Privacy Policy

Effective date: October 15, 2025

Last updated: November 12, 2025

1. Introduction

Content24 ("we," "our," or "us") is an AI-powered content generation platform operated by CONTENT24 TECHNOLOGIES LIMITED. We are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, store, and protect your personal information when you use our AI-powered content generation platform (the "Service").

This Privacy Policy is designed to comply with applicable data protection requirements, including the General Data Protection Regulation (GDPR) (EU) 2016/679, the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), and other applicable data protection laws.

By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy.

2. Data Controller

Company Name: CONTENT24 TECHNOLOGIES LIMITED.

Operating As: Content24.

Registered In: 34 Falirou, 1st Floor, Office 103, 2066 Strovolos, Nicosia, Cyprus.

Contact Email: legal@content24.ai.

Data Protection Contact: privacy@content24.ai.

Supervisory Authority: Office of the Commissioner for Personal Data Protection (Cyprus).

For any questions about this Privacy Policy or to exercise your data protection rights, please contact us at the email address above.

3. Information We Collect

3.1 Personal Data You Provide

When you register for and use our Service, we collect personal data that may include account information, payment information, and content or usage data.

Account Information

  • Full name.
  • Email address.
  • Password (stored securely using encryption).
  • Country.
  • Optional details such as phone number, company name, website, address, postal code, and profile avatar.

Payment Information

  • Billing details.
  • Payment method information (processed via secure third-party payment processors).
  • Subscription and transaction information.

Content and Usage Data

  • AI-generated content (text, images, code).
  • Chat conversations and messages.
  • User preferences and settings.
  • API keys (encrypted).
  • Integration credentials (encrypted).

3.2 Automatically Collected Data

  • IP address.
  • Browser type and version.
  • Device and operating system.
  • Session and analytics data.
  • Cookies and similar technologies.
  • Login timestamps and activity logs.

3.3 Information from Third-Party Logins

If you sign in through third-party services (Google, GitHub, and similar providers), we may receive profile information, email address, profile picture, and authentication tokens.

4. How We Use Your Information

We process your personal data for the following purposes and legal bases.

  • Service Provision (Contractual Necessity): to provide, maintain, and improve the Service. Legal Basis: Article 6(1)(b) GDPR.
  • AI Content Generation (Contractual Necessity): to process your requests and generate content using AI models. Legal Basis: Article 6(1)(b) GDPR. We do not train AI models on your data.
  • Payment Processing (Contractual Necessity and Legal Obligation): to process payments and manage subscriptions. Legal Basis: Articles 6(1)(b) and 6(1)(c) GDPR.
  • Communication (Legitimate Interest): to send service-related notifications or support responses. Legal Basis: Article 6(1)(f) GDPR.
  • Security and Fraud Prevention (Legitimate Interest and Legal Obligation): to protect the Service and prevent misuse or fraud. Legal Basis: Articles 6(1)(f) and 6(1)(c) GDPR.
  • Legal Compliance (Legal Obligation): to comply with tax, accounting, and legal requirements. Legal Basis: Article 6(1)(c) GDPR.
  • Service Improvement (Legitimate Interest): to analyze usage and improve Service performance. Legal Basis: Article 6(1)(f) GDPR.

5. AI Services and Data Processing

5.1 AI Model Providers

We use the following providers for AI content generation.

  • OpenAI (GPT, DALL-E).
  • Anthropic (Claude).
  • AWS Bedrock (Stable Diffusion).
  • DeepSeek.
  • X.AI (Grok).
  • Other integrated image or text generation APIs.

5.2 How AI Services Process Data

  • Input processing: prompts are sent securely to AI model APIs.
  • Retention: OpenAI retains API inputs for 30 days for abuse monitoring; Anthropic and others retain data per their respective privacy terms.
  • Training: no personal data is used for AI training.
  • Storage: generated content is stored in your account and can be deleted at any time.

5.3 AI Act Compliance

  • We indicate when content is AI-generated.
  • No automated decision-making affecting users.
  • We use providers with bias mitigation and moderation controls.
  • We monitor compliance with EU AI Act requirements.

6. Data Sharing and Third-Party Services

6.1 Service Providers

We share data only with trusted processors under GDPR-compliant contracts.

  • AI Providers: OpenAI, Anthropic, AWS Bedrock, DeepSeek, and X.AI.
  • Payment Processors: Stripe, PayPal, and others.
  • Infrastructure Providers: Hetzner, AWS (hosting and storage), Cloudflare (CDN and security).
  • Other Services: email, analytics, and CRM tools.

6.2 Data Processing Agreements

We maintain Data Processing Agreements (DPAs) with all service providers to ensure data protection, limited processing purposes, and compliance with GDPR.

6.3 Legal Disclosures

We may disclose personal data to legal or governmental authorities if required by law or where necessary to protect our rights or users' safety.

7. International Data Transfers

Your data may be transferred to countries outside the EEA. We ensure compliance through recognized safeguards.

  • EU-US Data Privacy Framework (DPF) for certified U.S. companies.
  • Standard Contractual Clauses (SCCs) for transfers to countries without adequacy decisions.
  • Transfer Impact Assessments (TIAs) to ensure equivalent protection.
  • Additional safeguards including encryption in transit and at rest, access controls, and regular audits.

Data storage and AI processing locations depend on the selected provider and may include the EU or U.S. regions.

8. Data Security

We apply technical and organizational measures to protect your data.

  • Encryption: AES-256 for data at rest and TLS/SSL for data in transit.
  • Passwords: hashed with bcrypt.
  • Cookies: encrypted and secure.
  • Access controls: role-based controls and MFA for administrators.
  • Infrastructure security: firewalls, regular patching, and monitoring.
  • Incident response: documented procedures for breach handling.

In case of a data breach, we will notify the relevant authority within 72 hours and inform affected users without undue delay, as required by GDPR Articles 33 and 34.

9. Data Retention

We retain data only for as long as required for service delivery, legal compliance, and security operations.

  • Account Data: until account deletion.
  • Generated Content: until user deletion.
  • Chat History: until user deletion.
  • Payment Records: 7 years (legal requirement).
  • Activity Logs: 12 months.
  • Security Logs: 24 months.
  • Backups: 30 days maximum.
  • Marketing Data: until unsubscribe or withdrawal.

After these periods, data is securely deleted or anonymized. Backups are automatically purged after the retention window.

10. Your Rights Under GDPR

You have the following rights under GDPR.

  • Access: request copies of your personal data.
  • Rectification: correct inaccurate data.
  • Erasure: request deletion (right to be forgotten).
  • Restriction: limit processing under certain conditions.
  • Portability: receive your data in a machine-readable format.
  • Objection: object to processing for legitimate interests or marketing.
  • Withdraw Consent: withdraw consent at any time.
  • Complain: lodge a complaint with a supervisory authority.

To exercise any right, email privacy@content24.ai. We will respond within 30 days.

11. Cookies and Tracking

We use cookies for the following purposes.

  • Service functionality (essential cookies).
  • Preferences (functional cookies).
  • Analytics (where enabled).

You can manage cookies in your browser settings. Essential cookies are required for service operation.

12. Children's Privacy

Our Service is not directed to individuals under 18 years of age. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us so we can remove it.

13. Changes to This Policy

We may update this Privacy Policy periodically. Updates will be published on this page, and material changes will be notified by email or in-app message. Continued use of the Service after updates constitutes acceptance.

14. Contact Information

For all privacy-related inquiries:

CONTENT24 TECHNOLOGIES LIMITED, operating as Content24.

Address: 34 Falirou, 1st Floor, Office 103, 2066 Strovolos, Nicosia, Cyprus.

Email: privacy@content24.ai.

Support: support@content24.ai.

Supervisory Authority (Cyprus): Office of the Commissioner for Personal Data Protection.

Supervisory Authority Website: European Data Protection Board Members.

15. Consent and Acceptance

By using our Service, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, please discontinue use of the Service.

Newsletter

Stay ahead with Content24

Product updates, AI marketing tips, and launch news.

By subscribing, you agree to hear from Content24. See our Privacy Policy.