Privacy Policy
This Privacy Policy explains how Stichting De Lokale (Netherlands) (“we”) operates the Disint.ai / Informational Defence platform (the “Service”) and how the Service accesses, collects, stores, uses, and shares information obtained from official social network APIs. The Service is designed to work with public, non-authorized source data only. We do not ask social network users to authorize the Service, we do not access private accounts, and we do not sell personal data or disclose it for commercial purposes.
1) Scope & Audience
This Policy covers: (a) visitors to our website; (b) authorized internal platform users; and (c) public social network content selected for monitoring and analysis through official social network APIs.
2) API Data and Categories of Information We Process
The Service only accesses public, non-authorized API Data relating to selected media topics, channels, pages, posts, videos, comments, or other public content made available through official social network APIs. Depending on the source platform and selected monitoring topic, this API Data may include:
- Public content metadata — public post or video identifiers, titles, descriptions, captions, URLs, publication dates, timestamps, channel/page names, and public engagement counts where available.
- Public comments and reactions — public comment text, public reply text, timestamps, public usernames, handles, profile/channel identifiers, and public links connected to the content.
- Derived analytical data — topic matches, clusters, narrative labels, embeddings, confidence scores, risk indicators, summaries, and report findings generated by the Service from public source data.
- Operational data — internal dashboard activity, processing status, report-building status, API request logs, and technical records needed to operate, secure, debug, and improve the Service.
The Service does not collect private messages, private profile information, social network passwords, authentication tokens from social network users, payment data, or other non-public account data from social network users. Public source data may still contain names, usernames, handles, or other information that a person has made public on a social network; we use that information only as part of public media monitoring and report preparation.
3) Sources of Information
- Public source data retrieved from official social network APIs, including the YouTube API Services, in accordance with the applicable API terms.
- Information entered by authorized internal users when configuring monitored topics, reviewing results, and building reports.
- Technical and operational records generated by the Service while collecting public data, processing it, displaying it on the dashboard, and preparing reports.
4) How We Use and Process Information
We use public API Data and derived analytical data only to operate the Service and produce public-interest media monitoring outputs. This includes:
- collecting public, non-authorized content through official social network APIs for selected media topics;
- analyzing public content to identify narratives, coordination patterns, topic clusters, trends, and other indicators relevant to disinformation research;
- displaying collected public source data and derived analytical data in an internal dashboard for review by authorized internal employees;
- building reports, summaries, and supporting evidence for non-profit organizations and media organizations that monitor selected media topics;
- maintaining auditability, security, API compliance, rate-limit compliance, debugging, and system integrity.
5) Personal Data
The platform is not designed to use private personal data. We do not intentionally collect sensitive personal data or private user information from social network users. If public source data includes information that can identify a person because that information was publicly posted on a social network, we process it only for the limited public-interest purposes described in this Policy and we do not sell it, disclose it for commercial purposes, or use it for advertising, individual targeting, harassment, or unlawful profiling.
6) Sharing and Access
Access to collected public source data and derived analytical data is limited as follows:
- Internal access — collected data shown on the dashboard is available to authorized internal employees who need access to review results, operate the platform, maintain the system, or build reports.
- External report recipients — reports based on collected public data may be shared with non-profit organizations and media organizations that monitor selected media topics. These reports may include summaries, analysis, public evidence links, screenshots or excerpts of public content, and other findings needed to understand the monitored topic.
- Service providers — we may use trusted technical providers to host, secure, store, or process data for the Service. They may process information only for our instructions and only as needed to provide their services.
- Legal requirements — we may disclose information if required by applicable law, regulation, court order, or valid legal process.
We do not sell collected data. We do not share collected public source data with advertisers, data brokers, or parties seeking to target individuals.
7) Retention and Deletion
Collected public source data is deleted within 30 days after collection or earlier after the resulting report has been built, unless a shorter period is required by applicable API terms or law. In rare cases, when additional time is needed to complete report building, the relevant data may be refreshed or updated every 30 days until the report is completed. Once the report-building purpose has ended, the underlying collected source data is deleted according to this retention rule.
8) International Transfers
When transferring personal data outside the EEA/UK, we use appropriate safeguards such as the EU Standard Contractual Clauses. Data residency options (e.g., EU-only) are available on certain plans.
9) Security Measures
- Encryption in transit (TLS), network isolation, access controls with least privilege.
- Regular backups, vulnerability patching, and monitoring.
- Staff confidentiality commitments and security training.
10) Your Rights (EEA/UK & similar regimes)
Subject to law, you have rights to access, rectification, erasure, restriction, portability, and to object to processing based on our legitimate interests. You may withdraw consent at any time for processing that relies on consent. You may lodge complaints with your local authority.
11) Children
The Service is not directed to children under 16. We do not knowingly process children’s personal data. If you believe we have such data, contact us for deletion.
12) Public Source Data & Research Ethics
- We analyze publicly available content selected for public-interest media monitoring. Even when data is public, we design features to avoid harmful use, including access controls, rate-limit compliance, and auditable evidence links.
- The Service must not be used to target, harass, or unlawfully profile individuals.
13) Cookies
- Essential (required): authentication session, CSRF, load balancing.
- Analytics (optional): we use privacy-respecting analytics with IP truncation; disabled unless you consent.
14) Automated Processing & Profiling
We use machine learning to cluster comments and match narratives. Outputs are probabilistic and should be reviewed by human analysts. We do not make decisions producing legal or similarly significant effects on individuals without human involvement.
15) Law Enforcement & Requests
We may disclose information where required by law or valid legal process. We will notify the Customer unless prohibited.
16) Your Controllers & DPO
Controller: Stichting De Lokale (Netherlands). Data Protection Officer: info@delokale.org
17) Changes
We may update this Policy; we will notify you of material changes via the Service or email.
18) Contact
Email: info@delokale.org
Official Social Network API Disclosures
- Our Service uses official social network APIs, including the YouTube API Services, to retrieve public, non-authorized content and metadata for selected media topics.
- Use of YouTube is subject to Google’s Privacy Policy and YouTube’s Terms of Service. Customers must ensure their use of retrieved data complies with those policies.
- We do not claim ownership over YouTube content; rights remain with their respective owners.
- Reports, labels, summaries, clusters, and other analytical outputs presented by the platform are generated by Disint.ai and are not created, endorsed, or verified by YouTube or any other social network.