Privacy Policy

How we handle your data and protect your privacy.

1. Introduction

This Privacy Policy explains how AI Content Plan (“we”, “us”, “our”), processes personal data when you use the AI Content Plan platform available at aicontentplan.com and aicontentplan.nl (the “Service”). AI Content Plan is a SaaS platform that uses artificial intelligence to generate blog articles and automatically publish them to connected platforms.

We are the data controller within the meaning of the EU General Data Protection Regulation (GDPR). We are committed to protecting your privacy and handling your data in a transparent, lawful manner.

If you have any questions about this policy or your personal data, you can reach us at [email protected].

2. What Personal Data We Collect and Why

We process personal data only when we have a valid legal basis under Article 6(1) GDPR. Below is an overview of each processing activity, the data involved, and the legal basis we rely on.

2.1 Account Management

Legal basis: Performance of a contract — Art. 6(1)(b) GDPR

When you create an account, we process the following data through our authentication provider:

  • Email address
  • Name
  • Organization information

This data is necessary to create and manage your account, authenticate your identity, and provide you with access to the Service.

2.2 Payment Processing

Legal basis: Performance of a contract — Art. 6(1)(b) GDPR; Legal obligation — Art. 6(1)(c) GDPR

We use a certified third-party payment processor to handle payments. The following data is processed:

  • Name and email address
  • Billing information
  • Payment method details
  • Transaction history

We need this data to fulfil our contractual obligations and to comply with Dutch fiscal and tax regulations. We do not store full payment card details on our own servers.

2.3 AI Content Generation

Legal basis: Performance of a contract — Art. 6(1)(b) GDPR

To generate articles, we send data to third-party AI model providers. The data processed includes:

  • Article topics and keywords you provide
  • Writing instructions and preferences
  • The generated article content

Important: Your content is not used to train AI models. The data is processed solely to generate the output you request.

2.4 Analytics

Legal basis: Consent — Art. 6(1)(a) GDPR

We use analytics services to understand how visitors use our website. These tools may process:

  • Page views and interactions
  • Device and browser information
  • Session data

Analytics cookies and tracking are only activated after you give explicit consent via our cookie banner. You can withdraw your consent at any time. For full details on cookies, please see our Cookie Policy.

2.5 Email Notifications

Legal basis: Performance of a contract — Art. 6(1)(b) GDPR

We use a third-party email service provider to send transactional and notification emails. The data processed includes:

  • Email address
  • Notification preferences

2.6 File Storage

Legal basis: Performance of a contract — Art. 6(1)(b) GDPR

Generated images and article content are stored on secure cloud infrastructure within the European Union. No personal data is transferred outside the EU for storage purposes.

2.7 Content Publishing Integrations

Legal basis: Performance of a contract — Art. 6(1)(b) GDPR

When you connect external publishing platforms, the following data may be processed:

  • Published article content
  • API credentials for the connected platform (encrypted at rest)

The destination of this data depends on the platforms you choose to connect. You are responsible for ensuring that your use of these third-party platforms complies with their respective privacy policies.

2.8 Lead Capture

Legal basis: Legitimate interest — Art. 6(1)(f) GDPR

When you interact with our demo or lead capture forms, we may collect:

  • Email address
  • IP address
  • Browser and device information
  • Language preference
  • Referrer information

Purpose: Sales follow-up for users who have shown interest in the Service by using the demo.

Legitimate Interest Assessment: We have a legitimate interest in following up with potential customers who have actively engaged with our demo. The data collected is minimal and directly related to the interaction. We believe this interest outweighs any minimal privacy impact, given the business context of the interaction. You can object to this processing at any time (see Section 7).

3. International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA). We ensure that all international transfers of personal data are protected by appropriate safeguards as required by the GDPR, including:

  • The EU–US Data Privacy Framework (DPF) for certified US-based providers
  • Standard Contractual Clauses (SCCs) approved by the European Commission

Where possible, we select providers that process data within the EU. For a complete and up-to-date list of our sub-processors, please contact us at [email protected].

4. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law. Below are our retention periods:

Data CategoryRetention Period
Account dataRetained while your account is active, plus 30 days after account deletion
Payment and billing records7 years after the transaction (Dutch fiscal obligation)
Generated content (articles, images)Retained while your account is active; deleted 30 days after account closure
Analytics dataUp to 14 months
Lead capture data12 months if not converted to an account
Email notification logs90 days
Integration credentialsDeleted immediately upon removal by the user

5. Data Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of all data in transit and at rest
  • Access controls and authentication for all internal systems
  • Regular security reviews and updates
  • Use of reputable, security-certified service providers

6. AI-Specific Disclosures

Because our Service uses artificial intelligence, we want to be transparent about how it works:

  • Content you provide (topics, keywords, instructions) is processed through large language models to generate articles.
  • Your content is not used to train or fine-tune AI models. It is processed solely to generate the output you request.
  • AI-generated content may not be eligible for copyright protection under current EU law. You should seek independent legal advice if intellectual property ownership of AI-generated content is important to your use case.
  • AI-generated content may contain inaccuracies or errors. You are responsible for reviewing all AI output before publication.

7. Your Rights Under the GDPR

As a data subject, you have the following rights under the GDPR:

  • Right of access (Art. 15): You can request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): You can ask us to correct inaccurate or incomplete personal data.
  • Right to erasure (Art. 17): You can request the deletion of your personal data, subject to legal retention requirements.
  • Right to restriction (Art. 18): You can request that we limit the processing of your data in certain circumstances.
  • Right to data portability (Art. 20): You can request your personal data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21): You can object to processing based on legitimate interest, including for direct marketing purposes.
  • Right to withdraw consent (Art. 7(3)): Where we process data based on your consent (e.g. analytics), you can withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.

If you believe that we have not handled your data correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

8. Cookies

Our website uses cookies and similar technologies. Analytics cookies are only placed after you give explicit consent via our cookie banner. For a detailed overview of all cookies we use, their purposes, and how to manage them, please see our Cookie Policy.

9. Children’s Privacy

Our Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at [email protected] and we will promptly delete it.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by posting the updated policy on our website and updating the “Last updated” date below. We encourage you to review this policy periodically.

11. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

AI Content Plan
Email: [email protected]

Last updated: February 28, 2026