GDPR rights
Your data, your rights.
The core data-subject rights under GDPR are covered: you trigger the deletion of your account yourself in the app (Settings → Account); access and portability we grant on request via Contact, answered within 30 days per Art. 12(3) GDPR.
Data access
On request via Contact you receive a structured copy of the data we hold for your tenant.
Account deletion
You delete your account yourself in the app (Settings → Account), confirmed with a fresh second factor. Deletion cascades across our systems including rendered media, removes your posting-provider profile on a best-effort basis, and hard-deletes after a 30-day grace period — each step recorded in an erasure audit log.
Data portability
On request via Contact you receive your data in a machine-readable format — for migrating to another provider.
EU AI Act — Article 50
AI-generated content is labelled — by the pipeline, not by policy.
The EU AI Act (Art. 50) requires that AI-generated content be labelled as such. Entradigm enforces this in the publishing pipeline: every published cycle carries a footer badge rendered into the media itself plus a disclosure sentence appended to the caption in the post's language. The wording is fixed and the presence of the label cannot be switched off — if the disclosure cannot be applied, publishing fails rather than going out unlabelled. Where a platform offers its own synthetic-media flag (TikTok, YouTube), Entradigm sets it at dispatch.
Sub-processors
Who touches your data — visible, not hidden.
Exactly who processes which data, in which region and on which legal basis, is published in two places: the category table in this site's Privacy Policy and the full named register in the app's privacy policy. The overview below summarises that register; it invents nothing.
Cloudflare
Application edge, storage and embeddings (USA + EU). EU region available.
Supabase
Database + authentication. The database runs in the EU region.
Anthropic
Script and slide drafting (USA, EU Standard Contractual Clauses). Bring-your-own is live: add your Anthropic API key and cycles run on your account — verified on save, stored encrypted, never displayed again. Anthropic does not use these requests to train models.
AWS
Video rendering and GPU media generation (voice synthesis, music) — EU Frankfurt.
Upload-Post (TONVI TECH SL)
Cross-platform posting via an EU provider (Spain) — engaged only when you connect accounts. Your social-network OAuth lives there, never inside Entradigm. Data-processing agreement concluded.
Exa
Public-web industry signals (USA) — runs only on your opt-in consent.
We conclude data-processing agreements before a sub-processor touches any data, base third-country transfers on EU Standard Contractual Clauses (2021/914) plus supplementary measures, and announce new sub-processors at least 14 days in advance.
Encryption & hosting
EU-first, encrypted, passwordless.
EU jurisdiction first
The database runs in Supabase's EU region, media rendering and GPU generation on AWS in EU Frankfurt, and transactional email is sent from the EU (Ireland). Cloudflare provides the application edge, with an EU region available.
In-transit & at-rest
All in-transit traffic runs over TLS 1.3. Secrets — BYO keys and tokens — are encrypted at rest in Supabase Vault: never shown back, never logged, and resolved server-side only at the moment of use, never stored in workflow payloads or logs.
Passwordless + mandatory MFA
Sign-in via a one-time magic link plus a mandatory authenticator app (TOTP) as the second factor on every app session, with recovery codes and a fresh step-up before destructive actions like account deletion. There's no password that could leak, and the sign-in form is bot-protected.
Tenant isolation
Every request re-resolves your workspace membership from the live database — never trusted from a token or cookie. Row-level security fails closed, and each tenant's media lives under its own storage prefix, which doubles as the single-prefix GDPR erasure path.
Cost caps & abuse controls
Spending fails closed. Always.
A hard cost cap on every cycle
Every platform-managed cycle is subject to a hard $2.00 cost cap — the platform stops rather than overspending. And there is no silent overage on any plan: hard stop with an upgrade prompt, or a budget cap you set yourself.
Daily + monthly circuit-breakers
Every metered path — generation, posting, music, knowledge-base processing, the docs assistant — sits behind daily and monthly budget ceilings that fail closed: if a breaker can't be read, the platform refuses the spend instead of allowing it.
Rate-limited surfaces
Sign-in, account recovery, lead capture, social-account connection and the agent API are rate-limited per IP or per tenant, and the public forms are protected by Cloudflare Turnstile.
Supply chain & engineering assurance
How the platform itself is built.
Every change is gated
Static security analysis, dependency-vulnerability scanning, a seven-day quarantine on newly published dependencies, credential-leak checks and the full test suite run on every change — merges are blocked until green.
Signed commits, gated deploys
Commits are cryptographically signed, the main branch blocks force-pushes, and production deploys happen only through CI-gated release tags — no hand-pushed production code.
Production stays production
Production and test environments are strictly separated, with a runtime guard on every database call — test runs can never touch production data.
Legal
The documents in full.
You can find the full legal documents here: