GDPR and compliance
The data protection commitments Metric Vault makes under GDPR, UK GDPR and CCPA, how international transfers are covered, and the exact route for a rights request.
Last updated 2026-09-10
Summary#
Metric Vault is the data controller for personal data collected through the website and platform. We operate from Hollywood, Florida, in the United States, and our servers are in the US. For customers in the EEA, the UK and Switzerland we rely on Standard Contractual Clauses or the UK IDTA to cover that transfer.
Every data right is exercised the same way: email hello@metricvaultai.com with the appropriate subject line. There is no self-service portal for rights requests, and this page is deliberate about saying so rather than implying one. The response commitment is 30 days, extendable to 90 for complex requests with notice.
The binding documents are the Privacy Policy and the GDPR & Data page at metricvaultai.com/legal. This article explains what they mean in practice.
Purpose#
Two very different readers land here. Someone completing a vendor review needs the controller identity, the legal bases, the transfer mechanism, the sub-processor position and the breach commitment, in a form they can paste into an assessment. Someone exercising a right needs to know exactly what to send, where, and how long it takes.
Both are answered below without you having to read three legal pages to assemble them.
Overview#
| Question | Answer |
|---|---|
| Who is the controller? | Metric Vault AI, Hollywood, FL 33020, USA |
| Contact for data protection | hello@metricvaultai.com, +1 (866) 775-1331 |
| Is there a Data Protection Officer? | No. The Article 37 thresholds for mandatory appointment are not met. Privacy enquiries are handled directly by the operations team |
| Where is data processed? | The United States |
| Transfer mechanism for EEA data | Standard Contractual Clauses under Article 46(2)(c) |
| Transfer mechanism for UK data | The UK International Data Transfer Agreement, or UK-approved SCCs |
| Are sub-processors under DPAs? | Yes. Every processor is bound by a data processing agreement requiring processing on our instructions only |
| Automated decision-making with legal effect? | None. Article 22 does not apply to how we operate |
| Special category data? | Not requested, collected or processed |
| Minimum age | The platform is not directed at anyone under sixteen |
| Breach notification | Supervisory authority within 72 hours under Article 33; affected individuals without undue delay under Article 34 |
| Certifications held | GDPR and CCPA compliance posture; payments through Stripe, which is PCI-DSS Level 1 certified. No SOC 2 or ISO 27001 certification is claimed |
How it works#
Legal bases#
| Basis | What it covers |
|---|---|
| Performance of a contract — Article 6(1)(b) | Creating and running your account, generating reports, providing platform access, processing payments. Without this processing there is no service |
| Legitimate interests — Article 6(1)(f) | Product analytics and improvement, security monitoring, fraud prevention, and non-marketing business communications. You can object at any time |
| Consent — Article 6(1)(a) | Marketing emails and newsletters, and non-essential cookies. Withdrawable at any time, without affecting processing already carried out |
| Legal obligation — Article 6(1)(c) | Tax and financial record keeping, lawful law-enforcement requests, court orders |
Your rights, and exactly how to use them#
| Right | Article | How to exercise it |
|---|---|---|
| Access — a copy of the personal data we hold | 15 | Email us. See the request routes below |
| Rectification — correct inaccurate data | 16 | Change your display name yourself on the Account screen. Anything you cannot edit there, email us. Note that the email address on an account cannot be changed in the product; ask us |
| Erasure | 17 | Email us. See Erasure below |
| Restriction of processing | 18 | Email us |
| Portability — a machine-readable copy | 20 | Email us. The in-app Export My Data button is a summary of the Account screen, not a full archive. See Exporting your data |
| Objection, including to direct marketing | 21 | Email us. Marketing emails also carry an unsubscribe link, which is absolute and immediate |
| Not to be subject to solely automated decisions | 22 | Nothing to exercise. We make no such decisions |
California residents (CCPA / CPRA) have the right to know what is collected, used and disclosed; to delete; to correct; to opt out of sale or sharing; and to non-discrimination for exercising those rights. We do not sell or share personal information as those terms are defined under CCPA, so the opt-out has nothing to act on.
Making a request#
| Request type | Subject line | Response | |
|---|---|---|---|
| GDPR, UK GDPR or Swiss rights request | hello@metricvaultai.com | GDPR Rights Request | 30 days, extendable to 90 with notice inside the first 30 |
| Any other privacy right, including CCPA | hello@metricvaultai.com | Privacy Rights Request | 30 days |
| Account deletion | support@metricvaultai.com | Account deletion request | The Delete Account button writes this for you. See Deleting your account |
| A copy of the SCCs or IDTA, a DPA, or a completed security questionnaire | hello@metricvaultai.com | Say what you need | We aim to reply to data protection enquiries within five business days |
Send the request from the address on the account where you can. We may need to verify your identity before acting, which is a protection for you rather than an obstacle. There is no fee, except that we reserve the right to charge a reasonable administrative fee for a manifestly unfounded or excessive request.
Erasure in practice#
Erasure is handled by a person, not by an automated flow, and this page is explicit about that because assuming otherwise leads to unpleasant surprises.
Ordinary account closure and an Article 17 erasure request follow the same route and the same commitment: personal information is deleted or anonymised within 90 days. Two carve-outs apply and both are lawful.
- Billing and transaction records are retained for up to 7 years to meet tax and financial reporting obligations. Article 17(3)(b) covers this.
- Anonymised, aggregated data that cannot be used to identify you may be kept indefinitely. Once it is genuinely anonymous it is no longer personal data.
Cancel your subscription first — a deletion request does not stop billing — and export anything you want to keep, because everything goes. Data retention and deletion sets out what is deleted and when.
International transfers#
Our infrastructure is in the United States, which has no adequacy decision from the European Commission for general transfers. We therefore rely on:
- Standard Contractual Clauses approved by the European Commission under Article 46(2)(c) for EEA data.
- The UK International Data Transfer Agreement, or UK-approved SCCs, for UK data.
Copies of the applicable clauses are available on request. Switzerland's revised Federal Act on Data Protection imposes equivalent obligations, which we meet on the same basis.
Sub-processors#
Every third party that processes personal data on our behalf is bound by a data processing agreement requiring them to process only on our instructions, implement appropriate security measures, and assist us with our own obligations. They are not authorised to use your data for their own purposes.
The named list, and what each one receives, is in Subprocessors and data flow. If we onboard a new sub-processor that materially affects your data, that page and the GDPR page are updated and we notify you where required.
Cookies and consent#
The platform uses cookies and similar technologies for three purposes: essential ones that keep you signed in and maintain security, analytics that show how the product is used, and marketing ones set when you interact with our advertising. Essential cookies cannot be switched off while you have a signed-in account.
Whether analytics waits for consent depends on where you are. In the EEA, the UK and Switzerland it is opt-in: the banner appears on a first visit, analytics and marketing both start switched off, and until you accept, neither Google Analytics cookie is written at all. Declining leaves them unwritten, and so does closing the banner without answering.
Everywhere else it is opt-out. No banner appears and analytics is enabled by default. The Cookie settings link in the footer of every page is the way out, and it is wired on every page in every region, including for visitors who never see a banner. Withdrawing consent takes effect immediately.
An answer you chose decides every return visit, in every region and in both directions: a decline given in the EEA still holds if you next visit from the United States, and an acceptance still holds after you travel home. It is kept for 12 months, and while it exists no location check is made at all.
A default that applied because of where you were is treated differently. It is re-checked against your location on each visit, so a default granted somewhere that allows opt-out is discarded rather than carried with you if you later visit from the EEA, the UK or Switzerland. You are asked instead, and analytics stays off until you answer.
Opening Cookie settings and saving replaces either of those with an explicit choice.
If your browser sends a Global Privacy Control signal, we ask rather than assume: the banner is shown and analytics stays off until you answer it.
The region is read from Cloudflare's edge geolocation when the page loads, and only when there is no stored answer. If it cannot be established, for any reason, the banner is shown and analytics is withheld until you answer.
Two cookies are set before you answer and neither is used for analytics: zaraz-consent, which is the record of your answer and holds a refusal until you change it, and cf_zaraz_client, which the tag loader writes empty.
The Cookies Policy carries the itemised list, with every cookie name, provider, purpose, type and duration, so an assessment can be completed from the page itself. If you would rather have a tracking preference recorded and actioned by us directly instead of through the banner, email hello@metricvaultai.com and say so.
Breach notification#
If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the relevant supervisory authority within 72 hours of becoming aware of it, as Article 33 requires. Where the risk is substantial, we notify affected individuals directly without undue delay under Article 34, describing the nature of the breach, its likely consequences, the measures taken, and where to ask further questions.
If you are not satisfied#
You can lodge a complaint with your supervisory authority. We would much rather resolve it directly first, so please write to hello@metricvaultai.com before escalating.
| Where you are | Authority |
|---|---|
| European Union | The Data Protection Authority of the member state where you live, work, or where the alleged infringement occurred. The directory is at edpb.europa.eu |
| United Kingdom | The Information Commissioner's Office, ico.org.uk, 0303 123 1113 |
| Switzerland | The Federal Data Protection and Information Commissioner, edoeb.admin.ch |
What we commit to, plainly#
- We do not sell your personal information.
- We do not use your data to train third-party AI models.
- We do not share your analyzed domains or competitive intelligence with other Metric Vault customers.
- Data you submit remains yours. Our license to process it exists only to deliver the service.
- Staff access account data only to investigate a support request you raised, to diagnose a technical problem, or where a legal obligation requires it.
If your organization needs something this page does not cover — a signed DPA, a completed questionnaire, an attestation, or a specific contractual term — write to hello@metricvaultai.com and say what you need. Contacting support lists the other contact routes.
See also
Was this article helpful?
Thanks — feedback noted for the docs team.