Privacy policy
Last updated 1 October 2026
Brandwall is a service that collects posts about a brand from Instagram, lets the brand choose which ones to show, and shows them on the brand's website. This policy explains what personal data Brandwall handles, why, and what your rights are.
1. Who we are
Brandwall is provided by Vikba ApS, CVR 40234047, Lemnosvej 28A, 2300 København S, Denmark.
Questions about privacy: [email protected].
2. Our two roles
- For people who use Brandwall (the brand's team), we decide how their account data is used. We are the data controller for that data.
- For Instagram posts and the people who made them, we work on behalf of the brand that connected its Instagram account. The brand is the data controller, and we are its data processor. We only use this data to provide Brandwall to that brand, as set out in our data processing agreement with the brand.
3. What we collect
| About | What | Where it comes from |
|---|---|---|
| People who use Brandwall | Name, email address, a one-way hash of your password (never the password itself), or the ID of your Google or Microsoft account if you log in with one. The brands you belong to and your role. | You, when you sign up or log in |
| Brands | Brand name, website address, and the logo, colours and fonts we read from the brand's public website. | The brand, and its public website |
| Instagram content | For posts by the brand, posts that tag the brand, and posts by accounts the brand trusts: the post ID, caption, picture or video, link, time it was posted, and the creator's Instagram username. | Instagram, through the account the brand connected |
| The brand's Instagram connection | The Instagram business account and Facebook Page the brand chose, and an access token. We store the token encrypted. | Meta, when the brand connects Instagram |
| Activity in Brandwall | What was done in a brand's account, by whom and when, for example "Approved 5 posts". | Using Brandwall |
| Security logs | IP address, browser type and the pages and requests made, kept to keep Brandwall safe and working. | Your browser |
Visitors to a brand's website who see a Brandwall wall: the wall sets no cookies and stores nothing in your browser. It counts views, posts opened and product taps without identifying you, so the brand can see how its wall does. Our servers see your IP address when your browser loads the wall, as any website does, and only keep it in short-lived security logs.
4. Why we use it, and on what legal basis
- To provide Brandwall to the brand and its team: performing our contract with the brand (GDPR article 6(1)(b)).
- To keep Brandwall secure, prevent misuse and fix problems: our legitimate interest in running a safe service (article 6(1)(f)).
- Instagram content is processed on the brand's instructions. The brand is responsible for having a legal basis, and Brandwall helps by asking creators for permission before their posts are shown.
We do not sell personal data, and we do not use it for advertising.
5. Where your data is kept, and who helps us
Brandwall runs in the European Union. Our servers, database and file storage are in the Netherlands (Amsterdam).
| Company | What they do for us | Where |
|---|---|---|
| Railway Corporation | Hosts our servers, database and file storage | EU West region, Amsterdam. Railway is a US company; transfers are covered by the EU Standard Contractual Clauses in its data processing agreement. |
| Meta Platforms | Source of Instagram data, through the account the brand connects. Meta's own privacy policy applies to Instagram. | Meta's services |
Before we start using another company to handle personal data, for example for sending email or taking payments, we will add it to this list.
6. How long we keep it
- Account data is kept while your account exists. When an account is closed, we delete it within 30 days.
- A brand's data, including its Instagram content, is kept while the brand uses Brandwall. When a brand leaves Brandwall or asks us to, we delete it within 30 days.
- Backups are kept for up to 4 weeks, so deleted data is fully gone from backups within 4 weeks after that.
- Security logs are kept for up to 30 days.
7. How we protect it
- All traffic is encrypted (HTTPS).
- Instagram access tokens are encrypted when stored. Passwords are stored only as one-way hashes.
- Each brand's data is kept separate in our database, so one brand can never see another brand's data.
- Only the parts of Brandwall that need the database can reach it.
8. Cookies
The Brandwall app uses one cookie to keep you logged in. It is strictly necessary and is not used for tracking. We use no advertising or analytics cookies. Walls on brands' websites set no cookies.
9. Your rights
You can ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable format. Write to [email protected]. We answer within one month.
If your Instagram post is shown by a brand, the brand decides about it. You can contact the brand, or write to us and we will pass your request on and help the brand handle it. See also how to delete your data.
You can complain to the Danish Data Protection Agency (Datatilsynet), datatilsynet.dk.
10. Changes
If we change this policy, we update the date at the top. If a change matters for how we use your data, we tell the brands that use Brandwall before it takes effect.