This is a non-binding English translation for convenience. The German version is the only legally binding one. German version
Privacy Policy
Information on the processing of your personal data in accordance with the GDPR.
1. Controller
The controller within the meaning of the GDPR is:
FHC+P GmbH
Würmstraße 55
82166 Gräfelfing
Germany
E-mail: datenschutz@fhcp.de, Web: www.fhcp.de
2. Provision of the application and log files
Each time the application is accessed, our system automatically collects data from the accessing computer (browser type/version, operating system, IP address, date/time of access, referrer). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in functionality and security). Log files are deleted after seven days at the latest, or the IP address is anonymised. No evaluation for marketing purposes takes place.
3. User account and registration
To use the service, you create an account. We process your e-mail address, a cryptographic hash of your password as well as API keys generated by you (stored exclusively as a hash). For billing and abuse prevention, we keep a usage log (time, function accessed, consumption). The legal basis is Art. 6(1)(b) GDPR (performance of contract). To confirm the e-mail address, we send a confirmation link.
4. Your content and publication on channels
Content created by you (texts, images, videos) and the associated media files are stored in your account so that you can edit, schedule and publish them. Storage takes place on our systems within the EU. The legal basis is Art. 6(1)(b) GDPR.
To publish, you connect social network accounts or web destinations (e.g. X, LinkedIn, Facebook/Instagram, TikTok, YouTube, Mastodon, WordPress). For this purpose, we store the access tokens issued by the respective platform (encrypted). When publishing, we transmit the content you have released, on your instructions, to the selected platform; the latter processes the data as a separate controller under its own terms. You can disconnect connections at any time.
5. AI-supported functions (optional)
If you use AI functions (e.g. text preparation, image preparation, suggestions, transcription), the affected content is transmitted for processing to the AI provider configured in your account. Depending on the selected provider, processing may take place outside the EU, in particular in the USA. If processing takes place with a provider in a third country without an adequacy decision (in particular OpenRouter, Inc. in the USA), we base the transfer on the Standard Contractual Clauses issued by the European Commission (Art. 46(2)(c) GDPR) together with supplementary protective measures; a Transfer Impact Assessment is carried out prior to the first transfer. Before first use, we point this out to you separately and obtain your confirmation. Use is voluntary; without this function, no such transmission takes place. The legal basis is Art. 6(1)(b) GDPR as well as your confirmation.
6. Billing and invoices (Stripe, e-invoice)
For chargeable services we use the payment service provider Stripe (Stripe Payments Europe, Ltd., Ireland). In the case of a purchase, the data required for payment is processed directly by Stripe; we do not receive your complete payment method details. For your purchases, we create invoices (on request as an electronic invoice in the ZUGFeRD/Factur-X format); generation takes place on our systems in Germany. The legal basis is Art. 6(1)(b) GDPR; statutory retention obligations (e.g. Section 147 AO) may apply.
7. Hosting
The service is operated in a data centre within Germany (Hostinger International Ltd). A data processing agreement pursuant to Art. 28 GDPR exists with the hosting service provider. The processing and storage of the data, including backups, takes place exclusively on servers within the EU. The legal basis is Art. 6(1)(f) GDPR (secure and stable operation).
8. Processing of your data on your behalf
Insofar as you process personal data of third parties via the service, you are the controller for this and FHC+P GmbH is the processor. For this we provide a data processing agreement (Art. 28 GDPR). The technical and organisational measures include, among others, transport encryption (TLS/HTTPS), access and authorisation controls, account-based data separation at database level (row-level security), encrypted storage of access tokens (AES-256-GCM) as well as regular, integrity-checked backups. If we use providers in third countries for AI functions, we safeguard the transfer by means of the EU Standard Contractual Clauses together with supplementary protective measures (see section 5).
9. Cookies
We use a technically necessary session cookie to maintain your login for the duration of the session. We do not use tracking or marketing cookies. The legal basis is Art. 6(1)(f) GDPR. The fonts used are delivered locally from our server.
10. Storage period and erasure
We store your account and content data for as long as your account exists and you use the service (Art. 6(1)(b) GDPR). We delete or anonymise access log files after seven days at the latest (see section 2).
If you delete your workspace in the settings, it is immediately blocked and marked for deletion. Final deletion takes place automatically after 30 days have elapsed; the date is displayed to you. Within this period you can cancel the deletion yourself and continue using the workspace. The period protects you against accidental or unauthorised deletion; the legal basis is Art. 6(1)(f) GDPR (legitimate interest in a secure deletion process). At your express request, we will also delete before the period expires; to do so, please contact datenschutz@fhcp.de.
With final deletion, we irrevocably remove your content, media files, topic and analytics data, the stored access tokens of your connected channels as well as the user accounts of your workspace. You can then no longer access them via the application and we cannot restore any of them. In the technical backups, your data is still contained for up to 14 days beyond this; there it serves exclusively for recovery in the event of a malfunction, is not further processed and expires automatically with the backup cycle.
Invoices and the associated accounting data are excepted: we must retain these for up to ten years due to commercial and tax law obligations (including Section 147 AO, Section 14b UStG). Upon deletion, they are separated from your workspace, kept solely for these statutory purposes and deleted after the retention periods have expired. The legal basis is Art. 6(1)(c) GDPR; the right to erasure is restricted in this respect under Art. 17(3)(b) GDPR.
Content that you have already published on third-party channels cannot be deleted by us there; please contact the respective platform for this.
11. Rights of the data subject
You have the following rights vis-a-vis the controller:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future
12. Google Ads conversion measurement (server-side)
If you reach our website via a Google ad, Google appends a click identifier (parameter "gclid") to the target URL. We store this value exclusively locally in your browser (local storage) and, if you register, as technically necessary with your account. If you subsequently complete an action (registration or first chargeable purchase), we transmit this click identifier server-side together with the type and, where applicable, the value of the action to Google (Google Ireland Ltd. or Google LLC) in order to measure the effectiveness of our advertising.
No cookies are stored on or read from your device in this process, so that the storage/access requirement of Section 25 TDDDG is not triggered, and no cross-device profile is created. However, the server-side route does not replace consent: we treat the transfer to Google as separate processing and, when uploading, transmit the consent signals required by Google (advertising user data, personalisation). As long as you have not given consent, these signals are transmitted as "unspecified", so that Google only uses your click for aggregated, non-personal modelling. The legal basis for the server-side performance measurement is Art. 6(1)(f) GDPR (legitimate interest in measuring the success of our advertising); your legitimate interest is matched by a right to object under Art. 21 GDPR. The recipient is Google Ireland Limited; a data transfer to the USA (Google LLC) on the basis of the EU standard contractual clauses or the EU-US Data Privacy Framework is possible. You can object to the processing at any time by e-mail to datenschutz@fhcp.de; you can remove the stored click identifier by clearing your local browser storage.
13. Right to lodge a complaint
Without prejudice to any other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your place of residence, place of work or the place of the alleged infringement.
14. Contact
If you have any questions about data protection, you can reach us at datenschutz@fhcp.de.
15. Google and YouTube data (YouTube API Services)
When you connect your YouTube account to personativ, personativ uses the YouTube API Services. By using it you also agree to the YouTube Terms of Service (https://www.youtube.com/t/terms); the Google Privacy Policy applies (https://policies.google.com/privacy).
We access only data from your connected account and only on your action: your channel and video list (to attribute uploads and show basic metrics), uploading videos and shorts you created, uploading captions you generated and setting the thumbnail on your own videos, and YouTube Analytics (impressions, click-through rate, watch time) for reports and a thumbnail A/B test.
Limited Use: personativ's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not share this data with third parties, do not use it for advertising or for any purpose other than the features described, and do not allow humans to read it except as required by law, for security, or with your explicit consent.
Revocation and deletion: you can revoke access at any time at https://myaccount.google.com/permissions. On request or when the account is disconnected, we delete the associated credentials and retrieved YouTube data from personativ.
