Privacy Policy
1. Identity of the Data Controller
The data controller responsible for the processing of your personal data in accordance with Art. 4(7) of the EU General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR / DSGVO) and the Austrian Data Protection Act (Datenschutzgesetz - DSG) is:
2. Scope & Underlying Privacy Principles
This Privacy Policy applies to all services, websites, web applications, APIs, AI Creative Studio tools, and automated social publishing workflows provided under the GoSocio brand (collectively, the "Services").
We process all personal data strictly according to the core principles of Art. 5 GDPR: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
3. Categories of Personal Data We Process
We collect and process the following categories of data when you use GoSocio:
A. Account & Identity Data
Full name, business email address, hashed password, team/workspace identifier, billing country, and authentication logs (e.g., Auth0 or Google SSO tokens).
B. Knowledge Source & RAG Documents
Brand guidelines, PDFs, whitepapers, marketing catalogs, and company knowledge uploaded by your team to ground AI social agent workflows.
C. Social Media OAuth Tokens
Encrypted OAuth 2.0 access and refresh tokens for connected platforms (LinkedIn, Meta/Facebook/Instagram, X, TikTok, YouTube, Pinterest) used strictly to schedule and publish authorized posts.
D. Prompts & Creative Studio Content
Text prompts, tone specifications, generated captions, image creation prompts, video generation requests, and user revision feedback.
E. Payment & Subscription Data
Billing address, VAT ID (UID-Nummer for Austrian/EU businesses), invoice history, and token consumption metrics. Credit card data is handled directly by our PCI-DSS certified payment processor (Stripe).
F. Technical & Diagnostic Data
IP address, browser user-agent, operating system, timestamp of access, session tokens, and crash telemetry to maintain platform reliability and security.
4. AI Model Data Privacy & Zero-Training Guarantee
We treat corporate knowledge and proprietary brand materials with enterprise confidentiality:
- No Public Model Training: Your uploaded documents, internal brand strategies, draft posts, and generated creative media are NEVER used to train, retrain, or improve public foundation AI models.
- Isolated Tenant Vector Stores: Knowledge base embeddings (RAG) are strictly segregated by organization workspace with access control lists.
- Enterprise API Contracts: All downstream AI inference providers are engaged under enterprise Data Processing Agreements (DPAs) with strict zero-data-retention and non-training commitments.
5. Legal Bases for Data Processing (Art. 6 GDPR)
| Processing Purpose | Data Categories | Legal Basis (GDPR / DSGVO) |
|---|---|---|
| Provision of GoSocio platform & user workspace | Account, Auth, Workspace Data | Art. 6(1)(b) GDPR (Contract Performance) |
| AI Agent generation, Studio image/video creation, RAG indexing | Prompts, Uploaded Documents, Creative Output | Art. 6(1)(b) GDPR (Contract Performance) |
| Publishing scheduled social media posts to connected networks | OAuth Tokens, Post Text & Media Assets | Art. 6(1)(b) GDPR (Contract Performance) |
| Payment processing, subscriptions, and invoicing | Billing details, VAT UID, payment history | Art. 6(1)(b) & Art. 6(1)(c) (Legal Obligation - Austrian BAO / UGB) |
| Platform security, fraud prevention & DDoS protection | IP address, telemetry, security event logs | Art. 6(1)(f) GDPR (Legitimate Interest) |
| Product updates and marketing communications | Email, name, newsletter preferences | Art. 6(1)(a) GDPR (Consent - revocable at any time) |
6. International Data Transfers & Safeguards
Whenever personal data is transferred to subprocessors or infrastructure providers outside the European Economic Area (EEA), we ensure adequate data protection safeguards pursuant to Articles 44–49 GDPR:
- EU Adequacy Decisions (Art. 45 GDPR): Transfers to countries recognized by the European Commission as offering an adequate level of data protection (e.g., EU-US Data Privacy Framework participants).
- Standard Contractual Clauses (SCCs - Art. 46 GDPR): Execution of the European Commission’s approved Standard Contractual Clauses with technical measures (end-to-end encryption, strict access isolation).
7. Data Retention & Deletion
We retain your data only for as long as necessary to fulfill the operational purposes for which it was gathered, or as required by Austrian statutory retention obligations:
- Active Account Data: Retained for the duration of your active subscription. Upon account deletion, personal account details and indexed vector documents are permanently deleted within 30 days.
- Financial & Invoicing Records: Retained for 7 years in compliance with the Austrian Federal Fiscal Code (§ 132 Bundesabgabenordnung - BAO) and Commercial Code (Unternehmensgesetzbuch - UGB).
- Access Logs & Diagnostics: Maintained for a maximum period of 90 days before automated rotation and permanent purge.
8. Your Rights as a Data Subject (GDPR & Austrian DSG)
Under Chapter III of the GDPR and the Austrian Data Protection Act (DSG), you have the following irrevocable rights:
Competent Supervisory Authority in Austria (Aufsichtsbehörde):
You have the right under Art. 77 GDPR to lodge a complaint with the Austrian data protection authority:
Barichgasse 40-42, 1030 Wien, Österreich
Telefon: +43 1 52 152-0 | E-Mail: dsb@dsb.gv.at | Website: https://www.dsb.gv.at
9. How to Exercise Your Rights
To submit a data access request, request account erasure, or exercise any GDPR right, please send an email to our Data Protection Office:
We respond to all verified GDPR requests within the statutory 30-day timeline free of charge.

