Privacy Notice
Last updated: 19 August 2026
1. Who is responsible
Florian Kosel, Oserstrasse 22, 2130 Mistelbach, Austria, trading as ClubContent AI, is the data controller for the personal data described in this notice. Contact: florian.kosel@gmail.com.
2. What data we collect and why
- Account data (name, email address, login credentials, club membership and role) — to create and secure your account and provide the service. Legal basis: performance of a contract.
- Club and content data (club details, teams, players, sponsors, match information, uploaded logos and images, generated text and images) — to produce and store the content you request. Legal basis: performance of a contract.
- Integration credentials (access tokens for WordPress, Wix, Facebook, Instagram, LinkedIn, TikTok) — stored encrypted, used only to publish content on your instruction. Legal basis: performance of a contract.
- Support messages — to answer your questions. Legal basis: performance of a contract and legitimate interests.
- Usage and technical data (log entries, device identifiers, IP address, generation counts) — for security, fraud prevention, quota enforcement and improving the product. Legal basis: legitimate interests.
- Marketing communications — only if you opt in. Legal basis: consent, which you can withdraw at any time.
Payment data is collected and processed by Paddle as Merchant of Record; we receive only limited billing and subscription information.
3. Who we share data with
- Hosting and infrastructure providers that run the application and the database.
- AI providers that process the prompts and media needed to generate your content.
- Paddle.com, our Merchant of Record, for the sale of the product, subscription management, payments, tax compliance and invoicing.
- Third-party channels you connect (for example Meta, LinkedIn, TikTok, WordPress, Wix), which receive the content you choose to publish.
- Professional advisers (legal, accounting) and authorities where required by law.
We do not sell personal data.
4. International transfers
Some of our providers process data outside the EEA. Where that happens we rely on adequacy decisions or EU Standard Contractual Clauses together with appropriate additional safeguards.
5. Retention
We keep account and content data for as long as your account is active and for up to 30 days after deletion, unless a longer period is required for legal, tax or accounting purposes (invoicing records are kept for seven years under Austrian law). Log data is kept for up to 12 months. After that, data is deleted or anonymised.
6. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time. Write to florian.kosel@gmail.com and we will respond within one month. You also have the right to complain to a supervisory authority — in Austria, the Datenschutzbehörde (dsb.gv.at).
7. Security
We apply appropriate technical and organisational measures, including encryption in transit, encryption of stored integration credentials, row-level access controls in the database and role-based access to administrative functions.
8. Cookies
We use strictly necessary cookies and local storage to keep you signed in and to operate the checkout. We do not use advertising cookies. If we add analytics or marketing cookies in the future, we will ask for your consent first and provide a preference control.
9. Changes
We may update this notice. Material changes will be communicated by email or in the app.