Privacy Policy
EasyBiz Social
Version 1.1 — Effective: March 22, 2026
Plain Language Summary
What EasyBiz Social does with your data — in simple terms:
EasyBiz Social is a social media management tool that uses AI to help you create and publish posts. Here's what you need to know about your privacy:
What we collect:
- Account info: Email address for login
- Brand info: Your company name, description, and logo
- Your content: Posts, photos, ideas, and schedules you create
- Social media connections: OAuth tokens for Facebook, Instagram, etc.
Where your data goes:
- Our server: A dedicated server in Germany stores your account, content, and brand data
- Google AI (Gemini): Brand info and content are sent to Google for AI text and image generation (US servers)
- Meta (Facebook/Instagram): Posts and images are sent to Meta when you publish
- EmailLabs: Your email address is used for account verification (Poland)
You're in control:
- Access your data: Request a copy at any time
- Delete everything: Request account deletion
- Disconnect platforms: Revoke social media access at any time
Important:
- Content sent to Google AI is processed on US servers — we rely on Standard Contractual Clauses (SCCs) as the legal safeguard
- We do not use cookies on the marketing website (social.easybiz.pl)
- We do not sell your data to anyone
Questions?
Contact us at: contact@codepublishing.eu
Full Privacy Policy
This Service collects some Personal Data from its Users.
This document contains sections dedicated to Users in the European Union regarding their privacy rights under Regulation (EU) 2016/679 (General Data Protection Regulation).
Owner and Data Controller
Code Publishing sp. z o.o.
ul. Fabryczna 6
54-609 Wroclaw, Poland
KRS: 0001046452 | NIP: 8971924946 | REGON: 525831482
Contact email: contact@codepublishing.eu
No Data Protection Officer (DPO) has been appointed. For all privacy-related inquiries, please contact the Owner at the email address provided above.
Types of Data Collected
Among the types of Personal Data that this Service collects, by itself or through third parties, there are:
- Account Data (required): Email address, password (stored as bcrypt hash — we never store your password in plain text), user identifier, language and theme preferences
- Brand Data (provided by User): Company name, website URL, brand description, brand voice keywords, logo image
- Content Data (provided by User): Social media post text, photos, content ideas, event dates, scheduled publication dates, post type categories
- Social Media Data (required for publishing): OAuth access tokens for connected platforms (Facebook, Instagram), external account/page identifiers, account display names, profile images
- AI Interaction Data (generated during use): AI prompts used for text and image generation, AI-generated text and images, generation error messages
- Technical Data (collected automatically): IP address (during authentication), session tokens, timestamps
Data obtained from third parties: When Users connect their social media accounts, the Service may receive profile information (display names, profile images, page identifiers) from Meta Platforms via the Graph API. This data is obtained with the User's explicit authorization through OAuth.
Mode and Place of Processing the Data
Methods of Processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and IT-enabled tools, following organizational procedures and modes strictly related to the purposes indicated. Passwords are hashed using bcrypt. Authentication uses JWT tokens with HMAC-SHA512 signing.
Place
The primary server infrastructure is located in the European Union. However, certain data is transmitted to third-party processors located outside the EU for specific purposes:
- Application server and database: Germany (Hetzner Online GmbH)
- File storage: Germany (Hetzner Online GmbH)
- AI processing: United States (Google Gemini API)
- Social media publishing: Ireland / United States (Meta Platforms)
- Transactional email: Poland (EmailLabs / Vercom S.A.)
Retention Time
- Account Data: Retained for the duration of the account
- Brand Data: Retained until User deletes the brand or the account
- Content Data: Retained until User deletes the content or the account
- Social Media Tokens: Retained until User disconnects the platform or the account is deleted; Facebook long-lived page tokens do not expire but are revoked upon disconnection
- AI Interaction Data: Retained as part of the associated post; deleted when the post is deleted
- Technical Data (sessions): Retained for the duration of the session; expired sessions are periodically purged
- Consent Records: Retained for 3 years after account deletion (in accordance with the general limitation period under Article 118 of the Polish Civil Code)
The Purposes of Processing
The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests, detect any malicious or fraudulent activity, as well as the following:
- Registration and authentication: Creating and managing User accounts, email verification, password reset
- Brand management: Storing and displaying User's brand profiles and visual identity
- AI content generation: Transmitting brand information, content, and photos to Google Gemini for text and image generation
- Social media publishing: Transmitting posts and images to connected social media platforms for publication
- Content management: Storing, organizing, and scheduling User's content
- Legal compliance: Meeting GDPR and other regulatory requirements
Legal Bases for Processing
| Purpose | Legal Basis (GDPR) |
|---|---|
| Account registration, authentication, service delivery | Art. 6(1)(b) — performance of a contract |
| AI content generation (sending data to Google Gemini) | Art. 6(1)(b) — performance of a contract (core service feature) |
| Social media publishing (sending data to Meta) | Art. 6(1)(b) — performance of a contract (core service feature) |
| Transactional emails (verification, password reset) | Art. 6(1)(b) — performance of a contract |
| Establishing/defending against legal claims | Art. 6(1)(f) — legitimate interest |
| Legal compliance, consent record retention | Art. 6(1)(c) — legal obligation |
Detailed Information on the Processing of Personal Data
Registration and Authentication
Internal Authentication (Serverpod Auth)
This Service uses our internal backend system for User registration and login. Passwords are hashed with bcrypt and a secret pepper. Authentication tokens are signed with HMAC-SHA512.
Personal Data processed: Email address, user identifier, password hash, authentication tokens
Place of processing: European Union
EmailLabs — Vercom S.A.
Transactional emails for email verification codes and password reset codes.
Personal Data processed: Email address
Place of processing: Poland — Privacy Policy
AI Content Generation
Google Gemini (Google LLC)
This Service uses Google's Generative AI API (Gemini) for text post generation, image generation, photo analysis and tagging, and brand analysis. When Users generate content, the following data may be sent to Google:
- Brand name, description, website URL, and voice keywords
- User's content prompts and preferences
- Photos (for AI analysis and tagging)
- Previously generated content (for context)
Personal Data processed: Brand information, content, photos, prompts
Place of processing: United States — Privacy Policy
API: generativelanguage.googleapis.com (Google AI Studio)
Note: Google's Generative AI API is accessed via the global endpoint. Data may be processed on servers located in the United States. The transfer is governed by Standard Contractual Clauses (SCCs) as adopted by the European Commission.
Social Media Publishing
Meta Platforms, Inc. (Facebook & Instagram)
This Service connects to Facebook and Instagram via Meta's Graph API (v22.0) to publish posts and manage pages. When Users connect their social media accounts and publish content:
- OAuth authorization grants the Service access to User's pages
- Post text, images, and metadata are transmitted to Meta for publication
- Long-lived page access tokens are stored to maintain the connection
Personal Data processed: OAuth tokens, page identifiers, post content, images
Place of processing: Ireland / United States — Privacy Policy
Hosting and File Storage
Hetzner Online GmbH
Hetzner provides the cloud server infrastructure on which the application server, database, and file storage run.
Personal Data processed: All data described in this policy
Place of processing: Germany — Privacy Policy
International Data Transfers
The majority of User data is stored and processed within the European Union. However, certain data is transferred to third parties located outside the EEA:
| Recipient | Location | Data Transferred | Safeguard |
|---|---|---|---|
| Google LLC (Gemini AI) | United States | Brand info, content, photos, prompts | Standard Contractual Clauses (SCCs) |
| Meta Platforms, Inc. | Ireland / United States | Post content, images, OAuth tokens | EU-US Data Privacy Framework / SCCs |
International data transfers have been preceded by a Transfer Impact Assessment (TIA) in accordance with EDPB guidelines, taking into account the nature of the data transferred, the purposes of processing, and the technical and organizational safeguards in place.
In the event that the EU-US Data Privacy Framework is invalidated by the Court of Justice of the European Union, transfers to Meta Platforms will continue to be safeguarded by Standard Contractual Clauses (SCCs).
We do not sell, rent, or otherwise share Personal Data with third parties for their own marketing purposes.
Cookies and Local Storage
The marketing website (social.easybiz.pl) does not use cookies. It uses browser localStorage solely to remember the User's language preference (lang key with value "pl" or "en"). This is not considered a cookie under Directive 2002/58/EC but is disclosed here for transparency.
The application (app.social.easybiz.pl) uses essential technical storage only — authentication tokens stored in the browser to maintain the login session. No analytics, advertising, or third-party tracking cookies are used.
The Rights of Users Based on the GDPR
Users may exercise certain rights regarding their Data processed by the Owner. In particular, Users have the right to:
- Withdraw their consent at any time
- Object to processing of their Data
- Access their Data: Obtain disclosure and a copy of the Data
- Verify and seek rectification: Verify accuracy and request updates
- Restrict the processing of their Data
- Have their Personal Data deleted
- Receive their Data and have it transferred to another controller
- Lodge a complaint with a data protection authority
Right to Object (Article 21 GDPR)
Where Personal Data is processed on the basis of legitimate interest (Article 6(1)(f) GDPR), Users have the right to object to such processing at any time, on grounds relating to their particular situation. The Owner will cease processing unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the User, or for the establishment, exercise, or defense of legal claims.
How to Exercise These Rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered within one month, as required by GDPR Article 12(3).
Account Deletion
Since accounts are created and managed by an administrator, Users can request account deletion by contacting the Owner at contact@codepublishing.eu. The Owner will process the deletion request without undue delay. Upon deletion:
- All User data is permanently removed (brand profiles, content, social media connections)
- OAuth tokens for connected platforms are revoked
- Files in storage are deleted
- Consent records are retained for 3 years (in accordance with the general limitation period under Article 118 of the Polish Civil Code)
Supervisory Authority
Users in the EU have the right to lodge a complaint with the supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement. In Poland, the supervisory authority is:
Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2
00-193 Warszawa, Poland
https://uodo.gov.pl/
Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to the rights and freedoms of Users, the Owner will notify affected Users without undue delay, as required by GDPR Article 34. Notification will be sent to the email address associated with the User's account.
The Owner will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
Automated Decision-Making
This Service uses AI (Google Gemini) to generate content suggestions. However, no automated decisions with legal or similarly significant effects are made about Users. AI-generated content is always presented as a suggestion that the User must review and approve before publication. The User retains full control over what is published.
Terms of Service
To learn more about the terms and conditions governing the use of this Service, please refer to our Terms of Service.
Changes to This Privacy Policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page. Should the changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User, where required.
Contact
Code Publishing sp. z o.o.
Email: contact@codepublishing.eu
Address: ul. Fabryczna 6, 54-609 Wroclaw, Poland
Language Versions
This document is available in English and Polish. Both language versions are equally binding. In the event of discrepancies, the parties shall seek to resolve any ambiguity by reference to both versions together.