Privacy Policy
Draft, 4 August 2026 · not yet in forceThis is a draft. The operating entity, its registered address and the supervisory authority details are not yet filled in. This document must be reviewed and completed before the service accepts real customers.
1. Who we are
Acquisition Radar (“we”, “the service”) is operated by [LEGAL ENTITY NAME], registered at [ADDRESS], Slovak Republic, company ID [ICO]. We are the controller of the personal data described below within the meaning of Regulation (EU) 2016/679 (GDPR).
Questions about this policy, or any request under section 7: [CONTACT EMAIL].
2. What the service does
Acquisition Radar helps software companies find creators, podcasts and newsletters that have already published about comparable products. Two different kinds of personal data are involved, and they are treated differently. We keep them separate throughout this policy.
3. Data about you, our user
3.1 Waitlist and account
| What | Why | Legal basis | Kept for |
|---|---|---|---|
| Email address | To tell you when the service opens and to sign you in | Art. 6(1)(b) performance of a contract, or your request before entering one | Until you ask us to delete it |
| Your product URL | To prepare your report | Art. 6(1)(b) | Until you ask us to delete it |
| Marketing consent flag | To record whether you agreed to product emails | Art. 6(1)(a) consent | Until you withdraw it, plus proof of withdrawal |
Marketing email is a separate, unticked checkbox. Joining the waitlist does not sign you up for marketing, and you can withdraw consent at any time using the link in every message.
We deliberately do not log your IP address or browser user agent when you submit a form. We do not use advertising cookies or third-party analytics trackers.
3.2 Payment
When paid plans launch, card details will be handled by our payment processor and will never reach our servers. We will receive only the transaction record needed for accounting and tax.
4. Data about creators appearing in reports
Reports contain information about publicly visible creators, shows and publications: a channel or show name, a link to a specific public video, episode or issue, its publication date, and a publicly listed contact address where the creator has chosen to publish one.
4.1 Where it comes from
Only from public sources: official platform APIs, public RSS feeds (including the
itunes:owner field that podcast publishers put there specifically so they can be
contacted), a creator’s own website, and public sponsorship or media-kit pages.
We do not buy contact data, we do not use email-finding or data-enrichment providers, we do not guess email addresses, and we do not circumvent any technical protection measure such as a CAPTCHA. Every stored contact carries the URL it came from, and we will tell you that URL on request.
4.2 Legal basis
Article 6(1)(f), legitimate interests: connecting businesses with publishers who have publicly and commercially positioned themselves as reachable for exactly this kind of collaboration. We have weighed this against the interests of the individuals concerned. The data is limited to their public professional activity, it is data they published themselves in a business context, and it is used to contact them about work of the type they already do.
4.3 If you are a creator and want out
Write to [CONTACT EMAIL] and we will remove you from the index and suppress you from future reports. You do not need to give a reason. You have an unconditional right to object under Article 21(2) where the processing is for direct marketing purposes, and we will act on it.
5. Third parties who process data for us
| Provider | Purpose | Where |
|---|---|---|
| Neon | Database hosting | EU, Frankfurt |
| Cloudflare | Website and API hosting | EU edge, company in the USA |
| Google (YouTube Data API) | Public video and channel data | USA |
| Groq | Speech-to-text on public podcast audio | USA |
| Anthropic | Analysing product descriptions and ranking results | USA |
Transfers outside the European Economic Area rely on the European Commission’s Standard Contractual Clauses or an adequacy decision. We do not sell personal data to anyone, and we do not share your account data with other customers.
6. YouTube API Services
Acquisition Radar uses YouTube API Services. By using the service you agree to be bound by the YouTube Terms of Service. Google’s handling of data is described in the Google Privacy Policy. You can review and revoke Acquisition Radar’s access to your data through the Google security settings page, although note that the service reads only public data and does not ask you to connect a Google account.
Content retrieved from the YouTube API is refreshed or deleted within 30 days, in line with the YouTube API Services Developer Policies.
7. Your rights
Under the GDPR you may ask us to:
- give you a copy of the personal data we hold about you (Art. 15)
- correct it if it is wrong (Art. 16)
- delete it (Art. 17)
- restrict how we use it (Art. 18)
- hand it over in a portable format (Art. 20)
- stop processing based on legitimate interests (Art. 21)
Write to [CONTACT EMAIL]. We answer within one month. If you are not satisfied you may complain to the Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk) or to the authority where you live.
8. How long we keep things
- Your account and waitlist entry: until you ask us to delete it.
- YouTube-derived content: refreshed or deleted within 30 days.
- Creator contact records: reviewed regularly, and deleted on request.
- Invoices: ten years, because Slovak accounting law requires it.
9. Security
Data is encrypted in transit and at rest by our hosting providers. Access to the production database is limited to the operator. We keep the amount of personal data we hold deliberately small, which is the most effective protection available to a service of this size.
10. Children
The service is sold to businesses and is not intended for anyone under 16. We do not knowingly collect data from children.
11. Changes
If we change this policy materially we will email everyone on the list before the change takes effect. The date at the top always shows the current version.