Privacy Policy
Last updated: 26 June 2025
Thank you for choosing Fiko – an omnichannel CRM and automation platform provided by Fiko AI Labs Ltd ("Fiko", "we", "our" or "us"). Protecting your personal information and ensuring you remain in control of your data are core principles of our service.
This Privacy Policy explains how we collect, use, disclose and secure the information we obtain when you:
- connect a Facebook Page or Instagram Professional Account to Fiko;
- interact with our websites, dashboards, APIs or mobile apps (collectively, the "Services");
- communicate with us in any other way.
By accessing or using the Services you acknowledge that you have read and understood this Policy.
1. Who We Are (Data Controller)
Legal entity | Fiko AI Labs Ltd – a private limited company incorporated in England & Wales (Company No. ___) |
Registered address | 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom |
Contact email | info@fiko.net |
For the purposes of UK GDPR and EU GDPR we are the Data Controller for personal information described in this Policy.
2. Information We Collect
Category | Examples | Source |
---|---|---|
Account & Profile | Name, email, profile picture, locale, Facebook User ID or Instagram User ID | Provided by you / Meta Platforms via OAuth |
Page / IG Business Data | Page ID & name; Instagram Business Account ID & username; roles & permissions | Facebook & Instagram Graph APIs |
Conversation Content | Messages, attachments, reactions, timestamps, sender ID | Messenger API, Instagram Graph API |
Technical | IP address, device/browser type, cookies, access tokens | Your device/browser |
Billing & Usage | Subscription tier, invoices, payment confirmations (last 4 digits only) | Payment processor (Stripe) |
Sensitive Data: We do not deliberately collect sensitive personal data (e.g., health, ethnic origin, religious beliefs). If your messages contain such information, you are responsible for ensuring you have lawful grounds to process it.
3. How We Use Your Information
- Provide and maintain the Services – e.g. retrieve messages, send automated replies, display dashboards and analytics.
- Improve and develop new features – aggregate, anonymise or pseudonymise logs to train our AI models and enhance user experience.
- Security & fraud prevention – verify accounts, detect abuse, enforce our terms.
- Customer support – respond to enquiries and troubleshoot issues.
- Marketing (with consent) – send product updates; you may opt out at any time.
- Legal compliance – satisfy legal obligations, e.g. accounting records.
4. Legal Bases (UK / EU GDPR)
Basis | Typical scenarios |
---|---|
Performance of a contract | Operating the Services you have requested. |
Legitimate interests | Securing the platform, preventing fraud, improving features (we balance these interests against your rights). |
Consent | Optional marketing emails, cookies requiring consent. |
Legal obligation | Tax or regulatory filings. |
5. How We Share or Disclose Data
- Service providers – hosting (AWS EU-London), payment processing (Stripe), email (Postmark); bound by confidentiality agreements.
- Integrated platforms – Meta Platforms, when we process or write data back to Messenger / Instagram on your behalf.
- Legal authorities – only if required to comply with a legitimate court order or applicable law.
- Business transfers – if we are involved in a merger, acquisition or asset sale, subject to equivalent safeguards.
We never sell personal data to third parties.
6. International Transfers
Where data is transferred outside the UK or European Economic Area we rely on a valid transfer mechanism such as adequacy regulations or Standard Contractual Clauses approved by the European Commission/ICO.
7. Cookies & Tracking Technologies
- Maintain session authentication;
- Remember interface preferences;
- Compile anonymised analytics.
You can control cookies via your browser settings; however, blocking essential cookies may impair service functionality.
8. Data Retention
Data type | Typical retention period |
---|---|
Message content & metadata | 24 months after termination of the Page/IG connection or on request, whichever is earlier. |
Account & billing records | 6 years (UK statute of limitations for accounting). |
Logs (pseudonymised) | Up to 12 months for security & performance analysis. |
9. Your Rights
Subject to jurisdiction you may have the right to:
- Access a copy of your data;
- Correct inaccurate data;
- Delete or restrict processing;
- Object to processing based on legitimate interests;
- Data portability (structured, machine-readable format);
- Withdraw consent at any time (without affecting prior processing);
- Complain to the ICO or your local supervisory authority.
Exercising your rights: Email info@fiko.net or use the in-app "Request my data" option.
10. Security Measures
- TLS 1.3 encryption in transit; AES-256 at rest.
- OAuth 2.0 short-lived access tokens exchanged for long-lived page tokens stored encrypted.
- Role-based access control; least-privilege principle for employees.
- Annual penetration testing and continuous vulnerability scanning.
No system is 100% secure. If you believe your account or data has been compromised, please contact us immediately.
11. Children's Privacy
Fiko is intended for business users aged 18 years or older. We do not knowingly collect information from children. If we learn that we have inadvertently processed data from a child, we will delete it promptly.
12. Changes to This Policy
We may update this Policy periodically. Significant changes will be notified via email or in-app banner. Continued use of the Services after an update constitutes acceptance of the revised Policy.
13. Contact Us
Fiko AI Labs Ltd
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK
Tel: +447575890006
14. Data Deletion Instructions (Facebook Requirement)
You can permanently delete your profile, all stored data and the Facebook/Instagram permissions we hold for you inside the Fiko dashboard:
- Sign in at https://app.fiko.net and go to My Profile → Delete Account (bottom of the page).
- Click Delete Account and confirm. Your access tokens are revoked instantly and your workspace, conversations and related personal data are queued for erasure within 24 hours.
- A confirmation email will be sent to the address on file.
Alternative method: remove the "Fiko" app from your Facebook settings. Our system receives a de‑authorisation callback and will schedule deletion with the same 24‑hour SLA.
If you cannot access your dashboard, email info@fiko.net with subject "Data Deletion Request – <Page or IG username>" and we will erase your data within 30 days and confirm by email.
Thank you for trusting Fiko with your data. We are committed to safeguarding your privacy while empowering your customer conversations.