Streamlists Studio
TermsPrivacyContact
Privacy

Privacy Notice

How the private Streamlists Studio service handles connected-account and publishing data. Effective 21 August 2026.

Scope: This notice covers the private Service and this public information site. The Service has no public registration and is operated for one authorised operator.

1. Who is responsible

TECHAV operates Streamlists Studio and acts as controller for personal data handled through the Service. Privacy questions and rights requests may be submitted through the secure contact form. More information about the operator is available at techav.co.uk.

2. Data we handle

TikTok account data

When the operator connects TikTok, we may receive the account’s TikTok open_id and account/profile data made available by the approved integration, such as display name, avatar, and account status or capability information.

OAuth permissions and credentials

We handle the OAuth scopes approved on TikTok’s consent screen and the resulting access and refresh tokens. The exact scopes depend on the enabled features and may include basic user information, video upload, direct posting, and status access. Passwords for TikTok are not requested or stored by Streamlists Studio.

Content and publishing data

We may handle video files or references to them, thumbnails, captions, hashtags, disclosure or privacy selections, intended publication times, connected-account selection, publishing metadata, platform post identifiers, processing status, error messages, and an operational history of preparation, review, scheduling, and publishing actions.

Contact enquiry and technical data

If you use the contact form, we process your name, email address, subject, message, and any information you include so that TECHAV can review and respond to the enquiry. Our hosting and security systems may also process request time, IP address, user agent, requested path, and limited diagnostic logs. This public site does not set analytics or advertising cookies and includes no third-party tracking scripts.

3. Why we use data

We use this data only as needed to:

  • authenticate and identify the operator’s authorised connected account;
  • prepare, preview, review, schedule, upload, publish, and check the status of operator-approved content;
  • maintain security, prevent unauthorised access, diagnose errors, and keep operational records;
  • respond to support, privacy, deletion, or revocation requests; and
  • comply with applicable law and TikTok platform requirements.

For UK and European Economic Area data-protection purposes, likely legal bases are performance of requested service operations and our legitimate interests in operating and securing the private tool. Where consent is the appropriate basis for a platform connection, it may be withdrawn through revocation without affecting earlier lawful processing.

4. Retention and deletion

We keep data only for as long as reasonably needed for the private publishing workflow, security, troubleshooting, and legal obligations. Unless a shorter period is configured or deletion is requested:

  • OAuth tokens are kept while the account remains connected and are deleted or rendered unusable after disconnection, revocation, or expiry;
  • draft video files, captions, and scheduling data are kept while active and should normally be deleted within 30 days after successful publication or cancellation, unless retained by the operator for reuse;
  • publishing identifiers, status, and minimal operational records may be kept for up to 12 months for reconciliation and troubleshooting;
  • security and infrastructure logs are generally kept for up to 30 days, subject to a processor’s backup cycle or a longer period needed to investigate an incident; and
  • contact enquiries and replies are kept only as long as reasonably needed to respond, maintain necessary service records, or meet legal obligations.

Deletion from active systems may not immediately remove encrypted backups; backup copies are isolated and expire through normal rotation. We may retain limited information where law requires it or where reasonably needed to establish or defend legal claims.

5. Revoking TikTok access or requesting deletion

The operator can revoke permissions from TikTok’s connected-app settings. The operator may also use the secure contact form to request disconnection or deletion. We will verify the request, delete stored tokens and data that are not required to be retained, and explain any limited exception. Revocation prevents future TikTok API access but does not automatically delete posts already published to TikTok; those must be managed in the TikTok account.

6. Processors and disclosures

Data may be processed by service providers needed to operate the Service, such as private application hosting, database or object storage, security/network access, logging, Vercel for this public website and contact endpoint, and Resend for contact-message email delivery when that integration is configured. TikTok receives content and publishing instructions when the operator asks the Service to use TikTok. We require processors to handle data for the contracted service and not for their own advertising. We will update this notice if the relevant provider arrangements materially change.

We may disclose data if required by law, to protect security or legal rights, or during a legitimate business reorganisation subject to appropriate safeguards. We do not sell personal data and do not share it for cross-context behavioural advertising.

7. International transfers

TikTok and infrastructure processors may handle data outside the United Kingdom or EEA. Where UK or EEA transfer rules apply, we seek to use a lawful transfer mechanism offered by the relevant provider, such as an adequacy decision or approved contractual clauses. The applicable locations and safeguards depend on the providers used for the relevant processing.

8. Security

We use proportionate technical and organisational measures intended to protect data, including restricted private access, encrypted HTTPS connections, secret separation, access controls, and limited retention. No internet-connected system can be guaranteed completely secure. OAuth tokens must never be placed in this public site or exposed in browser content.

9. UK and European Economic Area rights

Depending on applicable law and the circumstances, individuals may have rights to access, correct, erase, restrict, or object to processing; receive portable data; and withdraw consent where processing relies on consent. A request can be sent to the secure contact form. We may need to verify identity and may retain information where an exemption applies.

Individuals may also complain to the UK Information Commissioner’s Office or, in the EEA, the supervisory authority where they live or work. We encourage contacting us first so we can try to resolve the concern.

10. Cookies and this public site

This public site does not use optional cookies, advertising technology, user accounts, or embedded media. Its contact form sends the information you enter to TECHAV through the server-side contact endpoint and configured email provider; the private recipient address and provider credentials are not sent to the browser. Basic server request logs may still be generated by the hosting provider for security and delivery.

11. Changes and contact

We may update this notice as the Service, processors, platform permissions, or law changes. The effective date will identify the current version. Contact: the secure contact form.

Streamlists Studio

A private content preparation and publishing workspace operated by TECHAV. No public registration or third-party access.

techav.co.uk

TermsPrivacyContact