Privacy Policy
Published: 9 September 2026 · Last updated: 10 September 2026 · Effective: 9 October 2026 · Digitallwork.hu Kft. (company reg. no. 01-09-426906, VAT no. 32489819-2-43)
This policy is available in Hungarian and English. In case of any discrepancy, the Hungarian text prevails.
1. Data Controller
Content Ninja (the "Service") is an AI-powered content marketing tool for online stores. The Service creates social media content (text, images, video) and publishes it on the user's behalf to the user's own Facebook Pages and Instagram business accounts; composes and sends newsletters through the user's own newsletter provider account; publishes blog articles to the user's webshop; rewrites product descriptions and category page copy; creates advertising creatives; and performs keyword and topic research. The Service is available to businesses only. It is operated by:
- Company name
- Digitallwork.hu Kft.
- Registered seat
- 1118 Budapest, Pálinkás Antal u. 3/A FSZ/8, Hungary
- Company reg. number
- 01-09-426906
- VAT number
- 32489819-2-43
- Privacy contact
- support@getcontentninja.com
- Phone
- +36 20 283 8831
This policy covers both this marketing website (getcontentninja.com) and the Content Ninja application (app.getcontentninja.com). It is drawn up in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR"), the Hungarian Act CXII of 2011 on informational self-determination, and Act C of 2000 on accounting.
The contractual conditions of using the Service are set out in the Terms of Service; this Privacy Policy forms an integral part of them.
2. What data we process
2.1. Account and registration data
2.2. Payment data
2.3. Content data
2.4. Facebook / Instagram (Meta) data
When you connect your Facebook account via Facebook Login, we access and store the following data through the Meta Graph API:
- your long-lived user access token (stored encrypted);
- the list and identifiers of the Facebook Pages you manage and the Instagram business accounts linked to them;
- Page access tokens (stored encrypted);
- the identifiers and links of the posts published through the Service;
- performance statistics (insights) of your Pages, Instagram account and published posts (e.g. reach, impressions, engagement);
- comments on your published posts, so that you can view and manage them in the Service.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR). These tokens and identifiers are used exclusively to publish and manage the content you create in the Service and to show you the performance statistics and comments of that content — see Sections 3 and 4.
2.5. Newsletter integrations (MailerLite, SalesAutopilot)
2.6. Usage logs
2.7. Content Ninja newsletter
2.8. Website visitors – Meta Pixel
2.9. Data of prospects (website forms, demo requests)
2.10. Public surfaces (Ninja AI demo chat, sample post generator)
The demo-chat and sample-post pages can be used without logging in.
2.11. Ninja AI assistant conversations and memories
2.12. Support access to your account
For troubleshooting and customer support, a member of our staff may view your account from your perspective for a maximum of 60 minutes, in read-only mode. During such access no data is modified, no credits are consumed and no content is published. Every such access is logged (who, whose account, when, for how long and on what grounds).
Legal basis: performance of a contract and legitimate interest in the quality of support (Art. 6(1)(b) and (f) GDPR).
3. How we use your data — purposes and legal bases
We use the data described above for the following purposes:
- Providing the Service — generating content, publishing / scheduling it on your behalf to the social media accounts you connected, sending newsletters and publishing blog articles on your instruction, and displaying the performance statistics (insights) and comments of your published posts (performance of a contract);
- Invoicing and accounting (legal obligation);
- Product improvement and reliability — usage logs and aggregated statistics (legitimate interest);
- Sales contact with prospects — replying to form submissions, organising demos, making offers (steps prior to a contract, legitimate interest);
- Marketing on this website — Meta Pixel remarketing (consent).
Meta access tokens and Meta platform data are used exclusively to publish and manage the content you create in the Service. We do not sell them, do not share them with any third party beyond the processors listed in Section 5, and do not use them for advertising, profiling, or any purpose unrelated to the Service.
4. Meta permissions we request and why
When you connect your account with Facebook Login, we request the following permissions:
- pages_show_list — to list the Facebook Pages you manage so you can choose which one to connect;
- pages_manage_posts — to create, schedule and publish posts on your connected Page on your behalf;
- pages_read_engagement — to read your Page's content and basic engagement data needed for publishing and for verifying that posts went live;
- instagram_basic — to identify the Instagram business account linked to your Facebook Page;
- instagram_content_publish — to publish content to your connected Instagram business account;
- read_insights — to read the performance statistics (insights) of your Page and its posts and display them to you in the Service;
- instagram_manage_insights — to read the performance statistics (insights) of your Instagram business account and its posts and display them to you in the Service;
- pages_manage_engagement — to read and reply to comments on your Page's posts from within the Service;
- instagram_manage_comments — to read and reply to comments on your Instagram posts from within the Service.
You can revoke these permissions at any time in your Facebook settings (Settings & privacy → Settings → Business integrations) or by disconnecting the account inside the Content Ninja application.
5. Who we share data with (processors and sub-processors)
We use the following processors to provide the Service. We never sell your personal data to third parties.
| Processor | Location | Activity |
|---|---|---|
| Supabase, Inc. | EU region | Database, authentication, file storage |
| Vercel, Inc. | EU (Frankfurt) | Application hosting |
| Cloudflare, Inc. | USA | Domain and content delivery (CDN), protection |
| GitHub, Inc. | USA | Hosting of this marketing website |
| Stripe, Inc. | USA | Payment processing |
| KBOSS.hu Kft. (Szamlazz.hu) | Hungary | Invoicing |
| Meta Platforms, Inc. | USA / Ireland | Publishing to Facebook / Instagram; website marketing (Pixel) |
| OpenAI, Inc. | USA | AI text and image generation, analysis, research; converting voice dictation to text |
| Anthropic, PBC | USA | AI text generation, Ninja AI assistant |
| Google LLC | USA | AI text, image and video generation; retrieving search performance data from Google Search Console |
| Google Ireland Limited | Ireland, EU | Google Search Console API — retrieving the search data of the website you connect (read-only) |
| xAI Corp. | USA | AI video generation |
| Alibaba Cloud (Singapore) Private Limited | EU (Frankfurt) | AI video generation |
| Replicate, Inc. | USA | Image-to-animation generation |
| MiniMax (MiniMax AI) | Singapore | AI voice and music generation for narrated video |
| Shotstack Pty Ltd | Australia | Video composition and rendering |
| DataForSEO | Third country | Retrieving keyword and search data |
| MailerLite (UAB MailerLite) | Lithuania, EU | Newsletter delivery (in the customer's account), managing our own prospect list |
| SalesAutopilot Kft. | Hungary | Newsletter delivery in the customer's account |
| Mailjet (Sinch Email) | France, EU | Transactional e-mail delivery (account, billing and system notifications) |
| Fillout, Inc. | USA | Demo booking form |
| Sentry (Functional Software, Inc.) | EU region | Error logging |
When generating content, only the inputs required for generation (e.g. product data, prompts, brand settings, uploaded images) are sent to the AI providers — never your access tokens or account credentials. Under their contractual terms, the AI providers do not use the data submitted to them to train their models.
Note on Sentry: when an error occurs in the application, the technical details of that error (error message, page address, browser type, timestamp) are sent to Sentry's European servers so that we can fix it. We do not send IP addresses, cookies, form contents, or the part of the web address after the question mark. Purpose: bug fixing and operational reliability; legal basis: our legitimate interest; retention: 90 days at most.
Note on Google Search Console: if you connect your website via Google Sign-in, we retrieve the search data of your own webshop through the Google Search Console API — search queries, impressions, clicks, average position and landing page URLs — and display it to you on the Analytics screen of the application. This access is read-only: we do not write, modify or delete anything in your Search Console account. The transfer stays within the European Union (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), under Google's data processing terms. Connecting requires the authorisation of your own Google account, which you can withdraw at any time — either by disconnecting the integration in the application, or in your Google account settings. We store the access token encrypted and delete it immediately when the connection is removed; access ceases at the same moment. We retain the search data collected for 16 months at most — the period Google itself returns — after which it is deleted automatically. Purpose: measuring and reporting the search performance of your webshop; legal basis: performance of a contract (you requested the connection).
Note on voice dictation: in the app you can give instructions by voice in text fields and to the Ninja AI assistant. The recording is sent to OpenAI solely to convert it to text. We do not store the recording: it is not saved to any database or file storage, and nothing of it is kept after processing. We only record its length (in seconds, totalled per day) for the daily limit. Dictation is optional, and the microphone turns on only when the user starts it and the browser grants permission. Legal basis: performance of contract.
Note on Meta Platforms: when the Service publishes content to your Facebook Page or Instagram account, or reads insights and comments on your behalf, Meta Platforms processes that data as an independent data controller under its own privacy policy — not as our processor. Meta acts as our processor only in respect of the Meta Pixel used on this marketing website (see Section 10).
Note on your webshop and newsletter provider: UNAS, Shoprenter and your newsletter provider are your own systems. The Service reads from and writes to them using your access key, on your instruction. Their operators act as independent controllers under their own privacy policies.
6. Where we store your data, and how we protect it
- Storage in the EU: your data is stored within the European Union (Supabase EU region, Vercel Frankfurt).
- Third-country transfers: some of our processors operate outside the European Union. Transfers to the United States (Stripe, Meta, OpenAI, Anthropic, Google LLC, xAI, Replicate, GitHub, Cloudflare, Fillout) rely on the adequacy decision under the EU–US Data Privacy Framework and/or on the European Commission's Standard Contractual Clauses (SCC). Transfers to Singapore (MiniMax), Australia (Shotstack) and other third countries (DataForSEO) are based on the European Commission's Standard Contractual Clauses (SCC) with the necessary supplementary measures. Only the inputs of generation (text, image, narration script) are sent to these providers — never account identifiers or access tokens.
- Isolation: data is separated per user / workspace at the database level (row-level security, RLS).
- Encryption: all platform access tokens (Meta user and Page tokens, webshop and newsletter API keys) are stored encrypted using AES-256-GCM; data in transit is protected by TLS.
7. Retention and deletion
- Account and content data: retained while your account exists, then deleted within 30 days after account deletion.
- Meta access tokens and connected-account data: deleted immediately when you disconnect the account in the app, revoke the app's access in your Facebook settings, or delete your account.
- Connected webshop and newsletter keys: deleted immediately when the connection is removed.
- Google Search Console search data: 16 months at most, deleted automatically thereafter; access ceases immediately when you disconnect the integration.
- Invoicing data: retained for 8 years, as required by the Hungarian Accounting Act (Act C of 2000).
- Usage logs: retained while your account exists and for as long as they are necessary for troubleshooting, accounting for credit usage and preventing abuse; they are deleted thereafter.
- Data audit log: retained for up to 90 days (deleted automatically).
- Error logs (Sentry): retained for up to 90 days.
- Backups: retained for the duration of the backup cycle, for as long as it is necessary to be able to restore the most recent backups; deleted data disappears from the backups when that cycle expires.
- Prospect (lead) data: 24 months from the last meaningful contact.
- Public demo conversations: for as long as it is necessary to continue the demo, to verify coupon redemption and to prevent abuse.
- Newsletter data: retained until you unsubscribe.
You can request deletion of your data at any time, in any of the following ways:
- delete your account inside the Content Ninja application;
- send a deletion request to support@getcontentninja.com;
- remove the app's access in your Facebook settings (Settings & privacy → Settings → Business integrations) — this immediately invalidates the stored tokens.
Deletion requests are completed within 30 days at the latest, except for data we are legally required to retain (e.g. invoices). Step-by-step instructions are available on our Data Deletion Instructions page.
8. Your rights under the GDPR
Right of access — you may request information about the data we process about you.
Right to rectification — you may request the correction of inaccurate data.
Right to erasure — you may request deletion of your data where there is no longer a legal basis for processing.
Right to restriction of processing — you may request that processing be restricted in certain cases.
Right to data portability — you may request your data in a machine-readable format.
Right to object — you may object to processing based on legitimate interest.
Right to withdraw consent — for consent-based processing (newsletter, Meta Pixel), you may withdraw consent at any time without giving reasons; withdrawal does not affect the lawfulness of processing before the withdrawal.
You can exercise these rights by e-mailing support@getcontentninja.com. We respond to requests within 30 days at the latest.
8.1. Automated decision-making
We do not take decisions based solely on automated processing that produce legal effects concerning you. The AI features of the Service suggest and produce content; the decision to publish and use it is always yours.
8.2. Personal data breach
In the event of a personal data breach we notify the supervisory authority within the statutory deadline (72 hours from becoming aware of it) and — if the breach is likely to result in a high risk — the data subjects as well.
8.3. Data Protection Officer
Based on the nature of our activity, appointing a Data Protection Officer is not mandatory; for data protection matters you can reach us at support@getcontentninja.com.
8.4. Restriction by age and user group
The Service is available to businesses only; we do not knowingly process the data of persons under 18.
9. Complaints
If you believe we have infringed the rules on data processing, you may lodge a complaint with the Hungarian supervisory authority:
You may also bring the matter before a court, or complain to the supervisory authority of your own EU member state.
10. Cookies
10.1. Strictly necessary cookies
Cookies essential for the operation of the website and the application: maintaining the login session (Supabase session cookie), the security (CSRF) cookie of the connection flow, and the browser identifier that allows a conversation on the public demo surfaces to be continued. These do not require consent.
10.2. Marketing cookies (Meta Pixel)
The Meta Pixel places cookies in the visitor's browser for remarketing and advertising purposes. These are activated only with your explicit consent given in the cookie banner.
10.3. Managing cookies
You may modify or withdraw your cookie consent at any time via the cookie banner, and cookies can also be deleted or blocked individually in your browser settings.
11. Facebook / Meta platform clause
The application accesses the user's Pages and accounts through the Meta Platform (Facebook Login, Facebook Graph API, Instagram Graph API) solely for the purpose of publishing and managing content created by the user and displaying the performance statistics (insights) and comments of that content to the user. This access can be revoked at any time in the user's Facebook settings and within the application. The use and transfer of information received from Meta APIs adheres to the Meta Platform Terms and the applicable Meta Developer Policies.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by e-mail and publish the updated policy on this page. Changes are published at least 15 days before they take effect; where a new processor is engaged, we publish notice at least 30 days in advance, in line with Section 9 of Annex 1 to our Terms. This version is effective from 9 October 2026 (published on 9 September 2026, last updated on 10 September 2026). The policy is available in Hungarian and English; in case of any discrepancy, the Hungarian text prevails.
12.1. Change log
- 9 October 2026 — New processor added to Section 5: Alibaba Cloud (Singapore) Private Limited (Alibaba Cloud Model Studio) — AI video generation. We use the service through an endpoint running in the European Union (Frankfurt region), so no third-country transfer takes place. Only the prompt text and the reference images are sent for generation — never account identifiers, access tokens or customer lists. Published: 9 September 2026.
- 16 September 2026 — New processor added to Section 5: Google Ireland Limited (Google Search Console API). We retrieve the search data of the website you connect (search queries, impressions, clicks, average position, landing page URLs) with read-only access and display it on the Analytics screen of the application. A related retention entry was added to Section 7 (16 months at most). Published: 1 September 2026.
- 10 September 2026 — The activity of OpenAI, Inc. in Section 5 was extended with converting voice dictation to text, and a note on voice dictation was added below the table (we do not store the recording; we only record its length for the daily limit). No new processor. Published and effective: 10 September 2026.
- 20 August 2026 — First effective version of this policy (published on 3 August 2026).