ContentLab Privacy Policy
Effective date: 16 September 2026
ContentLab is a product of Skill Studio AI Limited
Websites: https://www.content-lab.ie/ and https://app.content-lab.ie/
1 About this Privacy Policy
This Privacy Policy explains how Skill Studio AI Limited, trading through its ContentLab product (ContentLab, we, us or our), collects, uses, shares and protects personal data when you visit our websites, create or use an account, subscribe to a plan, contact us, connect third-party services, or use ContentLab’s AI-assisted content generation, repurposing, scheduling and publishing services (the Service).
Skill Studio AI Limited is an Irish company with company number 786924, VAT number 4413103BH, and registered office at Unit 2, 2 Bridge Street, N37 F1W4, Athlone, Ireland. For the processing described in this Policy, we generally act as data controller. When a business customer submits personal data for us to process only on its instructions, the customer is the controller and we act as processor under the ContentLab Data Processing Agreement.
This Policy should be read with the ContentLab Terms and Conditions, Cookie Policy, Data Processing Agreement and Subprocessor List. It does not govern independent processing by third-party services you choose to connect.
2 Contact details
Detail
Information
Legal entity
Skill Studio AI Limited
Registered office
Unit 2, 2 Bridge Street, N37 F1W4, Athlone, Ireland
Company number
786924
VAT number
4413103BH
Privacy and support contact
help@skillstudio.ai
We have not appointed a Data Protection Officer because we have determined that appointment is not currently mandatory for our processing activities. Privacy enquiries and data-subject requests may be sent to the email above. We may request reasonable information to verify identity and locate relevant records.
3 Personal data we collect
3.1 Account and profile data
Name, email address, organisation, role, account identifiers, profile settings, team membership, authentication information and records showing acceptance of applicable terms.
3.2 Billing and subscription data
Plan, billing status, transaction history, billing name and address, VAT information, payment status and limited payment-method information returned by the payment provider. Full card numbers and security codes are handled by the payment provider and are not intended to be stored by ContentLab.
3.3 Customer Content and AI interaction data
Prompts, instructions, text, drafts, generated output, uploaded documents, images, audio or video, brand assets, content guidelines, audience and tone settings, editing history, feedback, content ideas, automation configurations and other material submitted to or produced through the Service. This material may contain personal data about you or other people.
3.4 Integration and publishing data
When you connect WordPress, Framer, Notion, Shopify, Intercom, Google services or another integration, we may process account and workspace identifiers, site information, access tokens, application passwords, permissions, publishing destinations, categories, content and delivery status. The precise data depends on the integration and permissions you approve.
3.5 Technical and usage data
IP address, browser and device type, operating system, timestamps, pages and features used, referring URLs, approximate location derived from IP address, diagnostics, performance events, security logs, cookie identifiers and similar technical information.
3.6 Communications and marketing data
Support requests, enquiries, feedback, meeting records, survey responses, contact-form submissions, communication preferences, marketing-consent records and email engagement data.
4 How we use personal data and our legal bases
Where we rely on legitimate interests, we assess necessity and balance our interests against your rights and expectations. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out lawfully.
5 AI processing and model providers
ContentLab uses third-party AI providers to generate, transform and analyse content at your request. Relevant prompts, Customer Content and context may be sent to Google Cloud services including Gemini and to OpenAI services, depending on the feature used. Those providers are required to process customer data under contractual restrictions and applicable data-protection obligations.
ContentLab does not use Customer Content to train general-purpose AI models, and our subprocessor policy requires AI providers not to use Customer Content for model training or improvement. You should avoid entering unnecessary personal data, special-category data or confidential information in prompts. AI output may be inaccurate or may reproduce personal data from submitted or public source material; review it before publication.
ContentLab does not use personal data to make solely automated decisions about individuals that produce legal or similarly significant effects.
6 Marketing communications and consent
Marketing email is sent only after explicit consent is verified through a double opt-in process. Verification links expire after 48 hours. We keep an audit record of consent requests, confirmations, refusals and withdrawals, including timestamp and IP address, for three years to demonstrate compliance. You may withdraw marketing consent at any time through an unsubscribe link, available account controls or by emailing us. Withdrawal is effective for future marketing communications; essential account, security, billing and service notices may still be sent.
7 Cookies and similar technologies
We use essential cookies for authentication, security and core preferences. Analytics and other non-essential technologies are disabled by default and used only after consent where required. You may change or withdraw your choice through the cookie controls made available on the relevant website or application. A separate Cookie Policy should identify each technology, provider, purpose and duration.
8 How we share personal data
We disclose personal data only where necessary to the following recipients:
Supabase for database, authentication and storage services;
Google Cloud, including Gemini, for cloud and AI functionality;
OpenAI for AI model and media-generation functionality;
Resend for transactional and consent-related email delivery;
payment, invoicing and fraud-prevention providers used for subscriptions;
third-party integrations and publishing destinations you choose to connect;
professional advisers, auditors and insurers subject to confidentiality obligations;
public authorities or courts where disclosure is legally required or reasonably necessary to protect rights and security; and
a buyer or successor in a financing, merger, reorganisation or sale, subject to appropriate safeguards.
We do not sell personal data. Current subprocessors and material changes should be maintained on the ContentLab Subprocessor List.
9 International transfers
Some recipients may process personal data outside the European Economic Area. Where the destination is not covered by a European Commission adequacy decision, we use an approved safeguard such as the European Commission Standard Contractual Clauses and supplementary measures where required. You may request information about relevant safeguards at help@skillstudio.ai.
10 Data retention
Category
Retention approach
Active account data
Retained while the account is active and as needed to provide the Service.
Inactive accounts
Deleted after two years of inactivity, with notice where practicable.
Customer Content and generated output
Retained while the account is active or until deleted by an authorised user, subject to legal holds and backup cycles.
Deleted data and backups
Deleted data is removed from active systems and scheduled to be purged from backups within 30 days.
Integration credentials
Retained until the integration is disconnected, the token expires or the account is closed, subject to limited security logs.
Transaction and tax records
Retained for the period required by Irish accounting and tax law.
Marketing verification tokens
Expire and are deleted after 48 hours.
Marketing consent audit logs
Retained for three years.
Security, diagnostic and support records
Retained only for a proportionate period based on security, support and legal requirements.
11 Security
We use technical and organisational measures designed to protect personal data, including TLS or HTTPS encryption in transit, encryption at rest for sensitive data, role-based access controls, row-level security where appropriate, secure authentication, monitoring, audit logging, backups, incident response and vendor due diligence. Access is limited to personnel and providers who need it for authorised purposes and are subject to confidentiality obligations. No system is completely secure, so users should use strong credentials and promptly report suspected unauthorised access to help@skillstudio.ai.
12 Your rights
Subject to the GDPR and applicable Irish law, you may have the right to:
access your personal data and information about its processing;
correct inaccurate or incomplete data;
request erasure in qualifying circumstances;
restrict processing in qualifying circumstances;
object to processing based on legitimate interests and object at any time to direct marketing;
receive personal data you provided in a structured, commonly used and machine-readable format where portability applies;
withdraw consent at any time; and
lodge a complaint with a supervisory authority.
Send requests to help@skillstudio.ai. We normally respond within one month, subject to permitted extensions. If we process your data solely for a ContentLab business customer, please contact that customer first; we will assist the customer in responding.
13 Complaints
You may complain to the Irish Data Protection Commission at 6 Pembroke Row, Dublin 2, D02 X963, Ireland, through https://www.dataprotection.ie/, or to another competent supervisory authority in the EU or EEA country where you live, work or believe an infringement occurred. We encourage you to contact us first so we can address the concern.
14 Children
ContentLab is intended for business users aged 18 or over and is not directed to children. If you believe a child has provided personal data to us, contact help@skillstudio.ai so we can investigate and take appropriate action.
15 Changes to this Policy
We may update this Policy to reflect changes to the Service, providers, law or processing practices. We will publish the updated version and revise the effective date. We will provide reasonable notice of material changes and obtain consent where legally required for a new use of personal data.
16 Contact
Skill Studio AI Limited, Unit 2, 2 Bridge Street, N37 F1W4, Athlone, Ireland. Company number: 786924. VAT number: 4413103BH.
Email: help@skillstudio.ai
Purpose
Typical data
GDPR legal basis
Create accounts and provide the Service
Account data, Customer Content, integration data
Contract; legitimate interests where the user acts for an organisation
Generate, edit, schedule and publish content
Prompts, Customer Content, output, settings and integration data
Contract; customer instructions where we act as processor
Administer subscriptions and payments
Account, billing and transaction data
Contract; legal obligation; legitimate interests in payment administration
Secure, troubleshoot and monitor the Service
Authentication, technical, usage and security data
Legitimate interests in security, resilience and fraud prevention; legal obligation where applicable
Provide support and operational communications
Account, communications and diagnostics
Contract; legitimate interests in customer support
Improve product performance and usability
Usage, diagnostics and feedback
Legitimate interests; consent where required; never beyond customer instructions for processor data
Send marketing communications
Contact, consent, preference and engagement data
Consent
Comply with law and resolve disputes
Relevant account, transaction, content and communications data
Legal obligation; legitimate interests in legal claims
