smarter Social Media Planer
Privacy Policy
Privacy Policy
1. Controller
The controller responsible for data processing is:
Hefti OG
Schillerstraße 53, 6700 Bludenz, Österreich
Email: mail@hefti.at
2. What data we process
- Master & contact data (e.g. name, email address) to provide your account
- Usage data (e.g. content you create, settings, login times)
- Payment data to handle paid plans (via the respective payment provider)
- Device & notification data (e.g. push subscription, browser/device info), only if you enable push notifications
- Media data: images/videos you upload as well as AI-generated images you use in the app
- Social media connection data: if you connect a Facebook/Instagram account, the ID and name of your Facebook Page and Instagram business account, a user ID assigned by Meta, access tokens, and the reach/engagement/follower statistics we retrieve (see section 4b)
3. Purposes & legal bases
Processing is carried out to perform the contract (Art. 6(1)(b) GDPR), to comply with legal obligations (lit. c) and on the basis of legitimate interests (lit. f), e.g. for the security and improvement of the service.
3a. Push notifications
If you enable notifications, we store the subscription data technically required for this (push endpoint and keys) as well as a browser/device identifier for device management. The basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time in the settings or on your device.
3b. Cookies and local storage (Sec. 165(3) TKG 2021, Austria)
Technically necessary storage (no consent required, Sec. 165(3) TKG 2021):
- Application session cookie: keeps you logged in and becomes invalid when you close the browser or after the session expires.
- Your browser's local storage (localStorage): stores your app settings (e.g. light/dark mode, view states) solely on your device.
- Service worker cache (PWA): stores program files locally so the app loads faster and works offline.
Referral and campaign cookies (only set if you reach us via a referral or campaign link):
- "sp_ref": remembers the referral code so a referral can be attributed correctly (lifetime 30 days).
- "sp_src": remembers the source/campaign of your visit (lifetime 30 days).
- "sp_refclk_...": prevents the same click from being counted multiple times (lifetime 1 day).
These cookies are set exclusively by us (first-party) and are not used for cross-device or cross-site tracking by third parties. The legal basis is our legitimate interest in a functioning referral program (Art. 6(1)(f) GDPR). You can delete these cookies at any time in your browser settings.
Marketing cookies (only after your explicit consent via the notice on our home page):
- "sp_consent": stores your decision about that notice so we do not have to ask again on every visit (lifetime 6 months). This cookie is required to honour your choice and is also set if you decline.
- "_fbc": links your visit to the advertisement through which you reached us (lifetime 90 days). Only set if you actually arrive via such an ad.
- "_fbp": a random visitor identifier assigned by us so that several page views from the same browser can be linked (lifetime 90 days).
The legal basis is your consent (Art. 6(1)(a) GDPR, Sec. 165(3) TKG 2021, Austria). If you decline or withdraw, "_fbc" and "_fbp" are deleted and no measurement takes place. See section 4c for details.
You decide per category (necessary, statistics, marketing) in the notice on our home page and can change your choice at any time via the cookie icon at the bottom left. We record that you made a choice for evidence purposes (Art. 7(1) GDPR): stored are the selection, the time and the version of these texts, NOT your IP address.
External content (demo video):
A demo video may be embedded on our home page. If it is stored as a YouTube or Vimeo video, it is not loaded automatically: at first only a placeholder appears, and only when you actively click "Load video" is the video loaded from the respective provider (YouTube/Google or Vimeo, USA). In doing so, data (including your IP address) is transmitted to the provider; the legal basis is your consent via the click (Art. 6(1)(a) GDPR). A self-hosted video is delivered directly from our server without third parties.
3d. Our own reach measurement (no cookies)
To find out how our site is used, we count visits ourselves. No analytics service and no third-party script is involved.
- Nothing is stored on your device and nothing is read from it.
- What is recorded: the page opened, the referring page, the time spent, whether the device is a phone or a computer, and, where present, the campaign parameter in the address.
- To tell visits apart, the server calculates a one-way check value from your IP address and your browser identifier together with a salt that changes DAILY and is stored nowhere. Your IP address itself is never stored. On the following day the same device produces a different value, so you cannot be recognised across days, not even by us.
- Legal basis: our legitimate interest in understanding and improving the use of our site (Art. 6(1)(f) GDPR). Because no information is stored on or read from your device, no consent under Sec. 25 TDDDG / Sec. 165(3) TKG 2021 is required.
- The data is aggregated and evaluated only in summary form. It is not passed on.
Where an account came from
When you create an account, we additionally record the address through which you reached us. That is the address you opened the site with, including any campaign parameters it contains (utm_source, utm_medium, utm_campaign, utm_content, utm_term), any click identifier from the advertising network, the referring page, and whether the device was a phone or a computer.
- Purpose: we want to know which of our ads actually lead to customers, and which ones we can switch off.
- Legal basis: our legitimate interest in advertising our offering economically (Art. 6(1)(f) GDPR).
- Your IP address is NOT part of this. These details are not passed on and are deleted together with the account.
3c. Access by our team (support, optimization & security)
Staff with administrator rights may, to the extent necessary, access the content stored in your account (e.g. your content library with ideas and posts). Such access takes place exclusively for the following purposes: handling support and help requests, fixing technical faults and errors, ensuring proper operation, improving and optimizing our service, and maintaining security (e.g. checks in the event of justified suspicion of abuse). Access is limited to a small group of authorized persons bound to confidentiality, is read-only, and is logged together with the reason for access. We do not use your content for unrelated purposes and do not pass it on to third parties. The legal basis is our legitimate interest in a secure, stable and continuously improved service and in functioning support (Art. 6(1)(f) GDPR); insofar as access is necessary to handle your request, additionally the performance of the contract (Art. 6(1)(b) GDPR).
4. Disclosure to third parties
Data is only disclosed insofar as this is necessary to perform the contract (e.g. hosting, external storage of media files, payment processing, AI services for text and image generation) or is required by law. Contracts pursuant to Art. 28 GDPR exist with processors.
4a. Storage of media files (images/videos)
Images/videos you upload and AI-generated images/videos are stored on our behalf in object storage within the EU (processor located in Germany/the EU). Delivery takes place via publicly accessible, non-guessable links (random file names); this is technically required in order to display the media in the app and publish it on the social media networks you choose. Please only upload content that is intended for publication. For faster display, small preview images may additionally be stored on our server.
If you connect an external cloud source (e.g. Google Drive or OneDrive), the files remain in your own cloud; we only store the shareable link you have released.
For AI image generation, we transmit the necessary inputs to an AI provider (OpenAI, USA); the third-country transfer is safeguarded by standard contractual clauses / the EU-US Data Privacy Framework.
4b. Connecting your social media accounts (Meta: Facebook & Instagram)
When you connect your Facebook Page and/or Instagram business account to the app, we process the data required for this via Meta's official programming interfaces (Facebook Graph API / Instagram Graph API):
- Account connection data: the ID and name of your Facebook Page, the ID of your connected Instagram business account, a user identifier assigned by Meta (app-scoped user ID) and the access tokens technically required for the connection. Access tokens are stored securely and used exclusively to maintain the connection you requested.
- Publishing: content you create and approve in the app (feed posts, carousels, reels, stories) is published on your behalf to the accounts you select.
- Statistics/insights: at your request we retrieve reach, engagement and follower metrics as well as account- and post-related analytics in order to display them to you in the app.
We use this data exclusively to provide the functions you actively use (planning, publishing, analyzing) and do not pass it on to third parties for advertising purposes. The legal basis is the performance of the usage contract concluded with you (Art. 6(1)(b) GDPR).
You can end the connection at any time: in the app settings, in the security settings of your Facebook account (section "Logged in with Facebook" or "Business integrations") or by requesting data deletion. If you disconnect, we delete or block the stored access tokens. You can also trigger deletion of the Meta connection data stored with us at any time via our data deletion page (accessible via the "Data deletion & privacy" link); there you will receive a confirmation code for tracking.
The platform provider is Meta Platforms Ireland Ltd. (Ireland); processing in the USA cannot be ruled out and is safeguarded by appropriate guarantees (EU standard contractual clauses or the EU-US Data Privacy Framework).
4c. Measuring our advertising (Meta Conversions API)
We run ads on Facebook and Instagram. So that we can see whether those ads lead to visits and sign-ups, we report certain events to Meta.
- Events reported: opening our home page ("PageView") and the successful completion of a registration ("Lead").
- Data transmitted: your IP address, your browser identifier (user agent), the address of the page you opened, the attribution identifiers "_fbc"/"_fbp" and, on registration, your email address exclusively as a cryptographic check value (SHA256 hash). Your email address is not transmitted in plain text.
- How it is transmitted: the report is sent from our server via Meta's "Conversions API". No Meta script runs in your browser.
- Purpose: measuring the success of our ads, optimising them, and the formation of target groups by Meta.
- Legal basis: exclusively your consent (Art. 6(1)(a) GDPR). Without consent nothing at all is reported.
- Recipient: Meta Platforms Ireland Ltd., Ireland. For the collection and transmission, we and Meta are joint controllers within the meaning of Art. 26 GDPR; Meta provides the essential terms of that arrangement at https://www.facebook.com/legal/controller_addendum. Meta is solely responsible for any further processing.
- Third country transfer: processing in the USA cannot be ruled out; it is safeguarded by EU standard contractual clauses and/or the EU-US Data Privacy Framework.
- Storage period: the events are processed and deleted by Meta according to Meta's own rules; the attribution identifiers in your browser expire after 90 days.
- Withdrawal: you can withdraw your consent at any time with effect for the future. Click the cookie icon at the bottom left of our public pages and switch "Marketing" off, or choose "Just the essentials" in the notice. Any identifiers already set are deleted immediately. Meta's information is available at https://www.facebook.com/privacy/policy.
5. Storage period
We store personal data only for as long as is necessary for the stated purposes or as long as statutory retention periods exist.
5a. Data backups
For failover protection we automatically create a daily backup of the database. These backups are usually retained for seven (7) days and then deleted automatically. They serve solely for recovery in the event of a fault or emergency and are subject to the same technical and organizational protection measures as the live data. After your data is deleted, it may still be contained in backups created in the meantime for up to seven (7) days before the respective backup is deleted on schedule. If you need your own copy of your data beyond this, you can use the export function in the application at any time.
6. Your rights
You have the right to information, rectification, erasure, restriction of processing, data portability and objection. You also have the right to lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at).
7. Contact
For data protection inquiries you can reach us at: mail@hefti.at
Last updated: 07.09.2026
← Back