Italiano · English

Privacy policy

Service: Elvexa Cast (cast.elvexa.com) — the component of Elvexa that publishes a company's content to that company's own social channels.

Data controller: Elvexa Sagl, Via Nassa 46, 6900 Lugano, Switzerland — privacy@elvexa.com

1. What data we process

DataWhyHow long
Access and refresh tokens for your social account They are what allows us to publish to your channel on your behalf, when you ask us to. Until you disconnect the account. On disconnection they are deleted.
Identifier and name of the connected account (e.g. the ID and title of the YouTube channel, the member URN and name on LinkedIn) So we know which channel we are publishing to, and so we can show it to you ("Connected: channel name"). As above.
Publishing log: date, platform, account, outcome, post identifier Diagnostics, and evidence of what was published and when. 12 months.

The content you publish is not retained. The video (or image) passes through Cast and is delivered to the platform: we do not archive it, index it, or reuse it. If you schedule a post, its content stays in the queue only until it is sent: as soon as it goes out — or if you cancel the order — it is deleted, and only the identifier of the published post remains. We do not collect your contact lists and we do not profile your audience.

Statistics and comments: pass-through only. At your request we show, in your own console, the statistics of your content and the comments you received, and we let you reply. This data is read on demand and forwarded to your console: we do not store it, we do not use it for any other purpose, and we do not share it with anyone. Comments are written by other people: we process them only to show them to you and let you reply, exactly as you would on the platform itself.

2. Which permissions we ask for, and why

We ask for the minimum needed to do what we promised you — nothing more.

YouTube

PermissionWhat it is for
youtube.uploadUploading the video you decided to publish to your channel. It is the only way to do it.
youtube.readonlyKnowing which channel you connected (id and name) and showing it to you — without it, we could publish to the wrong channel — and showing you, in your console, the comments left on your videos.
yt-analytics.readonlyShowing you, in your console, the statistics of your videos (views, engagement), so you can see how your content is performing. It is the same data you see in YouTube Studio.
youtube.force-sslAllowing you to reply, from your console, to comments received on your videos. The reply is sent only when you write it and confirm it: we never post comments automatically.

Google Ads

PermissionWhat it is for
adwordsShowing you, in your console, how your advertising campaigns are performing (spend, impressions, clicks) alongside the results of your organic content, and letting you manage them from there: creating new campaigns — always paused, never live — and changing the budget or status of existing ones. Every change happens only when you confirm it. We never enable a campaign automatically and we never spend anything without an explicit action from you.

The budget is spent from your own Google Ads account, with your own billing: Elvexa does not resell advertising space and does not apply any margin on your spend.

Use of data received from the YouTube APIs is subject to the YouTube Terms of Service and the Google Privacy Policy. You can revoke access at any time at myaccount.google.com/permissions.

TikTok

PermissionWhat it is for
user.info.basicKnowing which account you connected, and showing its name.
video.uploadSending the video to your content inbox: inside the TikTok app it is you who writes the description, chooses the privacy setting and publishes.
video.publishPublishing directly to your account the video you decided to publish, when you choose that mode in your console. You write the description and choose the post's privacy before it is sent: we never publish anything without your explicit confirmation.
video.listShowing you, in your console, the list of your published videos and their statistics, so you can see how your content is performing.

LinkedIn

PermissionWhat it is for
w_member_socialPublishing a post on your profile, when you ask us to.
w_organization_socialPublishing a post on the Company Page you administer, when you ask us to.
r_organization_social, rw_organization_adminKnowing which Pages you administer, so you can choose which one to publish to, and showing you the statistics and the comments received on your own Page posts so you can reply to them.

We only ever read data for organizations the connected member administers. We do not scrape or bulk-collect LinkedIn data, we do not build audience profiles or segments from it, and we do not sell, license or share it with third parties.

Meta (Facebook and Instagram)

PermissionWhat it is for
pages_manage_posts, instagram_content_publishPublishing to your Page and your Instagram account the content you decided to publish.
pages_read_engagement, pages_read_user_content, instagram_basicShowing you the statistics of your own content and the comments you received.
pages_manage_engagement, instagram_manage_commentsLetting you reply to those comments, and hide them on your own Page. Replies are written by you.
ads_management, ads_readShowing you how your own campaigns are performing and letting you create them — always paused — or change budget and status, on your explicit confirmation.

3. How we protect the tokens

4. How you revoke access

At any time, in two ways, both immediate: from your console ("Disconnect account"), or from the platform's own settings (Google, TikTok → Settings → Manage app permissions, LinkedIn → Settings → Permitted services, Facebook → Settings → Business integrations). On revocation we delete the tokens; the log of publications that already happened is kept for the period stated above. On request we also delete that, and any other data we obtained through the platform APIs.

5. Who we share data with

Nobody. Data is not sold, licensed or used for advertising or model training. The only destinations are the social platforms you asked us to publish to. We do not share one customer's data with any other customer.

6. Data controller and contact

The data controller is Elvexa Sagl, Via Nassa 46, 6900 Lugano, Switzerland. For any request about your data — access, rectification, erasure, objection — write to privacy@elvexa.com: we reply within 30 days. Elvexa's general privacy policy is at elvexa.com/en/privacy.