How Zack AI by Ignite Systems Ltd collects, uses, stores, and protects your data.
Last updated: 15 February 2026
1. Who We Are
Zack AI is a product of Ignite Systems Ltd (Company No. 5137882), registered with the Information Commissioner's Office (ICO Registration No. ZA360107).
We are a UK-based managed hosting, AI automation, and web services provider with over 20 years of experience. Zack AI is our AI-powered business assistant platform that helps businesses automate day-to-day tasks, generate content, manage websites, and grow their online presence.
Data Controller: Ignite Systems Ltd, 6 Mardale Avenue, Orford, Warrington, Cheshire, WA2 9HF, United Kingdom.
2. What Data We Collect
We collect and process the following categories of personal data depending on how you interact with Zack AI:
Account & Contact Information
Name, email address, phone number
Company name and business details
Correspondence and communication history
Service preferences and account settings
Service Usage Data
Task instructions and AI conversation logs
Files, documents, and media you upload or generate
Email drafts and communication templates
Website analytics and SEO report data
Social media content and scheduling preferences
Video, image, and audio generation requests and outputs
Technical Data
IP address and browser user agent
Email open tracking (1x1 pixel, logged by timestamp and IP)
Page visit timestamps and referring URLs
Device type, operating system, and screen resolution
Lead Capture & Contact Forms
Name and email address submitted through our website forms
Website URL (if you request a free SEO audit)
Service interest and message content from our contact form
Cookie consent preferences
3. Facebook & Instagram Data
If you connect your Facebook or Instagram account to Zack AI, we request access to the following data through Meta's official APIs:
Data We Access
Facebook Page tokens — to publish posts, read Page insights, and manage content on your behalf
Page information — Page name, category, and profile details
Instagram Business account data — media, follower counts, and engagement metrics
Publishing permissions — to schedule and publish social media posts when you approve them
How We Use Facebook/Instagram Data
Publishing social media posts that you have explicitly approved through the Admin UI
Retrieving Page and account analytics for reporting
Managing your social media calendar and content schedule
What We Do NOT Do
We never sell, share, or transfer your Facebook/Instagram data to third parties
We never use your data for advertising, profiling, or any purpose beyond providing the Zack AI service
We never post content without your explicit human approval
We never access your personal Facebook profile — only connected Business Pages
Token Storage
Facebook and Instagram OAuth tokens are stored server-side on our UK-based infrastructure. Tokens are never exposed to client-side code, browser storage, or third-party services. Access is restricted to the Zack AI service processes only.
4. How We Use Your Data
We use the data we collect to:
Provide and operate the Zack AI service, including all AI automation features
Execute tasks you assign (email drafting, content creation, SEO analysis, social media management, video generation, website development)
Generate reports, proposals, and business insights
Communicate with you about your account, tasks, and service updates
Monitor website uptime and security for sites we manage
Improve and maintain our service based on usage patterns
Comply with legal obligations
5. Legal Basis for Processing
We process your personal data under the following legal bases as defined by the UK GDPR:
Contractual necessity — processing required to deliver the service you've subscribed to (hosting, AI automation, content generation, SEO)
Consent — where you explicitly connect third-party accounts (Facebook, Instagram), opt in to marketing communications, or submit your details via our contact or lead capture forms
Legitimate interests — service improvement, security monitoring, fraud prevention, and analytics to understand how our website is used
Legal obligation — where required by UK law, regulation, or court order
6. Data Storage & Security
All data is stored on UK-based servers managed by Ignite Systems Ltd. We implement the following security measures:
HTTPS/TLS encryption for all data in transit
Server-side credential storage — no API keys or tokens on client devices
Access controls and authentication on all admin endpoints
Regular security updates, patching, and monitoring
Human-in-the-loop approval for all external actions (emails, social posts, communications)
Draft-only email system — emails are never sent automatically without human review
SQLite databases with WAL mode for data integrity
Regular automated backups with 30-day retention
Your data is never stored on your local device. All processing occurs on our managed UK infrastructure.
7. Data Retention
Account data — retained for the duration of your subscription, plus 30 days after cancellation
Task and conversation logs — retained for 12 months, then automatically purged
OAuth tokens (Facebook, Instagram) — retained until you disconnect the integration or delete your account
Email tracking data — retained for 6 months
Lead capture submissions — retained for 24 months or until you request deletion
Generated media (videos, images, audio) — retained for the duration of your subscription
Backups — retained for 30 days on a rolling basis
Cookie consent preferences — retained for 12 months
You can request early deletion of your data at any time (see Data Deletion below).
8. Third-Party Sharing
We do not sell your personal data to any third party. We share data only with the following service providers, strictly for the purpose of delivering the Zack AI service:
Anthropic (Claude AI) — task instructions are processed by Claude to generate responses. Anthropic's data processing is governed by their privacy policy
Meta Platforms (Facebook/Instagram) — only when you connect your accounts, to publish approved content and retrieve analytics
Email service providers — for sending emails you have approved via the Admin UI
Kie.ai — for AI video, image, and music generation when you request these services
ElevenLabs — for premium text-to-speech generation when you request voice-overs
Stannp — for physical postcard and greeting card printing and delivery when you request this service
Clerk — for authentication services on our hosting portal
Each third-party provider processes only the minimum data necessary to perform their function. We do not use any advertising, remarketing, or behavioural tracking services from third parties.
9. Your Rights (UK GDPR)
Under the UK GDPR and Data Protection Act 2018, you have the following rights:
Right of access — request a copy of the personal data we hold about you
Right to rectification — request correction of inaccurate or incomplete data
Right to erasure — request deletion of your data ("right to be forgotten")
Right to restrict processing — request that we limit how we use your data
Right to data portability — receive your data in a structured, machine-readable format
Right to object — object to processing based on legitimate interests
Right to withdraw consent — withdraw consent for Facebook/Instagram integrations or marketing at any time
Rights related to automated decision-making — the right not to be subject to decisions based solely on automated processing. Zack AI always requires human approval for external actions
To exercise any of these rights, contact us using the details in Section 16 below. We will acknowledge your request within 48 hours and respond fully within 30 days.
10. Data Deletion
You can request deletion of your data at any time by:
Emailing zack@zackbot.ai with the subject "Data Deletion Request"
Or contact us directly — we will delete all stored tokens, Page data, and associated analytics within 48 hours
You can also use our data deletion callback endpoint. When you remove Zack AI from your Facebook settings, we automatically receive a deletion request and process it within 48 hours.
Upon receiving a deletion request, we will delete: all OAuth tokens, Page access tokens, stored Page data, analytics, content drafts, and any generated media associated with your account.
11. Cookies & Tracking
The Zack AI website uses minimal cookies and tracking technologies. We believe in transparency about what data we collect through your browser.
Essential cookies — session management and authentication for the Admin UI. These are strictly necessary for the site to function and cannot be disabled
Preference cookies — storing your cookie consent choice, theme preferences, and dismissed notifications (via localStorage)
Email tracking pixels — 1x1 transparent images in approved emails to confirm delivery and measure open rates
We do not use advertising cookies, social media tracking cookies, Google Analytics, or any third-party analytics or remarketing cookies.
12. Cookie Policy
This section details every cookie and local storage item used on the Zack AI website:
Strictly Necessary
Session cookie — authenticates your Admin UI session. Expires when you close your browser or after 24 hours of inactivity
CSRF token — prevents cross-site request forgery attacks on form submissions. Expires per session
Functional / Preference
cookie_consent (localStorage) — records whether you have accepted or declined non-essential cookies. Retained for 12 months
exit_popup_dismissed (localStorage) — records if you have dismissed the consultation offer popup. Retained for 7 days
lead_captured (localStorage) — records if you have already submitted the lead capture form, to avoid showing it again. Retained until cleared
zack_scroll_cta_dismissed (localStorage) — records if you have dismissed the floating call-to-action button. Retained for 24 hours
How to Manage Cookies
When you first visit our website, you will see a cookie consent banner. You can:
Accept All — enables all cookies and localStorage items listed above
Decline — only strictly necessary cookies will be used; functional/preference items will not be stored
You can also manage cookies through your browser settings. Most browsers allow you to block or delete cookies. Please note that blocking essential cookies may prevent the Admin UI from functioning correctly.
To clear your preferences and see the consent banner again, clear your browser's localStorage for zackbot.ai.
13. Children's Privacy
Zack AI is a business tool designed for use by businesses and professionals. It is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it within 48 hours.
14. International Data Transfers
Your data is primarily stored and processed on UK-based servers. However, some of our third-party service providers (Anthropic, Meta, Kie.ai, ElevenLabs) may process data outside the UK. Where this occurs:
We ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or UK adequacy decisions
Only the minimum data necessary is transferred
We have assessed the data protection practices of each provider
If you have questions about where your data is processed, contact us using the details below.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
Update the "Last updated" date at the top of this page
Notify you via email or through the Zack AI Admin UI where appropriate
Where changes are significant, provide at least 14 days' notice before they take effect
16. Contact Us
If you have any questions about this Privacy Policy, your data, or wish to exercise your rights, contact us: