Trigvanta Trust Center
Privacy Policy
How Trigvanta collects, uses, stores, and protects personal data.
Actions
Summary
Trigvanta is an automation-first SEO, content and social-listening platform. This policy explains exactly what personal data we collect when you sign up, connect a source, or use the browser extension, and why.
Who we are
Trigvanta is the data controller for account and workspace data you provide directly, and a data processor for content Trigvanta scans or generates on behalf of a connected workspace, per the Data Processing Agreement.
What data we collect
Account data: email, full name, phone number, country, and a hashed password (never stored in plain text). For company accounts, we also collect the organisation number, company name, and contact person.
Workspace and connection data: the sites, Google Search Console properties, WordPress/CMS credentials, and social accounts you connect, plus the automation rules you configure for each.
Content data from connected sources: crawl results from your own site, Search Console query/click/impression data, and — where you use the browser extension — posts read from social platforms you are logged into (see "The browser extension" below for the exact fields).
Generated content: AI-drafted articles, fixes, and replies, along with the evidence each draft is based on, kept traceable back to its source.
Security data: two-factor authentication secrets (encrypted at rest), login events, and audit logs of who did what and when.
How we collect data
Directly from you at signup and in account/workspace settings.
From providers you explicitly authorise, such as Google (Search Console OAuth) or your WordPress site (an application password you create and can revoke).
From our own crawler visiting the public pages of websites you connect.
From the Trigvanta browser extension, but only while it is installed, enabled, and you are actively browsing one of its supported platforms — see below.
The browser extension
The Trigvanta Connector browser extension reads posts on social platforms you are already logged into in that browser. It does not use developer API keys and does not ask for your platform password — it reads what your own browser can already see on screen.
It only runs on these platforms: Facebook, Instagram, TikTok, LinkedIn, X/Twitter, Threads, Pinterest, Bluesky, Gab, Truth Social, Minds, Rumble, and Odysee. It requests no browser permission beyond local storage, and its page access is scoped individually to those platforms only — never every website you visit.
For each post it captures exactly five things: which platform and group/page it is on, the post URL, the author’s display name, the post text, and the posted-at date if the page shows one. Comments and replies underneath a post are not currently captured — only the top-level post.
It never reads your password or login session token, private messages, or private groups/pages you have not already opened, and it does nothing at all while uninstalled or disabled.
This is a v1 connector: each platform is read via that platform’s own page layout, which can change without notice. If a platform changes its page structure, that one platform stops returning results until we update it — the rest keep working.
Why we process data
To operate your account and workspaces, run the automation rules you configure, generate and publish content you approve, and keep an auditable record of what the system did and why.
Legal basis / processing basis
Account and workspace data is processed because it is necessary to provide the service you signed up for. Cookie/marketing data is processed only with your explicit, revocable consent. Security and audit logging relies on our legitimate interest in keeping the platform safe.
Product analytics vs marketing analytics
Product analytics (e.g. crawl runs, automation decisions, publishing jobs) powers runtime operations and is not optional. Marketing analytics is off by default and only loads after you accept the Analytics cookie category — see the Cookie Policy.
AI and automated processing
Content drafts are generated by a third-party AI provider (currently OpenAI) from the evidence in your workspace. Drafts stay in a review queue and are never published automatically unless you explicitly configure that specific automation rule to full-auto — and even then, generation must pass validation first.
Data regions and transfers
Trigvanta’s infrastructure is hosted on Hetzner in the EU. Where a subprocessor processes data outside the EU/EEA, that transfer is documented on the subprocessor record with its legal mechanism.
Retention
Retention windows are configured per data category and, where applicable, per company, and govern when data is archived or deleted. You can review current retention settings via a data export request.
Your rights
You can request export, deletion, or correction of your personal data at any time. Export and erasure requests are fulfilled for real — export produces an actual downloadable archive of your data, and erasure anonymises your account record and revokes active sessions, rather than only flipping a status flag.
How to request export/deletion/correction
Submit a request from the Compliance section of your dashboard while logged in, or email legal@trigvanta.com.
Security
Passwords are hashed, never stored in plain text. Two-factor authentication (TOTP) is mandatory for owner, admin, and root accounts. Connected-source credentials (Search Console tokens, WordPress application passwords, DataForSEO keys) are encrypted at rest, each with its own encryption key. Every sensitive action is written to an audit log, and secrets are redacted before being written to any log or error report.
Changes to this policy
Material policy changes can require renewed acceptance before you can continue using the platform.
Contact
support@trigvanta.com and legal@trigvanta.com
Data categories
| Data type | Example | Purpose | Retention | Source |
|---|---|---|---|---|
| Identity | Email, name, phone, country, hashed password | Authentication and account access | Policy-based, see /compliance | You, at signup |
| Company | Org number, company name, contact person | Company-account billing and contact | Policy-based | You, at signup |
| Connected sources | Search Console tokens, WordPress app password | Running the scans/publishing you configured | Until you disconnect the source | OAuth grant / credential you enter |
| Social posts | Platform, page/group, post URL, author, text, date | Social monitoring and content actions | Policy-based | Browser extension, while installed |
| Audit | Actor + action logs | Security and compliance | Long-term, security purpose | Runtime events |
Rights
| Right | Description | How to request |
|---|---|---|
| Export | Get a real, downloadable copy of your data | Compliance page, or email legal@trigvanta.com |
| Deletion | Anonymise your account and revoke sessions | Compliance page, or email legal@trigvanta.com |
| Correction | Correct inaccurate account/company data | Account settings, or email legal@trigvanta.com |
FAQ
How can I contact Trigvanta support?
Use support@trigvanta.com for product support and legal@trigvanta.com for legal/compliance.
Are these pages versioned?
Yes, each document shows its own version and last updated metadata.
Are statuses real?
Yes. Trigvanta does not show fake provider, consent, or compliance statuses.
Need help?
Contact support@trigvanta.com or legal@trigvanta.com for compliance and privacy questions.