PRIVACY POLICY Last updated: August 2, 2026

This Privacy Policy explains how GuneTech OÜ («we», «us», «our» or the «Operator») collects, uses and protects your personal information when you use the website donnet.design (the «Site») and the services made available through it (collectively, the «Service»). By using the Service you consent to the practices described in this Privacy Policy.

1. WHO IS RESPONSIBLE FOR YOUR DATA

The entity responsible for your personal data (the «data controller») is: GuneTech OÜ, a company registered in Estonia. Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Tartu mnt 67/1-13b, 10115. Contact for privacy matters: natalia@donnet.design

2. INFORMATION WE COLLECT

We collect the following categories of personal information: 2.1 Information you provide directly

When you create an account, contact us, or otherwise interact with the Service, we may collect your name, email address, company name and any information you choose to provide in your messages to us. 2.2 Information collected automatically

When you visit the Site we may automatically collect your IP address, browser type, device information, referring URLs, pages visited and similar usage data, through server logs and cookies (see Section 10). 2.3 Information from third-party integrations

When you choose to connect a third-party social media account (such as TikTok or Meta, i.e. Facebook and Instagram) to the Service, after you have given your express consent through that platform’s own authorisation flow, we may receive the information described in Section 3.

3. THIRD-PARTY PLATFORM INTEGRATIONS

The Service may integrate with third-party social media platforms. Connecting any third-party account is optional and requires your explicit authorisation through that platform’s own authorisation flow. We never request or store your third-party account passwords; we only receive and store the authorisation tokens that those platforms issue, and only the data covered by the permissions and scopes you approve.

3.1 TikTok

The Service integrates with TikTok through TikTok’s «Login Kit» and «Content Posting API». Connecting your TikTok account is optional. When you authorise the connection, TikTok issues an access token to the Service and we may access and process the following information from your TikTok account, to the extent of the scopes you explicitly approve:

– Basic profile information available through the user.info.basic scope, such as your TikTok username, display name, open ID and profile picture URL.

– Additional profile information available through the user.info.profile scope, such as your bio description, profile link and account verification status.

– Engagement statistics available through the user.info.stats scope, such as your follower count, like count, following count and video count, so the Service can display your TikTok analytics.

– The authorisation token issued by TikTok, which the Service uses to call TikTok’s APIs on your behalf. We do NOT request, access or store your TikTok password at any point.

Using the Content Posting API, and always based on the captions, titles, privacy levels and other settings that you configure in the Service, we may:

– Publish, upload, schedule and manage videos and other content directly to your TikTok profile on your behalf, at your request (video.publish scope, Direct Post).

– Upload videos to your TikTok account as drafts for your review and manual publication inside the TikTok app (video.upload scope, Upload mode).

We do not access your private messages or the list of people who follow you; the user.info.stats scope only reads aggregate counts (follower count, like count, etc.), not the identities of your followers. We do not access any data that TikTok does not expose through the scopes you have authorised.

3.2 Meta (Facebook and Instagram)

The Service integrates with Meta platforms via Facebook Login and the official Meta APIs, including the Instagram Graph API, the Instagram Messaging API, the Pages API and the Messenger Platform. When you (the account holder) authorise the connection through Facebook Login, the Service may access and process, to the extent of the permissions and scopes you explicitly approve, the following information about you and the Facebook Pages and Instagram accounts you manage:

– Your basic public profile (such as your name and profile picture URL) and your email address; – The list of Facebook Pages you manage, including their Page ID and Page name; and – For each connected Instagram account and/or Facebook Page: its identifier, name, profile picture URL and account settings available through the relevant API.

We do NOT request, access or store your Facebook or Instagram password. We only receive and store the access tokens that Meta issues, which the Service uses to call Meta’s APIs on your behalf.

3.2.1 Publishing and engagement on your behalf

Based on the content, captions, scheduling and other settings that you configure in the Service, and within the permissions you authorise, we may:

– Publish, upload, schedule and manage posts, reels and other content on the Facebook Pages and Instagram accounts you connect (for example instagram_content_publish and pages_manage_posts); – Read, moderate, reply to, hide or delete comments on your posts (for example instagram_manage_comments and pages_read_engagement or pages_manage_engagement); – Send and receive direct and private messages on the connected Instagram accounts and Facebook Pages (for example instagram_manage_messages and pages_messaging), always subject to Meta’s messaging rules (see Section 3.2.3).

3.2.2 Webhooks: data we receive about your audience

The Service may subscribe to Meta webhooks so that it can react in real time to activity on the accounts you connect, including new comments, mentions and direct messages from your audience (your followers and other people who interact with your account). When a webhook event fires, the Service may receive and process, on your behalf and to the extent that Meta sends it, the following information about those third-party users (your audience): – Their Meta-scoped user identifier (a pseudonymous identifier returned by Meta, not their Facebook or Instagram profile URL or password); – Their display name and profile picture URL as shown on the platform; – The text content of their comment, mention or direct message, together with the timestamp and the object (such as the post, reel or story) it relates to; and – The metadata that Meta provides about the interaction (for example whether it is a comment, a reply or a direct message). The Service uses that information to display it to you in your dashboard, to generate and publish automatic replies on your behalf, or to notify your internal team. We do not use this information for our own purposes, profiling or marketing.

3.2.3 Auto-replies and the platform’s messaging windows

Where you enable automatic replies on Instagram or Facebook, the Service posts them through the relevant Meta API, on your behalf and under your control. Outbound messages through the Instagram Messaging API or the Messenger Platform are subject to Meta’s rules, including the 24-hour messaging window (within which a business may freely respond to a person’s message) and the specific message tags that permit certain message types outside that window. Where the Service is configured to send a reply outside that window, it does so only using the message tags that Meta permits for that case.

3.2.4 Processing roles for your audience data

To the extent that the Service, on your instructions, processes personal data of the people who interact with the Facebook Pages and Instagram accounts you connect (for example the content of their comments, mentions or direct messages received through webhooks), you are the data controller for that data and we act as your data processor, processing it only to provide the engagement features that you have enabled. We will process that data only on your documented instructions, will not use it for our own purposes, and may make it available to you so that you can respond to it. Where required by applicable law, this Privacy Policy is supplemented by a data processing agreement that you can request from natalia@donnet.design.

3.3 Revoking access (TikTok and Meta)

You can revoke the Service’s access to any connected third-party account at any time, either:

– from that platform’s own settings (for Facebook and Instagram: Meta’s «Apps and Websites» settings; for TikTok: Settings and privacy > Security and login > App permissions); or – by disconnecting the account from within the Service. Revoking access prevents the Service from performing any further actions on that account. Content already published on the platform remains governed by that platform’s own terms and policies. We delete the corresponding access token when you disconnect your account, or in accordance with Section 7.

3.4 What we do not access

We do not access your private messages unrelated to the accounts you have connected, your followers’ contact lists, or any data that the connected platform does not expose through the permissions and scopes you have authorised.

4. HOW WE USE YOUR INFORMATION

We use your personal information to:

– provide, operate and maintain the Service; – publish, schedule and manage content on the third-party platforms you connect, including TikTok and Meta (Facebook and Instagram), in accordance with your instructions; – receive, display and act on interactions (such as comments, mentions and direct messages) that people send to the accounts you connect, in order to deliver the engagement, automatic-reply and notification features that you have enabled; – generate and publish, on your behalf and under your control, replies and messages to those people on the third-party platforms you connect; – respond to your enquiries and communicate with you; – detect, prevent and address technical issues, fraud and abuse; – comply with applicable legal obligations; and – enforce our Terms of Service. We do not sell your personal information.

5. LEGAL BASES FOR PROCESSING (GDPR)

As a company established in the EU, we process your personal data only where we have a lawful basis, including: – Performance of a contract: to provide the Service you have requested. – Consent: for third-party integrations such as TikTok and Meta (Facebook and Instagram), and for non-essential cookies. – Legitimate interests: to ensure the security of the Service and to improve it. – Legal obligation: where required by applicable law. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before such withdrawal.

6. HOW WE SHARE YOUR INFORMATION

We share your personal information only in the following circumstances: – With third-party platforms you connect (such as TikTok and Meta (Facebook and Instagram)), solely to perform the actions you have requested through the Service, and, where applicable, to publish replies and messages on your behalf to persons who have interacted with your connected accounts. – With service providers acting as processors under contractual obligations (for example hosting and infrastructure providers). – When we believe in good faith that disclosure is required by law, court order or to protect our rights, property or safety, or that of others. We do not transfer your personal data to third parties for their own marketing purposes.

7. DATA RETENTION

We keep your personal information only for as long as is necessary to provide the Service and to comply with our legal obligations. Access tokens issued by TikTok and Meta are deleted when you disconnect the corresponding account. Information about interactions (comments, mentions and direct messages) that your audience sends to your connected accounts is retained for the minimum time necessary to deliver the engagement features you have enabled and to comply with applicable legal obligations, after which it is deleted or anonymised, unless retention is required by law.

8. YOUR RIGHTS (GDPR)

In relation to your personal data you have the right to: – access your data (and receive a copy); – request the rectification of inaccurate data; – request the erasure of your data; – restrict the processing of your data; – receive your data in a structured, machine-readable format (data portability); – object to the processing of your data; – withdraw consent where processing is based on consent; and – lodge a complaint with your local data protection authority, or with the Estonian Data Protection Inspectorate (andmeinspektsioon).

To exercise any of these rights, contact us at natalia@donnet.design. We will respond within one month.

9. INTERNATIONAL TRANSFERS

As we are established in the European Economic Area (EEA), your data is primarily processed within the EEA. Where any data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

10. COOKIES

We use essential cookies that are necessary for the Service to function. We only use optional or analytics cookies with your consent. You can disable non-essential cookies in your browser or through the cookie banner presented when you visit the Site.

11. CHILDREN

The Service is not directed to users under 13 years of age (or the minimum age required by applicable law, or by the third-party platforms you connect). The TikTok and Meta integrations are not enabled for users who do not meet those platforms’ minimum age requirement. We do not knowingly collect personal information from children. If you believe we have done so, contact us and we will delete it.

12. SECURITY

We implement reasonable technical and organisational measures designed to protect your personal information against unauthorised access, alteration, disclosure or destruction. However, no method of transmission over the Internet or electronic storage is completely secure.

13. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the «Last updated» date. For material changes, we will provide a more prominent notice. Your continued use of the Service after the changes become effective constitutes acceptance of the updated policy.

14. CONTACT

If you have any questions about this Privacy Policy or your personal data, contact us at: Email: natalia@donnet.design Operator: GuneTech OÜ Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Tartu mnt 67/1-13b, 10115