Privacy Policy
CloudVigil AB ("CloudVigil", "we", "us") is a Swedish technology company, registration number 559588-0393, with its registered office in Kista, Stockholm, Sweden. This Privacy Policy explains how we collect, use and protect personal data when you:
- visit our websites cloudvigil.se and cloudvigil.io;
- use our social media management and automated publishing services — including Campaign Studio, our application registered with Meta Platforms for Facebook and Instagram (App ID: 1060728986523789), and our applications for X (formerly Twitter) and other social networks (together, the "Services").
We are the data controller for the processing described in this policy under Regulation (EU) 2016/679 (GDPR).
Data we collect
Data you provide directly
- Contact details (name, email address, company) when you email us or sign up for the Services.
- Account information you create when using the Services.
- Content you compose, schedule or publish through the Services — text, images, video and links.
Data received from social media platforms
When you connect a social media account to the Services, you authorise the platform (for example Meta or X) to share certain data with us through their official APIs. Depending on the platform and the permissions you grant, this may include:
- Basic profile information: your name, username or handle, profile picture and account ID.
- Pages, professional accounts or business accounts you manage, and their metadata.
- Access tokens that allow us to act on your behalf (for example, to publish a post you scheduled).
- Content and media you have published or scheduled through the Services.
- Engagement and performance metrics (such as impressions, reach, likes and comments) used to show you analytics.
We only request the permissions needed to provide the features you use. We never receive your social media passwords — authentication happens directly with the platform via OAuth.
Data collected automatically
Our websites collect minimal technical data (such as server logs with IP address, browser type and requested pages) for security and operations. Our websites do not use advertising or cross-site tracking cookies.
How we use your data
We use personal data to:
- provide, operate and improve the Services, including publishing content you schedule and displaying analytics (performance of a contract, Art. 6(1)(b) GDPR);
- respond to enquiries and provide support (performance of a contract or legitimate interest, Art. 6(1)(b) and (f));
- keep the Services secure, prevent abuse and debug problems (legitimate interest, Art. 6(1)(f));
- comply with legal obligations, such as accounting rules (Art. 6(1)(c)).
We do not sell personal data. We do not use data received from Meta, X or any other platform for advertising, profiling unrelated to the Services, or building databases beyond what is needed to provide the Services. Our use of platform data complies with the applicable platform policies, including the Meta Platform Terms and Developer Policies and the X Developer Agreement and Policy.
Sharing of data
We share personal data only with:
- Service providers (processors) that host our infrastructure and help us operate the Services, under data processing agreements;
- The social media platforms you connect, to the extent required to publish and manage content on your behalf;
- Authorities, where required by law.
International transfers
We store data primarily within the EU/EEA. Where a transfer outside the EU/EEA is necessary (for example, because a connected platform operates globally), we rely on adequacy decisions or the European Commission's Standard Contractual Clauses.
Retention
We keep personal data only as long as needed for the purposes above:
- Social account connections, access tokens and cached platform data are deleted when you disconnect an account or delete your account, and in any event when no longer needed to provide the Services.
- Scheduled and published content history is kept while your account is active.
- Support correspondence is kept for up to 24 months.
- Accounting records are kept as required by Swedish law (currently 7 years).
Security
We protect data with industry-standard measures, including encryption in transit (TLS), encrypted storage of access tokens, least-privilege access controls and continuous monitoring.
Your rights
Under the GDPR you have the right to access, rectify and erase your personal data, to restrict or object to processing, and to data portability. You may withdraw consent at any time where processing is based on consent. To exercise your rights, email [email protected].
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) — imy.se — or your local supervisory authority.
Deleting your data
You can disconnect social accounts at any time and request full deletion of your data. See our User Data Deletion instructions for step-by-step guidance, including how to revoke access from within Facebook, Instagram and X.
Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last revised. Material changes will be announced on our website or by email.
Contact
CloudVigil AB (org. no. 559588-0393) Lofotengatan 2, 164 33 Kista, Sweden Email: [email protected]