Privacy Policy for ProductBird
Last updated: May 21, 2025
This Privacy Policy describes how Selektable VOF. (“we”, “us” or “our”) collects, uses, discloses, and protects your personal data when you visit our marketing website (https://productbird.ai), use our SaaS platform (https://app.productbird.ai), or install and use our WordPress plugin. This policy is designed to comply with the General Data Protection Regulation (GDPR), the Dutch Implementation Act (Uitvoeringswet AVG), and other applicable Dutch and European privacy laws.
1. Data Controller
Selektable VOF.
Address: [Street Address], Amsterdam, The Netherlands
Email: privacy@productbird.ai
Chamber of Commerce (KvK) number: [number]
As the data controller, we determine the purposes and means of processing your personal data.
2. Categories of Personal Data Collected
2.1 Marketing Website (https://productbird.ai)
- Analytics data: anonymized page views, device and browser type, referral URLs, and aggregate usage metrics collected via Pirsch Analytics (hosted in Germany; cookie-free and GDPR-compliant).
- Contact form submissions: name, email address, company name, and message content (if you submit inquiries).
2.2 SaaS Platform (https://app.productbird.ai)
- Account information: name, email address, company name, job title, and billing details you provide when registering.
- Authentication credentials: hashed passwords and API keys.
- Usage data: dates and times of access, features used, request logs, IP address (anonymized where possible).
- Product analytics: anonymous event data collected via PostHog for feature improvement and user behavior analysis.
- Error and performance logs: stack traces and error contexts collected via Sentry to diagnose and resolve technical issues.
2.3 WordPress Plugin
- API key: required to authenticate requests from your WordPress site to our API endpoints.
- Request metadata: anonymized request timestamps and endpoint usage; no content or personal data from your visitors is transmitted.
3. Purposes and Legal Basis for Processing
Purpose | Data Collected | Legal Basis |
---|---|---|
Provide and maintain our services | Account info, usage data, API logs | Performance of a contract |
Improve and optimize our platform | Analytics, error logs, usage metrics | Legitimate interest |
Respond to inquiries and support requests | Contact form data, account info | Consent; contract |
Billing and invoicing | Billing details | Performance of a contract |
Marketing and communications | Email address, name | Consent; legitimate interest |
4. Disclosure to Third Parties
We share personal data only with carefully vetted service providers:
- Pirsch Analytics (Germany): processing marketing-site analytics in a cookie-free manner under GDPR.
- PostHog, Inc. (EU instance): product analytics and feature usage data.
- Sentry, Inc. (USA/EU): error monitoring and debugging logs.
- Payment processors (e.g., Stripe): billing and invoicing data under strict data-processing agreements.
- Hosting providers: AWS (EU region) for data storage and processing.
All processors act on our instructions and are bound by confidentiality and GDPR-compliant data-processing agreements.
5. International Data Transfers
Data may be transferred to countries outside the European Economic Area (EEA), specifically to the United States for Sentry processing. We ensure adequate protections via Standard Contractual Clauses and only process data in jurisdictions with recognized data-protection frameworks.
6. Data Retention
- Marketing analytics: aggregated reports retained for up to 24 months.
- Account and billing data: retained for the duration of your account plus 7 years for tax and legal compliance.
- Product analytics & error logs: retained for 12 months, then aggregated or deleted.
- Contact inquiries: retained until the inquiry is resolved or withdrawn, then archived for 3 years.
7. Data Subject Rights
Under GDPR, you have the right to:
- Access, rectify, or update your personal data.
- Request deletion or restriction of processing.
- Object to processing for direct marketing or legitimate interests.
- Obtain a portable copy of your data.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with a supervisory authority (Autoriteit Persoonsgegevens in the Netherlands).
To exercise these rights, please contact us at privacy@productbird.ai.
8. Security Measures
- Encryption of data at rest and in transit (TLS 1.2+).
- Regular penetration testing and vulnerability assessments.
- Access controls, audit logs, and least-privilege policies.
- Incident response procedures and breach notification protocols.
9. Cookies and Tracking
- Marketing site: We use Pirsch, which does not set any cookies or require consent banners.
- SaaS application: Standard session cookies for authentication; necessary for service delivery.
10. Changes to This Policy
We may update this policy periodically. We will notify you of significant changes via email or a notice on our website. The “Last updated” date at the top reflects the most recent version.
11. Contact Information
If you have questions or concerns about this Privacy Policy, please contact us:
- Email: team@productbird.ai
- Address: Hoedemakerplein 3, Enschede, The Netherlands
- Supervisory Authority: Autoriteit Persoonsgegevens, P.O. Box 93374, 2509 AJ The Hague
By using our services, you acknowledge that you have read and understood this Privacy Policy.