Another SaaS

Privacy Policy

Last updated: August 2026

Introduction

Another SaaS EOOD ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we handle information across two contexts:

  • The Website — our public informational website at anothersaas.io.
  • The Service — the Another SaaS social media management platform, which schedules and publishes content to social media accounts you connect, such as TikTok, YouTube, and Instagram.

The Website is a static informational site. It does not use cookies, tracking technologies, or analytics services, and we do not collect personal data through it unless you voluntarily contact us via email.

The Service does require an account and does store personal data, including OAuth access tokens for the social media accounts you connect. Sections below marked as applying to the Service describe that processing in detail.

Data Controller

The data controller responsible for your personal data is:

Another SaaS EOOD
Alabin Street 33
Floor 3, Office 318
1000 Sofia
Bulgaria

Email: hello@anothersaas.io

Information We Collect Through the Website

Information You Provide Voluntarily

On the Website, we only collect personal information that you voluntarily provide to us when you contact us via email. This may include:

  • Your name
  • Your email address
  • Any other information you choose to include in your message

Information the Website Does NOT Collect

The Website is a static site and does not use:

  • Cookies set by us or similar tracking technologies
  • Analytics or tracking services (no Google Analytics, etc.)
  • Social media tracking pixels
  • Advertising networks
  • Contact forms that automatically collect data

Data We Collect Through the Service

When you use the Another SaaS social media management platform, we collect and store the following categories of data:

Account Information

  • Your name and email address
  • A cryptographic hash of your password (we never store passwords in plain text)
  • Workspace or team membership and role
  • Account preferences and settings

Connected Social Media Account Data

When you connect a social media account via OAuth, we store:

  • OAuth access tokens and refresh tokens issued by the platform
  • The platform user ID, handle or username, and display name
  • Your profile picture or avatar URL
  • The permission scopes you granted, and the token expiry date

These tokens are stored solely so that the Service can publish and schedule content on your behalf, and to refresh the connection when a token expires. We do not use them to read, analyze, or collect data from your account for any other purpose, and we never sell or share them.

Content You Upload

  • Post text, captions, hashtags, and scheduling metadata
  • Images and video files you upload for publication
  • Drafts and scheduled posts that have not yet been published

Usage and Technical Data

  • Publishing logs, including timestamps and success or failure status
  • API responses and error messages returned by connected platforms
  • IP address and browser user agent, recorded for security and abuse prevention
  • Login and session activity

Third-Party Platform Integrations

The Service integrates with third-party social media platforms so that it can publish on your behalf. These include:

  • TikTok — via the TikTok API, to publish videos and posts to the TikTok account you connect
  • YouTube — via the YouTube Data API, to upload and publish videos to the channel you connect
  • Instagram and Facebook — via the Meta Graph API
  • Other social networks you choose to connect within the Service

When you schedule a post, the content and its metadata are transmitted to the platform you selected. Once transmitted, that data is governed by the receiving platform's own privacy policy and terms, which we do not control. We recommend reviewing the privacy policy of each platform you connect.

We access these platforms only within the OAuth scopes you explicitly approve when connecting an account, and only to perform the actions you have requested.

Revoking Access

You can revoke our access at any time, either by disconnecting the account inside the Service or through the connected-apps or third-party-app settings of the platform itself. Revoking access immediately stops the Service from publishing to that account, and the associated OAuth tokens are deleted from our systems.

Third-Party Content on the Website

The Website embeds a Google Maps map on the homepage to show our office location. Loading this map means your browser connects to Google, which may set cookies and receive your IP address. This is governed by Google's privacy policy. No other third-party content is embedded on the Website.

Server Logs

Our web hosting provider may automatically collect standard server log information when you visit the Website. This may include:

  • Your IP address
  • Browser type and version
  • Operating system
  • Referring URL
  • Pages visited and time of access

This information is collected automatically by the server infrastructure and is used solely for security purposes and to ensure the proper functioning of the Website. We do not use this data for tracking or profiling purposes. Server logs are typically retained for a limited period and then automatically deleted.

How We Use Your Information

Website

If you contact us via email, we use the information you provide solely to:

  • Respond to your inquiry or request
  • Communicate with you about potential business opportunities
  • Comply with legal obligations

Service

Within the social media management platform, we use your data to:

  • Authenticate you and maintain your account
  • Schedule and publish your content to the social media accounts you have connected, using the OAuth tokens you granted
  • Store and deliver the media files attached to your posts
  • Show you the status and history of your scheduled and published posts
  • Operate, maintain, debug, and improve the Service
  • Detect and prevent abuse, fraud, and security incidents
  • Comply with legal obligations and platform requirements

We do not use your information for marketing purposes unless you have explicitly consented to receive marketing communications from us. We do not sell your data, use it to build advertising profiles, or use your content to train machine learning models.

Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:

  • Performance of a Contract: To provide the Service to you — including storing your content and using your OAuth tokens to publish it to the accounts you connected — as agreed in our Terms of Service.
  • Legitimate Interest: To respond to your inquiries, manage business communications, secure the Service, and prevent abuse.
  • Consent: Where you have given us explicit consent to process your data for specific purposes.
  • Legal Obligation: Where we are required to process data to comply with applicable laws.

Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  • Connected Social Media Platforms: When you schedule a post, we transmit that content and its metadata to the platform you selected (such as TikTok, YouTube, or Instagram) so that it can be published. This happens only at your direction.
  • Service Providers: We may share data with trusted service providers who assist us in operating our business — such as hosting, database, object storage, and email providers — subject to confidentiality and data processing obligations.
  • Legal Requirements: We may disclose information if required by law, court order, or governmental authority.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Email correspondence: Retained for the duration of our business relationship and a reasonable period thereafter for legal and administrative purposes.
  • Server logs: Typically retained for 30 days or less by our hosting provider.
  • OAuth access and refresh tokens: Retained until you disconnect the social media account or delete your Service account, at which point they are deleted from our database.
  • Account information: Retained for the lifetime of your account and deleted when you delete the account.
  • Posts, drafts, and scheduling data: Retained for the lifetime of your account so that you can review your publishing history.
  • Uploaded media: Retained in object storage for the lifetime of your account and deleted when the account or the associated post is deleted.
  • Publishing and security logs: Retained for a limited period for troubleshooting and abuse prevention, then deleted.

Deleting Your Data

You can delete your account at any time from within the Service, or request deletion by emailing hello@anothersaas.io. Deleting your account removes your account information, all stored OAuth tokens, your posts and drafts, and your uploaded media from our database and object storage.

Content that has already been published to a third-party platform remains on that platform and must be deleted there directly.

When personal data is no longer needed, it will be securely deleted or anonymized. Backups containing deleted data are overwritten on our normal backup rotation.

Your Rights Under GDPR

If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:

  • Right of Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request correction of inaccurate or incomplete data.
  • Right to Erasure: You can request deletion of your personal data ("right to be forgotten").
  • Right to Restriction: You can request that we limit the processing of your data.
  • Right to Data Portability: You can request to receive your data in a structured, commonly used format.
  • Right to Object: You can object to the processing of your personal data based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, please contact us at hello@anothersaas.io. We will respond to your request within 30 days.

Data Storage and Security

Where Your Data Is Stored

Data from the Service is stored in a PostgreSQL database, and uploaded media files are stored in S3-compatible object storage. Both are hosted with reputable infrastructure providers on servers located within the European Union.

How We Protect It

We take reasonable technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • HTTPS/TLS encryption for all traffic to the Website and the Service
  • OAuth access and refresh tokens stored encrypted at rest, with access restricted to the systems that need them to publish your content
  • Passwords stored only as salted cryptographic hashes, never in plain text
  • Access controls, authentication, and least-privilege permissions for our systems
  • Regular security updates to our infrastructure and dependencies
  • Secure email communication

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee its absolute security.

Cookies

Website: We set no cookies on anothersaas.io. Note that the embedded Google Maps map on the homepage may cause Google to set its own cookies in your browser.

Service: The social media management platform uses strictly necessary cookies only. These maintain your login session and protect against cross-site request forgery. They are required for the Service to function and cannot be disabled while you are logged in.

We do not use advertising cookies, analytics cookies, or third-party tracking cookies on either the Website or the Service.

International Data Transfers

Another SaaS EOOD is based in Bulgaria, a member state of the European Union. Your personal data is primarily processed within the EEA.

If we transfer personal data outside the EEA, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or transfers to countries with an adequate level of data protection.

Children's Privacy

Neither the Website nor the Service is intended for children under the age of 16, and the Service may not be used by them. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will take steps to delete such information.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. Any changes will be posted on this page with an updated "Last updated" date.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Supervisory Authority

If you believe that we have not complied with applicable data protection laws, you have the right to lodge a complaint with a supervisory authority. For Bulgaria, the relevant authority is:

Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd.
1592 Sofia
Bulgaria

Website: www.cpdp.bg

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Another SaaS EOOD
Alabin Street 33, Floor 3, Office 318, 1000 Sofia, Bulgaria

Email: hello@anothersaas.io