Privacy Policy | Personal Data Protection and Security - Plux
1. What This Privacy Policy Covers
This Privacy Policy explains how Nova Haberleşme Ltd. Şti. ("Plux", "we", "us") collects, uses, shares, and protects information when you use the Plux.com.tr website, applications, and social media management services (collectively, the "Service").
By using the Service, you acknowledge this Privacy Policy. Our Terms of Service also apply.
2. Information We Collect
Information you provide directly
We collect information when you register, subscribe, contact support, or configure the Service, including:
- Contact and account details (name, email address, organisation name, language and timezone preferences)
- Billing and subscription information (processed by our payment providers)
- Content you upload, draft, schedule, or publish through the Service
- Support requests, feedback, and communications with us
Information collected automatically
When you use the Service or visit our website, we may automatically collect:
- Log data (IP address, browser type, device information, pages visited, timestamps)
- Usage and session data (features used, errors, performance metrics)
- Cookies and similar technologies as described in our Cookie Policy
3. Connected Social Media Accounts
Plux is a social media management platform. When you connect a third-party social network or publishing destination, we access information from that platform only as needed to provide the Service and as authorized by you.
The categories below apply to each platform you choose to connect. We only access data for platforms you actively link to your Plux account.
If you connect a Facebook account or channel to Plux, we may access the following information from Facebook as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Facebook Page or profile ID
- Page roles where permitted by the API
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Facebook user data to third parties for their marketing purposes.
If you connect a Instagram account or channel to Plux, we may access the following information from Instagram as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Instagram Business or Creator account metadata where available
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Instagram user data to third parties for their marketing purposes.
X (Twitter)
If you connect a X (Twitter) account or channel to Plux, we may access the following information from X (Twitter) as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent X (Twitter) user data to third parties for their marketing purposes.
If you connect a LinkedIn account or channel to Plux, we may access the following information from LinkedIn as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Organization pages and profile types where applicable
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent LinkedIn user data to third parties for their marketing purposes.
TikTok
If you connect a TikTok account or channel to Plux, we may access the following information from TikTok as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Privacy and interaction settings selected at publish time
- Commercial content disclosure preferences where applicable
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent TikTok user data to third parties for their marketing purposes.
Threads
If you connect a Threads account or channel to Plux, we may access the following information from Threads as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Threads user data to third parties for their marketing purposes.
YouTube
If you connect a YouTube account or channel to Plux, we may access the following information from YouTube as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Channel ID
- Existing videos and playlists where permitted
- YouTube API Services are used subject to the Google Privacy Policy and YouTube Terms of Service
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent YouTube user data to third parties for their marketing purposes.
If you connect a Pinterest account or channel to Plux, we may access the following information from Pinterest as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Boards and pin metadata where permitted
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Pinterest user data to third parties for their marketing purposes.
Google Business Profile
If you connect a Google Business Profile account or channel to Plux, we may access the following information from Google Business Profile as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Business location and review-related metadata where permitted
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Google Business Profile user data to third parties for their marketing purposes.
Telegram
If you connect a Telegram account or channel to Plux, we may access the following information from Telegram as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Channel or group identifiers
- Bot connection tokens where applicable
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Telegram user data to third parties for their marketing purposes.
If you connect a Reddit account or channel to Plux, we may access the following information from Reddit as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Subreddit context for scheduled posts
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Reddit user data to third parties for their marketing purposes.
Mastodon
If you connect a Mastodon account or channel to Plux, we may access the following information from Mastodon as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Federated instance URL
- Application credentials created on your instance
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Mastodon user data to third parties for their marketing purposes.
WordPress
If you connect a WordPress account or channel to Plux, we may access the following information from WordPress as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Site URL
- Application passwords or API credentials you provide
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent WordPress user data to third parties for their marketing purposes.
Blogger
If you connect a Blogger account or channel to Plux, we may access the following information from Blogger as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Blog identifiers and publishing metadata
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Blogger user data to third parties for their marketing purposes.
Tumblr
If you connect a Tumblr account or channel to Plux, we may access the following information from Tumblr as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Blog identifiers and post metadata
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Tumblr user data to third parties for their marketing purposes.
Bluesky
If you connect a Bluesky account or channel to Plux, we may access the following information from Bluesky as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Decentralized identifier (DID) and app password credentials you provide
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent Bluesky user data to third parties for their marketing purposes.
RSS Feeds
If you connect a RSS Feeds account or channel to Plux, we may access the following information from RSS Feeds as permitted by applicable law and your authorization:
- Profile image, display name, and username / account or page ID
- OAuth or API access tokens (stored securely to maintain your connection)
- Posts you schedule or publish through Plux (text, images, videos, and related metadata)
- Engagement and performance data where permitted (impressions, clicks, likes, comments, shares, and similar metrics)
- Channel analytics, demographic summaries, and follower counts where permitted by the platform API
- Feed URLs you configure
- Titles, descriptions, links, and media referenced in feed items
This data is used solely to provide scheduling, publishing, analytics, and account management services. We do not sell or rent RSS Feeds user data to third parties for their marketing purposes.
4. How We Use Information
We use personal information to:
- Create and manage your account and authenticate you
- Schedule, publish, and manage content on connected social networks
- Provide analytics, reporting, team workflows, and AI-assisted content features
- Send service-related communications, security alerts, and support responses
- Process payments and manage subscriptions
- Improve, secure, and troubleshoot the Service
- Comply with legal obligations and enforce our agreements
5. Legal Bases for Processing
We process your data under GDPR (Article 6) and applicable local laws on the following bases:
- Performance of a contract: Required to create your account and provide the Service.
- Consent: Obtained for marketing communications, non-essential cookies, and certain integrations where required.
- Legitimate interests: Platform security, fraud prevention, and service improvement.
- Legal obligation: Tax compliance and responses to lawful requests.
6. How We Share Information
We do not sell your personal information. We may share information:
- With social networks you connect: To publish content and retrieve permitted account or performance data on your instructions.
- With service providers: Hosting, email, analytics, payment processing, and infrastructure partners who process data on our behalf under contractual safeguards.
- For legal reasons: When required by law, court order, or to protect rights, safety, and security.
- Business transfers: In connection with a merger, acquisition, or asset sale, subject to this Privacy Policy.
Once you publish content to a social network, its use on that platform is governed by that platform's privacy policy and terms.
7. Data Retention
We retain data only as long as necessary for the purposes described:
- Account data: While your membership is active and for statutory limitation periods after closure (up to 10 years where required).
- Scheduled and published content: While you use the Service and as needed for logs, audit, and restore functionality.
- Connected account tokens: Until you disconnect the account or delete your Plux account, unless earlier deletion is required.
- Transaction logs: Up to 2 years for security and audit purposes.
- Analytics data: Anonymised indefinitely, or in raw form for up to 26 months.
- Backups: Rotated on a 30-day cycle.
Content may remain on third-party social networks after deletion from Plux; contact the relevant platform to remove it there.
8. Security
We implement technical and organisational measures to protect your information, including encryption in transit, access controls, secure credential storage, and restricted employee access on a need-to-know basis. No online service can guarantee absolute security.
9. International Data Transfers
Plux is hosted on infrastructure located in Türkiye (Organik Trafik / Türk Telekom data centre). Data of users in the European Economic Area may be transferred to Türkiye. We rely on Standard Contractual Clauses (SCCs) and applicable safeguards. Legal and technical measures required for international transfers are in place.
10. Third-Party Service Providers
We may share data with the following categories of providers to deliver the Service:
- Google Analytics: Website traffic analysis.
- Resend / SendGrid / SMTP: Transactional email.
- Hetzner / Türk Telekom: Hosting and infrastructure.
- Iyzico / Stripe: Payment processing (data is sent directly to the payment provider).
Our current sub-processor list is published at Sub-processors.
11. Social Networks and Third-Party Terms
Each social network (including Facebook, Instagram, X, LinkedIn, TikTok, Threads, YouTube, Pinterest, Google, Telegram, Reddit, Mastodon, WordPress, Blogger, Tumblr, Bluesky, and others) governs its own collection and use of personal information through its privacy policy and terms. Plux is not responsible for third-party platforms. You must comply with their rules when using the Service.
12. Disconnecting Accounts and Revoking Access
You may disconnect any linked social account from your Plux account settings at any time. You may also revoke Plux access from the connected platform's own security or app permissions settings (for example, TikTok, Meta, Google, or LinkedIn account settings). Revoking access may limit or stop publishing features for that platform.
13. Data Breach Notification
If we detect a personal data breach, we will notify competent authorities and affected users within 72 hours where required by GDPR and applicable law.
14. Age Limit
Plux is intended for users who are at least 18 years old or the age of legal majority in their jurisdiction, using the Service for business or professional purposes. The Service is not directed to children under 13. If we learn that data was collected without appropriate authority, we will delete it promptly.
15. Your Rights
Under GDPR and applicable law you may request access, rectification, erasure (right to be forgotten), portability, restriction, objection, and withdrawal of consent where processing is consent-based. You can exercise these rights from the Privacy section in your profile settings or by contacting us at [email protected].
16. Contact Us
Data controller: Nova Haberleşme Ltd. Şti. (Plux)
Email: [email protected]
Website: https://plux.com.tr/contact
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date. Continued use of the Service after changes become effective constitutes acceptance of the revised policy.