Mediatison service · Code & Prod
Mediatison privacy policy
This policy explains how Mediatison processes user data, including when Facebook Pages and Instagram Professional are connected and used.
Last updated: August 29, 2026
Controller, service and roles
Mediatison is published by Code & Prod, a SASU — French single-member simplified joint-stock company with share capital of 500 euros, SIREN 104 391 636, registered as 104 391 636 R.C.S. Lyon.
30 avenue Maréchal FochBureau 3
69006 Lyon
France
For any data protection question or to exercise your rights, write to contact@codenprod.com.
Code & Prod determines the essential purposes and means of processing required for Mediatison accounts, security and service operations. When a customer Organization chooses its members, content and social destinations, it determines those editorial purposes; Code & Prod then performs the technical processing on its behalf, according to its instructions and the applicable agreement.
When Facebook or Instagram is connected or used on instruction, Meta receives and processes data to operate its own platforms under its terms and privacy policy. Code & Prod does not determine Meta’s own platform processing. Read Meta’s privacy policy.
Data processed
Mediatison account and context
Email address, optional display name, language, account status, hashed or encrypted authentication data, security dates, Organization, Workspace, Membership, role and SocialProfile. Passwords are hashed: Mediatison never stores a password in plain text.
Facebook Pages and Instagram Professional connection
During an authorized connection, Mediatison may receive a technical Meta delegator identifier, stored as a pseudonymized fingerprint, as well as the identifiers, names, tasks and statuses of manageable Facebook Pages and the identifier, username and name of the linked Instagram Professional account. Granted scopes and capabilities, connection state, provider version, and connection, verification, refresh or expiry dates are also recorded.
OAuth credentials
Access tokens required for connection and publishing are received server-side, encrypted at rest using a context specific to the Organization, connection and platform, and opened only for the authorized operation. Mediatison also stores the token type, scopes, expiry dates and a technical fingerprint. Tokens, secrets and OAuth codes are not displayed in the interface or written to logs.
Content and publications
Mediatison processes drafts, text, titles, options, targets, variants, media, file names, descriptions, alternative text, technical metadata and checksums supplied by authorized members. It stores publication snapshots, statuses, attempts, dates, external identifiers, filtered permalinks and error codes needed for delivery and reconciliation.
Security and operations
Internal identifiers, roles, audit events, timestamps, correlations, queue states and redacted errors are processed to secure the service, prevent abuse, diagnose incidents and maintain continuity. Messenger messages and the transactional outbox carry internal identifiers and versions, not OAuth tokens or publication text.
Data not requested by the Meta integration described here
Mediatison does not request Facebook or Instagram passwords, private messages, contact lists, Meta payment methods, ad accounts, Ads data, comments, reactions or audience insights. Any expansion of this scope would require separate information and validation.
Purposes
- Create and administer an account, an Organization, its members, Workspaces and SocialProfiles, and provide the Mediatison interface.
- Start a requested connection journey, verify permissions, discover Pages and the linked Instagram Professional account, create the selected connections and allow disconnection.
- Prepare, send on instruction and verify Facebook or Instagram content chosen by an authorized member. Merely viewing this policy never triggers a publication.
- Authenticate, enforce permissions, isolate tenants, prevent abuse, protect integrity, diagnose errors and retain proportionate evidence of operations.
- Receive, verify and process rights, deauthorization and data deletion requests.
Legal bases
- Performance of the agreement with the customer Organization, or requested pre-contractual steps, supports provision of the account, workspaces, composition tools and requested social features.
- Code & Prod’s legitimate interests in securing Mediatison, preventing abuse, maintaining continuity, diagnosing incidents and defending its rights support proportionate security and audit processing.
- Compliance with applicable legal obligations supports the processing of rights requests, valid legal demands and evidence that must be retained.
- The customer Organization must determine and inform its members of the basis applicable to the content, profiles and publications it chooses to process. Code & Prod processes them technically according to its instructions.
Choosing to authorize Facebook or Instagram enables the requested technical access; by itself, it is not general consent under the GDPR. If an optional processing activity actually relied on consent, it would be requested separately and could be withdrawn.
Recipients and service providers
Within their assigned duties, data is accessible to authorized Organization members, authorized Code & Prod personnel, strictly necessary hosting, storage, backup and operations providers, and legally empowered authorities.
Meta receives relevant connection data, content and media only when an authorized person connects Facebook or Instagram or requests an operation on those platforms. Tokens are not disclosed to other Organization members.
Code & Prod does not claim that all processing by its providers or Meta remains in the European Economic Area. Processing locations and applicable safeguards depend on the relevant provider’s agreement and may be requested from the privacy contact before external activation.
Retention
- Account, Organization and related resource data is kept while the service is used, then for the time needed to close the service, handle requests, and meet applicable obligations or claims. It is then deleted or anonymized according to its category.
- An authenticated session expires after 30 minutes of inactivity and no later than 12 hours. Revoked or expired technical records are then retained only for the period needed for security and diagnosis.
- An OAuth attempt expires after 10 minutes. Temporary Meta discovery secrets are destroyed when the journey completes, is cancelled, fails or expires; the technical state may remain temporarily to prevent replay and diagnose a failure.
- An OAuth credential is kept while the connection is active and needed. Disconnection, valid deauthorization or a valid deletion request deletes the credential. Meta deletion also erases readable social identifiers, scopes, capabilities and the delegator fingerprint from the connection.
- Drafts, media, snapshots and publication history are kept while active or needed for the history requested by the Organization, then according to applicable archiving, dereferencing, evidence and closure criteria.
- Transactional outbox messages that have already been dispatched are deleted after 30 days by the dedicated maintenance command.
- Logs and audits are limited to the time needed for security, diagnosis, accountability and applicable limitation periods; secrets and sensitive content are redacted.
- Data removed from the active system may remain until protected backups age out under their normal rotation. It is not reused in ordinary service, and deletion requests must be replayed after an emergency restore.
Your rights
Subject to the conditions set by law, you may request access, rectification, erasure, restriction, objection or portability of your data. You may withdraw consent when processing actually relies on it, without affecting prior lawful processing.
State your Mediatison account address, the relevant Organization and the nature of your request to contact@codenprod.com. Identity documents are not required by default. If there is reasonable doubt, Code & Prod may request proportionate information to verify identity.
Code & Prod responds within the applicable statutory period, normally one month; this may be extended by two months for a complex or numerous request, with notice during the first month.
You may also lodge a complaint with the French data protection authority, CNIL.
Data deletion for Facebook and Instagram
- An owner or admin can open “Connected networks” in Mediatison and choose “Disconnect”. This removes the local OAuth credential and prevents further use; a minimal technical connection record may remain for audit.
- To request erasure of Facebook- or Instagram-related data, identify the Mediatison account, Organization and connection concerned by writing to contact@codenprod.com.
- A request made from Meta’s “Apps and Websites” settings calls the Mediatison data deletion callback. A valid signature causes credentials to be deleted and readable social identifiers, scopes, capabilities and the associated delegator fingerprint to be erased locally.
- Meta then returns a confirmation code and a Mediatison URL. Open that URL to view a human-readable request status; the code retrieves the same request without exposing your Meta identifier.
When it carries a valid signature, the Meta deauthorization callback disconnects the associated Facebook and Instagram resources and deletes their credentials. Callbacks without a valid signature are rejected without deletion.
This procedure removes connection data received from Meta. Content and history created directly in Mediatison require a separate erasure request so that other members’ rights and applicable evidence obligations can be respected.
Security
Mediatison uses measures including TLS, tenant-aware access controls, roles, transactions, an encrypted OAuth token vault, hashed secrets, redacted logs, protected backups and health checks.
These measures reduce risk but are neither a certification nor a guarantee of absolute security. Report any incident promptly to the privacy contact.
Cookies, preferences and trackers
Mediatison uses session data strictly necessary for authentication and security, plus same-origin interface preferences. The current code contains no audience measurement tool, advertising pixel or marketing tracker. This public page creates no business session and loads no third-party asset.
Changes to this policy
This policy is updated when purposes, data categories, networks, recipients or rights procedures change materially. The date shown at the top identifies the applicable version.