# Targetlytics - /PRIVACY/OPT-OUT (ru)

*Generated for AI LLM consumption*

## Section: PrivacyPolicy

### meta

**title**: Privacy Policy

**description**: Privacy Policy for Targetlytics AI - Learn how we collect, use, and protect your data.

**title**: Privacy Policy

**lastUpdated**: Последнее обновление: 17 августа 2026 г.

### sections

#### introduction

**title**: Introduction

**content**: EYT Eesti OÜ ("we", "our", or "us") operates Targetlytics AI. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

#### dataCollection

**title**: Information We Collect

**content**: We collect information that you provide directly to us, including:

##### items

**name**: Name and contact information

**email**: Email address

**company**: Компания name and details

**usage**: Usage data and analytics

**cookies**: Cookies and tracking technologies

#### googleUserData

**title**: Данные пользователя Google

**intro**: Некоторые функции Targetlytics AI используют данные вашего аккаунта Google. В этом разделе подробно описано, к каким данным пользователя Google мы получаем доступ, зачем, кому они передаются, как защищаются и сколько хранятся. Раздел дополняет остальные положения настоящей политики; при расхождениях к данным пользователя Google применяются этот раздел и раздел об ограниченном использовании ниже.

**accessTitle**: К каким данным Google мы получаем доступ

**access**: Мы запрашиваем только права на чтение и только после того, как вы явно предоставите доступ на экране согласия Google. Мы никогда не запрашиваем разрешение создавать, изменять или удалять что-либо в вашем аккаунте Google.

##### items

**signIn**: Вход через аккаунт Google (openid, email, profile): ваше имя, адрес электронной почты, фотография профиля и идентификатор аккаунта Google, используемые исключительно для создания вашей учётной записи Targetlytics AI и аутентификации.

**analytics**: Google Analytics (analytics.readonly): доступный только для чтения список ресурсов GA4, к которым у вас есть доступ, и данные отчётов по выбранному ресурсу — например сеансы, пользователи, источники трафика, переходы, целевые страницы и события конверсии.

**searchConsole**: Google Search Console (webmasters.readonly): доступный только для чтения список подтверждённых вами сайтов и данные эффективности поиска по выбранному сайту — например поисковые запросы, страницы, показы, клики и средняя позиция.

**useTitle**: Как мы используем данные пользователя Google

**use**: Мы используем эти данные исключительно для предоставления запрошенных вами функций:

##### useItems

**auth**: Аутентификация и защита вашей учётной записи.

**reporting**: Отображение показателей поиска и аналитики в вашей панели Targetlytics AI.

**insights**: Формирование рекомендаций по AI-видимости, атрибуции, позициям и контенту, составляющих основу сервиса.

**support**: Диагностика ошибок и оказание поддержки при вашем обращении.

**aiTitle**: Обработка данных пользователя Google с помощью ИИ

**ai**: Targetlytics AI анализирует ваши данные Google Analytics и Search Console с помощью сторонних моделей ИИ (в настоящее время предоставляемых OpenAI, Google и Anthropic), чтобы формировать отчёты и рекомендации, которые вы видите в продукте. Эти поставщики выступают нашими обработчиками по договорам, запрещающим им использовать ваши данные для обучения или улучшения своих моделей. Данные пользователя Google никогда не используются для разработки, обучения или улучшения обобщённых или неперсонализированных моделей ИИ либо машинного обучения — ни нами, ни кем-либо ещё.

**sharingTitle**: Кому мы передаём данные пользователя Google

**sharing**: Мы не продаём данные пользователя Google и не передаём их в рекламных целях. Они передаются только тем инфраструктурным и ИИ-обработчикам, которые необходимы для работы описанных выше функций, — Google Cloud Platform и Firebase для хостинга и хранения, а также названным выше поставщикам моделей ИИ, — каждый из которых по договору обязан использовать их исключительно по нашим указаниям. В остальных случаях мы раскрываем их только тогда, когда это требуется по закону.

**carveOut**: Данные пользователя Google никогда не используются для идентификации личности или деанонимизации посетителей, никогда не передаются Warmly.ai либо каким-либо рекламным партнёрам, партнёрам по обогащению данных или брокерам данных и никогда не продаются и не передаются в том значении, которое придают этим терминам законы о конфиденциальности, такие как CCPA. Они исключены из процессов идентификации посетителей, описанных в других разделах настоящей политики.

**humansTitle**: Доступ сотрудников

**humans**: Мы не допускаем чтения ваших данных пользователя Google людьми, за исключением случаев, когда: вы дали на это отдельное разрешение (например, чтобы мы могли устранить сообщённую вами проблему); это необходимо в целях безопасности, например для расследования злоупотреблений; этого требует применимое законодательство; либо данные агрегированы и обезличены так, что более не позволяют идентифицировать вас или ваш сайт.

**securityTitle**: Как мы защищаем данные пользователя Google

**security**: Данные передаются по TLS и хранятся в Google Cloud Firestore в регионе europe-north1 в зашифрованном виде. Токены обновления OAuth хранятся только на стороне сервера, никогда не передаются в ваш браузер или третьим лицам и доступны лишь тем серверным функциям, которые выполняют синхронизацию ваших данных. Доступ внутри нашей организации ограничен сотрудниками, которым он необходим для эксплуатации или поддержки сервиса.

**retentionTitle**: Хранение, отключение и удаление

**retention**: Вы всегда сохраняете контроль над этими данными:

##### retentionItems

**disconnect**: Вы можете в любой момент отключить Google Analytics или Search Console на странице «Подключения» в Targetlytics AI. При этом мы немедленно отзываем токен в Google и удаляем сохранённые учётные данные.

**revoke**: Вы также можете в любой момент отозвать наш доступ напрямую в своём аккаунте Google по адресу google.com/permissions.

**reports**: Ранее импортированные данные отчётов остаются в вашем рабочем пространстве, чтобы исторические графики продолжали работать. Они удаляются при удалении бренда или вашей учётной записи, а также в течение 30 дней после запроса на удаление, отправленного на privacy@targetlytics.com.

**account**: При удалении вашей учётной записи все связанные с ней данные пользователя Google — как учётные данные, так и импортированные отчёты — удаляются из наших производственных систем в течение 30 дней.

#### googleLimitedUse

**title**: Ограниченное использование сервисов Google API

**intro**: Использование и передача в любые другие приложения информации, полученной Targetlytics AI через API Google, осуществляется в соответствии с Google API Services User Data Policy, включая требования об ограниченном использовании.

**content**: В частности, мы подтверждаем, что данные пользователя Google не:

##### items

**ads**: используются для таргетированной, персонализированной или ретаргетинговой рекламы и не передаются тем, кто этим занимается;

**sell**: продаются и не передаются брокерам данных, перепродавцам информации или иным лицам, торгующим персональными данными;

**credit**: используются для оценки кредитоспособности или в целях кредитования;

**training**: используются для разработки, обучения или улучшения обобщённых либо неперсонализированных моделей ИИ или машинного обучения.

**transfer**: На любую сторону, которой мы передаём данные пользователя Google, распространяются те же ограничения. Если мы когда-либо захотим использовать данные пользователя Google в новых целях, мы повторно запросим ваше согласие до начала такого использования.

#### dataUse

**title**: How We Use Your Information

**content**: We use the information we collect to:

##### items

**service**: Provide, maintain, and improve our services

**communication**: Communicate with you about our services

**improvement**: Analyze usage patterns to improve user experience

**legal**: Comply with legal obligations

#### dataSharing

**title**: Data Sharing

**content**: We do not sell your personal information. We may share your information only with service providers who assist us in operating our platform, and only to the extent necessary to provide our services.

#### dataSecurity

**title**: Data Security

**content**: We would rather describe our security measures than simply assert them. Data is transmitted over TLS and encrypted at rest. Core product data, our vector search index and our email delivery all run on EU infrastructure. Access to production systems is limited to the personnel who need it, protected by multi-factor authentication, and logged. OAuth tokens for accounts you connect are stored server-side only and are never exposed to your browser or to any third party. We review service providers before giving them access to personal data and bind them by written contract. No system is perfectly secure and we do not claim otherwise — the section below sets out what we do if something goes wrong.

#### userRights

**title**: Your Rights

**content**: You have the right to:

##### items

**access**: Access your personal data

**correction**: Request correction of inaccurate data

**deletion**: Request deletion of your data

**objection**: Object to processing of your data

**portability**: Request data portability

**withdrawal**: Withdraw your consent at any time, where processing is based on consent

**restriction**: Request that we restrict how we use your data, for example while we check the accuracy of data you have disputed

**complaint**: If you are located in the EU/EEA and believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — www.aki.ee — though you may also contact the supervisory authority in your own EU/EEA country of residence.

**requestProcessTitle**: How to exercise these rights, and what happens next

**requestProcess**: Email privacy@targetlytics.com. We do not charge for this. We will respond within one month of receiving your request; if the request is complex, or you have made several, we may extend that by up to two further months and will tell you within the first month if we need to. Before acting we may need to confirm your identity — normally by asking you to write from the email address we already hold — and we will never ask for more information than the request requires. If we cannot do what you have asked, we will explain why and tell you how to complain.

#### cookies

**title**: Cookies

**content**: We use cookies and similar technologies to operate our site and, with your consent, for analytics and marketing purposes. Non-essential cookies are only set after you consent, and you can accept, reject or change your choices at any time via the cookie banner or our Cookie Settings page.

#### socialMedia

**title**: Ссылки на социальные сети

**content**: В нижнем колонтитуле и на страницах нашего сайта есть ссылки на наши профили в LinkedIn и GitHub. Это обычные исходящие ссылки, а не встроенные плагины социальных сетей, кнопки «Нравится» или виджеты — мы не загружаем скрипты этих платформ на наши страницы, и они не могут отслеживать ваше посещение нашего сайта через эти ссылки. При переходе на LinkedIn или GitHub вы покидаете наш сайт, и далее действуют собственная политика конфиденциальности и практика использования файлов cookie этой платформы; платформа может собирать данные о вашем посещении в соответствии со своей собственной политикой конфиденциальности, независимо от нас. Мы не получаем никакой информации о вашей активности на этих платформах, если вы сами не взаимодействуете напрямую с нашим официальным аккаунтом (например, подписываясь, отправляя сообщения или оставляя комментарии).

**platformsTitle**: Платформы, на которые мы ссылаемся

**linkedin**: LinkedIn — см. политику конфиденциальности LinkedIn

**github**: GitHub — см. заявление о конфиденциальности GitHub

#### changes

**title**: Changes to This Policy

**content**: We may update this Privacy Policy as our product, our providers or the law change. The date at the top of this page always reflects the version currently in force. If we make a material change — a new purpose for processing, a new category of recipient, or a change affecting your rights — we will give notice before it takes effect: by email to account holders where we hold an address, and by a prominent notice on this page. We will not process your personal data for a new and incompatible purpose without informing you first and, where the law requires it, obtaining your consent. Previous versions are available on request at privacy@targetlytics.com.

#### contact

**title**: Contact Us

**content**: If you have questions about this Privacy Policy, please contact us at:

**company**: EYT Eesti OÜ

**email**: privacy@targetlytics.com

**regNumber**: Registration number: EE14426777

**address**: Mäepealse tn 31, Tallinn 12618, Estonia

#### controller

**title**: Data Controller

**content**: The data controller responsible for your personal information under the EU General Data Protection Regulation (GDPR) is:

**company**: EYT Eesti OÜ

**regNumber**: Registration number: EE14426777

**address**: Mäepealse tn 31, Tallinn 12618, Estonia

**repNote**: As we are established in the European Union, we are not required to appoint a separate EU representative under Article 27 of the GDPR.

**dpo**: We have assessed whether we must appoint a Data Protection Officer under Article 37 of the GDPR and concluded that we are not required to: our core activities do not consist of large-scale regular and systematic monitoring of individuals, nor of large-scale processing of special category data. Privacy matters are handled directly by our management team, reachable at privacy@targetlytics.com.

#### legalBasis

**title**: Legal Basis for Processing (EU/EEA Users)

**intro**: Where the GDPR applies to you, we only process personal data when we have a valid legal basis. Here is our legal basis for each main purpose:

##### items

**account**: Creating and administering your account and providing the service you signed up for — Contract (Art. 6(1)(b) GDPR)

**support**: Responding to support requests and service communications — Contract / legitimate interest (Art. 6(1)(b), (f) GDPR)

**improvement**: Analysing usage to maintain, secure and improve the product — Legitimate interest (Art. 6(1)(f) GDPR)

**marketing**: Sending marketing communications — Consent (Art. 6(1)(a) GDPR), which you can withdraw at any time

**visitorId**: Visitor identification and business-lead scoring via Warmly.ai — Legitimate interest (Art. 6(1)(f) GDPR), balanced against your rights; you can object at any time

**legal**: Complying with legal obligations and responding to lawful requests — Legal obligation (Art. 6(1)(c) GDPR)

#### internationalTransfers

**title**: International Data Transfers

**content**: Core product data and Google user data are hosted in the EU (Google Cloud Firestore, europe-north1 / Finland). Our vector search index (Qdrant) and our transactional email provider (SMTP2GO) likewise run on EU infrastructure. Some of our other service providers — including our AI model providers (OpenAI, Anthropic, Google, Microsoft, Amazon Web Services and NVIDIA), Stripe, SerpApi, Slack and Warmly.ai — are based in, or process data in, the United States or other countries outside the European Economic Area. Where those providers act as our processors, we transfer personal data on the basis of the European Commission's Standard Contractual Clauses or another legally recognised transfer mechanism, and we require safeguards equivalent to the GDPR. Where a provider acts as an independent controller, it is responsible for the lawfulness of its own transfers under its own privacy policy. You can ask us which mechanism applies to a specific provider by emailing privacy@targetlytics.com.

#### visitorIdentification

**title**: Visitor Identification and Warmly

**intro**: We use Warmly.ai to help us understand which companies are interested in Targetlytics. This can include identity resolution, which means automatically using website activity and business data to help de-anonymise website traffic. For visitors from the EEA this operates at company level only — Warmly states that its data providers do not match individual contacts inside the EU. Person-level identification applies to traffic from outside the EEA, principally the United States.

**profile**: The profile information we may collect or receive includes names, email addresses, job titles, companies, and social network links. We may connect information collected online with information collected offline or from trusted third-party sources so we can better understand interest in our services and follow up with relevant business communications.

**legalBasis**: Where the GDPR applies, we rely on our legitimate interest in identifying and following up with likely business customers (Art. 6(1)(f) GDPR). We have weighed this interest against your rights and freedoms. Targetlytics and Warmly.ai act as separate, independent controllers for this activity — not as joint controllers — and each is responsible for its own processing under its own privacy policy. You can object to this processing at any time via our Cookie Settings or by emailing us, and we will honour opt-outs.

**linkText**: Warmly's privacy FAQ

#### retention

**title**: How Long We Keep Data

**content**: We keep personal information only for as long as necessary for the purposes described in this policy, or as required by law:

##### items

**account**: Account and product data: for as long as your account is active, and up to 24 months after closure in case you wish to reactivate, unless you ask us to delete it sooner.

**googleData**: Google user data: as described in the Google User Data section above — deleted immediately on disconnection, except historical reports, which are deleted when you delete your account.

**visitorId**: Business-visitor identification data (Warmly.ai): kept for up to 24 months after our last meaningful interaction with the associated company, unless you ask us to delete it sooner.

**billing**: Billing and invoicing records: kept for the period required by Estonian tax and accounting law (currently 7 years).

**legal**: Any data needed to establish, exercise or defend legal claims: for as long as necessary for that purpose.

**deletionRequests**: Запросы на удаление: после проверки вашей личности мы выполняем запросы на удаление в течение 30 дней с момента получения.

**backups**: Резервные копии: удаление данных немедленно удаляет их из наших рабочих продуктивных систем. Зашифрованные резервные копии хранятся по скользящему циклу до 30 дней в целях аварийного восстановления и автоматически перезаписываются целиком (а не выборочно редактируются) в конце этого цикла — поэтому данные, на которые распространяется ваш запрос об удалении, полностью удаляются из резервных копий в течение 30 дней.

#### children

**title**: Children's Privacy

**content**: Targetlytics AI is a business-to-business product intended for use by professionals and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

#### thirdPartyData

**title**: Personal Data We Obtain From Other Sources

**intro**: We do not always receive personal data directly from you. We also obtain business-contact information about professionals from third parties. This section is provided to satisfy Article 14 of the GDPR.

**categoriesTitle**: What we receive

**categories**: Name, business email address, job title, employer, company size, industry and region, links to professional social network profiles, and a record of the pages viewed on our website. For visitors from the EEA, identification is company-level only — we do not receive your name, email address or personal profile from this source.

**sourcesTitle**: Where it comes from

**sources**: Primarily Warmly.ai and the data providers it licenses from, together with publicly available sources such as company websites, professional social networks and business registries. Warmly.ai acts as an independent data controller for this activity under its own privacy policy, not as our processor. Importantly for visitors from the EEA: Warmly states that its data providers do not match individual contacts inside the EU and resolve European traffic at company level only. If information does not identify an individual, it is not personal data and the individual rights described in this policy do not attach to it.

**basisTitle**: Why we are allowed to do this

**basis**: We rely on our legitimate interest in identifying and contacting likely business customers (Art. 6(1)(f) GDPR). We have weighed that interest against your rights and freedoms and limited the data to a professional, business-to-business context.

**rightsTitle**: Your control over it

**rights**: Where we contact you using information obtained this way, we will tell you in that first communication where we got your details, as Article 14 requires. You can object at any time, ask us what we hold, or ask us to delete it, by emailing privacy@targetlytics.com — we will action deletion requests and will not need a reason from you. We do not use data obtained from these sources to make any decision that produces legal effects for you.

#### profiling

**title**: Profiling and Automated Decision-Making

**intro**: We use automated processing in two places, and we want to be explicit about both.

**visitorTitle**: Scoring business visitors to our website

**visitorLogic**: The logic combines the pages you viewed on our site, how often and how recently you visited, and firmographic information about your employer (company size, industry, region) received from our providers, to produce a priority score visible to our sales team. For visitors from the EEA this scoring runs on company-level information only and does not identify you as an individual.

**visitorConsequence**: The only consequence is whether, and how quickly, a member of our team reaches out to you. It has no effect on pricing, on access to the service, or on any decision about you as an individual.

**productTitle**: Automated analysis inside the product

**productLogic**: Targetlytics AI generates visibility scores, competitor rankings and content recommendations by automated analysis of search, analytics and AI-answer data. This is the service our customers buy. It profiles brands and websites, not individuals.

**art22Title**: No decisions with legal or similarly significant effects

**art22**: We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 of the GDPR. We do not use automated processing to make credit, pricing, employment, insurance or eligibility decisions.

**objectTitle**: Your right to object

**object**: You have an absolute right to object to profiling carried out for direct marketing purposes (Art. 21(2) GDPR). If you object, we stop — no balancing test, no exceptions. Use our Cookie Settings, the opt-out page linked below, or email privacy@targetlytics.com.

#### aiTransparency

**title**: Системы ИИ, ограничения и Закон ЕС об ИИ

**intro**: Targetlytics — платформа на основе ИИ. Многие из создаваемых нами показателей, аналитических данных и контента — включая оценки видимости в ИИ, конкурентную аналитику, отслеживание цитирований, обнаружение галлюцинаций и предлагаемый контент — создаются или дополняются с помощью машинного обучения и больших языковых моделей (LLM), включая сторонние модели ИИ, которые мы используем в качестве субподрядчиков (см. раздел «Субобработчики» выше).

**mistakesTitle**: ИИ может ошибаться

**mistakes**: Результаты, созданные или дополненные ИИ, носят вероятностный характер и не являются проверенными фактами. Они могут быть неполными, устаревшими, неверно приписанными или просто ошибочными — включая «галлюцинированные» утверждения, неверные цитаты или неточные данные о конкурентах или видимости. Мы принимаем разумные меры для снижения таких ошибок, включая собственные функции обнаружения галлюцинаций, однако ни одна система ИИ не свободна от ошибок. Относитесь к созданным ИИ показателям, аналитике и контенту как к вспомогательному материалу для принятия решений, а не к проверенным фактам, и применяйте собственное суждение или независимую проверку перед тем, как полагаться на них при принятии деловых, юридических, финансовых или иных значимых решений.

**transparencyTitle**: Ваше право знать, когда вы взаимодействуете с ИИ (Закон ЕС об ИИ)

**transparency**: Согласно Регламенту (ЕС) 2024/1689 (Закон ЕС об ИИ) поставщики и операторы определённых систем ИИ обязаны информировать пользователей о том, что они взаимодействуют с системой ИИ, или о том, что контент создан или изменён ИИ (статья 50). В соответствии с этим мы обозначаем функции и контент, созданные с помощью ИИ, в продукте, если это не очевидно из контекста, помечаем созданный ИИ текст, изображения или отчёты, которые мы готовим для вас, где это требуется, и обозначаем наши чат- и инструменты поддержки, ориентированные на клиентов, как основанные на ИИ, где это применимо. Автоматизированное принятие решений с юридическими или аналогичными существенными последствиями для физических лиц описано в разделе «Профилирование и автоматизированное принятие решений» выше, включая ваше право на пересмотр решения человеком.

**riskTitle**: Классификация риска

**risk**: Targetlytics — инструмент бизнес-аналитики и маркетинговой разведки. Он не выполняет биометрическую идентификацию, кредитный скоринг, решения о найме, правоохранительную деятельность или иное использование, которое Закон ЕС об ИИ относит к «высокому риску» или «неприемлемому риску». Мы рассматриваем наш продукт как систему ИИ с ограниченным риском, подпадающую в первую очередь под описанные выше обязательства по прозрачности, и регулярно пересматриваем эту классификацию по мере развития нашего продукта и руководств по применению Закона.

**oversightTitle**: Контроль со стороны человека

**oversight**: Созданные ИИ результаты в Targetlytics призваны дополнять, а не заменять человеческое суждение. Вы можете запросить пересмотр человеком любого автоматизированного результата, существенно затрагивающего вас, обратившись по адресу privacy@targetlytics.com; см. также разделы «Права пользователей» и «Профилирование и автоматизированное принятие решений» выше.

#### controllerProcessor

**title**: When We Act as a Processor for Our Customers

**intro**: We play two different roles under the GDPR, and which one applies changes who is responsible for your data.

**controllerTitle**: Where we are the controller

**controller**: We are the data controller for visitors to our own website, for prospects we contact, and for the people who hold Targetlytics AI accounts. Everything else described in this policy concerns that role.

**processorTitle**: Where we are a processor

**processor**: We act as a processor on behalf of our business customers for the data they bring into the platform: their Google Analytics and Search Console data, data about visitors to their websites collected through our tracking script, and the brand, content and competitor information they upload. We process that data only on their documented instructions, in line with Article 28 of the GDPR.

**endUserTitle**: If you are a visitor to one of our customers' websites

**endUser**: In that case our customer is the controller and their privacy policy governs. Please direct requests to access, correct or delete your data to them. If you contact us instead, we will pass your request to the relevant customer without undue delay and assist them in responding.

**dpaTitle**: Data Processing Agreement

**dpa**: Business customers can request our Data Processing Agreement, which incorporates the European Commission's Standard Contractual Clauses and our current subprocessor list, by emailing privacy@targetlytics.com. It is also available as part of our enterprise contracting process.

#### subprocessors

**title**: Service Providers and Subprocessors

**intro**: We rely on the following categories of service provider to operate Targetlytics AI. Most act as our processors and are bound by a written contract to process personal data only on our instructions. A small number — notably Warmly.ai — act as independent controllers for part of their processing and apply their own privacy policies; we say so explicitly below where that is the case. Where a provider is located outside the European Economic Area we rely on the transfer mechanisms described above. We keep this list current and update it here when we add or replace a provider.

##### items

**infrastructure**: Hosting and infrastructure — Vercel (website hosting and content delivery), Google Cloud Platform and Firebase (authentication, database, serverless functions and file storage; core product data is stored in the EU), and Qdrant (vector search index, hosted in the EU).

**payments**: Payments and billing — Stripe (subscription billing and payment processing). We never see or store your full payment card details; Stripe handles them directly.

**ai**: AI model providers — OpenAI, Google (Gemini), Microsoft Azure AI Foundry, Amazon Web Services (Bedrock) and NVIDIA (NIM), used to generate the analyses and recommendations in the product. All are contractually prohibited from using your data to train or improve their models.

**integrations**: Data sources and integrations you authorise — Google Search Console, Google Analytics, the Google Ads API, Bing, Shopify and SerpApi, used to import the search, advertising, commerce and ranking data your reports are built from. These connect only when you choose to connect them.

**email**: Email delivery — SMTP2GO, used to send transactional and service email such as sign-in links, alerts and scheduled reports. Delivery runs on SMTP2GO's EU infrastructure.

**marketing**: Website analytics and visitor identification — Google Analytics (website analytics), Warmly.ai (business-visitor identification) and logo.dev (company logo lookup). These load only where you have consented to non-essential cookies. Warmly.ai acts as an independent data controller for the identification data it holds and applies its own privacy policy; for European traffic it resolves at company level only. You can opt out with Warmly directly at warmly.ai/p/do-not-sell-share-my-data.

**internal**: Internal operations — Slack, used for internal team communication and operational alerts.

**outro**: A detailed subprocessor list, including each provider's location and the transfer mechanism applied, is available to business customers on request at privacy@targetlytics.com.

#### breachNotification

**title**: Data Breach Notification

**content**: We maintain procedures to detect, investigate, record and respond to personal data breaches. If a breach is likely to result in a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 of the GDPR. Where a breach is likely to result in a high risk to you, we will also notify you directly without undue delay, in clear language, describing what happened and what you can do about it (Article 34). Where we act as a processor on behalf of a customer, we will notify that customer without undue delay so that they can meet their own obligations.

#### dataProvisionRequirement

**title**: Whether You Have to Provide Personal Data

**intro**: Providing personal data to us is not a statutory requirement. Some data is, however, necessary in order to enter into or perform a contract with you, and we want to be clear about what happens if you do not provide it:

##### items

**account**: Name and email address — required to create and operate an account. Without them we cannot provide the service.

**billing**: Billing and company details — required for paid plans. We are also legally required to record them for invoicing under Estonian accounting law.

**integrations**: Google, Shopify and other integrations — entirely optional. If you do not connect them, the product features that depend on that data simply will not work; nothing else changes.

**marketing**: Marketing consent — entirely optional. Refusing or withdrawing it has no effect on your access to or use of the service.

**outro**: There are no consequences of not providing personal data beyond those described above.

#### summary

**title**: At a Glance

**intro**: A short summary for orientation. The detailed sections below are what actually govern, and each link jumps straight to one.

**whatLabel**: What we collect

**whatValue**: Account and contact details you give us, usage and analytics data from our website and product, data you authorise us to import from Google, Shopify and similar services, and business-contact data we receive from third parties. We do not collect special category data.

**whyLabel**: Why we use it

**whyValue**: To run your account and deliver the service, to support and improve the product, to comply with the law, and — where you consent — to market to you. Every purpose has a stated legal basis below.

**whoLabel**: Who receives it

**whoValue**: Hosting, AI, payment, email and analytics providers, all named below. Most act only on our instructions; Warmly.ai acts as an independent controller. We do not sell personal data for money.

**whereLabel**: Where it is stored

**whereValue**: Core product data, our search index and our email delivery all run on EU infrastructure. Some providers process data in the United States under Standard Contractual Clauses.

**rightsLabel**: Your rights

**rightsValue**: Access, correction, deletion, restriction, objection, portability and withdrawal of consent — free of charge, answered within one month. Email privacy@targetlytics.com, or complain to the Estonian Data Protection Inspectorate.

**tocTitle**: Contents

#### specialCategories

**title**: Special Category and Sensitive Data

**content**: We do not seek, and have no need for, the special categories of personal data defined in Article 9 of the GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation. We also do not seek data about criminal convictions or offences. Please do not send us such information through forms, support messages or uploaded content. If you do, we will delete it as soon as we become aware of it, unless we are legally required to keep it.

#### ukGdpr

**title**: Visitors from the United Kingdom

**content**: If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply to our processing of your personal data. The rights described in this policy apply to you in materially the same way, and our lawful bases are the same. Where we transfer personal data out of the United Kingdom, we rely on the UK International Data Transfer Agreement, the UK Addendum to the European Commission's Standard Contractual Clauses, or another mechanism recognised under UK law.

**complaint**: You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom — ico.org.uk. We would ask you to raise it with us first at privacy@targetlytics.com so we have the chance to put it right.

**representative**: If you would like details of our UK representative, or want to confirm whether Article 27 of the UK GDPR applies to our processing of your data, contact us at privacy@targetlytics.com.

#### usStateRights

**title**: Privacy Rights in the United States

**intro**: If you are a resident of California, Colorado, Connecticut, Virginia, Texas or another US state with a comprehensive privacy law, you have the rights set out below. These matter here: visitor identification on our website operates at individual level for traffic from the United States, which is not the case for visitors from the European Economic Area. We encourage you to use them.

**salesStatement**: Мы не продаём персональные данные за деньги. Некоторые законы штатов США определяют «продажу» или «передачу» достаточно широко, включая определённую рекламную, аналитическую или кросс-контекстную поведенческую рекламную деятельность; в той мере, в какой наши практики подпадают под это более широкое определение, право на отказ ниже применяется к ним.

##### items

**know**: Know what personal information we have collected about you, where we obtained it, why we collected it, and the categories of third party we disclosed it to.

**access**: Obtain a copy of the personal information we hold about you, in a portable and readily usable format.

**correct**: Correct personal information about you that is inaccurate.

**delete**: Delete personal information we have collected about you, subject to the exceptions the law allows.

**optOut**: Opt out of the sale or sharing of your personal information and of targeted advertising.

**sensitivePI**: Ограничить использование или раскрытие чувствительных персональных данных до объёма, необходимого для предоставления запрошенной вами услуги. Мы не используем и не раскрываем чувствительные персональные данные (такие как точная геолокация, государственные идентификаторы или данные о здоровье) для каких-либо иных целей, поэтому в настоящее время ограничивать нечего; если это изменится, мы обновим данный раздел и предоставим вам способ реализовать это право.

**profiling**: Opt out of profiling in furtherance of decisions producing legal or similarly significant effects. As explained above, we do not carry out profiling of that kind.

**appeal**: Appeal a decision we make about your request. If we decline a request we will tell you how to appeal, and if we deny the appeal you may complain to your state attorney general.

**nonDiscrimination**: Not be treated differently for exercising any of these rights. We will not deny you service, charge a different price, or provide a lower quality of service because you exercised a privacy right.

**gpc**: We honour the Global Privacy Control (GPC). If your browser or a browser extension sends a GPC signal, we treat it as a valid request to opt out of the sale or sharing of your personal information and of targeted advertising for that browser. Because the signal is specific to a browser, you may need to enable it on each browser and device you use.

**agent**: You may use an authorised agent to submit a request for you. We will ask the agent for proof of your written permission, and we may ask you to confirm the authorisation with us directly.

**outro**: To exercise any of these rights, use our Do Not Sell/Share My Data page or email privacy@targetlytics.com. We do not knowingly sell or share the personal information of anyone under 16.


---


*Source: https://targetlytics.com/ru/privacy/opt-out*
*Last Updated: 2026-08-24T05:28:15.465Z*
