Terms of Service Privacy Policy DPA Cookie Policy

Privacy Policy

Effective date: 1 October 2026 Version: 1.2

This Privacy Policy explains how contenteam OÜ (registry code 16044560, Ahtri tn 12, 10151 Tallinn, Estonia) ("we," "us," "the Provider") processes personal data in connection with the iGamingTextLab platform https://client.igamingtextlab.com (the "Platform").

1. Two roles: controller and processor

We process personal data in two different capacities:

As a controller — for data you provide when you register, use the Platform, communicate with us, or browse our website. We decide why and how this data is processed. This Policy explains that processing.

As a processor — for personal data you upload to the Platform for the purpose of a task (for example, a brief that contains names, contact details, or other personal data). For this data, you are the controller and we act on your documented instructions. This processing is governed by our Data Processing Agreement (DPA), which forms part of the Terms of Service. In case of conflict between this Policy and the DPA regarding processor data, the DPA prevails.

2. What data we collect

Data you give us:

  • Account data: name, email address, company name, password (hashed), preferred language.
  • Payment data: payment details, transaction identifiers, top-up amounts. We do not collect or store card numbers.
  • Task data: briefs, key queries, target GEO, tone of voice, editorial policies, and any files or links you upload. If your briefs contain personal data, you are responsible for having a lawful basis to share it with us.
  • Communication data: messages sent through the dashboard, by email, or through the Telegram bot, including the channel from which each message arrived.
  • Support data: any information you provide when you contact us.

Data we collect automatically:

  • Log data: IP address, browser type, operating system, pages visited, referrer, timestamps.
  • Usage data: which tasks you create, which modes you select, how you interact with the dashboard.
  • Cookie data: as described in Section 9 and in our Cookie Policy.

Data we do not collect: we do not collect special categories of data (health, biometric, political opinions, etc.) and we do not ask you to provide them.

3. Why we process your data and on what legal basis

Purpose Legal basis (GDPR Art. 6)
Creating and managing your account Performance of a contract (Art. 6(1)(b))
Producing and delivering the content you commission Performance of a contract (Art. 6(1)(b))
Processing payments and maintaining your balance Performance of a contract (Art. 6(1)(b))
Communicating with you about tasks, revisions, and support Performance of a contract (Art. 6(1)(b))
Sending service notifications (task status, acceptance reminders) Performance of a contract (Art. 6(1)(b))
Sending promotional emails (only if you opt in) Consent (Art. 6(1)(a)) — you may withdraw at any time
Preventing fraud, securing the Platform, and detecting abuse Legitimate interests (Art. 6(1)(f)) — our interest in protecting the Platform and its users
Complying with tax, accounting, and anti-money-laundering obligations Legal obligation (Art. 6(1)(c))
Improving the Platform through aggregated, de-identified analytics Legitimate interests (Art. 6(1)(f)) — our interest in understanding how the Platform is used

We do not use your data for automated decision-making that produces legal effects or similarly significantly affects you. Although we use AI tools to generate and proofread content, the final decision on whether a task is accepted, revised, or rejected is always made by a human — either you, as the User, or a human editor on our side. AI tools assist in production but do not make decisions that produce legal effects or similarly significantly affect you. You retain full control over acceptance, revision requests, and publication.

4. How long we keep your data

We keep personal data only as long as necessary for the purposes described above.

Data Retention period
Account data While your account is active, plus 30 days after deletion
Task data (as controller: task metadata) While your account is active, plus 30 days
Task data (as processor: briefs, uploaded files) Per your instructions; by default, deleted 90 days after task acceptance or termination
Payment and financial records 5 years after the end of the financial year (Estonian accounting law)
Communication data 3 years after the last message
Log data 12 months
Cookie data As described in Section 9 and in our Cookie Policy
Marketing consent records Duration of consent + 3 years (proof of consent)

When a retention period ends, we delete or anonymise the data.

5. Who we share data with

We share personal data only as necessary:

  • Sub-processors. We use third-party providers for hosting, cloud infrastructure, AI processing, email delivery, and analytics. A current list is available in our DPA. We require all sub-processors to provide adequate safeguards.
  • Professional advisers. Accountants, auditors, and lawyers, where necessary.
  • Authorities. Tax authorities, law enforcement, or supervisory bodies, where required by law. We will notify you unless prohibited.
  • Business transfers. If we merge, are acquired, or sell assets, data may be transferred to the successor, subject to this Policy.

We do not sell your personal data.

6. International transfers

Some of our sub-processors may process data outside the European Economic Area (EEA). Where this happens, we rely on:

  • an adequacy decision of the European Commission, or
  • Standard Contractual Clauses (SCCs) approved by the European Commission, or
  • another lawful transfer mechanism under Chapter V of the GDPR.

You may request a copy of the relevant safeguards by contacting us.

7. Security

We take the protection of your data seriously, but we do not claim certifications or audits we have not obtained. What we do implement:

  • Encryption of data in transit (TLS 1.2 or higher).
  • Encryption of data at rest on our production systems.
  • Access controls on a strict need-to-know basis, with role-based permissions.
  • Confidentiality obligations for all personnel with access to personal data.
  • Logging and monitoring of access to production systems.
  • Incident response procedures for detecting, containing, and notifying breaches.

If a personal data breach affects your data, we will notify you without undue delay and within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR.

Important: no method of transmission or storage is completely secure. We cannot guarantee absolute security.

8. Use of artificial intelligence

We use artificial intelligence (AI) tools in the Human-assisted AI and Human-assisted AI + proofreader working modes. The Fully manual mode does not use AI generation.

What data is processed by AI. When you create a task in an AI-assisted mode, the following data may be transmitted to our AI sub-processors for the purpose of generating or proofreading the text: your brief, key queries, target GEO, tone of voice, editorial policies, and any reference materials you upload. We do not transmit your account credentials, payment data, or communication history to AI tools.

What we do. We do not train, fine-tune, or otherwise develop any AI model on your data. We do not use your data for anything other than performing your task, and we do not knowingly pass it to anyone for training, model development, or similar purposes. Where an AI provider offers a setting that excludes submitted data from training or shortens its retention, we make reasonable efforts to use it.

What we cannot promise. The models we use are operated by third parties, the set of providers changes over time, and their own terms differ. What happens to data inside a provider's systems is outside our control and we cannot verify it: for what purposes it is processed there, where or to whom it may be passed on, how long it is kept, how outputs are marked, or whether it is used for that provider's own model development. We make reasonable efforts to prevent such use, but we do not guarantee it and do not accept responsibility for what happens on a provider's side.

If you do not want your materials to be transmitted to third-party AI providers at all, choose the Fully manual mode, which does not use AI generation.

Transparency and marking. Where AI-generated content is intended for publication on a matter of public interest, we will ensure that the output is marked in a machine-readable format and detectable as artificially generated or manipulated, in accordance with Article 50(2) of Regulation (EU) 2024/1689 (the EU AI Act).

AI-generated output may be inaccurate, incomplete, or unsuitable for your purposes. You are responsible for reviewing and verifying any content before using it, and for complying with all applicable disclosure requirements in the jurisdictions where you publish.

9. Cookies and similar technologies

We use cookies and similar technologies for:

  • Strictly necessary purposes — keeping you logged in, maintaining your session, remembering your language. These do not require consent.
  • Analytics — understanding how the Platform is used, which pages are visited, which features are used. These require consent.
  • Marketing — measuring the effectiveness of our communications. These require consent.

You can manage cookies through your browser settings. Disabling strictly necessary cookies may prevent the Platform from working properly.

We do not use cookies to track you across third-party websites for advertising purposes.

Full details are set out in our Cookie Policy.

10. Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your data, subject to legal retention obligations.
  • Restrict processing in certain circumstances.
  • Object to processing based on legitimate interests.
  • Data portability — receive your data in a structured, commonly used, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with a supervisory authority. In Estonia, this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, https://www.aki.ee/). You may also complain to the authority in your country of residence.

To exercise any of these rights, contact us at legal@contenteam.com.

If your data was uploaded by a customer of ours (i.e., you are a data subject whose data appears in a brief or task), please direct your request to that customer. We will assist them as their processor.

11. Notice for California residents

If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA/CPRA):

  • Right to know what categories of personal information we collect, the sources, the purposes, and the categories of third parties with whom we share it.
  • Right to delete personal information we have collected from you.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information. We do not sell or share your personal information.
  • Right to non-discrimination for exercising your rights.

To exercise these rights, contact legal@contenteam.com. We will verify your request using the information associated with your account.

The categories of personal information we collect are: identifiers (name, email, IP address), commercial information (payment and transaction data), internet activity (usage and log data), and professional information (company name). We disclose these categories to service providers for business purposes as described in Section 5.

12. Children

The Platform is not intended for persons under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice in the Platform interface at least 30 days before the changes take effect. The effective date at the top of this document indicates the current version.

14. Meta Marketing API integration

GTL Ads Automation is an internal tool used to manage iGamingTextLab's advertising campaigns through the Meta Marketing API.

The integration accesses authorized advertising accounts and associated Facebook Pages and Instagram accounts. It processes account identifiers, campaign settings, audiences, advertising creatives and performance metrics to create, update and analyze advertising campaigns.

Access tokens are stored locally with restricted access and are used to authenticate requests to Meta. Advertising data may be processed by service providers used to operate the automation. We do not sell this data.

We retain integration data only for as long as necessary to operate the tool and maintain advertising records. Access can be revoked through Meta's settings.

To request deletion of data stored by this integration, contact legal@contenteam.com with the subject "GTL Ads Automation — Data deletion" and identify the relevant advertising account. Revoking access or deleting locally stored data does not automatically delete campaigns or records held by Meta.

15. Contact

For any questions about this Policy or your personal data:

contenteam OÜ Ahtri tn 12, 10151 Tallinn, Estonia Email: legal@contenteam.com Data Protection Officer (if appointed): legal@contenteam.com

iGamingTextLab.com Terms of Service Privacy Policy DPA Cookie Policy Cookie settings
We use cookies for analytics. Cookies · Details