1. Who we are
The data controller for information about visitors, account holders, and business contacts is MeltFlex s.r.o., a company registered in the Slovak Republic, Company ID (IČO): [COMPANY ID / IČO], registered office: [REGISTERED ADDRESS]. You can reach us at hello@aisocialmedianow.com.
For content that our customers upload or publish through the Services (posts, captions, images, and information drawn from connected social accounts), the customer is the data controller and MeltFlex acts as a data processor under a Data Processing Agreement (DPA), available on request. This split reflects GDPR Art. 4(7)–(8) and Art. 28.
2. Information we collect
2.1 Information you give us
- Account and profile data: name, email address, and a hashed password.
- Business details: company name, website, industry, and brand information you enter during onboarding.
- Billing data: company details and payment information. Card data is handled by our payment processor (Stripe) — we never store full card numbers.
- Content you create: brand inputs, prompts, generated posts, captions, edits, and anything you produce or publish through the Services.
- Support and other messages you send us.
2.2 Information collected automatically
- Usage data: pages and features used, actions taken, and timestamps.
- Technical data: IP address, device and browser type, operating system, and language settings.
- Approximate location derived from IP address (no precise GPS).
- Security and event logs used for operations and troubleshooting.
2.3 Information from connected services
When you sign in with a third party or connect a social account (e.g. Google, Meta, LinkedIn), we receive the profile information and access tokens you authorise. We use these only to provide the features you request.
2.4 Sensitive data and minors
We do not intentionally collect special categories of personal data (GDPR Art. 9) and ask that you not upload such content without a valid legal basis. The Services are for businesses and not directed at anyone under 18; we do not knowingly collect data from minors.
3. How we use your information
- To create and manage your account and subscription.
- To generate, schedule, and publish content on your behalf.
- To process payments and renewals.
- To provide support and respond to your requests.
- To operate, secure, troubleshoot, and improve the Services.
- To send service updates and — where permitted — relevant marketing you can opt out of at any time.
- To meet legal, accounting, and tax obligations.
We do not use AI or automated processing to make decisions that produce legal or similarly significant effects about individuals (GDPR Art. 22).
4. Legal bases for processing
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing, operating, and improving the Services (incl. AI features) | Contract — Art. 6(1)(b) |
| Billing, accounting, and record-keeping | Legal obligation — Art. 6(1)(c) |
| Security, abuse prevention, and product analytics (aggregated) | Legitimate interest — Art. 6(1)(f) |
| Newsletters and non-essential cookies | Consent — Art. 6(1)(a) |
You may withdraw consent at any time without affecting processing carried out before withdrawal (GDPR Art. 7(3)).
5. Use of artificial intelligence
We use third-party generative AI models to produce text and images for our customers. We do not train AI models on your data, and our AI providers are contractually prohibited from using content sent through the Services to train their models.
AI-generated content can contain errors or unintended similarities to existing works or people. You review and approve everything before it is published, and you are responsible for holding the rights to any material you upload or ask the AI to work with. You may not use the Services to create unauthorised impersonations or deepfakes of identifiable people. Where disclosure that content is AI-generated is required (e.g. EU AI Act Art. 50), you are responsible for that labelling at publication.
6. Sharing your information
We do not sell personal information and do not share it for cross-context behavioural advertising. We share data only with service providers acting as processors under appropriate agreements, and only as needed to run the Services:
| Provider | Purpose | Location | Transfer basis |
|---|---|---|---|
| Vercel Inc. | Website & app hosting, CDN | US | DPF + SCC |
| Supabase | Database, authentication & storage | EU | Within EEA / SCC |
| OpenAI, L.L.C. | AI text & image generation | US | DPF + SCC (no training) |
| Stripe | Payment processing | EU / US | DPF + SCC |
We may also disclose information to professional advisers, to authorities where legally required, and to a buyer in the event of a merger or sale of the business (with notice to you). An up-to-date list of processors is available on request.
When you connect Meta, LinkedIn, or other platforms, those services process your data as independent controllers under their own terms. You can disconnect an integration at any time in the app or with the platform directly.
7. Cookies
We use strictly necessary cookies to run the Services and, with your consent, optional cookies for analytics. See our Cookie Policy for details and to manage your choices.
8. How long we keep your data
| Category | Retention |
|---|---|
| Account, profile & content | For the subscription term; deleted within 90 days after it ends |
| Billing & accounting records | As required by Slovak accounting and tax law (up to 10 years) |
| Support communications | Up to 24 months after last contact |
| Logs & security data | Up to 12 months, then deleted or anonymised |
| Tokens for connected services | Deleted within 30 days of disconnection or account closure |
9. Security
We apply appropriate technical and organisational measures under GDPR Art. 32, including encryption in transit (TLS) and at rest, role-based access on a least-privilege basis, hashed passwords, and logging and monitoring. No system can be guaranteed 100% secure, so we encourage strong, unique passwords and keeping your credentials confidential. Where a personal data breach is likely to pose a risk, we will notify the competent supervisory authority within 72 hours and affected users without undue delay where required (GDPR Art. 33–34).
10. International transfers
Data is stored primarily within the EU/EEA. Where a processor operates in the United States or another third country, transfers rely on an adequacy decision (including the EU–US Data Privacy Framework for certified recipients) or the European Commission’s Standard Contractual Clauses (SCC 2021/914) with supplementary measures where needed.
11. Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have data deleted where conditions are met (Art. 17);
- restrict or object to certain processing (Art. 18, 21);
- receive your data in a portable format (Art. 20);
- withdraw consent at any time (Art. 7(3));
- lodge a complaint with a supervisory authority (Art. 77).
To exercise any right, contact hello@aisocialmedianow.com. We generally respond within 30 days. EU/EEA residents may complain to their local authority; in Slovakia this is the Office for Personal Data Protection (Úrad na ochranu osobných údajov SR, dataprotection.gov.sk).
12. Changes and contact
We may update this Policy from time to time; the “Last updated” date shows when. Material changes will be communicated by email or in the Services in advance. For any privacy question or request, contact us at hello@aisocialmedianow.com or MeltFlex s.r.o., [REGISTERED ADDRESS], Slovak Republic.