Last updated: 8 September 2026
On this page
1. Who we are
2. Our two roles — read this first
3. Personal data we collect as a controller
4. Legal bases (GDPR / UK GDPR)
5. Connected social Channels
6. Who we share personal data with
7. International transfers
8. Retention
9. Cookies and tracking
10. Your rights
11. Security
12. Children
13. Automated decision-making
14. Changes
15. Contact
Sociali — Privacy Policy
Last updated: 8 September 2026
1. Who we are
Sociali LLC, a Wyoming limited liability company trading as Sociali, 1023 E Lincolnway, Cheyenne, Wyoming 82001, United States.
General privacy enquiries: privacy@sociali.ai
Data subject / consumer rights requests: privacy@sociali.ai
Security: security@sociali.ai
[EU representative under GDPR Art. 27 — required if you target EU data subjects and have no EU establishment. Appoint one and name them here.]
[UK representative under UK GDPR Art. 27 — same requirement for UK data subjects.]
This policy explains how we handle personal data across the Sociali website (sociali.ai), the Sociali web application, and our APIs (together, the “Service“).
2. Our two roles — read this first
Sociali handles personal data in two distinct capacities, and your rights differ depending on which applies.
Controller
Processor
When
Data about our own customers and site visitors : account holders, Authorised Users, prospects, billing contacts, support correspondents, website visitors.
Data inside your workspace that you upload or connect: post content, brand assets, audience and engagement data pulled from your connected Channels, review authors, commenters, and anyone appearing in content you publish.
Who decides the purpose
We do.
You do. We act on your documented instructions.
Governed by
This Privacy Policy.
Our Data Processing Agreement , which forms part of your contract.
Rights requests go to
Us, at privacy@sociali.ai.
You , as controller. If an individual contacts us directly about workspace data, we will refer them to you and assist you in responding.
If you are an end user or a member of the public whose data appears in a Sociali customer’s workspace (for example, you left a Google review or commented on a post the customer manages), the customer is the controller. Contact them first; we will help them respond.
3. Personal data we collect as a controller
3.1 You give us
Category
Examples
Why
Account
Name, work email, password hash, avatar, job title, timezone, language
Create and secure your account
Organisation
Company name, Brands you manage, team members you invite, roles
Provide the multi-tenant workspace
Billing
Billing name, billing email, address, VAT/tax ID, plan, invoice history, last 4 digits and card brand only
Take payment, invoice, comply with tax law
Support
Emails, chat messages, attachments, demo booking details
Answer you
Marketing
Email address, form responses, content downloaded, demo requests
Send you material you asked for
We never see or store full card numbers. Payment card details are collected directly by Stripe in a payment form hosted by Stripe. See §6.
3.2 We collect automatically
Category
Examples
Why
Device & connection
IP address, browser and version, OS, device type, screen size
Deliver the site, security, fraud prevention
Usage
Pages and features used, clicks, session duration, referring URL, feature adoption events
Improve the product, measure the business
Diagnostics
Error traces, stack traces, performance timings, request IDs, breadcrumb events
Detect and fix faults
Cookies & similar
See §9
See §9
3.3 We receive from others
Connected social Channels — when you connect a Channel via OAuth, we receive the account/page identity and the profile, content, and insights data covered by the scopes you approve. See §5.
Payment processor — subscription status, payment success or failure, dispute notices.
Enrichment and prospecting sources — [Name the sources if the marketing stack enriches contact data; otherwise delete this line.]
4. Legal bases (GDPR / UK GDPR)
Purpose
Legal basis
Providing the Service to you under our Terms
Contract (Art. 6(1)(b))
Billing, invoicing, collections
Contract; Legal obligation (Art. 6(1)(c))
Securing the Service, preventing abuse and fraud
Legitimate interests (Art. 6(1)(f)) — protecting our platform and our customers
Product analytics and improvement
Legitimate interests; Consent where required by ePrivacy for non-essential cookies
Marketing to business contacts
Legitimate interests, or Consent where required by local law (opt-in in the EU/UK)
Retaining records for tax, accounting, legal claims
Legal obligation; Legitimate interests
Responding to lawful requests from authorities
Legal obligation
You may object to processing based on legitimate interests at any time — see §10. You may withdraw consent at any time without affecting prior processing.
5. Connected social Channels
When you connect a Channel, you authorise us — through the platform’s own OAuth consent screen — to act on your behalf. The specific scopes are shown to you at the moment of connection and are the authoritative statement of what we can access.
Broadly, for the platforms we support (Facebook, Instagram, LinkedIn, Threads, TikTok, Google Business Profile), we may:
read the connected account/page/location identity and profile;
publish, schedule, and delete content you create in Sociali;
read post performance, audience, and engagement metrics;
read and, where you enable it, reply to comments and reviews.
What this means for third parties. Data about other people — commenters, reviewers, followers, and the aggregate audience data platforms return — flows into your workspace. You are the controller of that data. For Google Business Profile in particular, we store review author display names, profile photo URLs, and review text. You must have a lawful basis for that processing and must tell those individuals as your own privacy notice requires.
Disconnecting. Removing a Channel revokes our token and stops all further access. Data already retrieved remains in your workspace until deleted under §8.
Platform data policies. Our use of information received from these APIs also adheres to each platform’s developer and platform-data policies, including the Meta Platform Terms, LinkedIn API Terms, TikTok Developer Terms, and the Google API Services User Data Policy including its Limited Use requirements.
6. Who we share personal data with
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
We disclose personal data to:
Sub-processors — vendors who process data to help us run the Service. The current list, with each vendor’s purpose, data categories, and location, is published at https://sociali.ai/subprocessors. Each is bound by a written contract with confidentiality and security obligations at least as protective as ours.
Connected platforms you choose — content you schedule is transmitted to the Channels you connect, at your instruction.
Professional advisers — lawyers, auditors, accountants, insurers, under duty of confidence.
Corporate transactions — an acquirer or successor in a merger, acquisition, financing, or sale of assets, subject to this policy and with notice to you.
Authorities — where legally compelled. We will notify you of a request for your workspace data unless legally prohibited, and we will challenge overbroad or unlawful requests.
We do not permit our AI sub-processors to use your content to train their general-purpose models. This is contracted through zero-data-retention or no-training terms with the providers listed in the Sub-processors document.
7. International transfers
We are established in the United States and our infrastructure runs primarily in the United States (us-central1, and Vercel/Supabase US regions). If you are in the EEA, UK, or Switzerland, your personal data will be transferred to and processed in the United States and in other countries where our sub-processors operate.
For those transfers we rely on:
the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two or Three as applicable, incorporated into our DPA;
the UK International Data Transfer Addendum to the SCCs;
the Swiss addendum, where relevant;
supplementary technical and organisational measures described in our Security page.
[Consider self-certifying to the EU–US Data Privacy Framework; it simplifies enterprise EU sales.]
A copy of the transfer mechanism is available on request at privacy@sociali.ai.
[Decide the position to state on EU/UK data residency.]
8. Retention
Data
Retention
Account and profile
For the life of the account, then [90] days after closure
Customer Data in your workspace
Until you delete it, or [30] days after subscription termination for export, then deleted within [90] days (§14.5 of the Terms)
Backups
Rolling [30]-day cycle; deleted data ages out with the backup
Billing and tax records
7 years (US tax and accounting requirements)
Security and audit logs
[12] months
Application and diagnostic logs
[90] days
Support correspondence
[3] years from last contact
Marketing contacts
Until you unsubscribe, then suppression-list only
Analytics events
[Set a retention period once enforced.]
9. Cookies and tracking
We use:
Strictly necessary — authentication, session, security, CSRF, load balancing. Cannot be disabled.
Functional — remembering preferences such as language, timezone, and UI state.
Analytics — understanding feature usage and improving the product.
Marketing — [Enumerate the tags actually deployed on the marketing site.]
[Deploy a consent management platform and publish a full cookie table at /cookies before serving EU/UK visitors — non-essential cookies require prior opt-in consent under the ePrivacy Directive.]
We honour Global Privacy Control (GPC) signals as an opt-out of sale/sharing where applicable law requires.
10. Your rights
10.1 EEA / UK / Switzerland
You have the right to: access your data; rectify it; erase it; restrict processing; object to processing based on legitimate interests or direct marketing; data portability; and to withdraw consent. You also have the right to lodge a complaint with your supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk).
10.2 California (CCPA/CPRA)
You have the right to know, delete, correct, opt out of sale/sharing (we do not sell or share), limit use of sensitive personal information (we do not use it for inferring characteristics), and to non-discrimination for exercising rights. You may use an authorised agent.
Categories collected in the last 12 months: identifiers; commercial information; internet/network activity; geolocation (approximate, from IP); professional/employment information; audio/visual information (content you upload); inferences. Sources, purposes, and recipients are described in §§3, 4 and 6. Retention is in §8.
10.3 Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have comparable rights, including appeal of a denied request. To appeal, reply to our decision or write to privacy@sociali.ai with “Appeal” in the subject.
10.4 How to exercise
Email privacy@sociali.ai. We will verify your identity proportionately to the sensitivity of the request. We respond within 30 days (EEA/UK, extendable by two months for complex requests) or 45 days (US states, extendable once). There is no fee unless the request is manifestly unfounded or excessive.
[Build self-serve export and account deletion in the product — questionnaires ask specifically whether a self-serve mechanism exists.]
11. Security
We maintain administrative, technical and physical safeguards described on our Security page. No system is perfectly secure; we do not guarantee absolute security.
We will notify affected customers of a personal data breach without undue delay and in any event within 72 hours of becoming aware where required, with the information needed for you to meet your own notification obligations.
12. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@sociali.ai and we will delete it.
You must not upload data about children under 13 to the Service — see the Acceptable Use Policy §4.
13. Automated decision-making
We do not make decisions producing legal or similarly significant effects about individuals through solely automated means. Our AI Features generate content suggestions; a human user reviews and decides whether to publish.
14. Changes
We will post updates here and change the “Last updated” date. For changes that materially affect how we handle personal data, we will notify account administrators by email at least [30] days before they take effect.
We keep prior versions available on request so you can see what changed.
15. Contact
Sociali LLC · 1023 E Lincolnway, Cheyenne, Wyoming 82001, USA
privacy@sociali.ai · security@sociali.ai · legal@sociali.ai