OrbVora Publishing — Privacy Policy
Effective date: 9 October 2026
1. Controller and scope
The controller for the OrbVora publishing integration is Luciano Nery, Via per Vobarno, 3, Brescia, Italia. For privacy questions or requests, email social@orbvora.com or call +39 320 834 5674.
This policy covers the OrbVora workspace in the self-hosted Postiz service at https://social.leonessadigital.com and its social-platform connections. It covers invited operators, connected account data and personal information included in submitted content. The OrbVora game's own privacy notice is separate.
2. Information processed
We process the information needed to operate the publishing workflow:
| Information | Examples and purpose |
|---|---|
| Operator account and access information | Email, name, workspace membership, authentication records and API credentials, to identify authorized operators and control access. |
| Connected account information | Platform account identifiers, display names, handles, avatars, selected channels, granted permissions, access tokens and refresh tokens, to maintain authorized connections. |
| Publishing content and instructions | Uploaded videos and images, captions, settings, drafts, destination accounts and scheduled times, to prepare and deliver posts. Content may contain names, faces, voices or game handles. |
| Results and platform data | Post identifiers, links, status and error messages; available account or post analytics when requested through supported features. |
| Technical and support information | IP addresses, request and security logs, browser information, authentication cookies or similar session storage, and correspondence about support or privacy requests. |
Platform information comes from the account you connect and the platform's APIs. Content and publishing instructions come from authorized operators or their authorized automation. Technical information comes from requests to the service. We do not need your social-platform password for an OAuth connection: authenticate with the platform itself.
3. Purposes and legal bases
We use this information to control workspace access, maintain account connections, carry out publishing instructions, show results, provide requested analytics, resolve errors and answer support or privacy requests.
Our legitimate interests are securely operating OrbVora's internal publishing workflow, preventing misuse and maintaining reliable service. We limit access and data collection to what those tasks require. Where a processing activity is necessary to provide a service under an agreement with you, we rely on performance of that agreement. We rely on a legal obligation where applicable law requires processing or retention. If an optional activity requires consent, we ask separately and you can withdraw it.
Platform OAuth approval controls access to that platform; it does not replace the legal basis required for processing another person's information. Operators must have an appropriate basis for including personal information in content submitted for publication. Providing connection information is necessary to use the associated platform features; declining access leaves those features unavailable.
The current publishing workflow does not make automated decisions about individuals that produce legal or similarly significant effects.
4. Access, recipients and publication
Authorized OrbVora workspace members and service administrators may access information where needed to operate and support the service. The workspace shares infrastructure with other Postiz workspaces; privileged infrastructure administrators have technical access. Workspace membership limits ordinary application access.
We send selected content, captions, settings and authorization data to the platform you instruct us to use. Platforms process that information under their own terms and privacy policies. Posts become visible according to the destination settings, and public content may be copied or shared by others.
Media delivery can use HTTPS links accessible to a platform. Anyone who obtains an accessible media URL may be able to retrieve the file even before the related post is published. Do not upload confidential material expecting that a draft or a scheduled post makes its source file private.
Infrastructure and communication providers process information needed to provide hosting, network delivery, security and email. The publishing application, databases and uploaded media run on operator-managed infrastructure. Encrypted recovery copies are also stored on a separate OVH-hosted server. Cloudflare provides public-page hosting, network delivery and security, and Zoho Mail provides email. Social platforms and these providers may use infrastructure in several countries; their own privacy notices describe their processing arrangements.
We do not sell connected account data. The integration does not use it for advertising or training general-purpose AI models. An optional AI-assisted editing feature would require a separate disclosure of its provider and data flow before activation.
5. International processing
Social platforms and infrastructure providers may process information outside the European Economic Area under their own processing arrangements. Their privacy notices describe the relevant locations and safeguards. Where we arrange a transfer that requires safeguards, it must have an applicable adequacy decision or appropriate safeguards, such as Standard Contractual Clauses, before it takes place. Contact us for information about a particular recipient or transfer.
6. Retention and deletion
We retain account and workspace information while access is needed. Connection tokens are retained while the connection is authorized and needed. Drafts and source media are retained while needed for their publishing purpose; publishing records and support information are retained only as needed for operations, troubleshooting or applicable obligations. We periodically review those needs.
Removing a connection or hiding a record in the interface may not physically erase all stored information. Request deletion by emailing the contact above and identify the account, workspace or content concerned. We verify authority without requesting your platform password, stop affected publishing jobs, and remove the relevant local data subject to lawful retention requirements.
For YouTube API data, we refresh or delete data within the applicable platform limits, and remove stored user data as soon as possible and within seven calendar days of a valid deletion request. Deleting local data does not delete content held by YouTube. Other privacy requests are handled within applicable legal deadlines.
Encrypted recovery copies can contain older data. The system keeps the fourteen most recent local backup copies after successful off-host delivery. Off-host copies currently have no automatic expiry and require operator review and removal. We include recovery copies when handling a valid deletion request: affected copies must be removed or replaced as needed to meet the applicable deletion deadline. Recovery copies are not used for routine access, and any recorded deletion must be reapplied before restored data is put back into use.
7. Platform controls
This service uses YouTube API Services. See the Google Privacy Policy. You can revoke access through Google's third-party connection settings.
For TikTok and Instagram, when connected, use the connected-app controls in the relevant platform's settings to revoke access. Their policies are available at TikTok Privacy Policy and Meta Privacy Policy. Revocation stops future authorized access; request local deletion separately and cancel pending jobs. Published content must be removed through the destination platform or an explicitly authorized removal action.
8. Your rights and contact
Where the GDPR applies, you may request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. These rights are subject to the conditions and exceptions in applicable law.
Send requests or complaints to social@orbvora.com. You may also complain to a competent supervisory authority, including Italy's Garante per la protezione dei dati personali.
We will update this policy when processing changes, identify its effective date and provide further notice or obtain consent where required before a new use begins.