Privacy Policy
ContentPeter
Effective date: 8 August 2026 Last updated: 8 August 2026
1. Controller
Peter Balog e.v., 5600 Békéscsaba, Szőlő u. 93/3., Hungary. EU VAT ID HU67571659.
Privacy contact: [email protected]
We are the data controller for personal data described in sections 3 and 4. Where we process personal data contained in a customer's workspace, we act as processor on that customer's instructions. See section 6.
We have not appointed a Data Protection Officer, as we are not required to. Privacy enquiries go to the address above.
2. Scope
This policy covers contentpeter.com, the ContentPeter application at app.contentpeter.com, and our related email and support channels. It does not cover third-party sites we link to, or the social platforms and content management systems you connect to the application, which are governed by their own policies.
3. Data we collect about you
3.1 Account and identity data. Name, work email, password (stored hashed, we never see it in plaintext), display name, profile photo, job title, organisation name, role, timezone and interface preferences. Source: you.
3.2 Billing data. We do not collect, see or store your card details. Payments are processed by Paddle.com Market Ltd, which acts as Merchant of Record and is an independent controller for the payment transaction. We receive from Paddle only: a customer and subscription identifier, billing name, billing country, VAT ID where supplied, subscription status, plan and seat quantity, invoice amounts and payment outcomes. Paddle's handling of your data is governed by its privacy policy at https://www.paddle.com/legal/privacy.
3.3 Customer Content. Everything you put into your workspace: brand assets and colours, product and audience positioning, voice settings, monitored source lists, ideas, drafts, edits, images, charts, schedules and connected-channel configuration.
3.4 Usage and technical data. IP address, browser and device type, pages and features used, timestamps, referring URL, error and performance logs, and identifiers stored in cookies or local storage. On the marketing site we use Google Tag Manager and associated analytics.
3.5 Communications. Emails, support tickets, and meetings you book with us, including anything you choose to include in them.
4. Personal data about people who are not our customers
This section matters and we want to be plain about it.
The Platform lets a customer monitor publicly available posts and profile information from professional social networks (primarily LinkedIn) so that the customer can see what topics are being discussed in their market. Where a customer adds a person or company as a monitored source, we collect and store:
- the public profile URL, name, headline, job title, employer and public profile photo;
- the text, engagement counts and timestamps of that account's public posts.
We collect this via third-party data providers (see section 8) and store it inside that customer's workspace.
We do not buy contact lists, collect private messages or non-public content, send outbound messages to these individuals, build advertising profiles, use this data for automated decisions that produce legal or similarly significant effects about a person, or use anyone's name, voice or likeness to generate content that impersonates them.
Scoring applies to topics and ideas, not to people.
If you are an individual whose public posts have been monitored and you want that stopped, email [email protected] with your profile URL. We will locate and remove your data across affected workspaces and instruct the relevant customers, ordinarily within 30 days.
5. Why we process data, and our legal basis (GDPR Article 6)
| Purpose | Data | Legal basis |
|---|---|---|
| Create and operate your account, provide the Platform | 3.1, 3.3 | Contract, Article 6(1)(b) |
| Process subscription payments, invoicing, tax | 3.2 | Contract; legal obligation, Article 6(1)(c), for tax records |
| Service emails: receipts, security, downtime, changes to terms | 3.1 | Contract |
| Support and troubleshooting | 3.1, 3.4, 3.5 | Contract; legitimate interests |
| Security, abuse prevention, rate limiting, fraud detection | 3.1, 3.4 | Legitimate interests, Article 6(1)(f), securing the service |
| Product analytics, reliability, improving features | 3.4 | Legitimate interests; consent for non-essential cookies |
| Monitoring public professional-network sources at customer instruction | Section 4 | Legitimate interests: the customer's interest in market research from public professional content, balanced against the individual's rights. A Legitimate Interests Assessment is on file and available on request |
| Marketing emails to prospects | 3.1, 3.5 | Consent, or legitimate interests for existing customers on comparable products (soft opt-in). Unsubscribe in any email |
| Establishing, exercising or defending legal claims | Any | Legitimate interests; legal obligation |
We do not sell personal data. We do not share it with third parties for their own marketing.
6. Your workspace: we act as processor
Where personal data sits inside a customer's workspace, including the customer's own team members and the third-party source data in section 4, the customer is the controller and we act as processor under GDPR Article 28. We process it only on that customer's documented instructions.
Customers are responsible for having a lawful basis for what they put in, and for responding to data-subject requests about it. We will assist. Our Data Processing Addendum is available at [email protected] and, once signed, forms part of the Terms of Service.
7. AI processing
The Platform sends your prompts, brand settings and content drafts to third-party AI providers to generate output.
- We do not use your content to train our own models.
- We contract with our AI providers on enterprise or API terms that exclude your data from their model training.
- Providers may retain inputs briefly for abuse monitoring, per their own terms.
- Please do not enter special-category data (health, biometric, political opinion and similar), payment card numbers, or credentials into content fields.
AI output is generated automatically. It concerns marketing topics and content, not decisions about individuals, and so does not constitute automated decision-making producing legal or similarly significant effects on a person under GDPR Article 22. All output is reviewed and approved by a named individual in the customer's workspace before it is published. There is no automatic-publication path that bypasses human approval.
8. Sub-processors and recipients
We use the following providers. The live list is maintained at https://contentpeter.com/subprocessors and we give notice of material changes.
| Provider | Purpose | Location and transfer safeguard |
|---|---|---|
| Supabase | Application database, authentication, file storage, serverless functions | EEA, Ireland (eu-west-1). No transfer. |
| Paddle.com Market Ltd | Payments, invoicing, tax, Merchant of Record | UK, adequacy decision |
| Anthropic | AI content and analysis generation | US, Standard Contractual Clauses |
| Apify | Public professional-network data collection | EEA (Czechia). No transfer. |
| Firecrawl | Public website content retrieval | US, Standard Contractual Clauses |
| DataForSEO | Search-keyword and SERP data | EEA. No transfer. |
| Cloudflare | CDN, DNS, security | Global, Standard Contractual Clauses. EU data localisation available. |
| Google (Tag Manager, Analytics) | Marketing-site analytics | US, EU-US Data Privacy Framework |
| Calendly | Meeting scheduling | US, Standard Contractual Clauses |
| MailerSend | Transactional and marketing email | EEA (Lithuania). No transfer. |
We also disclose data where legally required, and to professional advisers or an acquirer in a corporate transaction, on notice to you.
9. International transfers
Some providers are outside the EEA, principally in the United States. Where personal data is transferred outside the EEA or UK, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified), together with supplementary measures where appropriate. Copies of the safeguards are available at [email protected].
10. Retention
| Data | Retention |
|---|---|
| Account data | Life of account, then 30 days after deletion |
| Customer Content | Life of account. 30 days after account termination, then deleted |
| Monitored public source data | While the source is active. Deleted within 30 days of removal |
| Billing and invoice records | 8 years, under Hungarian accounting law (Act C of 2000) |
| Security and access logs | 12 months |
| Support correspondence | 24 months from last contact |
| Marketing contacts | Until you unsubscribe, or 24 months of no engagement |
| Encrypted backups | Rotated out within 35 days |
11. Security
Encryption in transit (TLS) and at rest. Hashed passwords. Role-based access control with per-tenant row-level isolation in the database. Least-privilege access for personnel. Audit logging. Regular dependency patching. Encrypted backups.
No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify the Hungarian supervisory authority within 72 hours and notify you without undue delay where the risk is high.
12. Your rights
Under the GDPR and equivalent UK law you have the right to access your data, rectify it, erase it, restrict processing, receive it in a portable format, object to processing based on legitimate interests (including profiling), object to direct marketing at any time absolutely, and withdraw consent at any time without affecting prior processing.
Exercise any of these at [email protected]. We respond within one month, extendable by two months for complex requests, and it is free unless the request is manifestly unfounded or excessive.
You may complain to your local supervisory authority. Ours is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), Budapest, Falk Miksa utca 9-11, 1055, https://naih.hu.
California residents may request disclosure or deletion of personal information and opt out of "sale" or "sharing". We do not sell or share personal information as those terms are defined under the CCPA and CPRA. Use the same contact address. We will not discriminate against you for exercising these rights.
13. Cookies
Essential cookies (session, authentication, security, load balancing) are set without consent as they are strictly necessary. Analytics and marketing cookies are set only with your consent via our banner, which you can change at any time via "Cookie preferences" in the footer. Most browsers also let you block cookies, though the application may not work correctly without essential ones.
14. Children
The Platform is for business use and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact [email protected] and we will delete it.
15. Changes
We may update this policy. Material changes will be notified by email or in-app at least 30 days before they take effect. The "Last updated" date at the top always reflects the current version.
16. Contact
Peter Balog e.v. 5600 Békéscsaba, Szőlő u. 93/3., Hungary [email protected] https://contentpeter.com
For payment or billing data specifically, you may also contact Paddle at https://paddle.net.
