Privacy Policy
Effective date: 24 August 2026 · Last updated: 24 August 2026
This Privacy Policy describes how
CHIDOJO SARL ("ChidoS", "we", "us", "our") collects, uses, shares, and protects personal data when you use
ChidoS Viral (the "Service") at
viral.chidos.tech. This policy complies with the General Data Protection Regulation (Regulation (EU) 2016/679) and with the Togolese law No. 2019-014 of 29 October 2019 on the protection of personal data.
1. Data controller
- Legal entity: CHIDOJO SARL
- Registered office: Lomé, Togo
- RCCM: [to be inserted before publication]
- Data protection contact: infos15@chidos.tech
2. Scope
This policy applies to personal data we process when you visit our website, create an account, connect your third-party accounts (TikTok, Instagram, YouTube), generate content, or contact us. It does not apply to third-party services you access from ChidoS Viral, which have their own privacy policies.
3. Personal data we collect
3.1 Account and profile data
- Full name, email address, hashed password, preferred language.
- Multi-factor authentication seed and recovery codes (encrypted).
- Profile picture (optional).
3.2 Connected platform data
When you connect your TikTok, Instagram, or YouTube account, we receive and store:
- OAuth access tokens and refresh tokens (encrypted at rest with AES-256-GCM).
- The connected account identifier and public display name.
- The permissions (scopes) you have granted.
We do not download, store, or analyse content from third-party platforms other than metadata for videos you explicitly submit to the analysis feature (public information retrieved through official APIs such as TikTok oEmbed).
3.3 Content data
- Product images and information you upload.
- Draft scripts, video assets, and captions generated with our AI tools.
- Publication schedules and editorial plans you create.
3.4 Usage and technical data
- IP address, browser type, device type, and operating system.
- Log data (timestamps, endpoints accessed, HTTP status codes).
- Authentication events (log-in, log-out, failed attempts).
- Actions performed within the Service (publications approved, content generated).
3.5 Communications
Emails, support requests, and any other correspondence you exchange with us.
4. Purposes and legal bases
| Purpose |
Legal basis |
| Providing the Service, authentication, publication on your behalf | Performance of contract |
| Security, fraud prevention, log analysis, incident response | Legitimate interest |
| Legal compliance, tax records, response to legitimate authority requests | Legal obligation |
| Sending non-essential communications (product updates) | Consent (opt-in) |
| Service improvement through aggregate analytics | Legitimate interest |
5. Recipients and subprocessors
We share personal data only with the following categories of recipients:
- Destination platforms (TikTok, Instagram, YouTube) — only content and metadata you have explicitly approved for publication, transmitted via each platform's official API.
- AI subprocessors — Anthropic PBC (United States) for language model processing; Black Forest Labs GmbH (Germany) for image and video generation. We transmit only the input strictly necessary to fulfil your request and never your third-party OAuth tokens or account credentials.
- Infrastructure subprocessors — our own dedicated server infrastructure (Republic of Togo), Backblaze Inc. (United States) for encrypted off-site backups.
- Communications subprocessor — our transactional email provider for account and security notifications.
- Legal authorities — where required by law, court order, or lawful request from a competent authority.
We do not sell your personal data. We do not share it for third-party advertising purposes.
6. International data transfers
Some of our subprocessors are located outside Togo, notably in the European Union and the United States. Where personal data is transferred to a country that has not been recognised as providing an adequate level of protection, we rely on:
- Standard Contractual Clauses (SCC) approved by the European Commission where applicable;
- The subprocessor's compliance with the EU-U.S. Data Privacy Framework where applicable;
- Additional technical safeguards including encryption in transit and at rest.
7. Retention
| Data category |
Retention |
| Account data | Duration of the account + 30 days after deletion |
| OAuth tokens | Until you disconnect the platform or delete your account |
| Content (drafts, videos, plans) | Duration of the account + 30 days |
| Security logs | 12 months |
| Billing and tax records | 10 years (Togolese tax law) |
| Backup copies | Rolling 12 months maximum, then permanently purged |
8. Your rights
Under GDPR and Togolese law No. 2019-014, you have the following rights over your personal data:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data (subject to legal retention obligations).
- Restriction — request that we limit the processing of your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdrawal of consent — withdraw any consent previously granted, at any time.
- Right to lodge a complaint — with a supervisory authority (see section 12).
To exercise these rights, contact us at infos15@chidos.tech. We will respond within one month.
9. Security
We implement technical and organisational measures aligned with ISO 27001 principles, including:
- TLS 1.2+ encryption in transit for all communications;
- AES-256-GCM encryption at rest for third-party OAuth tokens and sensitive fields;
- Multi-factor authentication for administrative access;
- Principle of least privilege on internal accounts;
- Regular vulnerability scanning of our infrastructure and dependencies;
- Segregated development, staging, and production environments;
- Encrypted, tested, off-site backups;
- Journalising of security events and administrative actions.
10. Data breaches
In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, we will notify the competent supervisory authority (in Togo, the Instance de Protection des Données à Caractère Personnel) within 72 hours where required, and notify affected users without undue delay where required by law.
11. Cookies
We use only strictly necessary cookies to operate the Service (authentication session, security tokens, language preference). These cookies do not require prior consent under GDPR. We do not use advertising, tracking, or third-party analytics cookies.
12. Complaint rights
If you believe your rights have not been respected, you may lodge a complaint with:
- Togo: Instance de Protection des Données à Caractère Personnel (IPDCP), Lomé.
- European Union: the data protection authority of your country of residence.
13. Children
The Service is not intended for persons under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, please contact us and we will delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through the Service at least fourteen (14) days before they take effect.
15. Contact