Privacy Policy
Last updated August 5, 2026
Effective date: 5 August 2026
Last updated: 5 August 2026
1. Introduction
This Privacy Policy explains how Realytics collects, uses, discloses, transfers and protects personal data, and describes the rights available to individuals under the laws that apply to us. It applies to the Realytics website at realytics.com, the Realytics platform and its analytics modules, our application programming interfaces, our browser extensions and mobile applications where offered, our newsletters, webinars and events, and our sales and support communications. Together these are referred to in this Policy as the Services.
We have written this Policy to be read rather than merely accepted. Where a practice carries a genuine trade-off for you, we describe it plainly rather than concealing it in general language.
Business customers, please note. Where an organisation subscribes to the Services and uploads or connects data relating to its own customers, employees or contacts, that organisation is the controller of that data and Realytics acts as its processor. Our handling of such data is governed by the subscription agreement and the Data Processing Addendum concluded with that organisation, not by this Policy. This Policy governs personal data for which Realytics is itself the controller, which includes account and contact data, billing data, usage and device data, marketing data, and data we collect independently from public and third-party sources.
2. Who we are and who is responsible for your data
Realytics operates through two legal entities.
|
Role |
Entity |
Details |
|---|---|---|
|
Data controller |
Realytics Corp Limited |
Registration number HE424817, 25 Martiou, 27, D. Michael Tower, office 105A, Nicosia, Cyprus |
|
Parent company and affiliate |
Reality Analytics, Inc. (Delaware C-Corporation) |
1000 N. West Street, Suite 1200, Wilmington, Delaware 19801, United States |
Realytics Corp Limited, the Cyprus entity, is the controller of the personal data described in this Policy. It determines the purposes and means of processing. Because Realytics Corp Limited is established in the European Union, it is directly subject to the EU General Data Protection Regulation and to Cypriot data protection law, and it is supervised by the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, which is the competent supervisory authority for our processing.
Reality Analytics, Inc. is our parent company. It provides group-level engineering, security, finance and corporate functions and processes personal data on behalf of and under the instruction of Realytics Corp Limited. Transfers between the two entities are governed by the safeguards described in Section 11.
For privacy enquiries, requests and complaints, contact us at , or write to the Cyprus address above marked for the attention of the data protection contact. If Realytics appoints a statutory Data Protection Officer, that person can be reached through the same contact details unless we publish different details.
3. Categories of personal data we collect
The data we hold falls into six groups, distinguished by how it reaches us.
Data you provide directly. When you create an account, request a demo, start a trial, subscribe to a newsletter, register for an event, apply for a role or contact support, you provide identifiers and contact details such as your name, business email address, telephone number, employer, job title and country. Account credentials are held as salted cryptographic hashes; we never store passwords in a form we can read. If you communicate with our support or sales teams, we retain the correspondence, including any attachments and, where you have been notified in advance, call recordings.
Content you submit to the Services. This includes projects and workspaces you configure, domains, locations, brands, competitors and keywords you track, files and datasets you upload, dashboards and reports you build, comments and annotations, and the prompts, instructions and inputs you provide to any AI-assisted or generative feature. Section 8 explains how this content may be used to develop and improve our models where our customer agreements and data protection law permit it, which is a point of substance that we ask you to read.
Payment and billing data. We collect billing name, billing address, tax identifiers where required, limited payment-card metadata such as the last four digits, card brand and expiry, and your transaction and invoice history. Full payment card numbers are handled by our payment processors and are not intended to be stored by Realytics.
Technical, usage and device data. We collect the IP address from which you connect, a coarse location inferred from it at city or country level, browser type and version, operating system, device type and screen characteristics, language and time zone, referring and exit pages, the pages and features you view, queries you run, clicks and scroll behaviour, session duration and timestamps, crash reports, diagnostic logs, and identifiers stored in cookies and similar technologies. Section 12 describes cookies and your controls over them.
Data from third parties. We receive personal data from analytics and product-telemetry providers, advertising and attribution partners, payment processors and fraud-prevention services, resellers and referral partners, security and anti-abuse services, and business-information and enrichment vendors from whom we obtain company size, sector, technology stack and role information about business contacts. Where you sign in using a third-party identity provider or authorise a third-party integration, we receive the data described in Section 9. Where you interact with us on social platforms, we receive limited engagement data from those platforms.
Data we collect from public and open sources. Realytics is an analytics company, and part of our product is built from information that is publicly accessible on the internet or licensed from data suppliers. Section 10 describes this activity, the safeguards that apply to it, and the rights available to individuals whose information may appear in such sources.
We do not seek to collect special categories of personal data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. Please do not submit such data to the Services. Where special category data reaches us incidentally, we delete it once identified unless we are required to retain it by law.
4. Why we process personal data, and on what legal basis
We do not rely on a general assertion that your use of the Services constitutes consent to everything described here. Under the GDPR every purpose requires its own legal basis, and the table below states ours. Where we rely on legitimate interests, we have weighed that interest against your rights and freedoms and consider the processing proportionate; if you would like to understand our reasoning for a particular purpose, write to and we will explain it.
|
Purpose |
Categories of data used |
Legal basis |
|---|---|---|
|
Creating and administering your account; authenticating you; providing the Services and their features |
Identifiers, contact data, account content, technical data |
Contract (Art. 6(1)(b)) |
|
Processing payments, invoicing, collections, tax and accounting records |
Billing and payment data, identifiers |
Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) where retention or reporting is required |
|
Providing customer support and responding to enquiries |
Identifiers, contact data, correspondence, technical data |
Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) where you are not yet a customer |
|
Monitoring service availability, diagnosing faults, debugging and capacity planning |
Technical, usage and device data |
Legitimate interests (Art. 6(1)(f)) in operating a reliable service |
|
Detecting and preventing fraud, abuse, credential sharing, scraping of our own Services, and security incidents |
Technical data, identifiers, usage data |
Legitimate interests (Art. 6(1)(f)) in protecting our Services and users; legal obligation (Art. 6(1)(c)) where reporting is required |
|
Analysing product usage to understand which features are used and to improve them |
Usage, technical and device data, in aggregated or pseudonymised form wherever practicable |
Legitimate interests (Art. 6(1)(f)) in developing our product |
|
Developing, training, evaluating and improving machine learning and AI models (see Section 8) |
Aggregated or de-identified customer content where permitted by contract, usage data, feedback, public and licensed data |
Legitimate interests (Art. 6(1)(f)) where Realytics acts as controller; contract (Art. 6(1)(b)) where necessary to provide a requested AI feature |
|
Building and maintaining our analytics datasets from public and licensed sources (see Section 10) |
Publicly accessible web data, licensed datasets |
Legitimate interests (Art. 6(1)(f)) in producing market and competitive analytics |
|
Sending service, security, billing and administrative notices you cannot opt out of while you hold an account |
Identifiers, contact data |
Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
|
Direct marketing by email to prospects and to existing customers about related products |
Identifiers, contact data, enrichment data, engagement data |
Consent (Art. 6(1)(a)) where required by law; otherwise legitimate interests (Art. 6(1)(f)) under the existing-customer exemption |
|
Advertising, retargeting, audience matching and measurement across third-party platforms (see Sections 12 and 13) |
Online identifiers, cookie data, hashed email addresses, usage data |
Consent (Art. 6(1)(a)) for EEA, UK and Swiss users; legitimate interests or opt-out mechanisms in other jurisdictions as permitted |
|
Non-essential cookies, pixels, session replay and similar technologies |
Cookie and device identifiers, usage data |
Consent (Art. 6(1)(a)), obtained through our cookie banner |
|
Recruitment and evaluation of job applicants |
Application data, correspondence |
Legitimate interests (Art. 6(1)(f)); consent where we retain your details for future roles |
|
Exercising and defending legal claims, responding to lawful requests, conducting audits, and managing corporate transactions |
Any relevant category |
Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
Where we rely on consent, you may withdraw it at any time and withdrawal is as easy as giving it; withdrawal does not affect the lawfulness of processing already carried out. Where we rely on legitimate interests, you have the right to object, and Section 14 explains how.
If we ever wish to use your personal data for a purpose that is not described in this Policy and is not compatible with the purposes above, we will inform you and, where the law requires it, obtain your consent before doing so. We do not reserve a right to process your data for undisclosed purposes.
5. How long we keep personal data
We retain personal data only for as long as it serves the purpose for which it was collected, or for as long as the law requires. The following periods are our operating defaults.
|
Data |
Retention period |
|---|---|
|
Account and profile data |
For the life of the account, then 90 days after closure to allow for reactivation and dispute resolution |
|
Content and projects you created |
Deleted or irreversibly anonymised within 90 days of account closure |
|
Backups containing account data |
Purged on the backup rotation cycle, not exceeding 12 months |
|
Invoices, payment records and tax documentation |
For the period required by applicable tax and accounting law |
|
Support tickets and correspondence |
3 years from the last message |
|
Security, audit and access logs |
12 months, extended where an incident is under investigation |
|
Marketing contact data and engagement history |
Until you unsubscribe or object, and in any event no more than 24 months after your last engagement with us |
|
Cookie and advertising identifiers |
Per the durations published in our Cookie Policy, with non-essential cookies capped at 13 months |
|
Recruitment data |
12 months after a decision, or longer with your consent |
|
Aggregated and anonymised statistics |
Indefinitely, as this data no longer identifies any individual |
|
Records needed for legal claims |
Until the claim and any appeal period is finally resolved |
Where data has been incorporated into a trained model in a form from which no individual can be identified or reconstructed, that model may persist after the underlying data has been deleted. Section 8 addresses this honestly, because we think you are entitled to know it.
6. How we protect personal data
We apply technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access, taking into account the nature of the data, the processing and the risk. Those measures include access controls, confidentiality obligations, transmission security, backup and recovery procedures, incident-response procedures, and data minimisation or pseudonymisation where appropriate.
We do not describe detailed system architecture or security implementation details publicly, because doing so would itself create security risk. Customers receive the additional processor-security information required by law through the Data Processing Addendum.
No system is perfectly secure, and we do not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Office of the Commissioner for Personal Data Protection within 72 hours of becoming aware of it as Article 33 requires, and we will notify affected individuals without undue delay where the risk is high. You can report a suspected vulnerability or incident to .
7. Who we disclose personal data to
We disclose personal data in the following circumstances and no others.
Service providers acting on our instructions. These include cloud hosting and infrastructure providers, database and storage providers, content delivery and DDoS protection networks, email delivery and communications platforms, customer relationship management and support ticketing platforms, product analytics and error monitoring tools, payment processors and tax calculation services, identity and authentication providers, and professional advisers including auditors and lawyers. Each is bound by a written data processing agreement that restricts them to our instructions, imposes confidentiality and security obligations, and prohibits use of the data for their own purposes. A current list of our sub-processors is maintained at https://realytics.com/legal/subprocessors and, for customers, is incorporated into the Data Processing Addendum.
Group companies. Reality Analytics, Inc. and any future affiliates receive personal data where necessary for the group functions described in Section 2, subject to the intra-group safeguards in Section 11.
Advertising and analytics partners. Where you have consented, or where an applicable law permits with an opt-out, we share online identifiers and hashed email addresses with advertising platforms for the purposes described in Section 13. Under certain United States state privacy laws this activity constitutes "sharing" for cross-context behavioural advertising and may constitute a "sale". We say so plainly in Section 13 rather than denying it, and we provide a working opt-out.
Resellers and referral partners. Where you were introduced to us by a reseller or partner, or where you request that a partner manage your account, we may exchange your contact details and subscription status with that partner for the purpose of servicing your relationship. We do not disclose your personal data to resellers or partners so that they may market their own unrelated products to you. If a partner wishes to market to you, they must obtain their own legal basis directly from you.
Corporate transactions. In connection with a merger, acquisition, financing, reorganisation, insolvency or sale of assets, personal data may be disclosed to counterparties and their advisers under confidentiality obligations. We will notify you of any change in the identity of the controller and of any material change to how your data is handled.
Legal and safety disclosures. We may disclose personal data where we are legally compelled to do so by a valid and binding legal process, or where disclosure is necessary to establish, exercise or defend legal claims, to enforce our terms, or to protect against fraud or a serious threat to the safety of any person. Our practice is to review each request for validity and proportionality, to reject requests that are overbroad or defective, to require formal process rather than informal requests, and, unless legally prohibited, to notify the affected individual or customer before disclosure so that they have an opportunity to object.
At your direction. We disclose data to third parties where you instruct us to, for example when you enable an integration or authorise an export.
We do not disclose personal data to data brokers.
8. Artificial intelligence and machine learning
This section describes a practice that affects you directly, and we would rather you read it here than discover it later.
What we do. Realytics develops machine learning and AI models that power features such as competitive insights, forecasting, segmentation, ranking, recommendation, anomaly detection, classification and generative assistance. To build, train, fine-tune, evaluate and improve these systems we use data from three sources: content and inputs submitted to the Services where our customer agreements permit that use, including prompts and instructions you give to AI-assisted features and the datasets and configurations you create; usage and interaction data, including which outputs you accept, edit, regenerate or reject, which is how we measure and improve quality; and public and licensed data, as described in Section 10.
Our legal basis is legitimate interests under Article 6(1)(f) where Realytics acts as controller, and contract under Article 6(1)(b) where the processing is necessary to provide an AI feature you requested. We consider that we have a genuine and specific interest in developing analytics and AI capabilities that make the Services more accurate, safer and more useful, and we document a legitimate-interest assessment before relying on that basis for model development. That assessment considers necessity, data minimisation, reasonable expectations, the source and sensitivity of the data, the relationship between Realytics and the individual, the availability of less intrusive alternatives, and the safeguards described below. We keep this assessment under review as our models and features develop. If you would like us to explain our reasoning for a particular processing activity, write to .
The safeguards we apply. We minimise personal data in training sets and, where a training objective can be met with aggregated, pseudonymised or de-identified data, we use that instead. We filter direct identifiers and special category data out of training material where we identify them. Our models are not designed or trained to generate personal data about identifiable individuals, and we do not use one customer's confidential content to generate outputs targeted at another identifiable customer. Access to training data and pipelines is restricted to authorised personnel. Where a business customer's agreement says that its Customer Data may not be used for model development, that agreement controls.
Third-party models. Some features are delivered using models operated by third-party AI providers. Where we route your input to such a provider, we do so under a data processing agreement that prohibits the provider from using your content to train its own models and requires deletion within a defined period. Where a feature depends on a provider whose terms we cannot align with this standard, we will tell you before you use the feature.
Your rights, stated accurately. Because this processing rests on legitimate interests, Article 21 of the GDPR gives you the right to object to it at any time. If you object, we will stop using your content for model development unless we can demonstrate compelling legitimate grounds that override your interests, and we will explain our reasoning to you if we reach that conclusion. Send objections to . We want to be straightforward about two limits. First, once a model has been trained, removing the influence of a specific individual's data from that model is not always technically possible; where it is not, we will exclude your data from future training runs and, where feasible, from subsequent model versions, and we will say so rather than implying a deletion we cannot perform. Second, an objection to model development does not entitle you to continue using features that depend on the processing you have objected to, though we will always look for a workable arrangement first.
Enterprise arrangements. Business customers may negotiate contractual terms excluding their content from model development entirely, and such terms in a subscription agreement, Order Form or Data Processing Addendum override this section for that customer's data.
Automated decision-making. Realytics does not make decisions about you that produce legal effects or similarly significantly affect you based solely on automated processing. Our models generate analytical insights, scores and recommendations about markets, locations, brands and competitors, which are intended to inform human commercial judgement rather than to replace it. Automated logic is used in fraud and abuse detection to flag activity for human review; a flagged account is not suspended without human assessment except where an immediate suspension is necessary to prevent harm, and in that case you may request human review by contacting us.
9. Connected accounts and integrations
The Services allow you to connect third-party accounts so that Realytics can retrieve data on your behalf. Today these include analytics, search, advertising and business-listing platforms, and we expect to add further connections over time, including advertising accounts, business profile and listing services, e-commerce and point-of-sale systems, and other marketing and data platforms.
The following commitments apply to every integration we offer, present or future.
We request the narrowest scope of access that the feature requires, and we ask for read-only access wherever the feature permits it. We use the data retrieved through an integration only to provide and improve the specific features you enabled it for. We do not use data obtained through a connected account for advertising or marketing purposes, we do not sell or transfer it, and we do not provide it to third parties except to sub-processors strictly necessary to operate the feature, to comply with binding legal process, or in connection with a corporate transaction as described in Section 7. Human access to data retrieved through an integration is limited to what is necessary to provide support you have requested, to investigate a security incident or suspected abuse, to comply with law, or where the data has been aggregated and anonymised for operational analysis. You may disconnect an integration at any time from your account settings, and on disconnection we cease further retrieval and delete or anonymise the retrieved data within 90 days, except where retention is required by law.
Where a platform's own developer terms impose stricter requirements than this Policy, those requirements govern our handling of data from that platform and we comply with them in addition to the commitments above. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Once you connect a third-party account, your relationship with that platform continues to be governed by that platform's own terms and privacy policy, over which we have no control.
10. Data collected from public and licensed sources
Realytics builds market, location, brand and competitive analytics, and a substantial part of the underlying data comes from sources other than our own customers. We describe this activity openly because individuals whose information may appear in public sources are entitled to know what we do.
Our web crawler. We operate an automated crawler that visits publicly accessible web pages. It collects structural, technical and commercial information about websites and businesses: URLs and site architecture, hyperlinks and anchor text, page titles and metadata, HTTP status and response headers, page performance and technical characteristics, product and pricing information, business names, addresses, opening hours and category listings, and aggregate signals used to compute market and visibility metrics.
Our crawler is not designed or used to build profiles of individuals. We do not target the crawler at personal profiles, social media accounts or user-generated content for the purpose of extracting information about individuals; we do not construct person-level records, contact lists or behavioural profiles of individuals from crawled data; and we do not knowingly crawl sources whose principal content is special category data, such as health, medical, religious, political or adult content. Where personal data such as an author's name, a byline or a business contact detail appears incidentally within a public page that we crawl, it is retained only as part of the page-level or business-level record and is not extracted into an individual-level dataset, enriched, or used to make inferences about that person.
How our crawler behaves. We identify our crawler with a dedicated, non-spoofed user-agent string that links to a public page explaining its purpose, so that site operators always know it is us. We respect robots.txt and in-page directives including noindex and nofollow, and we treat a robots.txt exclusion as a valid objection to crawling that we honour without requiring justification. We throttle our request rate to avoid placing an unreasonable load on any site. We do not attempt to circumvent authentication, paywalls, rate limits or technical access controls, and we do not access any content that is not publicly available. Site operators and individuals may request exclusion by writing to , and we maintain a permanent blocklist of hosts and addresses that have asked to be excluded.
Licensed and third-party datasets. We also license data from commercial data suppliers, including business-listing, location, foot-traffic, mobility, transaction-panel, pricing and market-research datasets.
Realytics does not hold individual-level data in these datasets. We acquire and process this data only in aggregated, de-identified or panel-level form — for example, visit counts for a location over a period, or category-level spend indices for a market — and we do not acquire, construct or hold records that describe the behaviour of an identified or identifiable person. We do not attempt to re-identify individuals within aggregated datasets, and we do not combine datasets for the purpose of doing so. We require our suppliers to warrant that they collected the underlying data lawfully, that they have a valid legal basis for supplying it to us, and that any consent or notice required in the jurisdiction of collection was obtained, and we contractually prohibit suppliers from providing us with special category data or individual-level records. If we discover that a supplier has provided data outside these limits, we cease ingestion and delete the affected data.
Because aggregated and de-identified data of this kind does not identify any individual, it falls outside the scope of data protection law. We describe it here because we would rather you understand what our analytics are built from than have to infer it.
Legal basis and your rights. Where this activity involves personal data, our legal basis is legitimate interests under Article 6(1)(f): producing market intelligence and competitive analytics is a recognised commercial activity, the data is limited to what is publicly accessible or lawfully licensed, and the safeguards above are designed to keep the impact on individuals minimal. Because the data is not obtained from you directly, Article 14 of the GDPR applies, and this section together with this Policy constitutes the information we make publicly available for that purpose. Providing individual notice to every person whose name might appear incidentally on a crawled page would involve disproportionate effort within the meaning of Article 14(5)(b), and publishing this section is the measure we take instead.
If you believe your personal data appears in our datasets, you may exercise the rights in Section 14, including the right to object and the right to erasure. Write to with enough detail for us to locate the data. We will not require you to justify an objection to processing based on legitimate interests in this context; if you object and we cannot demonstrate compelling overriding grounds, we will remove the data and add the relevant source to our exclusion list.
11. International transfers of personal data
Realytics is a Cyprus-controlled business with a United States parent and service providers in several countries, so personal data does cross borders. Transfers out of the European Economic Area include intra-group transfers from Realytics Corp Limited to Reality Analytics, Inc. in the United States, and transfers to service providers located outside the EEA.
Where we transfer personal data to a country that the European Commission has recognised as providing an adequate level of protection, we rely on that adequacy decision under Article 45. For transfers to the United States and other countries without an adequacy decision, including intra-group transfers to Reality Analytics, Inc., we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) where required. For transfers of United Kingdom data we use the Standard Contractual Clauses together with the UK International Data Transfer Addendum, and for Swiss data we apply the Swiss addendum. Where neither adequacy nor the Standard Contractual Clauses is available, we rely on another mechanism recognised by Article 46 or, exceptionally and only where the strict conditions are met, on a derogation under Article 49.
Contractual clauses alone are not sufficient, and we supplement them with practical measures. We keep a record of the transfers we make, their recipients, their purposes and the mechanism relied on for each, and we review the position when the legal position in a destination country materially changes. We minimise what is transferred at source, and we apply encryption in transit and pseudonymisation where the purpose still permits it. We commit contractually to notify the data exporter of any government request for personal data unless legally prohibited from doing so, to challenge requests that appear unlawful or overbroad, and to disclose no more than the minimum legally required.
You may request a copy of the safeguards applying to a specific transfer, including the relevant Standard Contractual Clauses with commercially confidential terms redacted, by writing to .
12. Cookies and similar technologies
We use cookies, pixels, local storage, software development kits and similar technologies in four categories. Strictly necessary technologies enable authentication, session management, security, load balancing and fraud prevention, and cannot be disabled without breaking the Services. Functional technologies remember your preferences such as language, time zone and interface settings. Analytics technologies help us understand how the Services are used so we can improve them. Advertising technologies support the activity described in Section 13.
For visitors in the EEA, the United Kingdom and Switzerland, all non-essential cookies are set only after you give consent through our cookie banner, which offers a genuine reject option presented with equal prominence to acceptance. You may change or withdraw your choices at any time through the cookie settings link in our website footer. We also honour the Global Privacy Control signal where your browser transmits it, and we treat it as a valid opt-out of advertising cookies and of sharing for cross-context behavioural advertising.
Non-essential cookies expire no later than 13 months after they are set. Our Cookie Policy describes the categories of cookies in use, their purposes and your controls, and is updated as our tooling changes. Browser-level controls also allow you to block or delete cookies, though blocking strictly necessary cookies will prevent the Services from functioning.
13. Advertising, and our position on "sale" and "sharing"
We advertise the Services, and we use third-party advertising platforms to do so. This means we place advertising pixels and tags from platforms such as Google, Meta, TikTok and LinkedIn on our marketing website, and we upload hashed email addresses to those platforms for audience matching, suppression of existing customers and measurement of campaign effectiveness. Hashing conceals the address from casual inspection but does not make it anonymous, and we do not pretend otherwise.
We state our position directly. Under the California Consumer Privacy Act as amended, and under comparable laws in other United States states, some of this activity constitutes "sharing" of personal information for cross-context behavioural advertising, and may constitute a "sale" because we receive a benefit in return. We do not exchange personal information for money. Many companies in our sector assert a blanket denial of sale and sharing while operating exactly these technologies; we would rather tell you what we do and give you a functioning way to stop it.
You may opt out at any time using the "Do Not Sell or Share My Personal Information" link in our website footer, by adjusting the advertising category in our cookie preference centre, or by transmitting a Global Privacy Control signal, which we honour automatically as an opt-out. We do not require you to create an account to opt out, and we do not discriminate against you for exercising the right.
We do not knowingly sell or share the personal information of consumers under 16 years of age. We do not use sensitive personal information for inferring characteristics, and we limit our use of any sensitive personal information to the purposes permitted by Section 7027(m) of the CCPA regulations.
Our marketing emails always contain a working one-click unsubscribe link, and we act on unsubscribe requests promptly. Unsubscribing from marketing does not stop service, security and billing notices, which we must send you while you hold an account.
14. Your rights and how to exercise them
Depending on where you live, you have some or all of the following rights.
Under the GDPR and Cypriot law, if you are in the EEA, and under equivalent United Kingdom and Swiss law, you have the right of access to your personal data and to a copy of it; the right to rectification of inaccurate or incomplete data; the right to erasure where one of the Article 17 grounds applies; the right to restriction of processing in the circumstances set out in Article 18; the right to data portability for data you provided which we process by automated means on the basis of consent or contract; the right to object to processing based on legitimate interests, including profiling, and an absolute right to object to direct marketing; the right to withdraw consent at any time; the right not to be subject to solely automated decisions with legal or similarly significant effects; and the right to lodge a complaint with a supervisory authority.
Under United States state privacy laws, including those of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Indiana, Kentucky, Rhode Island, Maryland, Minnesota and other states where those laws apply to us, you may have the right to know and access the categories and specific pieces of personal information we have collected, their sources, our purposes, and the categories of recipients; the right to delete personal information subject to statutory exceptions; the right to correct inaccurate personal information; the right to opt out of sale, sharing for cross-context behavioural advertising, targeted advertising and profiling in furtherance of decisions producing legal or similarly significant effects; the right to limit the use and disclosure of sensitive personal information; the right to non-discrimination; and, in states that provide it, the right to appeal a refusal of your request. California residents may also request information about disclosures for direct marketing purposes under the "Shine the Light" law.
We do not use automated decision-making technology to make significant decisions about consumers within the meaning of California's CCPA regulations. If that changes, we will provide the notices, opt-out rights, access rights and appeal mechanisms required by law before using the technology for that purpose.
How to exercise your rights. Write to , use the privacy controls in your account settings, or use the "Do Not Sell or Share My Personal Information" link for opt-outs. We respond within one month for GDPR requests, extendable by two further months for complex requests with notice to you, and within 45 days for United States state law requests, extendable once by a further 45 days. We do not charge a fee unless a request is manifestly unfounded or excessive.
Verification. We must be able to establish that a request comes from you or from someone entitled to act for you. We will normally verify by reference to your account credentials or the email address we hold. Where a request concerns data collected from public or licensed sources rather than from an account, we may need additional information to locate the relevant records, and we ask only for what is necessary. We will not use verification information for any other purpose. An authorised agent may act on your behalf on production of a signed authorisation, and we may still contact you to confirm it.
Authorised agents and appeals. If we refuse a request in whole or in part, we will explain why and inform you of your right to appeal or complain. To appeal a decision under a United States state law, reply to our response marked "Appeal" and a different member of our privacy team will review it.
Supervisory authorities. You may complain to the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (Iasonos 1, 1082 Nicosia, Cyprus; ), which is our lead supervisory authority, or to the authority in your own country of residence or workplace. In the United Kingdom you may complain to the Information Commissioner's Office. We would ask you to raise the matter with us first so that we have an opportunity to resolve it, but you are not obliged to do so.
15. Children
The Services are business tools intended for use by professionals and are not directed at children. We do not knowingly collect personal data from anyone under 16 years of age, and we do not knowingly sell or share the personal information of anyone under 16. If we learn that we have collected personal data from a child under 16 without appropriate authorisation, we will delete it promptly. A parent or guardian who believes a child has provided us with personal data should contact .
16. Third-party sites and services
The Services contain links to third-party websites, and our analytics necessarily describe and reference websites operated by others. This Policy does not apply to those sites, and we are not responsible for their content or privacy practices. Please review the privacy policy of any third-party site or service before providing it with personal data.
17. Changes to this Policy
We may update this Policy to reflect changes in our practices, our Services, or the law. When we do, we will revise the "Last updated" date at the top and publish the new version at realytics.com. Where a change is material — for example, a new purpose of processing, a new category of recipient, or a change to how we use your content for model development — we will provide advance notice by email to account holders or by prominent in-product notice, and, where the law requires consent for the change, we will obtain it before the change takes effect. We maintain an archive of previous versions and will supply an earlier version on request.
18. How to contact us
|
Purpose |
Contact |
|---|---|
|
Privacy questions, data subject requests, objections |
|
|
Data protection contact |
Realytics Corp Limited, 25 Martiou, 27, D. Michael Tower, office 105A, Nicosia, Cyprus, marked "Attention: Privacy" |
|
Security reports and suspected vulnerabilities |
|
|
Crawler exclusion and removal requests |
|
|
Postal address, United States parent |
Reality Analytics, Inc., 1000 N. West Street, Suite 1200, Wilmington, Delaware 19801, USA |
Annex A — California disclosure table
The following table summarises the categories of personal information we collect as enumerated in the California Consumer Privacy Act, the purposes for which we use them, and whether each category is disclosed for a business purpose or shared for cross-context behavioural advertising.
|
CCPA category |
Collected |
Disclosed for a business purpose |
Sold or shared for advertising |
|---|---|---|---|
|
Identifiers (name, email, IP address, account ID, cookie IDs) |
Yes |
Yes, to service providers |
Yes, online identifiers and hashed emails |
|
Customer records (billing name and address, telephone, payment card metadata) |
Yes |
Yes, to payment processors and accounting providers |
No |
|
Commercial information (subscription, transaction and purchase history) |
Yes |
Yes, to service providers and resellers servicing your account |
No |
|
Internet and network activity (browsing and search activity within the Services, feature usage, interaction data) |
Yes |
Yes, to analytics and monitoring providers |
Yes, where you have not opted out |
|
Geolocation data (coarse, derived from IP; business location data you enter) |
Yes |
Yes, to service providers |
No |
|
Professional or employment information (employer, job title, sector, company size) |
Yes |
Yes, to CRM and marketing providers |
Yes, for audience matching |
|
Audio and electronic information (support correspondence, notified call recordings) |
Yes |
Yes, to support platform providers |
No |
|
Inferences (segment, interest and propensity inferences drawn for marketing and product analytics) |
Yes |
Yes, to service providers |
Yes, where you have not opted out |
|
Sensitive personal information |
Not intentionally collected |
Not applicable |
No |
|
Biometric information |
No |
Not applicable |
No |
|
Education information |
No |
Not applicable |
No |
The business and commercial purposes for which each category is used are those set out in Section 4. The categories of sources from which personal information is collected are those set out in Section 3. Retention periods are set out in Section 5.
Annex B — Summary of key positions
This annex is provided for convenience and does not replace the body of the Policy.
|
Topic |
Realytics position |
|---|---|
|
Controller |
Realytics Corp Limited (Cyprus); Delaware parent is an affiliate acting on its instructions |
|
Lead supervisory authority |
Office of the Commissioner for Personal Data Protection, Cyprus |
|
Legal bases |
Mapped purpose by purpose in Section 4; no reliance on "use implies consent" |
|
AI and model training |
Yes, where permitted by customer agreements and law; legitimate-interest assessment documented where Art. 6(1)(f) is used; Article 21 objections honored as required |
|
Third-party AI providers |
Contractually prohibited from training on your content |
|
Security |
Risk-based technical and organisational measures; detailed implementation information provided to customers through the DPA where required |
|
Sale and sharing under US law |
Acknowledged for advertising identifiers, with a working opt-out and Global Privacy Control honoured |
|
Disclosure to partners for their own marketing |
Not permitted |
|
Data brokers |
No disclosures |
|
Web crawler |
Publishes user-agent, respects robots.txt, throttles, no person-level profiling, exclusion address provided |
|
Licensed datasets |
Aggregated, de-identified or panel-level only; no individual-level data held; no re-identification attempted |
|
EEA-to-US transfers |
Standard Contractual Clauses for transfers to non-adequate countries, including the United States, where required |
|
Government requests |
Reviewed for validity, challenged where overbroad, notified to the customer unless prohibited |
|
Undisclosed future purposes |
Not reserved; new purposes require notice and, where required, consent |
|
Children |
Under 16 not knowingly collected, sold or shared |