A note before the legalese
We try to write this in language a real human can read. Where the law makes us use a specific term (controller, processor, lawful basis), we explain what it means in plain English right next to it. If anything is unclear, email privacy@peutly.com and a founder will get back to you.
1. Who we are
Peutly B.V. ("Peutly", "we", "us") is a private company registered in the Netherlands and based in Amsterdam. We are the data controller — the party that decides how and why data is used — for the information you give us as a customer or visitor. We are the data processor — the party that handles data on someone else's instructions — for the demo content and viewer events that flow through Peutly on your behalf.
2. What we collect
- Account data: name, work email, company, password hash and billing address. Collected when you sign up or pay an invoice.
- Support and feedback data: anything you send us through support, surveys, or product feedback, so we can help and improve.
- Product telemetry: pages visited inside the Peutly app, clicks, feature usage, browser type and IP-derived country. Used only for debugging and product improvement — never sold.
- Demo content: the HTML, copy, screenshots and analytics you capture or import. We process this as your processor under our Data Processing Agreement.
- Viewer events: anonymous-by-default events from the people who watch your demos. You decide what we capture; our defaults exclude IP addresses and form input.
3. How we collect it
Most of what we hold, you give us directly — when you create an account, pay, contact support, or use the app. Some is collected automatically as you use the Service (see telemetry and cookies below). Occasionally we receive limited data from third parties such as our payment or authentication providers, and we handle it under this policy. By giving us information, or asking us to process data on your behalf, you consent to that processing as described here.
4. Why we collect it
We process personal data only to (a) provide, secure and bill the Service, (b) prevent abuse and meet our legal and security obligations, and (c) improve the product based on aggregate usage signals. We may occasionally tell you about features and updates that are relevant to you. We do not run ad networks, build shadow profiles, or sell data to third parties — ever. If you withhold information we genuinely need, some parts of the Service may not work.
5. Lawful bases (GDPR)
We rely on:
- Contract, for everything required to deliver Peutly to you.
- Legitimate interest, for product telemetry, abuse prevention, and direct service-related emails.
- Consent, for non-essential cookies and any marketing email you've opted into.
- Legal obligation, when tax, accounting or compliance laws require retention.
We don't knowingly collect special categories of sensitive data, and we ask that you don't put it into demos either. Peutly isn't aimed at children; if you are under 16, please only use it with a parent or guardian's consent.
6. Where data lives and international transfers
Peutly runs on established cloud infrastructure, and we keep EU customer data in the EU by default. Some of our sub-processors operate outside the EU, so data may at times be stored, processed or transferred internationally. When that happens we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses — to protect it. For the current list of regions and any options for pinned storage, email privacy@peutly.com.
7. Sub-processors
We use a small, carefully chosen set of sub-processors for hosting, payments, transactional email and AI-assisted features. Each is bound by data-protection terms at least as strict as ours. We'll share the current list, with the safeguards that apply, on request.
8. Cookies and analytics
We use a few cookies and similar technologies to keep you signed in, remember your preferences, and understand — in aggregate — how the site and app are used so we can improve them. Essential cookies are needed for the Service to work; non-essential ones run only with your consent. You can refuse or clear cookies in your browser settings, though some features may then behave differently.
9. Other websites
Our site and demos may link to services we don't control. This policy doesn't cover those third parties, and we're not responsible for their practices — please check their own privacy notices before sharing data with them.
10. How long we keep things
- Account data: while your account is active, plus a short period after deletion.
- Demo content: while the demo exists; deleted on request.
- Viewer events: for as long as they're useful to you — configurable.
- Backups: rotated regularly and encrypted.
- Billing data: for as long as Dutch tax law requires.
11. Your rights
Under the GDPR you can access, correct, port, restrict, object to, or delete your personal data, withdraw any consent you gave, and ask us not to subject you to solely automated decisions. Email privacy@peutly.com and we'll respond within 30 days (usually much sooner). We may need to verify your identity first. If you're not satisfied with our response, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.
12. Security
Data is encrypted at rest and in transit. We require two-factor authentication for every team member and follow current best practices for access management. No system is perfectly secure, but we work hard to keep yours safe and we're happy to walk you through our posture — email security@peutly.com. If you believe you've found a vulnerability, see our responsible disclosure page.
13. Complaints
We take privacy complaints seriously. Send yours to privacy@peutly.com and we'll acknowledge it quickly and work with you toward a resolution.
14. Changes to this policy
When we make a meaningful change we'll notify workspace admins by email before it takes effect, and we'll update the date at the top of this page. We encourage you to check back now and then.