto identify the connected profile and publish text, images or video when requested by the User. - Bluesky: the AT Protocol scope
atproto include:app.bsky.authCreatePosts?aud=did:web:api.bsky.app%23bsky_appview blob?accept=image/jpeg&accept=image/png&accept=image/webp&accept=text/vttto create posts and upload only JPEG/PNG/WebP images or WebVTT captions selected by the User. Video uses separate service authorisation inherited from the create-post permission; we do not request an OAuth video-blob permission.
8.2 Data we process
- Authorisation credentials: Pinterest and Threads OAuth tokens, or Bluesky's DPoP-bound OAuth session, encrypted before storage and limited to the ContentFlow365 account that initiated the connection.
- Minimum connection identifiers: for Threads, the identifier and username needed to display the connected destination; for Bluesky, the DID, verified handle and PDS server needed to identify the account and route requests to the correct server.
- User-provided content: text, title, description, link, media references or files, and publishing or scheduling instructions that the User saves or confirms in ContentFlow365.
- Publication state: internal job state, technical timestamps and the receipt or identifier returned by the network only where needed and permitted to confirm the result, prevent duplicates or link the publication history requested by the User.
- Pinterest minimisation: we query the profile and available boards live to display the selector, but do not retain the profile name or avatar, board names, or the board collection as persistent connection metadata. The selected destination is processed only to execute the authorised publication, in accordance with Pinterest's rules.
8.3 Purpose and limits
We use this data solely to connect the selected account, show the User which destination is in use, prepare and execute publications they confirm, and report their status. We do not publish to a different account, sell integration data, or request analytics, messaging, moderation, advertising or general account-administration permissions for these features.
8.4 Retention, disconnection and published content
Encrypted credentials are retained while the connection remains active. User-created content and the minimum operational history are retained while needed to provide account features or meet applicable security, fraud-prevention or legal-compliance requirements. When a network is disconnected, we delete or invalidate the credentials stored for that connection and stop making new calls on the User's behalf.
Disconnecting the integration or deleting its data from ContentFlow365 does not automatically remove Pins, Threads posts or Bluesky posts already published to the User's account. That content remains under the User's control on the relevant network and must be deleted there if the User also wants it removed.
See the public social-integration disconnection and data-deletion instructions.
9. Pinterest Ads integration
After Pinterest's specific approval and a separate enablement step, ContentFlow365 may offer a read-only view that lets an authorised User inspect their own Pinterest advertising accounts. This feature remains separate from organic publishing and is not enabled merely by connecting Pinterest.
9.1 Authorisation and permissions
The initial phase requests ads:read in addition to the organic permissions only when the User enables Pinterest Ads. billing:read will be requested only if read-only access to billing profiles and invoices is separately enabled. This phase does not request ads:write, billing:write, catalogue, lead-form, conversion, beta or restricted permissions.
9.2 Data we query
- Connection: encrypted OAuth credentials, granted scopes, expiry and technical connection status.
- Advertising accounts: identifier, name, country, currency, time zone and owner permissions needed to validate and display the selected account.
- Structure and performance: campaigns, ad groups and ads, their relationships, objective, format, settings, budgets or caps, configured status, delivery or review status, and aggregated metrics such as spend, impressions, clicks, CTR, conversions, leads or checkouts.
- Read-only supporting data: audiences without member lists; conversion tags and setup status without Conversion API events or personal identifiers; and, only with
billing:read, billing identifiers, type, brand, status and invoice amounts, never full card or bank-account numbers.
9.3 Purpose and limits
We use this data solely to let the User select their own advertising account, inspect a dashboard, hierarchy and delivery or review status, measure performance and diagnose configuration. We do not sell or disclose it, combine it across ContentFlow accounts, use it for our own advertising, profile individuals or train artificial-intelligence models.
9.4 Querying, retention and security
Pinterest Ads responses are queried live, returned as private non-cacheable content and not stored in the database or as persistent connection metadata. They remain only transiently during the authenticated request or session. Tokens are encrypted server-side and retained while the connection is active; minimum technical logs contain neither tokens nor the response body returned by Pinterest.
9.5 Enablement, disconnection and deletion
Initial access is restricted to the internal team and is read-only: it does not create, edit or activate campaigns, ads or audiences, send conversion events or initiate spend. Customer access requires Pinterest Standard approval and the corresponding review. On disconnection, ContentFlow365 deletes or invalidates the local authorisation and stops making calls; it does not delete existing Pins, campaigns or ads on Pinterest. Deletion requests are processed under the public data-deletion instructions.