Acquisition Radar

Privacy Policy

Draft, 4 August 2026 · not yet in force

This is a draft. The operating entity, its registered address and the supervisory authority details are not yet filled in. This document must be reviewed and completed before the service accepts real customers.

1. Who we are

Acquisition Radar (“we”, “the service”) is operated by [LEGAL ENTITY NAME], registered at [ADDRESS], Slovak Republic, company ID [ICO]. We are the controller of the personal data described below within the meaning of Regulation (EU) 2016/679 (GDPR).

Questions about this policy, or any request under section 7: [CONTACT EMAIL].

2. What the service does

Acquisition Radar helps software companies find creators, podcasts and newsletters that have already published about comparable products. Two different kinds of personal data are involved, and they are treated differently. We keep them separate throughout this policy.

3. Data about you, our user

3.1 Waitlist and account

WhatWhyLegal basisKept for
Email addressTo tell you when the service opens and to sign you inArt. 6(1)(b) performance of a contract, or your request before entering oneUntil you ask us to delete it
Your product URLTo prepare your reportArt. 6(1)(b)Until you ask us to delete it
Marketing consent flagTo record whether you agreed to product emailsArt. 6(1)(a) consentUntil you withdraw it, plus proof of withdrawal

Marketing email is a separate, unticked checkbox. Joining the waitlist does not sign you up for marketing, and you can withdraw consent at any time using the link in every message.

We deliberately do not log your IP address or browser user agent when you submit a form. We do not use advertising cookies or third-party analytics trackers.

3.2 Payment

When paid plans launch, card details will be handled by our payment processor and will never reach our servers. We will receive only the transaction record needed for accounting and tax.

4. Data about creators appearing in reports

Reports contain information about publicly visible creators, shows and publications: a channel or show name, a link to a specific public video, episode or issue, its publication date, and a publicly listed contact address where the creator has chosen to publish one.

4.1 Where it comes from

Only from public sources: official platform APIs, public RSS feeds (including the itunes:owner field that podcast publishers put there specifically so they can be contacted), a creator’s own website, and public sponsorship or media-kit pages.

We do not buy contact data, we do not use email-finding or data-enrichment providers, we do not guess email addresses, and we do not circumvent any technical protection measure such as a CAPTCHA. Every stored contact carries the URL it came from, and we will tell you that URL on request.

4.2 Legal basis

Article 6(1)(f), legitimate interests: connecting businesses with publishers who have publicly and commercially positioned themselves as reachable for exactly this kind of collaboration. We have weighed this against the interests of the individuals concerned. The data is limited to their public professional activity, it is data they published themselves in a business context, and it is used to contact them about work of the type they already do.

4.3 If you are a creator and want out

Write to [CONTACT EMAIL] and we will remove you from the index and suppress you from future reports. You do not need to give a reason. You have an unconditional right to object under Article 21(2) where the processing is for direct marketing purposes, and we will act on it.

5. Third parties who process data for us

ProviderPurposeWhere
NeonDatabase hostingEU, Frankfurt
CloudflareWebsite and API hostingEU edge, company in the USA
Google (YouTube Data API)Public video and channel dataUSA
GroqSpeech-to-text on public podcast audioUSA
AnthropicAnalysing product descriptions and ranking resultsUSA

Transfers outside the European Economic Area rely on the European Commission’s Standard Contractual Clauses or an adequacy decision. We do not sell personal data to anyone, and we do not share your account data with other customers.

6. YouTube API Services

Acquisition Radar uses YouTube API Services. By using the service you agree to be bound by the YouTube Terms of Service. Google’s handling of data is described in the Google Privacy Policy. You can review and revoke Acquisition Radar’s access to your data through the Google security settings page, although note that the service reads only public data and does not ask you to connect a Google account.

Content retrieved from the YouTube API is refreshed or deleted within 30 days, in line with the YouTube API Services Developer Policies.

7. Your rights

Under the GDPR you may ask us to:

Write to [CONTACT EMAIL]. We answer within one month. If you are not satisfied you may complain to the Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk) or to the authority where you live.

8. How long we keep things

9. Security

Data is encrypted in transit and at rest by our hosting providers. Access to the production database is limited to the operator. We keep the amount of personal data we hold deliberately small, which is the most effective protection available to a service of this size.

10. Children

The service is sold to businesses and is not intended for anyone under 16. We do not knowingly collect data from children.

11. Changes

If we change this policy materially we will email everyone on the list before the change takes effect. The date at the top always shows the current version.