This Privacy Policy describes how we (“we,” “us,” or “our”) handle information in connection with the Channel Ops Accelerator application (the “App”), an internal tool that automates publishing our own video content from YouTube to our own TikTok accounts.

1. Who we are

The App is operated by DGD OPCO LLC, a Texas limited liability company. Mailing address: 5900 Balcones Drive #25911, Austin, TX 78731. Contact: contact@deimar.co.

2. Scope

The App operates only on TikTok accounts we own or control (including channels under the innovations_mastery, Calavai, Qodflow, and OpsAccelerator brands). It does not serve unaffiliated end users and does not collect personal data from the public or from third-party creators.

3. Information the App accesses

Through the official TikTok API, and only after the account owner authorizes access, the App accesses:

The App also processes the video files, titles, captions, and hashtags we supply for publication. These originate from our own YouTube content.

The App does not collect TikTok viewer data, follower lists, direct messages, comments, payment information, or any data belonging to people other than the connected account owner.

We request the minimum API scopes necessary for publishing (such as user.info.basic and the video publishing/upload scopes) and no others.

4. How we use the information

We do not use TikTok data for advertising, profiling, resale, or training of machine-learning models.

Our access to and use of TikTok data complies with the TikTok Developer Terms of Service and TikTok’s Platform and Developer policies. We use TikTok data only to provide the publishing functionality described above and for no other purpose. We do not sell TikTok data, use it for advertising, or share it with third parties except the infrastructure providers needed to operate the App.

5. Storage and retention

OAuth tokens are stored securely in our own infrastructure and are used only to perform the publishing actions described above. Video files and captions are retained only as long as required to complete and verify publishing.

When the account owner revokes the App’s TikTok authorization, or upon a written deletion request, we delete the associated OAuth access and refresh tokens and any cached profile data within 30 days. Publishing logs containing TikTok identifiers are retained no longer than 90 days, after which they are deleted or irreversibly anonymized. We do not retain TikTok-derived data after the App’s authorization for an account ends, except where retention is required by law.

6. Sharing

We do not sell, rent, or trade any data accessed through the App. Data is shared only with:

We may disclose information if required by law, court order, or to protect our legal rights, and we will seek to limit such disclosure to what is legally required and notify affected parties where lawfully permitted.

Our infrastructure providers act as processors / service providers under written terms that restrict them to operating the App on our behalf. A current list of these sub-processors is available on request at the contact address below.

7. Security

We use commercially reasonable technical and organizational measures to protect access tokens and content, including encrypted storage of credentials and least-privilege API scopes. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

8. Data breach notification

In the event of a personal data breach affecting data processed by the App, we will, without undue delay and where feasible within 72 hours of becoming aware, notify the relevant supervisory authority and any affected individuals where required by GDPR, UK GDPR, or applicable US state law, and will promptly notify TikTok of any incident affecting TikTok-derived data as required by the TikTok Developer Terms.

9. Your controls and data deletion

The connected account owner can revoke the App’s access at any time from TikTok account settings (Manage app permissions). Revoking access immediately stops the App from publishing or reading data for that account, and the App deletes the stored tokens for it. To request deletion of all data tied to your account — stored tokens or logs — email contact@deimar.co; we will confirm completion within 30 days.

10. Legal bases for processing (GDPR)

Where we process personal data subject to the EU General Data Protection Regulation (GDPR) or the UK GDPR, we rely on the following legal bases:

11. Your rights under GDPR (EEA / UK users)

If you are in the European Economic Area, the United Kingdom, or another GDPR-equivalent jurisdiction, you have the right to: access your personal data; rectify inaccurate data; erase data (“right to be forgotten”); restrict or object to processing; data portability; and withdraw consent at any time without affecting prior lawful processing. You may also lodge a complaint with your local supervisory authority (e.g., your national Data Protection Authority, or the UK ICO).

To exercise any of these rights, email contact@deimar.co. We respond within 30 days. We do not engage in automated decision-making or profiling that produces legal or similarly significant effects. We act as the data controller for the limited data described in this Policy; for data processed on the TikTok platform itself, TikTok is an independent controller.

Because the App processes data only for our own internal accounts and does not offer goods or services to, or monitor, individuals in the EEA or UK, we have not appointed an Article 27 representative. Should this change, we will update this Policy and appoint one as required.

12. California privacy rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, grants you the right to: know what personal information we collect, use, and disclose; access and obtain a copy of that information; correct inaccurate information; delete your personal information; and not be discriminated against for exercising these rights.

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes beyond those permitted by the CCPA. We do not knowingly sell the personal information of minors under 16.

The categories of personal information we may process are limited to identifiers (TikTok open ID, display name) and internet activity / technical data (OAuth tokens, publishing status logs), used solely for the publishing purpose described in this Policy. To exercise your California rights, email contact@deimar.co; we will verify your request and respond within 45 days. You may use an authorized agent to submit a request on your behalf.

We retain each category only as long as necessary for the publishing purpose: OAuth tokens until revocation or a deletion request; identifiers and publishing-status logs for no more than 90 days. We do not use or disclose sensitive personal information beyond the limited purposes permitted under Cal. Civ. Code § 1798.121, and we therefore do not offer a “Limit the Use of My Sensitive Personal Information” option because no such use occurs.

We verify your identity before fulfilling access, correction, or deletion requests by confirming control of the connected TikTok account or the email on file. An authorized agent must provide written, signed permission, and we may require you to verify your own identity directly. We will not discriminate against you for exercising any CCPA/CPRA right.

13. International transfers

The App is operated from the United States. Data processed by the App may be stored and processed in the United States. Where personal data is transferred from the EEA or UK to the United States, we rely on appropriate safeguards such as the EU/UK Standard Contractual Clauses or an equivalent lawful transfer mechanism offered by our processors.

14. Children

The App is an internal business tool and is not directed to children. We do not knowingly process data of anyone under 13 (or under 16 in the EEA/UK). If we learn we have done so, we will delete it.

15. Changes

We may update this Privacy Policy from time to time. The “Last updated” date above reflects the most recent revision.

16. Contact

For privacy questions or to exercise any right described above, contact us at contact@deimar.co, 5900 Balcones Drive #25911, Austin, TX 78731.

See also our Terms of Service for this application.