Legal
Privacy Policy
Last updated: July 13, 2026
Protecting your personal data is essential to us, not just because the law requires it, but because data is at the core of what we do. We help our clients collect, process, and protect data correctly—and we apply the exact same principles to the data we collect from you.
This Privacy Policy describes what personal data we process, why we use it, how long we keep it, and what your rights are.
- Who is the Data Controller? The data controller responsible for your personal data under the General Data Protection Regulation (GDPR) is:
Marketing Intelligence s.r.o.
Dornych 486/47b, Trnitá, 617 00 Brno, Czech Republic
Company ID (IČO): 09546529
Email: info@marketingintelligence.io
Registered in the Commercial Register maintained by the Regional Court in Brno, Section C, Insert 119525.
We have not appointed a Data Protection Officer (DPO), as we are not legally required to do so. For any questions regarding your personal data, please contact us at the email address above.
- What Data We Process and Why We only process data that is strictly necessary for specific purposes. Our website is static and designed to respect your privacy—we do not use any marketing, tracking, or analytical cookies.
A. When you contact us via the contact form or email What data: Name, email address, phone number, company name, and the content of your message.
Purpose: To respond to your inquiry, request, or demand and discuss further business cooperation.
Legal basis: Taking steps prior to entering into a contract and our legitimate interest in communicating with potential clients (Art. 6(1)(b) and (f) GDPR).
Retention period: For the duration of our communication, and subsequently for a maximum of 3 years in case of follow-up inquiries.
B. When you order a service from us (B2B Clients) What data: Billing information, contact details of your employees/representatives, technical access details necessary to provide the service, and project-related cooperation data.
Purpose: Performance of the contract, invoicing, and legal compliance (accounting, taxes, archiving).
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).
Retention period: For the duration of the contract, and subsequently for 10 years as required by applicable accounting and tax laws.
C. When you visit our website (Server Logs & Analytics) Our website is hosted using Cloudflare. We use Cloudflare Web Analytics, which is a privacy-first, cookieless analytics tool, and Cloudflare Turnstile to protect our forms from spam without using invasive user tracking.
What data: Technical data about your browser and device, visited pages, approximate location (country/city level based on IP, but IP addresses are anonymized/not stored by us), timestamp, and referral source.
Purpose: Ensuring the security and stability of the website, defense against cyber attacks (bots/DDOS), and basic, non-identifiable traffic measurement.
Legal basis: Legitimate interest in website security and basic optimization (Art. 6(1)(f) GDPR).
Retention period: Generated server logs are automatically deleted or anonymized within 14 days.
- Who We Share Your Data With We only share your data with trusted third-party processors who provide essential infrastructure for our business, backed by Data Processing Agreements (DPAs):
Infrastructure & Security Providers: Cloudflare, Inc. (website hosting, security, and cookieless analytics).
Internal Productivity Tools: Google Ireland Ltd. / Google LLC (Google Workspace for emails and cloud storage, Google Cloud Platform / BigQuery for internal operations).
CRM Systems: HubSpot, Inc. (for managing client relationships and inquiries).
We do not sell or share your data with third parties for their own marketing purposes.
- Data Transfers Outside the EU Some of our infrastructure providers (specifically Cloudflare, Google, and HubSpot) are based in the United States. Data transfers to these companies are secured based on:
Adequacy Decisions: Specifically the EU-U.S. Data Privacy Framework (DPF), under which these entities are certified.
Standard Contractual Clauses (SCCs): Approved by the European Commission, ensuring an equivalent level of data protection.
- Your Rights Under the GDPR, you have the following rights regarding your personal data:
Right of access: To know what data we process about you and get a copy.
Right to rectification: To correct inaccurate or incomplete data.
Right to erasure ("right to be forgotten"): If there is no longer a legal basis for processing.
Right to restriction of processing: E.g., while we verify the accuracy of your data.
Right to data portability: To receive your data in a structured, machine-readable format.
Right to object: To object to data processing based on our legitimate interest.
Right to lodge a complaint: You have the right to file a complaint with a supervisory authority. In the Czech Republic, this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů – uoou.gov.cz).
To exercise your rights, contact us at info@marketingintelligence.io. We will respond within 30 days.
Automated Decision-Making and Profiling We do not use automated decision-making or profiling that would have legal effects on you.
Data Security We use encrypted connections (HTTPS), restrict access to systems based on the principle of least privilege, and regularly review security access. For client data processed during consulting projects, we strictly enforce data governance principles, meaning all client data is handled within separate, secure environments governed by specific non-disclosure and data processing agreements (NDAs/DPAs) signed directly with each B2B client.