Privacy Policy
Draft — must be reviewed by a qualified lawyer in the EU before publishing.
Words in [SQUARE BRACKETS] are placeholders to fill in. Notes marked Review, Decision, Verify or Engineering are for the reviewing lawyer and for Max; remove every one of them before publishing.
This policy explains what personal data [COMPANY LEGAL NAME] ("Otto", "we") collects when you visit our website, buy Otto or use it; why we collect it; how long we keep it; who else receives it; and what your rights are.
It covers the data for which we decide the purposes, as controller. When Otto works with personal data for a client (for example customer reviews on the client's website, or the results of the client's ads), we act as that client's processor under our Data Processing Agreement. The client's own privacy notice applies to that data, and the client is the first place to go with questions or requests about it; we help the client answer them.
Who we are and how to reach us
- Controller: [COMPANY LEGAL NAME], [REGISTERED ADDRESS], registered under [CHAMBER OF COMMERCE / CRO NUMBER].
- Privacy questions and requests: [PRIVACY EMAIL].
- Data protection officer: not appointed. Review: whether a DPO is required (Art. 37 GDPR); probably not at this size, but monitoring of ad performance for clients may count as regular monitoring.
- Representative in the EU: [EU REPRESENTATIVE — ONLY IF THE COMPANY IS ESTABLISHED OUTSIDE THE EU]. Review: needed under Art. 27 GDPR if the contracting entity is not established in the EU (for example an Israeli company).
The short version
- Our website runs no third-party analytics or advertising scripts. We count visits with our own tool, which uses no cookies and never stores your IP address.
- Only if you press Accept on our landing page, our server tells Meta when you scan a website, see the result, or start signing up or checking out, so we can measure our own ads. Reject, and nothing goes to Meta. You can change your answer at any time under Privacy choices.
- If your browser sends Do Not Track or Global Privacy Control, we record one anonymous page view and nothing else.
- You sign in to the Otto app with your Google account. From Google we receive only your e-mail address, your name and your Google account ID: no password, and nothing from your Gmail, Drive or contacts.
- For clients, we keep the data needed to run Otto for them, and we delete a brand's data 90 days after its plan or free trial ends.
- Our servers are in Germany. Our AI providers are mostly in the United States; those transfers are covered by the EU's standard contractual clauses or the EU–US Data Privacy Framework.
- We do not sell personal data and do not use it for advertising profiles.
What we collect, why, and on what legal basis
| Who | What we collect | Why | Legal basis (GDPR) | How long |
|---|---|---|---|---|
| Visitors to our website | Page path, referrer site (the domain only), campaign tags (utm), device type, and what you do on the page: scroll depth, sections seen, buttons clicked, questions opened, films played, your answer to the ad-measurement question. A visitor code that changes every day. | To see which parts of the site work and improve it | Legitimate interest, Art. 6(1)(f) | 400 days |
| Visitors who accept ad measurement | For a few moments (scan started, scan result shown, sign-up or checkout started, and, once sign-up opens, sign-up completed or trial started): the moment's name and time, the page address, IP address and browser type, the Meta click ID if you came from a Meta ad, one-way hashes of the daily visitor code and of the country code. Sent to Meta; we store nothing extra. | To measure which of our own ads work and to let Meta optimise their delivery | Consent, Art. 6(1)(a), with consent for the cookie under the ePrivacy rules | We keep nothing beyond the statistics above. Cookies: otto_consent 180 days, otto_fbc 90 days. Meta: under its own policy (section "Ad measurement with Meta") |
| People who use the website scan | The website address typed into the scan box, and the preview our server makes of that public website | To show the preview; to hand it to setup; to understand interest in Otto and follow up with the business | Legitimate interest, Art. 6(1)(f); steps before a contract, Art. 6(1)(b) | Preview: 1 hour, in memory. Scanned address as a lead: 24 months after the last activity |
| Clients (the business owner and their team) | E-mail addresses used to sign in, names if you give them, your Telegram user if you use Telegram, your answers in setup, your approvals, skips and edit requests, messages to support | To provide Otto under our contract, to support you, and to keep an audit trail of who approved what | Contract, Art. 6(1)(b); legitimate interest in security and accountability, Art. 6(1)(f) | While your plan is active, then 90 days (section "How long we keep data") |
| People who sign in with Google (clients, their team, and people trying Otto) | From Google: your e-mail address and that Google has verified it, your name, your Google account ID, and for a Google Workspace account your organisation's domain. From us: when you signed up and last signed in, the dates of your free trial and which trial e-mails we sent, and a session record (a one-way hash of the random code in your browser's sign-in cookie, and when it expires). We do not receive your Google password, keep your profile picture, or keep any Google access token. | To sign you in and keep you signed in; to run your free trial and send its e-mails; to match your payment to your account; to give each business one free trial | Contract and steps before a contract, Art. 6(1)(b); legitimate interest in giving one free trial per business, Art. 6(1)(f) | Account: as long as you have a brand with us, then deleted with the brand (90 days after its plan or trial ends); an account without a brand: 90 days after your last sign-in. Sign-in sessions: 30 days after last use, or when you sign out. A one-way hash of your e-mail address and of your website's domain: 3 years |
| Buyers | Name, e-mail, billing address, VAT ID, plan, amounts, payment status and dates, Stripe customer, subscription and invoice IDs, and to show you which payment method is on file only its type, brand, last four digits and expiry month (for founding seats bought before 1 October 2026: the Whop membership and payment IDs). We never receive full card numbers or bank details. | Billing, invoices, refunds, VAT and tax records | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) | As long as tax law requires, 7 years |
| Anyone who contacts us | Your message and contact details | To answer you | Legitimate interest, Art. 6(1)(f), or steps before a contract | 2 years after the conversation ends |
| Creators who appear in client videos | Name, the footage, and your consent and release | To use the footage in the client's ads as agreed with you | Contract with you or your consent, Art. 6(1)(b) or (a) Review: who contracts with the creator, Otto or the client, decides who is controller here | For as long as the release allows, then deleted |
Decision: fill in the lead and contact retention periods, and decide whether we ever contact a business whose address was scanned but which did not buy. If yes, the lawyer should check the e-mail marketing rules for businesses in NL and IE first.
Our website statistics, in detail
Our pages send short messages to our own server (/otto-track). They contain the page path, the referring site's domain (never the full address), any utm campaign tags in the link you followed (values that look like an e-mail address are dropped), whether you use a phone, tablet or computer, and events on the page: scroll depth in steps of 25%, which sections you looked at, which main buttons you clicked, which questions you opened, which films you played, and a scan you started (with the website address you typed).
We never store your IP address. Our server turns your IP address and browser type into a visitor code with a one-way hash and a random value (a "salt") that is replaced every day at midnight UTC; the old value is deleted. So we can count a visitor once per day, but we cannot recognise you the next day and cannot get your IP address back from the code. IP addresses are also used, in memory only and for minutes, to limit how many requests one connection can make. Nothing is stored on your device for these statistics: no cookies, no local storage.
If your browser sends Do Not Track or Global Privacy Control, the page sends one anonymous page view (path only, without a visitor code, referrer, campaign tags or device type) and nothing else, and our server enforces the same rule.
We keep these records for 400 days and delete older ones every month. We use them only as statistics about our own website: not to profile you, not for advertising, and they are not shared with anyone. You can object at any time; switching on Global Privacy Control in your browser does it automatically.
Review: the ePrivacy rule on accessing information on a device (Art. 5(3) of Directive 2002/58, the Dutch Telecommunicatiewet art. 11.7a, Irish S.I. 336/2011 reg. 5), read with EDPB Guidelines 2/2023: is our statistics beacon, which stores nothing and reads only the screen width, touch capability and the DNT and GPC signals, exempt from consent? This draft assumes it is. The consent question on the landing page covers only ad measurement with Meta (next section); if the lawyer decides the statistics need consent too, they can move under the same question.
Ad measurement with Meta
We advertise Otto on Facebook and Instagram. The landing page asks whether we may measure those ads. Reject and Accept are equal buttons, and the page works the same whichever you press. Your answer is stored in a cookie (otto_consent) so that we do not ask again; Privacy choices at the bottom of the landing page shows it and lets you change it, and withdrawing takes effect at once.
Only if you press Accept, our server sends Meta a message through Meta's Conversions API when you start a website scan, when Otto shows you the result, and when you press a button that starts checkout, sign-up or a trial. Once sign-up opens on our site, it also does so when our server confirms that you completed sign-up or that your trial started; for those two it uses a one-way hash of your account number only to avoid counting the same sign-up twice. The message holds: the name and time of the moment, a random event number, the page address, your IP address and browser type, the Meta click ID if you came to our page from a Meta ad (kept for 90 days in the otto_fbc cookie, which is set only after Accept), and one-way hashes (SHA-256) of our daily visitor code and of your country code. It never holds the website address you scanned, anything you typed, the referring site or campaign tags. No Meta code runs in your browser. If your browser sends Do Not Track or Global Privacy Control, nothing is sent to Meta, whatever you answered.
For collecting these moments on our page and passing them to Meta, we and Meta Platforms Ireland Ltd are joint controllers (Court of Justice of the EU, C-40/17 Fashion ID), under Meta's Business Tools Terms and its Controller Addendum; you can exercise your rights with either of us, and we answer questions about this part. What Meta then does with the data (matching it to a Facebook or Instagram account, measuring and optimising our ads) is Meta's own processing as a separate controller, described in Meta's privacy policy (facebook.com/privacy/policy). Meta may transfer data to Meta Platforms, Inc. in the United States under the EU–US Data Privacy Framework. We receive back only aggregated results: how many people our ads reached and how many of these moments followed.
Review: confirm the joint-controller wording and the Art. 26 essence to be made available; confirm that Meta Platforms, Inc. is certified under the Data Privacy Framework; confirm the legal basis (consent) for the Conversions API route, which reads no information from the device other than our own first-party cookies.
Engineering: forwarding starts only when the server holds the Meta dataset settings (meta-capi.json); until then nothing is sent, even after Accept. See platform/otto_track.py.
The website scan
When you type a web address into the scan box on our website or in setup, our server reads that public website (the home page and up to two more pages) and shows you what it found. The preview is kept in our server's memory for up to one hour so that setup can reuse it, and in your browser tab until you close it. If you go on to set up Otto, the full reading of your site becomes part of your brand, which we process for you as described below.
We keep the scanned address as a possible lead, with our own notes on it. We do not combine it with other data about you and do not buy contact lists. If the address belongs to a one-person business, it may be personal data; you can ask us to delete it at any time.
When you use Otto
To run Otto for your business, we keep your brand profile, your answers, your content calendar, the posts and ads Otto makes, your approvals and skips (Otto learns your taste from them), your connection to Meta and Google (access tokens, never passwords), your ad budgets and results, and the reports we send you. Most of this is business data. The personal data in it — for example a reviewer's name quoted from your website, or a creator in a video — we process on your behalf as your processor under the DPA.
For our own purposes we also keep: who signed in and when (Sign in with Google for the app; Cloudflare Access for our team's owner console), an audit trail of approvals and of every action our team takes in our owner console (who, what, when), error records of our system (without the content of requests), and billing records received from Stripe (and, for the legacy founding seats, Whop).
We may combine usage statistics across all clients, so that no client or person can be identified, to improve Otto (for example which ad styles get more clicks). We do not use client content to train AI models.
Payments
You pay on the Billing page in the Otto app. The payment form on that page is provided by Stripe (Stripe Payments Europe, Ltd., Ireland), our payment service provider: your card or bank details go straight from your browser to Stripe and never reach us. Stripe also calculates VAT and produces our invoices and receipts. We receive from Stripe your name, e-mail address, billing address and VAT ID, your plan and subscription status, the amounts and dates of payments, refunds and failed payments, links to your invoices, and, so we can show you which payment method is on file, its type, brand, last four digits and expiry month. We use this to switch your plan on or off, to show your billing page, and to keep our records. For the payment itself, fraud prevention and its own legal obligations, Stripe acts as an independent controller under its own privacy policy (stripe.com/privacy). To load the payment form, the Billing page loads Stripe's script from js.stripe.com; Stripe may set its own cookies there for fraud prevention, which are strictly necessary for the payment. Review: the processor / controller split under Stripe's DPA; whether Stripe's fraud-prevention cookies need a line in the Cookie notice. Founding seats bought before 1 October 2026 were paid through Whop; for those we keep the records Whop sent us (name, e-mail, plan, amounts, dates, membership status).
Who receives personal data
We use a small number of companies to run Otto. They process data only on our instructions and under data processing terms. The full, current list, with what each one does and where, is on our Sub-processors page. In short:
- Hetzner (Germany): our servers and backups.
- Cloudflare (USA, global network): delivery and protection of our websites, and our team's sign-in to the owner console.
- Google (Google Ireland Limited, with Google LLC in the USA): Sign in with Google. You sign in on Google's own page and Google tells us who you are. Review: Google is an independent controller for your Google account; we list it as a sub-processor for this authentication step.
- AI providers: Anthropic (USA) for writing and strategy; Higgsfield (USA) for images, using OpenAI's GPT Image 2, and for some video and voice-over; Leonardo.ai (Australia) as a fallback for images; ElevenLabs (USA) for synthetic voice-over.
- Stripe (Stripe Payments Europe, Ltd., Ireland, with Stripe, Inc. in the USA): payments, subscriptions, invoices and VAT for our own plans (section "Payments").
- Telegram, if you choose it for approvals, and [EMAIL PROVIDER] for e-mails.
If you accept ad measurement on our landing page, Meta Platforms Ireland Ltd receives the messages described in "Ad measurement with Meta" above, as joint controller with us for that step; it is not our sub-processor.
When you connect Meta or Google, Otto publishes and runs ads in your accounts on your instruction. Meta and Google are not our sub-processors: they are your providers, under your own contract with them.
We disclose data to authorities only when the law requires it, and we tell the person concerned when we are allowed to.
Transfers outside the EU
Our servers and backups are in Germany. Some of the providers above are in the United States or Australia. Where a provider is certified under the EU–US Data Privacy Framework, the transfer relies on the European Commission's adequacy decision for that framework; otherwise it relies on the EU standard contractual clauses (Commission Decision 2021/914), with extra measures where needed. The Sub-processors page says which applies to each provider. You can ask us for a copy of the relevant safeguards.
Verify: where our team works from. If people access Otto's data from Israel, say so: Israel has an EU adequacy decision.
How long we keep data
- Website statistics: 400 days. The daily salt: one day.
- Your answer to the ad-measurement question (
otto_consentcookie, in your browser): 180 days, then we ask again. The Meta click ID (otto_fbccookie, only after Accept): 90 days, deleted at once if you withdraw. - Scan previews: up to one hour, in memory only.
- Leads from the scan box: 24 months after the last activity.
- Client brand data: while the plan is active, then 90 days (so a client who comes back does not start again), then deleted. After a free trial that ended without a plan: 90 days from the end of the trial.
- Your sign-in account: as long as you have a brand with us, then deleted with it; without a brand, 90 days after your last sign-in. Sign-in sessions: 30 days after last use, or at once when you sign out.
- To give each business one free trial: a one-way hash (SHA-256) of the e-mail address and of the website domain that had a trial, without anything else, for 3 years. Decision: the period; the system keeps the hashes for 3 years.
- Billing records: as long as tax law requires, 7 years.
- System logs: 8 weeks. Our web server keeps no access logs; Cloudflare keeps its own logs under its policy.
- Backups: encrypted; daily copies for 14 days and weekly copies for 8 weeks, plus server snapshots for 7 days. Deleted data leaves the backups within about 8 weeks.
Your rights
You can ask us for access to your personal data, for a copy in a portable format, for correction or deletion, and for restriction of its use. You can object at any time to processing based on our legitimate interest, and withdraw any consent you gave, without affecting what happened before; for ad measurement, use Privacy choices at the bottom of our landing page. Send your request to [PRIVACY EMAIL]. We answer within one month and may ask you to confirm who you are.
If your request is about data we process for one of our clients (for example a review of yours on a client's website), we pass it to that client and help them answer.
You also have the right to complain to a data protection authority, for example the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), the Irish Data Protection Commission (dataprotection.ie), or the authority where you live or work. We would appreciate the chance to fix the problem first.
Security
We protect data with measures we describe in detail in the security annex of our DPA: servers in Germany reached only through Cloudflare, Sign in with Google for clients (Otto stores no passwords and checks Google's signed answer) and one-time codes for our team, encrypted connections, encrypted backups, restricted staff access and an audit trail.
Automated decisions
Otto makes marketing proposals automatically, but it takes no decisions about people that have legal or similarly significant effects on them.
Children
Otto is a service for businesses and is not directed at children.
Changes
We will update this policy when our processing changes, and we will tell clients about important changes by e-mail or in the app before they apply. The date at the top shows the current version.