Privacy Policy
Last updated: 11 August 2026
This Privacy Policy explains how Datacompany (“we”, “us”) handles personal data in connection with our marketing-mix-modelling (MMM) and attribution service, available at datacompany.nl and app.datacompany.nl (the “Service”).
We are a business-to-business service. Our customers are companies that connect their own marketing, analytics and CRM data sources to the Service so that we can build an attribution model for them. We do not offer the Service to consumers, and we do not build profiles of individual people.
1. Who we are and how to contact us
| Legal entity | Datacompany |
|---|---|
| Chamber of Commerce (KVK) | 64705439 |
| VAT number | NL002342945B10 |
| Address | Bovendiepen 9, 9471 JE Zuidlaren, the Netherlands |
| jeroen@datacompany.nl | |
| Phone | +31 50 211 5978 |
For any question about this policy, or to exercise your data-protection rights, email jeroen@datacompany.nl. We are not required to appoint a Data Protection Officer; the address above reaches the person responsible for privacy.
2. Our two roles: controller and processor
We handle two different kinds of data, and our legal role differs for each.
- Account data — we are the controller. The names, work email addresses and login activity of the people who use our application on behalf of a customer, plus our own billing and support correspondence.
- Connected source data — we are the processor. The marketing, analytics and CRM data we pull from the sources a customer authorises. The customer decides what to connect and why; we process it on their instructions, only to produce that customer’s own results. Where this data contains personal data, the customer is the controller and we act under a data processing agreement (see section 10).
3. What data we collect
3.1 Account and usage data
- Work email address and (optionally) name of each user we create an account for.
- A password hash (Argon2id). We never store passwords in readable form.
- Session cookie contents, login timestamps and last-seen time.
- A record of pages opened inside the application and of sensitive actions (for example: creating or deleting a connection, inviting a colleague, exporting data). We use this to support customers, to see whether the product is actually being used, and for security forensics.
- Support and sales correspondence you send us.
- Standard server logs (IP address, timestamp, requested URL, user agent, error traces).
3.2 Data from connected sources
We only pull data from a source after an authorised user of the customer has explicitly connected it — either by completing an OAuth consent screen at the provider, or by entering read-only credentials the customer chose to give us. We request read-only access everywhere it is offered, and we never write to, modify or delete anything in a connected account.
What we pull is aggregated reporting data, not visitor-level records:
| Source | How access is granted | What we read |
|---|---|---|
| Google Analytics 4 | Per-customer Google OAuth | Aggregated daily reports: date, country, region, default channel group, event name, event count, event value, sessions. Also the list of GA4 properties the authorising user can access, and that user’s email address (to show which account is connected). |
| Google Ads | Our manager (MCC) account with a Google Ads developer token, after the customer grants it access to their Google Ads account, or through Windsor.ai | Campaign-level cost, clicks, impressions and conversion metrics per day and geography. |
| Google Sheets | Per-customer Google OAuth (read-only) | Only the single spreadsheet whose URL the customer pastes into the connection, used to supply offline spend or conversion figures that exist in no ad platform — billboards, podcasts, telemarketing. We read the sheet’s rows and column headers; we never create, edit or delete anything. |
| Meta Ads, LinkedIn Ads, Microsoft Advertising | Per-connection OAuth | Campaign-level spend and performance metrics per day, and (for organic social) post-level impressions and engagement. |
| Piwik / Piwik PRO | Customer-issued API credentials | Aggregated session, channel and goal-completion counts per site and day. |
| HubSpot | Per-connection OAuth | Deal and company records used as the revenue anchor: deal name, amount, stage, pipeline, create and close dates, HubSpot source fields, UTM fields, currency, company name and lead-source property. A free-text deal or company name can incidentally contain a business contact’s name; we do not use it for anything other than matching revenue to a channel. |
| BigQuery, PostgreSQL | Read-only credentials the customer provides | Only the tables or queries the customer configures. The customer controls what those contain. |
| Windsor.ai | OAuth via Windsor.ai as an intermediary for some ad and organic-social connections | The same campaign-level metrics as above, retrieved through Windsor.ai’s API rather than the platform’s own. |
We do not place tracking pixels or tags on our customers’ websites, we do not read their visitors’ cookies, and we do not receive names, email addresses, IP addresses or device identifiers of website visitors from any analytics source.
3.3 Google user data — specifics
Because Google user data is subject to additional rules, here is exactly what we access and why.
-
Scopes we request. Each Google integration has its own
consent screen that asks only for what that integration needs:
-
Connecting Google Analytics 4 requests
https://www.googleapis.com/auth/analytics.readonly(read GA4 properties and run GA4 reports). -
Connecting Google Sheets requests
https://www.googleapis.com/auth/drive.file(access only the specific file the customer selects via Google's file picker — this scope cannot read any other Drive files). -
Connecting Google Ads requests
https://www.googleapis.com/auth/adwords(run reports over the advertising accounts the signed-in user can already reach). This is the only scope the Google Ads API offers; see below for what actually limits it. -
Every consent screen also requests
https://www.googleapis.com/auth/userinfo.emailandopenid(to display which Google account is connected, so the customer can confirm the right one was used).
-
Connecting Google Analytics 4 requests
-
Why we need them. The GA4 read-only scope is what lets us
pull the aggregated session, channel and conversion history a
marketing-mix model needs. Without it there is no model. A narrower scope
does not exist for reading GA4 report data. The Google Ads scope is
the only one that API publishes: Google uses the same scope for reading
and for writing, so there is no read-only variant to ask for instead. We
call read endpoints exclusively and never create, change or delete
campaigns, budgets or billing settings. What genuinely bounds the access
is the Google Ads role of the account that signs in, which is why we
recommend connecting with a user that has the Read only role: it can run
the performance reports we need and cannot change anything.
The
drive.filescope covers the offline marketing a model would otherwise be blind to — billboards, podcasts, telemarketing — which customers keep in a spreadsheet, not in any advertising platform. This scope is granted per-file: only the specific spreadsheet the customer selects via Google's file picker becomes accessible; no other Drive files are reachable. - What we do with it. We store the aggregated report rows in the customer’s own isolated area of our database and use them as inputs to that customer’s attribution and MMM results, which only that customer’s users (and, if they enable it, their own Slack workspace and email recipients) can see.
- Tokens. Refresh and access tokens are encrypted at rest (Fernet/AES with a key derived via PBKDF2-SHA256) and are used only to refresh the connection on the customer’s behalf. Disconnecting a connection deletes the stored token and stops all future access.
- Retention and deletion. Google user data we have synced follows the same rules as all connected-source data: kept for the duration of the subscription, deleted on written request at any time, and deleted within 30 days of termination (sections 7 and 10). Customers can also revoke our access at myaccount.google.com/permissions.
- What we never do. We do not use Google user data for advertising, we do not sell it, we do not share it with other customers, and we do not use it to build any product other than the requesting customer’s own results.
4. Google API Services User Data Policy and Limited Use
Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means:
- We only use Google user data to provide or improve user-facing features that are prominent in our interface — the attribution and MMM results, dashboards, reports and answers we produce for the customer who authorised the connection.
- We do not transfer or sell Google user data to third parties, other than to the sub-processors listed in section 6 that are strictly necessary to provide the Service (hosting, and — for narrative report text — the AI provider described there), to comply with applicable law, or as part of a merger or acquisition after the customer has been notified and continues to use the Service.
- We do not use Google user data for serving advertising of any kind.
- We do not use Google user data to develop, improve or train generalised or non-personalised AI or machine-learning models. Where we send data to an AI provider to write the narrative text of a customer’s own report or to answer that customer’s own question, that provider is contractually prohibited from using it to train its models. The statistical models we fit are per-customer attribution models built from that customer’s data and are not shared across customers.
- We do not allow humans to read Google user data unless: the customer has given explicit permission (for example when they ask us to investigate a figure); it is necessary for security purposes such as investigating abuse; it is required to comply with applicable law; or the data is aggregated and anonymised and used for internal operations such as capacity planning. Access is limited to the small number of our staff who need it, and such access is logged.
5. Why we process data, and our legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Creating and running accounts, authenticating users, providing the Service | Performance of a contract |
| Pulling data from a source the customer connected, and building their attribution/MMM results | Performance of a contract (and, for the individual granting OAuth access, their consent given at the provider’s consent screen) |
| Sending transactional email (password resets, invitations, scheduled reports the customer configured) | Performance of a contract |
| Security, abuse prevention, audit logging, keeping backups | Legitimate interests — running a secure service |
| Understanding which parts of the product are used, so we can improve it | Legitimate interests — product improvement, using account and usage data only |
| Invoicing and statutory bookkeeping | Legal obligation |
| Responding to sales enquiries you send us | Legitimate interests / steps prior to a contract |
| Measuring how our public marketing website is used (Google Analytics) | Consent, asked before anything is placed — see section 11.2 |
We do not use personal data for automated decision-making that has legal effects on individuals. Our models make statements about marketing channels, not about people.
6. Sub-processors and other recipients
We keep this list short on purpose. We do not sell data, and we do not share it with advertising networks, data brokers or any third party for their own marketing purposes.
| Provider | What it does for us | Data involved | Location |
|---|---|---|---|
| Fly.io | Application hosting and the managed PostgreSQL database (including backups) | All account data and all connected source data | Primary region Amsterdam (EU); provider established in the United States |
| Resend | Transactional email delivery (password resets, invitations, scheduled reports) | Recipient email address, message content — which may include the customer’s own report figures | United States / EU |
| Anthropic | Generates the narrative text of reports and answers a customer’s questions about their own data | Aggregated figures from that customer’s own results, plus the question asked. Contractually not used to train models. | United States |
| Slack | Optional: posts a customer’s digest and answers into their own Slack workspace, only if they enable it | The report content the customer chose to receive | United States / EU, per the customer’s own Slack agreement |
| Windsor.ai | Optional connector layer used for some ad and organic-social sources | Campaign-level metrics from the platforms connected through it. Windsor.ai caches this data to serve our requests; it does not resell it. | EU (Lithuania) |
| Netlify | Hosts our public marketing website | Server logs of website visits only. No customer data. | United States |
| Google (Google Analytics 4) | Aggregate visitor statistics for our public marketing website, and only for visitors who consent | Pages viewed, approximate location derived from the IP address, device and browser type, and a cookie-based visitor identifier. No customer data and nothing from any connected data source. | United States / EU |
We may also disclose data to our professional advisers, or to authorities where we are legally required to. Where a provider is outside the European Economic Area, transfers are covered by the European Commission’s Standard Contractual Clauses, by the EU–US Data Privacy Framework where the provider is certified, or by another valid transfer mechanism.
We notify customers before adding a new sub-processor that handles their connected source data, so they have the opportunity to object.
7. How long we keep data
- Connected source data: for as long as the customer’s subscription runs, because a marketing-mix model needs multiple years of history to be meaningful. After termination we delete it within 30 days, unless the customer asks us in writing to keep it longer or to delete it sooner.
- OAuth tokens and connection credentials: deleted as soon as the connection is disconnected or the account is closed.
- Account data: for the duration of the contract, then deleted within 30 days.
- Product usage records (page views): 180 days, then automatically deleted.
- Audit records of sensitive actions: 730 days, then automatically deleted.
- Model run history: only the five most recent runs per customer are retained; older runs are pruned automatically.
- Server logs: short-lived, retained by our hosting provider for troubleshooting.
- Invoices and bookkeeping records: seven years, as Dutch tax law requires.
Database backups are kept on a rolling schedule by our hosting provider, so deleted data can persist in a backup for a short period before the backup itself expires.
8. Security
- All traffic is served over HTTPS with HSTS enforced.
- Connection credentials and OAuth refresh tokens are encrypted at rest.
- Passwords are hashed with Argon2id.
- Every database query is scoped to a single customer’s organisation, so one customer’s data is never returned to another.
- We request read-only access to every source we connect to.
- Administrative access is limited to the staff who need it, and sensitive actions are written to an audit log.
- Security response headers, including a Content Security Policy, are set on every response.
We are a small company and we do not currently hold an ISO 27001 or SOC 2 certification. We say so plainly rather than implying otherwise. If a personal data breach occurs, we will notify affected customers without undue delay and, where required, the Dutch Data Protection Authority within 72 hours.
9. Your rights
If you are in the EEA or the UK you have the right to access, correct, delete or receive a copy of your personal data, to ask us to restrict or stop processing it, and to object to processing based on legitimate interests.
- If you are a user of our application: email jeroen@datacompany.nl and we will respond within one month.
- If your data reached us through one of our customers’ connected sources: that customer is the controller. Please contact them; if you contact us instead, we will forward your request to them and support them in answering it.
You can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or with the supervisory authority in your own country.
10. Revoking access, export and deletion
- Disconnecting. An authorised user can disconnect any data source at any time from the Connections screen in the application. This deletes the stored token or credentials and stops all future syncing immediately. You can additionally revoke our access at the provider — for Google, at myaccount.google.com/permissions.
- Historical data. Data already synced remains available so existing models keep working. We will delete it on request — email us and we will confirm deletion within 30 days.
- Export. On request we provide a customer’s stored data and results in a machine-readable format.
- Closing an account. Everything above happens automatically: connections are removed and data is deleted within 30 days of termination.
A data processing agreement (DPA) covering our processing on behalf of customers is available on request from jeroen@datacompany.nl.
11. Cookies
We use cookies differently on the two parts of our site, so we describe them separately.
11.1 The application (app.datacompany.nl)
The application sets one strictly necessary cookie, dc_session,
which keeps you signed in. It is signed, restricted to our own site, sent
only over HTTPS in production, and expires after 30 days or when you sign
out. Because it is strictly necessary to deliver a service you requested, no
consent is required for it.
There is no analytics or advertising cookie anywhere in the application. It loads two third-party JavaScript libraries from public CDNs (htmx and Chart.js) purely to render the interface; they set no cookies. Our customers’ data is never used to profile anyone.
11.2 The marketing website (datacompany.nl)
On our public marketing website we use Google Analytics 4 to see which pages people read, so we know what to improve. It is loaded only after you consent: until you choose, no Google script is requested and no analytics cookie is placed. Declining costs you nothing — the site works identically either way, and we do not ask again unless you reopen the choice yourself.
| Cookie | Purpose | Lifetime |
|---|---|---|
_ga |
Distinguishes one visitor from another so visit counts aren’t inflated | 2 years |
_ga_HNWZ95Z9RM |
Keeps the session state for our specific Analytics property | 2 years |
dc-analytics-consent |
Remembers your choice, so we don’t ask on every page. Stored in your browser’s local storage rather than as a cookie, and set whichever way you choose. | Until you clear it |
Legal basis: your consent (GDPR art. 6(1)(a) and art. 5(3) of the ePrivacy Directive). Recipient: Google, acting as our processor for these statistics; we have not enabled Google’s advertising features, so this data is not used for ad personalisation or combined with Google’s advertising products. We do not track you across other websites and we place no advertising cookies at all.
Changing your mind: use the Cookie settings link in the website footer. It deletes the analytics cookies immediately and reopens the choice — withdrawal is as easy as consent was. Clearing cookies in your browser has the same effect.
12. Children
The Service is intended for businesses. We do not knowingly collect personal data from anyone under 16, and no part of the Service is directed at children.
13. Changes to this policy
We may update this policy as the Service evolves. The date at the top shows when it last changed. If a change materially affects how we handle personal data, we will notify customers by email or in the application before it takes effect.
14. Contact
Datacompany · Bovendiepen 9, 9471 JE Zuidlaren, the Netherlands · KVK 64705439 · jeroen@datacompany.nl · +31 50 211 5978
See also our Terms of Service.