Privacy information for WIMS social-media and AI integrations

Effective date: 9 August 2026
Version: 1.0
Provider: SIA “WIMS”, registration No. 40103980623

This Privacy Policy explains how SIA “WIMS” processes personal data through its restricted technology integrations for social-media publishing, analytics and AI-assisted content functions (the “Integration Services” or the “Platform”). The Integration Services are intended solely for WIMS personnel and other expressly authorised users. They are not a public consumer application and do not offer public registration.

This Policy is published on wims.lv to provide transparent information and to support authorisation and review by connected service providers. It applies only to the Integration Services. It does not govern personal data relating to visitors, customers, purchases, payments or other activities of the wims.lv Shopify store, which must be covered by the store’s separate privacy information.

1. Controller and contact details

The data controller is SIA “WIMS”, registration No. 40103980623, VAT No. LV40103980623, legal address Baznīcas iela 45–21, Riga, LV-1010, Latvia (“WIMS”, “we”, “us”).

Privacy enquiries and data-subject requests may be sent to wims@wims.lv. Telephone: +371 26107194.

2. Whose data we process

We may process personal data relating to WIMS employees, officers, contractors, technical administrators and other Authorised Users; persons administering or appearing through a connected WIMS social-media account; and individuals whose public interactions with WIMS content are lawfully retrieved through a connected service.

The Platform is not directed to children and WIMS does not knowingly provide Platform access to children.

3. Categories of personal data

Authorised-user data. Name, business contact details, role, organisation, account identifier, access permissions, authentication events and account status.

Social-account and authorisation data. Connected service, account identifiers such as an open ID, username, display name, avatar, granted scopes, authorisation status, access and refresh tokens, token expiry information and disconnection status.

Content and workflow data. Draft and approved content, captions, prompts, uploaded media, approval decisions, reviewers, timestamps, schedules, target account, privacy and interaction settings, publication identifiers, publication status and error records.

Public interaction and analytics data. Public comments, public usernames or account identifiers, reactions, engagement data, reach, performance metrics and AI-generated response drafts where this functionality is enabled by WIMS and supported by the connected service.

Technical and security data. IP address, device and browser information, session data, logs, diagnostic information, security events, API requests, audit trails and support records.

We do not intend to access or process private social-media messages unless WIMS separately enables that functionality after a documented legal, security and data-protection assessment.

4. Sources of personal data

We obtain data directly from Authorised Users; from WIMS identity, employment, contractor and access-management records; from content and actions entered in the Platform; automatically from Platform use and security logs; and from connected services such as TikTok, Meta services, Pinterest or other APIs when an authorised account holder connects an account and grants the relevant permissions.

5. Purposes and legal bases

Platform access and operation. We process authorised-user, account and workflow data to provide and administer the Platform, manage access and perform WIMS employment, contractor or other authorised-user arrangements. The legal basis is performance of a contract or steps connected with it under Article 6(1)(b) GDPR where applicable, and WIMS legitimate interests under Article 6(1)(f) GDPR in operating its business systems and workflows.

Content creation, review and publication. We process content, approval and social-account data to create, review, schedule, transmit and monitor WIMS business content. The legal basis is WIMS legitimate interests under Article 6(1)(f) GDPR in conducting and improving its lawful marketing and communications activities.

Security, audit and misuse prevention. We process account, log, device and security data to protect the Platform, investigate incidents, maintain audit trails and enforce access restrictions. The legal basis is WIMS legitimate interests under Article 6(1)(f) GDPR and, where applicable, compliance with legal obligations under Article 6(1)(c) GDPR.

Legal compliance and claims. We may process relevant data to meet legal, accounting, regulatory or record-keeping duties and to establish, exercise or defend legal claims. The legal basis is Article 6(1)(c) and Article 6(1)(f) GDPR.

Consent. We rely on consent under Article 6(1)(a) GDPR only where the relevant processing is genuinely optional and consent is specifically requested. Authorising a social-media connection through OAuth records the account holder’s permission for technical access; it does not by itself replace the GDPR legal basis described in this Policy.

6. Connected platforms and publication workflow

The Integration Services are intended to connect only to social-media accounts owned or lawfully managed by WIMS. The account holder authorises each connection through the relevant provider. WIMS receives only the identifiers, permissions, access and refresh tokens, expiry information and other account data made available under the approved authorisation flow.

For TikTok, WIMS may request user.info.basic, video.publish and video.upload permissions and use them to identify the connected account, obtain current creator and privacy options, upload or publish approved content and query publication status. For Pinterest, WIMS may request boards:read, pins:read and pins:write permissions to identify the authorised account and target board and create approved Pins. For Meta services, WIMS may process the permissions and account data necessary to publish and manage approved WIMS Facebook and Instagram content and related insights.

Approval given inside the WIMS workflow constitutes the Authorised User’s instruction to send the selected content and metadata to the relevant platform. The backend may then transmit or publish the content without a second approval step in the connected platform where the provider’s API and review status permit this. Each connected platform processes data independently under its own privacy policy and terms. The account holder may disconnect an integration, and WIMS may revoke or delete the relevant tokens when the connection is no longer required.

7. AI-assisted processing

The Integration Services may use AI providers, including Google Gemini where approved, to generate or adapt text, images, videos, classifications, summaries, analytics or proposed responses to public comments. WIMS limits personal data sent to an AI service to what is reasonably necessary for the approved function and applies contractual and security controls to service providers.

AI output is subject to human review before publication. The Platform is not intended to make decisions producing legal or similarly significant effects about individuals solely by automated means. WIMS service providers may not reuse WIMS content or personal data for unrelated purposes or model training unless WIMS has expressly approved the arrangement and a valid legal basis and contractual safeguards are in place.

8. Recipients and processors

Personal data may be accessible to authorised WIMS personnel according to role; the supplier that develops, hosts, supports or maintains the Platform; hosting, security, communications, analytics and AI service providers used by WIMS; connected social-media platforms; professional advisers, auditors and insurers where necessary; and public authorities where disclosure is required by law.

Providers acting as processors may process personal data only under WIMS instructions and a data-processing agreement. Connected social-media platforms may act as independent controllers for processing performed under their own services and policies. WIMS can provide further information about relevant recipient categories on request, subject to legitimate confidentiality and security limitations.

9. International transfers

Some technology and social-media providers may process data outside Latvia or the European Economic Area. Where the GDPR requires transfer safeguards, WIMS relies on an applicable adequacy decision, the European Commission’s Standard Contractual Clauses together with supplementary measures where necessary, or another lawful transfer mechanism. Connected platforms may conduct their own international transfers as described in their privacy policies.

10. Retention

We retain personal data only for as long as necessary for the purposes described above, taking account of the user’s role and access period, the active social-media connection, operational and audit requirements, security risks, statutory retention duties and limitation periods for claims.

Access and refresh tokens are retained only while the relevant connection is authorised and operational. When a connection is removed, the tokens are revoked where supported and deleted from active systems without undue delay, subject to secure backup rotation. Platform accounts and permissions are disabled when access is no longer authorised. Security, publication and audit records may be retained for a limited period after access ends where necessary to investigate incidents, demonstrate approvals, comply with legal duties or protect legal claims. WIMS maintains internal retention rules for the applicable data categories.

11. Security

WIMS applies measures appropriate to the risks, including role-based access, authentication controls, encryption in transit, secure server-side credential storage, logging, access review, backup controls, vulnerability management and incident handling. Client secrets, access tokens and refresh tokens are not intended to be exposed in front-end code, public repositories, ordinary email or unsecured chat.

No system can guarantee absolute security. Authorised Users must follow WIMS security instructions and report suspected incidents immediately.

12. Your rights

Subject to the GDPR and applicable limitations, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, data portability where applicable, and information about recipients. You may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting processing carried out before withdrawal.

You also have the right to lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija), Elijas iela 17, Riga, LV-1050, Latvia, www.dvi.gov.lv. We encourage you to contact WIMS first so that the matter can be assessed and addressed promptly.

13. How to exercise your rights or disconnect an account

Send a request to wims@wims.lv and identify the right you wish to exercise and the relevant Platform or social-media account. WIMS may request information reasonably necessary to verify identity and authority. We will respond without undue delay and normally within one month, subject to any extension permitted by the GDPR.

An Authorised User may also request that a connected social-media account be disconnected. WIMS will revoke or remove the Platform-side authorisation where technically supported. The user may additionally remove the connection through the relevant social-media service’s account settings.

14. Changes to this Policy

WIMS may update this Policy to reflect legal, operational, technical or service-provider changes. The effective date and version will be updated on publication. Material changes affecting Authorised Users will be communicated through the Platform or another appropriate internal channel.

15. Contact

SIA “WIMS”
Registration No. 40103980623
Baznīcas iela 45–21, Riga, LV-1010, Latvia
Email: wims@wims.lv
Telephone: +371 26107194