Privacy Policy
Draft for legal review, not yet in effect.
1. Who We Are and What This Policy Covers
INFLYN PTY LTD, ABN 52 682 983 197 ("Inflyn", "we", "us") provides the Inflyn distribution platform (the "Service") to businesses ("Customers"). Customers use the Service to publish videos to their own social media accounts and to analyze how those videos perform.
We handle personal information in two roles:
- As a controller, for people who visit our website or contact us, for contacts at our Customers, and for the account and security records of people who use the Service ("Users"). This policy describes that processing.
- As a processor for our Customers, for personal information contained in the data a Customer puts into or collects through the Service, such as the social media accounts it connects and the content it publishes. We process that information only on the Customer's instructions under our agreement with it, and the Customer's own privacy policy governs it. If your information is in a Customer's data, please contact that Customer; we will help it respond.
This policy covers the Service hosted in Japan. The service for mainland China is operated separately and has its own privacy policy.
2. Information We Collect
- User accounts: name, work email address, role and store scope in each workspace, language preference and last sign-in time. Passwords are stored only as Argon2id hashes; we never store or see them in readable form. One-time activation and password-reset links are stored only as hashes and expire.
- Security records: session identifiers (stored only as hashes), counts of failed sign-ins by email address and by source IP address (used to block password-guessing attempts), a record of account and permission changes, and a record of each video download (who, which video, when).
- Connected account information: received from social media platforms with the account owner's authorization. See Section 4.
- Content and publishing data: videos and captions delivered to a workspace, publishing schedules, the result of each publication and the link to the published post, and performance figures such as views, likes, comments, shares and completion rate, either imported by Users or retrieved from the platform.
- Communications: your name, email address, company and message when you contact us.
- Device information: IP address and browser type recorded in server logs.
Cookies and similar technologies. The Service uses one strictly necessary cookie to keep you signed in; page scripts cannot read it, and it expires after 14 days or when you sign out. Your language and last-used workspace are stored in your browser's local storage. The Service does not use advertising or cross-site tracking cookies. Service pages load fonts from Google Fonts, which receives your IP address when the fonts load; see Google's privacy policy. Our website sets no cookies, runs no analytics and loads nothing from other sites.
3. How We Use Information
- To provide the Service: signing Users in, applying roles and store scopes, publishing content on the Customer's instructions, and showing publishing status and performance.
- To keep the Service secure: detecting and blocking misuse, investigating incidents, and keeping records of account changes.
- To communicate: account activation and password-reset emails, service notices and support.
- To improve our services: using statistics that are aggregated and do not identify any Customer, individual or connected account.
- To meet legal obligations.
Where the GDPR or similar laws apply, we rely on performance of our contract, our legitimate interests in running and securing the Service, compliance with legal obligations, and consent where it is required.
We do not sell personal information and do not use it for targeted advertising.
4. Information from TikTok and Other Connected Platforms
What we receive. A Customer connects a TikTok account when the account owner signs in with TikTok and approves the permissions shown on TikTok's authorization screen. With that approval we receive the account's TikTok open ID and display name, and an access token and refresh token that let the Service upload and publish videos to that account. We never receive the account's TikTok password, and we do not request access to the account's messages, followers or other content.
How we use it. Only to show which account is connected, to publish the videos and captions that the Customer's Users schedule for that account, and to confirm the result of each post.
How we protect it. Tokens are encrypted at rest with AES-256-GCM, using a key that is kept separately from the database. They are never displayed in the Service or returned by its interfaces; only the Service's internal processes that publish content or renew the authorization can decrypt them.
Who we share it with. No one, except our hosting provider acting on our instructions and authorities where the law requires it. We do not use information from TikTok for advertising or to build profiles.
How long we keep it. Tokens are kept while the account stays connected and are deleted as soon as the Customer removes the account from its workspace, and in any case when the Customer's subscription ends (see Section 7). If the owner revokes access on TikTok, the tokens stop working and the account appears as expired in the Service until it is authorized again or removed.
How to disconnect. A Customer's workspace administrator can remove the account in the Service. The account owner can also revoke access at any time in the TikTok app under Settings and privacy, Security, Manage app permissions, by selecting Inflyn and removing access. Menu names can vary between app versions.
When we connect further platforms, we will add them to this section before they become available.
5. How We Share Information
- Service providers that process information on our behalf under contract: Google Cloud (hosting, database, storage and key management in Tokyo, Japan) and Google Fonts (font delivery).
- Social media platforms, on the Customer's instructions: publishing sends the scheduled video and caption to the selected platform.
- Within a Customer's workspace: Users' activity is visible to that workspace's administrators, and to Inflyn personnel assigned to support that Customer.
- For legal reasons: to comply with law, respond to lawful requests, or protect the rights and safety of our Customers, Users, Inflyn or others.
- In a business transfer: as part of a merger, acquisition or sale of assets, subject to this policy.
6. Where Information Is Stored
The information covered by this policy is stored in Japan (Google Cloud, Tokyo region). Each Customer workspace keeps its data in its hosting region; the service for mainland China does not share databases with this Service. The European Commission and the United Kingdom recognize Japan as providing adequate protection for personal data. When Inflyn personnel access information from outside Japan, for example to support a Customer, we protect that access with standard contractual clauses or other approved safeguards where the law requires them.
7. How Long We Keep Information
We keep personal information only as long as needed for the purposes described above:
- User accounts: while the User has access to the Service; removed Users' account records are deleted no later than the Customer data.
- Records of account changes and downloads: until the Customer data is deleted, so that questions about who did what can be answered.
- Customer data: during the subscription and for 30 days after it ends so that the Customer can export it; we then delete it within 30 days, except where the law requires us to keep it. Backups are overwritten on their normal cycle.
- Communications: as long as needed to answer you.
8. Security
We protect information with measures appropriate to the risk, including encryption in transit, encryption of platform tokens at rest, hashing of passwords and session identifiers, role- and store-based access control, limits on repeated sign-in attempts, records of account changes, and separation of data by hosting region. No method of transmission or storage is completely secure; if a breach affects your personal information, we will notify you and the relevant authorities as the law requires.
9. Your Rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to restrict or object to how we use it, and to withdraw consent. You may also complain to your data protection authority. To exercise these rights, email operation@inflyn.com; we respond within the time the law requires. If your information is part of a Customer's data, please contact that Customer; we will help it respond.
We do not sell or share personal information for cross-context behavioral advertising, as those terms are defined under California law.
10. Children
The Service is for businesses and is not directed to children. Users must be at least 18 years old. If we learn that we have collected information from a child, we will delete it.
11. Changes to This Policy
We will post any change here with a new "Last updated" date. If a change is material, we will also notify Customers by email or in the Service before it takes effect.
12. Contact
INFLYN PTY LTD, ABN 52 682 983 197, operation@inflyn.com.