Data security
Your accounts. Our access. Every rule, written down.
The page for whoever in your company asks "wait — who exactly gets access to what?" Short answers first, details below.
Signed before a single account is shared. Yours or ours — signed within one business day.
Viewer/analyst roles only, limited to the accounts in scope. We never hold admin rights and never make changes.
Access revoked at readout; working data deleted within 30 days. Never used to train AI models.
Four steps. No copies left behind.
You grant viewer/analyst roles from your side — we never hold your passwords.
Scoped API reads of the accounts in scope — aggregates and reports, never customer PII.
Agents run inside EU infrastructure; a senior auditor reviews before anything advances. Nothing trains AI models.
Access revoked at your readout; working data deleted ≤ 30 days after close. You can verify both.
| System | Access level | Used for |
|---|---|---|
| GA4 / analytics | Viewer | Funnel & attribution |
| Meta / Google Ads | Analyst (read-only) | Spend efficiency |
| Email / CRM (e.g. Klaviyo, HubSpot) | Read-only | Lifecycle coverage |
| Revenue (e.g. Shopify, Stripe, exports) | Reports only | Margin verification |
| Customer PII | Never requested | Aggregates only |
Who touches the data, and under what terms.
| Subprocessor | Purpose | Location | Safeguard |
|---|---|---|---|
| Netlify, Inc. | Website hosting & form intake | Global CDN / US | DPA + SCCs |
| Zoho Corporation | CRM — lead & client records | EU (crm.zoho.eu) | DPA + SCCs |
| Google (GA4) & Microsoft Clarity | Site analytics (consent-gated) | EU / US | DPA · consent-mode gated |
| Google Workspace | Report delivery & client communication | EU / US | DPA + SCCs |
Current as of Jul 2026 · changes announced 30 days ahead to active clients · the full legal list ships with the DPA.
Security cleared? Let’s find your margin.
Fixed fee. 5–7 days. $10k–$50k of findings, or your money back.