Trigvanta Trust Center

Privacy Policy

How Trigvanta collects, uses, stores, and protects personal data.

PrivacyVersion 2.0Updated 2026-07-28

Actions

Summary

Trigvanta is an automation-first SEO, content and social-listening platform. This policy explains exactly what personal data we collect when you sign up, connect a source, or use the browser extension, and why.

Who we are

Trigvanta is the data controller for account and workspace data you provide directly, and a data processor for content Trigvanta scans or generates on behalf of a connected workspace, per the Data Processing Agreement.

What data we collect

Account data: email, full name, phone number, country, and a hashed password (never stored in plain text). For company accounts, we also collect the organisation number, company name, and contact person.

Workspace and connection data: the sites, Google Search Console properties, WordPress/CMS credentials, and social accounts you connect, plus the automation rules you configure for each.

Content data from connected sources: crawl results from your own site, Search Console query/click/impression data, and — where you use the browser extension — posts read from social platforms you are logged into (see "The browser extension" below for the exact fields).

Generated content: AI-drafted articles, fixes, and replies, along with the evidence each draft is based on, kept traceable back to its source.

Security data: two-factor authentication secrets (encrypted at rest), login events, and audit logs of who did what and when.

How we collect data

Directly from you at signup and in account/workspace settings.

From providers you explicitly authorise, such as Google (Search Console OAuth) or your WordPress site (an application password you create and can revoke).

From our own crawler visiting the public pages of websites you connect.

From the Trigvanta browser extension, but only while it is installed, enabled, and you are actively browsing one of its supported platforms — see below.

The browser extension

The Trigvanta Connector browser extension reads posts on social platforms you are already logged into in that browser. It does not use developer API keys and does not ask for your platform password — it reads what your own browser can already see on screen.

It only runs on these platforms: Facebook, Instagram, TikTok, LinkedIn, X/Twitter, Threads, Pinterest, Bluesky, Gab, Truth Social, Minds, Rumble, and Odysee. It requests no browser permission beyond local storage, and its page access is scoped individually to those platforms only — never every website you visit.

For each post it captures exactly five things: which platform and group/page it is on, the post URL, the author’s display name, the post text, and the posted-at date if the page shows one. Comments and replies underneath a post are not currently captured — only the top-level post.

It never reads your password or login session token, private messages, or private groups/pages you have not already opened, and it does nothing at all while uninstalled or disabled.

This is a v1 connector: each platform is read via that platform’s own page layout, which can change without notice. If a platform changes its page structure, that one platform stops returning results until we update it — the rest keep working.

Why we process data

To operate your account and workspaces, run the automation rules you configure, generate and publish content you approve, and keep an auditable record of what the system did and why.

Legal basis / processing basis

Account and workspace data is processed because it is necessary to provide the service you signed up for. Cookie/marketing data is processed only with your explicit, revocable consent. Security and audit logging relies on our legitimate interest in keeping the platform safe.

Product analytics vs marketing analytics

Product analytics (e.g. crawl runs, automation decisions, publishing jobs) powers runtime operations and is not optional. Marketing analytics is off by default and only loads after you accept the Analytics cookie category — see the Cookie Policy.

AI and automated processing

Content drafts are generated by a third-party AI provider (currently OpenAI) from the evidence in your workspace. Drafts stay in a review queue and are never published automatically unless you explicitly configure that specific automation rule to full-auto — and even then, generation must pass validation first.

Data sharing and subprocessors

We share data only with the subprocessors listed at /subprocessors, each recorded with its purpose and region — never sold, never shared for third-party advertising.

Data regions and transfers

Trigvanta’s infrastructure is hosted on Hetzner in the EU. Where a subprocessor processes data outside the EU/EEA, that transfer is documented on the subprocessor record with its legal mechanism.

Retention

Retention windows are configured per data category and, where applicable, per company, and govern when data is archived or deleted. You can review current retention settings via a data export request.

Your rights

You can request export, deletion, or correction of your personal data at any time. Export and erasure requests are fulfilled for real — export produces an actual downloadable archive of your data, and erasure anonymises your account record and revokes active sessions, rather than only flipping a status flag.

How to request export/deletion/correction

Submit a request from the Compliance section of your dashboard while logged in, or email legal@trigvanta.com.

Security

Passwords are hashed, never stored in plain text. Two-factor authentication (TOTP) is mandatory for owner, admin, and root accounts. Connected-source credentials (Search Console tokens, WordPress application passwords, DataForSEO keys) are encrypted at rest, each with its own encryption key. Every sensitive action is written to an audit log, and secrets are redacted before being written to any log or error report.

Changes to this policy

Material policy changes can require renewed acceptance before you can continue using the platform.

Contact

support@trigvanta.com and legal@trigvanta.com

Data categories

Data typeExamplePurposeRetentionSource
IdentityEmail, name, phone, country, hashed passwordAuthentication and account accessPolicy-based, see /complianceYou, at signup
CompanyOrg number, company name, contact personCompany-account billing and contactPolicy-basedYou, at signup
Connected sourcesSearch Console tokens, WordPress app passwordRunning the scans/publishing you configuredUntil you disconnect the sourceOAuth grant / credential you enter
Social postsPlatform, page/group, post URL, author, text, dateSocial monitoring and content actionsPolicy-basedBrowser extension, while installed
AuditActor + action logsSecurity and complianceLong-term, security purposeRuntime events

Rights

RightDescriptionHow to request
ExportGet a real, downloadable copy of your dataCompliance page, or email legal@trigvanta.com
DeletionAnonymise your account and revoke sessionsCompliance page, or email legal@trigvanta.com
CorrectionCorrect inaccurate account/company dataAccount settings, or email legal@trigvanta.com

FAQ

How can I contact Trigvanta support?

Use support@trigvanta.com for product support and legal@trigvanta.com for legal/compliance.

Are these pages versioned?

Yes, each document shows its own version and last updated metadata.

Are statuses real?

Yes. Trigvanta does not show fake provider, consent, or compliance statuses.

Need help?

Contact support@trigvanta.com or legal@trigvanta.com for compliance and privacy questions.

Trigvanta Admin