Skip to content

Certello Compliance Analyzer · Legal information

Privacy Policy

How Certello AB processes personal data on its public website and in Certello Compliance Analyzer.

Updated 4 October 2026

Certello analyses content within a customer’s documented instructions, with limited access, traceable sources and procedures for data protection, revocation and deletion. Each connected platform has its own terms and authorised permissions.

1. Who is responsible?

Certello AB, registration no. 559540-7668, Skråmsta 553, 193 91 Sigtuna, Sweden, is controller for its own business contacts, public website and security operations. Contact: hello@certello.se.

Where a customer determines which of its channels are reviewed, why they are reviewed and who may access the results, the customer is normally controller and Certello normally processor under a written agreement. The roles for each workflow must be established before processing begins.

2. Data and sources

For the website and business contacts, we may process names, organisations, work email addresses, messages and necessary security logs. Within CCA, data may include channel and content identifiers, account name, publication time, links, images, video, captions, permitted engagement metadata, visible text, speech transcripts, OCR text and analytical findings with source references.

Sources may include the customer’s websites, documents and authorised accounts on social platforms. Mentioning a platform does not mean that it is connected or that all of its content is available.

3. TikTok integration

A TikTok account is connected by an authorised representative through TikTok Login Kit. Certello requests only the scopes used by the selected function:

  • user.info.basic for permitted basic profile information about the connected account.
  • video.list for public video metadata made available for that authorised account.
  • portability.postsandprofile.single for a separate, one-time Posts and Profile transfer after TikTok consent.

Certello does not request TikTok direct messages, activity history or a full account archive for this integration. Each account must be authorised separately. Display API metadata access does not by itself provide a media file for transcription or OCR. Where the account owner separately authorises a Posts and Profile transfer, permitted media may be processed for transcription, OCR, evidence-frame extraction and compliance analysis.

4. Purpose and legal basis

Customer-authorised material is used to identify published claims, create transcription and OCR where permitted, compare content with requirements selected for the engagement and provide traceable findings and reports. Certello does not use social-platform data for independent surveillance, sale of profiles or training of general-purpose AI models without a separate valid basis and platform permission.

The customer must document its legal basis, instructions and any required notices or permissions. Certello does not assume one legal basis that applies to every customer or every source.

5. Recipients and international transfers

Data may be processed by the connected platform and contracted providers used for hosting, storage, transcription, OCR, analysis and security. Applicable subprocessors, processing regions and transfer safeguards are documented for the customer. Data is not disclosed for a provider’s own advertising purposes under Certello’s instructions.

6. Retention, revocation and deletion

Platform data is not retained indefinitely. OAuth tokens are retained only while a connection is active and are revoked when the connection or engagement ends or when the platform requires it. Downloaded source media is temporary processing material and is removed from primary processing storage after completed or aborted processing, subject to any shorter platform rule and the documented customer agreement.

Transcripts, OCR, findings, exports, logs and backups have separate retention and deletion events described on the GDPR and deletion page. A shorter platform deadline, account-owner revocation or deletion of the source takes precedence over a longer contractual period where required.

7. Security

Access is restricted by organisation and role. Tokens are protected and are not included in reports. Transport is encrypted, and access, authentication and deletion events are logged with data minimisation. Providers are assessed before use, and incidents are handled under applicable contracts and law.

8. Your rights

You may request access, correction, deletion, restriction and, where applicable, portability, or object to processing based on legitimate interests. Consent may be withdrawn where it is used. Contact hello@certello.se and include the relevant channel, content link or other information needed to locate the data. We may need to verify identity and direct the request to the customer where the customer is controller.

9. Changes

This policy is updated when material functions, providers or data sources change. Significant changes are communicated as appropriate before new processing starts. The current version is published on this page.