Privacy Policy
Last updated: August 30, 2026
GTM Studio builds and runs go-to-market systems for B2B companies. To do that work we handle personal data. This page says what we collect, why, and what your rights are. We keep it short and in plain language.
1. Who we are
GTM Studio is operated by [legal entity name], registered at [address]. We are the data controller for this website and for our own client records. For prospect data we process on behalf of a client, the client is the controller and we are the processor (see our Data Processing Agreement).
2. Three kinds of people, three kinds of data
Visitors to this website: basic technical data only. Clients and people who contact us: name, work email, company, and what you write to us. Prospects in the systems we build for clients: business contact data (name, role, company, work email, public signals), processed under the client's instructions.
3. What this website collects
This site does not set tracking cookies and does not show a consent banner. Server logs record requests (IP address, page, time) for security and error diagnosis, and rotate automatically.
4. What we never do
We do not sell personal data. We do not buy or use consumer data. We do not enrich private information about individuals — signals we track are business signals: job posts, product launches, technology changes, company news.
5. Prospect data in client systems
The systems we build watch a client's market and score companies. Personal data in those systems is limited to business contact details of people in relevant roles. Each client's data lives in that client's own accounts (their CRM, their outreach tools) wherever the tool allows it. When an engagement ends, the system and its data stay with the client.
6. What we hold about you, the client
Contract details, billing details, contact history, and the working documents of the engagement. We keep them as long as the engagement runs, plus what tax and contract law requires.
7. Where data lives
Our own records are stored with providers located in the EU or covered by EU-approved transfer safeguards. Client systems live in the tools the client chooses; their locations are listed in the engagement documentation.
8. Subprocessors
We use a short list of service providers (hosting, email, document storage, and the GTM tools named in each engagement). The current list is available on request and in the DPA annex for clients.
9. How long we keep things
Contact form messages: up to 12 months. Client records: the engagement plus legal retention periods. Server logs: 30 days. Prospect data: controlled by the client, not by us.
10. Legal bases
We rely on contract performance (running your engagement), legitimate interest (answering messages, securing the site, B2B outreach on behalf of clients), and legal obligation (bookkeeping). Where a client's campaign requires consent under local law, the client obtains it.
11. International transfers
When data leaves the EEA we use EU Standard Contractual Clauses or an adequacy decision. Details per provider are in the subprocessor list.
12. Your rights
You can ask for access, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Write to us and we answer within 30 days. If we process your data as a processor, we forward the request to the client who controls it. You can also complain to your local data protection authority.
13. Changes to this policy
When this policy changes, the date at the top changes with it. Material changes are announced to active clients directly.
14. Contact
Questions about privacy: use the contact page or write to [privacy email].