Legal

Privacy Policy

Last updated: June 13, 2026

1. Introduction & Scope

Intelligent Insights (“we”, “us”, “our”) provides a business-to-business platform that generates AI-powered sales-intelligence reports — including competitor battlecards, pricing intelligence, go-to-market analysis, target-account profiles, buying-signals reports, and industry-vertical and decision-maker analyses.

This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it. It applies to our website and to the Intelligent Insights application (together, the "Service").

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD). Our supervisory authority is the Spanish Data Protection Agency (AEPD).

The Service is intended for business users only. It is not directed to consumers or to anyone under 18.

2. Data Controller

The data controller responsible for your personal data is:

Intelligent Insights lab

Ronda de ponent 35, Miramar, 46711

NIF/VAT: [NIF/VAT]

Email: [email protected]

If you have any questions about this policy or how we handle your data, please contact us at the email address above.

3. What Data We Collect

We collect personal data that you provide directly when you create an account, generate reports, make payments, and contact us, as well as a limited amount of technical data generated automatically when you use the Service. The categories below describe what we collect and the context in which it is collected.

Account & profile data

When you register and use your account, we store your email address, full name, company name, and company website. We also record signup context (such as signup source, UTM parameters, or a referral code), your account creation date, and your last sign-in date. We maintain your credit balance and the history of credit transactions, and — where applicable — company-member records (each member's email, name, role, and status). For internal administration we may also hold admin-only flags, such as whether an account is deactivated and internal administrative notes.

Report data

Each report you generate is stored together with the inputs you provide. Depending on the report type, these inputs may include your company name and website, the software or product being analyzed and its URL, competitor names, target-account names and URLs, an industry name and geographic focus, decision-maker details, your chosen language, and the credits or pricing applied. We also store operational data tied to the report, including the Stripe checkout session identifier and AI token-usage statistics. Alongside the inputs we retain the generated outputs: the report PDF, the associated invoice PDF, any star rating and feedback comment you leave, and an internal AI quality-review field.

Billing & payment data

Payments are processed by Stripe. At checkout, Stripe collects your billing name, billing email, billing address, country, and (optionally) an EU VAT number. We store these billing details and the VAT number in our database to issue invoices and meet our tax obligations, and we retain the invoice PDFs generated by Stripe in our secure file storage. We do not store card or payment-instrument numbers — these are sent directly to Stripe, which is PCI-DSS compliant. We keep VAT and IRPF expense records as required by Spanish tax law.

Support tickets

When you open a support ticket, we store the subject, category, and status of the ticket, an optional link to a specific report, and all messages in the thread. This includes your messages, replies from our team, and automated replies generated by an AI assistant (an AI assistant may produce the initial automated response to a ticket).

Contact form

If you use our contact form, we store your name, email, company, country, and the content of your message. This information is also emailed to our team so we can respond.

Technical & log data

Our servers keep operational pipeline logs that record the context of each report run — such as the software, company, or competitor names and URLs involved — for debugging and quality purposes. These pipeline logs do not contain account email addresses. We also maintain standard web-server and security logs. Our website analytics are handled by a self-hosted, cookieless tool that does not collect personal data (see Cookies & Analytics below).

4. How We Use Your Data & Legal Bases

We use your personal data to operate and deliver the Service, to meet our legal obligations, and to keep the Service secure. Under the GDPR, every use is supported by a specific legal basis, set out below.

  • Creating and managing your account, generating reports, and providing customer support — performance of our contract with you (Art. 6(1)(b)).
  • Processing payments and credits — performance of our contract with you (Art. 6(1)(b)).
  • Issuing invoices and keeping VAT/IRPF tax and accounting records — compliance with a legal obligation (Art. 6(1)(c)).
  • Securing the Service, preventing fraud and abuse, and operating our self-hosted website analytics — our legitimate interests (Art. 6(1)(f)).
  • Maintaining and improving the quality and reliability of the Service — our legitimate interests (Art. 6(1)(f)).
  • Any processing for which we specifically ask your permission — your consent (Art. 6(1)(a)), which you may withdraw at any time.

Where we rely on legitimate interests, we balance those interests against your rights and freedoms and only proceed where our interest is not overridden by them.

5. AI Processing & Web Scraping

Generating a report involves automated AI analysis. To produce your report, we send the report inputs you provide — such as the software, company, competitor, target-account, and industry names and the associated URLs — together with publicly available web content, to our AI provider Anthropic (the Claude API). Anthropic processes this information solely to perform the analysis and generate the report. It does not receive your account login credentials.

Anthropic does not use data submitted through its API to train its models.

To gather the context needed for analysis, we collect publicly accessible web pages of the companies and competitors being analyzed using a web-scraping engine. This engine (Firecrawl) runs on our own private, self-hosted infrastructure; it does not transmit your data to an external scraping provider.

The outputs of this process — the generated report and its analysis — are stored in your account as described in "What Data We Collect" above.

6. Service Providers & Sub-processors

We share personal data with a small number of carefully selected service providers who process it on our behalf, under data processing agreements and only for the purposes described below. We do not sell your personal data. Two of these components — Umami and Firecrawl — are self-hosted on our own infrastructure rather than operated by an external company.

Provider Purpose Data processed Location / note
Supabase Database, authentication, and file-storage hosting All stored personal data (account and profile data, report data, billing details, support and contact messages, stored files) Third-party processor; may process data outside the EEA under appropriate safeguards.
Stripe Payment processing and invoicing Billing name and email, billing address, country, EU VAT number; card data is processed directly by Stripe and not stored by us Third-party processor; PCI-DSS compliant; may process data outside the EEA (including the US) under appropriate safeguards.
Anthropic AI analysis to generate reports (Claude API) Report inputs (software/company/competitor/target/industry names and URLs) and publicly scraped web content; no account login credentials Third-party processor; may process data outside the EEA (including the US) under appropriate safeguards. Does not train its models on data submitted via the API.
Resend Transactional email delivery Recipient email, name, and company name; report links; and the content of support or contact messages where relevant Third-party processor; may process data outside the EEA (including the US) under appropriate safeguards.
Umami Self-hosted Website analytics None — cookieless analytics that collects no personal data and performs no cross-site tracking Self-hosted on our own infrastructure; no data shared with a third party. See our Cookie Policy.
Firecrawl Self-hosted Web-scraping engine for collecting public web pages The company/competitor URLs being analyzed and the public page content retrieved Self-hosted on our own private infrastructure; no data shared with an external third party.

7. International Data Transfers

We are based in Spain and store data within the European Economic Area (EEA) where possible. However, some of our service providers — including Stripe, Resend, and Anthropic — may process personal data outside the EEA, including in the United States.

Where data is transferred outside the EEA, we ensure it is protected by appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses (SCCs) and/or an applicable adequacy decision, supported by the data processing agreements we maintain with each provider. You can request more information about these safeguards by contacting us at [email protected].

8. Data Retention

We retain your account and report data for as long as your account is active and for as long as we need it to provide the Service to you.

Billing, invoicing, and tax records (including VAT and IRPF records) are kept for the periods required by Spanish and EU law, even after your account is closed. Abandoned or unpaid report checkouts are deleted automatically.

We do not currently run automatic deletion of aged data. You may ask us to erase your personal data at any time, and we will do so subject to any legal-retention obligations that require us to keep certain records (such as tax and accounting data) for a defined period.

9. Your Rights

Under the GDPR and the LOPDGDD, you have the following rights over your personal data:

  • Access — to obtain confirmation of whether we process your data and a copy of it.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to have your data deleted (the "right to be forgotten"), subject to legal-retention exceptions.
  • Restriction — to limit how we process your data in certain circumstances.
  • Portability — to receive your data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Objection — to object to processing based on our legitimate interests.
  • Withdrawal of consent — to withdraw any consent you have given, at any time, without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, email us at [email protected]. We action requests manually and will respond within one month of receiving your request, as required by the GDPR. We may need to verify your identity before acting on a request.

If you believe we have not handled your data properly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es. We would, however, appreciate the chance to address your concerns directly first.

10. Data Security

We take appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or loss. Access to personal data is restricted to those who need it to operate the Service.

Payment card data is handled entirely by Stripe, a PCI-DSS compliant payment processor, and is never stored on our systems. Invoice documents and other files are kept in secure file storage, and our self-hosted components (analytics and web scraping) run on our own private infrastructure.

No method of transmission or storage is completely secure, but we work to protect your data using measures appropriate to the risk. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the AEPD and, where required, affected users in line with our legal obligations.

11. Cookies & Analytics

We use a self-hosted, cookieless analytics tool (Umami) to understand how our website is used. It does not set cookies, does not collect personal data, and does not track you across other websites.

For full details of any cookies or similar technologies we use, please see our Cookie Policy.

12. Children's Privacy

The Service is a business-to-business product intended for professional users and is not directed to anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us at [email protected] and we will take appropriate steps to delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our service providers, or legal requirements. When we make changes, we will revise the "Last updated" date at the top of this page. If the changes are significant, we will provide a more prominent notice where appropriate. We encourage you to review this page periodically.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Intelligent Insights lab

Ronda de ponent 35, Miramar, 46711

NIF/VAT: [NIF/VAT]

Email: [email protected]