Privacy Policy
This Privacy Policy explains how Softop collects, uses, discloses, stores, shares, and deletes personal data
when you visit our websites, create an account, or use our software products and integrations — including
ERP–eshop connectivity, invoicing (myDATA), messaging, business intelligence, and our social media /
community management features (including automated content creation and publishing via platforms such as LinkedIn).
We design our privacy practices to meet applicable law (including the EU GDPR) and, for LinkedIn integrations,
the LinkedIn API Terms of Use,
the LinkedIn Marketing API Terms,
and LinkedIn’s published
Marketing API data storage requirements.
1. Who this policy covers
This policy applies to:
- Visitors to softop.gr and related Softop product pages
- Customers, administrators, and authorized users of Softop products
- Individuals whose data is processed when a Softop customer connects third-party services (e.g. LinkedIn Company Pages) through Softop
Softop provides B2B software. Our services are intended for businesses and professionals, not for children.
We do not knowingly collect personal data from anyone under 16.
2. Products and services covered
- ERP–Eshop connectivity: inventory, availability, orders, customer/user sync between ERP systems and online stores
- Invoicing / myDATA: issuance and transmission of invoices and related fiscal data
- Messaging: email, SMS, and Viber communications you configure
- Business Intelligence: financial and market analytics dashboards
- Social / Community Management (including auto content creation): drafting, scheduling, and publishing posts; managing page engagement (comments, mentions, reactions); and showing page/post analytics for connected social accounts such as LinkedIn Organization Pages
3. Information we collect
3.1 Information you provide
- Account data: name, email address, password (hashed), company name, and account settings
- Business / fiscal data: company details, VAT/AFM, addresses, invoice content, and related configuration you enter
- Contact form data: name, phone, email, and message content when you contact us
- Content you create: draft posts, captions, media, schedules, and other materials for social publishing
- Support communications: messages you send us about the service
3.2 Information collected automatically
- IP address, browser type, device/OS information
- Access times, pages viewed, and diagnostic/error logs
- Session cookies and similar technologies needed for authentication and security
3.3 Information from third-party integrations (including LinkedIn)
When you (or an authorized page admin) connect a LinkedIn account or Organization Page to Softop via OAuth,
we receive and process only the data necessary to deliver the community management features you enable, which may include:
- Authenticated member identifiers and basic profile information of the user who authorizes Softop
- Organization Page profile and administrative data for pages you authorize
- Posts/shares you create or manage through Softop, and related metadata
- Engagement data needed to operate community management (e.g. comments, nested comments, reactions, mentions) and limited profile fields of members who interact with your page content, solely to display that engagement to authorized users of your Softop workspace
- Aggregate page, follower, and share/post statistics for reporting inside Softop
- OAuth tokens required to call LinkedIn APIs on your behalf
We request only the LinkedIn permissions needed for the approved community management / page management use cases
you enable. We do not request more member data than is required to operate those features.
4. How we use information
We use personal data to:
- Provide, maintain, and secure Softop products and customer accounts
- Sync ERP, eshop, invoicing, messaging, and analytics features you configure
- Generate draft social content (where enabled), schedule and publish posts to platforms you connect, and manage community engagement
- Show page/post performance and engagement inside Softop to authorized users of the relevant customer account
- Provide customer support and service communications
- Prevent fraud, abuse, and security incidents
- Comply with legal obligations (including tax/invoicing requirements where applicable)
- Improve product reliability and user experience using aggregated or de-identified analytics where appropriate
5. LinkedIn Community Management — specific commitments
Softop’s LinkedIn integration is intended for commercial community / page management for registered business customers —
including creating and publishing Organization Page content (including AI-assisted drafts you review and approve),
retrieving and displaying engagement on those posts, and reporting page/post analytics to authorized users.
5.1 Lawful access and consent
- LinkedIn data is accessed only after an authorized user completes LinkedIn’s OAuth consent flow
- Before or at connection time, we explain what data Softop will access, why it is needed, that Softop may retrieve data more than once while the connection remains active, and how consent can be withdrawn
- Users can disconnect LinkedIn from Softop and/or revoke access in LinkedIn account settings; we will stop new API access and delete or cease using LinkedIn data as described in Sections 7–8
5.2 Permitted display and audience limitation
- Member data obtained to manage a specific LinkedIn Page or Profile is displayed only to individuals associated with that Page/Profile in Softop (e.g. the customer’s authorized admins/users)
- We do not publicly republish LinkedIn member personal data
5.3 Prohibited uses (we do not do these with LinkedIn Community Management data)
- We do not use LinkedIn member data for advertising, sales prospecting, recruiting, lead generation, CRM enrichment, audience list building, ad targeting, account-based marketing, or mass messaging
- We do not use Community Management API data to build a social feed of LinkedIn updates for display on public websites or intranets
- We do not sell, rent, or trade LinkedIn member data
- We do not use LinkedIn or Microsoft names/logos in a way that implies endorsement, and our app name does not include LinkedIn branding
- We do not create fake/headless LinkedIn profiles or misuse individual profiles to manage unrelated customers’ accounts
5.4 Storage limits for LinkedIn Marketing / Community Management data
Where Softop processes data received via LinkedIn Marketing / Community Management APIs, we follow LinkedIn’s
data storage requirements (or shorter periods). In particular:
| LinkedIn data type |
Softop retention approach |
| Authenticated member person ID / URN and that member’s basic profile (page admin who connected Softop) |
Stored while the LinkedIn connection / Softop account needs it; deleted on disconnect or account closure (subject to legal holds) |
| Other members’ basic profile data (e.g. commenters / engagers) |
Cached at most 24 hours; not stored beyond caching needed to display engagement |
| Members’ social activity data (member posts, likes, comments, mentions, related metadata) |
Retained at most 48 hours |
| Organizations’ social activity data for pages authenticated into Softop |
Up to six months (or shorter if LinkedIn requirements become stricter) |
| Organization profile data for authenticated pages |
Up to eight weeks |
| Organization page admin / reporting aggregates (non-individual) |
Up to one year |
| IDs/URNs for organizations, posts, and social actions used to manage page activity |
While needed to operate the connected features; deleted when no longer required or on disconnect |
If LinkedIn’s requirements and this policy conflict, the more restrictive / more protective rule applies.
Data your organization independently provides to Softop (and not retrieved via LinkedIn APIs) is not limited by the table above
and is retained under Section 7.
6. Legal bases (GDPR)
Depending on the context, we process personal data on these bases:
- Contract: to provide Softop services you request
- Consent: for optional integrations (including LinkedIn OAuth) and certain communications
- Legitimate interests: securing our services, preventing abuse, and improving reliability — balanced against your rights
- Legal obligation: tax, accounting, and other mandatory compliance
7. Retention (non-LinkedIn Softop data)
- Account and configuration data: for the life of the account and a reasonable period afterward for backup, dispute, and compliance purposes
- Invoicing / fiscal records: for the periods required by applicable Greek and EU tax/commercial law
- Support and contact messages: as needed to handle your request and maintain service records
- Logs: for security and diagnostics for a limited period
- Social drafts you create in Softop: until you delete them or close the account, unless a shorter platform-specific rule applies to mirrored third-party data
8. Your rights and choices
Subject to applicable law (including GDPR), you may request to:
- Access your personal data
- Correct inaccurate or incomplete data
- Delete your personal data
- Restrict or object to certain processing
- Receive a portable copy of data you provided
- Withdraw consent at any time (without affecting prior lawful processing)
To exercise these rights, email [email protected].
We will respond within the time required by law. You may also lodge a complaint with the Hellenic Data Protection Authority
(www.dpa.gr) or your local supervisory authority.
8.1 Disconnecting LinkedIn / deletion of LinkedIn data
- Disconnect Softop in your Softop account settings and/or revoke the Softop app under LinkedIn → Settings → Data privacy → Permitted services
- Request deletion of LinkedIn-derived data associated with your Softop account by emailing [email protected]
- Upon disconnect or a valid deletion request, we delete or irreversibly de-identify LinkedIn data we hold, except where we must retain limited records to meet legal obligations or resolve disputes
9. Sharing and disclosure
We do not sell personal information. We may share data only with:
- Service providers that help us host, operate, send messages, or secure Softop (under confidentiality and data-processing terms)
- Platform providers you connect (e.g. LinkedIn), to carry out actions you request such as publishing a post
- Your organization — admins and authorized users of your Softop workspace
- Authorities when required by law or to protect rights, safety, and security
Softop customers act as independent controllers (or joint controllers, where applicable) for data they upload or instruct Softop to process
for their own business purposes. Softop processes such data on their instructions as a processor where GDPR requires that role.
10. International transfers
Softop primarily operates services for customers in Greece and the EU. If personal data is transferred outside the EEA,
we use appropriate safeguards (such as EU Standard Contractual Clauses) where required by law.
11. Security
We implement technical and organizational measures appropriate to the risk, including:
- TLS encryption in transit
- Access controls, authenticated sessions, and least-privilege administrative access
- Hashed passwords and protected secrets management practices
- Monitoring, logging, and rate limiting to reduce abuse
- Vendor and infrastructure hardening for production systems
No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal data,
we will notify you and regulators as required by law, and we will notify LinkedIn where a breach may impact LinkedIn members
in connection with our LinkedIn integration.
12. Cookies
We use essential cookies and similar technologies for login sessions, security, and basic site operation.
We do not use LinkedIn member data obtained via Community Management APIs for cross-site advertising cookies.
13. Third-party services
Softop may link to or integrate with third-party services (ERP vendors, eshop platforms, messaging providers, LinkedIn, etc.).
Their privacy practices are governed by their own policies. Please review those policies before connecting an integration.
LinkedIn’s privacy policy is available at
linkedin.com/legal/privacy-policy.
14. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do.
Material changes will be posted on this page. If a change materially affects how we use LinkedIn data,
we will obtain any additional consent required and update our LinkedIn app listing / access request information as needed.
15. Contact