Privacy Statement
This application (COOS) enables you to connect social media accounts
to our website
for managing, scheduling, and publishing posts on behalf of your
company or organization.
Data Controller:
BURO RUW – COOS
Attn. Walter Hoogerwerf
???? walter@buroruw.nl
???? De Wadi 1 – Hendrik-Ido-Ambacht
???? 010 – 078 204 00 92
Chamber of Commerce: 24482682
Last updated / effective date: 03-10-2025
What data do we collect?

Facebook (Meta)
- Access tokens – we store the user token and then a page token to be able to post on behalf of your Facebook page.
- Page information – ID, name, and profile picture of linked pages, so you can select the correct page in COOS.
- Scopes – we only request the permissions that are necessary:
pages_show_list: to retrieve and display your pages in COOS.pages_read_engagement: to read basic info and engagement data from published posts.pages_manage_posts: to publish posts, photos, and videos on behalf of your page.business_management: to manage the connection between pages and Instagram accounts.
- Post content – the text, photos, and videos you enter in COOS are published via the Facebook API.
- @Mentions & tags – if you use @IDs in your post, we try to pass them along so the correct page or user is tagged.
- Token validity – we store your token’s expiration date so you’ll be notified when you need to reconnect.
We do not collect private messages, passwords, or personal data beyond the API data mentioned above.

Instagram (via Facebook/Meta Login – Instagram Graph API)
- Access tokens – we store a user token and then a page/account token to publish on behalf of your Instagram Business or Creator account.
- Profile information – ID, username, and profile picture of the linked Instagram Business/Creator account, so you can manage the correct connection in COOS.
- Scopes / permissions – we only request the permissions needed for the intended functionality:
instagram_business_basic: to retrieve basic information from the connected account.instagram_content_publish: to publish posts, carousels, and reels.pages_show_list&business_management: to show linked Facebook pages and connect the right Instagram account to them.pages_manage_posts&pages_read_engagement: to view published posts and basic statistics.
- Post content – the text, photos, and videos you enter are sent via the Graph API to Instagram for publishing.
- Statistics (limited) – we may retrieve follower counts and post totals to display basic insights.
- Token validity – we store the token’s expiration date and notify you when you need to reconnect.
We do not collect private messages, passwords, or other personal data beyond the API data mentioned above.

LinkedIn
- Access tokens – we store the LinkedIn access token so COOS can publish posts on behalf of your organization.
- Organization information – ID, name, and logo of the linked organization pages where you are an administrator.
- Scopes / permissions – we only request the permissions necessary through the Community Management API:
rw_organization_admin: to verify that you are an administrator of the organization page.r_organization_social&w_organization_social: to read and publish your organization’s social content and interactions.r_organization_social_feed&w_organization_social_feed: to manage the organization’s feed and publish posts.r_organization_followers: to retrieve follower counts and basic insights.r_basicprofile: to use your basic profile information (such as name and profile picture) during the connection process.w_member_social: to optionally publish content on your personal profile if required.
- Post content – the text, photos, videos, and carousel posts you enter in COOS are sent to LinkedIn via the API for publishing.
- Statistics – we request limited access to post performance and follower data to display within COOS.
- Token validity – we store the expiration date of your token and notify you when it needs renewal.
- Rate limiting & caching – to maintain stable connections, we temporarily store results (like your organization list) in cache. This prevents overload and improves performance.
We do not collect private messages, passwords, or personal data beyond the API data mentioned above.
We do not collect private messages, passwords, or other personal data beyond the API data listed above.
Why do we collect this data?
COOS uses this data solely to:
- Schedule and publish social media posts
- Display data about published posts and connected pages
- Keep connections active and functional (such as token refresh and error handling)
Data retention
- Tokens and connection data are stored as long as the connection is active or until you revoke it.
- Log files and cache are generally kept for a maximum of 30 days, unless longer retention is necessary for security or troubleshooting.
- We can delete connected data earlier upon your request.
How is your data stored?
- Data (such as tokens and page information) is securely stored in our WordPress database.
- Only authorized COOS users have access.
- Data is not shared with third parties and not used for marketing purposes, except where necessary for hosting/IT providers acting solely on our behalf.
- We use technical and organizational measures to prevent misuse, loss, and unauthorized access.
Your rights
- You can revoke the connection with your social media account at any time (via COOS or the platform itself).
- Your access tokens will then automatically expire or be manually deleted.
- You have the right to access, correct, delete, and transfer your data.
- You may object to processing or withdraw your consent.
- Submit a request via info@ruw-web.nl. We will respond as soon as possible.
Contact
For questions about this privacy statement or the use of your data, please contact:
BURO RUW – COOS
Attn. Walter Hoogerwerf
???? walter@buroruw.nl
???? Rotterdam, The Netherlands
???? 078 204 00 92
Chamber of Commerce: 24482682