GDPR and CCPA
Last updated September 2, 2026
This page explains how Aidelly handles obligations under the GDPR, the UK GDPR, and the CCPA as amended. The contractual detail is in the Data Processing Agreement; this is the plain-language version.
Which role we are in
For the content you create and the social accounts you connect, you are the controller and we are the processor. We handle that data on your instructions and do not decide what to do with it ourselves.
For your own account, billing records, and how you use the product, we are the controller. That is covered by the Privacy Policy.
If you are an agency, you are usually a processor for your own clients and we are your sub-processor. The DPA is written to work that way, because it is the normal arrangement here rather than an edge case.
Your rights
Under the GDPR you can ask for access to your personal data, its correction or deletion, a portable copy, restriction of processing, or object to processing. Under the CCPA you can ask what we collect and why, request deletion, and opt out of any sale or sharing of personal information.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is no opt-out to offer because there is nothing to opt out of.
We will not treat you differently for exercising any of these rights.
How to exercise them
Email privacy@aidelly.com. We will confirm receipt and respond within 30 days. If a request is complex and we need longer, we will tell you before that deadline rather than let it pass.
If your data is in a customer's workspace, for example because you commented on a post an agency published, we are the processor and cannot act on it directly. Tell us and we will identify the customer and pass the request to them, and we will help them fulfil it.
International transfers
Aidelly processes and stores customer data in the United States. The application runs on Vercel in AWS us-east-1 and the database and file storage run on Supabase in AWS us-east-2.
For personal data subject to the GDPR or the UK GDPR, transfers rely on the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, with the UK International Data Transfer Addendum where applicable. These are incorporated into the DPA.
We do not currently offer EU or UK data residency. If your assessment requires it, tell us so we can understand the demand rather than guess.
Sub-processors and AI providers
Every third party that can process customer data is listed at aidelly.ai/subprocessors, with what it does and what reaches it. That page is updated before a new sub-processor starts processing.
AI providers receive the prompts and content you ask Aidelly to generate or analyse. We do not use your content to train models for our own purposes.
What we do not have
We hold no SOC 2 or ISO 27001 certification, and we have not appointed a Data Protection Officer or an EU or UK representative under Articles 27 and 37. Where those are obligations rather than good practice, we will say so here once they apply to us. We would rather state this than let an assessment assume otherwise.
The measures we do have are described on the security page, including the ones we have not built yet.
Complaints
If you are unhappy with how we handled your data or your request, tell us at privacy@aidelly.com first so we can put it right. You also have the right to complain to your local supervisory authority, and you do not have to come to us before doing so.
Aidelly Corporation, a Delaware corporation. 8 The Green STE B, Dover, DE 19901. privacy@aidelly.com.