Privacy Policy
ContentPeter
Effective date: 30 September 2026 Last updated: 30 September 2026
1. Controller
Peter Balog e.v., 5600 Békéscsaba, Szőlő u. 93/3., Hungary. EU VAT ID HU67571659.
Privacy contact: [email protected]
We are the data controller for personal data described in sections 3, 4 and 5. Where we process personal data contained in a customer’s workspace, we act as processor on that customer’s instructions. See section 7.
We have not appointed a Data Protection Officer, as we are not required to. Privacy enquiries go to the address above.
2. Scope
This policy covers contentpeter.com, the ContentPeter application at app.contentpeter.com, and our related email and support channels. It does not cover third-party sites we link to, or the social platforms and content management systems you connect to the application, which are governed by their own policies.
3. Data we collect about you
3.1 Account and identity data. Name, work email, password (stored hashed, we never see it in plaintext), display name, profile photo, job title, organisation name, role, timezone and interface preferences. Source: you.
3.2 Billing data. We do not collect, see or store your full card details. Stripe processes your payment on a checkout page that Stripe hosts. From Stripe we receive: a customer and subscription identifier, billing email, business name, billing address and country, VAT ID and its verification result, currency, plan, subscription status, invoice amounts, tax amounts and payment outcomes. We send your business name, billing address, email, VAT ID and the items you bought to Billingo, which issues our Hungarian VAT invoices (számla). Billingo reports each invoice to the Hungarian Tax Authority (NAV), as Hungarian law requires.
Stripe also processes payment data as an independent controller for its own purposes, such as fraud prevention and meeting its legal duties. See Stripe’s privacy policy at https://stripe.com/privacy.
3.3 Credit usage data. For each action that uses credits, we record the action, the number of credits, the time and the team member who started it. We use this to show your balance and statement, and to answer billing questions.
3.4 Customer Content. Everything you put into your workspace: brand assets and colours, product and audience positioning, voice settings, monitored source lists, ideas, uploaded documents, audio and video, drafts, edits, images, charts, schedules and connected-channel configuration.
3.5 Usage and technical data. IP address, browser and device type, pages and features used, timestamps, referring URL, error and performance logs, and identifiers stored in cookies or local storage. On the marketing site we use Google Tag Manager and associated analytics.
3.6 Communications. Emails, support tickets, and meetings you book with us, including anything you choose to include in them.
4. Demo accounts
Before a business becomes a customer, we may build a demo account for it, so that it can see ContentPeter with its own brand. To build it, we collect from public sources:
- the company’s name, website, logo, colours, fonts and public company page;
- the name, job title and public profile photo of up to two of the company’s leaders, such as the founder or CEO, and the public profile URL where we find one.
We use this to create sample profiles and sample content in the style of the company and those leaders. The demo account is private. We share it only with people at that company. A demo account cannot publish, and we never publish sample content anywhere.
When the company subscribes, we delete the sample profiles and all sample content. If nobody signs in to a demo account within 45 days, we close it.
Our legal basis is our legitimate interest in showing a business what our product does for it, balanced against the rights of the people involved. We only use business information that the people involved made public in a professional role. If you are one of these people and you want us to remove your data, email [email protected]. We will delete it within 30 days.
5. Personal data about people who are not our customers
This section matters and we want to be plain about it.
The Platform lets a customer monitor publicly available posts and profile information from professional social networks (primarily LinkedIn) so that the customer can see what topics are being discussed in their market. Where a customer adds a person or company as a monitored source, we collect and store:
- the public profile URL, name, headline, job title, employer and public profile photo;
- the text, engagement counts and timestamps of that account’s public posts.
We collect this via third-party data providers (see section 9) and store it inside that customer’s workspace.
We do not buy contact lists, collect private messages or non-public content, send outbound messages to these individuals, build advertising profiles, or use this data for automated decisions that produce legal or similarly significant effects about a person. Except for the private sample content in a demo account (section 4), we do not use anyone’s name, voice or likeness to generate content that impersonates them.
Scoring applies to topics and ideas, not to people.
If you are an individual whose public posts have been monitored and you want that stopped, email [email protected] with your profile URL. We will locate and remove your data across affected workspaces and instruct the relevant customers, ordinarily within 30 days.
6. Why we process data, and our legal basis (GDPR Article 6)
| Purpose | Data | Legal basis |
|---|---|---|
| Create and operate your account, provide the Platform | 3.1, 3.4 | Contract, Article 6(1)(b) |
| Take payments, calculate tax, verify VAT numbers | 3.2 | Contract |
| Issue invoices, report them to NAV, keep accounting records | 3.2 | Legal obligation, Article 6(1)(c) |
| Grant, spend and show credits | 3.3 | Contract |
| Service emails: receipts, payment problems, security, downtime, changes to terms | 3.1, 3.2 | Contract |
| Support and troubleshooting | 3.1, 3.3, 3.5, 3.6 | Contract; legitimate interests |
| Security, abuse prevention, rate limiting, fraud detection | 3.1, 3.2, 3.5 | Legitimate interests, Article 6(1)(f), securing the service |
| Product analytics, reliability, improving features | 3.5 | Legitimate interests; consent for non-essential cookies |
| Build demo accounts for prospective customers | Section 4 | Legitimate interests: showing a business what our product does for it |
| Monitoring public professional-network sources at customer instruction | Section 5 | Legitimate interests: the customer’s interest in market research from public professional content, balanced against the individual’s rights. A Legitimate Interests Assessment is on file and available on request |
| Marketing emails to prospects | 3.1, 3.6 | Consent, or legitimate interests for existing customers on comparable products (soft opt-in). Unsubscribe in any email |
| Establishing, exercising or defending legal claims | Any | Legitimate interests; legal obligation |
We do not sell personal data. We do not share it with third parties for their own marketing.
7. Your workspace: we act as processor
Where personal data sits inside a customer’s workspace, including the customer’s own team members and the third-party source data in section 5, the customer is the controller and we act as processor under GDPR Article 28. We process it only on that customer’s documented instructions.
On Expert-Led plans, our experts work inside the customer’s workspace and can see its content. They work for ContentPeter, are bound by confidentiality, and only access workspaces they are assigned to. Our support staff may also access a workspace to solve a problem you report.
Customers are responsible for having a lawful basis for what they put in, and for responding to data-subject requests about it. We will assist. Our Data Processing Addendum is available at [email protected] and, once signed, forms part of the Terms of Service.
8. AI processing
The Platform sends your prompts, brand settings, uploaded material and content drafts to third-party AI providers to generate output, transcribe audio and video, and create images.
- We do not use your content to train our own models.
- We contract with our AI providers on enterprise or API terms that exclude your data from their model training.
- Providers may retain inputs briefly for abuse monitoring, per their own terms.
- Please do not enter special-category data (health, biometric, political opinion and similar), payment card numbers, or credentials into content fields.
AI output is generated automatically. It concerns marketing topics and content, not decisions about individuals, and so does not constitute automated decision-making producing legal or similarly significant effects on a person under GDPR Article 22. All output is reviewed and approved by a named individual in the customer’s workspace before it is published. There is no automatic-publication path that bypasses human approval.
9. Sub-processors and recipients
We use the following providers. This list is current on the date at the top of this policy, and we give notice of material changes.
| Provider | Purpose | Location and transfer safeguard |
|---|---|---|
| Supabase | Application database, authentication, file storage, serverless functions | EEA, Ireland (eu-west-1). No transfer. |
| Stripe Payments Europe, Ltd. | Payment processing, tax calculation, billing portal | EEA, Ireland. Onward transfer to Stripe, Inc. (US) under the EU-US Data Privacy Framework and Standard Contractual Clauses |
| Billingo Technologies Zrt. | Hungarian VAT invoices and reporting to NAV | EEA, Hungary. No transfer. |
| Anthropic | AI content and analysis generation | US, Standard Contractual Clauses |
| Google (Gemini API) | AI analysis and generation | US, EU-US Data Privacy Framework |
| OpenAI | AI image generation | US, Standard Contractual Clauses |
| AssemblyAI | Transcription of uploaded audio and video | US, Standard Contractual Clauses |
| htmlcsstoimage.com | Rendering charts and branded images | US, Standard Contractual Clauses |
| Zernio | Publishing to connected social channels, post analytics and comments | Standard Contractual Clauses where data leaves the EEA |
| Apify | Public professional-network data collection | EEA (Czechia). No transfer. |
| Firecrawl | Public website content retrieval | US, Standard Contractual Clauses |
| DataForSEO | Search-keyword and SERP data | EEA. No transfer. |
| Cloudflare | CDN, DNS, security, marketing-site hosting | Global, Standard Contractual Clauses. EU data localisation available. |
| Google (Tag Manager, Analytics) | Marketing-site analytics | US, EU-US Data Privacy Framework |
| Calendly | Meeting scheduling | US, Standard Contractual Clauses |
| MailerSend | Transactional and marketing email | EEA (Lithuania). No transfer. |
We also disclose data where legally required, including invoice data to the Hungarian Tax Authority (NAV), and to professional advisers or an acquirer in a corporate transaction, on notice to you.
10. International transfers
Some providers are outside the EEA, principally in the United States. Where personal data is transferred outside the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified), together with supplementary measures where appropriate. Copies of the safeguards are available at [email protected].
11. Retention
| Data | Retention |
|---|---|
| Account data | Life of account, then 30 days after deletion |
| Customer Content | Life of account. 30 days after account termination, then deleted |
| Credit usage records | Life of account, then 30 days after deletion |
| Demo account data | Sample profiles and content: until the company subscribes. A closed demo account: deleted within 30 days of a removal request |
| Monitored public source data | While the source is active. Deleted within 30 days of removal |
| Invoices and billing records | 8 years, under Hungarian accounting law (Act C of 2000) |
| Security and access logs | 12 months |
| Support correspondence | 24 months from last contact |
| Marketing contacts | Until you unsubscribe, or 24 months of no engagement |
| Encrypted backups | Rotated out within 35 days |
12. Security
Encryption in transit (TLS) and at rest. Hashed passwords. Role-based access control with per-tenant row-level isolation in the database. Least-privilege access for personnel. Audit logging. Regular dependency patching. Encrypted backups. Card payments are handled only by Stripe, which is certified to PCI DSS Level 1.
No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify the Hungarian supervisory authority within 72 hours and notify you without undue delay where the risk is high.
13. Your rights
Under the GDPR and equivalent UK law you have the right to access your data, rectify it, erase it, restrict processing, receive it in a portable format, object to processing based on legitimate interests (including profiling), object to direct marketing at any time absolutely, and withdraw consent at any time without affecting prior processing.
We cannot erase invoices and billing records before the end of the period the law requires us to keep them.
Exercise any of these at [email protected]. We respond within one month, extendable by two months for complex requests, and it is free unless the request is manifestly unfounded or excessive.
You may complain to your local supervisory authority. Ours is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), Budapest, Falk Miksa utca 9-11, 1055, https://naih.hu.
California residents may request disclosure or deletion of personal information and opt out of “sale” or “sharing”. We do not sell or share personal information as those terms are defined under the CCPA and CPRA. Use the same contact address. We will not discriminate against you for exercising these rights.
14. Cookies
Essential cookies (session, authentication, security, load balancing) are set without consent as they are strictly necessary. Analytics and marketing cookies are set only with your consent via our banner, which you can change at any time via “Cookie preferences” in the footer. Most browsers also let you block cookies, though the application may not work correctly without essential ones.
Stripe’s checkout and billing portal pages run on Stripe’s own domain. Stripe sets its own cookies there to process your payment and prevent fraud, under Stripe’s cookie policy.
15. Children
The Platform is for business use and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact [email protected] and we will delete it.
16. Changes
We may update this policy. Material changes will be notified by email or in-app at least 30 days before they take effect. The “Last updated” date at the top always reflects the current version.
17. Contact
Peter Balog e.v.
5600 Békéscsaba, Szőlő u. 93/3., Hungary
[email protected]
https://contentpeter.com