Skip to content
Metric VaultHelp Center
Open app

GDPR and compliance

The data protection commitments Metric Vault makes under GDPR, UK GDPR and CCPA, how international transfers are covered, and the exact route for a rights request.

Last updated 2026-09-10

Summary#

Metric Vault is the data controller for personal data collected through the website and platform. We operate from Hollywood, Florida, in the United States, and our servers are in the US. For customers in the EEA, the UK and Switzerland we rely on Standard Contractual Clauses or the UK IDTA to cover that transfer.

Every data right is exercised the same way: email hello@metricvaultai.com with the appropriate subject line. There is no self-service portal for rights requests, and this page is deliberate about saying so rather than implying one. The response commitment is 30 days, extendable to 90 for complex requests with notice.

The binding documents are the Privacy Policy and the GDPR & Data page at metricvaultai.com/legal. This article explains what they mean in practice.

Purpose#

Two very different readers land here. Someone completing a vendor review needs the controller identity, the legal bases, the transfer mechanism, the sub-processor position and the breach commitment, in a form they can paste into an assessment. Someone exercising a right needs to know exactly what to send, where, and how long it takes.

Both are answered below without you having to read three legal pages to assemble them.

Overview#

QuestionAnswer
Who is the controller?Metric Vault AI, Hollywood, FL 33020, USA
Contact for data protectionhello@metricvaultai.com, +1 (866) 775-1331
Is there a Data Protection Officer?No. The Article 37 thresholds for mandatory appointment are not met. Privacy enquiries are handled directly by the operations team
Where is data processed?The United States
Transfer mechanism for EEA dataStandard Contractual Clauses under Article 46(2)(c)
Transfer mechanism for UK dataThe UK International Data Transfer Agreement, or UK-approved SCCs
Are sub-processors under DPAs?Yes. Every processor is bound by a data processing agreement requiring processing on our instructions only
Automated decision-making with legal effect?None. Article 22 does not apply to how we operate
Special category data?Not requested, collected or processed
Minimum ageThe platform is not directed at anyone under sixteen
Breach notificationSupervisory authority within 72 hours under Article 33; affected individuals without undue delay under Article 34
Certifications heldGDPR and CCPA compliance posture; payments through Stripe, which is PCI-DSS Level 1 certified. No SOC 2 or ISO 27001 certification is claimed

How it works#

BasisWhat it covers
Performance of a contract — Article 6(1)(b)Creating and running your account, generating reports, providing platform access, processing payments. Without this processing there is no service
Legitimate interests — Article 6(1)(f)Product analytics and improvement, security monitoring, fraud prevention, and non-marketing business communications. You can object at any time
Consent — Article 6(1)(a)Marketing emails and newsletters, and non-essential cookies. Withdrawable at any time, without affecting processing already carried out
Legal obligation — Article 6(1)(c)Tax and financial record keeping, lawful law-enforcement requests, court orders

Your rights, and exactly how to use them#

RightArticleHow to exercise it
Access — a copy of the personal data we hold15Email us. See the request routes below
Rectification — correct inaccurate data16Change your display name yourself on the Account screen. Anything you cannot edit there, email us. Note that the email address on an account cannot be changed in the product; ask us
Erasure17Email us. See Erasure below
Restriction of processing18Email us
Portability — a machine-readable copy20Email us. The in-app Export My Data button is a summary of the Account screen, not a full archive. See Exporting your data
Objection, including to direct marketing21Email us. Marketing emails also carry an unsubscribe link, which is absolute and immediate
Not to be subject to solely automated decisions22Nothing to exercise. We make no such decisions

California residents (CCPA / CPRA) have the right to know what is collected, used and disclosed; to delete; to correct; to opt out of sale or sharing; and to non-discrimination for exercising those rights. We do not sell or share personal information as those terms are defined under CCPA, so the opt-out has nothing to act on.

Making a request#

Request typeEmailSubject lineResponse
GDPR, UK GDPR or Swiss rights requesthello@metricvaultai.comGDPR Rights Request30 days, extendable to 90 with notice inside the first 30
Any other privacy right, including CCPAhello@metricvaultai.comPrivacy Rights Request30 days
Account deletionsupport@metricvaultai.comAccount deletion requestThe Delete Account button writes this for you. See Deleting your account
A copy of the SCCs or IDTA, a DPA, or a completed security questionnairehello@metricvaultai.comSay what you needWe aim to reply to data protection enquiries within five business days

Send the request from the address on the account where you can. We may need to verify your identity before acting, which is a protection for you rather than an obstacle. There is no fee, except that we reserve the right to charge a reasonable administrative fee for a manifestly unfounded or excessive request.

Erasure in practice#

Erasure is handled by a person, not by an automated flow, and this page is explicit about that because assuming otherwise leads to unpleasant surprises.

Ordinary account closure and an Article 17 erasure request follow the same route and the same commitment: personal information is deleted or anonymised within 90 days. Two carve-outs apply and both are lawful.

  • Billing and transaction records are retained for up to 7 years to meet tax and financial reporting obligations. Article 17(3)(b) covers this.
  • Anonymised, aggregated data that cannot be used to identify you may be kept indefinitely. Once it is genuinely anonymous it is no longer personal data.

Cancel your subscription first — a deletion request does not stop billing — and export anything you want to keep, because everything goes. Data retention and deletion sets out what is deleted and when.

International transfers#

Our infrastructure is in the United States, which has no adequacy decision from the European Commission for general transfers. We therefore rely on:

  • Standard Contractual Clauses approved by the European Commission under Article 46(2)(c) for EEA data.
  • The UK International Data Transfer Agreement, or UK-approved SCCs, for UK data.

Copies of the applicable clauses are available on request. Switzerland's revised Federal Act on Data Protection imposes equivalent obligations, which we meet on the same basis.

Sub-processors#

Every third party that processes personal data on our behalf is bound by a data processing agreement requiring them to process only on our instructions, implement appropriate security measures, and assist us with our own obligations. They are not authorised to use your data for their own purposes.

The named list, and what each one receives, is in Subprocessors and data flow. If we onboard a new sub-processor that materially affects your data, that page and the GDPR page are updated and we notify you where required.

The platform uses cookies and similar technologies for three purposes: essential ones that keep you signed in and maintain security, analytics that show how the product is used, and marketing ones set when you interact with our advertising. Essential cookies cannot be switched off while you have a signed-in account.

Whether analytics waits for consent depends on where you are. In the EEA, the UK and Switzerland it is opt-in: the banner appears on a first visit, analytics and marketing both start switched off, and until you accept, neither Google Analytics cookie is written at all. Declining leaves them unwritten, and so does closing the banner without answering.

Everywhere else it is opt-out. No banner appears and analytics is enabled by default. The Cookie settings link in the footer of every page is the way out, and it is wired on every page in every region, including for visitors who never see a banner. Withdrawing consent takes effect immediately.

An answer you chose decides every return visit, in every region and in both directions: a decline given in the EEA still holds if you next visit from the United States, and an acceptance still holds after you travel home. It is kept for 12 months, and while it exists no location check is made at all.

A default that applied because of where you were is treated differently. It is re-checked against your location on each visit, so a default granted somewhere that allows opt-out is discarded rather than carried with you if you later visit from the EEA, the UK or Switzerland. You are asked instead, and analytics stays off until you answer.

Opening Cookie settings and saving replaces either of those with an explicit choice.

If your browser sends a Global Privacy Control signal, we ask rather than assume: the banner is shown and analytics stays off until you answer it.

The region is read from Cloudflare's edge geolocation when the page loads, and only when there is no stored answer. If it cannot be established, for any reason, the banner is shown and analytics is withheld until you answer.

Two cookies are set before you answer and neither is used for analytics: zaraz-consent, which is the record of your answer and holds a refusal until you change it, and cf_zaraz_client, which the tag loader writes empty.

The Cookies Policy carries the itemised list, with every cookie name, provider, purpose, type and duration, so an assessment can be completed from the page itself. If you would rather have a tracking preference recorded and actioned by us directly instead of through the banner, email hello@metricvaultai.com and say so.

Breach notification#

If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the relevant supervisory authority within 72 hours of becoming aware of it, as Article 33 requires. Where the risk is substantial, we notify affected individuals directly without undue delay under Article 34, describing the nature of the breach, its likely consequences, the measures taken, and where to ask further questions.

If you are not satisfied#

You can lodge a complaint with your supervisory authority. We would much rather resolve it directly first, so please write to hello@metricvaultai.com before escalating.

Where you areAuthority
European UnionThe Data Protection Authority of the member state where you live, work, or where the alleged infringement occurred. The directory is at edpb.europa.eu
United KingdomThe Information Commissioner's Office, ico.org.uk, 0303 123 1113
SwitzerlandThe Federal Data Protection and Information Commissioner, edoeb.admin.ch

What we commit to, plainly#

  • We do not sell your personal information.
  • We do not use your data to train third-party AI models.
  • We do not share your analyzed domains or competitive intelligence with other Metric Vault customers.
  • Data you submit remains yours. Our license to process it exists only to deliver the service.
  • Staff access account data only to investigate a support request you raised, to diagnose a technical problem, or where a legal obligation requires it.

If your organization needs something this page does not cover — a signed DPA, a completed questionnaire, an attestation, or a specific contractual term — write to hello@metricvaultai.com and say what you need. Contacting support lists the other contact routes.

See also

Was this article helpful?