Morphos Studio

Privacy Policy

Version 1.1 · Last updated: 10 September 2026

1. Data controller

The data controller responsible for the processing described in this policy is Morphos Studio ("we", "us"), a web design studio operating in London, United Kingdom.

We have not appointed a Data Protection Officer because our processing does not meet the criteria requiring one. All privacy enquiries go to the contact above.

2. What this policy covers

It covers the internal publishing tool autopost (Meta App ID 1380546197018462) that we operate, and any personal data processed through it. The tool publishes our own video content (Instagram Reels) to Instagram professional accounts that we own and operate: @morphos_studiouk and @meowandvows. The tool has no end-user login and is used only by our own team.

3. What we process, why, and on what legal basis

DataPurposeLegal basisStorage
Access tokens (Meta)To authenticate our own API calls so we can publish our own contentLegitimate interests (operating our own publishing workflow)Stored locally on our own computer, access-restricted
Facebook Page IDs, Instagram professional account IDs and usernamesTo resolve the correct publishing target before each scheduled postLegitimate interestsUsed in-memory during a publishing run; not retained in our database
Publishing queue records (item ID, timestamp, Instagram media ID/permalink)Operational logging, duplicate-prevention and troubleshootingLegitimate interestsLocal files on our own computer
Server logs (including IP address) kept by our hosting providers (Cloudflare) and by Meta as API providerSecurity, abuse prevention and service deliveryLegitimate interests of those providers, as described in their own privacy noticesHeld by the providers under their retention rules

We do not rely on consent for any processing, we carry out no marketing or profiling, and we make no automated decisions with legal or similarly significant effects. We do not knowingly collect data from children: the tool is an internal business tool and is not directed to anyone under 16.

4. Sharing and international transfers

We do not sell data and we do not share it with third parties for their own marketing. Data is transmitted only to:

Both providers are based in the United States, so transfers leave the UK. Where a transfer occurs, it is protected by the provider's transfer safeguards (for example the UK International Data Transfer Addendum / Standard Contractual Clauses, or the UK–US Data Bridge where the provider is certified), as set out in those providers' own data transfer terms.

5. Retention

Access tokens are deleted or replaced when rotated and in any event no later than their expiry. Publishing queue records and operational logs are kept for up to 12 months so we can troubleshoot failed posts and prevent duplicate publishing, and are then deleted. We do not keep personal data for longer than necessary for that purpose.

6. Security

We restrict access to the tool and its credentials to our own staff, store tokens locally rather than in a public service, rotate tokens on a regular basis, and transmit data to the API over encrypted connections (HTTPS/TLS). If we became aware of a personal data breach affecting individuals' rights, we would assess it and, where required, notify the UK Information Commissioner's Office (ICO) within 72 hours and inform affected individuals without undue delay.

7. Your rights

Under the UK GDPR you have the right to:

To exercise any of these rights, email Morphostech@outlook.com. We will respond within one month; we may ask for information to confirm your identity. Because the tool processes very little personal data, in most cases we will simply confirm that we hold no personal data about you.

Right to complain

You have the right to lodge a complaint with the UK supervisory authority: the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk/make-a-complaint. We would appreciate the chance to address your concern first.

8. Cookies

These legal pages are static and set no cookies and run no analytics, advertising or tracking scripts, which is why you are not shown a cookie banner. Our hosting provider may process your IP address in its standard server logs for security and delivery purposes.

9. Changes to this policy

We may update this policy. The version number and "last updated" date above will change, and material changes will be reflected here before they take effect.


隐私政策(中文)

版本 1.1 · 最后更新:2026 年 9 月 10 日

1. 数据控制者

本政策所述处理的控制者为 Morphos Studio(下称"我们"),一家在伦敦运营的网页设计工作室。联系邮箱:Morphostech@outlook.com;邮寄地址与公司注册号:[待补充]。我们无需设立数据保护官(DPO),隐私事务由上述联系方式处理。

2. 处理范围

涵盖我们运营的内部发布工具 autopost(Meta 应用编号 1380546197018462)。该工具仅用于把我们自有的视频发布到我们自有的 Instagram 专业账号(@morphos_studiouk@meowandvows),无终端用户登录,仅内部团队使用。

3. 处理内容、目的与法律依据

访问令牌(用于我们自己的 API 调用鉴权,依据:正当利益,仅存本机受限访问);主页 ID 与 Instagram 账号 ID/用户名(用于定位发布目标,依据:正当利益,运行期内存处理不落库);发布队列记录(条目、时间戳、媒体 ID/链接,依据:正当利益,本机日志,用于防重复与排障);托管商(Cloudflare)与 Meta 采集的服务器日志含 IP(依据:服务商正当利益,用于安全与服务交付)。我们不依赖同意、无营销与画像、不做自动化决策、不面向 16 岁以下人群。

4. 共享与跨境传输

我们不出售数据,也不向第三方共享用于其营销。数据仅传输给 Meta(官方 Instagram Graph API 发布)与 Cloudflare(托管媒体与法务页)。两者位于美国,传输依据其各自的跨境传输保障条款(如 UK IDTA/SCC 或英国-美国数据桥)。

5. 保留期限

访问令牌在轮换或到期时删除;发布队列与运行日志最多保留 12 个月用于排障与防重复,之后删除。

6. 安全

仅内部人员可访问工具与凭据;令牌存本机而非公共服务;定期轮换;传输使用 HTTPS/TLS 加密。若发生影响个人权利的泄露,我们将按英国法律要求评估,必要时在 72 小时内通知 ICO 并及时告知受影响个人。

7. 你的权利

依英国 GDPR,你可要求访问更正删除限制处理反对基于正当利益的处理,以及获取可携带格式的数据。请邮件 Morphostech@outlook.com,我们将在 1 个月内回复。你可向英国监管机构 ICO(Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF,ico.org.uk/make-a-complaint)投诉。

8. Cookie

本法务页为静态页面,不使用 Cookie,也不含分析/广告/追踪脚本;托管商可能在其标准服务器日志中处理你的 IP。

9. 变更

我们可能更新本政策,版本号与更新日期会相应变化。

Contact: Morphostech@outlook.com