PRIVACY POLICY

1. INTRODUCTION

Marketing Upgrade ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.

This policy is compliant with the General Data Protection Regulation (GDPR), the Dutch Data Protection Act (Autoriteit Persoonsgegevens), and applicable Dutch law. Please read this policy carefully. If you do not agree with our practices, please do not use our services.

2. DATA CONTROLLER

Data Controller: Marketing Upgrade
Location: Netherlands (CET)
Email: hi@marketingupgrade.pro
Responsibility: We are the data controller for personal data collected through our website and services.

3. INFORMATION WE COLLECT

A. Information You Provide Directly:

  • Name, email address, phone number (when booking a consultation)
  • Company information and business details
  • Payment information (processed securely; we do not store credit card details)
  • Messages and communications with our team
  • Information provided during consultations or audits

B. Information Collected Automatically:

  • IP address and device information
  • Browser type and operating system
  • Pages visited and time spent on site
  • Referral source and clickstream data
  • Analytics data (via Umami analytics, privacy-focused and GDPR-compliant)
  • Visitor enrichment data: Company name, domain, location, and size identified from your IP address using IP2Location and Hunter.io APIs

Visitor Tracking & Company Identification: We use IP enrichment services (IP2Location and Hunter.io) to identify your company from your IP address. When confidence is ≥60%, we sync this data to our Notion CRM for lead qualification. This includes: company name, domain, industry, size, location, visit count, and form completion status. This processing is based on our legitimate interest in B2B lead generation.

C. Cookies and Tracking: We use cookies to enhance user experience. See our Cookie Policy for details.

D. Unfinished intake forms: When you complete the first step of the intake form (/apply) and continue, our server emails a six-digit code to the address you gave, to confirm it is yours. The code is not stored: it is signed, so the server can check it without keeping it. Once you enter it, the contact details from that step (name, email address and company, plus phone number and website if you gave them) and any engagement type or challenge already selected are sent to us by email, so we can follow up if you do not finish the form. They are not stored in a database. The legal basis is our legitimate interest in answering an enquiry you started. We delete that email within 30 days if you do not continue, and sooner if you ask. Our server also records that an intake was started, without your name, email address, phone number or company.

E. Calculator and audit emails: Before the calculator and audit forms email you a result, our server emails a six-digit code to the address you gave, to confirm it is yours. The code is not stored: it is signed, so the server can check it without keeping it. Once you enter it, the result is sent to that address, with a copy to us so we can reply. Our server also records that a code was sent and whether it was entered, without your email address.

4. LEGAL BASIS FOR PROCESSING (GDPR)

We process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide services you've requested
  • Legitimate Interest: Marketing, analytics, service improvement, B2B lead generation (visitor tracking and company identification), and following up an intake form you started but did not finish (see 3.D)
  • Consent: For marketing communications and non-essential cookies
  • Legal Obligation: Compliance with Dutch tax and accounting laws

5. HOW WE USE YOUR DATA

We use collected information for:

  • Providing and improving our services
  • Processing payments and sending invoices
  • Communicating with you about bookings and services
  • Sending marketing communications (with your consent)
  • Analyzing website performance and user behavior
  • Complying with legal obligations
  • Detecting and preventing fraud or abuse

6. DATA SHARING & THIRD PARTIES

We do not sell your personal data. We may share data with:

  • Service Providers: Payment processors, email services, analytics platforms (all GDPR-compliant)
  • Enrichment APIs: IP2Location (IP geolocation) and Hunter.io (email domain enrichment) for visitor identification
  • CRM Platform: Notion (for storing enriched company data and lead qualification)
  • Legal Requirements: When required by Dutch law or court order
  • Business Transfers: In case of merger or acquisition

All third parties are bound by confidentiality agreements and process data only as instructed.

6.1 GOOGLE ANALYTICS 4

We use Google Analytics 4 (measurement ID G-7286DPK512) with IP anonymisation and Consent Mode v2. Until you grant analytics consent in the cookie banner, GA4 receives only consent-mode signals — no personal identifiers, no advertising signals, no cross-site tracking. For details see the Google Privacy Policy.

6.2 MICROSOFT CLARITY

We partner with Microsoft Clarity to capture how you use and interact with our website through behavioural metrics, heatmaps, and session replay so we can improve the site. Until you grant analytics consent, Clarity runs in cookieless mode (no first- or third-party cookies set, no persistent identifier). When you grant consent, Clarity records the consent and may use first- and third-party cookies and other tracking technologies to attribute behaviour to a session. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.

6.3 POSTHOG

We use PostHog (data hosted in the EU) to measure how the site is used and which pages lead to an enquiry. Until you accept analytics cookies, or if you refuse them, PostHog counts visits without cookies: nothing is stored on your device, a visit is recognised by a privacy-preserving hash made on PostHog's servers, and IP addresses are discarded. If you accept, PostHog uses first-party cookies to recognise a returning visit and may record the session, with every form input masked. When you submit the intake form, our server records that an intake arrived and the scope you chose (tier, engagement type, challenge, timeline, budget range, company size, industry), never your name, email address, phone number or company. For details see the PostHog privacy policy.

7. DATA RETENTION

We retain personal data for as long as necessary:

  • Service Data: Duration of engagement + 7 years (Dutch tax law requirement)
  • Marketing Contacts: Until you unsubscribe
  • Analytics Data: Google Analytics 4 — 14 months default; Microsoft Clarity — 1 year (then auto-purged); PostHog session recordings — 30 days
  • Visitor Enrichment Data: 24 months or until you request deletion (stored in Notion CRM)
  • Unfinished Intake Forms: Deleted within 30 days if you do not continue, or sooner on request
  • Cookies: As specified in Cookie Policy

8. YOUR GDPR RIGHTS

Under GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate information
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restrict Processing: Limit how we use your data
  • Data Portability: Receive your data in a portable format
  • Object: Opt-out of marketing communications
  • Withdraw Consent: Revoke consent for non-essential processing

To exercise these rights, contact us at hi@marketingupgrade.pro. We will respond within 30 days (GDPR requirement).

9. DATA SECURITY

We implement industry-standard security measures:

  • SSL/TLS encryption for data in transit
  • Secure password storage and authentication
  • Regular security audits and updates
  • Limited access to personal data (need-to-know basis)
  • Incident response procedures

While we strive to protect your data, no system is 100% secure. We will notify you of any data breaches as required by GDPR (within 72 hours).

10. INTERNATIONAL DATA TRANSFERS

Your data is primarily processed in the Netherlands. If we transfer data outside the EU/EEA, we ensure adequate safeguards (Standard Contractual Clauses or adequacy decisions) as required by GDPR.

11. CONTACT & COMPLAINTS

Data Protection Officer / Contact:
Email: hi@marketingupgrade.pro
Location: Netherlands

Complaints: You have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at www.autoriteitpersoonsgegevens.nl if you believe we've violated your privacy rights.

12. POLICY UPDATES

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or website notice. Continued use of our services constitutes acceptance of the updated policy.
Last Updated: September 28, 2026