Last updated: September 6, 2025
CloutPilot is designed with privacy as a fundamental principle. We process data locally on your devices, comply with GDPR and Belgian privacy laws, and do not store your social media credentials. This comprehensive policy explains our data practices and your rights under EU privacy law.
The data controller responsible for processing your personal data is the operator of CloutPilot, a company incorporated under Belgian law. As a Belgian entity, we are subject to the General Data Protection Regulation (GDPR) and Belgian data protection laws.
For any questions, concerns, or requests regarding your personal data or this Privacy Policy, please contact us through the official support channels available on our website. We are committed to responding to your inquiries within the timeframes required by GDPR.
In accordance with GDPR requirements, we have appointed a Data Protection Officer (DPO) to oversee our data protection practices. You may contact our DPO for any privacy-related concerns through our official support channels.
As a Belgian company, our lead supervisory authority is the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit). You have the right to lodge complaints with this authority or your local EU data protection authority.
When you create an account with CloutPilot, we collect:
For paid services, we collect and process:
To provide, secure, and improve our Service, we automatically collect:
To provide automation services, we store:
When you contact us for support or communicate with us:
We explicitly DO NOT collect, store, or have access to:
We do not intentionally collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or data concerning sexual orientation) unless explicitly necessary for specific service features and with your explicit consent.
Under GDPR, we must have a legal basis for processing your personal data. We process your data based on the following legal bases and for the following purposes:
Processing necessary to perform our contract with you:
Processing based on our legitimate interests (balanced against your rights):
Processing based on your explicit consent:
You can withdraw your consent at any time through your account settings or by contacting us.
Processing required to comply with legal obligations:
In exceptional circumstances, we may process data to protect someone's vital interests, such as in medical emergencies or to prevent serious harm.
Where we rely on legitimate interests, we have conducted balancing tests to ensure our interests do not override your fundamental rights and freedoms. You can request details of these assessments by contacting us.
We share personal data with trusted third-party service providers who process data on our behalf under strict contractual obligations:
All service providers are bound by Data Processing Agreements (DPAs) that require GDPR compliance, appropriate security measures, and restrictions on data use.
We may disclose personal data when required by law or to protect legitimate interests:
We will challenge disproportionate or inappropriate requests and will notify affected users where legally permitted.
In the event of a merger, acquisition, reorganization, or sale of assets, personal data may be transferred to the new entity. Any such transfer will be subject to appropriate safeguards and notification requirements under GDPR. The receiving entity will be required to honor the commitments made in this Privacy Policy.
We never share or sell your personal data for:
We may share data with other companies in our corporate group for internal administration, consolidated reporting, and service improvement, always under the same privacy protection standards as outlined in this policy.
We conduct regular audits and assessments of our data processors to ensure ongoing compliance with GDPR requirements. All processors are contractually required to implement appropriate technical and organizational measures to protect personal data.
Your personal data is primarily processed and stored within the European Union. Our primary data centers are located in Germany and Ireland, providing enhanced data protection under EU law. We maintain data residency within the EU wherever possible to provide maximum privacy protection.
In limited circumstances, some of our service providers may process data outside the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place:
We conduct Transfer Impact Assessments (TIAs) to evaluate the level of protection in destination countries and implement supplementary measures where necessary. These assessments consider local laws, surveillance practices, and available legal remedies.
For any US-based processors, we ensure compliance with applicable frameworks and implement additional safeguards including encryption, pseudonymization, and strict contractual limitations on data access and use.
You have the right to request information about international transfers of your data and to obtain copies of the safeguards we have put in place. Contact us if you have specific concerns about data transfers.
We implement industry-leading technical security measures to protect your personal data:
We maintain strict organizational controls to protect personal data:
We implement privacy by design principles in all our systems and processes, including data minimization, purpose limitation, and privacy-friendly default settings. Our local processing architecture ensures that sensitive data remains on your devices wherever possible.
Our security practices align with international standards including ISO 27001, SOC 2, and other industry frameworks. We undergo regular independent security audits and maintain compliance certifications.
In the unlikely event of a personal data breach, we have comprehensive incident response procedures in place. We will notify the relevant supervisory authority within 72 hours as required by GDPR and will inform affected data subjects without undue delay when the breach is likely to result in high risk to rights and freedoms.
While we implement robust security measures, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we continuously work to improve our security posture and respond to emerging threats.
As a data subject under GDPR, you have comprehensive rights regarding your personal data. We are committed to facilitating the exercise of these rights:
Request a copy of your personal data and information about how it's processed
Correct inaccurate or incomplete personal data
Request deletion of your personal data ("right to be forgotten")
Limit how we process your personal data in certain circumstances
Receive your data in a structured, machine-readable format
Object to processing based on legitimate interests or for direct marketing
Withdraw consent for processing at any time
File complaints with supervisory authorities
To exercise any of these rights, contact us through our official support channels. We will respond to your request within one month (extendable by two additional months for complex requests). We may require identity verification to protect your data security.
These rights are not absolute and may be limited by law or where necessary for important public interests, legal compliance, or the protection of rights and freedoms of others. We will explain any limitations when responding to your requests.
We will not charge fees for reasonable requests to exercise your rights. However, we may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests, or provide further copies of information already provided.
For all data subject requests, please use our official support channels. Include "Data Subject Request" in your subject line and provide sufficient information for us to verify your identity and locate your data. We are committed to processing all legitimate requests promptly and in accordance with GDPR requirements.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. We regularly review our data retention needs and delete data when it is no longer required.
When you close your account or request data deletion, we will delete your personal data within 30 days, except for data we are legally required to retain. You will have the opportunity to export your data before deletion. Some data may be retained in anonymized form for statistical purposes.
Deleted data may remain in encrypted backups for up to 90 days for disaster recovery purposes. This backup data is not accessible for normal business operations and is subject to the same security measures as live data.
In case of legal proceedings, regulatory investigations, or potential claims, we may need to retain relevant data beyond normal retention periods. Such data will be securely stored and access will be limited to authorized personnel.
We regularly review our data retention schedules to ensure they remain appropriate and compliant with evolving legal requirements. We may update retention periods based on business needs, legal changes, or technological developments.
Cookies are small text files stored on your device when you visit our website. We also use similar technologies such as local storage, session storage, and web beacons. These technologies help us provide and improve our Service.
Essential for website functionality, security, and providing requested services. These cannot be disabled.
Remember your preferences and settings to enhance your experience.
Help us understand how visitors interact with our website to improve functionality and user experience.
Used to deliver relevant advertising and measure campaign effectiveness (only with your consent).
We use a cookie consent management platform that allows you to control which cookies you accept. You can change your preferences at any time through our cookie settings or by clearing your browser cookies.
Some cookies are set by third-party services we use. These are governed by the privacy policies of those third parties. We carefully select partners and require them to comply with privacy regulations.
You can control cookies through your browser settings, our cookie preference center, or by using browser extensions. Note that disabling certain cookies may affect website functionality.
Our Service is not intended for children under 16 years of age (or the minimum age specified by local law in your jurisdiction). We do not knowingly collect personal information from children under this age without appropriate parental consent.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will take steps to remove such information and terminate the child's account if necessary.
Where we do process children's data with appropriate consent, we apply enhanced privacy protections including additional security measures, limited data collection, and special retention policies.
If our Service is used in educational settings involving minors, we work with schools and educational institutions to ensure appropriate safeguards and parental notifications are in place.
We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities as required by GDPR Article 35. These assessments help us identify and mitigate privacy risks before implementing new systems or processes.
We have identified and assessed potential high-risk processing activities including automated decision-making, large-scale processing of personal data, and any new technologies that may affect individual privacy.
Based on our DPIAs, we implement appropriate technical and organizational measures to reduce identified risks, including privacy by design principles, data minimization, and enhanced security controls.
Where required, we consult with supervisory authorities on high-risk processing activities and regularly review our DPIAs to ensure they remain current and effective.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. We will provide appropriate notice of material changes as required by law.
For significant changes that affect your rights, we will notify you through email, prominent notices in our Service, or other appropriate communication methods at least 30 days before the changes take effect.
Each version of this Privacy Policy is dated and archived. You can request previous versions of this policy to understand how our practices have evolved over time.
Your continued use of our Service after we publish or send a notice about changes to this Privacy Policy means that you consent to the updated Privacy Policy to the extent permitted by law.
For any questions about this Privacy Policy, our data practices, or to exercise your rights under GDPR, please contact us through our official support channels available on our website. We are committed to responding promptly and thoroughly to all privacy-related inquiries.
You have the right to lodge a complaint with a data protection supervisory authority if you believe we have violated your privacy rights:
Belgium: Autorité de protection des données / Gegevensbeschermingsautoriteit
EU Data Protection Authorities: You may also contact the supervisory authority in your EU member state
Website: https://edpb.europa.eu/about-edpb/board/members_en for a complete list
We will acknowledge receipt of your inquiry within 2 business days and provide a substantive response within 30 days (or 3 months for complex requests, with explanation of the delay).
We are committed to protecting your privacy and handling your personal data responsibly and transparently. Our privacy-first design ensures your sensitive information remains secure and under your control. We comply with the highest standards of data protection under GDPR and Belgian law.
This Privacy Policy has been prepared in accordance with GDPR, Belgian data protection law, and other applicable EU privacy regulations. We continuously monitor legal developments to ensure ongoing compliance with evolving privacy requirements.
We use cookies for functionality and analytics.Privacy Policy