What we store
Your Google sign-in basics, the pages and accounts you connect, and the posts and comments we sync from them so your team can manage them in one inbox.
What we never do
We don't sell your data, use it for advertising, or train AI models on it. We don't store images or videos either; media stays on the platforms' own servers.
Where it lives
On our own servers in the European Union (OVHcloud, France). A small set of named providers process specific slices, listed in full in section 5.
Your controls
Disconnect any platform in Settings at any time, ask us to delete everything at hello@socia.cx, and exercise the full set of UK GDPR rights (section 10).
01 Who we are & scope
Socia (“Socia”, “we”, “us”) operates the service at socia.cx from the United Kingdom. You can reach us at hello@socia.cx.
This policy covers the Socia website, dashboard, and mobile apps. Two roles matter when you read it:
- For your account data (your sign-in details, team, settings, billing), we decide how and why it is processed, acting as the data controller.
- For your audience's data (the comments, names, and profile details of people who interact with your connected social accounts), we process it on your organisation's behalf and on your instructions, to provide the service to you.
02 Information we collect
Account & team
- Google sign-in: your name, email address, and profile picture, used to create and identify your account. We never see your Google password.
- Organisation data: your team name, member list, roles, and pending invitations.
Connected social platforms
When you connect Facebook, Instagram, or TikTok, we access those platforms strictly through the permissions you grant on their consent screens:
- Access tokens that let Socia act on your behalf. We never see your platform passwords.
- Account metadata: page and account names, usernames, IDs, and profile images.
- Content: your posts, videos and captions, and the comments on them, including each commenter's public display name, platform ID, comment text, and timestamps.
- Ad references: if you grant ad access, your ad account IDs and the identifiers of currently running ads, used solely so comments on your ads appear in your inbox. We do not collect ad spend, targeting, or performance data.
- What we deliberately don't store: images and videos. Media is loaded from the platforms' own servers when you view it; only the URLs pass through us.
Content you create in Socia
- Replies you write or send, labels, assignments, resolved/unresolved status, and notes.
- AI configuration you provide, such as brand voice, context notes, and custom instructions used to shape AI-drafted replies.
Billing
Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers. We store records of purchases (package, amount, date, who purchased) and a running usage ledger for AI features (token counts and credits used per draft).
Technical & usage data
- Server logs: IP address, browser type, and requested URLs, kept briefly for security and debugging.
- Page analytics: aggregate page-view statistics via Oculis Analytics (see section 9).
03 How we use information
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Providing the service: syncing your content, showing your inbox, sending replies, running your team | Performance of our contract with you |
| AI features: drafting replies and classifying comment sentiment and topics (section 4) | Performance of our contract with you |
| Billing, receipts, and preventing abuse of paid features | Contract; legitimate interests; legal obligation (tax/accounting) |
| Security: protecting accounts, investigating misuse, keeping logs | Legitimate interests |
| Improving Socia via aggregate, non-identifying usage analytics | Legitimate interests |
| Service emails: invites, security notices, important product changes | Contract; legitimate interests |
We do not sell personal data, share it with data brokers, or use your content or your audience's content for advertising.
04 AI features & automated processing
Two AI features process comment text, and it's worth being precise about both:
- Automatic sentiment & labels: every synced comment's text (with the post caption and parent comment for context) is sent to an AI model to classify its sentiment (positive / neutral / negative) and apply your organisation's labels. This runs automatically as comments arrive.
- Reply drafts: when you click to draft a reply, the comment thread and your brand-voice settings are sent to an AI model, which returns a suggested reply. Nothing is sent to anyone until you review and choose to send it.
The AI providers we use (listed in section 5) receive the text needed for the feature and return a result. We never use your content to train AI models ourselves and choose provider settings that restrict training use. The classifications we store (a sentiment value and label names) are indicative aids for your team, not decisions with legal effect on anyone.
06 International transfers
Our own infrastructure is in the EU. Where a provider processes data in the United States (Anthropic, OpenRouter, Groq, and parts of Stripe, Google, Meta, and TikTok), we rely on appropriate safeguards recognised under UK GDPR: the UK's data-bridge and adequacy decisions, and standard contractual clauses in the providers' data-processing terms.
07 Retention & deletion
- While connected: we keep synced content so your inbox has history your team can search and act on.
- Disconnecting a platform (Settings) immediately deletes our access tokens and stops all syncing. Your organisation's existing inbox history is kept so your records survive a reconnect; ask us and we'll erase it instead.
- Account deletion: email hello@socia.cx and we delete your account, your organisation (if you're its owner), and all associated data.
- Facebook data-deletion requests: if you ask Meta to delete your data from Socia, their automated request to us removes your Facebook connection and its access grants, with a confirmation code you can check.
- Housekeeping: operational telemetry (sync-job logs) is automatically deleted after 14 days; server logs rotate out on short cycles and database backups are periodically replaced; billing records are kept as long as tax law requires.
08 Security
- All traffic between you, our servers, and the platforms is encrypted in transit (TLS).
- Platform access tokens are held in our database with access restricted to the systems that need them, and are used only to call the platform APIs on your behalf.
- Production access is limited to the operators who run the service, and the dashboard enforces organisation boundaries so one customer can never read another's data.
- If a breach ever affects your data, we will notify you and the ICO as UK law requires.
10 Your rights
Under UK GDPR you can ask us to:
- Access: get a copy of the personal data we hold about you.
- Rectify: correct inaccurate data.
- Erase: delete your data (the “right to be forgotten”).
- Restrict or object: limit processing based on legitimate interests.
- Port: receive your data in a machine-readable format.
Email hello@socia.cx and we respond within one month. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk). If you're a commenter on a page managed through Socia rather than a Socia customer, we'll also refer your request to the organisation that manages that page.
11 Platform commitments
- Google: Socia's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
- Meta: we use Facebook and Instagram data solely to provide the service you connect, in line with Meta's Platform Terms, and honour Meta-initiated data-deletion requests automatically.
- TikTok: we access TikTok Business Account data under TikTok's terms using only the permissions you grant.
12 Children
Socia is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16 as a user of the service; if you believe a child has created an account, contact us and we will delete it.
13 Changes to this policy
When we change this policy we update the date at the top; for material changes we'll tell you in the product or by email before they take effect. Earlier versions are available on request.
14 Contact
Privacy questions, rights requests, or anything unclear: hello@socia.cx.