bruknow
Pricing
Log in Get Started
Choose Language
English Español
Pricing Log in Get Started →
Choose Language
English Español
← Home
Privacy Policy TikTok Notice Terms of Service

TikTok Business Messaging Privacy Notice

Last updated: July 21, 2026

This notice explains how bruknow handles TikTok Business Messaging data. bruknow is operated by Framesoft Solutions Ltda. (NIT 900266799-2), a company registered in Bogotá, Colombia. It supplements our general Privacy Policy and applies specifically to data obtained through the TikTok Business Messaging API.

1. Our role

When a business connects its TikTok Business Account to bruknow, bruknow acts as a data processor on that business's behalf, to help it receive and respond to the direct messages its own customers send it. The business is the data controller of those conversations and remains responsible for obtaining any consent required from its own customers.

2. What we collect

  • Connected account data: the business's TikTok account identifier (open_id / business id), username, and profile picture.
  • Authorization tokens: OAuth access and refresh tokens for the connected account.
  • Direct messages: the content of messages exchanged between the business and the TikTok users who message it, plus basic sender identifiers (open_id and display name or nickname where provided).

We practise data minimization: we request only the permissions and data needed to provide the messaging service, and nothing more.

3. Why we collect it

  • To display the business's TikTok conversations in its bruknow inbox.
  • To let the business reply, automatically via its configured chatbot flow or manually via a human agent.
  • To operate, secure, and support the Service.

We do not sell TikTok data, do not use it for advertising or profiling, and do not use it to train third-party models beyond generating replies within the business's own conversation.

4. Where it is transferred (subprocessors)

TikTok data may be processed by the following subprocessors, which are bound by data-protection terms and may process it solely to provide the Service to us:

  • DigitalOcean — hosting and managed PostgreSQL/Valkey database.
  • OpenAI — generating automated replies within a conversation.
  • Microsoft 365 — email and operational notifications.

5. How we protect it

  • In transit: TLS 1.2 or higher (HTTPS) for all data exchange, webhooks, and OAuth redirects.
  • At rest: AES-256-GCM encryption of message content, identifiers, and tokens at the application layer, plus AES-256 storage-level encryption on the database.
  • Access control: least-privilege access protected by multi-factor authentication; each business's data is isolated from every other business's.

6. How long we keep it

  • Authorization tokens are deleted when the business disconnects its TikTok account.
  • Direct-message content is retained for up to 12 months, then deleted.
  • Ended conversations are pruned after 30 days by scheduled jobs.

7. Your rights

Individuals may request access, a copy of their data (portability), correction, or deletion. We respond within the period required by applicable law (for example, within 30 days under GDPR or CPRA). Requests are verified with the relevant TikTok Business Account before being actioned.

Contact for privacy requests

Email: [email protected]

Framesoft Solutions Ltda. — NIT 900266799-2 — Bogotá, Colombia

8. Changes to this notice

We may update this notice from time to time. The "Last updated" date above reflects the latest version.

bruknow

Conversational automation and artificial intelligence platform for businesses. Connect, automate, and scale your communication.

"From reasoning to knowing."

Platform

Chatflows AI Extraction Channels Flow Builder Live agents CRM

Modules

Email Service SMS Service AI Assistants WhatsApp Web Chat

Resources

How it works Free Demo Get Started
© 2026 bruknow. All rights reserved. Privacy Policy Terms of Service