Last updated: 1 July 2026 · SocialCore, socialcore.ae
SocialCore ("SocialCore", "we", "us") provides an autonomous, managed social-media content generation and publishing service. This Policy explains how we handle personal data for (a) visitors to socialcore.ae, (b) prospects and customers, and (c) end-users whose data is contained in content we manage on behalf of a customer.
Roles. For our website and our own customer relationships, we act as a controller. When we process personal data on behalf of a customer (e.g. connecting their social accounts and publishing their content), we act as a processor, and the customer is the controller. A separate Data Processing Agreement (DPA) governs that relationship.
We rely on vetted providers to deliver the service, including: DigitalOcean (hosting, Frankfurt/EEA), Cloudflare (edge/security), Infisical (secrets vault), Resend (transactional email), and large-language-model providers accessed through a controlled gateway. A current list is available on request and forms part of the DPA. We impose contractual data-protection obligations on each sub-processor.
Our primary infrastructure is in Frankfurt (EEA). Where data is transferred across borders, we rely on appropriate safeguards — Standard Contractual Clauses (EU/UK) and, for Türkiye, KVKK-compliant transfer mechanisms and notifications. UAE customers are served consistent with the UAE PDPL and, where applicable, DIFC/ADGM data-protection regulations.
We keep personal data only as long as necessary for the purposes above or as required by law. On termination, customer data and credentials are deleted or returned in line with the DPA; we then securely erase remaining copies.
Security is foundational. Secrets and access tokens are held in an encrypted vault (never in plaintext), each customer is isolated at the data layer, access is least-privilege and audited, and our origin is not directly exposed to the public internet. No system is perfectly secure, but we apply industry-standard technical and organisational measures.
Subject to applicable law (GDPR/UK GDPR, KVKK, UAE PDPL), you may request access, rectification, erasure, restriction, portability, or object to processing, and withdraw consent. Where we process data as a processor for a customer, we will direct such requests to that customer (the controller). Contact privacy@socialcore.ae or our Data Protection contact dpo@socialcore.ae. You may also lodge a complaint with your local supervisory authority (e.g. the UK ICO, the Turkish KVKK Authority, or the relevant UAE regulator).
We use essential and, with consent, analytics cookies. See our Cookie Policy and manage your choice via the cookie banner.
We may update this Policy; material changes will be posted here with a new date. Questions: privacy@socialcore.ae.