Privacy Policy — DUK MKT
Last updated: July 28, 2026
DUK MKT is a multi-tenant social media management platform (SaaS) operated by Duk Informática & Cloud Ltda. ("Duk", "we"). Each business client uses DUK MKT to connect their own social media accounts and to schedule and publish content that the client has reviewed and approved. This policy explains what data we process and how, in compliance with the Brazilian LGPD (Law 13.709/2018) and with the developer terms of each connected platform.
1. Data We Collect
- Login credentials of the client's authorized users (email, password hash).
- OAuth tokens for the social accounts that each client connects and authorizes (Meta, LinkedIn, Google/YouTube, TikTok).
- Basic profile info of the connected account (e.g., display name and avatar) to confirm the correct account is linked.
- Content the client creates, schedules and publishes through the platform.
- Performance metrics returned by the social platforms' official APIs.
- Technical logs (IP, user-agent, timestamps) for security and auditing.
2. How We Use Data
Data is used solely to: (i) operate the platform; (ii) authenticate users; (iii) publish and schedule content to each client's own connected accounts, on their behalf and with their approval; (iv) generate performance reports for that client; (v) comply with legal obligations. We do not sell data and we do not use connected-account data for any purpose other than delivering the service to the account owner.
3. Sharing
Data is shared only with the third-party platforms strictly necessary to publish the client's content (Meta, LinkedIn, Google/YouTube, TikTok), always via their official APIs and subject to those platforms' policies.
4. TikTok Integration
Clients may connect their own TikTok account to DUK MKT via TikTok's official OAuth (Login Kit) and Content Posting API. We request only the scopes required to deliver the service, and we use the data obtained from each scope strictly as follows:
- user.info.basic — to read the connected account's open id, display name and avatar, shown to the client so they can confirm the correct TikTok account is linked.
- video.upload and video.publish — to publish the videos the client has reviewed and approved to that client's own TikTok account, at the time the client scheduled.
We do NOT access, display, or aggregate other TikTok users' content, and we do not use TikTok data for advertising or profiling. The client is the owner of the connected account and may disconnect it at any time, which revokes our access.
5. Retention & Deletion
Technical logs are kept for 90 days. Published content remains until manually deleted. OAuth tokens are refreshed automatically while the connection is active and are deleted when the client disconnects the account or requests deletion. Clients can request deletion of their data at any time (see Contact).
6. Security
We use HTTPS, password hashing, per-tenant isolated storage, tokens kept in isolated server-side storage, and role-based access control (RBAC).
7. Data Subject Rights
Data subjects may request access, correction, portability or deletion via atendimento@duk.com.br. The Duk DPO will respond within 15 days.
8. Contact
Duk Informática & Cloud Ltda. — atendimento@duk.com.br — https://duk.com.br