Data Protection & Trust

Effective date: October 15, 2025

Last updated: November 12, 2025

ISO 9001

ISO 9001

ISO 27001

ISO 27001

DSGVO

DSGVO

EU AI ACT

EU AI ACT

1. Our Commitment

Content24 is operated by CONTENT24 TECHNOLOGIES LIMITED, a company registered in Cyprus. We design and maintain our platform in accordance with privacy-by-design and security-by-default principles.

We are aligned with international privacy and data protection standards, including the General Data Protection Regulation (GDPR) (EU) 2016/679, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), Cyprus data protection law, and ISO/IEC 27001 and ISO/IEC 9001 certified management systems.

Our ISO certifications demonstrate our commitment to implementing and maintaining strict information security and quality management processes.

2. ISO Certification

We maintain active certification for ISO/IEC 27001 (Information Security Management) and ISO/IEC 9001 (Quality Management).

These certifications cover our data handling, infrastructure management, and operational processes.

They confirm that Content24 has implemented systematic controls to protect data confidentiality, integrity, and availability, and to continually improve internal processes.

3. Data Protection Overview

Data Controller

CONTENT24 TECHNOLOGIES LIMITED, operating as Content24.

Address: 34 Falirou, 1st Floor, Office 103, 2066 Strovolos, Nicosia, Cyprus.

Email: privacy@content24.ai.

Data Storage

  • Primary hosting: Hetzner and Amazon Web Services (AWS) in EU regions.
  • File and content storage: Hetzner Cloud, AWS S3, and Cloudflare R2.
  • All data encrypted in transit (TLS 1.2+) and at rest (AES-256).

Data Processing

We only collect and process personal data necessary to provide our services. Generated content and user inputs are never used to train AI models.

We maintain Data Processing Agreements (DPAs) with all subprocessors.

  • AWS
  • OpenAI
  • Anthropic
  • Cloudflare
  • Stripe and PayPal

4. Security Measures

Infrastructure Security

  • Hosted on secure cloud environments in EU regions.
  • Network isolation, firewall rules, and intrusion detection.
  • Continuous monitoring and vulnerability management.

Data Security

  • AES-256 encryption at rest.
  • TLS/SSL encryption in transit.
  • Hashed passwords using bcrypt.
  • Encrypted API keys and tokens.

Application Security

  • Role-based access control (RBAC).
  • Multi-factor authentication for admin access.
  • Secure session handling and CSRF protection.
  • Regular dependency and package updates.

Operational Security

  • Encrypted daily backups retained for 30 days.
  • Access logging and audit trails.
  • Defined incident response plan and breach notification policy.
  • Annual third-party penetration testing.

5. GDPR and AI Act Compliance

GDPR Compliance

  • Clear consent and cookie management.
  • User rights implemented (access, erasure, rectification, portability).
  • Right to be forgotten via account deletion.
  • Data retention and deletion policies.
  • Subprocessor transparency and DPAs.

AI Act Compliance

  • Transparency in AI-generated content.
  • No automated decision-making that affects user rights.
  • Bias and risk mitigation practices.
  • Human oversight maintained in critical operations.

6. Data Breach and Incident Response

In the event of a data breach that may affect users' personal data, we notify the Cyprus Data Protection Authority within 72 hours, inform affected users without undue delay, and implement technical and procedural remediation steps immediately.

Our team maintains a documented incident response procedure reviewed quarterly.

7. International Data Transfers

When data is transferred outside the European Economic Area (EEA), we ensure compliance through Standard Contractual Clauses (SCCs) approved by the European Commission, the EU-US Data Privacy Framework (DPF) for certified providers, and Transfer Impact Assessments (TIAs) where applicable.

All data transfers are encrypted and monitored to maintain compliance and security.

8. User Rights

Under GDPR, users have the right to:

  • Access their data.
  • Request correction or deletion.
  • Request data portability.
  • Restrict or object to processing.
  • Withdraw consent at any time.

Requests can be submitted to privacy@content24.ai.

9. Review and Auditing

Our security and compliance documentation is reviewed at least annually or whenever major updates occur. Regular audits are conducted to verify ongoing adherence to ISO, GDPR, and AI Act standards.

10. Contact

CONTENT24 TECHNOLOGIES LIMITED, operating as Content24.

Address: 34 Falirou, 1st Floor, Office 103, 2066 Strovolos, Nicosia, Cyprus.

Email: privacy@content24.ai.

Support: support@content24.ai.

Newsletter

Stay ahead with Content24

Product updates, AI marketing tips, and launch news.

By subscribing, you agree to hear from Content24. See our Privacy Policy.