GDPR Compliance

Last Updated: January 4, 2026

Author Central is committed to full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page explains how we meet our obligations as a data controller and processor, and how you can exercise your rights.

1. Data Controller

CoreLogic AI Ltd (Registered in England & Wales, No: 16919694) is the data controller for personal data collected through the Author Central platform. This means we determine how and why your personal data is processed.

For data protection enquiries, contact us at: privacy@authorcentral.net

2. Lawful Basis for Processing

We process personal data under the following lawful bases:

a)

Consent (Art. 6(1)(a)): When you subscribe to author newsletters, sign up for bonus content, or opt into marketing communications.

b)

Contract (Art. 6(1)(b)): When you create an account, purchase books, or use our paid services — processing is necessary to deliver the service you requested.

c)

Legal Obligation (Art. 6(1)(c)): When we must process data to comply with tax, accounting, or other legal requirements.

d)

Legitimate Interests (Art. 6(1)(f)): For analytics, fraud prevention, platform security, and improving our services — balanced against your rights and expectations.

3. Your Rights Under GDPR

You have the following rights regarding your personal data:

Right of Access

Request a copy of the personal data we hold about you (Art. 15).

Right to Rectification

Correct inaccurate or incomplete personal data (Art. 16).

Right to Erasure

Request deletion of your personal data ("right to be forgotten") (Art. 17).

Right to Restriction

Limit how we process your data in certain circumstances (Art. 18).

Right to Data Portability

Receive your data in a structured, machine-readable format (Art. 20).

Right to Object

Object to processing based on legitimate interests or direct marketing (Art. 21).

Right to Withdraw Consent

Withdraw consent at any time without affecting prior processing (Art. 7(3)).

Right to Lodge a Complaint

Complain to your local supervisory authority or the ICO (Art. 77).

To exercise any of these rights, email privacy@authorcentral.net. We respond within one month, as required by GDPR.

4. Personal Data We Process

For Authors (Account Holders)

Name, email, password (hashed), author profile information, book content, payment data (processed by Stripe), and usage analytics.

For Readers (Subscribers)

Email address, name (if provided), reading engagement data, and email open/click metrics. Note: Authors are the data controller for subscriber data they collect through their companion pages; we act as processor on their behalf.

For Shop Customers

Name, email, shipping address, and order history. Payment card data is handled by Stripe — we never store full card numbers.

5. International Data Transfers

Your data may be transferred to and processed in countries outside the EU/EEA (e.g. the United States for cloud hosting and payment processing). We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, and we only work with processors that provide an adequate level of data protection.

6. Cookies and Tracking Technologies

We use cookies and similar technologies for functionality, analytics, and (with consent) advertising. We comply with the ePrivacy Directive (Cookie Law) by:

  • • Obtaining your consent before setting non-essential cookies
  • • Providing a consent banner that allows you to accept or reject cookies
  • • Allowing you to withdraw consent at any time
  • • Not using cookies for purposes you have not agreed to

You can control cookies through your browser settings. See our Privacy Policy for more details.

7. Data Retention

We retain personal data only as long as necessary for the purposes set out in this policy. Account data is kept while your account is active. After deletion, we may retain limited data for legal compliance, tax records, and legitimate business purposes, in line with GDPR Article 5(1)(e) storage limitation principles.

8. Children's Data (Art. 8)

Our service is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

9. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Articles 33 and 34. If the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.

10. Contact & Complaints

For any questions about your personal data or to exercise your GDPR rights, contact us at privacy@authorcentral.net.

You also have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ICO).

Important Disclaimer: Author Central is an independent service and is not affiliated with, endorsed by, or connected to Amazon, Amazon.com, Inc., Amazon KDP, or Amazon's Author Central service.

Author Central provides independent author engagement tools including QR code generation, bonus content hosting, and reader communication management.

Author CentralAuthorCentral

© 2026 CoreLogic AI Ltd. All rights reserved.

Registered in England & Wales No: 16919694