GO CREAjt (www.gocreajt.com) is software that creative agencies and freelancers use to manage their work and their clients, including planning, approving and publishing social media content for those clients. This privacy policy explains which personal data we process, why, with whom we share it, how long we keep it and what your rights are. We comply with the EU General Data Protection Regulation (GDPR).
Who is responsible
GO CREAjt is a trade name of CREAJT, a creative agency in Nijmegen, the Netherlands. Address: Sint Annastraat 37A, 6524 EE Nijmegen, the Netherlands. Chamber of Commerce (KvK) 99234017, VAT NL005377107B89. For privacy questions, e-mail privacy@gocreajt.com. For other questions: info@gocreajt.com.
Two roles: controller and processor
- We are the controller for the data we need ourselves: your account, your agency and team, your subscription and payments, contact with us and the use of our website.
- The agency is the controller for the data it puts into GO CREAjt about its own clients, such as contact details, content, photos, invoices and contracts, the client's portal accounts and the social media accounts the client connects. We process that data only on the agency's instructions, under our data processing agreement.
- Are you a client of an agency and do you have a question about your data? Please ask that agency first. We help the agency to handle your request.
What data we process and why
- Account and sign-in. Name, e-mail address, optionally phone number and profile photo, and an encrypted password. If you sign in with Google or Apple, we receive your name and e-mail address from them. Legal basis: performance of the contract.
- Agency and team. Agency name, logo, branding, website, team members, their roles and permissions, and invitations. Legal basis: performance of the contract.
- Subscription and payments. Your plan, billing interval, trial date, discounts, referral credit, billing details and payment status. You enter card or bank details at Stripe; we do not store them. Legal basis: performance of the contract and our legal obligation to keep records.
- Work data. Everything an agency puts into GO CREAjt: clients and contacts, content and planning, photos, videos, projects, tasks, hours, invoices, contracts, feedback and messages in the client portal. We process this on behalf of the agency.
- Social media. When a social media account is connected: the connection, the posts published through GO CREAjt and the metrics of those posts. See the next section.
- AI features. The text, images and documents you submit for an AI feature (see "AI" below).
- Contact and support. Your messages through the help button, the contact form or e-mail. Legal basis: our legitimate interest in answering you, or performance of the contract.
- Service e-mails and push notifications. E-mails that belong to the service (sign-in, invitations, notifications, reports) and, if you turn them on, push notifications. Legal basis: performance of the contract, our legitimate interest, or your consent (push). You can turn notifications off at any time.
- Technical data. IP address, device and browser type, and log files, to run, secure and troubleshoot the service. Legal basis: our legitimate interest.
Data from Meta, TikTok and Google/YouTube
An agency or its client can connect social media accounts of the client to GO CREAjt: an Instagram professional account, a Facebook Page, a TikTok account or a YouTube channel. The account owner signs in with the platform and chooses which access to grant. GO CREAjt only uses that access to do what the user asks: publish content and show the results.
- What we receive. The account or Page ID, name or username and profile picture; the IDs and links of posts and videos published through GO CREAjt; and the metrics of those posts, such as reach, views, likes, comments count, shares, saves and new follows. For YouTube also the channel name and picture, and views, likes and watch time of the videos uploaded through GO CREAjt. We do not read private messages, we do not read or manage comments, and we do not access ads or ad accounts.
- Why. To show which account is connected to which client; to publish the posts, reels, stories, videos and Shorts that the agency prepared and the user chose to publish (immediately or at a scheduled time); and to show the agency and its client how those posts perform, in the analytics screen and in a monthly report. We never post without an explicit action of a user.
- Who sees it. Only the members of that agency and that client. We do not sell this data, we do not use it for advertising or profiling, and we do not use it to train AI models.
- Processor. Publishing and retrieving data runs server-to-server through our processor Post for Me (api.postforme.dev), using the apps of GO CREAjt. Post for Me stores the access tokens of connected accounts on our behalf and uses them only for GO CREAjt.
- How long. As long as the account is connected. Metrics are refreshed regularly while a post is recent and are not kept for more than 30 days without being refreshed from the platform. When an account is disconnected in GO CREAjt, or access is removed on the platform, we delete the connection and the access tokens right away and the stored platform data within 30 days. Content you published stays on the platform itself; you can delete it there.
- Removing access. In GO CREAjt: Clients, then the client, Settings, Connections, then remove the account or choose "Disconnect". On the platform: Facebook (Settings, Business integrations), Instagram (Settings, Website permissions, Apps and websites), TikTok (Settings and privacy, Security, Manage app permissions) and Google (https://security.google.com/settings/security/permissions). See also how to delete your data.
Google and YouTube. GO CREAjt's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. GO CREAjt uses YouTube API Services. When you connect YouTube, you also agree to the YouTube Terms of Service. Google's Privacy Policy applies: https://policies.google.com/privacy. You can revoke GO CREAjt's access at any time via https://security.google.com/settings/security/permissions.
Meta and TikTok. For Instagram and Facebook the Meta Privacy Policy applies, and for TikTok the TikTok Privacy Policy. When you remove GO CREAjt from your Facebook or Instagram settings, Meta informs us and we delete the connection and its data.
AI
For AI features we use Claude by Anthropic. It suggests captions and ideas and reads invoices and contracts. We only send the data needed for that one task. Anthropic does not use this data to train its models. The result is a suggestion that you check yourself. No decisions about people are made fully automatically. Data from Meta, TikTok or Google/YouTube is not sent to AI services.
Who we share data with
We never sell your data. We work with a few carefully chosen service providers (processors). We have agreements with each of them to protect your data:
| Party | Purpose | Which data | Where |
|---|---|---|---|
| Supabase | Database, accounts and sign-in; some older files | Account and agency data, client and work data, support messages | EU (Frankfurt). Supabase Inc. (US) may have access for maintenance and support; with Standard Contractual Clauses (SCCs) |
| Vercel | Hosting of the website and the app | IP address, technical data and logs; all data that passes through the app | Servers in the EU (Frankfurt). Vercel Inc. is based in the US; with SCCs and the EU-US Data Privacy Framework (DPF) |
| Cloudflare (R2) | Storage and delivery of files | Photos, videos, music and documents uploaded by you, your team or your client | Stored in the EU (EU jurisdiction). Cloudflare Inc. is based in the US; with SCCs and DPF |
| Resend | Sending e-mail (sign-in, invitations, notifications, reports, reminders) | Name, e-mail address and the content of the e-mail | US; with SCCs |
| Stripe | Payments, subscriptions, discounts and invoices | Name, e-mail, company and billing details, VAT number, payment details, IP address | EU (Stripe Payments Europe, Ireland) and US; with SCCs and DPF |
| Anthropic (Claude) | AI features: captions and ideas, reading invoices and contracts | The text, images and documents you submit for such a feature | US; with SCCs. Not used to train AI models |
| Post for Me | Connecting social media accounts, publishing posts and retrieving post metrics | The connection with social accounts (including access tokens), the content you publish and the metrics of published posts | US; with SCCs |
| Google (Firebase Cloud Messaging) | Delivering push notifications in the app | A device token and the content of the notification | US and worldwide; with SCCs and DPF |
When you publish to Instagram, Facebook, Threads (Meta), TikTok, LinkedIn or YouTube (Google) through GO CREAjt, your content goes to that platform, and that platform's own policy applies. We only share data otherwise when the law requires it.
Data outside Europe
We keep your data in Europe as much as possible: the app runs in the EU (Frankfurt), the database is at Supabase in the EU and files are at Cloudflare in the EU. Some parties are (also) based in the United States. When data goes there, we use appropriate safeguards: the European Commission's Standard Contractual Clauses and, where the party is certified, the EU-US Data Privacy Framework.
How long we keep data
- Account, agency and work data: as long as your account exists. After a subscription ends, we keep the agency locked for 12 months so you can come back, and then delete it after an e-mail warning.
- If you delete your account: we delete your data from the database right away, and remove files and backup copies within 90 days.
- Data from connected social media accounts: see "Data from Meta, TikTok and Google/YouTube" above.
- Invoices and records: 7 years, as required by law.
- Contact messages: as long as needed to handle your question, and then at most 2 years.
- Log files: at most 12 months.
Security
- All connections are encrypted (HTTPS). Passwords are stored encrypted.
- The database and storage are encrypted at our providers. Access tokens of social media accounts are held by our processor Post for Me, not in the browser or the app.
- Every agency and every client is strictly separated at database level (row level security). Within an agency, access works per role and permission.
- Secret keys are only on the server, never in the browser or the app. We make automatic database backups.
- Our own team only looks into an account when needed for support, maintenance or fixing an outage, and every such access is logged and visible to the agency owner.
Your rights
- You may access, correct or delete your data.
- You may ask to restrict processing, and object to processing based on our legitimate interest.
- You may receive your data in a common file format (data portability).
- Where you gave consent, you may withdraw it at any time.
You can do a lot yourself in the app: download all your data, delete your own account or, as owner, request deletion of the whole agency. See how to delete your data. For other requests, e-mail privacy@gocreajt.com. We respond within one month. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Children
GO CREAjt is intended for business use and not for children under 16. We do not knowingly collect data from children.
Cookies
We only use necessary and functional cookies, for example to keep you signed in. We do not use advertising or tracking cookies or third-party analytics. See our cookie policy (in Dutch).
Changes
We may update this privacy policy, for example when the service changes or we start working with a new party. The date and version are shown at the top. We announce important changes in advance. This is a translation of our Dutch privacybeleid; if the two differ, the Dutch version prevails, except for the section on data from Meta, TikTok and Google/YouTube, which is identical in both.