Compliance and GDPR Statement
Effective date: 15 October 2025
Last updated: 12 November 2025
Entity Responsible
CONTENT24 TECHNOLOGIES LIMITED (operating as Content24).
Registered in: 34 Falirou, 1st Floor, Office 103, 2066 Strovolos, Nicosia, Cyprus.
Contact: privacy@content24.ai.
Introduction
Content24, operated by CONTENT24 TECHNOLOGIES LIMITED, is committed to maintaining full compliance with the General Data Protection Regulation (GDPR) (EU 2016/679), the EU AI Act, and other applicable data protection and privacy laws.
We apply the principles of privacy-by-design, data minimization, and security-by-default across all systems and processes.
Scope of Compliance
This statement applies to all data collected and processed through the Content24 platform, including user registration, subscriptions, payments, generated content, and API interactions.
It covers both end users and business clients using Content24 for AI-powered content generation.
Legal Basis for Processing
We process personal data under the following lawful bases:
- Contractual necessity for providing access to the platform and services.
- Legal obligation for compliance with tax, accounting, and consumer protection laws.
- Legitimate interest in maintaining service quality, security, and customer support.
- User consent for marketing communications and optional analytics.
Hosting and Infrastructure
Our primary infrastructure is hosted on Hetzner Cloud's ISO 27001-certified data centers located in Germany, providing secure and compliant VPS environments.
For optimization, redundancy, and CDN distribution, we utilize Amazon Web Services (AWS) for storage and AI integrations, and Cloudflare for DDoS protection, CDN performance, and R2 data storage.
All systems are configured to ensure that data remains within GDPR-compliant jurisdictions (EU/EEA).
Security and Encryption Controls
We employ industry-standard security and encryption protocols, including:
- Data encryption: AES-256 at rest and TLS 1.2+ in transit.
- Access management: role-based access control (RBAC) and multi-factor authentication (MFA) for administrators.
- Network protection: Cloudflare WAF, firewall policies, and DDoS mitigation.
- Secure sessions: HTTP-only, same-site cookies and encrypted session tokens.
- Regular audits: daily dependency scans, composer audit checks, and quarterly penetration tests.
- Monitoring: intrusion detection, logging, and automated security alerts.
Vendor and Subprocessor Management
We only engage subprocessors and vendors that meet GDPR and ISO 27001/9001 standards. Each subprocessor is bound by a Data Processing Agreement (DPA) outlining confidentiality, purpose limitation, and security obligations.
Our key subprocessors include Hetzner Cloud GmbH (VPS and primary hosting in Germany), Amazon Web Services (AWS) (cloud and AI model integrations), Cloudflare Inc. (CDN, DNS, and network security), Stripe, Klarna, and PayPal (payment processing, including credit card and bank transfer), and OpenAI / Anthropic / AWS Bedrock (AI content generation, including Zero Data Retention where applicable).
Data Transfers Outside the EEA
Where data is transferred outside the EEA, we implement safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission, EU-US Data Privacy Framework certification for eligible U.S. vendors, and Transfer Impact Assessments (TIAs) to evaluate and mitigate risks.
Technical safeguards include encryption, pseudonymization, and access restriction.
Data Processing and Retention
We retain personal and usage data only as long as necessary to provide the service or comply with legal obligations.
Retention schedules include account data until account deletion or inactivity beyond 24 months, payment and transaction data for 7 years, logs and security data for 12 to 24 months depending on purpose, and AI-generated content until deleted by the user.
All data deletion requests are processed within 30 days. Backups containing personal data are purged after a 30-day retention cycle.
User Rights Under GDPR
Users have the following rights under GDPR:
- Right to access personal data.
- Right to rectification of inaccurate information.
- Right to erasure (right to be forgotten).
- Right to restrict or object to processing.
- Right to data portability.
- Right to withdraw consent at any time.
Requests can be submitted to privacy@content24.ai and are handled within 30 days with identity verification for security.
AI Model Processing and Data Protection
When users generate content using AI models, inputs and outputs are processed securely through API connections with the selected provider.
- User data is not used to train AI models.
- Zero Data Retention (ZDR) modes are applied where available (for example, OpenAI Enterprise).
- Inputs are used solely to produce the requested output.
- No automated decision-making occurs that significantly affects users.
- AI providers' data handling practices are reviewed regularly for compliance.
Compliance Certifications
CONTENT24 TECHNOLOGIES LIMITED and its infrastructure providers maintain and comply with certifications and standards including ISO/IEC 27001 (Information Security Management Systems), ISO/IEC 9001 (Quality Management Systems), GDPR compliance frameworks, Hetzner Cloud DPA commitments, and AWS and Cloudflare security and compliance programs.
Accountability and Oversight
We maintain internal documentation to demonstrate compliance with GDPR Articles 5(2) and 30, including Records of Processing Activities (ROPA), Transfer Impact Assessments, and vendor audit reports.
A dedicated Data Protection Officer (DPO) oversees compliance and handles incident management, risk assessments, and data breach procedures.
Incident Response and Breach Notification
In the event of a personal data breach, the supervisory authority will be notified within 72 hours (GDPR Article 33), affected users will be notified without undue delay (GDPR Article 34), and incident reports will include breach details, potential impacts, and remediation actions.
User Transparency and Communication
We communicate transparently about data handling, AI processing, and security updates.
Changes to this statement are reflected on our website and, for significant updates, notified via email. Users are encouraged to review this statement periodically.
Supervisory Authority Contact
If you are located in the EU or EEA, you may contact your local data protection authority or the Office of the Commissioner for Personal Data Protection (Cyprus) regarding unresolved complaints.
Contact Information
For privacy or security matters:
Privacy Contact: privacy@content24.ai.
Security Contact: security@content24.ai.
Support Contact: support@content24.ai.
Company: CONTENT24 TECHNOLOGIES LIMITED, 34 Falirou, 1st Floor, Office 103, 2066 Strovolos, Nicosia, Cyprus.
Final Statement
Content24 operates with a strong commitment to privacy, data protection, and ethical AI usage.
Our infrastructure, vendors, and internal controls align with GDPR, ISO standards, and responsible AI governance principles. We continuously review and enhance our compliance to maintain user trust and transparency.