your data, handled like it’s ours.
the short version: your coverage archive is yours, we never sell it, and we collect the minimum needed to run the product. the long version is below and follows the GDPR and the Dutch UAVG — it's shorter than most.
1. who is responsible
Rezultaro B.V., Kerklaan 4, 1211 PP Hilversum, the Netherlands operates rezultaro.com and the Rezultaro application. For questions about this statement, or to exercise any of the rights in section 9, write to privacy@rezultaro.com.
This statement is governed by Regulation (EU) 2016/679 (the GDPR, in Dutch the AVG) and the Dutch implementation act (Uitvoeringswet AVG). We are not required to appoint a data protection officer under art. 37 GDPR and have not appointed one; the address above reaches the people who actually handle these requests.
2. two roles: controller and processor
Which role we play depends on the data, and it matters for who you address a request to.
- Controller — for the data of the people who use Rezultaro: account details, billing details, support correspondence and usage data. We decide why and how those are processed, and this statement describes it.
- Processor — for the content you put into the product: the coverage you archive, the outlets and contacts it mentions, the uploads, and the recipients you share reports with. You (the customer, normally an agency or a communications team) are the controller of that material; we only process it on your instructions. Our data processing agreement (verwerkersovereenkomst, art. 28 GDPR) forms part of the agreement and is available at privacy@rezultaro.com.
3. what we process, and why
As controller, we process:
- account data — first and last name, email address, password (stored only as a scrypt hash), company or team name, role within the team, language preference. Purpose: creating and running your account, authentication, support. Legal basis: performance of the agreement (art. 6(1)(b) GDPR).
- billing data — company name, address, VAT number, plan, invoices and payment status. Purpose: invoicing and bookkeeping. Legal basis: performance of the agreement and our legal obligation to keep an administration (art. 6(1)(b) and (c) GDPR, art. 52 Algemene wet inzake rijksbelastingen).
- usage and diagnostic data — which features are used, error logs, IP address, browser and device type, and timestamps. Purpose: keeping the service secure and working, detecting abuse, and deciding what to improve. Legal basis: our legitimate interest in a secure, functioning product (art. 6(1)(f) GDPR). We keep this data at the level of the account, not the individual, wherever that is possible.
- correspondence — what you send us through the contact form or by email, plus our answer. Purpose: answering you. Legal basis: legitimate interest, or performance of the agreement where you are a customer.
As processor, on your instructions, the product also processes the personal data contained in the coverage you archive: journalists' and authors' names, quotes, images, and whatever else appears in the articles, clippings and broadcasts you point it at, together with the names and email addresses of the report recipients you choose to share with. Determining that this processing is lawful — including the media-monitoring and copyright aspects covered in our terms — is the customer's responsibility as controller.
4. report links and the people who open them
When you share a report, we record when the link is opened, how long the page is read and from which coarse region, and we show that back to you. Recipients see a notice about this in the report footer. The purpose is to tell the customer whether their report was read; the legal basis is the customer's legitimate interest as controller, and we process it only on their instructions. No advertising or tracking cookies are placed on a recipient's device, and the reading data is not enriched with anything from outside the report.
5. artificial intelligence
Rezultaro uses a large language model to read uploads and extract the text, a description, and a sentiment classification for each page. The uploads are sent to Google's Gemini API for that purpose and nothing else. The paid API tier we use does not use submitted content to train models, and we do not train models on your content either. No decision with a legal or similarly significant effect on a person is taken automatically (art. 22 GDPR): sentiment and estimated-reach figures are suggestions in a report, always visible and always editable by you.
6. who else sees it
We use a small number of processors, each under a data processing agreement:
- Amazon Web Services (AWS) — hosting, databases, file storage and outbound email, in the Frankfurt region (eu-central-1).
- Google (Gemini API) — the AI extraction described in section 5.
- our payment and accounting providers — invoicing and bookkeeping.
We do not sell personal data, we do not share it for advertising, and we do not disclose who your clients are. Beyond the processors above we only disclose data when a Dutch court or a competent authority validly requires it, or when it is necessary to establish or defend a legal claim.
7. transfers outside the EEA
Data is stored in the European Union. Where a processor's support or infrastructure reaches outside the EEA — this applies to parts of AWS's and Google's operations — the transfer is covered by the European Commission's standard contractual clauses (art. 46(2)(c) GDPR) together with the additional technical measures described in those providers' terms, principally encryption in transit and at rest.
8. how long we keep it
- account data — for as long as the account exists, then deleted within 14 days of the account being closed.
- coverage data and reports — for as long as the customer keeps them, and deleted on the customer's instruction; after termination we keep the archive for 30 days so it can still be exported, then delete it.
- backups — rolling, overwritten within 30 days.
- invoices and the underlying administration — seven years, because Dutch tax law requires it (art. 52 AWR).
- security and error logs — 12 months.
9. your rights
You may ask us for access to your personal data, and for rectification, erasure or restriction of it; you may object to processing based on our legitimate interest; and you may ask for a copy of the data you provided in a portable format (art. 15–22 GDPR). Where we rely on consent you may withdraw it at any time, which does not affect processing that already took place.
Email privacy@rezultaro.com and a person answers within 30 days, usually much sooner. We may ask you to identify yourself so we do not hand your data to someone else. If your request concerns coverage data held in a customer's account, we will refer you to that customer, who is the controller for it.
If you are not satisfied, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl), or to the authority in your own EU country of residence.
10. cookies
Rezultaro sets only what it needs to work: a session token that keeps you logged in, and a stored language preference. Both are strictly necessary for a service you asked for, so no consent banner is required under art. 11.7a of the Dutch Telecommunicatiewet. We use no advertising cookies, no third-party analytics scripts and no cross-site trackers. Clearing your browser storage signs you out; nothing else breaks.
11. security
Transport is encrypted (TLS), storage is encrypted at rest, passwords are stored as salted scrypt hashes, access to production data is limited to the engineers who need it, and every team's data is separated at the query level. Should a personal data breach occur, we report it to the Autoriteit Persoonsgegevens within 72 hours where art. 33 GDPR requires it, and inform affected customers without undue delay.
12. changes
We may update this statement — for a new processor, a new feature, or a change in the law. The date at the top says when it last changed, and material changes are announced in the app or by email before they take effect.