GDPR Compliance
We are committed to transparency and the protection of your personal data in accordance with the General Data Protection Regulation (EU).
Last Updated: December 19, 2025
1. Data Controller & Processor
Tareno acts as both a Data Controller and a Data Processor depending on the context of the data being processed.
- Controller: For account information, billing details, and direct communications with you.
- Processor: For social media content, analytics data, and media files you upload to our platform for scheduling.
2. Data We Collect
To provide our Social Media Management services, we collect:
- Account Data: Name, email address, password (hashed), and billing information.
- Social Data: OAuth tokens for connected platforms (Instagram, TikTok, YouTube, etc.), profile names, and avatars. We do not store your social media passwords.
- Content Data: Images, videos, and captions you upload for scheduling.
- Usage Data: Logs of how you interact with our dashboard to improve system performance and security.
3. Your Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
You can request a copy of all personal data we hold about you.
Right to Erasure
You can request complete deletion of your account and associated data ("Right to be Forgotten").
Right to Rectification
You can update inaccurate or incomplete personal information at any time via Settings.
Right to Portability
You can request your data in a structured, commonly used, and machine-readable format.
4. Data Storage & Security
Your data is stored securely on servers located within the European Union (EU) or in countries with adequacy decisions. We utilize industry-standard encryption (AES-256) for data at rest and TLS 1.3 for data in transit.
Our database providers (Supabase/PostgreSQL) are fully GDPR compliant. We perform regular security audits to ensure the integrity of our systems.
5. Subprocessors
We use trusted third-party services to operate our platform. These subprocessors are bound by Data Processing Agreements (DPAs) to uphold GDPR standards.
- Vercel: Hosting and Edge Network.
- Supabase: Database and Authentication.
- Stripe: Payment processing (if applicable).
- Google/Meta/TikTok/etc: API interactions (only when you explicitly connect an account).
Contact Our Data Protection Officer
If you have any questions about this policy or wish to exercise your rights, please contact our DPO at:
privacy@tareno.co