Privacy Policy

This Privacy Policy explains what personal data Newspilot (operated by DataCrab AI, "we", "us") collects, how we use it, and your rights under applicable law including the EU General Data Protection Regulation (GDPR), the UK GDPR, and similar regulations.

Contents

  1. Scope & controller
  2. Personal data we collect
  3. How and why we use your data
  4. Legal basis for processing
  5. Sharing & sub-processors
  6. International transfers
  7. Data retention
  8. Security
  9. Your rights
  10. Children
  11. Changes to this policy
  12. Contact us

1. Scope & controller

This policy applies to the Newspilot website (newspilot.io) and the Newspilot platform. The data controller is DataCrab AI. You can reach us at privacy@newspilot.io.

2. Personal data we collect

We collect personal data in three contexts:

2.1 Information you give us

2.2 Information collected automatically

2.3 Information from third parties

3. How and why we use your data

PurposeLawful basis
Account, billing, service deliveryContract (Art. 6(1)(b))
Support & security communicationsLegitimate interest (Art. 6(1)(f))
Marketing emails to EU residentsConsent (Art. 6(1)(a))
Product analytics & improvementLegitimate interest, balanced against your rights
Legal & tax obligationsLegal obligation (Art. 6(1)(c))

5. Sharing & sub-processors

We share personal data only with sub-processors we contract to deliver the service. The current list (also available in our DPA):

Sub-processorPurposeRegion
Stripe, Inc.Payment processingUS · EU
Amazon Web ServicesHosting, storageEU (eu-central-1) · optional US/AZ
Cloudflare, Inc.CDN, DDoS protectionGlobal edge
PostmarkTransactional emailUS
Plausible AnalyticsPrivacy-friendly usage analyticsEU

We do not sell your personal data. We do not share it with advertisers.

6. International transfers

Newspilot is operated from the EU with primary data hosted in eu-central-1 (Frankfurt). Where data is transferred outside the EEA (for example to US sub-processors), we rely on EU Standard Contractual Clauses (2021) and supplementary measures including encryption in transit and at rest.

Enterprise customers can opt into a dedicated EU-only or AZ-residency deployment via contract.

7. Data retention

8. Security

We use industry-standard technical and organisational measures including TLS 1.3 in transit, AES-256 at rest, customer-data isolation at the database level, principle-of-least-privilege access, mandatory MFA for staff, and audit logging.

Specific compliance certifications and audit reports are available under NDA. Contact security@newspilot.io.

9. Your rights

Under the GDPR and similar laws you have the right to:

Email privacy@newspilot.io to exercise any of these rights. We respond within 30 days.

10. Children

Newspilot is a B2B product not intended for anyone under 18. We do not knowingly collect personal data from children.

11. Changes to this policy

We update this policy when our practices change. Material changes are notified by email to account holders at least 30 days before they take effect. The "Last updated" date at the top reflects the latest revision.

12. Contact us

Privacy questions: privacy@newspilot.io

Security disclosures: security@newspilot.io

General contact: hello@newspilot.io