FOLX Publisher iconFOLX Publisher
How it works Support Privacy Terms

Privacy Policy — FOLX Publisher

Effective 5 September 2026 · Version 2.0

This Privacy Policy explains which data the application FOLX Publisher processes, why, on what legal basis, how long it is kept and what rights you have. It applies to the Tool itself and to this website, folxpublisher.biba.live.

1. Controller

PRIME TIME Consulting GmbH
Sigmaringer Str. 10, 72379 Hechingen, Germany
Managing Director: Heike Artič
E-mail: office@primetime.consulting · Telephone: +49 172 56 75 800

For all questions concerning data protection, including requests to exercise your rights, please write to the e-mail address above with the subject line "Data protection — FOLX Publisher".

2. What FOLX Publisher is, in data-protection terms

FOLX Publisher is an internal server application. It publishes video clips from our own media library to social media accounts that we own. It is not offered to the public, has no user registration and processes no data belonging to viewers, followers or other users of those platforms.

3. Data processed when a platform account is connected

To publish to a social media account, an authorised member of our team connects the Tool to that account through the platform's own login and consent screen. From that process we receive and store:

  • An access token — the credential that allows the Tool to upload and publish to the connected account.
  • A refresh token — used to renew the access token automatically so the authorisation does not have to be repeated.
  • The account's open ID and display name — so the Tool can verify that it is publishing to the intended profile.
  • The granted scopes and their expiry — so the Tool can detect when re-authorisation is required.

In the case of TikTok, the scopes requested are user.info.basic and video.publish. No further permissions are requested and no further data is retrieved.

What we do not process. The Tool does not read or store comments, direct messages, follower lists, audience statistics, viewer profiles, contact lists, location data or any content published by other users. It does not track individuals across services and does not build profiles of any kind.

4. Data processed when a post is published

Each publishing attempt is recorded in our internal log with: the time of the attempt, the identifier of the clip, the caption sent, the destination account, the result reported by the platform and, on success, the identifier of the resulting post. This log contains no personal data of third parties.

5. Data processed on this website

This website is a static information site. It sets no cookies, embeds no advertising, uses no analytics or tracking services and loads no fonts or scripts from external providers. When a page is requested, our web server writes a standard log entry containing the IP address, time of request, the page requested, the HTTP status and the user agent. These entries serve the security and stability of the server, are not combined with other data and are deleted after seven days.

6. Legal basis

  • Art. 6(1)(f) GDPR — legitimate interests: operating our own broadcast and social media presence, publishing our own content reliably and on schedule, and keeping our servers secure. Our legitimate interest lies in the efficient operation of the television channels we run.
  • Art. 6(1)(b) GDPR — performance of a contract: where processing is necessary in the employment relationship with the members of our team who operate the Tool.
  • Art. 6(1)(c) GDPR — legal obligation: where retention is required by commercial or tax law.

7. Recipients

Data is not sold, rented or passed to third parties for their own purposes. Access tokens are transmitted only to the platform that issued them, in the API calls needed to publish. The following categories of recipient are involved in the operation of the Tool:

  • The connected social platform (for example TikTok), which receives the video file, the caption and the credential, in order to publish the post. That platform's own privacy policy applies to its processing.
  • Our hosting provider, Hetzner Online GmbH, Gunzenhausen, Germany, on whose servers in Germany and Finland the Tool and this website run. A data processing agreement under Art. 28 GDPR is in place.

Where a connected platform processes data outside the European Economic Area, that transfer takes place under the safeguards described in the platform's own privacy policy, typically the European Commission's standard contractual clauses.

8. Retention

Access and refresh tokensKept for as long as the account is connected. Overwritten on every renewal. Deleted immediately when the authorisation is withdrawn or the account is disconnected.
Open ID and display nameDeleted together with the tokens of that account.
Publishing logKept for 24 months for operational review and duplicate prevention, then deleted, unless longer retention is required by law.
Web server logSeven days.

9. Security

Credentials are stored in a file with restricted permissions on a server to which only a small number of named administrators have access. All access is over encrypted connections; this website and all API calls use TLS. Servers are patched regularly, access is via key-based authentication, and credentials are revoked and replaced when a compromise is suspected.

10. Your rights

Under the GDPR you have the right to request access to your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). To exercise any of these rights, write to office@primetime.consulting. We answer within one month.

You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

11. Deleting data

Instructions for having the stored credentials and publishing history of a connected account deleted are set out on the data deletion page. Deletion is carried out within 30 days of a verified request.

12. Children

FOLX Publisher is an internal business tool. It is not directed at children, has no public users and knowingly processes no data of persons under 16.

13. Changes to this policy

We update this policy when the Tool or the applicable legal requirements change. The current version, with its effective date, is always published on this page.

FOLX Publisher How it works Support
Legal Terms of Service Privacy Policy Data deletion Imprint
Operator PRIME TIME Consulting GmbH
Sigmaringer Str. 10
72379 Hechingen, Germany
© 2026 PRIME TIME Consulting GmbH.