Legal
Privacy Policy
Last updated: 11 August 2026
RokData (“we”, “us”, “our”) provides a multi-tenant SaaS platform for social publishing, SEO audits, security scans, and related analytics (“Service”) at rokdata.co.uk. This Privacy Policy explains what personal data we collect, why we use it, and the choices you have.
1. Who we are
The data controller for account and platform data is the operator of RokData. For privacy questions or data requests, contact privacy@rokdata.co.uk.
If you use RokData for a business or agency client, you may process their data as an independent controller or processor under your own agreements. We process Service data on your instructions as a processor where applicable.
2. Data we collect
- Account data — name, email, password hash, organisation/workspace details, plan and billing metadata.
- Workspace content — brands, scheduled posts, media you upload, SEO properties, security findings, inbox items, automations, and similar content you enter into the Service.
- Connected network tokens — OAuth access/refresh tokens for networks you connect (for example Meta, LinkedIn, X, TikTok, Pinterest, YouTube, Google). Tokens are encrypted at rest where configured.
- Usage & technical data — login times, IP address, browser/user agent, audit logs, job/cron diagnostics, and error logs needed to operate and secure the Service.
- Payment data — if you subscribe via Stripe, payment details are handled by Stripe. We store limited billing references (for example customer/session identifiers and plan status), not full card numbers.
3. How we use data
- Provide, maintain, and improve the Service (including publishing, scanning, reporting, and automations you enable).
- Authenticate users, enforce access control, and protect against abuse.
- Communicate service notices (for example password reset, security alerts, billing).
- Comply with law and respond to lawful requests.
We do not sell your personal data.
4. Legal bases (UK GDPR)
Where UK GDPR applies, we typically rely on: contract (to provide the Service), legitimate interests (security, product improvement, fraud prevention), and consent where required (for example optional marketing or certain browser permissions). You may withdraw consent where processing is consent-based.
5. Connected platforms (Meta and others)
When you connect a third-party network, we request only the permissions needed for features you use (posting, insights, inbox, etc.). Data retrieved from those APIs is used to deliver those features. Their own policies also apply. You can disconnect accounts in the dashboard; we stop using those tokens for new API calls after disconnect.
6. Sharing
We share data with:
- Infrastructure providers hosting the Service and database.
- Payment processors (Stripe) for subscriptions.
- AI providers if you enable AI features (for example caption or reply assistance) — prompts may include content you submit for that purpose.
- Authorities when required by law.
Platform admins may access workspace data only as needed for support, abuse investigation, or platform operations.
7. Retention
We retain account and workspace data while your organisation is active. After account closure or deletion requests, we delete or anonymise personal data within a reasonable period unless we must retain it for legal, security, or accounting reasons. Backups may persist for a limited window before expiry.
8. Security
We use industry-standard measures appropriate to a shared-hosting SaaS product, including hashed passwords, encrypted OAuth tokens (when app_key is configured), HTTPS on production, session controls, and optional two-factor authentication. No method of transmission or storage is 100% secure.
9. Your rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Contact privacy@rokdata.co.uk. You may also complain to the UK Information Commissioner’s Office (ICO).
10. Data deletion
To delete your RokData account and associated personal data, email privacy@rokdata.co.uk from your registered address with subject “Data deletion request”, or use in-product account deletion if available. We will confirm and process the request. Content you published to third-party networks remains under those networks’ controls.
11. International transfers
If we or our processors store data outside the UK/EEA, we use appropriate safeguards (for example standard contractual clauses) where required.
12. Children
The Service is intended for business users aged 18+. We do not knowingly collect data from children.
13. Changes
We may update this policy. Material changes will be posted on this page with a revised “Last updated” date. Continued use after changes means you accept the updated policy.