Privacy Policy — ElenaGiappone Posting

Last updated: July 2026

1. Introduction and scope

This Privacy Policy describes how personal data is processed in connection with the use of ElenaGiappone Posting (the “Service”), a web-based publishing tool that allows content creators to publish and schedule photo-carousel posts to their own TikTok profile. It explains what data the Service processes, on what legal basis, and how a creator can exercise their rights, including data deletion.

2. Data controller and contact details

The data controller is:

Luca Valotto Marketing Consulting LTD
CMS House, Third Floor, St. Peter’s Street
San Gwann, SGN2310, Malta

Contact email for any privacy-related matter and to exercise your rights:
lucavalottobusiness@protonmail.com

3. What data is processed and for what purposes

The Service processes only the data strictly necessary to let a creator publish content to their own TikTok profile. In particular:

a) Creator account information

When a creator connects their TikTok account through TikTok’s official Login Kit, the Service receives basic profile information (user.info.basic): the account’s TikTok identifier (open ID), display name (nickname) and avatar (profile picture).
Purpose: to identify the connected account and display it in the Service, so the creator can confirm they are publishing to the correct profile.

b) Authorization tokens

To publish on the creator’s behalf, the Service uses the access token and refresh token issued by TikTok upon authorization. These tokens authorize publishing to the creator’s own profile and identify the authorized session.
Purpose: to operate the Service (authenticate requests and publish content) on behalf of the creator who granted authorization.

c) Content published by the creator

The images and captions that the creator creates and chooses to publish, transmitted — at the creator’s explicit request and confirmation — to the creator’s own TikTok profile through TikTok’s Content Posting API.
Purpose: publishing and scheduling the creator’s own content on their own profile.

The Service does not use cookies or end-user tracking technologies, does not collect email addresses, telephone numbers or browsing data, does not process data of the creator’s audience, and does not build profiles of any person. No data is sold or shared for commercial purposes.

4. Legal basis for processing

The processing is based on the following legal bases pursuant to Regulation (EU) 2016/679 (“GDPR”):

  • Provision of the Service (Art. 6(1)(b) GDPR): processing of the account information, tokens and content is necessary to provide the publishing functionality that the creator has requested by connecting their account.
  • Legitimate interest (Art. 6(1)(f) GDPR): for the secure operation, maintenance and integrity of the Service.

5. Recipients of the data

The Service operates through the official TikTok APIs. Account information and published content are processed on the TikTok platform, operated for users of the European Economic Area by TikTok Technology Limited (10 Earlsfort Terrace, Dublin 2, D02 T380, Ireland), in its capacity as provider of the platform and its interfaces (APIs). Published content resides on TikTok’s systems and is subject to TikTok’s own privacy policy, available at https://www.tiktok.com/legal/page/eea/privacy-policy/en.

The data controller does not transmit the data to other recipients for commercial purposes, does not sell it and does not transfer it to third parties. Any technical providers (for example, the hosting service for the website on which this Policy is published) process data solely as processors and within the limits of the data controller’s instructions.

6. Data transfers and retention

Transfers. Content and account data handled by TikTok’s infrastructure may involve transfers to countries outside the European Economic Area. Such transfers take place within the framework of the safeguards adopted by TikTok (including Standard Contractual Clauses approved by the European Commission), as described in TikTok’s privacy policy.

Retention.

  • Tokens are retained only for as long as the connection between the creator’s account and the Service is active. When the creator revokes access, the tokens become invalid and are deleted.
  • Published content remains on the creator’s TikTok profile until the creator decides to remove it; the original copies are stored locally by the creator.

Data is not retained longer than necessary for the purposes indicated above.

7. Rights of the data subject

The creator whose data is processed may exercise, pursuant to Articles 15 to 22 of the GDPR, the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), objection (Art. 21) and portability (Art. 20). To exercise these rights, write to lucavalottobusiness@protonmail.com. The data controller will respond without undue delay and within the timeframes provided by the GDPR.

8. Data deletion instructions

A creator can obtain deletion of the data processed by the Service in the following ways:

  1. Revoke access on TikTok (fastest way): in the TikTok app, go to Settings and privacy → Security & permissions → Manage app permissions, and remove the authorization granted to ElenaGiappone Posting. Once access is revoked, the tokens held by the Service become invalid and are deleted, and the Service can no longer access the account.
  2. Request to the data controller: you may request deletion of your data held by the Service by writing to lucavalottobusiness@protonmail.com. The data controller will carry out the deletion without undue delay and, in any case, within 30 days.
  3. Content already published on TikTok can be removed by the creator directly from their TikTok profile, using TikTok’s own tools.

This page constitutes the data deletion instructions for the Service.

9. Complaint to the supervisory authority

A data subject who believes that the processing of their data infringes the GDPR has the right to lodge a complaint with the competent supervisory authority. Since the data controller is established in Malta, the relevant authority is:

Information and Data Protection Commissioner (IDPC)
Floor 2, Airways House, High Street, Sliema, SLM 1549, Malta
Website: https://idpc.org.mt — Email: idpc.info@idpc.org.mt

This is without prejudice to the right to contact the supervisory authority of your Member State of residence in the European Union.

10. Changes to this Policy

This Policy may be updated to reflect regulatory or operational changes. The updated version will always be available at the address where it is published, with the date of the last update shown at the top.

Last updated: July 2026