Last updated: July 2026
This Privacy Policy explains how heropiks ("heropiks", "we", "us") collects, uses, discloses and protects information when a business uses our AI-powered social CRM and marketing-analytics platform (the "Service"). heropiks is a business-to-business (B2B) product: our customers are businesses that connect their own accounts (social, messaging, advertising and CRM) so that heropiks can provide analytics, a unified inbox and AI-assisted replies on their behalf.
For data belonging to our business customers and their end-users (for example, the leads, ad accounts, conversations and page/channel data a customer connects), the business customer is the data controller and heropiks acts as a data processor that processes such data only to provide the Service under the customer's instructions. For account registration and our own website, heropiks acts as the controller.
Name, email address and authentication identity (e.g. Google sign-in) of the users who administer a heropiks account.
When a customer authorizes a connection, we access only the data needed for the enabled features, which may include:
Access is granted by the customer through the relevant platform's official authorization mechanism (such as OAuth / "Login for Business", partner sharing, or webhooks). We never ask for or store a user's password to any third-party platform. Access tokens are stored in encrypted form and can be revoked by the customer at any time.
We do not sell personal data, and we do not use connected-platform data for advertising to unrelated third parties.
Data obtained from Meta, Google and TikTok is used only in accordance with each platform's developer terms and policies, including the Meta Platform Terms, Google API Services User Data Policy and the TikTok Developer Terms. Such data is used solely to provide features the customer has enabled and is not transferred except as described in this Policy.
To generate suggested or automatic replies, message content may be processed by large-language-model providers acting as sub-processors under confidentiality obligations. This data is used only to produce the reply and is not used to train third-party models where the provider offers such controls.
We share data only with service providers that help us run the Service — cloud/hosting infrastructure, database hosting and AI model providers — under appropriate agreements. We may disclose data where required by law.
We retain data for as long as the relevant account/connection is active or as needed to provide the Service, after which it is deleted or anonymized. Customers may request earlier deletion (see Section 11).
We apply reasonable technical and organizational measures, including encryption of access tokens, access controls and network isolation, to protect data against unauthorized access, loss or misuse.
heropiks operates from Türkiye and may process data on infrastructure located in other regions. Where data is transferred internationally, we take steps to ensure an appropriate level of protection.
Depending on your jurisdiction (including GDPR and Türkiye's KVKK), you may have rights to access, correct, delete or restrict processing of your personal data. To exercise these rights, or to request deletion of data connected to heropiks, see our Data Deletion instructions or email [email protected].
The Service is intended for businesses and is not directed to children under 16.
We may update this Policy; material changes will be posted on this page with a new "Last updated" date.
Privacy questions or data requests? Email [email protected].