Privacy Policy
As of: June 2026 · DLA-DP-001
DLA-DP-001 · Version 1.0 · As of: June 2026 · Drion AI AG
Drion AI AG
Privacy Policy for Neos7.io As of: June 2026 Data protection and trust Welcome to Neos7.io. Neos7.io is a platform of Drion AI AG that combines modern technologies such as artificial intelligence, social media management, and digital communication solutions. Our aim is to provide companies, organizations, and individuals with powerful tools for creating, managing, and publishing digital content. The responsible handling of personal data is of great importance to us. We process personal data exclusively within the framework of applicable data protection laws and in accordance with the principles of lawfulness, transparency, purpose limitation, data minimization, and data security. Please also read our Terms and Conditions at DLA-AGB-001. This Privacy Policy informs you of
- which personal data we process,
- the reasons we need this data,
- how we protect your data,
- which rights you have, and
- whom you can contact with questions about data protection.
If technical, legal, or organizational changes occur, this Privacy Policy will be adapted accordingly. The current version published on Neos7.io shall apply in each case.
1. Controller
The controller for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR), the revised Swiss Federal Act on Data Protection (revDSG), and
the applicable national data protection provisions is: Drion AI AG Kantonstrasse 32 6207 Nottwil Switzerland Email: info@neos7.com Further information about the company can be found in the Imprint.
2. About Neos7.io
Neos7.io is an AI-supported platform for planning, creating, managing, and publishing digital content for various social networks.
The platform supports users in particular with:
- creating and optimizing posts,
- managing connected social media accounts,
- publishing content via supported platforms,
- using AI-supported assistance functions,
- participating in the Neos7 Points program.
Neos7.io is continuously developed technically in order to provide new functions, platforms, and integrations. Changes are made in compliance with applicable data protection and security requirements.
3. Collection and processing of personal data
Depending on the nature and scope of use of Neos7.io, different personal data are processed. Processing takes place exclusively within the framework of applicable data protection provisions and only insofar as it is necessary for the provision of the platform and its functions.
3.1 Visiting the website
When visiting the website, technical information is automatically processed that your
browser transmits to our servers. This includes in particular:
- IP address
- Date and time of access
- Browser type and browser version
- Operating system used
- Referrer URL (if transmitted)
- Pages accessed
- Technical log data
These data serve to provide the website, ensure system security, analyze errors, and protect against misuse. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
3.2 Registration and user account
Use of the Neos7.io platform requires the creation of a personal user account. In the course of registration, the following personal data may be processed – depending on the chosen method of registration –
in particular:
- First and last name (if provided)
- Username
- Email address
- Encrypted password (in the case of registration by email)
- Authentication information when using supported sign-in services (e.g.
Google or Facebook)
- Date and time of registration
- Language settings
- Account settings
These data are processed exclusively for the creation and administration of your user account, for authentication, for the provision of platform functions, and to ensure the security of your user account. Where users connect social media accounts with Neos7.io or publish content via connected platforms, the respective terms of use as well as age and participation requirements of the relevant platform operators apply in addition. Each user is responsible for complying with the requirements and provisions applicable to the services they use. Please also read our subscription terms at DLA-SUB-001
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps prior to entering into a contract).
3.3 Sign-in via third-party providers
Neos7.io supports – where available – sign-in via external
authentication services, for example:
When signing in via such a service, only those items of information are processed that are necessary for authentication and for creating your user account. Which data the respective provider transmits to Neos7.io depends on your settings with the respective provider and the permissions you have granted. The data processing by the respective authentication provider is additionally governed by that provider’s privacy policy.
3.4
Use of the platform During use of Neos7.io, those data are processed that are necessary for the provision of the functions offered. These include in particular:
- created posts,
- drafts,
- publication times,
- connected social media accounts,
- platform settings,
- usage logs,
- system events,
- error logs.
This processing takes place in order to provide the platform, to analyze errors, and to ensure secure and reliable operation.
3.5 Social media connections
Neos7.io enables connection to various social media platforms via their official application programming interfaces (APIs). At the time this Privacy Policy was prepared, the following platforms in particular are supported or are in the process of being integrated:
- X (formerly Twitter)
- TikTok
- Mastodon
- Discord
Further platforms, in particular Facebook and Instagram, may be added in the future. In connection with connected accounts, Neos7.io processes only those items of information that are necessary for authentication, publication of posts, and provision of the selected functions. Where statistics are processed, this is limited to information relating to posts published via Neos7.io. Private messages or other content of connected social media accounts are not read by Neos7.io unless this is expressly provided as a platform function and initiated by the user.
3.6
Neos7 Points In the context of the Neos7 Points program, user-related information is processed in order to enable participation in the bonus program. This includes in particular:
- user account,
- user activities within the platform,
- points balance,
- bonus history.
The data are generally stored for as long as your user account exists or statutory retention obligations prevent deletion.
3.7 Contact
If you contact us, for example by email or – after its introduction – via a contact form, we process the data you transmit solely for the purpose of handling your inquiry and communicating with you. Processing takes place on the basis of Art. 6(1)(b) GDPR (pre-contractual measures or performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in handling your inquiry).
4. Use of artificial intelligence (AI)
Neos7.io uses artificial intelligence (AI) functions to support users in creating, optimizing, and managing digital content. The AI functions may be used in particular for the following purposes:
- creation and optimization of texts,
- support in creating social media posts,
- analysis and structuring of content,
- creation of AI-generated images,
- provision of further AI-supported assistance functions.
To provide these services, both proprietary AI components of Drion AI AG and external AI technologies may be used. At the time this Privacy Policy was prepared, the following AI services in particular are used:
- DeepSeek to support chat and text functions,
- Grok to create AI-generated images.
The AI technologies used may, in the course of the technical further development of the platform, be supplemented or replaced by equivalent or further developed systems, provided that this does not materially change the purpose of the data processing. Inputs that users make in the context of the AI functions (e.g. text inputs or instructions) are processed only insofar as this is necessary to provide the respective function, to improve the user experience, and to further develop the platform. Please also read our provisions on the use of AI at DLA-AI-002. Drion AI AG also continuously further develops its own AI components and platform functions. Details of the internal system architecture and of technical security measures are not disclosed publicly for reasons of IT security and the protection of trade secrets. Where external AI technologies are used, their use takes place in compliance with applicable data protection provisions and solely within the scope of the processing of personal data required for the respective function.
5. Social media connections
Neos7.io enables users to connect their own accounts on supported social media platforms with their user account in order to create, manage, schedule, and – where supported – automatically publish content centrally. The connection to the respective platforms takes place exclusively via the official application programming interfaces (APIs) provided by the platform operators and after express authorization by the respective user. At the time this Privacy Policy was prepared, Neos7.io supports in particular the following platforms:
- X (formerly Twitter)
- TikTok
- Mastodon
- Discord
Further platforms, in particular Facebook and Instagram, may be added in the future. Planning and publication of posts Neos7.io enables users to create and edit posts and to schedule publications for a desired time. Publication takes place solely on behalf of the user and in accordance with the settings specified by the user via the connected social media accounts. For this purpose, Neos7.io processes only the data necessary to perform these functions. Scope of data processing In connection with connected social media accounts, Neos7.io processes only the data that are necessary to provide the functions selected by the user. These may include in particular:
- account designation or profile name,
- unique user or account identifiers,
- authorization information (access tokens),
- posts created or scheduled via Neos7.io,
- publication times,
- technical status information,
- statistical evaluations of posts published via Neos7.io.
Under the current range of functions, Neos7.io does not process private messages or direct messages of connected social media accounts unless the user expressly makes these available in the context of future functions. Responsibility of users Each user independently decides which social media accounts are connected with Neos7.io. For use of the respective platforms, their terms of use, privacy policies, and age and participation requirements apply in addition. Drion AI AG has no influence over data processing by the respective platform operators outside the functions provided via Neos7.io. Privacy notices of the connected social media platforms Further information on the processing of personal data by the respective platform operators can be found in their privacy policies:
- LinkedIn: https://www.linkedin.com/legal/privacy-policy
- X (formerly Twitter): https://x.com/en/privacy
- TikTok: https://www.tiktok.com/legal/privacy-policy
- Discord: https://discord.com/privacy
- Reddit: https://www.redditinc.com/policies/privacy-policy
- Mastodon: https://joinmastodon.org/privacy-policy
- Facebook: https://www.facebook.com/privacy/policy/
- Instagram: https://privacycenter.instagram.com/policy/
- Google: https://policies.google.com/privacy
- YouTube: https://www.youtube.com/howyoutubeworks/user-settings/privacy/
6. Neos7 Points
Neos7.io provides registered users with the platform’s own bonus program Neos7 Points. By using the platform, users may collect Neos7 Points in accordance with the applicable participation terms. Points are awarded exclusively for activities defined within the platform and serve to promote active use of the functions offered. To administer the bonus program, Drion AI AG processes in particular the following data:
- User account
- Username
- Email address
- Activities within the platform insofar as they are relevant to the awarding of points
- Current points balance
- History of credited and redeemed Neos7 Points
- Times of points credits or redemptions
These data are processed exclusively to operate and administer the Neos7 Points program, to calculate the points balance, and to provide the corresponding platform functions. Neos7 Points do not constitute legal tender or a financial instrument. They serve solely for use within the platform ecosystem operated by Drion AI AG and – subject to separate participation terms – do not confer any direct claim to payout. If a conversion of Neos7 Points into NB7 Utility Tokens is provided for in the future, the then-applicable participation terms and the relevant legal provisions shall apply in addition. The data are generally stored for as long as the user account exists or statutory retention obligations prevent deletion. Please also read the participation terms DLA-Points-001 Legal basis: The processing of personal data in the context of the Neos7 Points program takes place pursuant to Art. 6(1)(b) GDPR insofar as it is necessary for the performance of the user relationship and for the provision and administration of the bonus program.
7. NB7 Utility Token and wallet connection
Neos7.io offers users the possibility of connecting a compatible blockchain wallet with their user account in order to use functions in connection with the NB7 Utility Token. In the context of the wallet connection, the following data in particular may be processed:
- public wallet address,
- time of connecting and disconnecting the wallet,
- technical information for authenticating the wallet connection,
- information required to provide the respective platform functions.
Drion AI AG does not store private keys, seed phrases, or other access credentials to users’ wallets. Control over the wallet remains at all times exclusively with the respective user. The wallet address is processed solely to provide the platform functions offered and – where used by the user – to participate in the NB7 Utility Token system and the associated functions. Where blockchain transactions are carried out, they are processed via the respective blockchain. Drion AI AG has no influence over the processing of publicly available blockchain data by the respective blockchain network. Please also read the participation terms DLA-Token-001. Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps prior to entering into a contract).
8. Cookies and Google Analytics
Neos7.io uses cookies and comparable technologies to ensure the technical functionality of the platform, to improve usability, and to enable statistical evaluations of the use of the website and platform. Technically required cookies Technically necessary cookies are indispensable for the operation of the platform. They are used in particular to:
- enable user sign-in and authentication,
- maintain user sessions,
- store security settings,
- ensure the stability and functionality of the platform.
These cookies are required for the operation of Neos7.io and therefore cannot be disabled. Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in the secure and functional operation of the platform). Google Analytics To analyze and continuously improve our offering, Neos7.io uses Google Analytics, a web analytics service of Google Ireland Limited or Google LLC. Google Analytics may process in particular the following information:
- pages accessed,
- duration of visit,
- browser used,
- operating system,
- device type,
- approximate geographic origin (based on the IP address),
- interactions within the platform.
Where required by law, Google Analytics is used only after the user’s prior consent via the cookie consent procedure used on the website. Further information on data processing by Google can be found at: https://policies.google.com/privacy Legal basis: Art. 6(1)(a) GDPR (consent), where consent is required by law. Management of cookie settings Users may adjust their cookie settings at any time via the cookie consent tool on the website or withdraw consent already given with effect for the future. Cookies may also be deleted or blocked via the settings of the internet browser used. This may, however, result in individual functions of Neos7.io being available only to a limited extent or no longer being available.
9. Hosting and technical infrastructure
Neos7.io is operated on a cloud infrastructure of Amazon Web Services (AWS). The data required for the operation of the platform are processed in data centers within the European Union. The primary hosting location is currently in the AWS region Frankfurt (eu-central-1). The technical infrastructure serves in particular:
- provision of the website and platform,
- secure authentication of users,
- storage of user-related data,
- execution of platform functions,
- ensuring availability, stability, and IT security.
Drion AI AG implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or other unlawful processing. Where Amazon Web Services processes personal data as a processor, this takes place solely on the basis of a data processing agreement pursuant to Art. 28 GDPR. The choice of hosting location may be adjusted in the course of technical further development, provided that applicable data protection requirements are complied with. Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps prior to entering into a contract) and Art. 6(1)(f) GDPR (legitimate interest in the secure, high-performance, and reliable operation of the platform).
10. Storage period
Drion AI AG processes and stores personal data only for as long as is necessary for the fulfillment of the respective processing purposes, for the provision of the Neos7.io platform, or due to statutory retention obligations. The storage period depends in particular on the type of data processed:
- User account data are generally stored for the duration of the existing
user account.
- Neos7 Points as well as the associated transaction and administration processes
are generally stored for the duration of the user account, unless statutory retention obligations require longer storage.
- Wallet connection data are stored only for as long as is necessary for the
provision of the platform functions used by the user.
- Technical log and security data are stored only for the period
necessary to ensure system security, error analysis, and detection of misuse.
- Communication data transmitted in the context of support inquiries or
contact are deleted after the inquiry has been concluded, unless statutory retention obligations or legitimate interests prevent deletion. As soon as personal data are no longer required for the purposes stated and no statutory retention obligations exist, they are deleted or anonymized. Statutory retention periods, in particular commercial, tax, or other statutory documentation obligations, remain unaffected.
12. Transfers of data to third countries
The processing of personal data takes place in principle within the European Union (EU) or the European Economic Area (EEA). Where external service providers or platforms are used in the context of Neos7.io, a transfer of personal data to states outside the EU or the EEA (so-called third countries) may take place if this is necessary to provide the respective function. Such a transfer may take place in particular in connection with the following services:
- AI services,
- social media platforms,
- web analytics and statistics services,
- other technical service providers.
Where personal data are transferred to third countries, this takes place solely in compliance with applicable data protection provisions. Where required, appropriate safeguards pursuant to Art. 44 et seq. GDPR are provided. These include in particular:
- adequacy decisions of the European Commission,
- Standard Contractual Clauses (SCC),
- or other legally recognized safeguards for the protection of personal data.
Independently of this, it cannot be excluded that individual platform operators or service providers process personal data outside the European Economic Area in accordance with their own privacy policies. Drion AI AG has no influence over this data processing. Users can find further information in the respective privacy policies of the third-party providers used.
13. Data security
Drion AI AG takes appropriate technical and organizational measures (TOM) to protect personal data against loss, misuse, unauthorized access, unauthorized disclosure, alteration, or destruction. The security measures are reviewed regularly and continuously further developed taking into account technical progress and statutory requirements. The protective measures used by Drion AI AG include in particular:
- encrypted data transmission using current TLS/SSL encryption,
- role- and permission-based access concepts,
- protection of the IT infrastructure by suitable technical security measures,
- regular security reviews and system updates,
- logging of security-relevant events,
- measures to ensure the availability and integrity of the systems,
- organizational measures to protect personal data.
Access to personal data is permitted only to those persons who need these data to perform their respective tasks and who have been bound to confidentiality accordingly. Despite all technical and organizational measures taken, complete security of data transmission over the internet or of electronic storage systems cannot be guaranteed. Drion AI AG therefore continuously adapts its security measures to the state of the art and to new security requirements. Supplementary information on the technical and organizational measures may be made available to data subjects or authorized business partners upon request to the extent permitted by law, insofar as this does not impair security interests or trade secrets of Drion AI AG.
14. Rights of data subjects
Where the statutory requirements are met, you as a data subject have the following rights with regard to the processing of your personal data: Right of access You have the right to obtain confirmation as to whether and which personal data Drion AI AG processes about you (Art. 15 GDPR). Right to rectification You have the right to obtain the rectification of inaccurate or the completion of incomplete personal data (Art. 16 GDPR). Right to erasure You may, under the statutory conditions, request the erasure of your personal data (Art. 17 GDPR). Right to restriction of processing You have the right to obtain restriction of the processing of your personal data where the statutory requirements are met (Art. 18 GDPR). Right to data portability You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format or – where technically feasible – to have them transmitted to another controller (Art. 20 GDPR). Right to object You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR). Right to withdraw consent Where the processing of personal data is based on your consent, you may withdraw that consent at any time with effect for the future. The lawfulness of processing carried out until withdrawal remains unaffected. Exercising your rights To exercise your rights, you may contact Drion AI AG at any time. The contact details can be found in the Imprint and in the “Controller” section of this Privacy Policy.
15. Right to lodge a complaint
If you are of the opinion that the processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a competent data protection supervisory authority. For data subjects within the European Union, this right exists in particular pursuant to Art. 77 GDPR with the data protection supervisory authority of the Member State of their habitual residence, their place of work, or the place of the alleged infringement. For data subjects in Switzerland, it is possible to contact the Federal Data Protection and Information Commissioner (FDPIC). Independently of this, Drion AI AG welcomes the opportunity to clarify data protection questions or concerns with us first. You can reach us via the contact details stated in this Privacy Policy or in the Imprint.
16. Changes to this Privacy Policy
Drion AI AG reserves the right to adapt this Privacy Policy as needed, in particular where this becomes necessary due to technical further development of the Neos7.io platform, new functions, changed statutory requirements, or official requirements. The version of the Privacy Policy published on Neos7.io at the time of use shall be decisive in each case. In the event of material changes that affect the processing of personal data, registered users will – where required by law or technically possible – be informed of the changes in an appropriate manner. The current version of the Privacy Policy is available at any time on Neos7.io.
