Legal document

Privacy Policy

How Merkflow collects, uses, and protects your personal data.

Last updated: April 2026 Jurisdiction: European Union (GDPR) Contact: support@merkflow.eu
1

Who we are

Merkflow is an AI-powered social media management platform operated by Niels van Haren Holding B.V. (trading as Merkflow), a company registered in the Netherlands (Chamber of Commerce: 73338397).

For the purposes of the General Data Protection Regulation (GDPR), we are the data controller for the personal data described in this policy.

Merkflow Niels van Haren Holding B.V. (trading as Merkflow)
Saltshof 2014
6604 ES Wijchen
The Netherlands

Email: support@merkflow.eu
Website: https://www.merkflow.eu
2

Data we collect

We collect only the data necessary to provide the Merkflow service.

CategoryExamplesSource
Account dataName, email address, profile photoGoogle OAuth, LinkedIn OAuth, or email/password registration
Password (if applicable)Hashed password (bcrypt/argon2 — never stored in plaintext)Provided at registration; only applies to email/password accounts
Social media tokensOAuth access & refresh tokens for LinkedIn, Instagram, Facebook, XPlatform OAuth flows; encrypted at rest
Brand dataWebsite URLs, onboarding answers, post content you create or approveProvided directly by you
AI-generated contentPost drafts, captions, hashtags generated by the AICreated by Merkflow on your behalf
Analytics dataImpressions, reach, engagement metrics per postFetched from social platform APIs
Usage dataPosts generated, platforms connected, workspace activityAutomatically collected
Technical dataIP address, browser type, device type, session identifiersAutomatically collected
Payment dataSubscription plan, billing historyMollie (we never store card numbers)

We do not collect special categories of personal data (Article 9 GDPR) such as health, religion, or biometric data.

3

Why we collect it

PurposeDescription
AuthenticationTo sign you in securely via Google OAuth, LinkedIn OAuth, or email/password, and to maintain your session. For email/password accounts, your password is hashed before storage using a one-way algorithm and is never readable by us.
Social publishingTo publish posts to your connected LinkedIn, Instagram, Facebook, and X accounts on your behalf.
AI content generationTo generate post drafts using your brand knowledge as context. Your brand data is sent as prompt input to our AI provider (Anthropic).
AnalyticsTo display post performance metrics fetched from social platform APIs within your dashboard.
Product notificationsTo send you service-related emails (e.g. publishing errors, weekly digests). You can unsubscribe at any time.
Platform improvementAggregated, anonymised usage data helps us understand which features are used and where to invest. No individual users are identified in this analysis.
Security & fraud preventionTo detect and prevent abuse, unauthorised access, and technical failures.
Legal complianceTo fulfil our obligations under applicable law, including GDPR and Dutch law.
5

Third parties we work with

We share data with the following sub-processors to deliver the service. We have a Data Processing Agreement (DPA) with each.

ProviderRoleLocation
AnthropicAI content generation. Your brand context and approved post content is sent as prompt input. Anthropic does not use API inputs to train models by default.United States (SCCs in place)
Meta (Facebook / Instagram)Post publishing and analytics retrieval via the Meta Graph API.United States (SCCs in place)
LinkedInPost publishing and analytics retrieval via the LinkedIn API.United States (SCCs in place)
GoogleAuthentication (OAuth). We receive your name, email, and profile photo only.United States (SCCs in place)
Hetzner Online GmbHCloud infrastructure. All servers are located in Germany (EU).Germany, EU
MolliePayment processing. We never store card or payment details; Mollie handles all payment data. Mollie is headquartered in Amsterdam, the Netherlands.Netherlands, EU
fal.aiAI image generation (Pro and Agency plans only).United States (SCCs in place)

We do not sell your data. We do not share your personal data with advertisers, data brokers, or any other third parties except those listed above for the stated purposes.

6

Data retention

We keep your data for as long as necessary to provide the service or meet legal obligations.

Data typeRetention period
Account & brand dataUntil account deletion
Published post contentUntil account deletion
Post analytics (impressions, reach, etc.)90 days rolling
Connected Products API events365 days rolling
Failed publish reasons30 days (then anonymised)
OAuth tokens (social platforms)Deleted immediately when you disconnect a platform
Consent audit logs7 years (legal requirement)
Account deletion request records7 years (legal requirement)
Anonymised usage dataIndefinitely (no individual can be identified)

When you delete your account, all personal data is permanently erased within 30 days of the deletion request. A confirmation email will be sent when deletion is complete.

7

Your rights under GDPR

As a data subject under the GDPR, you have the following rights. These can be exercised free of charge and we will respond within 30 days.

Right of access (Art. 15)

Request a copy of all personal data we hold about you.

Right to rectification (Art. 16)

Ask us to correct inaccurate or incomplete data.

Right to erasure (Art. 17)

Request permanent deletion of your personal data (“right to be forgotten”).

Right to portability (Art. 20)

Receive your data in a structured, machine-readable format (JSON/CSV).

Right to restriction (Art. 18)

Ask us to pause processing of your data while a dispute is resolved.

Right to object (Art. 21)

Object to processing based on legitimate interests or for direct marketing.

Withdraw consent

Withdraw consent for marketing emails at any time without affecting prior processing.

Automated decision-making (Art. 22)

Merkflow does not make solely automated decisions that produce legal or similarly significant effects.

To exercise any of these rights, or to download or delete your data directly, log in to your account and go to Settings → Privacy & Data, or email us at support@merkflow.eu.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

8

Cookies

We use a minimal set of cookies required to operate the service. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

Cookie typePurposeConsent required?
Session cookiesKeep you authenticated while using the platform. Expire when you close your browser or after a fixed inactivity period.No — essential
Preference cookiesRemember your workspace selection and UI preferences (e.g. sidebar state).No — functional

Because we use only strictly necessary and functional cookies, no consent banner is required under the Dutch Telecommunications Act (Telecommunicatiewet) and the ePrivacy Directive.

9

Security

Encryption at rest: All OAuth access tokens and refresh tokens are encrypted using AES-256-GCM before being stored in the database. The encryption key never leaves the application layer.

Encryption in transit: All data is transmitted over HTTPS/TLS. Unencrypted connections are rejected.

Infrastructure: The platform runs on Hetzner servers in Germany (EU). No personal data is stored outside the EU by default.

Password security: Passwords (for email/password accounts) are hashed using a one-way algorithm (bcrypt/argon2) and are never stored in readable form — not even by us.

Access control: Access to production systems is restricted to authorised personnel via key-based authentication.

Incident response: In the event of a personal data breach, we will notify the Autoriteit Persoonsgegevens within 72 hours and affected users without undue delay, as required by GDPR Article 33–34.

10

International data transfers

Our infrastructure is hosted in Germany (EU). However, some of our sub-processors are based in the United States. We ensure adequate protection for these transfers through:

Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Decision 2021/914) are in place with all US-based sub-processors, including Anthropic, Meta, LinkedIn, Google, and fal.ai.

These transfers are made in accordance with GDPR Chapter V and the Schrems II ruling requirements, including a Transfer Impact Assessment (TIA) where appropriate.

11

LinkedIn & Meta platform compliance

LinkedIn data: We access your LinkedIn profile, organisation pages, and post analytics solely to provide the Merkflow service. We do not store LinkedIn member data beyond what is necessary for the service. We comply with the LinkedIn API Terms of Use and the LinkedIn Privacy Policy. LinkedIn member data is not used for advertising, re-sold, or shared with third parties beyond the processors listed in Section 5.

Meta (Facebook & Instagram) data: We access your Facebook Pages, Instagram Professional accounts, and post metrics solely to publish content and display analytics within Merkflow. We comply with Meta’s Platform Policy and Data Policy. Meta user data is not used for advertising, profiling, or any purpose beyond the stated service.

Data deletion callback: Meta requires that we provide a mechanism for users to request deletion of data associated with their Facebook login. You can request deletion of all your Merkflow data (including any data obtained via Facebook) by:

  1. Visiting Settings → Privacy & Data → Delete Account in your Merkflow dashboard, or
  2. Emailing support@merkflow.eu with the subject line “Data Deletion Request”, or
  3. Removing Merkflow from your Facebook app settings at facebook.com/settings, which triggers an automatic deletion request.

Upon receiving a deletion request through any of the above channels, all data associated with your account will be permanently deleted within 30 days. You will receive a confirmation email when deletion is complete.

Note for Meta App Review: The data deletion callback URL for the Merkflow Facebook application is: https://www.merkflow.eu/data-deletion. This endpoint processes signed deletion requests from Facebook and confirms deletion within 30 days.

12

Children

Merkflow is a professional B2B platform intended for adults. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has created an account, please contact us at support@merkflow.eu and we will delete the account promptly.

13

Changes to this policy

We may update this privacy policy from time to time. For any material changes — changes that meaningfully affect your rights or how we use your data — we will notify you by email at least 14 days before the change takes effect.

The “Last updated” date at the top of this policy reflects the most recent revision. The current version is always available at https://www.merkflow.eu/privacy-policy/.

Continued use of Merkflow after a change takes effect constitutes acceptance of the updated policy, where permitted by law.

14

Contact

If you have questions about this privacy policy, want to exercise your data rights, or have a complaint, please contact us:

Merkflow — Privacy Niels van Haren Holding B.V. (trading as Merkflow)
Saltshof 2014
6604 ES Wijchen
The Netherlands

Email: support@merkflow.eu

We aim to respond to all privacy-related requests within 30 days in accordance with GDPR Article 12(3). If your request is complex or numerous, we may extend this by a further two months and will inform you accordingly.

Autoriteit Persoonsgegevens PO Box 93374
2509 AJ Den Haag
The Netherlands

autoriteitpersoonsgegevens.nl