Through this website we do not collect personal data and we do not use analytics or advertising cookies. Through the SIGES platform, we process the data of authorized users of the organizations that operate it (identification and contact data, credentials, activity logs) and, in the context of healthcare activity, patient data under the specific conditions and safeguards of healthcare regulations, which are informed to patients through the corresponding channels.
When an authorized administrator connects the organization's social media account (for example a TikTok account through Login Kit), we store the authorization tokens issued by the network and the basic profile information needed to display which account is connected (such as the account name). We use these tokens exclusively to publish the content approved by the organization's team through the network's official API (such as TikTok's Content Posting API) and to read engagement metrics of the organization's own posts. We do not access other users' data, we do not sell data, and tokens can be revoked at any time from the network's own settings or by disconnecting the account in the platform.
Processing is based on the performance of the contract with the organizations that use the platform, compliance with legal obligations, and, where applicable, the legitimate interest in managing the organization's own communication channels and the consent granted when connecting a social media account.
Data is kept while the service relationship remains in force and, thereafter, for the periods required by applicable regulations. Authorization tokens are deleted when the account is disconnected or the integration is removed.
Data is not transferred to third parties except as required by law or as strictly necessary to provide the service (hosting and infrastructure providers acting as processors under contract, and the social networks themselves when content is published to them).
You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to conceptum@conceptum.es. You may also lodge a complaint with the Spanish Data Protection Agency (AEPD).
We apply technical and organizational measures appropriate to the risk, including encryption of sensitive fields, access control by roles, audit logging and encrypted backups.