Legal document

Privacy Policy

How Merkflow collects, uses, and protects your personal data.

Last updated: April 2026 Jurisdiction: European Union (GDPR) Contact: support@merkflow.eu
1

Who we are

Merkflow is an AI-powered social media management platform operated by Niels van Haren Holding B.V. (trading as Merkflow), a company registered in the Netherlands (Chamber of Commerce: 73338397).

For the purposes of the General Data Protection Regulation (GDPR), we are the data controller for the personal data described in this policy.

Merkflow Niels van Haren Holding B.V. (trading as Merkflow)
Saltshof 2014
6604 ES Wijchen
The Netherlands

Email: support@merkflow.eu
Website: https://www.merkflow.eu
2

Data we collect

We collect only the data necessary to provide the Merkflow service.

CategoryExamplesSource
Account dataName, email address, profile photoGoogle OAuth, LinkedIn OAuth, or email/password registration
Password (if applicable)Hashed password (bcrypt/argon2 — never stored in plaintext)Provided at registration; only applies to email/password accounts
Social media tokensOAuth access & refresh tokens for LinkedIn, Instagram, Facebook, XPlatform OAuth flows; encrypted at rest
Brand dataWebsite URLs, onboarding answers, post content you create or approveProvided directly by you
AI-generated contentPost drafts, captions, hashtags generated by the AICreated by Merkflow on your behalf
Analytics dataImpressions, reach, engagement metrics per postFetched from social platform APIs
Usage dataPosts generated, platforms connected, workspace activityAutomatically collected
Technical dataIP address, browser type, device type, session identifiersAutomatically collected
Payment dataSubscription plan, billing historyMollie (we never store card numbers)

We do not collect special categories of personal data (Article 9 GDPR) such as health, religion, or biometric data.

3

Why we collect it

PurposeDescription
AuthenticationTo sign you in securely via Google OAuth, LinkedIn OAuth, or email/password, and to maintain your session. For email/password accounts, your password is hashed before storage using a one-way algorithm and is never readable by us.
Social publishingTo publish posts to your connected LinkedIn, Instagram, Facebook, and X accounts on your behalf.
AI content generationTo generate post drafts using your brand knowledge as context. Your brand data is sent as prompt input to our AI provider (Anthropic).
AnalyticsTo display post performance metrics fetched from social platform APIs within your dashboard.
Product notificationsTo send you service-related emails (e.g. publishing errors, weekly digests). You can unsubscribe at any time.
Platform improvementAggregated, anonymised usage data helps us understand which features are used and where to invest. No individual users are identified in this analysis.
Security & fraud preventionTo detect and prevent abuse, unauthorised access, and technical failures.
Legal complianceTo fulfil our obligations under applicable law, including GDPR and Dutch law.
5

Third parties we work with

We share data with the following sub-processors to deliver the service. We have a Data Processing Agreement (DPA) with each.

ProviderRoleLocation
AnthropicAI content generation. Your brand context and approved post content is sent as prompt input. Anthropic does not use API inputs to train models by default.United States (SCCs in place)
Meta (Facebook / Instagram)Post publishing and analytics retrieval via the Meta Graph API.United States (SCCs in place)
LinkedInPost publishing and analytics retrieval via the LinkedIn API.United States (SCCs in place)
GoogleAuthentication (OAuth) — we receive your name, email, and profile photo only. Also Google Analytics on our marketing website (www.merkflow.eu), loaded only after you accept analytics cookies (see “Cookies”).United States (SCCs in place)
Hetzner Online GmbHCloud infrastructure. All servers are located in Germany (EU).Germany, EU
MolliePayment processing. We never store card or payment details; Mollie handles all payment data. Mollie is headquartered in Amsterdam, the Netherlands.Netherlands, EU
fal.aiAI image generation (Pro and Agency plans only).United States (SCCs in place)

We do not sell your data. We do not share your personal data with advertisers, data brokers, or any other third parties except those listed above for the stated purposes.

6

Data retention

We keep your data for as long as necessary to provide the service or meet legal obligations.

Data typeRetention period
Account & brand dataUntil account deletion
Your authored post contentUp to 24 months (after which the text is removed; the record is kept until account deletion)
Posts synced from connected platformsContent kept up to 6 months (e.g. LinkedIn organisation pages); reference IDs retained. Removed sooner if the platform requires it or the post is deleted upstream.
Comments, mentions & likes from other people on your postsLinkedIn: content removed within 48 hours, the member's display name within 24 hours; reference IDs (URNs) retained. See Section 11.
Post analytics (impressions, reach, etc.)12 months rolling
Connected Products API events365 days rolling
Failed publish reasons30 days (then anonymised)
OAuth tokens (social platforms)Deleted immediately when you disconnect a platform
Consent audit logs7 years (legal requirement)
Account deletion request records7 years (legal requirement)
Anonymised usage dataIndefinitely (no individual can be identified)

When you delete your account, all personal data is permanently erased within 30 days of the deletion request. A confirmation email will be sent when deletion is complete.

7

Your rights under GDPR

As a data subject under the GDPR, you have the following rights. These can be exercised free of charge and we will respond within 30 days.

Right of access (Art. 15)

Request a copy of all personal data we hold about you.

Right to rectification (Art. 16)

Ask us to correct inaccurate or incomplete data.

Right to erasure (Art. 17)

Request permanent deletion of your personal data (“right to be forgotten”).

Right to portability (Art. 20)

Receive your data in a structured, machine-readable format (JSON/CSV).

Right to restriction (Art. 18)

Ask us to pause processing of your data while a dispute is resolved.

Right to object (Art. 21)

Object to processing based on legitimate interests or for direct marketing.

Withdraw consent

Withdraw consent for marketing emails at any time without affecting prior processing.

Automated decision-making (Art. 22)

Merkflow does not make solely automated decisions that produce legal or similarly significant effects.

To exercise any of these rights, or to download or delete your data directly, log in to your account and go to Settings → Privacy & Data, or email us at support@merkflow.eu.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

8

Cookies

We use a small set of cookies. Strictly necessary and functional cookies are always active because the service cannot work without them. Analytics cookies are only set if you accept them via our cookie banner — we use no advertising cookies or tracking pixels.

Cookie typePurposeConsent required?
Session cookiesKeep you authenticated while using the platform. Expire when you close your browser or after a fixed inactivity period.No — essential
Preference cookiesRemember your workspace selection and UI preferences (e.g. sidebar state).No — functional
Google Analytics (_ga, _ga_*)Help us understand how visitors find and use our marketing website (www.merkflow.eu) so we can improve it. Aggregated statistics only — never used for advertising.Yes — opt-in

Your choice. Google Analytics loads with Google Consent Mode v2 and storage denied by default — no analytics cookies are placed until you click “Accept” on the cookie banner shown on your first visit. If you decline, no analytics cookies are set. You can change or withdraw your choice at any time via the “Cookie settings” link in the website footer.

Google Analytics is provided by Google Ireland Ltd. / Google LLC (United States), acting as a processor on our behalf. GA4 does not store full IP addresses. See “Third parties we work with” and “International data transfers” below for the safeguards that apply to this transfer.

9

Security

Encryption at rest: All OAuth access tokens and refresh tokens are encrypted using AES-256-GCM before being stored in the database. The encryption key never leaves the application layer.

Encryption in transit: All data is transmitted over HTTPS/TLS. Unencrypted connections are rejected.

Infrastructure: The platform runs on Hetzner servers in Germany (EU). No personal data is stored outside the EU by default.

Password security: Passwords (for email/password accounts) are hashed using a one-way algorithm (bcrypt/argon2) and are never stored in readable form — not even by us.

Access control: Access to production systems is restricted to authorised personnel via key-based authentication.

Incident response: In the event of a personal data breach, we will notify the Autoriteit Persoonsgegevens within 72 hours and affected users without undue delay, as required by GDPR Article 33–34.

10

International data transfers

Our infrastructure is hosted in Germany (EU). However, some of our sub-processors are based in the United States. We ensure adequate protection for these transfers through:

Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Decision 2021/914) are in place with all US-based sub-processors, including Anthropic, Meta, LinkedIn, Google, and fal.ai.

These transfers are made in accordance with GDPR Chapter V and the Schrems II ruling requirements, including a Transfer Impact Assessment (TIA) where appropriate.

11

LinkedIn & Meta platform compliance

LinkedIn data: We access your LinkedIn profile, organisation pages, and post analytics solely to provide the Merkflow service — not for advertising, sales, or recruiting. We comply with the LinkedIn API Terms of Use and the LinkedIn Privacy Policy, including their data-storage limits. In line with those limits we retain LinkedIn member data only for the minimum necessary period: a member’s comment or mention content for at most 48 hours, a member’s display name for at most 24 hours, synced organisation-page post content for at most 6 months, and aggregate page statistics for at most 12 months. We keep the underlying reference IDs (URNs) but not the content beyond these windows. When content is deleted or changed on LinkedIn (or another connected platform), we delete or update our copy within 24 hours. LinkedIn member data is never used for advertising, re-sold, exported, or shared with third parties beyond the processors listed in Section 5 — other people’s comments and likes are shown to you in-app only.

Meta (Facebook & Instagram) data: We access your Facebook Pages, Instagram Professional accounts, and post metrics solely to publish content and display analytics within Merkflow. We comply with Meta’s Platform Policy and Data Policy. Meta user data is not used for advertising, profiling, or any purpose beyond the stated service.

Data deletion callback: Meta requires that we provide a mechanism for users to request deletion of data associated with their Facebook login. You can request deletion of all your Merkflow data (including any data obtained via Facebook) by:

  1. Visiting Settings → Privacy & Data → Delete Account in your Merkflow dashboard, or
  2. Emailing support@merkflow.eu with the subject line “Data Deletion Request”, or
  3. Removing Merkflow from your Facebook app settings at facebook.com/settings, which triggers an automatic deletion request.

Upon receiving a deletion request through any of the above channels, all data associated with your account will be permanently deleted within 30 days. You will receive a confirmation email when deletion is complete.

Note for Meta App Review: The data deletion callback URL for the Merkflow Facebook application is: https://www.merkflow.eu/data-deletion. This endpoint processes signed deletion requests from Facebook and confirms deletion within 30 days.

12

Children

Merkflow is a professional B2B platform intended for adults. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has created an account, please contact us at support@merkflow.eu and we will delete the account promptly.

13

Changes to this policy

We may update this privacy policy from time to time. For any material changes — changes that meaningfully affect your rights or how we use your data — we will notify you by email at least 14 days before the change takes effect.

The “Last updated” date at the top of this policy reflects the most recent revision. The current version is always available at https://www.merkflow.eu/privacy-policy/.

Continued use of Merkflow after a change takes effect constitutes acceptance of the updated policy, where permitted by law.

14

Contact

If you have questions about this privacy policy, want to exercise your data rights, or have a complaint, please contact us:

Merkflow — Privacy Niels van Haren Holding B.V. (trading as Merkflow)
Saltshof 2014
6604 ES Wijchen
The Netherlands

Email: support@merkflow.eu

We aim to respond to all privacy-related requests within 30 days in accordance with GDPR Article 12(3). If your request is complex or numerous, we may extend this by a further two months and will inform you accordingly.

Autoriteit Persoonsgegevens PO Box 93374
2509 AJ Den Haag
The Netherlands

autoriteitpersoonsgegevens.nl