Legal
Privacy Notice
What personal data SocialHolmes holds about you as a customer, why, how long for, and what you can ask us to do about it.
Last updated August 28, 2026
This document is published in English only. The rest of the site reads in ten languages; these terms do not, because a translated clause and an English one can disagree, and only one of them can govern. The English text is the one that does.
1.In short#
We hold the account details you gave us, a record of what you paid and spent, and the operational logs needed to run an API. We do not sell any of it and we do not use it to advertise to you.
This notice is about you, our customer. It is not about the people whose public pages the API reads — for those, you are the controller and your own privacy notice applies. The data clause in the Terms says the same thing from the other side.
2.What we collect#
Account: your name, your email address, your company name if you give one, and a password stored only as a hash.
Billing: what you bought, when, how much, and the transaction reference our payment processor returns. We never see or store your card details.
Usage: the runs you make — which platform, which endpoint, when, how many results, what it cost — and the results of those runs until they are deleted. API key identifiers, and the IP address a request came from.
Technical: ordinary server logs, and a session cookie plus a language preference. No advertising or cross-site tracking cookies.
3.What we use it for#
To run the service and deliver your results. To bill you correctly and show you your ledger. To answer your support questions. To detect and stop abuse. To meet our legal and accounting obligations.
We do not use your data to train models, and we do not sell or rent it to anybody.
4.Our lawful basis#
Performing our contract with you, for everything needed to give you the service and bill you for it. Legal obligation, for accounting and tax records. Legitimate interests, for security, abuse prevention and keeping the service working — balanced against your rights, which is why the retention periods below are as short as they are.
5.Who else sees it#
Our payment processor, PayPal, which handles the payment and returns us a reference. Our hosting and infrastructure providers, which process data on our instructions under contract. Professional advisers and authorities, where we are legally required.
That is the whole list. We have no advertising partners and no data brokers.
6.How long we keep it#
Run results: deleted thirty days after the run completes. You can delete them sooner from the dashboard.
Run metadata — which endpoint, when, what it cost: kept for as long as the account is open, because it is your ledger.
Billing records: seven years, which is what accounting law requires.
Account details: until you close the account, then thirty days, then deleted except for what the billing retention above requires.
Server logs: ninety days.
7.How we protect it#
Everything travels over TLS. Passwords are hashed, never stored. API keys are stored as hashes and shown once, at creation. Access to production is limited to the people who need it and is logged.
If a breach affects your personal data we will tell you and the relevant supervisory authority within seventy-two hours of becoming aware of it.
8.What you can ask for#
A copy of your data, correction of anything wrong, deletion, a machine-readable export, restriction of processing, or an objection to processing based on legitimate interests. You may also withdraw consent where consent is what we relied on.
Write to team@socialholmes.com and we will answer within thirty days. If you are not satisfied you can complain to your national data protection authority; in Italy that is the Garante per la protezione dei dati personali.
9.Cookies#
Two, both necessary: a session cookie that keeps you signed in, and a cookie remembering which language you chose. Neither tracks you across sites, and there is no third-party analytics or advertising script on this site.
10.Where it goes#
Our infrastructure is in the European Union. Where a provider processes data outside it, that transfer is covered by the European Commission's standard contractual clauses.
11.Children#
The service is for businesses and developers and is not directed at children. We do not knowingly hold personal data about anyone under sixteen as a customer. If you believe we do, tell us and we will delete it.
12.Changes to this notice#
We may update this notice. Where a change materially affects you we will email the address on the account before it takes effect. The date at the top is always the date of the current version.
13.Who we are, and how to reach us#
SocialHolmes is operated by Pandev, and is the controller of the personal data described here.
Write to team@socialholmes.com for anything in this notice, including to exercise any of the rights above.