How we process personal data, the rights you have and how to reach us. Transparent, GDPR-compliant and aligned with the Google API Services User Data Policy.
This is a courtesy translation. The Dutch version is the legally binding original. View the Dutch version →
Social Media Tools ("we", "us", "Senly") provides a SaaS platform that allows marketing professionals — including agencies, social media managers, content creators, in-house marketers and freelancers — to manage their client relationships, content, scheduling, appointments, email communication, marketing and reporting. In this statement we explain which personal data we process, why, for how long, with whom we share it and which rights you have.
We act as a processor within the meaning of the GDPR. The marketing agency that uses the portal is the controller for the personal data of its own end clients. We are happy to conclude a data processing agreement (DPA) with each agency on request.
For data we collect directly from you as an agency (account, payments, support) we act as controller.
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email address, password hash, role, language, avatar | Authentication, access control, personalisation |
| Company data | Company name, logo, colours, domain, contact person | White-label portal and invoicing |
| End client data | Company name, contact person, email, notes, subscription stage | CRM functionality within the portal |
| Content | Designs (Canva/Metricool), captions, files, posts, calendars | Content and scheduling management |
| Payment data | Stripe customer ID, subscription status, billing address, currency (EUR/USD) | Subscription billing via Stripe |
| OAuth tokens | Encrypted access and refresh tokens from Google, Microsoft, LinkedIn, Facebook, etc. | Authorised API calls on behalf of the connected user |
| Email data | Connected Gmail/Outlook/IMAP accounts, emails sent and received within the portal, signatures | Email functionality in the portal |
| Calendar data | Connected Google/Outlook calendars, available time slots, bookings via the public booking page | Appointment management and calendars |
| Insights data | Statistics from Google Analytics, Search Console and Business Profile as connected by the user | Dashboard widgets and AI summaries |
| Log data | IP address, timestamp, action, user agent | Security, debugging and audit log |
| Session data | JWT token, language cookie (portal_locale) | Staying signed in, remembering language preference |
| Marketing tracking | Cookieless tracker (anonymised), UTM parameters, signup quiz answers | Insight into which campaigns generate leads |
| Social session cookies | Auth cookies from LinkedIn, Facebook, TikTok, Instagram — only when you explicitly click "Connect" via the Senly Connector | Running automation features on behalf of your agency |
When you connect your Google account through Senly, the use of your Google data is governed by the Google API Services User Data Policy, including the Limited Use requirements. Below we explain exactly which Google services Senly accesses and what we do — and do not do — with your data.
userinfo.email — to display which Google account you are connected with.drive — to fetch and display your client folders (designs, files) within the client profile. Senly only writes when you explicitly perform an upload from the portal.analytics.readonly — read-only access to Google Analytics 4 reports for the property you select, to display them as dashboard widgets.webmasters.readonly — read-only access to Search Console statistics (clicks, impressions, positions, queries) for the site you select.business.manage — reading your own Google Business Profile statistics (search impressions, phone clicks, direction requests). Senly never modifies your Business Profile.gmail.send / gmail.modify (only if you connect Gmail) — to send and read emails from within the portal on behalf of the connected account.calendar (only if you connect Google Calendar) — to display available time slots on your public booking page and add bookings to your calendar.We use your Google data solely to deliver the Senly functionality you request:
You can disconnect in two ways:
Within the Senly Content Planner, an agency can connect its end-client's social media accounts to schedule and publish content on their behalf. Each connection uses the official OAuth flow or API of the respective platform, and any use of the obtained data is fully subject to the applicable Platform Developer Agreement (Meta Platform Terms, LinkedIn API Terms of Use, TikTok Developer Terms, X Developer Agreement, Pinterest Developer Guidelines, YouTube API Services Terms, Threads Platform Policy, Bluesky Terms, Mastodon API Terms) as well as the GDPR. Below we explain, per platform, which permissions we request, what we do and do not do with the resulting data, how long we retain it and how you can revoke it.
| Category | Examples | Purpose |
|---|---|---|
| Meta — Facebook Pages | pages_show_list, pages_read_engagement, pages_manage_posts, business_management | On behalf of the agency's client, show which Pages are managed, publish scheduled posts and display publication status. We do not read DMs, ads data or perform comment moderation. |
| Meta — Instagram (Business account linked to a Facebook Page) | instagram_basic, instagram_content_publish | Publish scheduled posts, reels or stories to the client's Instagram Business account and show the account in the connections list. We do not read DMs or the comment inbox. |
| Meta — Threads | threads_basic, threads_content_publish | Publish scheduled Threads posts on behalf of the connected account and display the profile name. We do not process replies, mentions or trending topics. |
| LinkedIn — personal profiles | openid, profile, w_member_social | Publish scheduled posts to the personal LinkedIn profile of the user who approved the connection. We do not read connections, inbox or feed. |
| LinkedIn — Company Pages (Community Management API) | w_organization_social, r_organization_social, rw_organization_admin | Publish scheduled posts to the client's LinkedIn Company Page (for which the connecting user is admin), display publication status and show aggregate post performance (impressions, clicks, engagement) to the agency as part of client reporting. We do not read personal profiles of followers or connections. Use of this data is subject to the <a href="https://legal.linkedin.com/api-terms-of-use" target="_blank" rel="noopener noreferrer">LinkedIn API Terms of Use</a> and the additional Marketing Developer Platform terms. |
| X (Twitter) | tweet.read, tweet.write, users.read, offline.access | Publish scheduled tweets on behalf of the connected account. We do not read DMs or follower lists. |
| TikTok | user.info.basic, video.publish, video.upload | Upload and publish scheduled videos to the connected TikTok Business account, and display the account name. We do not read personal feeds or DMs. |
pins:write, boards:read, user_accounts:read | Publish Pins to boards the user selected and display the account name. | |
| YouTube | youtube.upload, youtube.readonly | Upload scheduled videos to the connected YouTube channel and display the channel name. We do not read comments or viewer statistics beyond what you have published. |
| Bluesky | App password (created by you in Bluesky settings) | Publish scheduled posts to your Bluesky account via the AT Protocol. We store the app password encrypted and use it solely for publication. |
| Mastodon | Per-instance access token (via OAuth on your own instance) | Publish scheduled toots to your Mastodon account on the instance you specify. |
We use the obtained data solely to deliver the requested planner functionality to the agency that approved the connection:
https://app.senly.io/api/planner/webhooks/meta receives the signal and we remove all associated tokens, page metadata and publication data for the affected account within 30 days. A confirmation code is available on request.Senly uses the YouTube API Services for the YouTube integration in the Content Planner. By connecting your YouTube account through Senly, you agree that your use of YouTube data is subject to the YouTube Terms of Service and the Google Privacy Policy. Senly complies with the YouTube API Services Developer Policies, including the Limited Use requirements and the prohibition on unauthorized transfer of YouTube data.
youtube.upload (used only to upload the videos you schedule) and youtube.readonly (used only to display the channel name, avatar and public channel statistics in your reporting).In addition to the social media platforms and Google services in sections 3, 3b and 3c, Senly offers optional integrations with a range of external tools. Every integration is created by you explicitly via OAuth or an API key; we store tokens/keys encrypted (AES-256-GCM, per-tenant AAD) and use them only for the requested function. We never sell platform data, do not share it between tenants and do not train AI models on it.
Monday.com, ClickUp, Asana, Notion, Linear, Jira (Atlassian), Basecamp, Todoist, Teamwork, Trello, Wrike: connect via OAuth or API token to import your assigned tasks/issues as Senly tasks. We only read what the connecting user is allowed to see; we do not write tasks back unless you explicitly enable that.
Canva: fetch designs via OAuth to display them in the client profile. Figma, Adobe Express: connect design files. Google Drive, Dropbox, OneDrive, iCloud: optional connection to display client folders; we do not copy files to our own storage unless you explicitly upload.
Gmail (Google), Outlook (Microsoft Graph), IMAP/SMTP: connect via OAuth or username+password to send and read emails from the portal on behalf of the connected account. Google Calendar, Outlook Calendar: display available times on your public booking page and add bookings to the calendar. IMAP/SMTP passwords are stored encrypted.
Slack, Microsoft Teams, Discord: connect your workspace/server and pick a channel for notifications (e.g. new lead, published post). We only receive a webhook URL or OAuth token and post messages to the channels you choose; we do not read existing conversations.
HubSpot, Pipedrive, Salesforce, GoHighLevel, Typeform: optionally connect to import contacts and form submissions as leads into Senly. We only read the fields you select at contact/deal level and only write back if you explicitly activate a sync.
Moneybird, Xero, QuickBooks, Mollie: connect your accounting to display invoices and payments in Senly. We read invoice metadata (number, client, amount, status). Stripe: Senly uses Stripe for our own subscriptions and Stripe Connect for affiliate payouts (see section 8).
Mailchimp, Klaviyo: connect your audiences and campaigns so you get an overview in Senly. We only read aggregate figures and list names; we do not send emails through your account unless you activate a specific workflow.
Google Analytics (GA4), Google Search Console, Google Business Profile: see section 3 above for scopes and retention.
Metricool, Buffer, Hootsuite, Later, Sprout Social: optionally connect when using Senly alongside an existing planner. We only read what is needed to display your connected accounts and publications; we do not post through these tools without an explicit instruction.
You can disconnect each integration within Senly via Integrations or Manage connections. On disconnect the token/API key and cached metadata are removed immediately; historical sync records (e.g. imported tasks) remain until you delete them yourself. You can also always revoke access at the platform level (e.g. in the connected tool's account settings). For full deletion of stored data for a specific integration, contact info@senly.io.
When you install the optional Senly Connector Chrome extension and manually click "Connect" within a client profile, the extension reads the session cookies of the relevant social media platform (LinkedIn, Facebook, TikTok or Instagram) from your own browser and sends them encrypted to our server.
Senly offers AI-assisted features such as caption suggestions, brand checks, note suggestions and weekly Insights summaries. We use a tiered AI fallback ladder:
We send only the minimum data necessary to the AI provider to fulfil the request. AI summaries of your Insights data contain only numbers and top-N lists — no personal data of your end clients.
Agencies can optionally set their own Gemini API key in Integrations → AI; in that case the AI request goes directly via your own account.
Senly uses a proprietary cookieless visitor tracker on the marketing website (senly.io). It hashes IP addresses and User-Agent strings into a 24-hour identifier without storing personal data. We do not place third-party tracking cookies (Facebook Pixel, Google Ads, etc.) on the website.
When you sign up for a trial, we optionally ask about your role, challenge and platforms (signup quiz) to personalise your onboarding. These answers are stored in your own account and used to improve Senly's marketing — your personal answers are never shared publicly.
Agencies can submit content to their end clients for approval via a unique review link (senly.io/review/[token]). We do not store personal data of end clients who open this link — only an aggregate of approve/reject actions per token. We do not place tracking cookies on this page.
Subscriptions are billed via Stripe. Stripe is an independent controller for your payment data. We only receive a Stripe customer ID, invoice status and the chosen currency (EUR or USD, automatically detected based on your IP address and adjustable until the first payment).
For the affiliate programme Senly uses Stripe Connect to automatically process payouts to partners. Affiliates are paid directly from Stripe.
We share data only with sub-processors that are necessary for the service:
We never sell or rent personal data to third parties.
As a data subject you have the right under the GDPR to access, rectification, erasure, restriction, portability and objection. Please direct your request in the first instance to the agency you work with. Agencies can handle these requests via the portal or contact us at info@senly.io.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
In the event of a data breach that poses a risk to data subjects, we will inform the relevant agency without undue delay (within 24 hours of discovery). The agency is responsible for notifying the Data Protection Authority within 72 hours if required.
Our primary hosting and data storage runs via Railway in the United States. Some sub-processors (Stripe, Google, Microsoft, AI providers) also process data outside the EU. For these transfers outside the EU we rely on the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework. We keep track of which processor processes which data outside the EU and can explain this on request. A current overview of our sub-processors is available at /subverwerkers.
For privacy questions you can reach us via:
Social Media ToolsWe may amend this statement. For material changes we will inform agencies via the portal or by email. The date at the top indicates when the statement was last updated. We keep earlier versions internally for reference.