Sociali — Privacy Policy

Sociali — Privacy Policy

Last updated: 8 September 2026

On this page

1. Who we are

2. Our two roles — read this first

3. Personal data we collect as a controller

4. Legal bases (GDPR / UK GDPR)

5. Connected social Channels

6. Who we share personal data with

7. International transfers

8. Retention

9. Cookies and tracking

10. Your rights

11. Security

12. Children

13. Automated decision-making

14. Changes

15. Contact

Sociali — Privacy Policy

Last updated: 8 September 2026

1. Who we are

Sociali LLC, a Wyoming limited liability company trading as Sociali, 1023 E Lincolnway, Cheyenne, Wyoming 82001, United States.

  • General privacy enquiries: privacy@sociali.ai

  • Data subject / consumer rights requests: privacy@sociali.ai

  • Security: security@sociali.ai

  • [EU representative under GDPR Art. 27 — required if you target EU data subjects and have no EU establishment. Appoint one and name them here.]

  • [UK representative under UK GDPR Art. 27 — same requirement for UK data subjects.]

This policy explains how we handle personal data across the Sociali website (sociali.ai), the Sociali web application, and our APIs (together, the “Service“).

2. Our two roles — read this first

Sociali handles personal data in two distinct capacities, and your rights differ depending on which applies.

Controller

Processor

When

Data about our own customers and site visitors : account holders, Authorised Users, prospects, billing contacts, support correspondents, website visitors.

Data inside your workspace that you upload or connect: post content, brand assets, audience and engagement data pulled from your connected Channels, review authors, commenters, and anyone appearing in content you publish.

Who decides the purpose

We do.

You do. We act on your documented instructions.

Governed by

This Privacy Policy.

Our Data Processing Agreement , which forms part of your contract.

Rights requests go to

Us, at privacy@sociali.ai.

You , as controller. If an individual contacts us directly about workspace data, we will refer them to you and assist you in responding.

If you are an end user or a member of the public whose data appears in a Sociali customer’s workspace (for example, you left a Google review or commented on a post the customer manages), the customer is the controller. Contact them first; we will help them respond.

3. Personal data we collect as a controller

3.1 You give us

Category

Examples

Why

Account

Name, work email, password hash, avatar, job title, timezone, language

Create and secure your account

Organisation

Company name, Brands you manage, team members you invite, roles

Provide the multi-tenant workspace

Billing

Billing name, billing email, address, VAT/tax ID, plan, invoice history, last 4 digits and card brand only

Take payment, invoice, comply with tax law

Support

Emails, chat messages, attachments, demo booking details

Answer you

Marketing

Email address, form responses, content downloaded, demo requests

Send you material you asked for

We never see or store full card numbers. Payment card details are collected directly by Stripe in a payment form hosted by Stripe. See §6.

3.2 We collect automatically

Category

Examples

Why

Device & connection

IP address, browser and version, OS, device type, screen size

Deliver the site, security, fraud prevention

Usage

Pages and features used, clicks, session duration, referring URL, feature adoption events

Improve the product, measure the business

Diagnostics

Error traces, stack traces, performance timings, request IDs, breadcrumb events

Detect and fix faults

Cookies & similar

See §9

See §9

3.3 We receive from others

  • Connected social Channels — when you connect a Channel via OAuth, we receive the account/page identity and the profile, content, and insights data covered by the scopes you approve. See §5.

  • Payment processor — subscription status, payment success or failure, dispute notices.

  • Enrichment and prospecting sources[Name the sources if the marketing stack enriches contact data; otherwise delete this line.]

4. Legal bases (GDPR / UK GDPR)

Purpose

Legal basis

Providing the Service to you under our Terms

Contract (Art. 6(1)(b))

Billing, invoicing, collections

Contract; Legal obligation (Art. 6(1)(c))

Securing the Service, preventing abuse and fraud

Legitimate interests (Art. 6(1)(f)) — protecting our platform and our customers

Product analytics and improvement

Legitimate interests; Consent where required by ePrivacy for non-essential cookies

Marketing to business contacts

Legitimate interests, or Consent where required by local law (opt-in in the EU/UK)

Retaining records for tax, accounting, legal claims

Legal obligation; Legitimate interests

Responding to lawful requests from authorities

Legal obligation

You may object to processing based on legitimate interests at any time — see §10. You may withdraw consent at any time without affecting prior processing.

5. Connected social Channels

When you connect a Channel, you authorise us — through the platform’s own OAuth consent screen — to act on your behalf. The specific scopes are shown to you at the moment of connection and are the authoritative statement of what we can access.

Broadly, for the platforms we support (Facebook, Instagram, LinkedIn, Threads, TikTok, Google Business Profile), we may:

  • read the connected account/page/location identity and profile;

  • publish, schedule, and delete content you create in Sociali;

  • read post performance, audience, and engagement metrics;

  • read and, where you enable it, reply to comments and reviews.

What this means for third parties. Data about other people — commenters, reviewers, followers, and the aggregate audience data platforms return — flows into your workspace. You are the controller of that data. For Google Business Profile in particular, we store review author display names, profile photo URLs, and review text. You must have a lawful basis for that processing and must tell those individuals as your own privacy notice requires.

Disconnecting. Removing a Channel revokes our token and stops all further access. Data already retrieved remains in your workspace until deleted under §8.

Platform data policies. Our use of information received from these APIs also adheres to each platform’s developer and platform-data policies, including the Meta Platform Terms, LinkedIn API Terms, TikTok Developer Terms, and the Google API Services User Data Policy including its Limited Use requirements.

6. Who we share personal data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

We disclose personal data to:

  1. Sub-processors — vendors who process data to help us run the Service. The current list, with each vendor’s purpose, data categories, and location, is published at https://sociali.ai/subprocessors. Each is bound by a written contract with confidentiality and security obligations at least as protective as ours.

  2. Connected platforms you choose — content you schedule is transmitted to the Channels you connect, at your instruction.

  3. Professional advisers — lawyers, auditors, accountants, insurers, under duty of confidence.

  4. Corporate transactions — an acquirer or successor in a merger, acquisition, financing, or sale of assets, subject to this policy and with notice to you.

  5. Authorities — where legally compelled. We will notify you of a request for your workspace data unless legally prohibited, and we will challenge overbroad or unlawful requests.

We do not permit our AI sub-processors to use your content to train their general-purpose models. This is contracted through zero-data-retention or no-training terms with the providers listed in the Sub-processors document.

7. International transfers

We are established in the United States and our infrastructure runs primarily in the United States (us-central1, and Vercel/Supabase US regions). If you are in the EEA, UK, or Switzerland, your personal data will be transferred to and processed in the United States and in other countries where our sub-processors operate.

For those transfers we rely on:

  • the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two or Three as applicable, incorporated into our DPA;

  • the UK International Data Transfer Addendum to the SCCs;

  • the Swiss addendum, where relevant;

  • supplementary technical and organisational measures described in our Security page.

[Consider self-certifying to the EU–US Data Privacy Framework; it simplifies enterprise EU sales.]

A copy of the transfer mechanism is available on request at privacy@sociali.ai.

[Decide the position to state on EU/UK data residency.]

8. Retention

Data

Retention

Account and profile

For the life of the account, then [90] days after closure

Customer Data in your workspace

Until you delete it, or [30] days after subscription termination for export, then deleted within [90] days (§14.5 of the Terms)

Backups

Rolling [30]-day cycle; deleted data ages out with the backup

Billing and tax records

7 years (US tax and accounting requirements)

Security and audit logs

[12] months

Application and diagnostic logs

[90] days

Support correspondence

[3] years from last contact

Marketing contacts

Until you unsubscribe, then suppression-list only

Analytics events

[Set a retention period once enforced.]

9. Cookies and tracking

We use:

  • Strictly necessary — authentication, session, security, CSRF, load balancing. Cannot be disabled.

  • Functional — remembering preferences such as language, timezone, and UI state.

  • Analytics — understanding feature usage and improving the product.

  • Marketing[Enumerate the tags actually deployed on the marketing site.]

[Deploy a consent management platform and publish a full cookie table at /cookies before serving EU/UK visitors — non-essential cookies require prior opt-in consent under the ePrivacy Directive.]

We honour Global Privacy Control (GPC) signals as an opt-out of sale/sharing where applicable law requires.

10. Your rights

10.1 EEA / UK / Switzerland

You have the right to: access your data; rectify it; erase it; restrict processing; object to processing based on legitimate interests or direct marketing; data portability; and to withdraw consent. You also have the right to lodge a complaint with your supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk).

10.2 California (CCPA/CPRA)

You have the right to know, delete, correct, opt out of sale/sharing (we do not sell or share), limit use of sensitive personal information (we do not use it for inferring characteristics), and to non-discrimination for exercising rights. You may use an authorised agent.

Categories collected in the last 12 months: identifiers; commercial information; internet/network activity; geolocation (approximate, from IP); professional/employment information; audio/visual information (content you upload); inferences. Sources, purposes, and recipients are described in §§3, 4 and 6. Retention is in §8.

10.3 Other US states

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have comparable rights, including appeal of a denied request. To appeal, reply to our decision or write to privacy@sociali.ai with “Appeal” in the subject.

10.4 How to exercise

Email privacy@sociali.ai. We will verify your identity proportionately to the sensitivity of the request. We respond within 30 days (EEA/UK, extendable by two months for complex requests) or 45 days (US states, extendable once). There is no fee unless the request is manifestly unfounded or excessive.

[Build self-serve export and account deletion in the product — questionnaires ask specifically whether a self-serve mechanism exists.]

11. Security

We maintain administrative, technical and physical safeguards described on our Security page. No system is perfectly secure; we do not guarantee absolute security.

We will notify affected customers of a personal data breach without undue delay and in any event within 72 hours of becoming aware where required, with the information needed for you to meet your own notification obligations.

12. Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@sociali.ai and we will delete it.

You must not upload data about children under 13 to the Service — see the Acceptable Use Policy §4.

13. Automated decision-making

We do not make decisions producing legal or similarly significant effects about individuals through solely automated means. Our AI Features generate content suggestions; a human user reviews and decides whether to publish.

14. Changes

We will post updates here and change the “Last updated” date. For changes that materially affect how we handle personal data, we will notify account administrators by email at least [30] days before they take effect.

We keep prior versions available on request so you can see what changed.

15. Contact

Sociali LLC · 1023 E Lincolnway, Cheyenne, Wyoming 82001, USA

privacy@sociali.ai · security@sociali.ai · legal@sociali.ai