This policy explains how InstantViewAI B.V. ("InstantViewAI", "we", "us") handles personal data when you visit instantview.ai or use our product. We're an EU-first company, and we built our data practices around the GDPR baseline no matter where you happen to be.
1. Who is the controller
For data we collect through this marketing website, InstantViewAI B.V. (registered with the Dutch Chamber of Commerce, KvK 73381187) is the controller. For data we process inside the product on a customer's behalf, the roles flip: the customer is the controller and we're the processor, with the terms set out in our Data Processing Agreement (DPA).
Privacy questions go to privacy@instantview.ai.
2. What we collect
On the website
- Form submissions. Your name, work email, company, role, and whatever you type into a free-text field when you ask for a demo, ROI numbers, or trust documents.
- Analytics. We use two privacy-conscious tools:
- Plausible Analytics measures usage in aggregate: pages viewed, country, device class, referrer. It is cookieless, sets nothing on your device, and stores no personal data or IP addresses, so it runs without a consent banner. Plausible is an EU company and processes the data within the EU.
- Microsoft Clarity records anonymised session replays and click and scroll heatmaps, which show us where the design trips people up. It masks input fields and anything else you'd type into automatically, and we leave all of Clarity's optional identification features switched off.
- Server logs. Short-lived request logs we keep for security, abuse prevention, and uptime monitoring.
Inside the product
Here we handle customer billing and inventory data pulled in from cloud providers (GCP BigQuery billing exports, for example), product user identities (via Keycloak), and audit-trail events. The details and processing terms live in the DPA.
3. Why we use it (legal bases)
- Contract and pre-contract. To reply to your demo request, send the materials you asked for, and run the product you signed up for.
- Legitimate interest. To keep the service secure, head off abuse, and improve our documentation.
- Consent. For analytics cookies, which you can withdraw at any time through Cookie settings.
- Legal obligation. To meet tax, accounting, and other compliance requirements.
4. Who we share it with
We only share personal data with the subprocessors we need to run the service. Right now the main ones are:
- Google Cloud Platform for hosting, BigQuery, Cloud Storage, and KMS, in EU regions by default.
- Mailjet for transactional email and report delivery.
- Plausible Analytics (Plausible Insights OÜ) for cookieless, aggregated website analytics, processed in the EU. No cookies, no personal data, no consent required.
- Microsoft Clarity (Microsoft Corporation) for anonymised session replays and behaviour heatmaps on the marketing site, again only when you accept cookies. That data is processed on Microsoft Azure infrastructure, primarily in the United States, under Microsoft's cookie and consent documentation and Standard Contractual Clauses for international transfers.
- Keycloak for identity and authentication, self-hosted by us with a separate realm per customer.
An up-to-date subprocessor list comes with our DPA, and you can request it from trust@instantview.ai. We don't sell personal data, full stop.
5. Where data lives
EU data residency is the default. Customer data stays in EU regions unless a customer deliberately chooses US residency during onboarding. Service-account keys and other secrets are encrypted at rest with GCP KMS envelope encryption.
6. How long we keep it
We hold marketing form submissions for up to 24 months after our last contact, unless you ask us to delete them sooner. Microsoft Clarity behavioural data is kept for up to a year; Plausible holds only aggregated, non-personal statistics. Customer product data follows the DPA and is usually gone within 30 days of a contract ending, while audit-trail records are kept for the length of the contract so customers can run their audits.
7. Your rights
You can ask us for access, correction, deletion, or restriction, request a portable copy, or object to processing altogether. Email privacy@instantview.ai to exercise any of them and we'll respond within 30 days. You're also free to complain to your supervisory authority, which for EU users is the national Data Protection Authority where you live.
8. Cookies
This site uses just a handful of cookies, and the analytics ones fire only if you accept them. The Cookie Policy has the full list.
9. Security
The product is built to be audit-ready from the start: read-only cloud access, tenant isolation, KMS encryption, and an append-only audit log. You'll find the details on the Security & Trust page.
10. Children
InstantViewAI is a B2B product, and we don't knowingly collect data from anyone under 16.
11. Changes
Whenever our practices change in a meaningful way, we'll update this policy and post the new effective date at the top. If a change is significant and affects existing customers, we'll also reach out to the account's primary contact directly.
12. Contact
InstantViewAI
Vlagzalm 40, Krommenie
Privacy contact: privacy@instantview.ai
Trust documents (DPA and subprocessor list, provided at contracting): trust@instantview.ai