GDPR
How Social9 meets the EU and UK General Data Protection Regulation, and how you exercise your rights.
Social9, Inc. ("Social9") is committed to the EU General Data Protection Regulation (GDPR), the UK GDPR and the UK Data Protection Act 2018, and the Swiss Federal Act on Data Protection. This page explains how they apply to Social9. Full detail of the data we collect is in our Privacy Policy.
1. Our Role: Controller and Processor
Social9 as controller
Social9 is the controller for data we need to run our own business: your account and sign-in details, billing records, support conversations, website analytics, security logs, and the profile details we receive when you connect your own social media account.
Social9 as processor
When a business uses Social9, the business is the controller of the content and personal data its team puts into Social9, such as posts, media, and details of people named or shown in them. Social9 processes that data only on the business's instructions, under our Data Processing Addendum. If you are a member of the public with a question about such content, please contact the business that published it; we will help them respond.
2. Legal Bases for Processing
| Purpose | Legal basis |
|---|---|
| Creating and running your account, scheduling and publishing your posts, providing support | Performance of a contract (Art. 6(1)(b)) |
| Connecting social media accounts and publishing to them | Performance of a contract, at your request; you can withdraw by disconnecting the account |
| Billing, tax and accounting records | Legal obligation (Art. 6(1)(c)) |
| Securing the service, preventing fraud and abuse | Legitimate interests (Art. 6(1)(f)) in keeping Social9 and its users safe |
| Improving the service using aggregated usage data | Legitimate interests in understanding how Social9 is used |
| Website analytics cookies | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Marketing emails | Consent, or legitimate interests for existing customers where the law allows; you can unsubscribe at any time |
3. Your Rights
Right to access
Get a copy of the personal data we hold about you.
Right to rectification
Have inaccurate or incomplete data corrected.
Right to erasure
Have your data deleted. See our Data Deletion Instructions for the fastest routes.
Right to restriction
Ask us to limit how we use your data while a concern is resolved.
Right to portability
Receive data you gave us in a machine-readable format, or have it sent to another provider.
Right to objection
Object to processing based on legitimate interests, and to direct marketing at any time.
Right to withdraw consent
Withdraw consent you gave, without affecting processing that already took place.
Right to complain
Lodge a complaint with your data protection supervisory authority.
How to exercise them
- Most rights can be used directly in the app: edit your profile, download your data, disconnect accounts or delete your account.
- For anything else, email [email protected] with "GDPR Request" in the subject.
- We reply within one month. If a request is complex we may extend this by up to two further months, and we will tell you why within the first month.
- We may ask you to confirm your identity before acting on a request. Exercising your rights is free.
4. International Data Transfers
Social9 is based in the United States, and some of our sub-processors process data in the United States. When personal data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we protect it with:
- The European Commission's Standard Contractual Clauses (2021/914)
- The UK International Data Transfer Addendum, for UK data
- The Standard Contractual Clauses as adapted for Swiss law, for Swiss data
- Supplementary measures, including encryption in transit and at rest and strict access control
Where a recipient is certified under the EU-U.S. Data Privacy Framework, we may rely on that certification instead.
5. How We Protect Personal Data
We apply privacy by design and by default: we collect only what the service needs, request the narrowest permissions from social media platforms, encrypt data in transit and at rest, and limit staff access. The controls are described in our Information Security Policy. We assess new features that involve higher-risk processing before launch.
6. Retention
We keep personal data only as long as needed for the purposes above. Retention periods for each type of data, including connected social media accounts, are listed in our Privacy Policy.
7. Automated Decision-Making
Social9 uses AI to suggest and generate content that you review before it is published. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
8. Personal Data Breaches
If a breach affects personal data for which we are controller, we notify the competent supervisory authority within 72 hours where required, and affected individuals where the risk to them is high. Business customers are notified as set out in our Data Processing Addendum.
9. Complaints
We would like the chance to resolve any concern first, so please contact us at [email protected]. You also have the right to complain to the data protection authority where you live or work. In the EU, the list of authorities is on the European Data Protection Board website; in the UK, it is the Information Commissioner's Office.
10. Contact
Social9, Inc., 201 Spear St, San Francisco, CA 94105, United States
Privacy and data protection: [email protected]