Privacy Policy of the Application Collab Analytics

Effective Date: 17.06.2026

This Privacy Policy defines the rules for the processing and protection of personal data of Users (Creators) using the internal analytics application Collab Analytics (hereinafter referred to as the "Application").

§ 1. General Provisions

The Data Controller of the Users' personal data processed within the Application is COLLAB SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office in Warsaw, at ul. Tadeusza Czackiego 15 / 17, 00-043 Warszawa, Poland, entered into the Register of Entrepreneurs of the National Court Register (KRS) under number: 0001103652, Tax Identification Number (NIP): 5253003095, National Official Register of Business Entities (REGON): 528586155 (hereinafter referred to as the "Controller" or the "Agency").

Contact with the Controller regarding personal data protection matters is possible via email at: hello@collabmgmt.pl.

Users' personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and applicable national data protection laws.

The Application (Collab Analytics) is closed in nature and is intended exclusively for Creators bound to the Agency by a cooperation agreement.

§ 2. Scope of Processed Data

As part of using the Application, the Controller may process the following categories of data:

User Identification and Contact Data: name, surname, email address, social media handle/username, user IDs assigned by the external platforms.

Analytical and Statistical Profile Data (retrieved via official APIs of Instagram, Facebook, and TikTok):

  • impressions, reach, and engagement metrics (likes, comments, shares, saves),
  • audience demographic data (age structure, gender, geolocation at the country/city level in percentage terms),
  • publishing history (dates, content formats: posts, reels, stories, videos).

Technical Data: IP address, web browser type, system logs (date and time of logging into the Application).

§ 3. Purposes and Legal Bases for Data Processing

Users' personal data is processed for the following purposes:

Performance of the cooperation agreement binding the Creator and the Agency, including the technical maintenance of the Application, presentation of statistics in the dashboard, and generation of reports required for advertising campaigns - legal basis: Article 6(1)(b) GDPR (processing is necessary for the performance of a contract).

Pursuit of the Controller's legitimate interests - legal basis: Article 6(1)(f) GDPR, consisting of:

  • marketing the services of the Agency and the Creator by creating promotional kits ("Media Kits") for potential clients and advertisers,
  • establishing, pursuing, or defending against potential legal claims,
  • ensuring the ICT security of the Application and preventing abuse.

§ 4. Source of Data and Integration Mechanism (API)

Identification data (e.g., email) is provided directly by the User during account setup or is transferred from the Agency's internal databases.

Analytical data, as specified in § 2 point 2, is retrieved from external social media platforms (Meta Platforms Ireland Limited for Instagram/Facebook and TikTok Technology Limited for TikTok) via official developer tools (APIs).

Data retrieval occurs exclusively after prior authorization (login and consent to access) performed by the User within the respective external platform's system.

The Application operates strictly on a "read-only" basis. The Controller does not have access to the User's private direct messages (DMs), does not retrieve login passwords, and does not hold permissions to publish content on behalf of the User.

§ 5. Data Recipients

The User's personal data may be disclosed only to the following entities:

  • Authorized employees and contractors of the Agency managing marketing campaigns and supporting the Creator's growth.
  • Entities providing technical infrastructure and services to the Agency (e.g., server hosting providers, IT software vendors maintaining the Application).
  • Contractors, brands, and advertisers cooperating with the Agency - strictly within the scope of aggregated analytical reports required to evaluate or settle an advertising campaign involving the Creator.

§ 6. Data Retention Period

Personal and analytical data processed for contract execution will be retained for the entire duration of the cooperation agreement linking the Creator and the Agency.

Upon termination of cooperation and the "disconnection" of accounts by the Creator (pursuant to the Terms of Service), no new analytical data will be retrieved.

Historical data aggregated during the term of the contract may be retained for the duration of the limitation period for potential claims resulting from legal provisions (typically 3 or 6 years) and for the period required by tax and accounting regulations.

§ 7. User Rights

In connection with the processing of personal data, the User is entitled to the following rights:

  • The right to access their data and receive a copy thereof.
  • The right to rectify (correct) their data.
  • The right to erasure ("the right to be forgotten") - under the circumstances outlined in Article 17 GDPR.
  • The right to restrict data processing.
  • The right to data portability.
  • The right to object to data processing based on the Controller's legitimate interest (Article 6(1)(f) GDPR).
  • The right to withdraw integration consent:The User may at any time disconnect their social accounts within the Application panel or revoke the Application's access permissions directly inside the security settings of Instagram, Facebook, or TikTok, which results in an immediate cessation of data retrieval by the Application.
  • The right to lodge a complaint with a supervisory authority (e.g., UODO in Poland or the equivalent in the User's country) if the User considers that the processing violates the GDPR.

§ 8. Data Security

The Controller implements appropriate technical and organizational measures to ensure a level of security appropriate to the risks and categories of protected data. In particular, data is safeguarded against unauthorized access, loss, alteration, or destruction (e.g., via SSL/TLS connection encryption).

§ 9. Changes to the Privacy Policy

The Controller reserves the right to introduce amendments to this Privacy Policy to align it with legal updates or technical modifications within the Application. Users will be notified of any changes via electronic communication.