Hakuya Scheduler
Privacy Notice
Effective 18 July 2026. Clawd Industries AS, org. 937378246, Trondheim, Norway, is the controller for Hakuya Scheduler account administration and service operations. Contact: sales@hakuya.io. Client agreements may assign controller and processor roles differently for client-supplied content.
Data we use
We process client user and organization identifiers, authorization roles, validated timezone, TikTok account identifier and nickname, granted scopes, encrypted access and refresh tokens, creator capabilities, post media and captions, publishing settings and approvals, TikTok status and identifiers, public profile and video analytics, revocation status, and sanitized security events. The OAuth code is never persisted.
Purposes and legal basis
We use this data to connect an authorized account, schedule and publish approved content, show status and analytics, secure and audit the service, handle disconnects, and meet legal obligations. Processing is based on providing the contracted service, legitimate interests in security and reliability, and legal obligations where applicable.
Recipients and locations
TikTok receives authorization, account, media, settings, and publishing requests needed for the selected features. Cloudflare R2 stores delivery and source-library media. The private scheduling application runs on Hakuya-controlled infrastructure and is reachable through Tailscale. Hostinger provides DNS administration but does not host Scheduler page content. Google advertising scripts are disabled on Scheduler, Terms, Privacy, Legal, OAuth callback, and OAuth result surfaces.
These providers may process data outside Norway or the EEA under their own service terms and transfer mechanisms. We do not sell Scheduler data.
Retention
- OAuth code: never persisted.
- OAuth state: one-time use, maximum ten minutes.
- TikTok tokens: only while connected, then erased locally on disconnect or revocation.
- TikTok delivery copy: deleted no later than seven days after success, final failure, cancellation, or disconnect.
- Post content, settings, status, and publish metadata: removed or redacted no later than 30 days after terminal status.
- Analytics cache: maximum one hour and cleared on disconnect.
- Sanitized security logs: seven days and exclude callback queries, codes, tokens, captions, and media content.
- Reusable source-library media: until the client deletes it or the managed-service relationship ends.
- Published TikTok content: remains on TikTok until the user deletes it there.
The routine fleet backup does not include the live Scheduler database. A protected pre-upgrade database dump may be retained for disaster rollback; the planned initial dump predates TikTok connections and contains no TikTok account data.
Revocation and deletion
Disconnecting disables the integration, stops new jobs, handles queued work, attempts TikTok revocation, removes local tokens even if remote revocation fails, clears cached analytics, and deletes unneeded delivery objects. If remote revocation fails, the user is directed to TikTok settings. Disconnecting does not remove posts already published on TikTok.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may complain to the Norwegian Data Protection Authority. Contact sales@hakuya.io. We may need to verify identity and organizational authority before acting.