We use personal data to provide and secure AutoPoster, operate customer workspaces, connect services selected by customers, process subscriptions, administer affiliate referrals, and provide support. We do not sell personal data. On our webinar and signup pages, optional first-party analytics run only after you choose “Allow analytics.”
1. Who we are
BURO OPS AS
Organisation number 832 405 612
Ullevålsveien 12, 0171 Oslo, Norway
team@buroventures.com
BURO OPS AS operates AutoPoster. References to “BURO,” “AutoPoster,” “we,” or “us” in this notice mean BURO OPS AS.
2. When we are controller and processor
BURO as controller
We act as data controller for account registration, authentication, security, billing administration, product operations, support, and our own service communications.
BURO as processor
A business customer normally decides why and how personal data is placed in its workspace. For workspace content, connected-profile data, leads, comments, and integration data processed on that customer’s instructions, the customer is normally the controller and BURO acts as processor. Requests concerning data in a customer workspace may therefore need to be handled by that customer. Customers that require a data processing agreement can contact us.
3. Personal data we process
| Category | Examples | Purpose and legal basis | Retention criteria |
|---|---|---|---|
| Account and workspace data | Name, email, password hash, workspace name, role, membership, timezone, onboarding details and preferences. | Provide the account and workspace under our contract; manage access and customer support. | For the life of the account or workspace. Following a verified deletion or termination request, data is deleted or anonymised within 30 days unless it must be retained for security, disputes, or law. |
| Authentication and security data | Hashed session tokens, session expiry, browser or user-agent data, hashed IP values, login failures, password-reset and invite records, audit events. | Our legitimate interest in protecting accounts, investigating abuse, maintaining availability, and documenting security events. | Sessions remain until expiry or revocation. Reset and invite records remain through their validity and audit lifecycle. Security records remain while reasonably necessary to investigate, prevent, or document incidents. |
| Website and funnel analytics | A random journey identifier, webinar and signup page or step events, timestamps, referring page, campaign parameters, advertising click identifiers supplied in the URL, intended plan and billing period, and broad device category. We do not place passwords or form-field contents in analytics events. | Measure advertising and funnel performance, identify aggregate drop-off, and improve the signup journey. Optional analytics are based on consent. Attribution is connected to an account only when you register. | Journey and event-level analytics are normally deleted or anonymised after 12 months. Aggregate statistics that no longer identify a person may be kept longer. |
| Affiliate referral data | Affiliate link or partner key, referral cookie, referred account and workspace, signup time, and subscription or commission attribution. | Recognise and administer referrals, prevent duplicate or fraudulent commissions, and maintain financial records for our affiliate program. We process this data for our legitimate interests in operating and protecting the program and, where applicable, to perform an affiliate agreement. | Referral and commission records remain for the attribution and payout lifecycle and thereafter while required for accounting, fraud prevention, disputes, or legal obligations. |
| Saved signup progress | Email address, name, intended workspace name, selected plan, last completed signup step, and attribution. | Save unfinished signup progress in the background so we can provide a secure resume link and send signup-recovery messages when needed. The basis is our legitimate interest in helping you complete registration, and you can unsubscribe from recovery messages at any time. | Unfinished signup drafts expire after 30 days. Recovery stops earlier if you complete the relevant step, withdraw, unsubscribe, or are suppressed. |
| Workspace content | Business context, goals, writing rules, resources, URLs, templates, prompts, drafts, post text, images, schedules, review decisions, and publishing status. | Perform the service under our contract and the customer’s documented instructions. | Until the customer deletes the item or workspace, or the account is terminated, subject to the 30-day deletion process and required backups or legal holds. |
| LinkedIn and professional data | Connected-member identifiers, display name, email, profile image, LinkedIn URL, public professional profile information, posts, comments, engagement data, job title, company and contact details. | Connect and publish to authorised profiles, analyse content response, capture resource requests, and operate customer-directed B2B workflows. The basis is contract/customer instruction and, where BURO acts as controller, legitimate interests that must not override individual rights. | Connected credentials remain until disconnected, revoked, or expired. Workspace profile, lead, and engagement records remain until the customer deletes them or terminates the workspace, subject to legal or dispute requirements. |
| Credentials and integration data | Encrypted LinkedIn tokens, API credentials, webhook secrets, provider identifiers, scopes, connection status, last-used time, and integration metadata. | Operate integrations chosen by the customer and protect access under our contract. | Until removed, rotated, disconnected, expired, or the workspace is deleted. Hashed or audit records may remain where needed for security. |
| AI and usage metadata | Prompt context sent to a selected model, model and provider, generation purpose, token and image usage, cost, response status, and related content references. | Generate requested content, administer plan usage, diagnose failures, and improve service reliability under contract and our legitimate operational interests. | Generated content follows workspace-content retention. Usage and cost records are retained for billing, quota administration, troubleshooting, and financial reconciliation, normally up to 12 months unless a longer period is required for a dispute or law. |
| Billing data | Plan, Stripe customer and subscription identifiers, subscription status, billing period, checkout-session data, refund and webhook records. We do not store full payment-card details. | Manage subscriptions and payments under our contract and comply with accounting and tax obligations. | For the subscription lifecycle and thereafter for the period required by accounting, tax, fraud-prevention, or dispute rules. |
| Support and communications | Email address, message content, service notices, support history, and communication preferences. | Respond to requests, send necessary product or security messages, and send marketing where permitted. Bases include contract, legitimate interest, and consent where required. | Support correspondence remains for as long as needed to resolve and document the request. Marketing preferences remain until withdrawal or unsubscribe. |
Providing account and workspace information is necessary to use the relevant parts of AutoPoster. If you do not provide it, we may be unable to create an account, connect a service, process payment, or perform the requested workflow.
4. Where the data comes from
- Directly from you when you register, configure a workspace, create content, contact support, or provide credentials.
- From the organisation that invites you to or administers a workspace.
- From LinkedIn and other services you or the customer connect.
- From public professional sources and supported enrichment or publishing providers when a customer enables those workflows.
- Automatically from service use, authentication, API calls, publishing jobs, and security events.
6. International transfers
Some providers may process data outside Norway or the EEA. Where GDPR requires a transfer mechanism, we use an applicable adequacy decision, the European Commission’s Standard Contractual Clauses, or another valid safeguard. The exact destination can depend on the provider and model selected by the customer. Contact us for information about safeguards relevant to a specific workflow.
8. How we protect data
Measures in the current service include password hashing, hashed session and API tokens, encryption of supported integration credentials and LinkedIn tokens, secure production cookies, CSRF protection, rate limits, workspace access checks, database row-level policies for sensitive connection data, and restricted administrative access. No system is completely secure, and we cannot guarantee that unauthorised access will never occur.
9. AI, scoring, and automated decisions
AutoPoster uses AI to draft and transform content, select templates, analyse publishing context, and, where enabled, score leads or identify performance patterns. These features support customer workflows; BURO does not use AutoPoster to make solely automated decisions about individuals that produce legal or similarly significant effects. Customers are responsible for reviewing their own use of lead scoring and automated workflows.
10. Your privacy rights
Depending on the circumstances, you may have the right to access, correct, delete, restrict, or receive a portable copy of your personal data, and to object to processing based on legitimate interests. Where processing depends on consent, you may withdraw that consent without affecting earlier lawful processing.
Authenticated users can request a portable copy of their account data and owned workspace data from My account → Export. Email team@buroventures.com to exercise another right or request assistance. We may need to verify your identity. If the data belongs to a customer workspace, we may direct the request to that customer or assist them as processor.
You may complain to the Norwegian Data Protection Authority (Datatilsynet) or another competent supervisory authority.
11. Children
AutoPoster is a business and professional service and is not intended for children. Do not create an account if you are under 18.
12. Changes to this notice
We may update this notice when the product, providers, or legal requirements change. We will update the effective date and provide reasonable notice of material changes through the service or by email where appropriate.
13. Contact
Privacy questions, rights requests, or data-processing-agreement requests can be sent to team@buroventures.com.
BURO OPS AS, Ullevålsveien 12, 0171 Oslo, Norway. Organisation number 832 405 612.