Junnect Studio Privacy Policy
Last updated: 30 July 2026
Junnect Studio is a social media management platform operated by Junnect B.V. Client organisations connect their own social media accounts to Junnect Studio and use it to create, review, schedule and publish content, and to see how that content performs.
This policy explains what personal data Junnect Studio collects, what Junnect Studio accesses on each connected platform and why, how access tokens are stored, where data is kept and for how long, what happens when a connected account is disconnected, and how you can exercise your rights under the GDPR.
Parent document: the general privacy statement of Junnect B.V.
1. Who operates Junnect Studio, and how to contact us
Junnect Studio is operated by Junnect B.V., a company registered in the Netherlands. Junnect B.V. is responsible for Junnect Studio and is the point of contact for every question, request or complaint about this policy.
- Junnect B.V.
- Hoge Bergen 14 - 1e verdieping, 4704 RH Roosendaal, The Netherlands
- E-mail: [email protected]
- Chamber of Commerce (KvK) number: 97395064
Junnect Studio is reachable at studio.junnect.nl. Section 17 explains when Junnect B.V. acts as controller and when it acts as a processor on behalf of a client organisation.
2. What Junnect Studio is
Junnect Studio is a multi-tenant social media management platform: several client organisations use the same software, each in their own separated workspace (a "brand"). A client organisation connects the social media accounts it owns or administers — on TikTok, Meta (Facebook and Instagram), LinkedIn and Pinterest — and its users then plan, review, approve, publish and report on content for those accounts inside Junnect Studio.
Alongside publishing, Junnect Studio offers SEO content tooling for a client organisation's own website and Link in Bio pages. Access is account-based: users sign in with an account issued to them, and every user only sees the workspaces of the client organisation they belong to. Data belonging to one client organisation is never shown to, or mixed with the data of, another.
Junnect Studio only ever processes data from accounts, pages and websites that the client organisation concerned has explicitly connected and authorised.
3. What data Junnect Studio collects
Junnect Studio collects four kinds of data.
Account details of the people who use Junnect Studio:
- name, e-mail address and (optionally) telephone number
- sign-in data: for employees of Junnect B.V. the single sign-on identity of the organisation's Microsoft account; for contacts of a client organisation the one-time code sent to their e-mail address
- role, workspace membership and access rights
- activity in Junnect Studio, such as which content someone created, approved, scheduled or published
Content uploaded by users:
- captions, titles, descriptions and other post text
- images, videos, documents and other media files uploaded to the content library or imported from a connected design or stock service
- planning data: schedules, approval status, comments and feedback within the approval workflow
- any personal data a user chooses to put in that content — Junnect Studio does not inspect content for personal data, so users decide what it contains
OAuth access and refresh tokens for connected social platforms, together with the identity of the connected account (see sections 4 to 7 for exactly what is collected per platform, and section 8 for how tokens are stored).
Publishing and performance data returned by the platforms:
- the identifier of the published post and the moment publication succeeded or failed, plus the error the platform returned on failure
- performance figures the platform makes available for the connected account, such as reach, impressions, clicks and interactions
- where a client organisation switches on the comment-display feature, the comments left on its own posts, including the display name and profile picture of the person who left them
4. TikTok: what Junnect Studio accesses, and why
Junnect Studio connects to TikTok through TikTok Login Kit and publishes through the TikTok Content Posting API (Direct Post). Junnect Studio requests two permissions and no others: user.info.basic, to read the basic profile of the account being connected, and video.publish, to post content a user has created and scheduled. Junnect Studio does not request draft upload, and does not request access to your videos, comments, direct messages or analytics.
When a TikTok account is connected, Junnect Studio receives and stores:
- the TikTok user identifier (open_id) of the connected account — the pseudonymous identifier TikTok issues for that account — so the connection can be recognised again
- the display name of the account, so users can tell connected accounts apart in the interface
- the URL of the profile picture, shown next to the display name
- the OAuth access token and refresh token, with their expiry moments, so scheduled posts can be published without asking you to sign in again
- the permissions granted (user.info.basic and video.publish)
- which Junnect Studio user made the connection, and which client workspace the account belongs to
When a user publishes to TikTok, Junnect Studio sends the video or the images, the caption, the privacy level chosen for that post, the duet, stitch and comment settings, and the branded-content and brand-organic disclosure flags. TikTok either fetches the media from a link on Junnect Studio's media storage or receives the file directly. Immediately before publishing, Junnect Studio asks TikTok which privacy levels the account may use, as TikTok requires; that answer is used for the post and is not stored. Afterwards Junnect Studio stores the publish identifier and the identifier of the created post, so it can show that the post really went out.
That is the complete list. Junnect Studio does not download or store your TikTok videos, does not read followers, likes, comments, direct messages or statistics, and never collects data about other TikTok users through your account. Nothing is posted unless a user of Junnect Studio creates that post and publishes or schedules it.
5. Meta (Facebook and Instagram): what Junnect Studio accesses, and why
Junnect Studio connects to Facebook Pages and Instagram business accounts through Facebook Login and the Meta Graph API. During the connection, Junnect Studio reads the list of Facebook Pages the connecting person administers (identifier, name, profile picture and the Page access token) and, for each Page, the linked Instagram business account (identifier, username and profile picture). Those details are stored so the Pages and accounts can be shown, selected and published to.
The permissions Junnect Studio requests are pages_show_list, pages_read_engagement, pages_manage_posts, pages_read_user_content, instagram_basic, instagram_content_publish, instagram_manage_insights, instagram_manage_comments and business_management. They are used to list the Pages and Instagram accounts a person administers, to publish posts, images, videos, carousels, stories and reels that a user has scheduled, and to read back how those posts perform and what people reply to them for the reporting and community-management features.
Junnect Studio reads engagement, comment and insight data only for the connected Page or Instagram account itself and only when the client organisation uses those features; the reporting and community-management surfaces are switched on per client organisation, and while they are off Junnect Studio makes no such calls. Junnect Studio does not read a person's private profile, friends, messages or advertising data.
6. LinkedIn: what Junnect Studio accesses, and why
Junnect Studio connects to LinkedIn Company Pages through the LinkedIn Community Management API, with the permissions r_basicprofile, rw_organization_admin, w_organization_social, r_organization_social and r_organization_social_feed.
- r_basicprofile is used once, at connection time, to establish who is connecting: LinkedIn returns the member identifier, first and last name and profile picture of that person, which Junnect Studio stores as the audit record of who made the connection. LinkedIn does not release an e-mail address under this permission, and Junnect Studio does not ask for one.
- rw_organization_admin is used to list the Company Pages the connecting member administers, and to read the name and logo of those Pages.
- w_organization_social is used to publish text, image, video and document posts a user has scheduled to the Company Page.
- r_organization_social and r_organization_social_feed are used, where the client organisation switches the feature on, to display the comments on the Company Page's own posts — including the commenter's name and profile picture — so the client organisation can respond. This surface is off by default.
Junnect Studio does not access a member's connections, messages, feed or job data.
7. Pinterest: what Junnect Studio accesses, and why
Junnect Studio connects to Pinterest business accounts through the Pinterest API v5, with the permissions user_accounts:read, boards:read, boards:write, pins:read and pins:write.
- user_accounts:read is used to read the connected account (username, account type and profile picture), so the connection can be shown and recognised.
- boards:read is used to list the existing boards, so a user can choose which board a pin is published to.
- boards:write is required by Pinterest to publish a pin to a board. Junnect Studio has no board-creation feature and does not create, rename or delete boards.
- pins:write is used to create the pins a user has scheduled: image, title, description, alt text, destination link and board.
- pins:read is used to read back the created pin, so Junnect Studio can confirm publication and report on it.
Junnect Studio does not read a person's private boards, saved pins or activity outside the connected business account.
8. How Junnect Studio stores OAuth tokens
Every connection is made with OAuth: you sign in at the platform itself and approve the permissions there. Junnect Studio never sees and never stores your password for TikTok, Meta, LinkedIn or Pinterest.
- Tokens are encrypted at rest. Access tokens and refresh tokens are encrypted with AES-256-CBC before they are written to the database, using an application key that stays on the server. They are decrypted in memory only, at the moment a call to the platform is made.
- Tokens are never logged. Junnect Studio deliberately keeps token material out of its log files, including out of the diagnostic logging of outgoing publish requests.
- Tokens are never shown in the interface, never exported, and never shared with anyone — not with other client organisations, not with the AI providers that help draft content, not with anyone else.
- Tokens travel over an encrypted HTTPS connection only, and only to the endpoints of the platform they belong to.
- Tokens are renewed automatically. The TikTok access token, for example, expires within 24 hours and is renewed with the refresh token by a scheduled job. Junnect Studio stores the expiry moment of the refresh token so it can ask a user to reconnect before access lapses.
- If a platform refuses a token, Junnect Studio flags the account as needing reconnection and stops attempting to publish for it.
9. How platform data is used — and what Junnect Studio never does with it
Data Junnect Studio receives from TikTok, Meta, LinkedIn and Pinterest is used for one purpose only: to provide Junnect Studio to the client organisation that owns the connected account — publishing the content that organisation schedules, showing the state of its accounts, and reporting on how its content performs.
Junnect Studio never:
- sells platform data, or makes it available to data brokers
- shares platform data with third parties, other than the sub-processors listed in section 14, who act only on Junnect B.V.'s instructions and under a processing agreement
- uses platform data for advertising, ad targeting or audience building
- uses platform data, connected-account data or uploaded content to train AI models — neither its own nor those of a third party
- builds profiles of individuals, and does not track people across other websites or apps
- combines the data of one client organisation with that of another, and does not use one client organisation's data for the benefit of another
Junnect Studio does use AI to help draft text and images. What is sent to the AI provider is the content being worked on and the brand description that belongs to it — never access tokens, never platform data received from TikTok, Meta, LinkedIn or Pinterest, and never the names or e-mail addresses of users. AI output is always a proposal that a person reviews before anything is published.
10. Compliance with platform terms
Junnect Studio uses the TikTok APIs in accordance with the TikTok Developer Terms of Service and TikTok's developer policies, and uses the Meta APIs in accordance with the Meta Platform Terms and Meta's Developer Policies. Junnect Studio likewise follows the LinkedIn API Terms of Use and the Pinterest Developer Guidelines.
For platform data this means in particular that Junnect Studio requests only the permissions its features actually need, uses platform data only to provide the service to the client organisation that authorised the connection, does not sell it or pass it to data brokers, keeps it no longer than necessary, deletes it when a connection is disconnected or when deletion is requested, and protects it with the measures set out in section 12.
11. Disconnecting an account: revocation and deletion
A connected account can be disconnected at any time in Junnect Studio, under Brand settings, tab Accounts, with the Disconnect button. You can also withdraw access from the platform side, in the connected-apps overview of TikTok, Meta, LinkedIn or Pinterest.
When an account is disconnected in Junnect Studio:
- the account is immediately detached from the workspace: it disappears from the interface, it can no longer be chosen when composing or planning, and Junnect Studio makes no further calls to the platform for that account
- the access token and refresh token for that account are revoked with the platform and deleted from the database
- the platform data stored for that account is removed: the account identifier, the display name, the profile-picture URL, the granted permissions and any cached page, board or account details
Posts that were already published stay on the platform: they belong to the account there and can be deleted there. Junnect Studio keeps its own publication record — the caption, the media and the identifier of the published post — as part of the client organisation's content history, unless that organisation asks for it to be deleted.
To have everything removed at once, e-mail [email protected]. Junnect B.V. erases the connection, the tokens and the associated platform data without undue delay and at the latest within 30 days, and confirms when it has been done. When a client organisation stops using Junnect Studio, the same removal happens for all of its connected accounts.
12. Where data is stored, and how it is protected
Junnect Studio runs on servers in the Netherlands. The application, the database and the cache and queue infrastructure are located in the European Union, and the media files that belong to content are stored in object storage under an EU jurisdiction. Personal data therefore stays within the European Economic Area, except where section 14 states otherwise for a specific sub-processor; those transfers take place with appropriate safeguards, including the European Commission's standard contractual clauses.
Junnect B.V. takes appropriate technical and organisational measures to protect this data:
- traffic to and from Junnect Studio runs over an encrypted HTTPS connection
- access tokens, refresh tokens and other credentials are encrypted at rest (see section 8)
- employees of Junnect B.V. sign in through the single sign-on of the organisation's Microsoft account, with multi-factor authentication; contacts of a client organisation sign in with a one-time code sent to their e-mail address, so there are no shared passwords
- access is role-based and limited to the people who need it for their work; every workspace is separated, so a user only ever sees the data of their own client organisation
- log files deliberately contain no tokens and no response bodies from the platforms
- the managed hosting at Rootnet B.V. is certified to ISO 9001, ISO 27001 and NEN 7510, and holds an ISAE 3000 (TPM) assurance statement
- backups are made twice a day and kept for 30 days; they are used only to restore the service after an incident, and data that has been deleted — including revoked tokens and removed accounts — automatically disappears from the backups within 30 days at the latest
- backups are encrypted and stored in a physically separate datacenter, always within the Netherlands, connected over Rootnet's own redundant network; every backup is automatically checked for integrity, the backup process is monitored with engineers alerted when a backup fails, and restoring from backup has been tested
13. How long Junnect Studio keeps data
Junnect Studio does not keep personal data longer than is necessary for the purpose it was collected for. In concrete terms:
- Connection data of a connected account (identifier, display name, profile-picture URL, granted permissions, encrypted tokens): for as long as the account is connected. On disconnection it is revoked and deleted, as described in section 11.
- Access tokens: short-lived and replaced at every renewal — a TikTok access token, for example, lasts at most 24 hours. Of the refresh token, only the expiry moment is kept alongside it, so a reconnection can be requested in time.
- Content and its publication record (caption, media, identifier of the published post): for as long as the client organisation uses Junnect Studio for that channel, so its content history and reporting remain available. It is deleted at the organisation's request and when it stops using Junnect Studio.
- Performance figures retrieved from a platform: for as long as the channel is being managed in Junnect Studio, so trends over time can be reported.
- Accounts of Junnect Studio users: for as long as the person needs access; access is withdrawn when someone leaves or no longer needs it.
- One-time login codes for the client approval portal: valid for 15 minutes, after which they can no longer be used.
- Records of the e-mails Junnect Studio sends, such as approval notifications: 90 days.
- Coarse visit and click statistics of public Link in Bio pages: for as long as the page exists, so its performance can be reported.
Where the law obliges Junnect B.V. to keep data longer, that obligation prevails.
14. Sub-processors and hosting providers
Junnect B.V. engages the following parties to deliver Junnect Studio. They act only on Junnect B.V.'s instructions, under a processing agreement, and they never receive access tokens.
- Rootnet B.V. — hosting of the application server, the database and the cache and queue infrastructure on which Junnect Studio runs, on green-powered servers in BIT datacenters in the Netherlands (EU).
- Cloudflare — object storage for the media files that belong to content (EU jurisdiction bucket), and routing of the custom domains of Link in Bio pages.
- Brevo — sending transactional e-mail such as one-time login codes and approval notifications (EU).
- Microsoft — single sign-on for employees of Junnect B.V. (Entra ID); only the employee's work identity is exchanged.
- Anthropic and OpenAI — AI assistance in drafting text and images. They receive the content being worked on; no access tokens, no platform data and no user identities (United States, under standard contractual clauses).
- Google — retrieving search performance from Search Console and measuring page speed for the SEO tooling, for the client organisation's own website.
- Canva and Shutterstock — importing or licensing media, only when a user actively chooses to do so.
TikTok, Meta, LinkedIn and Pinterest are not sub-processors of Junnect B.V.: they are independent parties with their own responsibility and their own privacy policy, and their terms apply alongside this policy when content is published or data is received through their connections. Their policies:
15. Other personal data Junnect Studio processes
Two parts of Junnect Studio process data that does not come from a social platform.
Public Link in Bio pages:
- coarse, aggregated visit and click statistics, including the type of device, browser and operating system derived from technical request data
- these figures serve only to report how a page performs; Junnect Studio builds no advertising profiles and does not follow visitors across other websites
The SEO tooling, for a client organisation's own website:
- the content and structure of that website, which Junnect Studio reads in order to suggest improvements
- search-performance data from Google Search Console for that same website, such as search queries, impressions, clicks and average position — this data describes the website, not identifiable visitors
16. Purposes and legal bases
Junnect B.V. processes the personal data described above in order to:
- let client organisations plan, review, approve, schedule and publish content on their connected accounts
- run the approval workflow, in which content moves through the statuses draft, awaiting approval and scheduled before anything is published
- show reactions and interactions on a client organisation's own content, so it can respond
- report on the performance of published content
- improve the content and findability of a client organisation's own website through the SEO tooling
- secure access to Junnect Studio, prevent misuse, and keep the service available
The legal bases under the GDPR are: performance of a contract, for delivering Junnect Studio under the agreement with the client organisation; legitimate interest, for securing the service and reporting on performance, weighed against the interests of the people concerned; and legal obligation, insofar as the law requires data to be retained or provided.
17. Junnect's role: controller and processor
For the personal data that reaches Junnect Studio through a client organisation's connected accounts and website — including content and the data of people who interact with that content — Junnect B.V. acts as a processor on behalf of that client organisation. The client organisation is the controller and determines the purposes and means of the processing; the arrangements are recorded in a processing agreement.
For the data of Junnect Studio users and the data needed to secure and administer Junnect Studio, Junnect B.V. acts as the controller.
18. Your rights under the GDPR
Anyone whose personal data Junnect Studio processes has the following rights:
- access — a copy of the personal data held about you, and an explanation of what is done with it
- rectification — correction of data that is incorrect or incomplete
- erasure — deletion of your data, including a connected account and its tokens
- data portability — a copy of the data you provided, in a common, machine-readable format
- objection — objecting to processing based on legitimate interest
- restriction — temporarily freezing the processing while a request or objection is being handled
- withdrawal of consent — where processing rests on consent, withdrawing it at any time, without affecting what happened before
To exercise a right, e-mail [email protected], stating what you are asking for. Junnect B.V. responds without undue delay and at the latest within 30 days, and may ask for confirmation of your identity to make sure data is not released to the wrong person. Exercising a right is free of charge.
Where Junnect B.V. acts as a processor, a request is forwarded to the controller — usually the client organisation whose account, page or website it concerns — and Junnect B.V. supports that organisation in handling it. For people who interact with a client organisation's content, the management of their own account data and privacy settings lies with the social platform concerned.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the supervisory authority of the EU member state where you live.
19. Contact
For questions about this privacy policy, about the processing of personal data in Junnect Studio, or to request deletion of a connected account, contact Junnect B.V. at [email protected] or at Hoge Bergen 14 - 1e verdieping, 4704 RH Roosendaal, The Netherlands.
This policy applies to the use of Junnect Studio. Where it differs from the general privacy statement of Junnect B.V. — the parent document linked at the top of this page — this policy applies to Junnect Studio. Junnect B.V. publishes the current version on this page, with the date on which it was last updated.