Please note. This document is a general template provided for information only. It is not legal advice and has not been reviewed by a qualified lawyer for your jurisdiction or business. Have it reviewed and adapted before relying on it.
1. Introduction
This Privacy Policy explains how AutoPilot (“AutoPilot”, “we”, “us” or “our”) collects, uses, discloses, retains and protects personal information when you visit our website, create an account, or use the AutoPilot platform and related services (together, the “Services”). It also describes the choices available to you regarding our use of your personal information and how you can access, correct or delete it.
AutoPilot is an artificial-intelligence content marketing platform. The Services analyse a customer’s website and business, research search demand and competitors, produce written articles and accompanying visual assets, adapt that material for social media, schedule and publish it to connected destinations, and measure the resulting performance in order to refine future recommendations. Because the Services operate on material you supply and on publicly accessible information about your business, this policy addresses both personal information about you as a user and the broader body of data processed on your behalf.
We have written this policy to be read and understood rather than merely acknowledged. Where a term carries a specific legal meaning — “controller”, “processor”, “personal data”, “sale” — we use it in the sense given by the applicable law and explain the practical consequence in plain language alongside it.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Services. If you use the Services on behalf of an organisation, you represent that you have authority to accept this policy for that organisation and that you have made the relevant individuals aware of it.
2. Definitions
The following terms are used throughout this policy with the meanings given here.
- “Personal information” (or “personal data”) means any information relating to an identified or identifiable natural person. It includes obvious identifiers such as a name or email address, and less obvious ones such as an IP address or device identifier where these can be linked to an individual.
- “Processing” means any operation performed on personal information, whether or not by automated means — including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure and destruction.
- “Controller” means the party that determines the purposes and means of processing personal information.
- “Processor” means a party that processes personal information on behalf of a controller and on that controller’s documented instructions.
- “Sub-processor” means a third party engaged by a processor to carry out specific processing activities on behalf of the controller.
- “Customer Content” means the websites, text, images, brand materials, instructions and other material a customer submits to or connects with the Services, together with any personal information contained within it.
- “Output” means content generated by the Services, including articles, images, social posts, metadata and strategy documents.
- “De-identified information” means information that cannot reasonably be used to infer anything about, or be linked to, a particular individual or household.
3. Scope and roles
This policy applies to personal information we process in connection with the Services, including our marketing website, product interfaces, application programming interfaces, customer support channels, and communications we send you. It does not apply to third-party websites, platforms or services that you connect to AutoPilot or that we link to, each of which is governed by its own privacy practices.
3.1 Where we act as a controller
We act as a controller — meaning we determine why and how personal information is processed — in relation to information about you as a visitor to our website, as a prospective customer who contacts us, and as an account holder. This includes your name, contact details, billing information, authentication data, product usage telemetry, and correspondence with our team.
3.2 Where we act as a processor
We act as a processor — meaning we process information on your documented instructions — in relation to the Customer Content you place into the Services, and any personal information contained within it. If you upload a customer list, connect a social account containing audience data, or write content that mentions identifiable individuals, we process that material on your behalf and under your control. You remain responsible for having a lawful basis to provide it to us and for the accuracy of what you supply.
Where we act as a processor, our processing is additionally governed by the data processing terms that form part of our agreement with you. Where those terms conflict with this policy in respect of Customer Content, those terms take precedence.
3.3 Joint responsibilities
Some activities involve both roles. When we analyse aggregate usage of a feature to decide whether to keep building it, we act as a controller over that de-identified telemetry, even though the underlying activity occurred while we were processing your content as a processor. We keep these purposes separate and do not use Customer Content itself for product analytics.
4. Information we collect
We collect information in three ways: information you provide directly, information generated automatically as you use the Services, and information we receive from third parties acting on your instruction.
4.1 Information you provide
- Account information — your name, email address, password (stored only as a cryptographic hash), and any profile details you choose to add.
- Organisation information — company name, industry, size, role, and other business context supplied during setup or in the course of support.
- Website and business inputs — the URLs you connect, any brand guidance, tone instructions, product descriptions, target audience notes or reference material you supply.
- Content you create or edit — briefs, drafts, prompts, edits, approvals, comments and scheduling decisions made within the platform.
- Billing information — billing name, address, tax identifiers, and the last four digits and expiry of a payment card. Full card numbers are collected and stored by our payment processor and are never held on our systems.
- Communications — the content of enquiries, support requests, survey responses and any attachments you send us.
4.2 Information collected automatically
- Device and connection data — IP address, browser type and version, operating system, device type, screen characteristics, language and time zone.
- Usage data — pages and screens viewed, features used, actions taken, timestamps, session duration, referring pages and navigation paths.
- Performance and diagnostic data — error reports, crash traces, latency measurements and similar technical signals used to keep the Services reliable.
- Cookies and similar technologies — identifiers stored on your device as described in section 13.
4.3 Information from third parties
- Connected platforms — when you authorise AutoPilot to publish to a content management system or social network, we receive the access tokens and account metadata necessary to perform that publication, together with the performance metrics those platforms return.
- Publicly accessible sources — content retrieved from the website you connect, from competitor websites, and from search results, in order to perform analysis and research.
- Payment processor — confirmation of transaction status, subscription state and limited card metadata.
- Analytics and infrastructure providers — aggregated measurement and security signals relating to use of the Services.
4.4 Information we do not seek
We do not intentionally collect special categories of personal data — such as information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sexual orientation. Please do not submit such information to the Services unless it is strictly necessary and you have a lawful basis to do so. If we become aware that such information has been submitted without a lawful basis, we may delete it.
We also do not collect precise geolocation data, and we do not purchase personal information from data brokers for marketing purposes.
5. How we use information
We use personal information for the following purposes, and only where we have a lawful basis to do so:
- To provide the Services — creating and maintaining your account, authenticating you, analysing connected websites, generating strategies and content, producing images, scheduling and publishing material, and reporting on performance.
- To operate and improve the platform — monitoring reliability, diagnosing faults, testing changes, measuring feature adoption and prioritising development work.
- To provide support — responding to enquiries, investigating issues you report and communicating about the resolution.
- To administer billing — processing subscription payments, issuing invoices, managing renewals, refunds and collections.
- To communicate with you — sending service notices, security alerts, changes to terms, and, where permitted, marketing about features and offers you can opt out of at any time.
- To maintain security — detecting, investigating and preventing fraud, abuse, unauthorised access and other activity that threatens the Services or our users.
- To comply with legal obligations — meeting accounting, tax, regulatory and law-enforcement requirements, and establishing, exercising or defending legal claims.
We do not use the content you create in AutoPilot to advertise to you, and we do not sell personal information. Where we aggregate or de-identify information so that it no longer identifies any individual or customer, we may use it to understand usage patterns and improve the Services; we maintain such information in de-identified form and do not attempt to re-identify it.
If we intend to use personal information for a purpose materially different from those described here, we will provide notice and, where required, obtain your consent before doing so.
6. Legal bases for processing
If you are located in the European Economic Area, the United Kingdom or Switzerland, we rely on the following legal bases under the General Data Protection Regulation and equivalent legislation:
- Performance of a contract — to supply the Services you have subscribed to, administer your account and provide support.
- Legitimate interests — to secure and improve the Services, understand how they are used, prevent abuse, and market to business contacts in a proportionate way. We balance these interests against your rights and freedoms and do not rely on this basis where those rights override our interests.
- Consent — for non-essential cookies, certain marketing communications, and any processing that specifically requires it. Where we rely on consent, you may withdraw it at any time without affecting processing carried out beforehand.
- Legal obligation — to comply with laws applicable to us, including tax, accounting and lawful requests from competent authorities.
Where we rely on legitimate interests, we carry out a balancing assessment recording the interest pursued, why the processing is necessary to achieve it, and the impact on the individuals concerned. You may request a summary of the relevant assessment using the contact details in section 20.
7. Artificial intelligence processing
The Services use machine-learning models to analyse business context, plan content, generate written material and produce images. This section explains what that means for your information.
7.1 What is sent to models
To generate a strategy, article or image, we transmit the relevant inputs — such as your business profile, the topic brief, tone guidance and reference material — to the model provider configured for your workspace. We send only what is necessary to complete the requested task. We do not transmit your password, payment details or authentication tokens to model providers.
7.2 Training
We do not use Customer Content to train foundation models, and we contract with model providers on terms that prohibit them from using content submitted through our integration to train their models. Where we improve our own systems — for example, refining a prompt or a quality check — we do so using aggregated, de-identified signals rather than the substance of your content, unless you have explicitly asked us to review specific material as part of support.
7.3 Accuracy and human oversight
Generated content is probabilistic. It may contain inaccuracies, outdated statements or assertions that require verification, and it should be reviewed before publication. The Services provide approval controls for this purpose, and you remain responsible for the material you publish. We do not present generated output as professional advice of any kind.
7.4 Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Content prioritisation and scheduling recommendations produced by the Services are operational suggestions that you may accept, amend or reject.
7.5 Retention by model providers
Model providers may retain inputs and outputs for a limited period for abuse monitoring, after which they are deleted in accordance with the provider’s policy. We select providers whose retention periods are bounded and documented, and we do not enable optional features that extend retention for training purposes.
9. International data transfers
We operate internationally, and information may be transferred to, stored in and processed in countries other than the one in which you are located, including countries whose data protection laws differ from those of your jurisdiction.
Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland to a country not benefiting from an adequacy decision, we implement appropriate safeguards. These typically comprise the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum where relevant, and supplementary technical and organisational measures assessed on a case-by-case basis.
Our transfer assessments consider the laws and practices of the destination country, the nature of the information, the likelihood of access by public authorities, and the effectiveness of the technical measures applied — principally encryption in transit and at rest, and access controls that limit which personnel can read the information. You may request a copy of the relevant safeguards using the contact details in section 20.
10. Data retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting or reporting requirements. In determining retention periods we consider the volume, nature and sensitivity of the information, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and whether those purposes can be achieved by other means.
- Account records are retained for the life of the account and for a limited period afterwards to allow reactivation and to resolve disputes.
- Customer Content and business data are retained while your subscription is active. Following termination, they are deleted or irreversibly anonymised within a defined window, subject to any legal hold.
- Billing and transaction records are retained for the period required by tax and accounting law in the relevant jurisdiction, typically between six and ten years.
- Security, audit and access logs are retained for a limited period appropriate to their purpose, ordinarily not exceeding twelve months.
- Support correspondence is retained for as long as needed to resolve the matter and to maintain a record of the resolution.
- Marketing contact records are retained until you opt out, after which we keep a minimal suppression record so that we do not contact you again.
- Backups are cycled on a rolling schedule; information deleted from live systems persists in backups until those backups expire.
You may request deletion of your account and associated data as described in section 11. Where deletion is not immediately possible — for example because information is required for an ongoing legal claim — we will restrict processing of that information instead and delete it once the reason for retention has passed.
11. Your rights and choices
Depending on where you live, you may have some or all of the following rights in relation to your personal information:
- Access — to obtain confirmation of whether we process your personal information and to receive a copy of it.
- Rectification — to have inaccurate information corrected and incomplete information completed.
- Erasure — to have personal information deleted in certain circumstances.
- Restriction — to limit how we process your information in certain circumstances.
- Portability — to receive information you provided to us in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Objection — to object to processing based on legitimate interests, and to object at any time to processing for direct marketing.
- Withdrawal of consent — to withdraw consent where processing is based on it, without affecting the lawfulness of prior processing.
- Complaint — to lodge a complaint with your local supervisory authority.
11.1 How to exercise your rights
Contact us using the details in section 20. We will respond within the period required by applicable law, ordinarily within one month, and will tell you if we need longer and why. We may ask you to verify your identity before acting, in order to protect your information from unauthorised disclosure; the verification we request will be proportionate to the sensitivity of the information concerned. We will not discriminate against you for exercising your rights, and we do not charge a fee unless a request is manifestly unfounded or excessive.
You may use an authorised agent to submit a request where applicable law permits. We will ask for evidence of the agent’s authority and may contact you directly to confirm it.
11.2 Requests about customer data
Where we act as a processor on behalf of a customer, requests relating to that customer’s data should be directed to the customer. If you contact us directly, we will refer you to them and assist them in responding, as required by our agreement with them.
11.3 Appeals
If we decline a request, we will explain why. Where applicable law provides a right of appeal, you may ask us to reconsider by replying to our decision; a different reviewer will assess the appeal and respond within the statutory period.
11.4 Marketing preferences
You can opt out of marketing email at any time using the unsubscribe link in the message or by contacting us. Opting out does not affect service messages such as billing notices, security alerts and changes to terms, which are necessary to the provision of the Services.
12. Region-specific disclosures
12.1 European Economic Area, United Kingdom and Switzerland
The legal bases on which we rely are set out in section 6, and international transfer safeguards in section 9. You have the right to lodge a complaint with the supervisory authority in your country of residence, place of work or the place of an alleged infringement. Where we are required to appoint a representative or a data protection officer, their details are available on request.
12.2 California
Under the California Consumer Privacy Act as amended, California residents have the right to know what personal information is collected, used, disclosed and “sold” or shared; to delete personal information; to correct inaccurate information; to opt out of sale or sharing for cross-context behavioural advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising those rights.
We do not sell personal information and do not share it for cross-context behavioural advertising. The categories of personal information we collect, the sources, purposes and categories of recipients are described in sections 4, 5 and 8. We do not knowingly collect or process sensitive personal information for the purpose of inferring characteristics. Retention is described in section 10.
12.3 Other United States jurisdictions
Residents of states with comprehensive privacy legislation — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others as such laws take effect — have rights of access, correction, deletion, portability and opt-out of targeted advertising, sale and certain profiling. We honour these rights as described in section 11 and provide the appeal process described in section 11.3.
12.4 Brazil
Under the Lei Geral de Proteção de Dados, data subjects in Brazil have rights of confirmation and access, correction, anonymisation, blocking or deletion of unnecessary or excessive data, portability, information about sharing, and revocation of consent. Requests may be made using the contact details in section 20.
12.5 Canada
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act and applicable provincial legislation. You may request access to your personal information and challenge its accuracy, and you may direct any unresolved concern to the Office of the Privacy Commissioner of Canada.
12.6 Australia
We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988. You may request access to and correction of your personal information, and may complain to the Office of the Australian Information Commissioner if you are dissatisfied with our response.
14. Security
We maintain technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration and destruction. These include encryption of data in transit, encryption at rest for stored data, hashing of credentials using industry-standard algorithms, role-based access controls with least-privilege defaults, network isolation, logging and monitoring, dependency and vulnerability management, and periodic review of our controls.
Access to production systems is limited to personnel who require it for their role, is authenticated individually, is subject to multi-factor authentication, and is logged. Credentials and tokens for connected platforms are encrypted and are used only to perform the actions you have authorised. Personnel with access to personal information are bound by confidentiality obligations and receive periodic training.
14.1 Incident response
We maintain an incident response process covering detection, triage, containment, eradication, recovery and post-incident review. Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay. Where we act as a processor, we will notify the affected customer promptly so that they can meet their own obligations.
14.2 Your responsibilities
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials, for using a strong and unique password, for enabling any additional authentication factors we offer, for managing which users in your organisation have access, and for notifying us promptly if you suspect unauthorised access.
15. Children
The Services are intended for use by businesses and are not directed to children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it. Where local law sets a higher age of digital consent, we apply that age.
16. Third-party links and platforms
The Services may contain links to third-party websites and allow you to connect third-party platforms. We do not control those services and are not responsible for their content or privacy practices. Connecting a platform authorises the exchange of information between it and AutoPilot as described in sections 4 and 8; you may revoke that authorisation at any time through your AutoPilot settings or the third party’s own controls. We encourage you to review the privacy policy of any service you connect.
17. Personal information within your content
Content produced through the Services may reference identifiable individuals — a named expert, a quoted source, a customer described in a case study. Where that happens, you are the controller of that information and are responsible for ensuring there is a lawful basis for including it, that any required notice has been given, and that the depiction is accurate and not misleading.
If an individual contacts us about content published through your account, we will refer them to you and, where required, assist you in responding. We may remove or restrict access to content within the platform where we are legally required to do so, or where it plainly breaches our terms.
18. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we do, we will revise the date at the top of this page. If the changes are material, we will provide more prominent notice — by email to the address associated with your account, or by an in-product notice — before the changes take effect. We encourage you to review this page periodically. Where a change requires your consent under applicable law, we will obtain it before applying the change to you.
19. Complaints
If you are unhappy with how we have handled your personal information or a request you have made, please tell us first. Describe what happened and what outcome you are seeking, and we will investigate and respond. Most concerns are resolved at this stage.
If you remain dissatisfied, you may complain to the data protection authority in your jurisdiction. Doing so does not require you to have raised the matter with us first, though we would appreciate the opportunity to put things right.
20. Contact us
If you have questions about this Privacy Policy, wish to exercise your rights, would like our current sub-processor list, or would like a copy of the safeguards applied to international transfers, please contact us through the contact form on this website. Please include enough detail for us to identify the information concerned and the right you wish to exercise.
For requests relating to an account, please write from the email address associated with that account where possible — it allows us to verify you quickly and respond sooner.
Questions about this document? Get in touch.