C Componi
Voice Profile
AI that learns how you write
Post Engine
From news to posts in your tone
Content Studio
Topic to post in 30s
Weekly Plan
5 drafts ready every Monday
Autopilot
6-level publishing
Engagement Inbox
Comments with Human-in-the-Loop
Analytics
Natural-language insights
For Agencies
Manage your clients' LinkedIn
Personal Branding
Thought leader without burnout
For Teams
Orchestrated employee advocacy
Enterprise
SSO, SCIM, compliance, SLA
Pricing Blog FAQ
Sign in Try free →
ITItalianoFRFrançaisDEDeutschESEspañol

Features

Voice Profile Post Engine Content Studio Weekly Plan Autopilot Engagement Inbox Analytics

Use Cases

For Agencies Personal Branding For Teams Enterprise
Pricing Blog FAQ
Sign in Try free →

Language

ITItalianoENEnglishFRFrançaisDEDeutschESEspañol
Home / Privacy Policy

Privacy Policy

How we process your personal data under EU Regulation 2016/679 (GDPR) and applicable law.

Last updated: April 18, 2026

⚠ Note: This document is a starter version based on GDPR and applicable EU law. For production launch, review by a qualified privacy and digital law practitioner is recommended for each target jurisdiction.

Table of contents

  1. 1. Data Controller
  2. 2. Data Protection Officer (DPO)
  3. 3. Categories of data processed
  4. 4. Purposes and legal basis of processing
  5. 5. Processing methods and security
  6. 6. Data recipients and external processors
  7. 7. Transfers outside the EU
  8. 8. Retention period
  9. 9. Data subject rights
  10. 10. Automated decisions and AI
  11. 11. Minors' data
  12. 12. Changes to the Privacy Policy

This Privacy Policy describes how {{COMPANY_LEGAL_NAME}} (hereinafter "Componi", "we") collects, uses, and protects personal data of users of the Componi platform available at www.componi.ai (hereinafter the "Service"). Processing is carried out in compliance with Regulation (EU) 2016/679 ("GDPR") and other applicable laws.

1. Data Controller

The Data Controller is {{COMPANY_LEGAL_NAME}}, with registered office at {{COMPANY_ADDRESS}}, VAT {{VAT_NUMBER}}, registered in the Company Register under REA {{REA}}. Contact: hello@componi.ai.

2. Data Protection Officer (DPO)

A Data Protection Officer has been appointed, reachable at {{DPO_EMAIL}} for any matter related to the processing of personal data or the exercise of data subject rights.

3. Categories of data processed

We process the following categories of personal data:

a) Registration data: first name, last name, email, hashed password, billing information for paid subscriptions.
b) LinkedIn integration data: via official OAuth we obtain access tokens, profile ID, public profile data (name, role, photo, headline), content of your posts and comments you have created, engagement metrics of your content.
c) User-generated content: drafts, corrections, content feedback, Voice Profile settings, configured RSS and news sources, editorial plans.
d) Service usage data: access logs, IP address, user-agent, visited pages, actions performed in the platform, date and time.
e) Payment data: processed directly by Stripe (external processor). We do not store full credit card numbers.

4. Purposes and legal basis of processing

Your data is processed for the following purposes:

Provision of the Service (Art. 6.1.b GDPR — contract performance): account creation and management, integration with LinkedIn via official APIs, AI-generated drafts, content publishing, subscription management.

Individual Voice Profile training (Art. 6.1.b GDPR): analysis of your posts and corrections to create and improve your personal Voice Profile. This data stays in your workspace and is not used to train public models or shared with other users.

Legal obligations (Art. 6.1.c GDPR): invoicing, tax and accounting compliance, responses to authority requests.

Legitimate interest (Art. 6.1.f GDPR): platform security, fraud and abuse prevention, Service improvement through aggregated and anonymized analysis, communications about features similar to those subscribed to.

Direct marketing (Art. 6.1.a GDPR — consent): newsletters, promotional and informational communications. Consent is revocable at any time via the unsubscribe link or by writing to hello@componi.ai.

5. Processing methods and security

Processing is performed using electronic tools, applying technical and organizational measures adequate to ensure confidentiality, integrity, availability, and resilience of systems. Specifically: encryption of data in transit (TLS 1.3) and at rest (AES-256), role-based access control, workspace segregation between users, access logs, encrypted backups with limited retention, periodic security testing.

6. Data recipients and external processors

Your data may be disclosed to the following parties, appointed as processors under Art. 28 GDPR:

• Cloud infrastructure providers: Amazon Web Services (AWS) — EU servers (Ireland and Frankfurt).
• Payment processor: Stripe Payments Europe, Ltd. (based in Ireland).
• AI model providers: Anthropic PBC and/or OpenAI, LLC for processing text generation requests. Prompts sent are not used to train public models (commercial agreements with zero or limited retention).
• LinkedIn API bridge: Zernio (in beta, official OAuth). Direct migration to LinkedIn Marketing Partner API is planned in Q3 2026.
• Operational tools: transactional email providers (e.g., Postmark/SendGrid), customer support tools (e.g., Intercom), aggregated analytics tools (e.g., PostHog, Plausible).

An updated list of sub-processors is available on request at {{DPO_EMAIL}}.

7. Transfers outside the EU

Some sub-processors (e.g., AI model providers) may process data outside the European Economic Area. In such cases, transfers are safeguarded by Standard Contractual Clauses approved by the European Commission (decision 2021/914), supplemented where necessary by additional technical measures (end-to-end encryption, pseudonymization). For US providers, where applicable, we rely on their certification under the EU-US Data Privacy Framework.

8. Retention period

Account data and generated content: retained for the duration of the contract and for 30 days after cancellation (restore and data export window), after which they are permanently deleted or anonymized.

Billing data: retained for 10 years, as required by Italian civil and tax law.

Security and audit logs: retained for 12 months.

Marketing data (newsletter): retained until consent is revoked.

9. Data subject rights

Under Articles 15–22 GDPR you have the right to:

• Access: obtain confirmation of processing and a copy of your personal data.
• Rectification: correct inaccurate or incomplete data.
• Erasure ("right to be forgotten"): obtain deletion of your data in the cases provided for.
• Restriction: request restriction of processing in specific circumstances.
• Portability: receive data in a structured, commonly used, machine-readable format. Componi offers direct export of generated content in account settings.
• Objection: object to processing based on legitimate interest or for marketing purposes.
• Withdraw consent: for consent-based processing, at any time.
• Complaint: lodge a complaint with the Italian Data Protection Authority (Garante Privacy — www.garanteprivacy.it) or the supervisory authority of your EU Member State.

To exercise your rights, write to {{DPO_EMAIL}}. We will respond within 30 days.

10. Automated decisions and AI

Componi uses AI systems to generate content drafts, suggest replies to comments, and provide analytics. These processes do NOT produce decisions with legal or significant effects on the user under Art. 22 GDPR: all outputs are editorial proposals that the user can accept, modify, or reject. The publication of AI-generated content always happens under user control (Human-in-the-Loop mode or Autopilot with safety guardrails configured by the user themselves).

11. Minors' data

The Service is not addressed to minors under 18. We do not knowingly collect minors' data. Should we become aware of having processed a minor's data, we will proceed with deletion.

12. Changes to the Privacy Policy

We reserve the right to modify this Privacy Policy to reflect regulatory updates or Service evolution. Substantial changes will be communicated via email and/or in-app notification at least 30 days in advance. The most up-to-date version is always available at www.componi.ai/privacy.html.
C Componi

The AI platform for LinkedIn that learns how you write, creates posts from industry news, and plans your content calendar.

Product

  • Voice Profile
  • Content Studio
  • Post Engine
  • Weekly Plan
  • Autopilot
  • Engagement Inbox
  • Analytics
  • Features

Use Cases

  • For Agencies
  • Personal Branding
  • For Teams
  • Enterprise

Resources

  • Blog
  • FAQ
  • Pricing
  • iOS App
  • Android App
  • Changelog
  • Roadmap

Company

  • About
  • Careers
  • Privacy
  • Terms
  • Cookie Policy

Contact

  • hello@componi.ai
  • LinkedIn
  • Twitter / X

© 2026 Componi · All rights reserved

Compose your LinkedIn.