1. Who we are
Triggerize (“Triggerize”, “we”, “us”) is a multi-tenant SaaS platform that helps marketing teams measure and improve brand visibility across AI search engines, traditional search, and social media. Triggerize is operated by Triggerize B.V., established in the Netherlands.
For the personal data of our platform users (account and identity data), Triggerize acts as a data controller. For the marketing and content data our customers load into their workspaces, Triggerize acts as a data processoron the customer’s behalf; that processing is governed by our Data Processing Agreement.
Data protection enquiries: dpo@triggerize.io.
2. What data we collect
- Account & identity: name, email address, profile image, and a securely hashed password (if you sign in with a password).
- Authentication & security: multi-factor authentication secrets (encrypted), hashed backup codes, IP address, browser/user-agent, trusted-device tokens, and authentication attempt records — used to keep your account secure.
- Single sign-on: where you connect Google or Microsoft, the account identifiers and tokens those providers return.
- Workspace & collaboration: organisation membership, roles and access grants, comments, @mentions, and activity logs.
- Billing: subscription and payment status. Card details are handled directly by our payment processor (Stripe); we do not store card numbers.
- Product & usage data: the domains, keywords, prompts, and content you create, plus telemetry needed to operate and secure the service.
- Application logs: operational logs in which direct identifiers (email, user/organisation IDs, IP) are pseudonymised with a keyed hash before storage.
3. Why we process it & our legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service and your account | Performance of a contract (Art. 6(1)(b)) |
| Security, MFA, fraud & abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Billing and financial records | Contract & legal obligation (Art. 6(1)(b),(c)) |
| Product improvement & analytics | Legitimate interests / consent where required |
| Non-essential cookies & marketing | Consent (Art. 6(1)(a)) |
4. AI features
Triggerize uses AI to generate content drafts, classify keywords, produce recommendations, and score brand visibility. Content you generate with AI is marked as AI-assisted and always passes through human review before it is published. We do not use your data to train third-party foundation models, and our AI providers (Microsoft Azure OpenAI and Mistral AI) are contractually bound not to train their models on our customers’ prompts or outputs. See our Cookie Policy and the in-product AI notices for detail.
5. Who we share data with (sub-processors)
We share data only with vetted service providers bound by data-processing terms. Our principal sub-processors are:
- Microsoft Azure — cloud hosting, database, storage, email, and Azure OpenAI (EU region).
- Mistral AI — LLM visibility scoring (France/EU).
- Serper.dev — search-engine results data (United States).
- Google — PageSpeed Insights performance data (United States).
- Stripe — payment processing (USA/Ireland).
A current sub-processor list is maintained in our compliance records and available on request.
6. International transfers
Our infrastructure and AI processing are hosted in the EU. Where a provider processes data outside the EEA (for example Serper, Google, and Stripe in the United States), transfers are protected by the EU–US Data Privacy Framework where the provider is certified and by Standard Contractual Clauses with supplementary measures as a backstop.
7. How long we keep it
We retain personal data only as long as necessary for the purposes above. Indicative periods: application logs are purged after 90 days; AI model response records after 180 days; deleted or anonymised accounts are purged within 30 days; expired tokens and trusted devices are removed immediately; billing records are kept as required by law. Our full retention schedule is available on request.
8. Your rights
Under the GDPR you have the right to:
- access a copy of your personal data;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to processing;
- data portability;
- not be subject to solely automated decisions with legal or similarly significant effect.
You can download your data and delete your account yourself from your profile settings, or contact dpo@triggerize.io. We respond within one month. You also have the right to lodge a complaint with your supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).
9. Security
We apply encryption in transit (TLS) and at rest, application-level encryption for MFA secrets, role-based access control with audit logging, multi-factor authentication, pseudonymised logging, and least-privilege infrastructure. No system is perfectly secure, but we work continuously to protect your data and will notify you and the relevant authority of a qualifying breach without undue delay.
10. Children
Triggerize is a business tool not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children.
11. Changes
We may update this policy. Material changes will be notified in-product or by email. The “last updated” date above always reflects the current version.