# Targetlytics - /PRIVACY/OPT-OUT (en)

*Generated for AI LLM consumption*

## Section: PrivacyPolicy

### meta

**title**: Privacy Policy

**description**: Privacy Policy for Targetlytics AI - Learn how we collect, use, and protect your data.

**title**: Privacy Policy

**lastUpdated**: Last updated: 17th of August, 2026

### sections

#### introduction

**title**: Introduction

**content**: EYT Eesti OÜ ("we", "our", or "us") operates Targetlytics AI. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

#### dataCollection

**title**: Information We Collect

**content**: We collect information that you provide directly to us, including:

##### items

**name**: Name and contact information

**email**: Email address

**company**: Company name and details

**usage**: Usage data and analytics

**cookies**: Cookies and tracking technologies

#### googleUserData

**title**: Google User Data

**intro**: Some Targetlytics AI features rely on data from your Google Account. This section explains exactly what Google user data we access, why we access it, who it is shared with, how it is protected and how long we keep it. It applies in addition to the rest of this policy, and where the two differ, this section and the Limited Use section below govern Google user data.

**accessTitle**: What Google data we access

**access**: We request read-only scopes only, and only after you explicitly grant access on Google's own consent screen. We never request permission to create, change or delete anything in your Google Account.

##### items

**signIn**: Google Account sign-in (openid, email, profile): your name, email address, profile picture and Google account identifier, used solely to create and authenticate your Targetlytics AI account.

**analytics**: Google Analytics (analytics.readonly): a read-only list of the GA4 properties you can access, and report data for the property you select — such as sessions, users, traffic sources, referrers, landing pages and conversion events.

**searchConsole**: Google Search Console (webmasters.readonly): a read-only list of the sites you have verified, and Search performance data for the site you select — such as search queries, pages, impressions, clicks and average position.

**useTitle**: How we use Google user data

**use**: We use this data only to deliver the features you asked for:

##### useItems

**auth**: Authenticate you and keep your account secure.

**reporting**: Show your search and analytics performance inside your Targetlytics AI dashboard.

**insights**: Generate the AI visibility, attribution, ranking and content recommendations that are the core of the service.

**support**: Diagnose errors and provide support when you contact us.

**aiTitle**: AI processing of Google user data

**ai**: Targetlytics AI analyses your Google Analytics and Search Console data using third-party AI models (currently provided by OpenAI, Google and Anthropic) to produce the reports and recommendations you see in the product. These providers act as our processors under contracts that prohibit them from using your data to train or improve their models. Google user data is never used to develop, train or improve any generalised or non-personalised AI or machine learning model, by us or by anyone else.

**sharingTitle**: Who we share Google user data with

**sharing**: We do not sell Google user data and we do not share it for advertising. It is shared only with the infrastructure and AI processors needed to run the features described above — Google Cloud Platform and Firebase for hosting and storage, and the AI model providers named above — each bound by contract to use it only on our instructions. We disclose it otherwise only where we are legally required to do so.

**carveOut**: Google user data is never used for identity resolution or visitor de-anonymisation, is never shared with Warmly.ai or with any advertising, enrichment or data-broker partner, and is never sold or shared as those terms are defined by privacy laws such as the CCPA. It is excluded from the visitor identification activities described elsewhere in this policy.

**humansTitle**: Human access

**humans**: We do not allow humans to read your Google user data unless: you give us specific permission (for example, so we can troubleshoot a problem you reported); it is necessary for security purposes, such as investigating abuse; we are required to do so to comply with applicable law; or the data has been aggregated and anonymised so that it can no longer identify you or your site.

**securityTitle**: How we protect Google user data

**security**: Data is transmitted over TLS and stored in Google Cloud Firestore in the europe-north1 region, encrypted at rest. OAuth refresh tokens are stored server-side only, are never exposed to your browser or to any third party, and are reachable only by the server functions that run your data syncs. Access inside our organisation is limited to the personnel who need it to operate or support the service.

**retentionTitle**: Retention, disconnection and deletion

**retention**: You stay in control of this data at all times:

##### retentionItems

**disconnect**: You can disconnect Google Analytics or Search Console at any time from the Connections page in Targetlytics AI. When you do, we immediately revoke the token with Google and delete the stored credentials.

**revoke**: You can also revoke our access directly from your Google Account at any time, at google.com/permissions.

**reports**: Reporting data we previously imported stays in your workspace so your historical charts keep working. It is deleted when you delete the brand or your account, and within 30 days of a deletion request sent to privacy@targetlytics.com.

**account**: When your account is deleted, all Google user data associated with it — credentials and imported reports alike — is deleted from our production systems within 30 days.

#### googleLimitedUse

**title**: Google API Services Limited Use

**intro**: Targetlytics AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

**content**: In particular, we confirm that Google user data is not:

##### items

**ads**: used to serve targeted, personalised or retargeted advertising, or transferred to anyone who does so;

**sell**: sold, or transferred to data brokers, information resellers or any other party that trades in personal data;

**credit**: used to determine credit-worthiness or for lending purposes;

**training**: used to develop, train or improve generalised or non-personalised AI or machine learning models.

**transfer**: Any party we transfer Google user data to is bound by these same restrictions. If we ever want to use Google user data for a new purpose, we will ask for your consent again before that use begins.

#### dataUse

**title**: How We Use Your Information

**content**: We use the information we collect to:

##### items

**service**: Provide, maintain, and improve our services

**communication**: Communicate with you about our services

**improvement**: Analyze usage patterns to improve user experience

**legal**: Comply with legal obligations

#### dataSharing

**title**: Data Sharing

**content**: We do not sell your personal information. We may share your information only with service providers who assist us in operating our platform, and only to the extent necessary to provide our services.

#### dataSecurity

**title**: Data Security

**content**: We would rather describe our security measures than simply assert them. Data is transmitted over TLS and encrypted at rest. Core product data, our vector search index and our email delivery all run on EU infrastructure. Access to production systems is limited to the personnel who need it, protected by multi-factor authentication, and logged. OAuth tokens for accounts you connect are stored server-side only and are never exposed to your browser or to any third party. We review service providers before giving them access to personal data and bind them by written contract. No system is perfectly secure and we do not claim otherwise — the section below sets out what we do if something goes wrong.

#### userRights

**title**: Your Rights

**content**: You have the right to:

##### items

**access**: Access your personal data

**correction**: Request correction of inaccurate data

**deletion**: Request deletion of your data

**objection**: Object to processing of your data

**portability**: Request data portability

**withdrawal**: Withdraw your consent at any time, where processing is based on consent

**restriction**: Request that we restrict how we use your data, for example while we check the accuracy of data you have disputed

**complaint**: If you are located in the EU/EEA and believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — www.aki.ee — though you may also contact the supervisory authority in your own EU/EEA country of residence.

**requestProcessTitle**: How to exercise these rights, and what happens next

**requestProcess**: Email privacy@targetlytics.com. We do not charge for this. We will respond within one month of receiving your request; if the request is complex, or you have made several, we may extend that by up to two further months and will tell you within the first month if we need to. Before acting we may need to confirm your identity — normally by asking you to write from the email address we already hold — and we will never ask for more information than the request requires. If we cannot do what you have asked, we will explain why and tell you how to complain.

#### cookies

**title**: Cookies

**content**: We use cookies and similar technologies to operate our site and, with your consent, for analytics and marketing purposes. Non-essential cookies are only set after you consent, and you can accept, reject or change your choices at any time via the cookie banner or our Cookie Settings page.

#### socialMedia

**title**: Social Media Links

**content**: Our footer and site pages include links to our LinkedIn and GitHub profiles. These are plain outbound links, not embedded social media plugins, "Like" buttons, or widgets — we do not load scripts from these platforms on our pages, and they cannot track your visit to our site through these links. When you click through to LinkedIn or GitHub, you leave our site and that platform's own privacy policy and cookie practices apply; the platform may collect data about your visit to its site under its own privacy policy, independently of us. We do not receive any information about your activity on these platforms unless you choose to interact directly with our official account (for example, by following, messaging, or commenting).

**platformsTitle**: Platforms we link to

**linkedin**: LinkedIn — see LinkedIn's Privacy Policy

**github**: GitHub — see GitHub's Privacy Statement

#### changes

**title**: Changes to This Policy

**content**: We may update this Privacy Policy as our product, our providers or the law change. The date at the top of this page always reflects the version currently in force. If we make a material change — a new purpose for processing, a new category of recipient, or a change affecting your rights — we will give notice before it takes effect: by email to account holders where we hold an address, and by a prominent notice on this page. We will not process your personal data for a new and incompatible purpose without informing you first and, where the law requires it, obtaining your consent. Previous versions are available on request at privacy@targetlytics.com.

#### contact

**title**: Contact Us

**content**: If you have questions about this Privacy Policy, please contact us at:

**company**: EYT Eesti OÜ

**email**: privacy@targetlytics.com

**regNumber**: Registration number: EE14426777

**address**: Mäepealse tn 31, Tallinn 12618, Estonia

#### controller

**title**: Data Controller

**content**: The data controller responsible for your personal information under the EU General Data Protection Regulation (GDPR) is:

**company**: EYT Eesti OÜ

**regNumber**: Registration number: EE14426777

**address**: Mäepealse tn 31, Tallinn 12618, Estonia

**repNote**: As we are established in the European Union, we are not required to appoint a separate EU representative under Article 27 of the GDPR.

**dpo**: We have assessed whether we must appoint a Data Protection Officer under Article 37 of the GDPR and concluded that we are not required to: our core activities do not consist of large-scale regular and systematic monitoring of individuals, nor of large-scale processing of special category data. Privacy matters are handled directly by our management team, reachable at privacy@targetlytics.com.

#### legalBasis

**title**: Legal Basis for Processing (EU/EEA Users)

**intro**: Where the GDPR applies to you, we only process personal data when we have a valid legal basis. Here is our legal basis for each main purpose:

##### items

**account**: Creating and administering your account and providing the service you signed up for — Contract (Art. 6(1)(b) GDPR)

**support**: Responding to support requests and service communications — Contract / legitimate interest (Art. 6(1)(b), (f) GDPR)

**improvement**: Analysing usage to maintain, secure and improve the product — Legitimate interest (Art. 6(1)(f) GDPR)

**marketing**: Sending marketing communications — Consent (Art. 6(1)(a) GDPR), which you can withdraw at any time

**visitorId**: Visitor identification and business-lead scoring via Warmly.ai — Legitimate interest (Art. 6(1)(f) GDPR), balanced against your rights; you can object at any time

**legal**: Complying with legal obligations and responding to lawful requests — Legal obligation (Art. 6(1)(c) GDPR)

#### internationalTransfers

**title**: International Data Transfers

**content**: Core product data and Google user data are hosted in the EU (Google Cloud Firestore, europe-north1 / Finland). Our vector search index (Qdrant) and our transactional email provider (SMTP2GO) likewise run on EU infrastructure. Some of our other service providers — including our AI model providers (OpenAI, Anthropic, Google, Microsoft, Amazon Web Services and NVIDIA), Stripe, SerpApi, Slack and Warmly.ai — are based in, or process data in, the United States or other countries outside the European Economic Area. Where those providers act as our processors, we transfer personal data on the basis of the European Commission's Standard Contractual Clauses or another legally recognised transfer mechanism, and we require safeguards equivalent to the GDPR. Where a provider acts as an independent controller, it is responsible for the lawfulness of its own transfers under its own privacy policy. You can ask us which mechanism applies to a specific provider by emailing privacy@targetlytics.com.

#### visitorIdentification

**title**: Visitor Identification and Warmly

**intro**: We use Warmly.ai to help us understand which companies are interested in Targetlytics. This can include identity resolution, which means automatically using website activity and business data to help de-anonymise website traffic. For visitors from the EEA this operates at company level only — Warmly states that its data providers do not match individual contacts inside the EU. Person-level identification applies to traffic from outside the EEA, principally the United States.

**profile**: The profile information we may collect or receive includes names, email addresses, job titles, companies, and social network links. We may connect information collected online with information collected offline or from trusted third-party sources so we can better understand interest in our services and follow up with relevant business communications.

**legalBasis**: Where the GDPR applies, we rely on our legitimate interest in identifying and following up with likely business customers (Art. 6(1)(f) GDPR). We have weighed this interest against your rights and freedoms. Targetlytics and Warmly.ai act as separate, independent controllers for this activity — not as joint controllers — and each is responsible for its own processing under its own privacy policy. You can object to this processing at any time via our Cookie Settings or by emailing us, and we will honour opt-outs.

**linkText**: Warmly's privacy FAQ

#### retention

**title**: How Long We Keep Data

**content**: We keep personal information only for as long as necessary for the purposes described in this policy, or as required by law:

##### items

**account**: Account and product data: for as long as your account is active, and up to 24 months after closure in case you wish to reactivate, unless you ask us to delete it sooner.

**googleData**: Google user data: as described in the Google User Data section above — deleted immediately on disconnection, except historical reports, which are deleted when you delete your account.

**visitorId**: Business-visitor identification data (Warmly.ai): kept for up to 24 months after our last meaningful interaction with the associated company, unless you ask us to delete it sooner.

**billing**: Billing and invoicing records: kept for the period required by Estonian tax and accounting law (currently 7 years).

**legal**: Any data needed to establish, exercise or defend legal claims: for as long as necessary for that purpose.

**deletionRequests**: Deletion requests: once we have verified your identity, we complete deletion requests within 30 days of receipt.

**backups**: Backups: deleting data removes it from our live production systems immediately. Encrypted backups are kept on a rolling cycle of up to 30 days for disaster-recovery purposes and are automatically overwritten, not selectively edited, at the end of that cycle — so data covered by your deletion request is fully purged from backups within 30 days.

#### children

**title**: Children's Privacy

**content**: Targetlytics AI is a business-to-business product intended for use by professionals and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

#### thirdPartyData

**title**: Personal Data We Obtain From Other Sources

**intro**: We do not always receive personal data directly from you. We also obtain business-contact information about professionals from third parties. This section is provided to satisfy Article 14 of the GDPR.

**categoriesTitle**: What we receive

**categories**: Name, business email address, job title, employer, company size, industry and region, links to professional social network profiles, and a record of the pages viewed on our website. For visitors from the EEA, identification is company-level only — we do not receive your name, email address or personal profile from this source.

**sourcesTitle**: Where it comes from

**sources**: Primarily Warmly.ai and the data providers it licenses from, together with publicly available sources such as company websites, professional social networks and business registries. Warmly.ai acts as an independent data controller for this activity under its own privacy policy, not as our processor. Importantly for visitors from the EEA: Warmly states that its data providers do not match individual contacts inside the EU and resolve European traffic at company level only. If information does not identify an individual, it is not personal data and the individual rights described in this policy do not attach to it.

**basisTitle**: Why we are allowed to do this

**basis**: We rely on our legitimate interest in identifying and contacting likely business customers (Art. 6(1)(f) GDPR). We have weighed that interest against your rights and freedoms and limited the data to a professional, business-to-business context.

**rightsTitle**: Your control over it

**rights**: Where we contact you using information obtained this way, we will tell you in that first communication where we got your details, as Article 14 requires. You can object at any time, ask us what we hold, or ask us to delete it, by emailing privacy@targetlytics.com — we will action deletion requests and will not need a reason from you. We do not use data obtained from these sources to make any decision that produces legal effects for you.

#### profiling

**title**: Profiling and Automated Decision-Making

**intro**: We use automated processing in two places, and we want to be explicit about both.

**visitorTitle**: Scoring business visitors to our website

**visitorLogic**: The logic combines the pages you viewed on our site, how often and how recently you visited, and firmographic information about your employer (company size, industry, region) received from our providers, to produce a priority score visible to our sales team. For visitors from the EEA this scoring runs on company-level information only and does not identify you as an individual.

**visitorConsequence**: The only consequence is whether, and how quickly, a member of our team reaches out to you. It has no effect on pricing, on access to the service, or on any decision about you as an individual.

**productTitle**: Automated analysis inside the product

**productLogic**: Targetlytics AI generates visibility scores, competitor rankings and content recommendations by automated analysis of search, analytics and AI-answer data. This is the service our customers buy. It profiles brands and websites, not individuals.

**art22Title**: No decisions with legal or similarly significant effects

**art22**: We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 of the GDPR. We do not use automated processing to make credit, pricing, employment, insurance or eligibility decisions.

**objectTitle**: Your right to object

**object**: You have an absolute right to object to profiling carried out for direct marketing purposes (Art. 21(2) GDPR). If you object, we stop — no balancing test, no exceptions. Use our Cookie Settings, the opt-out page linked below, or email privacy@targetlytics.com.

#### aiTransparency

**title**: AI Systems, Limitations & the EU AI Act

**intro**: Targetlytics is an AI-powered platform. Several of the scores, insights, and content we generate — including AI visibility scores, competitor intelligence, citation tracking, hallucination detection, and suggested content — are produced or assisted by machine learning and large language models (LLMs), including third-party AI models we use as subprocessors (see Subprocessors above).

**mistakesTitle**: AI can make mistakes

**mistakes**: Outputs generated or assisted by AI are probabilistic, not verified facts. They may be incomplete, outdated, misattributed, or simply wrong — including "hallucinated" claims, incorrect citations, or inaccurate competitor or visibility data. We take reasonable steps to reduce these errors, including our own hallucination-detection features, but no AI system is error-free. Treat AI-generated scores, insights, and content as decision support, not verified fact, and apply your own judgment or independent verification before relying on them for business, legal, financial, or other consequential decisions.

**transparencyTitle**: Your right to know when you're dealing with AI (EU AI Act)

**transparency**: Under Regulation (EU) 2024/1689 (the EU AI Act), providers and deployers of certain AI systems must inform users when they are interacting with an AI system, or when content has been AI-generated or manipulated (Article 50). In line with this, we identify AI-assisted features and content within the product where it is not obvious from context, label AI-generated text, images, or reports we produce for you where required, and identify our customer-facing chat and support tools as AI-powered where applicable. Automated decision-making with legal or similarly significant effects on individuals is described in the Profiling and Automated Decision-Making section above, including your right to human review.

**riskTitle**: Risk classification

**risk**: Targetlytics is a business analytics and marketing intelligence tool. It does not perform biometric identification, credit scoring, employment decisions, law-enforcement activities, or any other use the EU AI Act classifies as "high-risk" or "unacceptable-risk". We treat our product as a limited-risk AI system, subject primarily to the transparency obligations described above, and we keep this classification under review as our product and the Act's implementing guidance evolve.

**oversightTitle**: Human oversight

**oversight**: AI-generated outputs in Targetlytics are designed to support, not replace, human judgment. You can request human review of any automated output that materially affects you by contacting privacy@targetlytics.com; see also User Rights and Profiling and Automated Decision-Making above.

#### controllerProcessor

**title**: When We Act as a Processor for Our Customers

**intro**: We play two different roles under the GDPR, and which one applies changes who is responsible for your data.

**controllerTitle**: Where we are the controller

**controller**: We are the data controller for visitors to our own website, for prospects we contact, and for the people who hold Targetlytics AI accounts. Everything else described in this policy concerns that role.

**processorTitle**: Where we are a processor

**processor**: We act as a processor on behalf of our business customers for the data they bring into the platform: their Google Analytics and Search Console data, data about visitors to their websites collected through our tracking script, and the brand, content and competitor information they upload. We process that data only on their documented instructions, in line with Article 28 of the GDPR.

**endUserTitle**: If you are a visitor to one of our customers' websites

**endUser**: In that case our customer is the controller and their privacy policy governs. Please direct requests to access, correct or delete your data to them. If you contact us instead, we will pass your request to the relevant customer without undue delay and assist them in responding.

**dpaTitle**: Data Processing Agreement

**dpa**: Business customers can request our Data Processing Agreement, which incorporates the European Commission's Standard Contractual Clauses and our current subprocessor list, by emailing privacy@targetlytics.com. It is also available as part of our enterprise contracting process.

#### subprocessors

**title**: Service Providers and Subprocessors

**intro**: We rely on the following categories of service provider to operate Targetlytics AI. Most act as our processors and are bound by a written contract to process personal data only on our instructions. A small number — notably Warmly.ai — act as independent controllers for part of their processing and apply their own privacy policies; we say so explicitly below where that is the case. Where a provider is located outside the European Economic Area we rely on the transfer mechanisms described above. We keep this list current and update it here when we add or replace a provider.

##### items

**infrastructure**: Hosting and infrastructure — Vercel (website hosting and content delivery), Google Cloud Platform and Firebase (authentication, database, serverless functions and file storage; core product data is stored in the EU), and Qdrant (vector search index, hosted in the EU).

**payments**: Payments and billing — Stripe (subscription billing and payment processing). We never see or store your full payment card details; Stripe handles them directly.

**ai**: AI model providers — OpenAI, Google (Gemini), Microsoft Azure AI Foundry, Amazon Web Services (Bedrock) and NVIDIA (NIM), used to generate the analyses and recommendations in the product. All are contractually prohibited from using your data to train or improve their models.

**integrations**: Data sources and integrations you authorise — Google Search Console, Google Analytics, the Google Ads API, Bing, Shopify and SerpApi, used to import the search, advertising, commerce and ranking data your reports are built from. These connect only when you choose to connect them.

**email**: Email delivery — SMTP2GO, used to send transactional and service email such as sign-in links, alerts and scheduled reports. Delivery runs on SMTP2GO's EU infrastructure.

**marketing**: Website analytics and visitor identification — Google Analytics (website analytics), Warmly.ai (business-visitor identification) and logo.dev (company logo lookup). These load only where you have consented to non-essential cookies. Warmly.ai acts as an independent data controller for the identification data it holds and applies its own privacy policy; for European traffic it resolves at company level only. You can opt out with Warmly directly at warmly.ai/p/do-not-sell-share-my-data.

**internal**: Internal operations — Slack, used for internal team communication and operational alerts.

**outro**: A detailed subprocessor list, including each provider's location and the transfer mechanism applied, is available to business customers on request at privacy@targetlytics.com.

#### breachNotification

**title**: Data Breach Notification

**content**: We maintain procedures to detect, investigate, record and respond to personal data breaches. If a breach is likely to result in a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 of the GDPR. Where a breach is likely to result in a high risk to you, we will also notify you directly without undue delay, in clear language, describing what happened and what you can do about it (Article 34). Where we act as a processor on behalf of a customer, we will notify that customer without undue delay so that they can meet their own obligations.

#### dataProvisionRequirement

**title**: Whether You Have to Provide Personal Data

**intro**: Providing personal data to us is not a statutory requirement. Some data is, however, necessary in order to enter into or perform a contract with you, and we want to be clear about what happens if you do not provide it:

##### items

**account**: Name and email address — required to create and operate an account. Without them we cannot provide the service.

**billing**: Billing and company details — required for paid plans. We are also legally required to record them for invoicing under Estonian accounting law.

**integrations**: Google, Shopify and other integrations — entirely optional. If you do not connect them, the product features that depend on that data simply will not work; nothing else changes.

**marketing**: Marketing consent — entirely optional. Refusing or withdrawing it has no effect on your access to or use of the service.

**outro**: There are no consequences of not providing personal data beyond those described above.

#### summary

**title**: At a Glance

**intro**: A short summary for orientation. The detailed sections below are what actually govern, and each link jumps straight to one.

**whatLabel**: What we collect

**whatValue**: Account and contact details you give us, usage and analytics data from our website and product, data you authorise us to import from Google, Shopify and similar services, and business-contact data we receive from third parties. We do not collect special category data.

**whyLabel**: Why we use it

**whyValue**: To run your account and deliver the service, to support and improve the product, to comply with the law, and — where you consent — to market to you. Every purpose has a stated legal basis below.

**whoLabel**: Who receives it

**whoValue**: Hosting, AI, payment, email and analytics providers, all named below. Most act only on our instructions; Warmly.ai acts as an independent controller. We do not sell personal data for money.

**whereLabel**: Where it is stored

**whereValue**: Core product data, our search index and our email delivery all run on EU infrastructure. Some providers process data in the United States under Standard Contractual Clauses.

**rightsLabel**: Your rights

**rightsValue**: Access, correction, deletion, restriction, objection, portability and withdrawal of consent — free of charge, answered within one month. Email privacy@targetlytics.com, or complain to the Estonian Data Protection Inspectorate.

**tocTitle**: Contents

#### specialCategories

**title**: Special Category and Sensitive Data

**content**: We do not seek, and have no need for, the special categories of personal data defined in Article 9 of the GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation. We also do not seek data about criminal convictions or offences. Please do not send us such information through forms, support messages or uploaded content. If you do, we will delete it as soon as we become aware of it, unless we are legally required to keep it.

#### ukGdpr

**title**: Visitors from the United Kingdom

**content**: If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply to our processing of your personal data. The rights described in this policy apply to you in materially the same way, and our lawful bases are the same. Where we transfer personal data out of the United Kingdom, we rely on the UK International Data Transfer Agreement, the UK Addendum to the European Commission's Standard Contractual Clauses, or another mechanism recognised under UK law.

**complaint**: You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom — ico.org.uk. We would ask you to raise it with us first at privacy@targetlytics.com so we have the chance to put it right.

**representative**: If you would like details of our UK representative, or want to confirm whether Article 27 of the UK GDPR applies to our processing of your data, contact us at privacy@targetlytics.com.

#### usStateRights

**title**: Privacy Rights in the United States

**intro**: If you are a resident of California, Colorado, Connecticut, Virginia, Texas or another US state with a comprehensive privacy law, you have the rights set out below. These matter here: visitor identification on our website operates at individual level for traffic from the United States, which is not the case for visitors from the European Economic Area. We encourage you to use them.

**salesStatement**: We do not sell personal information for money. Some US state laws define “sale” or “sharing” broadly enough to include certain advertising, analytics, or cross-context behavioural-advertising activities; to the extent any of our practices fall within that broader definition, the opt-out right below applies to them.

##### items

**know**: Know what personal information we have collected about you, where we obtained it, why we collected it, and the categories of third party we disclosed it to.

**access**: Obtain a copy of the personal information we hold about you, in a portable and readily usable format.

**correct**: Correct personal information about you that is inaccurate.

**delete**: Delete personal information we have collected about you, subject to the exceptions the law allows.

**optOut**: Opt out of the sale or sharing of your personal information and of targeted advertising.

**sensitivePI**: Limit the use or disclosure of sensitive personal information to what is necessary to provide the service you requested. We do not use or disclose sensitive personal information (such as precise geolocation, government identifiers, or health data) for any purpose beyond that, so there is currently nothing further to limit; if that changes, we will update this section and give you a way to exercise this right.

**profiling**: Opt out of profiling in furtherance of decisions producing legal or similarly significant effects. As explained above, we do not carry out profiling of that kind.

**appeal**: Appeal a decision we make about your request. If we decline a request we will tell you how to appeal, and if we deny the appeal you may complain to your state attorney general.

**nonDiscrimination**: Not be treated differently for exercising any of these rights. We will not deny you service, charge a different price, or provide a lower quality of service because you exercised a privacy right.

**gpc**: We honour the Global Privacy Control (GPC). If your browser or a browser extension sends a GPC signal, we treat it as a valid request to opt out of the sale or sharing of your personal information and of targeted advertising for that browser. Because the signal is specific to a browser, you may need to enable it on each browser and device you use.

**agent**: You may use an authorised agent to submit a request for you. We will ask the agent for proof of your written permission, and we may ask you to confirm the authorisation with us directly.

**outro**: To exercise any of these rights, use our Do Not Sell/Share My Data page or email privacy@targetlytics.com. We do not knowingly sell or share the personal information of anyone under 16.


---


*Source: https://targetlytics.com/en/privacy/opt-out*
*Last Updated: 2026-08-24T02:29:16.994Z*
