SocialFuse SocialFuse
Features How it works Analytics FAQ Compare About
EN
English 简体中文 Español Français العربية Русский Ελληνικά Deutsch Türkçe
Start a workspace
Features How it works Analytics FAQ Compare About Contact Start a workspace

Privacy Policy

Last updated: 9 October 2026

SocialFuse LTD ("SocialFuse", "we", "us") operates the SocialFuse social media management platform. This policy explains what personal data we collect, why we hold it, who else can see it, and what you can do about it. We process personal data under the EU General Data Protection Regulation (GDPR), Cyprus Law 125(I)/2018, and the ePrivacy rules on cookies.

  1. Who is responsible for your data
  2. What we collect
  3. Why we process it, and on what legal basis
  4. Where your data is stored
  5. Who else processes your data
  6. Cookies
  7. International transfers
  8. How long we keep it
  9. Your rights
  10. Platform-specific terms
  11. Security incidents
  12. Children
  13. Changes to this policy
  14. Contact

1. Who is responsible for your data

Controller: SocialFuse LTD
Address: Spartis 4, Limassol, Cyprus
General privacy contact: privacy@socialfuse.net
Data protection contact: dpo@socialfuse.net

We are the controller for your account, billing and support data. For the content and audience data we pull from your connected social accounts on your instruction, we act as a processor on your behalf. Business customers can request our standard Data Processing Agreement (GDPR Art. 28) at dpo@socialfuse.net.

2. What we collect

2.1 Data you give us

  • Account: name, email address, hashed password, workspace and role settings.
  • Billing: plan, invoices and transaction references. Card details are entered directly with our payment processor; we never receive or store full card numbers.
  • Content you create: drafts, scheduled posts, uploaded media, comments left for teammates.
  • Support: messages you send us and our replies.

2.2 Data from the networks you connect

When you connect an account through Meta (Facebook, Instagram), Google, LinkedIn or TikTok, we receive only what the permissions you approve allow:

  • Profile: account ID, username, profile picture.
  • Content: your posts, and the comments and messages sent to your accounts, so the inbox can show them.
  • Metrics: reach, impressions, likes, shares and other engagement figures.
  • OAuth tokens: access and refresh tokens, encrypted at rest. We never receive your network password.

2.3 Data we generate

  • Technical logs: IP address, browser and device type, timestamps, and the actions taken in the app, kept for security and debugging.
  • Cookies: see section 6.

3. Why we process it, and on what legal basis

  • Providing the Service — publishing, scheduling, inbox, analytics, team access. Basis: performance of a contract (Art. 6(1)(b)).
  • Connecting a social account — reading and writing on your behalf. Basis: your consent, given in the network's own permission screen and withdrawable there or in our settings (Art. 6(1)(a)).
  • Security, abuse prevention and service improvement. Basis: our legitimate interests (Art. 6(1)(f)), balanced against your rights.
  • Invoicing, tax and accounting records. Basis: legal obligation (Art. 6(1)(c)).
  • Product emails you opt into. Basis: consent, withdrawable from any message.

We do not use your data for advertising, we do not sell it, and we make no decisions about you by automated means that produce legal or similarly significant effects.

4. Where your data is stored

  • Hosting: application servers, databases, media and backups run on managed infrastructure located in the European Union. Our hosting provider acts as a processor under a GDPR Art. 28 agreement and has no access to the content of your workspace. The provider is named in our Data Processing Agreement, available to business customers on request.
  • Encryption: traffic is protected with TLS 1.2 or higher; OAuth tokens and other secrets are encrypted at rest.
  • Access: limited to staff who need it for operations or support, under confidentiality obligations, with individual accounts and multi-factor authentication.
  • Backups: encrypted and stored within the EU.

5. Who else processes your data

We share data only with the processors below, each under a written agreement, and with the networks you have chosen to connect:

  • Cloud hosting provider (European Union) — hosting and backups, named in the Data Processing Agreement.
  • Stripe and PayPal — payment processing and fraud checks.
  • Meta, Google, LinkedIn, TikTok — we send them the posts, replies and requests you initiate, and read back the data their permissions allow. Their own privacy policies govern what they do with it.
  • Email delivery and support tooling — to send transactional messages and answer tickets.
  • Google Ireland Limited (Google Analytics) — visit statistics for the marketing site at socialfuse.net, only if you allow analytics cookies. Google may process this data in the United States under the EU–US Data Privacy Framework.

We may also disclose data where the law requires it, or to establish or defend legal claims. If we are ever party to a merger or acquisition, we will tell you before your data moves to a new controller.

A current list of processors is available on request from dpo@socialfuse.net.

6. Cookies

  • Strictly necessary: session and authentication cookies. These are required to keep you signed in and need no consent.
  • Analytics: the marketing site uses Google Analytics (_ga cookies, kept up to two years) only after you choose "Allow analytics" in the cookie banner. Nothing is loaded from Google before that. You can change your mind at any time from "Cookie settings" at the bottom of every page; declining deletes the analytics cookies and does not limit the Service.

The marketing site at socialfuse.net sets no advertising or cross-site tracking cookies.

7. International transfers

Your workspace data stays in the EU. Some processors — payment providers in particular — may process limited data outside the EEA. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, by an adequacy decision, or by the EU–US Data Privacy Framework where the recipient is certified. You can ask us for a copy of the safeguards that apply.

8. How long we keep it

  • Account and workspace content: for as long as the account is open. After you delete the account, active copies are removed within 30 days.
  • OAuth tokens: deleted immediately when you disconnect a network or close the account.
  • Backups: deleted data can persist in encrypted backups for up to 90 days and is then purged in the normal rotation.
  • Technical logs: 12 months; personal identifiers in logs are anonymised after 90 days.
  • Invoices and tax records: 7 years, as Cyprus tax law requires.

9. Your rights

Under the GDPR you can ask us to:

  • Access the personal data we hold about you, and get a copy.
  • Correct anything inaccurate or incomplete.
  • Delete your data, where no legal obligation requires us to keep it.
  • Restrict or object to processing based on our legitimate interests.
  • Port your data to another provider in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting processing already carried out.

Write to dpo@socialfuse.net. We answer within one month and will not charge you for it. If you are unhappy with our response, you can complain to the Office of the Commissioner for Personal Data Protection in Cyprus (dataprotection.gov.cy), or to the supervisory authority where you live.

10. Platform-specific terms

Our use of data from each network follows that network's developer terms as well as this policy.

  • Meta (Facebook, Instagram): we use Platform Data only to provide the features you use in SocialFuse — composing and publishing posts, reels and stories, handling comments and messages, and reporting. You can revoke access in SocialFuse settings or in your Facebook or Instagram app settings.
  • Google: our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, and we do not transfer it except to provide or improve features you use, to comply with law, or for security.
  • LinkedIn and TikTok: data is used solely to deliver the publishing, inbox and analytics features you have enabled, and is held to the same security standard as all other platform data.

11. Security incidents

If a breach occurs that poses a risk to your rights and freedoms, we notify the Cyprus supervisory authority within 72 hours of becoming aware of it, and we tell affected users without undue delay where the risk is high (GDPR Arts. 33–34).

12. Children

SocialFuse is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16. If you believe a minor has an account, write to dpo@socialfuse.net and we will remove it.

13. Changes to this policy

We update this page when our processing changes. Material changes are announced by email or in the app at least 14 days before they take effect, and the "last updated" date above always reflects the current version.

14. Contact

Privacy: privacy@socialfuse.net
Data protection: dpo@socialfuse.net
Post: SocialFuse LTD, Spartis 4, Limassol, Cyprus

Terms of Service Back to home
SocialFuse SocialFuse
Features How it works Compare About Terms Privacy Contact
© 2026 SocialFuse

Analytics cookies. With your permission we use Google Analytics to see which pages help people. No advertising cookies, and you can change your mind any time. Privacy