Privacy
Privacy Policy
Last updated: 12 July 2026
This policy explains how Caast processes personal data through Squad, its micro-influence campaign management platform available at squad.caast.fr. It also describes the data obtained through the Meta Platform (Facebook and Instagram).
1. Data controller
Caast SAS, a French simplified joint-stock company (société par actions simplifiée) with share capital of €101,830.00, registered office at 165 avenue de Bretagne, 59000 Lille, France, registered with the Lille Métropole Trade and Companies Register under number 528 509 060 (SIRET 528 509 060 00026, VAT FR15528509060).
Publication director: Antoine Leclercq, President.
Privacy contact: privacy@caast.tv.
2. Scope
Squad is a private, professional tool used by Caast staff to run influence campaigns on behalf of our clients. It is not a consumer-facing application: access is restricted to authenticated Caast administrators and to invited creators, for their own campaign information only.
3. Data we process
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email, role of Caast users | Authentication, access control, audit log |
| Creator data | Public handles, contact details, published content and its metrics | Campaign management and reporting |
| Meta Platform data | See section 4 | Tracking creator replies and campaign progress |
| Technical data | Connection logs, IP address | Security, fraud prevention |
4. Data obtained through the Meta Platform
When a Caast administrator connects, via Facebook Login, the professional Instagram account operated by Caast, Squad accesses the following data, with the stated permissions and for the stated purposes only:
| Permission | What we access | Why |
|---|---|---|
instagram_basic | Profile information and media of the connected professional account | Identify the account and match conversations |
pages_read_engagement | Engagement data of the Facebook Page linked to the connected account | Required by the Graph API to access the account's conversations |
instagram_manage_messages | Direct messages of the connected professional account | Detect when a contacted creator replies and advance their campaign status |
We do not access the private data of third parties without a lawful basis, we do not sell Platform data, and we do not use it for advertising or profiling. Messages are visible only to authorized Caast administrators.
5. Purposes and legal bases
- Access and account management: performance of the contract and legitimate interest in securing the platform.
- Creator and campaign management: pre-contractual and contractual measures, legitimate interest in running our campaigns.
- Reading Instagram messages of our own account: legitimate interest in tracking replies from contacted creators and advancing the pipeline.
- Security and audit: legitimate interest and legal obligations.
6. Recipients and processors
We do not sell personal data. We share it only with service providers acting on our instructions and bound by a data processing agreement: cloud hosting (OVHcloud, EU), file storage (Cloudflare R2), transactional email (Amazon SES), and the Meta Platform for the data described in section 4 only.
7. Transfers outside the European Union
Our data is hosted in the European Union (OVHcloud, France). Some providers (Cloudflare, Amazon Web Services, Meta) may process data outside the EU. Such transfers are covered by appropriate safeguards: European Commission Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
8. Retention
- Account data: duration of the relationship, then archived per our legal obligations.
- Creator and campaign data: duration of the campaign, then up to 3 years after the last contact for prospection.
- Meta data (including messages): deleted when no longer needed, upon account disconnection, or upon a valid request (see section 12).
- Technical logs: up to 12 months.
9. Cookies
The marketing website uses no tracking, analytics, or advertising cookies. The authenticated platform uses only strictly necessary cookies (secure session cookies) required to sign in.
10. Security
Data is encrypted in transit (HTTPS/TLS). Sensitive data (access tokens, bank details) is encrypted at rest, access is restricted and logged, and authentication secrets are never stored in clear text.
11. Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict, object to, and port your data. To exercise these rights, email privacy@caast.tv. We respond within one month, extendable by two months where necessary.
12. Deleting your data
You can request deletion of your data at any time. See our Data Deletion Instructions.
13. Complaints
You may lodge a complaint with the French Data Protection Authority (CNIL), 3 Place de Fontenoy, 75007 Paris. Website: cnil.fr.
14. Changes
We may update this policy; the effective date above will change accordingly.