1.Controller
The controller of your personal data as an Onecast User is a sole trader registered in CEIDG:
- Name
- Onecast Paweł Zaręba
- Address
- ul. Piastowska 17, 42-256 Przymiłowice, Polska
- Tax ID (NIP)
- 9492285992
- REGON
- 545521872
- Phone
- +48786583222
- kontakt@onecast.pl
For personal data matters, contact us at kontakt@onecast.pl.
2.Controller or processor
Onecast is the CONTROLLER of data directly related to using the service:
- Account data, memberships, roles and invitations,
- access tokens and authorisation data of connected Channels (including the account ID on the platform and granted permissions) — to the extent needed for the integrations to work and stay secure,
- agreement, declaration, billing and payment data,
- Support requests, complaints and other requests,
- technical data: sessions, logs and security data.
Onecast is a PROCESSOR of data it processes on behalf of your Organization, on its instructions and for its purposes:
- personal data contained in the posts and media you create, schedule and publish, and in your Channels’ publications (including those imported from platforms),
- comments and their authors’ data (display name, handle, avatar, ID, text) retrieved from platforms, where the comments feature is enabled,
- profile data of connected Channels (name, handle, avatar) displayed and used in Onecast for your Organization,
- personal data of other people that you put in the name, description, icon or logo of an Organization or Workspace (e.g. data of the client a Workspace is run for).
The post and Channel statistics we retrieve are aggregate numbers (e.g. like or follower counts) and contain no data about individual audience members.
3.Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and running the Account, Organizations and Workspaces, handling invitations and roles | Article 6(1)(b) GDPR — performance of a contract and steps prior to entering into it. |
| Connecting Channels, publishing and scheduling posts, retrieving statistics and publications (including storing access tokens) | Article 6(1)(b) GDPR — performance of a contract. |
| Service messages (publication status, Channel reconnection, trial, billing) | Article 6(1)(b) GDPR. |
| Concluding and performing the paid agreement, handling payments and subscriptions | Article 6(1)(b) GDPR. |
| Delivering the contract confirmation on a durable medium; tax and accounting obligations | Article 6(1)(c) GDPR in conjunction with Article 21 of the Polish Consumer Rights Act and tax and accounting laws. |
| Documenting acceptance of the Terms and Checkout declarations; establishing, exercising and defending legal claims — also after the Account is deleted, in pseudonymised form | Article 6(1)(f) GDPR — legitimate interest in being able to prove the agreement terms and defend against claims; after Account deletion also Article 17(3)(e) GDPR. |
| Handling complaints, withdrawals and data requests | Article 6(1)(c) GDPR (obligations under the Consumer Rights Act and GDPR) and point (b). |
| Handling Support requests | Article 6(1)(b) GDPR and, for keeping correspondence after the matter is closed, Article 6(1)(f) GDPR. |
| Service security, bot protection (Cloudflare Turnstile), logs, abuse detection | Article 6(1)(f) GDPR — legitimate interest in ensuring security. |
| Handling notices of illegal content (Digital Services Act) | Article 6(1)(c) GDPR in conjunction with Articles 16–17 of Regulation (EU) 2022/2065. |
- Purpose
- Creating and running the Account, Organizations and Workspaces, handling invitations and roles
- Legal basis
- Article 6(1)(b) GDPR — performance of a contract and steps prior to entering into it.
- Purpose
- Connecting Channels, publishing and scheduling posts, retrieving statistics and publications (including storing access tokens)
- Legal basis
- Article 6(1)(b) GDPR — performance of a contract.
- Purpose
- Service messages (publication status, Channel reconnection, trial, billing)
- Legal basis
- Article 6(1)(b) GDPR.
- Purpose
- Concluding and performing the paid agreement, handling payments and subscriptions
- Legal basis
- Article 6(1)(b) GDPR.
- Purpose
- Delivering the contract confirmation on a durable medium; tax and accounting obligations
- Legal basis
- Article 6(1)(c) GDPR in conjunction with Article 21 of the Polish Consumer Rights Act and tax and accounting laws.
- Purpose
- Documenting acceptance of the Terms and Checkout declarations; establishing, exercising and defending legal claims — also after the Account is deleted, in pseudonymised form
- Legal basis
- Article 6(1)(f) GDPR — legitimate interest in being able to prove the agreement terms and defend against claims; after Account deletion also Article 17(3)(e) GDPR.
- Purpose
- Handling complaints, withdrawals and data requests
- Legal basis
- Article 6(1)(c) GDPR (obligations under the Consumer Rights Act and GDPR) and point (b).
- Purpose
- Handling Support requests
- Legal basis
- Article 6(1)(b) GDPR and, for keeping correspondence after the matter is closed, Article 6(1)(f) GDPR.
- Purpose
- Service security, bot protection (Cloudflare Turnstile), logs, abuse detection
- Legal basis
- Article 6(1)(f) GDPR — legitimate interest in ensuring security.
- Purpose
- Handling notices of illegal content (Digital Services Act)
- Legal basis
- Article 6(1)(c) GDPR in conjunction with Articles 16–17 of Regulation (EU) 2022/2065.
4.What data we process
- Account data
- name, e-mail address, password (hash only), date of last sign-in, settings and preferences, optionally passkey/2FA data.
- Organization and Workspace data
- name, time zone, members and their roles and — optionally — icon, logo, brand colour, description and website address.
- Channel data
- access tokens (encrypted), name, handle, avatar and ID of the connected account, scope of granted permissions.
- Content and publications
- post content and media; publication metadata (ID, link, description, thumbnail, date) for posts published through Onecast and publications imported at your request.
- Statistics
- history of aggregate engagement numbers of posts and follower counts of Channels.
- Third-party comments
- comment text, display name, handle, avatar and ID of the author, like count — only for platforms with the comments feature enabled.
- Agreement and billing data
- billing details from Checkout (name or company name, address, country, optionally tax ID), agreement terms and declaration wording, Stripe IDs and statuses, plan, amounts, dates, payment method type and the last four card digits. Full card details are processed only by Stripe.
- Declaration records
- document type, version, language, date and context (registration, Checkout) — without IP address or browser information.
- Technical data
- IP address and browser information in the active session record, application logs, technical signals analysed by Cloudflare Turnstile.
- Correspondence
- Support requests, complaints, withdrawal statements, data requests and attachments.
5.Recipients and processors
We share data only with entities without which the service cannot run, under data processing agreements or — where the recipient acts as a separate controller — to the extent necessary for the given service:
| Recipient | Purpose and data | Role and location |
|---|---|---|
| OVH Sp. z o.o. (OVHcloud), Wrocław | Application server (VPS), database and backups — all data processed by the application. | Processor; data centre in the EU. Remote access by OVHcloud group companies, including outside the EEA — see below. |
| OVH Sp. z o.o. (OVHcloud), Wrocław — Zimbra e-mail | Sending messages over SMTP: contract confirmations with attachments, notifications, invitations, password resets — e-mail address and message content. | Processor; mailboxes in OVHcloud data centres in France. |
| Cloudflare, Inc. — R2 | File storage, in particular post media and their versions. | Processor; US company — possible transfer outside the EEA (see below). |
| Cloudflare, Inc. — Turnstile | Protecting sign-in and registration forms from bots: IP address, browser and connection information. | Processor; for improving bot detection — a separate controller. US company. |
| Stripe Payments Europe, Limited (Ireland) and Stripe group companies | Payments, payment methods, subscriptions, payment documents: billing details, e-mail address, payment method data. | Processor for payment processing; separate controller for fraud prevention, risk management and AML obligations. Possible transfer to the US. |
- Recipient
- OVH Sp. z o.o. (OVHcloud), Wrocław
- Purpose and data
- Application server (VPS), database and backups — all data processed by the application.
- Role and location
- Processor; data centre in the EU. Remote access by OVHcloud group companies, including outside the EEA — see below.
- Recipient
- OVH Sp. z o.o. (OVHcloud), Wrocław — Zimbra e-mail
- Purpose and data
- Sending messages over SMTP: contract confirmations with attachments, notifications, invitations, password resets — e-mail address and message content.
- Role and location
- Processor; mailboxes in OVHcloud data centres in France.
- Recipient
- Cloudflare, Inc. — R2
- Purpose and data
- File storage, in particular post media and their versions.
- Role and location
- Processor; US company — possible transfer outside the EEA (see below).
- Recipient
- Cloudflare, Inc. — Turnstile
- Purpose and data
- Protecting sign-in and registration forms from bots: IP address, browser and connection information.
- Role and location
- Processor; for improving bot detection — a separate controller. US company.
- Recipient
- Stripe Payments Europe, Limited (Ireland) and Stripe group companies
- Purpose and data
- Payments, payment methods, subscriptions, payment documents: billing details, e-mail address, payment method data.
- Role and location
- Processor for payment processing; separate controller for fraud prevention, risk management and AML obligations. Possible transfer to the US.
When you connect a Channel and publish through Onecast, at your instruction we transfer content and media to the chosen platform (e.g. Meta Platforms — Facebook, Instagram, Threads; TikTok; LinkedIn; Google — YouTube; Bluesky; the operator of the chosen Mastodon instance). Those platforms are separate controllers of data processed on their side, under their own privacy policies.
We may also disclose data to public authorities where required by law and — in case of a dispute — to our legal or accounting advisers bound by confidentiality.
6.Transfers outside the European Economic Area
Some recipients (Cloudflare, the Stripe group, the social platforms you integrate with) are based or process data outside the EEA, in particular in the United States; OVHcloud group companies outside the EEA (e.g. in Canada) may have remote access to data where necessary to provide the service. Transfers rely on:
- Commission adequacy decisions (Article 45 GDPR), including Implementing Decision (EU) 2023/1795 on the EU–U.S. Data Privacy Framework — for US recipients certified under it,
- standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 (Article 46(2)(c) GDPR) — where the recipient does not rely on an adequacy decision; used by, among others, Stripe and OVHcloud.
You can obtain a copy of the safeguards applied by writing to the address under “Controller”. Decision 2023/1795 remains in force; its validity is the subject of an appeal before the Court of Justice of the EU (case C-703/25 P).
7.Retention periods
| Data category | Retention period |
|---|---|
| Account, Organization and Workspace data | Until you delete the Account, Organization or Workspace — see Data deletion. We automatically delete: an Account that does not belong to any Organization — after 30 days; an Organization without an active plan — 90 days after its last plan ended, together with its Owner’s Account if the Owner does not belong to another Organization. In both cases we give notice by e-mail, as set out in the Terms of Service. |
| Channel access tokens | Until the Channel is disconnected, access to it is permanently lost or the Workspace, Organization or Account is deleted — deleted immediately. The “needs reconnection” state after an ambiguous error does not delete them by itself. |
| Post content and media | Until the Workspace, Organization or Account is deleted, or the Channel history is deleted. A deleted post disappears from the post list at once, while its technical record remains until the Workspace is deleted. Deleted media are erased from file storage within minutes and, in case of technical problems, in further automatically retried attempts. |
| Publications and statistics | Imported publications — until the Channel is disconnected. Publications created through Onecast and statistics — until the Channel history, Workspace, Organization or Account is deleted. |
| YouTube API data | Titles, descriptions, thumbnails, channel profile data and the publishing response — at most 30 days from the last retrieval from YouTube (refreshed or deleted before that). Statistics — as long as needed, provided authorization is confirmed at least every 30 days. After the channel is disconnected, all YouTube data, including channel and video IDs, is deleted without undue delay; when access cannot be confirmed — after 30 days at the latest. The Onecast post history remains, with the channel shown as “Disconnected YouTube channel”. On request — deleted within 7 days. |
| Third-party comments | 30 days from when the comment was posted on the platform (Facebook, Instagram, Threads, YouTube, Bluesky); earlier — when the Channel is disconnected or access is permanently lost. After a comment is deleted on the platform, its text and author data are deleted immediately and the technical marker after 72 hours, never later than the comment itself. LinkedIn comments are not stored. |
| Registration and Checkout declaration records; contract confirmations | For as long as the Account exists. After the Account is deleted: for people without a paid agreement — deleted with the Account; for people who concluded a paid agreement — the personalised PDF is deleted and minimal pseudonymised evidence of the agreement terms is kept until the end of the calendar year in which 6 years pass from the last relevant event of the agreement (conclusion, end of subscription, last payment or refund) — the longest limitation period for claims that may arise from the agreement (Articles 118 and 120 of the Polish Civil Code). Longer only for the duration of an ongoing dispute. |
| Accounting and payment documents | For the period required by tax and accounting laws — as a rule 5 years from the end of the calendar year in which the tax payment deadline passed (Polish Tax Ordinance), also after the Account is deleted. Payment documents are kept by Stripe. |
| Support requests | Not deleted automatically with the Account — after it is deleted they are no longer linked to it. We delete them on request, unless they are needed to establish, exercise or defend legal claims. |
| Sessions | Until sign-out or 2 hours of inactivity; with “Remember me” — until sign-out, at most about 400 days. |
| Technical logs | Up to 14 days. |
| Backups | The database is backed up daily. Data deleted in the application remains in backups until they are rotated — backups are used only to restore the service after a failure and for no other purpose. |
- Data category
- Account, Organization and Workspace data
- Retention period
- Until you delete the Account, Organization or Workspace — see Data deletion. We automatically delete: an Account that does not belong to any Organization — after 30 days; an Organization without an active plan — 90 days after its last plan ended, together with its Owner’s Account if the Owner does not belong to another Organization. In both cases we give notice by e-mail, as set out in the Terms of Service.
- Data category
- Channel access tokens
- Retention period
- Until the Channel is disconnected, access to it is permanently lost or the Workspace, Organization or Account is deleted — deleted immediately. The “needs reconnection” state after an ambiguous error does not delete them by itself.
- Data category
- Post content and media
- Retention period
- Until the Workspace, Organization or Account is deleted, or the Channel history is deleted. A deleted post disappears from the post list at once, while its technical record remains until the Workspace is deleted. Deleted media are erased from file storage within minutes and, in case of technical problems, in further automatically retried attempts.
- Data category
- Publications and statistics
- Retention period
- Imported publications — until the Channel is disconnected. Publications created through Onecast and statistics — until the Channel history, Workspace, Organization or Account is deleted.
- Data category
- YouTube API data
- Retention period
- Titles, descriptions, thumbnails, channel profile data and the publishing response — at most 30 days from the last retrieval from YouTube (refreshed or deleted before that). Statistics — as long as needed, provided authorization is confirmed at least every 30 days. After the channel is disconnected, all YouTube data, including channel and video IDs, is deleted without undue delay; when access cannot be confirmed — after 30 days at the latest. The Onecast post history remains, with the channel shown as “Disconnected YouTube channel”. On request — deleted within 7 days.
- Data category
- Third-party comments
- Retention period
- 30 days from when the comment was posted on the platform (Facebook, Instagram, Threads, YouTube, Bluesky); earlier — when the Channel is disconnected or access is permanently lost. After a comment is deleted on the platform, its text and author data are deleted immediately and the technical marker after 72 hours, never later than the comment itself. LinkedIn comments are not stored.
- Data category
- Registration and Checkout declaration records; contract confirmations
- Retention period
- For as long as the Account exists. After the Account is deleted: for people without a paid agreement — deleted with the Account; for people who concluded a paid agreement — the personalised PDF is deleted and minimal pseudonymised evidence of the agreement terms is kept until the end of the calendar year in which 6 years pass from the last relevant event of the agreement (conclusion, end of subscription, last payment or refund) — the longest limitation period for claims that may arise from the agreement (Articles 118 and 120 of the Polish Civil Code). Longer only for the duration of an ongoing dispute.
- Data category
- Accounting and payment documents
- Retention period
- For the period required by tax and accounting laws — as a rule 5 years from the end of the calendar year in which the tax payment deadline passed (Polish Tax Ordinance), also after the Account is deleted. Payment documents are kept by Stripe.
- Data category
- Support requests
- Retention period
- Not deleted automatically with the Account — after it is deleted they are no longer linked to it. We delete them on request, unless they are needed to establish, exercise or defend legal claims.
- Data category
- Sessions
- Retention period
- Until sign-out or 2 hours of inactivity; with “Remember me” — until sign-out, at most about 400 days.
- Data category
- Technical logs
- Retention period
- Up to 14 days.
- Data category
- Backups
- Retention period
- The database is backed up daily. Data deleted in the application remains in backups until they are rotated — backups are used only to restore the service after a failure and for no other purpose.
8.Security
- all communication with Onecast uses an encrypted HTTPS connection,
- Channel access tokens are encrypted and passwords stored only as hashes,
- files and documents are stored privately, without public URLs,
- only authorized people have access to the operations panel, with a separate sign-in and an activity log,
- in the event of a personal data breach we notify the President of the Personal Data Protection Office without undue delay — where feasible, within 72 hours — unless the breach is unlikely to result in a risk to individuals, and we notify the data subjects without undue delay where the breach is likely to result in a high risk (Articles 33–34 GDPR).
9.Data processing agreement (DPA)
To the extent Onecast processes personal data as your Organization’s processor (see “Controller or processor”), the terms are set out in the Data Processing Agreement — Annex 1 to the Terms of Service, concluded together with them when you sign up. It describes the subject matter, duration, nature and purpose of processing, the types of data and categories of data subjects, the parties’ rights and obligations, the sub-processors (Annex A) and the technical and organisational measures (Annex B). Send questions about data processing to kontakt@onecast.pl.
10.Your rights
Regarding processing by Onecast as controller, you have the right to:
- access your data and obtain a copy,
- rectify your data,
- erasure — except for data we must or may keep (e.g. accounting documents, pseudonymised evidence of a paid agreement needed to defend claims),
- restriction of processing,
- portability of data processed under a contract,
- object to processing based on legitimate interest,
- lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).
To exercise these rights, write to the address under “Controller”. You can exercise some of them yourself in Onecast (e.g. editing Account details, disconnecting a Channel, deleting a post, Workspace, Organization or Account). We reply within one month of receiving a request.
For data controlled by an Organization using Onecast (e.g. your comment under its post), contact that Organization or the platform where you posted the comment. If you write to us, we will help identify the right Organization and forward your request. Deleting a comment on the platform also deletes its text and author data in Onecast.
11.Whether providing data is required
Providing data is voluntary, but necessary to create an Account and use Onecast. Billing details are necessary to conclude a Paid Agreement and are also required by tax law; without them you can use the trial and, once it ends, your Account and collected data in read-only mode. Continuing to use the active features (publishing, scheduling publications, synchronizing Channels) requires concluding a Paid Agreement.
12.Automated decision-making
We do not take decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. Automatic rules (e.g. plan limits, pausing publishing when a subscription is unpaid) follow directly from the agreement.