Privacy Policy
Version 2026-10-02
1. Who is responsible
[company name], Netherlands (“we”) provides AI Mention Monitor. For questions or requests about your data: [privacy email address].
We play two roles:
- Controller for the data of our customers' accounts: names, email addresses, login, billing and support. This policy covers that.
- Processor for personal data that customers put into the Service (for example in monitored questions, brands or reports). Our customer is the controller of that data; the Data Processing Agreement applies.
2. What we collect and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Name, email, password (hashed), language, time zone | Your account and signing in | Contract (Art. 6(1)(b)) |
| Organisation name, address, VAT number, invoices, payment status | Billing, tax records | Contract; legal obligation (Art. 6(1)(c)) |
| IP address, browser, actions in the app (audit log) | Security, preventing abuse, tracing changes | Legitimate interest (Art. 6(1)(f)) |
| Emails you receive from us | Account, alerts and reports you set up | Contract |
| Error reports | Finding and fixing bugs | Legitimate interest |
| Use of the Service, and results of measurements (questions, AI answers, mentions, scores) | Analysing, improving and extending the Service; aggregated statistics and benchmarks that cannot be traced back to a customer | Legitimate interest; personal data only as far as needed, pseudonymised where possible |
| Names and websites of companies that our customers' results show as competitors | Contacting those companies about our services (business-to-business). We never tell them which customer tracks them. | Legitimate interest; you can object at any time and we stop |
We do not sell personal data, do not use it for advertising (other than contacting companies directly as described above), and do not use your data to train AI models.
Google Analytics and Search Console
When a customer connects Google Analytics 4 or Google Search Console to a site, we read, with read-only access that the customer grants and can withdraw at any time:
- from Google Analytics: per day, the number of visits, engaged visits, conversions and revenue, from AI assistants per source and landing page, and for the whole site;
- from Search Console: per day, the clicks, impressions, click-through rate and position per search query, page, country and device type.
These are totals: they contain no data about individual visitors. We use them only to show the customer, in the Service and its reports, how visibility in AI answers relates to its visits, conversions and search results. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we do not sell it, do not use it for advertising, do not let people read it except with the customer's permission, for security or where the law requires it, and do not use it to train AI models.
Access is granted either by adding our service account in Google Analytics and Search Console, or by connecting a Google account (Google's consent screen, read-only permissions). For a connected Google account we store its email address and its access tokens, encrypted, so that we can keep syncing; the tokens are deleted when the account is disconnected or the organisation is deleted, and we then also withdraw our access at Google.
To disconnect a site: Site → Integrations → Disconnect. To disconnect a Google account: Settings → Google accounts → Disconnect, or withdraw it at myaccount.google.com/permissions. With our service account, also remove it in Google Analytics and Search Console. Syncing stops at once; the synced figures are deleted after 30 days, or right away with Delete the data now.
3. How long we keep it
- Account data: as long as the account exists. After an organisation is deleted, its data is removed after a 30-day grace period.
- Invoices and payment records: 7 years (Dutch tax law).
- IP addresses in the audit log: 180 days.
- Full AI provider responses: 90 days; the extracted results stay with the organisation's data.
- Webhook and integration delivery logs: 90 days. Read notifications: 180 days. Invitations: 90 days after they expire.
- Data exports: 7 days.
- Google Analytics and Search Console figures: while the site stays connected; 30 days after disconnecting (or earlier on request), and with the organisation.
- Database backups: rolled off after 14 days.
4. Who receives data
Only the service providers listed on the subprocessors page, bound by processing agreements, and authorities when the law requires it. Our servers and backups are in the EU. Monitored questions are sent to AI providers, some of them in the United States; they receive the question text, not your account data. Transfers outside the EU rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
5. Security
Encrypted connections (TLS), encrypted backups, hashed passwords, strict separation between organisations, role-based access, and an audit log. See the DPA for the full list of measures.
6. Your rights
You can ask to see, correct, delete or receive (export) your data, object to processing based on legitimate interest, or restrict processing. Much of this you can do yourself in the app: your profile, the data export, and deleting your account or organisation. For anything else email us; we answer within one month. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
7. Cookies
We only use functional cookies: a session cookie to keep you signed in and a security (CSRF) token. No tracking or advertising cookies, so no cookie consent is needed.
8. Changes
We announce material changes to this policy in advance by email or in the app.