Back to Home
Austrian DSG & EU GDPR (DSGVO) Compliant

Privacy Policy

Last Updated: September 2026Jurisdiction: Republic of Austria (European Union)Supervisory Authority: Österreichische Datenschutzbehörde (DSB)

1. Identity of the Data Controller

The data controller responsible for the processing of your personal data in accordance with Art. 4(7) of the EU General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR / DSGVO) and the Austrian Data Protection Act (Datenschutzgesetz - DSG) is:

Company: GoSocio AI
Registered Jurisdiction: Graz / Vienna, Austria (European Union)
General Contact & Support: support@gosocio.at
Data Protection Contact: privacy@gosocio.at

2. Scope & Underlying Privacy Principles

This Privacy Policy applies to all services, websites, web applications, APIs, AI Creative Studio tools, and automated social publishing workflows provided under the GoSocio brand (collectively, the "Services").

We process all personal data strictly according to the core principles of Art. 5 GDPR: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.

3. Categories of Personal Data We Process

We collect and process the following categories of data when you use GoSocio:

A. Account & Identity Data

Full name, business email address, hashed password, team/workspace identifier, billing country, and authentication logs (e.g., Auth0 or Google SSO tokens).

B. Knowledge Source & RAG Documents

Brand guidelines, PDFs, whitepapers, marketing catalogs, and company knowledge uploaded by your team to ground AI social agent workflows.

C. Social Media OAuth Tokens

Encrypted OAuth 2.0 access and refresh tokens for connected platforms (LinkedIn, Meta/Facebook/Instagram, X, TikTok, YouTube, Pinterest) used strictly to schedule and publish authorized posts.

D. Prompts & Creative Studio Content

Text prompts, tone specifications, generated captions, image creation prompts, video generation requests, and user revision feedback.

E. Payment & Subscription Data

Billing address, VAT ID (UID-Nummer for Austrian/EU businesses), invoice history, and token consumption metrics. Credit card data is handled directly by our PCI-DSS certified payment processor (Stripe).

F. Technical & Diagnostic Data

IP address, browser user-agent, operating system, timestamp of access, session tokens, and crash telemetry to maintain platform reliability and security.

4. AI Model Data Privacy & Zero-Training Guarantee

We treat corporate knowledge and proprietary brand materials with enterprise confidentiality:

  • No Public Model Training: Your uploaded documents, internal brand strategies, draft posts, and generated creative media are NEVER used to train, retrain, or improve public foundation AI models.
  • Isolated Tenant Vector Stores: Knowledge base embeddings (RAG) are strictly segregated by organization workspace with access control lists.
  • Enterprise API Contracts: All downstream AI inference providers are engaged under enterprise Data Processing Agreements (DPAs) with strict zero-data-retention and non-training commitments.

5. Legal Bases for Data Processing (Art. 6 GDPR)

Processing PurposeData CategoriesLegal Basis (GDPR / DSGVO)
Provision of GoSocio platform & user workspaceAccount, Auth, Workspace DataArt. 6(1)(b) GDPR (Contract Performance)
AI Agent generation, Studio image/video creation, RAG indexingPrompts, Uploaded Documents, Creative OutputArt. 6(1)(b) GDPR (Contract Performance)
Publishing scheduled social media posts to connected networksOAuth Tokens, Post Text & Media AssetsArt. 6(1)(b) GDPR (Contract Performance)
Payment processing, subscriptions, and invoicingBilling details, VAT UID, payment historyArt. 6(1)(b) & Art. 6(1)(c) (Legal Obligation - Austrian BAO / UGB)
Platform security, fraud prevention & DDoS protectionIP address, telemetry, security event logsArt. 6(1)(f) GDPR (Legitimate Interest)
Product updates and marketing communicationsEmail, name, newsletter preferencesArt. 6(1)(a) GDPR (Consent - revocable at any time)

6. International Data Transfers & Safeguards

Whenever personal data is transferred to subprocessors or infrastructure providers outside the European Economic Area (EEA), we ensure adequate data protection safeguards pursuant to Articles 44–49 GDPR:

  • EU Adequacy Decisions (Art. 45 GDPR): Transfers to countries recognized by the European Commission as offering an adequate level of data protection (e.g., EU-US Data Privacy Framework participants).
  • Standard Contractual Clauses (SCCs - Art. 46 GDPR): Execution of the European Commission’s approved Standard Contractual Clauses with technical measures (end-to-end encryption, strict access isolation).

7. Data Retention & Deletion

We retain your data only for as long as necessary to fulfill the operational purposes for which it was gathered, or as required by Austrian statutory retention obligations:

  • Active Account Data: Retained for the duration of your active subscription. Upon account deletion, personal account details and indexed vector documents are permanently deleted within 30 days.
  • Financial & Invoicing Records: Retained for 7 years in compliance with the Austrian Federal Fiscal Code (§ 132 Bundesabgabenordnung - BAO) and Commercial Code (Unternehmensgesetzbuch - UGB).
  • Access Logs & Diagnostics: Maintained for a maximum period of 90 days before automated rotation and permanent purge.

8. Your Rights as a Data Subject (GDPR & Austrian DSG)

Under Chapter III of the GDPR and the Austrian Data Protection Act (DSG), you have the following irrevocable rights:

• Right of Access (Art. 15 GDPR): Request a copy of all personal data held about you.
• Right to Rectification (Art. 16 GDPR): Correct inaccurate or incomplete personal records.
• Right to Erasure (Art. 17 GDPR): Request deletion of your data ("Right to be Forgotten").
• Right to Restriction (Art. 18 GDPR): Limit how your personal data is processed.
• Right to Data Portability (Art. 20 GDPR): Receive data in a structured, machine-readable format.
• Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests or direct marketing.

Competent Supervisory Authority in Austria (Aufsichtsbehörde):

You have the right under Art. 77 GDPR to lodge a complaint with the Austrian data protection authority:

Österreichische Datenschutzbehörde (DSB)
Barichgasse 40-42, 1030 Wien, Österreich
Telefon: +43 1 52 152-0 | E-Mail: dsb@dsb.gv.at | Website: https://www.dsb.gv.at

9. How to Exercise Your Rights

To submit a data access request, request account erasure, or exercise any GDPR right, please send an email to our Data Protection Office:

privacy@gosocio.at

We respond to all verified GDPR requests within the statutory 30-day timeline free of charge.