Loading...
Last updated: 1 August 2026
This summary is for convenience. The full policy below is what applies.
SocialAuto is a sole proprietorship registered in Dhaka, Bangladesh, licensed for software development by Dhaka North City Corporation. We are the data controller for the personal data described in this policy, except where section 2 says otherwise.
| Registered name | SocialAuto |
| Trade licence | TRAD/DNCC/051526/2025, Dhaka North City Corporation |
| Registered address | Road 27/A, Plot 7, Rupnagar R/A, Mirpur, Dhaka 1216, Bangladesh |
| Nature of business | Software development |
Contact for any privacy matter: privacy@socialauto.site.
This policy applies to the SocialAuto web application at socialauto.site, its administrative interface, and the background services that publish content and retrieve engagement data on your behalf.
It covers two different relationships, and your rights differ between them:
This policy does not cover the social platforms themselves. Once content is published to Facebook, Instagram, LinkedIn, YouTube or X, that platform's own privacy policy governs it.
| Category | Examples | Where it comes from |
|---|---|---|
| Identity and contact | Name, email address, profile picture | You, or the provider you sign in with |
| Authentication | Password (stored only as a bcrypt hash), session cookies, email confirmation and password reset tokens | You |
| Content | Post drafts, captions, images, video, schedules, brand voice and persona settings, product catalogues, knowledge base documents | You |
| Connected account data | Access tokens, account name and identifier, profile picture, follower counts, published post identifiers | The social platform, with your authorisation |
| Engagement data | Impressions, reach, reactions, comments, shares, clicks, story metrics | The social platform |
| Message and comment data | Message and comment text, sender display name and platform identifier, attached images | The social platform, where you enable the bots |
| Billing | Plan, credit balance, transaction reference, amount, status, Stripe customer identifier | You and Stripe |
| Usage and technical | IP address, browser and device type, pages visited, timestamps, error reports | Automatically |
We do not collect special category data (health, biometrics, political opinions and similar) and ask that you do not upload it. We never receive or store full payment card numbers.
Connecting an account gives us an access token issued by that platform. We use it only for the features you have switched on, only for the accounts you connected, and only while the connection remains active.
| What we access | Why | Only when |
|---|---|---|
| Publish posts, images and video | To send the content you create or schedule | Always, for connected accounts |
| Account name, identifier, picture, follower count | So you can tell your connected accounts apart | Always, for connected accounts |
| Post performance metrics | To show analytics for posts published through SocialAuto | Always, for connected accounts |
| Comments on your posts | To draft and send replies | You enable the engagement bot |
| Direct messages to your accounts | To draft and send replies | You enable the message bot |
| Images sent by customers | To identify which product is being asked about | You enable the message bot and product catalogue |
What we do not do. We do not read your personal feed, your connections or contacts, or any account you have not connected. We do not use platform data for advertising, for building profiles of individuals, or for training our own models. We do not combine data across different customers. We do not sell it.
Where a platform requires it, our use is additionally governed by that platform's developer terms, including Meta's Platform Terms and LinkedIn's API Terms of Use.
Several features work by sending content to third-party AI providers. This is worth reading carefully, because it means data leaves our servers.
| Feature | What is sent |
|---|---|
| Post generation | Your topic or prompt, brand voice settings, selected persona |
| Message and comment replies | The incoming message or comment, sender display name, your knowledge base documents and product details, recent conversation history |
| Business scan | Your page profile, recent post text, and pages from the website listed on your profile |
| Image understanding | Images customers send to your accounts |
| Brand voice matching | Sample posts you provide, converted to numerical embeddings |
| Trends and research | The topic you enter |
We send only what a given request needs, and we use these providers through their APIs under terms that do not permit training on submitted data. We do not use your content to train any model of our own.
Automated replies are drafts by default. Nothing is sent to a customer unless you approve it, or you explicitly enable automatic sending above a confidence threshold you set. You can disable the bots at any time.
We do not carry out automated decision-making that produces legal or similarly significant effects concerning you.
For people in the UK, EU and other jurisdictions with equivalent law, the relevant legal bases are:
| Purpose | Legal basis |
|---|---|
| Providing the Service — publishing, scheduling, analytics, replies | Performance of a contract |
| Account creation, authentication, email confirmation, password reset | Performance of a contract |
| Billing, credits and fraud prevention | Performance of a contract; legal obligation |
| Security, rate limiting, abuse prevention, logging | Legitimate interests — keeping the Service available and secure |
| Service messages, such as an expiring social connection | Legitimate interests — you would expect to be told |
| Improving reliability and diagnosing faults | Legitimate interests — a working product |
| Meeting accounting and tax obligations | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you may object at any time (see section 10).
Our servers and database are located in the European Union (Finland). Several processors listed in section 7 operate elsewhere, including in the United States.
We operate from Bangladesh. Our staff administer the Service from Dhaka, which means personal data stored on our EU servers is accessed from Bangladesh. Bangladesh is not currently the subject of a European Commission adequacy decision.
Where personal data is transferred outside the UK or EEA — whether to a processor or to our own staff — we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable, together with the technical measures described in section 11. You can ask us for details of the safeguards applied to a particular transfer.
| Data | Retention |
|---|---|
| Account and profile | While your account is active |
| Content you create | While your account is active, or until you delete it |
| Connected account access tokens | Until you disconnect the account, or the token expires |
| Post analytics | While the account remains connected |
| Messages and comments | While the account remains connected |
| Email confirmation and password reset tokens | Up to 24 hours (confirmation) or 1 hour (reset); removed after 7 days |
| Server and error logs | Typically 30–90 days |
| Billing and transaction records | As required by accounting and tax law, generally 6 years |
On an account deletion request we remove your personal data and content within 30 days, except records we must retain for legal or accounting purposes, which are isolated and deleted when that obligation ends. Backups are overwritten on a rolling basis and any residual copies are removed within that cycle.
Available in the application:
By request to privacy@socialauto.site, actioned within 30 days:
We do not charge for these requests or treat you differently for making one. We may need to verify your identity first.
If you are in the UK or EEA you may complain to your supervisory authority — in the UK, the Information Commissioner's Office. If you are a California resident, you have the rights to know, delete, correct and opt out of sale or sharing; we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and the same contact address serves those requests.
If you interacted with a business that uses SocialAuto — for example by messaging their Page — that business is the controller of your data. Contact them directly; we will assist them in responding.
No system is perfectly secure and we cannot guarantee absolute security. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by law, without undue delay.
The Service is intended for businesses and is not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will delete it promptly.
We may update this policy as the Service changes. The date at the top shows when it last changed. For material changes we will give notice in the application, or by email, before they take effect. Continuing to use the Service after a change takes effect means you accept the updated policy.
Questions, requests or complaints about this policy or your data: privacy@socialauto.site.
We aim to acknowledge within 5 working days and to resolve within 30 days. If you are not satisfied with our response, you may complain to your data protection authority.