Skip to content

Certello Compliance Analyzer · Legal information

GDPR, roles and deletion

How access, retention, user rights, revocation and deletion are handled across customer-authorised integrations.

Updated 4 October 2026

1. Roles in a customer engagement

The customer chooses its authorised sources, purposes, users and applicable compliance requirements. The customer is normally controller for a customer-directed review, and Certello normally acts as processor under documented instructions. Certello is controller for its own website, business contacts and security operations.

2. TikTok authorisation and data flow

A representative authorised for the TikTok account initiates Login Kit and grants the scopes shown on TikTok’s consent page. Display API access and a one-time Data Portability request are distinct steps. The user is informed about the requested data and purpose before proceeding.

  • Display API: basic connected-account information and public video metadata.
  • One-time Posts and Profile transfer: permitted post and profile data, including media download links where TikTok supplies them.
  • Excluded: activity history, direct messages and full-archive access.

Each TikTok account requires its own authorisation. Independent creators or influencer accounts are not covered by another organisation’s authorisation.

3. Retention and deletion by data type

Data typeRetention principleDeletion eventVerification
OAuth token and account connectionOnly while the connection is activeRevocation, end of engagement or platform requirementToken revoked and access no longer succeeds
Temporary video, audio and imagesOnly while the authorised analysis job requires themCompleted or aborted processing, customer request or shorter platform ruleSource media removed from primary processing storage and queue
Transcription and OCRWhile required for the documented engagementApproved report, deleted source or customer instructionDerivatives and search indexes checked and removed
Metadata, findings and source referencesAccording to the engagement purpose and agreementContracted period, valid request or platform ruleCases, exports and caches checked
Security and access logsOnly while required for security or lawRolling expiryLog-retention control
BackupsUntil controlled backup rotationRotation or restorationDeletion marker reapplied after restoration

Specific maximum periods are documented in the applicable customer agreement and technical configuration. Certello does not publish a shorter period unless the deployed service can enforce it. A shorter platform rule or valid deletion request takes precedence where required.

4. Individual, customer or platform request

  1. Receive the request through hello@certello.se, the responsible customer or a supported in-app channel.
  2. Verify identity, authority and the responsible controller.
  3. Locate data by source ID, content ID, organisation and linked derivatives.
  4. Restrict new processing and revoke the connection where required.
  5. Delete or de-identify permitted source media, caches, transcripts, OCR, findings and exports.
  6. Apply deletion markers to controlled backups and reapply them after restoration.
  7. Document the outcome with minimum personal data and respond to the requester or customer.

5. Disconnecting TikTok

A connected user may revoke TikTok authorisation. Certello then stops new API processing for that connection and handles associated data under the documented retention and deletion rules. Revocation does not remove information that must lawfully be retained for legal claims or mandatory requirements, but such information is isolated and access-restricted.

6. Integration review

Before a platform integration is enabled, Certello documents purpose, selected scopes, licensed data fields, third-person data, providers, processing region, transfers, retention and deletion events. The end-to-end flow is tested with an account whose representative is authorised to connect it.