Last updated: July 21, 2026
1. Data controller
The controller is We Are Content LLC (“Hepteon”, “we”), a limited liability company incorporated in the State of Delaware, USA (EIN 30-0890847). Mailing address: 1709 N Francisco Ave, Chicago, Illinois 60647, USA (correspondence only; no physical offices). Privacy contact: [email protected].
2. Scope and applicable law
We operate a 100% online platform worldwide. We apply a baseline standard under US law (including the privacy law of the State of Delaware and other applicable states). In addition, where the law requires it based on your location, we comply with the GDPR (EU/EEA), the UK GDPR (United Kingdom) and the CCPA/CPRA (California). If you reside elsewhere, we honor the equivalent rights your local law grants you; you can exercise them at the email indicated. In the event of conflict, the mandatory law applicable to your country prevails.
3. Roles: controller and processor
As controller, we process your account, billing and service-usage data.
As processor, when you upload or connect third-party data (for example, data of your own customers or of the sites you audit), you are the controller and we process it on your documented instructions, under our Data Processing Agreement (DPA), available at https://www.hepteon.com/en/data-processing-agreement-dpa/, which forms part of the Terms.
4. Data we process
- Identification and credentials (name, email, encrypted password).
- URLs and content of the sites you ask us to audit or manage.
- Data from accounts you connect (Google, social networks, CMS and online stores or ecommerce platforms) via OAuth authorizations.
- Technical and usage data (IP, logs, identifiers, activity on the platform).
- Billing data (payments are processed through Stripe; we do not store full card numbers).
5. Purposes and legal bases
| Purpose | Legal basis (GDPR art. 6; local equivalents) |
|---|---|
| Provide and operate the service; manage your account | Performance of a contract |
| Charging and billing | Performance of a contract / legal obligation |
| Security, fraud and abuse prevention | Legitimate interest |
| Product improvement and aggregate analytics | Legitimate interest / consent (depending on country) |
| Marketing communications | Consent (revocable at any time) |
| Compliance with legal and tax obligations | Legal obligation |
6. Connecting accounts and publishing content (Google Limited Use)
To provide the service, you can connect third-party accounts: Google services (for example, Search Console, Google Analytics, Google Ads, Google Tag Manager or the Google Business Profile, formerly Google My Business), social networks (for example, Facebook, Instagram, Threads, X/Twitter, LinkedIn, TikTok, YouTube, Pinterest, Snapchat, Reddit, Tumblr, WhatsApp Business, Telegram, Bluesky and Mastodon, among others), content management systems (CMS) and online stores or ecommerce platforms (for example, Shopify, WooCommerce, PrestaShop, Magento/Adobe Commerce, Wix, BigCommerce and VTEX, among others). On your instructions, Hepteon may access those accounts and publish, edit and manage content on them. Our use of information obtained through Google APIs complies with the Google API Services User Data Policy, including its “Limited Use” requirements: we do not use it for advertising, we do not sell it, we use it only to provide the features you request, and we do not use it to train artificial intelligence models. The processing of data obtained from other platforms and social networks is governed by each platform’s developer policies, with equivalent use requirements.
7. Recipients and processors
We share data, as necessary, with providers acting as processors under contract: Google, Stripe (payments), Cloudflare (security/CDN), DigitalOcean (hosting), AI model providers and SEO tools.
8. International transfers
As a global online platform, your data may be processed in the USA and other countries. When we transfer data from the EEA or the United Kingdom, we apply appropriate safeguards: the EU Standard Contractual Clauses (Decision 2021/914), the UK Addendum/IDTA and, where the provider is certified, the EU-US Data Privacy Framework. You can request a copy of the safeguards at [email protected].
9. Automated decisions and artificial intelligence
We use AI to generate content, audits and recommendations. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you (art. 22 GDPR). AI content is a suggestion subject to your review and approval; you retain final editorial responsibility.
10. Retention
We keep account data while the account is active; billing data for the legally required tax periods; and technical logs for limited periods. Afterwards, data is deleted or anonymized, unless there is a legal retention obligation.
11. Minors
The service is not intended for minors and we do not knowingly collect data from minors.
12. Security
We apply reasonable technical and organizational measures (encryption in transit, access controls, logs). Please safeguard your credentials.
13. Your rights
You may exercise the rights of access, rectification, erasure, objection, restriction, portability and withdrawal of consent; in California and other US states, to know, delete, correct and to opt out of the sale/sharing of your data. To exercise them, write to [email protected]; we will respond within the legal deadlines. You may lodge a complaint with your supervisory authority.
14. Changes to this policy
We may update this policy; we will publish the current version with its date and, if the change is material, we will notify you by reasonable means.
15. Sections based on your location
Users in the EU/EEA and United Kingdom (GDPR / UK GDPR)
Controller: We Are Content LLC (Delaware). EU representative (art. 27 GDPR) and UK representative: being appointed; in the meantime, you can contact us at [email protected]. Legal bases: section 5. Transfers: section 8. Rights: section 13. You may lodge a complaint with your country’s supervisory authority (for example, the AEPD in Spain or the ICO in the United Kingdom).
Users in California, USA (CCPA/CPRA)
Categories processed: identifiers, commercial information and network activity. We do not sell personal data nor “share” it for cross-context behavioral advertising; if we did, we would enable the “Do Not Sell or Share My Personal Information” link. Rights: to know, delete, correct and non-discrimination. Requests: [email protected].
Users in other countries
We honor the data protection rights your local law grants you and will handle your request at the email indicated, in accordance with the deadlines and requirements of that law.