Privacy policy
Last updated · 4 August 2026
Social Zakio · Cairo, Egypt
Social Zakio manages Facebook and Instagram pages on behalf of agencies and their clients. This policy explains what we collect, why we hold it, and what you can ask us to do with it.
What we collect
Only what the product needs to run your pages.
- Account details you give us: name, work email, agency name, password hash, time zone.
- Meta platform data we read with your permission: page and account identifiers, posts, comments, direct messages, reactions, and page-level metrics.
- Product usage: which screens your team opens, which rules fire, and when replies are sent — used for the audit log and for support.
- Billing details, handled by our payment processor. We never see or store full card numbers.
What we do not collect
We do not buy data, we do not scrape profiles, and we do not build advertising profiles of the people who comment on your clients' pages.
How we use it
To show your comments and messages in one queue, to fire the auto-reply rules you write, to produce your analytics and reports, to keep an audit trail of who did what, and to answer your support requests. We do not use your content or your customers' messages to train models.
Meta platform data
Access to Facebook and Instagram data comes from the permissions you grant when you connect a page, and is used only to provide the features you enabled for that page. You can disconnect a page at any time, which revokes our access. We follow Meta's Platform Terms and Developer Policies, including their limits on retention and onward transfer.
Who we share it with
A short, fixed list of processors, each under contract and each used for one job.
- Cloud hosting and database providers that run the service.
- A payment processor for subscriptions and invoices.
- An error-monitoring and email provider for product notifications.
- Authorities, only where we are legally required, and we tell you unless the law forbids it.
Where it is stored
Data is held on servers in the European Union. Where a processor is outside the EU, the transfer is covered by standard contractual clauses.
How long we keep it
Comments, messages and rule history stay for as long as your workspace is open, then 30 days after you close it, after which they are deleted from live systems and roll out of backups within 90 days. Audit logs are held for 12 months. Invoices are held for seven years because tax law requires it.
Your rights
Wherever you are, you can ask us to show you the data we hold, correct it, export it, or delete it, and you can object to processing or withdraw a permission. Owners can export or delete a whole workspace from Settings without asking us.
Security
Traffic is encrypted in transit and data is encrypted at rest. Access inside our team is role-based and logged, two-factor authentication is available to every account and required for owners, and we notify you within 72 hours of confirming a breach that affects your data.
Changes to this policy
If we change something material, we email the workspace owner and show a notice in the product at least 14 days before it takes effect. The date at the top always reflects the current version.
Questions about your data
Write to privacy@socialzakio.com and we will answer within five working days. To delete a workspace and everything in it, ask from the owner account and we action it within 30 days.