Our Commitment to Privacy
At Socigen, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, process, and safeguard your information when you use our social media management platform.
This policy complies with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy laws worldwide.
Data Controller Information
Socigen acts as the data controller for personal data processed through our platform. Our contact information:
Data Protection Officer: Thomas Cooke
Email: soci.gen.ai@gmail.com
Address: 261 Shankill Road
Belfast, BT13 1FR
Northern Ireland, UK
Information We Collect
Personal Information You Provide
- Account Information: Name, email address, phone number, company details
- Profile Information: Profile picture, bio, preferences, settings
- Content: Posts, images, videos, comments, and other content you create or share
- Payment Information: Billing address, payment method details (processed securely by third-party providers)
- Communication Data: Messages, support tickets, feedback, and correspondence
Information Collected Automatically
- Usage Data: How you interact with our platform, features used, time spent
- Device Information: IP address, browser type, operating system, device identifiers
- Log Data: Server logs, error reports, performance metrics
- Cookies and Tracking: Session data, preferences, authentication tokens
Social Media Platform Data
- Connected Accounts: Profile information from connected social media platforms
- Analytics Data: Performance metrics, engagement statistics, audience insights
- Content: Posts, media, comments from connected platforms (with your authorization)
Instagram & Facebook Data Access
When you connect your Instagram or Facebook account, we request specific permissions (scopes) via Instagram Login, Facebook Login (for Page management), and the Facebook Marketing API (for ad campaigns). Below is exactly what each permission grants us access to and why we need it:
Instagram Login Permissions
| Permission Scope | What We Access | Why We Need It |
|---|---|---|
instagram_business_basic | Your Instagram profile info (username, account type, profile picture) and media | To display your connected account and sync your content |
instagram_business_content_publish | Ability to create and publish posts on your behalf | To enable scheduled posting and content publishing |
instagram_business_manage_comments | Read and reply to comments on your media | To provide comment moderation tools |
instagram_business_manage_messages | Read and send Instagram Direct messages | To enable DM management features |
instagram_business_manage_insights | Account and media performance metrics | To generate analytics dashboards and reports |
Facebook Page Permissions (Graph API)
| Permission Scope | What We Access | Why We Need It |
|---|---|---|
pages_show_list | List of Facebook Pages you manage | To let you select which Pages to connect |
pages_read_engagement | Page post engagement data (reactions, comments, shares) | To display engagement analytics and enable comment management |
pages_manage_posts | Create and manage posts on your Pages | To enable scheduled posting and content publishing |
pages_manage_engagement | Respond to comments and messages on your Pages | To provide comment reply and moderation tools |
pages_read_user_content | User-generated content on your Pages (visitor posts, reviews) | To display and moderate community content |
pages_manage_metadata | Page settings and metadata | To sync Page profile information and settings |
pages_messaging | Send and receive Page messages via Messenger | To enable Messenger conversation management |
read_insights | Page and post performance analytics | To generate performance reports and dashboards |
business_management | Business asset access and management | To link your Business Manager assets and ad accounts |
public_profile | Your basic Facebook profile info (name, profile picture) | To identify your connected Facebook account |
Facebook Marketing API Permissions
| Permission Scope | What We Access | Why We Need It |
|---|---|---|
ads_management | Create, edit, and manage ad campaigns, ad sets, and ads | To enable the Meta Ads Campaign Wizard and campaign management |
ads_read | Read ad campaign performance data and metrics | To display ad analytics, spend tracking, and ROI reports |
leads_retrieval | Access lead form submissions from lead ads | To retrieve and display leads generated by your ad campaigns |
pages_manage_ads | Manage ads associated with your Pages | To link ad creatives to your Facebook Pages |
How We Protect Your Social Media Data
- Encrypted Tokens: Access tokens are encrypted server-side using AES-256 encryption and are never exposed to your browser
- Authentication Method: We use Instagram Login (OAuth 2.0) — we never see or store your Instagram/Facebook password
- Disconnect Anytime: You can disconnect your Instagram or Facebook account at any time via Settings, which immediately revokes all stored tokens and removes associated data
- Automated Data Deletion: We support Meta's data deletion callback — when you remove our app from your Meta account, your data is automatically deleted from our systems
How We Use Your Information
Service Provision
- Provide, maintain, and improve our social media management platform
- Enable you to create, schedule, and publish content across social platforms
- Generate analytics and insights about your social media performance
- Facilitate account management and user authentication
Communication
- Send service-related notifications and updates
- Respond to your inquiries and provide customer support
- Send marketing communications (with your consent)
- Notify you about new features, updates, and promotional offers
Legal Basis for Processing (GDPR)
- Contract Performance: Processing necessary to provide our services
- Legitimate Interest: Service improvement, security, fraud prevention
- Consent: Marketing communications, optional features
- Legal Obligation: Compliance with applicable laws and regulations
Data Sharing and Disclosure
Third-Party Service Providers
We may share your data with trusted third-party providers who assist us in:
- Cloud hosting and infrastructure services
- Payment processing and billing
- Analytics and performance monitoring
- Customer support and communication tools
- Security and fraud prevention services
Social Media Platforms
With your explicit authorization, we share content and interact with social media platforms (Facebook, Instagram, Twitter, LinkedIn, etc.) to provide our core services.
Legal Requirements
We may disclose your information when required by law or to:
- Comply with legal processes, court orders, or government requests
- Protect our rights, property, or safety
- Investigate potential violations of our Terms of Service
- Prevent fraud, security threats, or illegal activities
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction, subject to the same privacy protections.
Data Security and Protection
Security Measures
- Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Role-based access, multi-factor authentication
- Infrastructure: Secure cloud hosting with enterprise-grade security
- Monitoring: 24/7 security monitoring and incident response
- Regular Audits: Security assessments and penetration testing
Compliance Standards
- SOC 2 Type II: Annual compliance certification
- ISO 27001: Information security management standards
- GDPR: Full compliance with EU data protection regulations
- Industry Best Practices: Following OWASP and NIST guidelines
Data Breach Response
In the unlikely event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by GDPR and other applicable laws.
Your Privacy Rights (GDPR & CCPA)
GDPR Rights (EU Residents)
- Right of Access: Request copies of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Limit how we process your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for processing activities
CCPA Rights (California Residents)
- Right to Know: Information about data collection and use
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt-out of the sale of personal information
- Right to Non-Discrimination: Equal service regardless of privacy choices
Exercising Your Rights
To exercise any of these rights, please contact us at soci.gen.ai@gmail.com or through your account settings. We will respond to your request within 30 days (or as required by applicable law).
Data Retention
Retention Periods
- Account Data: Retained while your account is active plus 90 days after deletion
- Content: Retained according to your preferences and platform requirements
- Analytics Data: Aggregated data retained for up to 5 years for trend analysis
- Support Data: Communication records retained for 3 years
- Log Data: Technical logs retained for 12 months for security and debugging
Automated Deletion
We have automated systems in place to delete data according to our retention schedule. You can also request immediate deletion of your data by contacting us.
International Data Transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers:
- Adequacy Decisions: Transfers to countries with adequate data protection
- Standard Contractual Clauses: EU-approved contract terms with processors
- Binding Corporate Rules: Internal policies ensuring consistent protection
- Certification Programs: Participation in recognized privacy frameworks
Cookies and Tracking Technologies
Types of Cookies We Use
- Essential Cookies: Required for basic platform functionality
- Performance Cookies: Help us understand how you use our platform
- Functionality Cookies: Remember your preferences and settings
- Marketing Cookies: Used for targeted advertising (with consent)
Cookie Management
You can manage cookie preferences through your browser settings or our cookie consent manager. Note that disabling essential cookies may affect platform functionality.
Children's Privacy
Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us immediately.
If we discover that we have collected personal information from a child under 16, we will delete such information from our systems promptly.
Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Posting the updated policy on our website
- Sending email notifications to registered users
- Displaying prominent notices within our platform
Your continued use of our Service after the effective date of the updated Privacy Policy constitutes acceptance of the changes.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Officer: Thomas Cooke
Email: soci.gen.ai@gmail.com
General Inquiries: support@socigen.com
Address: 261 Shankill Road
Belfast, BT13 1FR
Northern Ireland, UK
Cookie Preferences
Change your cookie choices at any time. This will re-open the consent banner so you can accept or reject non-essential cookies again.