Privacy notice
Effective from 2 October 2026
This notice describes the information handled by Malholly, a scheduling and reporting workspace for TikTok advertising accounts, and by the website at malholly.com. It applies to people who connect an advertising account, to members of our team who use the workspace, and to anyone who writes to us.
1. Who we are
Malholly is operated by Mal & Holly Limited, a company registered in England and Wales under number 15140057, with its registered office at 128 City Road, London, EC1V 2NX. We are the data controller for the information described in this notice. You can reach us at support@malholly.com.
We process personal data under the UK General Data Protection Regulation and the Data Protection Act 2018.
2. Information we collect
From connected advertising accounts. When an account is connected, Malholly receives through the TikTok Marketing API:
- the advertiser ID, account name, currency and time zone;
- the IDs, names, status, schedule and budget of campaigns, ad groups and ads;
- daily totals for spend, impressions, clicks and conversions.
These are records about advertising activity. Malholly does not receive the names, contact details, device identifiers or browsing history of people who see or interact with an advertisement.
Connection credentials. TikTok issues an access token and a refresh token for each connected account. We store them in encrypted form. We never receive or store a TikTok password.
About people who use the workspace. Name, work email address, a hashed password, two-step verification settings, role, and a history of the actions taken in the workspace.
Technical records. Our servers log the date and time of each request, the page or endpoint requested, the response status and the IP address it came from.
Messages. If you email us, we keep your message, your address and our reply.
3. How we use it
| Purpose | Lawful basis |
|---|---|
| Showing campaigns in the calendar and switching them on and off as scheduled | Legitimate interests: managing the advertising accounts connected to the workspace |
| Producing the weekly performance summary | Legitimate interests: reporting on that advertising |
| Signing team members in and recording who did what | Legitimate interests: keeping the workspace secure and accountable |
| Finding faults and detecting misuse | Legitimate interests: keeping the service available and secure |
| Replying to enquiries and rights requests | Legitimate interests, and legal obligation where the law requires a reply |
We do not use any of this information for marketing, and we do not make decisions about individuals by automated means.
4. Data from TikTok
Information obtained through the TikTok Marketing API is used only to provide the functions described on our home page for the account it came from. We do not:
- sell it or license it to anyone;
- pass it to advertising networks, data brokers or other third parties for their own use;
- combine it with other data in order to identify or profile individuals;
- use it to train machine learning or artificial intelligence models;
- access any advertising account that has not been approved for connection on TikTok.
If TikTok's developer terms set a stricter rule than this notice on any point, we follow the stricter rule.
5. Who we share it with
- Service providers. The companies that host the workspace, its database, its backups and our email. They act on our instructions under contract and may not use the data for their own purposes.
- TikTok. Malholly sends requests to the TikTok Marketing API on behalf of connected accounts.
- Authorities. Where a law, court order or regulator requires disclosure, and only to the extent required.
We do not share information with anyone else.
6. How long we keep it
- Account details: for as long as the account is connected, then deleted within 10 days.
- Campaign structure, performance figures and action history: 13 months on a rolling basis.
- Access and refresh tokens: deleted immediately when the connection is withdrawn.
- Team member accounts: until access ends, then 6 months.
- Server logs: 90 days.
- Backups: encrypted and overwritten within 35 days.
- Emails: 12 months after the last message in the conversation.
7. Where it is stored
Malholly is hosted on servers in the United Kingdom and the European Economic Area. If we need to transfer personal data to a country that is not covered by UK adequacy regulations, we use the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
8. How we protect it
Data is encrypted in transit using HTTPS, and tokens and backups are encrypted at rest. Access to the workspace requires an individual account with two-step verification, and each role sees only what it needs. Administrative access is logged. If a personal data breach is likely to put people's rights at risk, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it and inform the people affected where the law requires.
9. Your rights
You have the right to:
- ask for a copy of the personal data we hold about you;
- ask us to correct data that is inaccurate;
- ask us to delete your data;
- ask us to restrict how we use it, or object to our use of it;
- ask for your data in a portable format.
To use any of these rights, email support@malholly.com. We confirm receipt within 2 working days and respond in full within 30 days. There is no charge. To delete the data of a connected advertising account, see data removal.
You can also complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to resolve your concern first.
10. Children
Malholly is a tool for work and is used only by adults on our team. We do not knowingly collect information from anyone under 18.
11. Cookies
This website does not use cookies, analytics or advertising trackers, and it loads nothing from other domains. The workspace uses a single session cookie that keeps a team member signed in. It is essential to the service and is removed at sign-out.
12. Changes to this notice
When we change this notice, we update the date at the top. If a change affects how we use data from a connected account, we will tell the person responsible for that account by email before the change applies.