Akemis Creator Analytics
Privacy Policy
1. Who we are
This Privacy Policy describes how Akemis (HK) Limited ("Akemis", "we", "us") collects, uses, and protects personal data in connection with the Akemis Creator Analytics application (the "Service").
- Data controller: Akemis (HK) Limited, [Registered office address, Hong Kong]
- Contact for privacy enquiries: invoicing@akemis.com
- EU Representative (GDPR Article 27): [To be appointed if/when EU-resident data subjects are processed — e.g. EDPO, Prighter, or VeraSafe]
2. What the Service does
The Service is an internal analytics tool that helps a small number of authorised content creators understand the performance of their TikTok videos and the resulting commercial impact of links they include in those videos. The Service is not offered to the general public, does not sell data, and does not deliver advertising.
3. Personal data we collect
We process the following categories of personal data:
From content creators who connect their TikTok account to the Service:
- Public profile information (display name, handle, avatar, bio, follower count, total likes)
- List of their published videos and associated metadata (caption, hashtags, sound, posting time)
- Per-video engagement metrics (views, likes, comments, shares, saves)
- Authentication tokens (OAuth access and refresh tokens issued by TikTok)
- Video files downloaded from TikTok for content analysis (transcripts, on-screen text, scene description)
From viewers and customers who interact with creator-supplied links:
- Click events on shortened URLs (timestamp, country derived from IP, referring page, device type)
- Pseudonymised order data forwarded by partner platforms (e.g. Litbuy) — typically: pseudonymised customer ID, supplier ID, order amount, order timestamp, referring video identifier
- We do not collect names, email addresses, postal addresses, or payment details of viewers or customers.
From operational use:
- Diagnostic logs from the analytics pipeline (error messages, sync timestamps)
4. Why we process this data (purposes and legal bases)
| Purpose | Legal basis (GDPR) |
|---|---|
| Reading creators' TikTok metrics via OAuth | Consent (Art. 6(1)(a)) — granted via TikTok OAuth screen |
| Downloading and analysing creator videos for performance insights | Consent (Art. 6(1)(a)) and contract (Art. 6(1)(b)) — necessary to provide the Service |
| Counting and attributing link clicks at video level | Legitimate interest (Art. 6(1)(f)) — measuring marketing effectiveness; minimal data, no individual profiling |
| Calculating commissions based on conversions reported by partners | Contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) |
| Security, troubleshooting, fraud prevention | Legitimate interest (Art. 6(1)(f)) |
Under Hong Kong's PDPO, the corresponding lawful basis is consent (creators) and legitimate purpose directly related to a function or activity of Akemis (operational data).
5. Who we share data with
We share personal data only with the following categories of recipients, each acting as a processor under a written agreement:
- TikTok / ByteDance (source of creator and video data — pursuant to the TikTok API Terms of Service)
- Cloud infrastructure providers: [Supabase / Cloudflare / Cloudinary — list the ones actually used]
- Link-tracking provider: [Bitly, if used]
- AI processing providers for transcription and content analysis: [OpenAI (Whisper), Google (Gemini), and/or Anthropic (Claude) — list the ones actually used]
- Partner platforms (e.g. Litbuy) for the limited purpose of receiving pseudonymised conversion data
We do not sell personal data and do not share it with advertisers.
6. International transfers
Personal data may be processed outside Hong Kong and outside the European Economic Area, including in the United States and other jurisdictions where our processors operate. Where applicable:
- Transfers from the EEA are governed by the European Commission's Standard Contractual Clauses (SCCs).
- Transfers from Hong Kong follow the cross-border transfer guidance issued by the PCPD (Office of the Privacy Commissioner for Personal Data).
7. Retention
| Data category | Retention |
|---|---|
| Creator OAuth tokens | Until creator revokes access or relationship ends, plus 30 days |
| Video metrics and analysis | 24 months after collection |
| Click and order events | 24 months after collection |
| Aggregated/anonymised analytics | Indefinite (no longer personal data) |
| Operational logs | 90 days |
8. Your rights
Depending on the jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data erased ("right to be forgotten")
- Object to or restrict certain processing
- Receive your data in a portable format
- Withdraw consent at any time (without affecting prior processing)
- Lodge a complaint with a supervisory authority — in the EEA, your local DPA; in Hong Kong, the PCPD (pcpd.org.hk)
To exercise any of these rights, email invoicing@akemis.com with the subject line "Privacy Request". We respond within 30 days.
Creators can also revoke the Service's access to their TikTok account at any time directly from TikTok settings → Manage app permissions.
9. Security
We protect personal data with: encryption in transit (TLS 1.2+), encryption at rest, access controls limited to authorised personnel, OAuth tokens stored in a secrets vault (not in code or logs), audit logging of administrative actions.
10. Children
The Service is not directed at children. We do not knowingly process personal data of anyone under 16.
11. Changes to this policy
We will update this page when our processing changes. Material changes will be notified to connected creators by email at least 14 days before taking effect.
12. Contact
Akemis (HK) Limited[Registered office address]
Email: invoicing@akemis.com
