Privacy Policy

Last updated: August 30, 2026

GTM Studio builds and runs go-to-market systems for B2B companies. To do that work we handle personal data. This page says what we collect, why, and what your rights are. We keep it short and in plain language.

1. Who we are

GTM Studio is operated by [legal entity name], registered at [address]. We are the data controller for this website and for our own client records. For prospect data we process on behalf of a client, the client is the controller and we are the processor (see our Data Processing Agreement).

2. Three kinds of people, three kinds of data

Visitors to this website: basic technical data only. Clients and people who contact us: name, work email, company, and what you write to us. Prospects in the systems we build for clients: business contact data (name, role, company, work email, public signals), processed under the client's instructions.

3. What this website collects

This site does not set tracking cookies and does not show a consent banner. Server logs record requests (IP address, page, time) for security and error diagnosis, and rotate automatically.

4. What we never do

We do not sell personal data. We do not buy or use consumer data. We do not enrich private information about individuals — signals we track are business signals: job posts, product launches, technology changes, company news.

5. Prospect data in client systems

The systems we build watch a client's market and score companies. Personal data in those systems is limited to business contact details of people in relevant roles. Each client's data lives in that client's own accounts (their CRM, their outreach tools) wherever the tool allows it. When an engagement ends, the system and its data stay with the client.

6. What we hold about you, the client

Contract details, billing details, contact history, and the working documents of the engagement. We keep them as long as the engagement runs, plus what tax and contract law requires.

7. Where data lives

Our own records are stored with providers located in the EU or covered by EU-approved transfer safeguards. Client systems live in the tools the client chooses; their locations are listed in the engagement documentation.

8. Subprocessors

We use a short list of service providers (hosting, email, document storage, and the GTM tools named in each engagement). The current list is available on request and in the DPA annex for clients.

9. How long we keep things

Contact form messages: up to 12 months. Client records: the engagement plus legal retention periods. Server logs: 30 days. Prospect data: controlled by the client, not by us.

10. Legal bases

We rely on contract performance (running your engagement), legitimate interest (answering messages, securing the site, B2B outreach on behalf of clients), and legal obligation (bookkeeping). Where a client's campaign requires consent under local law, the client obtains it.

11. International transfers

When data leaves the EEA we use EU Standard Contractual Clauses or an adequacy decision. Details per provider are in the subprocessor list.

12. Your rights

You can ask for access, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Write to us and we answer within 30 days. If we process your data as a processor, we forward the request to the client who controls it. You can also complain to your local data protection authority.

13. Changes to this policy

When this policy changes, the date at the top changes with it. Material changes are announced to active clients directly.

14. Contact

Questions about privacy: use the contact page or write to [privacy email].