SECTION 1 – DATA COLLECTED, METRICS, AND USAGE
For legal compliance purposes, we may be required to collect certain types of personal data.
This data shall remain on our servers for a period of time as required by law and kept for such a period for which responsibilities could be derived for the services provided. This data may be used for legally-required bookkeeping, our own service metrics, or to prove our inculpability in case we are ordered by governments, local authorities, or the services you’ve associated with your account to prove that the posts generated and/or posted on your behalf by our service were not illegal in nature nor contravened the applicable Terms and Conditions due to any fault of Content System OS.
The following data is required for registration and use of the service: username/email address, password, and full legal name.
For project creation and content access, the following data is necessary: phone number, company name and tax identification code/VAT number (for legal entities), user’s website (if applicable), address, product/service website, product/service names, project description, competitor names, and company size.
Optional data required for content generation includes: photographs, videos, descriptive texts, and facial photographs of the user for avatar creation.
Other types of stored data may include, but are not limited to: contact, account, personalization, communication, billing, service plan, messaging, logs, IP addresses, location, language, login, usage, and customer support data.
These data points are used to improve our services and are necessary for the operation of our services and any third-party services linked to your account (for example, artificial intelligence services that include machine learning for enhanced content processing, or social network services connected to your account).
In some cases, we may also adopt data encryption and pseudonymization measures. However, data transmission over the Internet can never be guaranteed to be entirely secure, though we take all necessary precautions to achieve data security.
Content System OS will not sell your data to third parties.
SECTION 2 – DATA DELETION
As outlined in “SECTION 28 – ACCOUNT DELETION & DATA RETENTION” of our Terms and Conditions and in “SECTION 1 – DATA COLLECTED, METRICS, AND USAGE” of this Privacy Policy, once you delete your account, we shall delete your data after the legal time required (5 years for financial-accounting and tax liabilities purposes, as per Romanian legislation, calculated from July 1st of the following year) for keeping it has expired, for the reasons outlined in said sections.
In the event we require your data for a further period of time exceeding the legal requirement, for the betterment of our own services, and you have requested the deletion of your account and thus your data, we shall endeavor to anonymize your data by various technical processes.
SECTION 3 – SOCIAL NETWORK PERMISSIONS
In order for our service to function, we require you to accept the permissions requested by each social network, each of them thus allowing Content System OS to have access to the administration of the account in the corresponding social network, with access to the creation and administration of content and/or publications, comments, direct messages, and statistics, as well as, once said modules are in effect, the administration of advertisements and the statistical data of such advertisements, with the sole purpose of providing our services, as contracted by you, according to your payment plan and associated optional features.
SECTION 4 – SOCIAL MEDIA INTEGRATIONS
Meta, Facebook and Instagram. Content System OS allows users to connect their Facebook Pages and Instagram professional accounts in order to publish, schedule and manage marketing content from the platform.
When you connect a Facebook or Instagram account, we may receive and store data provided through Meta APIs, including:
- your Meta user ID and basic profile information needed for authentication;
- the list of Facebook Pages you manage, so you can choose where to publish;
- Page access tokens required to publish approved content;
- connected Instagram professional account information;
- post IDs, publishing status and basic performance/engagement data for content published through Content System OS.
We use this data only to provide the social media publishing features of Content System OS, including account connection, Page selection, post publishing, scheduling, status tracking and performance reporting.
We do not sell Meta, Facebook or Instagram data. We do not use this data for unrelated advertising purposes. We do not publish anything to your Facebook Page or Instagram account unless you explicitly approve, schedule or trigger the publishing action inside Content System OS.
You can disconnect your Facebook or Instagram integration at any time from your Content System OS account - connect-platforms page. After disconnecting, Content System OS will stop using the related access tokens.
To request deletion of your Meta/Facebook/Instagram data from Content System OS, contact us at: office@contentsystemos.com or use the data deletion page: https://contentsystemos.com/data-deletion.
LinkedIn. When you connect LinkedIn, we may receive and store your LinkedIn user ID, basic profile information, email address if provided by LinkedIn, the LinkedIn organizations or Pages you administer, the selected organization reference, access tokens, post IDs, publishing status and basic performance or engagement data. We use this data only to authenticate the connection, select the correct LinkedIn destination, publish or schedule approved content, track publishing status and report performance.
X. When you connect X, we may receive and store your X account ID, basic profile information, access and refresh tokens, media upload references, post IDs, publishing status, comments or replies where supported, and basic performance data. We use this data only to publish or schedule approved posts, manage uploaded media, track status and display reporting for content handled through Content System OS.
YouTube and YouTube Shorts. When you connect YouTube, we may receive and store Google account authentication data, basic profile and email information, YouTube channel identifiers, access and refresh tokens, video IDs, upload status, titles, descriptions, comments and basic channel or video performance data. We use this data only to upload, schedule and manage approved YouTube videos or Shorts, reply to or review comments where enabled, track status and report performance.
TikTok. When you connect TikTok, we may receive and store your TikTok open ID, basic profile information, access tokens, video or post IDs, publishing status, comments where supported and basic performance data. We use this data only to authenticate the account, publish or schedule approved TikTok content, track status and display performance reporting.
Reddit. When you connect Reddit, we may receive and store your Reddit user identity, username, selected subreddit, access and refresh tokens, post IDs, comment IDs, comment content returned by Reddit, voting or moderation-related permissions where granted, publishing status and basic performance data. We use this data only to publish approved content to the selected subreddit, manage or review comments where enabled, track status and report performance.
Pinterest. When you configure Pinterest, we may receive and store the Pinterest board identifier you provide, connection data made available by Pinterest or Metricool where applicable, pin IDs, publishing status and basic performance data. We use this data only to publish or schedule approved pins to the selected board, track status and report performance.
WordPress. When you connect WordPress, we may receive and store the WordPress site URL, username, application password or token, default post category, created post IDs, media IDs, post URLs, comment counts and related publishing status. We use this data only to authenticate your WordPress site, upload approved media, publish approved blog posts, assign categories, track status and report basic post activity.
Medium. Where Medium publishing is enabled, we may receive and store account or publication identifiers, access tokens, article IDs, publishing status and basic performance data made available by Medium. We use this data only to publish or schedule approved articles, track status and report performance for Medium content handled through Content System OS.
Telegram. Where Telegram publishing is enabled, we may receive and store bot, channel or chat identifiers, access tokens or bot tokens, message IDs, publishing status and basic delivery or engagement data made available by Telegram. We use this data only to publish or schedule approved messages, track status and report performance for Telegram content handled through Content System OS.
Metricool. For supported channels, Content System OS may use Metricool as a scheduling, publishing or analytics provider. When this happens, Metricool may process platform connection identifiers, scheduled post content, media links, publishing status and analytics data needed to complete the publishing workflow and return performance reporting to Content System OS.
For all social media integrations, Content System OS does not sell social media integration data, does not use it for unrelated advertising purposes and does not publish anything unless you explicitly approve, schedule or trigger the publishing action inside Content System OS. You may disconnect integrations from the connect-platforms page, and you may request deletion of integration data by contacting office@contentsystemos.com or using https://contentsystemos.com/data-deletion.
SECTION 5 – THIRD-PARTY POLICIES
As stated in our Terms and Conditions, “SECTION 18 – THIRD-PARTY SERVICES” and “SECTION 19 – THIRD-PARTY LINKS”, third parties have their own policies you may need to agree to in order to use their services and Content System OS is in no way responsible nor liable for any such policy or its enforcement.
SECTION 6 – PAYMENT PROCESSOR
Our service plans require monthly or annual payments and can only be paid by online means, through our payment processor, Stripe. Content System OS does not store nor do we have access to your credit/debit card information. Your card information is securely handled by Stripe and thus subject to their terms and policies.
SECTION 7 – TOKENS
As stated in our Terms and Conditions, “SECTION 39 – AI MODELS”, our service uses various AI models in order to generate content. Due to this fact, as stated in our Terms and Conditions “SECTION 38 – TOKENS”, we use AI tokens in order to pay for the processing power requested by our prompts. These are visible to users and split into two categories - basic and premium tokens.
The service plan bought determines the amount of tokens acquired, the number of allowed users, the number of allowed projects, and the maximum number of allowed posts. Our service handles any and all token transactions with the AI services involved.
SECTION 8 – COOKIES
Some of the information we collected may be stored locally using cookies and similar tracking technologies, explicitly essential and functional cookies. Cookie settings can be changed at a later date by the user.
For further details on cookies and your legal protections thereof, please refer to https://european-union.europa.eu/cookies_en.
SECTION 9 – ADDS & TRACKING
Our service uses internal tracking systems as well as the third-party services Facebook Pixel and Google Analytics.
SECTION 10 – GDPR & YOUR RIGHTS
We operate inside the European Economic Area and, if you are a citizen of the European Union, the European General Data Protection Regulation 2016/679 (GDPR) legislation grants you certain rights regarding your personal data: the right to be clearly and transparently informed about how his data is collected and used, the right to access personal data held by an operator (in this case Content System OS), the right to rectify inaccurate data and complete relevant details, the right to delete personal data (‘right to be forgotten’, which can be exercised by deleting your Content System OS account) as per the extent of the law, the right to request the restriction of processing, the right to data portability, the right to opt-out of certain types of data processing, the right not to be subject to automated individual decisions.
Reference: https://gdpr-info.eu/
The implementation and enforcement of these rights are ensured by the national supervisory authorities of each EU member state. In the case of Romania this is handled by the National Supervisory Authority for Personal Data Processing (ANSPDCP).
SECTION 11 – INTERNATIONAL DATA TRANSFERS
Content System OS uses third-party service providers, such as managed hosting providers, credit card processors, and technology partners to provide the software, networking, infrastructure and other services required to operate our services. These third-party service providers may process or store your personal data on servers outside of the European Economic Area where we are located.
Social media data can be shared with people around the world. The social media platforms and third-party services that you choose to integrate with our services may collect, store, and process your information from various locations around the world according to their own terms and privacy policies.
SECTION 12 – SECURITY
Our website and/or service implements and maintains various reasonable and appropriate administrative, physical, and technical security safeguards to help protect information about you from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction. These security safeguards include, but are not limited to, protecting or otherwise encrypting your ID and password, network and host security controls (e.g., firewalls, intrusion detection systems, etc.), data encryption & pseudonymization, and operating procedures that are designed to protect your information.
Nevertheless, transmission via the internet can never be guaranteed to be completely secure and, thus, we cannot fully guarantee the security of data or information, though we take every reasonable step to safeguard it, as outlined above.
No employee of Content System OS will ever ask for your password and neither can we see your password.
Furthermore, users should take steps to protect their user IDs and passwords and NOT share them with anyone that is not authorized to administer their account.