OttoLegal

Privacy Policy

Draft — must be reviewed by a qualified lawyer in the EU before publishing.

Words in [SQUARE BRACKETS] are placeholders to fill in. Notes marked Review, Decision, Verify or Engineering are for the reviewing lawyer and for Max; remove every one of them before publishing.

Version: Draft 0.2 · 30 September 2026 · In force from [EFFECTIVE DATE]

This policy explains what personal data [COMPANY LEGAL NAME] ("Otto", "we") collects when you visit our website, buy Otto or use it; why we collect it; how long we keep it; who else receives it; and what your rights are.

It covers the data for which we decide the purposes, as controller. When Otto works with personal data for a client (for example customer reviews on the client's website, or the results of the client's ads), we act as that client's processor under our Data Processing Agreement. The client's own privacy notice applies to that data, and the client is the first place to go with questions or requests about it; we help the client answer them.

Who we are and how to reach us

The short version

WhoWhat we collectWhyLegal basis (GDPR)How long
Visitors to our websitePage path, referrer site (the domain only), campaign tags (utm), device type, and what you do on the page: scroll depth, sections seen, buttons clicked, questions opened, films played, your answer to the ad-measurement question. A visitor code that changes every day.To see which parts of the site work and improve itLegitimate interest, Art. 6(1)(f)400 days
Visitors who accept ad measurementFor a few moments (scan started, scan result shown, sign-up or checkout started, and, once sign-up opens, sign-up completed or trial started): the moment's name and time, the page address, IP address and browser type, the Meta click ID if you came from a Meta ad, one-way hashes of the daily visitor code and of the country code. Sent to Meta; we store nothing extra.To measure which of our own ads work and to let Meta optimise their deliveryConsent, Art. 6(1)(a), with consent for the cookie under the ePrivacy rulesWe keep nothing beyond the statistics above. Cookies: otto_consent 180 days, otto_fbc 90 days. Meta: under its own policy (section "Ad measurement with Meta")
People who use the website scanThe website address typed into the scan box, and the preview our server makes of that public websiteTo show the preview; to hand it to setup; to understand interest in Otto and follow up with the businessLegitimate interest, Art. 6(1)(f); steps before a contract, Art. 6(1)(b)Preview: 1 hour, in memory. Scanned address as a lead: 24 months after the last activity
Clients (the business owner and their team)E-mail addresses used to sign in, names if you give them, your Telegram user if you use Telegram, your answers in setup, your approvals, skips and edit requests, messages to supportTo provide Otto under our contract, to support you, and to keep an audit trail of who approved whatContract, Art. 6(1)(b); legitimate interest in security and accountability, Art. 6(1)(f)While your plan is active, then 90 days (section "How long we keep data")
People who sign in with Google (clients, their team, and people trying Otto)From Google: your e-mail address and that Google has verified it, your name, your Google account ID, and for a Google Workspace account your organisation's domain. From us: when you signed up and last signed in, the dates of your free trial and which trial e-mails we sent, and a session record (a one-way hash of the random code in your browser's sign-in cookie, and when it expires). We do not receive your Google password, keep your profile picture, or keep any Google access token.To sign you in and keep you signed in; to run your free trial and send its e-mails; to match your payment to your account; to give each business one free trialContract and steps before a contract, Art. 6(1)(b); legitimate interest in giving one free trial per business, Art. 6(1)(f)Account: as long as you have a brand with us, then deleted with the brand (90 days after its plan or trial ends); an account without a brand: 90 days after your last sign-in. Sign-in sessions: 30 days after last use, or when you sign out. A one-way hash of your e-mail address and of your website's domain: 3 years
BuyersName, e-mail, billing address, VAT ID, plan, amounts, payment status and dates, Stripe customer, subscription and invoice IDs, and to show you which payment method is on file only its type, brand, last four digits and expiry month (for founding seats bought before 1 October 2026: the Whop membership and payment IDs). We never receive full card numbers or bank details.Billing, invoices, refunds, VAT and tax recordsContract, Art. 6(1)(b); legal obligation, Art. 6(1)(c)As long as tax law requires, 7 years
Anyone who contacts usYour message and contact detailsTo answer youLegitimate interest, Art. 6(1)(f), or steps before a contract2 years after the conversation ends
Creators who appear in client videosName, the footage, and your consent and releaseTo use the footage in the client's ads as agreed with youContract with you or your consent, Art. 6(1)(b) or (a) Review: who contracts with the creator, Otto or the client, decides who is controller hereFor as long as the release allows, then deleted

Decision: fill in the lead and contact retention periods, and decide whether we ever contact a business whose address was scanned but which did not buy. If yes, the lawyer should check the e-mail marketing rules for businesses in NL and IE first.

Our website statistics, in detail

Our pages send short messages to our own server (/otto-track). They contain the page path, the referring site's domain (never the full address), any utm campaign tags in the link you followed (values that look like an e-mail address are dropped), whether you use a phone, tablet or computer, and events on the page: scroll depth in steps of 25%, which sections you looked at, which main buttons you clicked, which questions you opened, which films you played, and a scan you started (with the website address you typed).

We never store your IP address. Our server turns your IP address and browser type into a visitor code with a one-way hash and a random value (a "salt") that is replaced every day at midnight UTC; the old value is deleted. So we can count a visitor once per day, but we cannot recognise you the next day and cannot get your IP address back from the code. IP addresses are also used, in memory only and for minutes, to limit how many requests one connection can make. Nothing is stored on your device for these statistics: no cookies, no local storage.

If your browser sends Do Not Track or Global Privacy Control, the page sends one anonymous page view (path only, without a visitor code, referrer, campaign tags or device type) and nothing else, and our server enforces the same rule.

We keep these records for 400 days and delete older ones every month. We use them only as statistics about our own website: not to profile you, not for advertising, and they are not shared with anyone. You can object at any time; switching on Global Privacy Control in your browser does it automatically.

Review: the ePrivacy rule on accessing information on a device (Art. 5(3) of Directive 2002/58, the Dutch Telecommunicatiewet art. 11.7a, Irish S.I. 336/2011 reg. 5), read with EDPB Guidelines 2/2023: is our statistics beacon, which stores nothing and reads only the screen width, touch capability and the DNT and GPC signals, exempt from consent? This draft assumes it is. The consent question on the landing page covers only ad measurement with Meta (next section); if the lawyer decides the statistics need consent too, they can move under the same question.

Ad measurement with Meta

We advertise Otto on Facebook and Instagram. The landing page asks whether we may measure those ads. Reject and Accept are equal buttons, and the page works the same whichever you press. Your answer is stored in a cookie (otto_consent) so that we do not ask again; Privacy choices at the bottom of the landing page shows it and lets you change it, and withdrawing takes effect at once.

Only if you press Accept, our server sends Meta a message through Meta's Conversions API when you start a website scan, when Otto shows you the result, and when you press a button that starts checkout, sign-up or a trial. Once sign-up opens on our site, it also does so when our server confirms that you completed sign-up or that your trial started; for those two it uses a one-way hash of your account number only to avoid counting the same sign-up twice. The message holds: the name and time of the moment, a random event number, the page address, your IP address and browser type, the Meta click ID if you came to our page from a Meta ad (kept for 90 days in the otto_fbc cookie, which is set only after Accept), and one-way hashes (SHA-256) of our daily visitor code and of your country code. It never holds the website address you scanned, anything you typed, the referring site or campaign tags. No Meta code runs in your browser. If your browser sends Do Not Track or Global Privacy Control, nothing is sent to Meta, whatever you answered.

For collecting these moments on our page and passing them to Meta, we and Meta Platforms Ireland Ltd are joint controllers (Court of Justice of the EU, C-40/17 Fashion ID), under Meta's Business Tools Terms and its Controller Addendum; you can exercise your rights with either of us, and we answer questions about this part. What Meta then does with the data (matching it to a Facebook or Instagram account, measuring and optimising our ads) is Meta's own processing as a separate controller, described in Meta's privacy policy (facebook.com/privacy/policy). Meta may transfer data to Meta Platforms, Inc. in the United States under the EU–US Data Privacy Framework. We receive back only aggregated results: how many people our ads reached and how many of these moments followed.

Review: confirm the joint-controller wording and the Art. 26 essence to be made available; confirm that Meta Platforms, Inc. is certified under the Data Privacy Framework; confirm the legal basis (consent) for the Conversions API route, which reads no information from the device other than our own first-party cookies.

Engineering: forwarding starts only when the server holds the Meta dataset settings (meta-capi.json); until then nothing is sent, even after Accept. See platform/otto_track.py.

The website scan

When you type a web address into the scan box on our website or in setup, our server reads that public website (the home page and up to two more pages) and shows you what it found. The preview is kept in our server's memory for up to one hour so that setup can reuse it, and in your browser tab until you close it. If you go on to set up Otto, the full reading of your site becomes part of your brand, which we process for you as described below.

We keep the scanned address as a possible lead, with our own notes on it. We do not combine it with other data about you and do not buy contact lists. If the address belongs to a one-person business, it may be personal data; you can ask us to delete it at any time.

When you use Otto

To run Otto for your business, we keep your brand profile, your answers, your content calendar, the posts and ads Otto makes, your approvals and skips (Otto learns your taste from them), your connection to Meta and Google (access tokens, never passwords), your ad budgets and results, and the reports we send you. Most of this is business data. The personal data in it — for example a reviewer's name quoted from your website, or a creator in a video — we process on your behalf as your processor under the DPA.

For our own purposes we also keep: who signed in and when (Sign in with Google for the app; Cloudflare Access for our team's owner console), an audit trail of approvals and of every action our team takes in our owner console (who, what, when), error records of our system (without the content of requests), and billing records received from Stripe (and, for the legacy founding seats, Whop).

We may combine usage statistics across all clients, so that no client or person can be identified, to improve Otto (for example which ad styles get more clicks). We do not use client content to train AI models.

Payments

You pay on the Billing page in the Otto app. The payment form on that page is provided by Stripe (Stripe Payments Europe, Ltd., Ireland), our payment service provider: your card or bank details go straight from your browser to Stripe and never reach us. Stripe also calculates VAT and produces our invoices and receipts. We receive from Stripe your name, e-mail address, billing address and VAT ID, your plan and subscription status, the amounts and dates of payments, refunds and failed payments, links to your invoices, and, so we can show you which payment method is on file, its type, brand, last four digits and expiry month. We use this to switch your plan on or off, to show your billing page, and to keep our records. For the payment itself, fraud prevention and its own legal obligations, Stripe acts as an independent controller under its own privacy policy (stripe.com/privacy). To load the payment form, the Billing page loads Stripe's script from js.stripe.com; Stripe may set its own cookies there for fraud prevention, which are strictly necessary for the payment. Review: the processor / controller split under Stripe's DPA; whether Stripe's fraud-prevention cookies need a line in the Cookie notice. Founding seats bought before 1 October 2026 were paid through Whop; for those we keep the records Whop sent us (name, e-mail, plan, amounts, dates, membership status).

Who receives personal data

We use a small number of companies to run Otto. They process data only on our instructions and under data processing terms. The full, current list, with what each one does and where, is on our Sub-processors page. In short:

If you accept ad measurement on our landing page, Meta Platforms Ireland Ltd receives the messages described in "Ad measurement with Meta" above, as joint controller with us for that step; it is not our sub-processor.

When you connect Meta or Google, Otto publishes and runs ads in your accounts on your instruction. Meta and Google are not our sub-processors: they are your providers, under your own contract with them.

We disclose data to authorities only when the law requires it, and we tell the person concerned when we are allowed to.

Transfers outside the EU

Our servers and backups are in Germany. Some of the providers above are in the United States or Australia. Where a provider is certified under the EU–US Data Privacy Framework, the transfer relies on the European Commission's adequacy decision for that framework; otherwise it relies on the EU standard contractual clauses (Commission Decision 2021/914), with extra measures where needed. The Sub-processors page says which applies to each provider. You can ask us for a copy of the relevant safeguards.

Verify: where our team works from. If people access Otto's data from Israel, say so: Israel has an EU adequacy decision.

How long we keep data

Your rights

You can ask us for access to your personal data, for a copy in a portable format, for correction or deletion, and for restriction of its use. You can object at any time to processing based on our legitimate interest, and withdraw any consent you gave, without affecting what happened before; for ad measurement, use Privacy choices at the bottom of our landing page. Send your request to [PRIVACY EMAIL]. We answer within one month and may ask you to confirm who you are.

If your request is about data we process for one of our clients (for example a review of yours on a client's website), we pass it to that client and help them answer.

You also have the right to complain to a data protection authority, for example the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), the Irish Data Protection Commission (dataprotection.ie), or the authority where you live or work. We would appreciate the chance to fix the problem first.

Security

We protect data with measures we describe in detail in the security annex of our DPA: servers in Germany reached only through Cloudflare, Sign in with Google for clients (Otto stores no passwords and checks Google's signed answer) and one-time codes for our team, encrypted connections, encrypted backups, restricted staff access and an audit trail.

Automated decisions

Otto makes marketing proposals automatically, but it takes no decisions about people that have legal or similarly significant effects on them.

Children

Otto is a service for businesses and is not directed at children.

Changes

We will update this policy when our processing changes, and we will tell clients about important changes by e-mail or in the app before they apply. The date at the top shows the current version.

Back to top