Datacompany

Privacy Policy

Last updated: 11 August 2026

This Privacy Policy explains how Datacompany (“we”, “us”) handles personal data in connection with our marketing-mix-modelling (MMM) and attribution service, available at datacompany.nl and app.datacompany.nl (the “Service”).

We are a business-to-business service. Our customers are companies that connect their own marketing, analytics and CRM data sources to the Service so that we can build an attribution model for them. We do not offer the Service to consumers, and we do not build profiles of individual people.

1. Who we are and how to contact us

Legal entityDatacompany
Chamber of Commerce (KVK)64705439
VAT numberNL002342945B10
AddressBovendiepen 9, 9471 JE Zuidlaren, the Netherlands
Emailjeroen@datacompany.nl
Phone+31 50 211 5978

For any question about this policy, or to exercise your data-protection rights, email jeroen@datacompany.nl. We are not required to appoint a Data Protection Officer; the address above reaches the person responsible for privacy.

2. Our two roles: controller and processor

We handle two different kinds of data, and our legal role differs for each.

3. What data we collect

3.1 Account and usage data

3.2 Data from connected sources

We only pull data from a source after an authorised user of the customer has explicitly connected it — either by completing an OAuth consent screen at the provider, or by entering read-only credentials the customer chose to give us. We request read-only access everywhere it is offered, and we never write to, modify or delete anything in a connected account.

What we pull is aggregated reporting data, not visitor-level records:

SourceHow access is grantedWhat we read
Google Analytics 4 Per-customer Google OAuth Aggregated daily reports: date, country, region, default channel group, event name, event count, event value, sessions. Also the list of GA4 properties the authorising user can access, and that user’s email address (to show which account is connected).
Google Ads Our manager (MCC) account with a Google Ads developer token, after the customer grants it access to their Google Ads account, or through Windsor.ai Campaign-level cost, clicks, impressions and conversion metrics per day and geography.
Google Sheets Per-customer Google OAuth (read-only) Only the single spreadsheet whose URL the customer pastes into the connection, used to supply offline spend or conversion figures that exist in no ad platform — billboards, podcasts, telemarketing. We read the sheet’s rows and column headers; we never create, edit or delete anything.
Meta Ads, LinkedIn Ads, Microsoft Advertising Per-connection OAuth Campaign-level spend and performance metrics per day, and (for organic social) post-level impressions and engagement.
Piwik / Piwik PRO Customer-issued API credentials Aggregated session, channel and goal-completion counts per site and day.
HubSpot Per-connection OAuth Deal and company records used as the revenue anchor: deal name, amount, stage, pipeline, create and close dates, HubSpot source fields, UTM fields, currency, company name and lead-source property. A free-text deal or company name can incidentally contain a business contact’s name; we do not use it for anything other than matching revenue to a channel.
BigQuery, PostgreSQL Read-only credentials the customer provides Only the tables or queries the customer configures. The customer controls what those contain.
Windsor.ai OAuth via Windsor.ai as an intermediary for some ad and organic-social connections The same campaign-level metrics as above, retrieved through Windsor.ai’s API rather than the platform’s own.

We do not place tracking pixels or tags on our customers’ websites, we do not read their visitors’ cookies, and we do not receive names, email addresses, IP addresses or device identifiers of website visitors from any analytics source.

3.3 Google user data — specifics

Because Google user data is subject to additional rules, here is exactly what we access and why.

4. Google API Services User Data Policy and Limited Use

Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, that means:

5. Why we process data, and our legal basis

PurposeLegal basis (GDPR art. 6)
Creating and running accounts, authenticating users, providing the ServicePerformance of a contract
Pulling data from a source the customer connected, and building their attribution/MMM resultsPerformance of a contract (and, for the individual granting OAuth access, their consent given at the provider’s consent screen)
Sending transactional email (password resets, invitations, scheduled reports the customer configured)Performance of a contract
Security, abuse prevention, audit logging, keeping backupsLegitimate interests — running a secure service
Understanding which parts of the product are used, so we can improve itLegitimate interests — product improvement, using account and usage data only
Invoicing and statutory bookkeepingLegal obligation
Responding to sales enquiries you send usLegitimate interests / steps prior to a contract
Measuring how our public marketing website is used (Google Analytics)Consent, asked before anything is placed — see section 11.2

We do not use personal data for automated decision-making that has legal effects on individuals. Our models make statements about marketing channels, not about people.

6. Sub-processors and other recipients

We keep this list short on purpose. We do not sell data, and we do not share it with advertising networks, data brokers or any third party for their own marketing purposes.

ProviderWhat it does for usData involvedLocation
Fly.io Application hosting and the managed PostgreSQL database (including backups) All account data and all connected source data Primary region Amsterdam (EU); provider established in the United States
Resend Transactional email delivery (password resets, invitations, scheduled reports) Recipient email address, message content — which may include the customer’s own report figures United States / EU
Anthropic Generates the narrative text of reports and answers a customer’s questions about their own data Aggregated figures from that customer’s own results, plus the question asked. Contractually not used to train models. United States
Slack Optional: posts a customer’s digest and answers into their own Slack workspace, only if they enable it The report content the customer chose to receive United States / EU, per the customer’s own Slack agreement
Windsor.ai Optional connector layer used for some ad and organic-social sources Campaign-level metrics from the platforms connected through it. Windsor.ai caches this data to serve our requests; it does not resell it. EU (Lithuania)
Netlify Hosts our public marketing website Server logs of website visits only. No customer data. United States
Google (Google Analytics 4) Aggregate visitor statistics for our public marketing website, and only for visitors who consent Pages viewed, approximate location derived from the IP address, device and browser type, and a cookie-based visitor identifier. No customer data and nothing from any connected data source. United States / EU

We may also disclose data to our professional advisers, or to authorities where we are legally required to. Where a provider is outside the European Economic Area, transfers are covered by the European Commission’s Standard Contractual Clauses, by the EU–US Data Privacy Framework where the provider is certified, or by another valid transfer mechanism.

We notify customers before adding a new sub-processor that handles their connected source data, so they have the opportunity to object.

7. How long we keep data

Database backups are kept on a rolling schedule by our hosting provider, so deleted data can persist in a backup for a short period before the backup itself expires.

8. Security

We are a small company and we do not currently hold an ISO 27001 or SOC 2 certification. We say so plainly rather than implying otherwise. If a personal data breach occurs, we will notify affected customers without undue delay and, where required, the Dutch Data Protection Authority within 72 hours.

9. Your rights

If you are in the EEA or the UK you have the right to access, correct, delete or receive a copy of your personal data, to ask us to restrict or stop processing it, and to object to processing based on legitimate interests.

You can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or with the supervisory authority in your own country.

10. Revoking access, export and deletion

A data processing agreement (DPA) covering our processing on behalf of customers is available on request from jeroen@datacompany.nl.

11. Cookies

We use cookies differently on the two parts of our site, so we describe them separately.

11.1 The application (app.datacompany.nl)

The application sets one strictly necessary cookie, dc_session, which keeps you signed in. It is signed, restricted to our own site, sent only over HTTPS in production, and expires after 30 days or when you sign out. Because it is strictly necessary to deliver a service you requested, no consent is required for it.

There is no analytics or advertising cookie anywhere in the application. It loads two third-party JavaScript libraries from public CDNs (htmx and Chart.js) purely to render the interface; they set no cookies. Our customers’ data is never used to profile anyone.

11.2 The marketing website (datacompany.nl)

On our public marketing website we use Google Analytics 4 to see which pages people read, so we know what to improve. It is loaded only after you consent: until you choose, no Google script is requested and no analytics cookie is placed. Declining costs you nothing — the site works identically either way, and we do not ask again unless you reopen the choice yourself.

CookiePurposeLifetime
_ga Distinguishes one visitor from another so visit counts aren’t inflated 2 years
_ga_HNWZ95Z9RM Keeps the session state for our specific Analytics property 2 years
dc-analytics-consent Remembers your choice, so we don’t ask on every page. Stored in your browser’s local storage rather than as a cookie, and set whichever way you choose. Until you clear it

Legal basis: your consent (GDPR art. 6(1)(a) and art. 5(3) of the ePrivacy Directive). Recipient: Google, acting as our processor for these statistics; we have not enabled Google’s advertising features, so this data is not used for ad personalisation or combined with Google’s advertising products. We do not track you across other websites and we place no advertising cookies at all.

Changing your mind: use the Cookie settings link in the website footer. It deletes the analytics cookies immediately and reopens the choice — withdrawal is as easy as consent was. Clearing cookies in your browser has the same effect.

12. Children

The Service is intended for businesses. We do not knowingly collect personal data from anyone under 16, and no part of the Service is directed at children.

13. Changes to this policy

We may update this policy as the Service evolves. The date at the top shows when it last changed. If a change materially affects how we handle personal data, we will notify customers by email or in the application before it takes effect.

14. Contact

Datacompany · Bovendiepen 9, 9471 JE Zuidlaren, the Netherlands · KVK 64705439 · jeroen@datacompany.nl · +31 50 211 5978