smarter Social Media Planer
Privacy Policy
Privacy Policy
1. Controller
The controller responsible for data processing is:
Hefti OG
Schillerstraße 53, 6700 Bludenz, Österreich
Email: mail@hefti.at
2. What data we process
- Master & contact data (e.g. name, email address) to provide your account
- Usage data (e.g. content you create, settings, login times)
- Payment data to handle paid plans (via the respective payment provider)
- Device & notification data (e.g. push subscription, browser/device info), only if you enable push notifications
- Media data: images/videos you upload as well as AI-generated images you use in the app
- Social media connection data: if you connect a Facebook/Instagram account, the ID and name of your Facebook Page and Instagram business account, a user ID assigned by Meta, access tokens, and the reach/engagement/follower statistics we retrieve (see section 4b)
3. Purposes & legal bases
Processing is carried out to perform the contract (Art. 6(1)(b) GDPR), to comply with legal obligations (lit. c) and on the basis of legitimate interests (lit. f), e.g. for the security and improvement of the service.
3a. Push notifications
If you enable notifications, we store the subscription data technically required for this (push endpoint and keys) as well as a browser/device identifier for device management. The basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time in the settings or on your device.
3b. Cookies and local storage (Sec. 25 TDDDG)
Technically necessary storage (no consent required, Sec. 25(2) TDDDG):
- Application session cookie: keeps you logged in and becomes invalid when you close the browser or after the session expires.
- Your browser's local storage (localStorage): stores your app settings (e.g. light/dark mode, view states) solely on your device.
- Service worker cache (PWA): stores program files locally so the app loads faster and works offline.
Referral and campaign cookies (only set if you reach us via a referral or campaign link):
- "sp_ref": remembers the referral code so a referral can be attributed correctly (lifetime 30 days).
- "sp_src": remembers the source/campaign of your visit (lifetime 30 days).
- "sp_refclk_...": prevents the same click from being counted multiple times (lifetime 1 day).
These cookies are set exclusively by us (first-party) and are not used for cross-device or cross-site tracking by third parties. The legal basis is our legitimate interest in a functioning referral program (Art. 6(1)(f) GDPR). You can delete these cookies at any time in your browser settings.
External content (demo video):
A demo video may be embedded on our home page. If it is stored as a YouTube or Vimeo video, it is not loaded automatically: at first only a placeholder appears, and only when you actively click "Load video" is the video loaded from the respective provider (YouTube/Google or Vimeo, USA). In doing so, data (including your IP address) is transmitted to the provider; the legal basis is your consent via the click (Art. 6(1)(a) GDPR). A self-hosted video is delivered directly from our server without third parties.
3d. Our own reach measurement (no cookies)
To find out how our site is used, we count visits ourselves. No analytics service and no third-party script is involved.
- Nothing is stored on your device and nothing is read from it.
- What is recorded: the page opened, the referring page, the time spent, whether the device is a phone or a computer, and, where present, the campaign parameter in the address.
- To tell visits apart, the server calculates a one-way check value from your IP address and your browser identifier together with a salt that changes DAILY and is stored nowhere. Your IP address itself is never stored. On the following day the same device produces a different value, so you cannot be recognised across days, not even by us.
- Legal basis: our legitimate interest in understanding and improving the use of our site (Art. 6(1)(f) GDPR). Because no information is stored on or read from your device, no consent under Sec. 25 TDDDG / Sec. 165(3) TKG 2021 is required.
- The data is aggregated and evaluated only in summary form. It is not passed on.
Where an account came from
When you create an account, we additionally record the address through which you reached us. That is the address you opened the site with, including any campaign parameters it contains (utm_source, utm_medium, utm_campaign, utm_content, utm_term), any click identifier from the advertising network, the referring page, and whether the device was a phone or a computer.
- Purpose: we want to know which of our ads actually lead to customers, and which ones we can switch off.
- Legal basis: our legitimate interest in advertising our offering economically (Art. 6(1)(f) GDPR).
- Your IP address is NOT part of this. These details are not passed on and are deleted together with the account.
3c. Access by our team (support, optimization & security)
Staff with administrator rights may, to the extent necessary, access the content stored in your account (e.g. your content library with ideas and posts). Such access takes place exclusively for the following purposes: handling support and help requests, fixing technical faults and errors, ensuring proper operation, improving and optimizing our service, and maintaining security (e.g. checks in the event of justified suspicion of abuse). Access is limited to a small group of authorized persons bound to confidentiality, is read-only, and is logged together with the reason for access. We do not use your content for unrelated purposes and do not pass it on to third parties. The legal basis is our legitimate interest in a secure, stable and continuously improved service and in functioning support (Art. 6(1)(f) GDPR); insofar as access is necessary to handle your request, additionally the performance of the contract (Art. 6(1)(b) GDPR).
4. Disclosure to third parties
Data is only disclosed insofar as this is necessary to perform the contract (e.g. hosting, external storage of media files, payment processing, AI services for text and image generation) or is required by law. Contracts pursuant to Art. 28 GDPR exist with processors.
4a. Storage of media files (images/videos)
Images/videos you upload and AI-generated images/videos are stored on our behalf in object storage within the EU (processor located in Germany/the EU). Delivery takes place via publicly accessible, non-guessable links (random file names); this is technically required in order to display the media in the app and publish it on the social media networks you choose. Please only upload content that is intended for publication. For faster display, small preview images may additionally be stored on our server.
If you connect an external cloud source (e.g. Google Drive or OneDrive), the files remain in your own cloud; we only store the shareable link you have released.
For AI image generation, we transmit the necessary inputs to an AI provider (OpenAI, USA); the third-country transfer is safeguarded by standard contractual clauses / the EU-US Data Privacy Framework.
4b. Connecting your social media accounts (Meta: Facebook & Instagram)
When you connect your Facebook Page and/or Instagram business account to the app, we process the data required for this via Meta's official programming interfaces (Facebook Graph API / Instagram Graph API):
- Account connection data: the ID and name of your Facebook Page, the ID of your connected Instagram business account, a user identifier assigned by Meta (app-scoped user ID) and the access tokens technically required for the connection. Access tokens are stored securely and used exclusively to maintain the connection you requested.
- Publishing: content you create and approve in the app (feed posts, carousels, reels, stories) is published on your behalf to the accounts you select.
- Statistics/insights: at your request we retrieve reach, engagement and follower metrics as well as account- and post-related analytics in order to display them to you in the app.
We use this data exclusively to provide the functions you actively use (planning, publishing, analyzing) and do not pass it on to third parties for advertising purposes. The legal basis is the performance of the usage contract concluded with you (Art. 6(1)(b) GDPR).
You can end the connection at any time: in the app settings, in the security settings of your Facebook account (section "Logged in with Facebook" or "Business integrations") or by requesting data deletion. If you disconnect, we delete or block the stored access tokens. You can also trigger deletion of the Meta connection data stored with us at any time via our data deletion page (accessible via the "Data deletion & privacy" link); there you will receive a confirmation code for tracking.
The platform provider is Meta Platforms Ireland Ltd. (Ireland); processing in the USA cannot be ruled out and is safeguarded by appropriate guarantees (EU standard contractual clauses or the EU-US Data Privacy Framework).
5. Storage period
We store personal data only for as long as is necessary for the stated purposes or as long as statutory retention periods exist.
5a. Data backups
For failover protection we automatically create a daily backup of the database. These backups are usually retained for seven (7) days and then deleted automatically. They serve solely for recovery in the event of a fault or emergency and are subject to the same technical and organizational protection measures as the live data. After your data is deleted, it may still be contained in backups created in the meantime for up to seven (7) days before the respective backup is deleted on schedule. If you need your own copy of your data beyond this, you can use the export function in the application at any time.
6. Your rights
You have the right to information, rectification, erasure, restriction of processing, data portability and objection. You also have the right to lodge a complaint with a data protection supervisory authority.
7. Contact
For data protection inquiries you can reach us at: mail@hefti.at
Last updated: 08.10.2026
← Back