1. Roles in a customer engagement
The customer chooses its authorised sources, purposes, users and applicable compliance requirements. The customer is normally controller for a customer-directed review, and Certello normally acts as processor under documented instructions. Certello is controller for its own website, business contacts and security operations.
2. TikTok authorisation and data flow
A representative authorised for the TikTok account initiates Login Kit and grants the scopes shown on TikTok’s consent page. Display API access and a one-time Data Portability request are distinct steps. The user is informed about the requested data and purpose before proceeding.
- Display API: basic connected-account information and public video metadata.
- One-time Posts and Profile transfer: permitted post and profile data, including media download links where TikTok supplies them.
- Excluded: activity history, direct messages and full-archive access.
Each TikTok account requires its own authorisation. Independent creators or influencer accounts are not covered by another organisation’s authorisation.
3. Retention and deletion by data type
| Data type | Retention principle | Deletion event | Verification |
|---|---|---|---|
| OAuth token and account connection | Only while the connection is active | Revocation, end of engagement or platform requirement | Token revoked and access no longer succeeds |
| Temporary video, audio and images | Only while the authorised analysis job requires them | Completed or aborted processing, customer request or shorter platform rule | Source media removed from primary processing storage and queue |
| Transcription and OCR | While required for the documented engagement | Approved report, deleted source or customer instruction | Derivatives and search indexes checked and removed |
| Metadata, findings and source references | According to the engagement purpose and agreement | Contracted period, valid request or platform rule | Cases, exports and caches checked |
| Security and access logs | Only while required for security or law | Rolling expiry | Log-retention control |
| Backups | Until controlled backup rotation | Rotation or restoration | Deletion marker reapplied after restoration |
Specific maximum periods are documented in the applicable customer agreement and technical configuration. Certello does not publish a shorter period unless the deployed service can enforce it. A shorter platform rule or valid deletion request takes precedence where required.
4. Individual, customer or platform request
- Receive the request through hello@certello.se, the responsible customer or a supported in-app channel.
- Verify identity, authority and the responsible controller.
- Locate data by source ID, content ID, organisation and linked derivatives.
- Restrict new processing and revoke the connection where required.
- Delete or de-identify permitted source media, caches, transcripts, OCR, findings and exports.
- Apply deletion markers to controlled backups and reapply them after restoration.
- Document the outcome with minimum personal data and respond to the requester or customer.
5. Disconnecting TikTok
A connected user may revoke TikTok authorisation. Certello then stops new API processing for that connection and handles associated data under the documented retention and deletion rules. Revocation does not remove information that must lawfully be retained for legal claims or mandatory requirements, but such information is isolated and access-restricted.
6. Integration review
Before a platform integration is enabled, Certello documents purpose, selected scopes, licensed data fields, third-person data, providers, processing region, transfers, retention and deletion events. The end-to-end flow is tested with an account whose representative is authorised to connect it.