MetricVault AI serves users across Europe, the UK, and Switzerland. This page explains how we comply with the General Data Protection Regulation (GDPR) and equivalent laws, and what that means for you in practice.
GDPR & Data
MetricVault AI · metricvaultai.com
Effective Date: July 2, 2026 | Last Updated: July 2, 2026
1. Overview
The General Data Protection Regulation (EU) 2016/679, commonly known as GDPR, is a comprehensive data protection law that applies to organizations that collect or process personal data of individuals in the European Economic Area (EEA). The UK GDPR (retained from EU law post-Brexit) and Switzerland's revised Federal Act on Data Protection (revFADP) impose equivalent obligations.
MetricVault AI, operated from Hollywood, Florida, USA, is committed to meeting these obligations for all users in these regions. This document is a supplement to our Privacy Policy and explains our GDPR-specific commitments in detail. Where this document conflicts with our Privacy Policy, the more specific provision applies.
2. Data Controller
MetricVault AI acts as the data controller for personal data collected through our website and Platform. As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring that processing is lawful, fair, and transparent.
Our contact details for data protection matters:
- Email: hello@metricvaultai.com
- Phone: +1 (305) 563-5051
- Mailing address: MetricVault AI, Hollywood, FL 33020, USA
We do not currently have a formal Data Protection Officer (DPO) on staff, as we do not meet the mandatory DPO appointment thresholds under Article 37 GDPR. However, privacy inquiries are managed directly and promptly by our operations team.
3. What Personal Data We Process
We process the following categories of personal data for EEA, UK, and Swiss users:
3.1 Account and Identity Data
- Full name
- Email address.
- Encrypted password hash
- Company name (if provided)
3.2 Transaction and Billing Data
- Subscription plan and billing cycle
- Payment transaction records (amounts, dates, reference IDs)
- Billing country
Note: We do not store card numbers, CVVs, or full payment details. These are managed exclusively by Stripe, a PCI-DSS Level 1 certified processor.
3.3 Usage and Technical Data
- IP address (used for approximate geolocation and security monitoring)
- Browser and device type
- Pages visited and features used within the Platform.
- Session timestamps and activity logs
3.4 Communication Data
- Content of emails or support messages you send us.
- Marketing email engagement data (opens, clicks, unsubscribes)
We do not process special categories of personal data (e.g., health data, biometric data, racial or ethnic origin, political opinions, or religious beliefs).
4. Legal Bases for Processing
Under Article 6 of the GDPR, we rely on the following legal bases for processing your personal data:
4.1 Performance of a Contract (Article 6(1)(b))
Most of our processing is necessary to deliver the services you signed up for. This includes creating and managing your account, generating reports, processing payments, and providing platform access. Without this processing, we cannot provide the service.
4.2 Legitimate Interests (Article 6(1)(f))
We rely on legitimate interests for:
- Platform analytics and product improvement (understanding how features are used)
- Security monitoring and fraud prevention
- Business communications that are not purely marketing (e.g., product updates that benefit you as a user)
In each case, we have assessed that our legitimate interests are not overridden by your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time. See Section 7.
4.3 Consent (Article 6(1)(a))
We rely on consent for:
- Marketing emails and newsletters: you can withdraw consent at any time via the unsubscribe link in any email.
- Non-essential cookies (analytics and marketing cookies): managed via our cookie banner.
Withdrawing consent does not affect the lawfulness of any processing conducted before withdrawal.
4.4 Legal Obligation (Article 6(1)(c))
We may retain or disclose data where required by applicable law, including tax and financial record-keeping obligations, law enforcement requests under lawful authority, or court orders.
5. International Data Transfers
MetricVault AI is based in the United States, and our servers are in the US. Transfers of personal data from the EEA, UK, or Switzerland to the US are subject to specific rules under GDPR because the US is not deemed to offer an equivalent level of data protection by default.
For transfers of EEA user data to the US, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR as our transfer mechanism. These contractual safeguards require our processors to protect your data to an equivalent standard.
For UK users, we rely on the UK International Data Transfer Agreement (IDTA) or UK-approved SCCs as appropriate.
You can request a copy of the applicable SCCs or IDTA by contacting hello@metricvaultai.com.
6. Data Processors and Sub-Processors
As a data controller, we engage third-party data processors who process personal data on our behalf. All processors are bound by data processing agreements (DPAs) that require them to process data only on our instructions, implement appropriate security measures, and assist us in fulfilling our GDPR obligations.
Our current sub-processors include:
- Stripe, Inc. (USA): payment processing and billing management
- DataForSEO (Ukraine/International): SEO data, backlink analysis, and SERP data
- Uptime Robot (USA): platform availability monitoring
- Cloud hosting and infrastructure providers: server storage and platform delivery
We do not authorize our processors to use your personal data for their own purposes. If we onboard new sub-processors that materially affect your data, we will update this page and notify you where required.
7. Your Rights Under GDPR
As a data subject in the EEA, UK, or Switzerland, you have the following rights under GDPR. We take these seriously and will respond to all valid requests within the periods required by law (typically 30 days, extendable to 90 days for complex requests with notice).
7.1 Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you, along with information about how and why we process it. We will provide this in a structured, commonly used format.
7.2 Right to Rectification (Article 16)
If any personal data we hold about you is inaccurate or incomplete, you have the right to ask us to correct it. For account information, you can update most details directly in your dashboard.
7.3 Right to Erasure (Article 17)
You have the right to request deletion of your personal data in certain circumstances, including where:
- The data is no longer necessary for the purpose it was collected.
- You withdraw consent and there is no other legal basis for processing.
- You object to processing and there are no overriding legitimate grounds.
- The data was unlawfully processed.
Note: We may be unable to delete data we are legally obligated to retain, such as billing records required for tax compliance.
7.4 Right to Restriction of Processing (Article 18)
You have the right to request that we restrict how we use your personal data in certain circumstances, for example, while we verify the accuracy of data you have contested, or while we assess an objection you have raised.
7.5 Right to Data Portability (Article 20)
Where processing is based on consent or contract and conducted by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV) and to transmit it to another controller.
7.6 Right to Object (Article 21)
You have the right to object at any time to processing of your personal data that is based on our legitimate interests (Article 6(1)(f)). If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, or where the processing is necessary for legal claims.
You also have an absolute right to object to processing for direct marketing purposes at any time.
7.7 Right Not to Be Subject to Automated Decision-Making (Article 22)
MetricVault AI does not make decisions about you that produce legal or similarly significant effects based solely on automated processing. Our platform generates reports and data outputs, but decisions about your account (e.g., plan eligibility, access) are based on your subscription choice, not automated profiling.
8. How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at:
- Email: hello@metricvaultai.com (subject: 'GDPR Rights Request')
- Phone: +1 (305) 563-5051
We may need to verify your identity before processing a request. We will not charge a fee for legitimate requests, though we reserve the right to charge a reasonable administrative fee for manifestly unfounded or excessive requests.
We will respond within 30 days. If we need more time (up to 90 days total), we will notify you within the initial 30-day window and explain the reason.
9. Right to Lodge a Complaint
If you believe we have processed your personal data unlawfully or failed to respect your GDPR rights, you have the right to lodge a complaint with your national supervisory authority:
- European Union: Contact the Data Protection Authority (DPA) in the EU member state where you live, work, or where the alleged infringement occurred. A directory of EU DPAs is available at edpb.europa.eu.
- United Kingdom: Contact the Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.
- Switzerland: Contact the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
We would always prefer to resolve concerns directly before you escalate to a regulator. Please reach out to us first at hello@metricvaultai.com.
10. Data Retention
We retain personal data for as long as your account is active or as needed to deliver services. Upon account closure:
- Personal account data (name, email, usage history) is deleted or anonymized within 90 days.
- Billing and transaction records are retained for 7 years to meet tax and financial compliance requirements.
- Anonymized, aggregated data that cannot identify you may be retained indefinitely for product analytics.
You may request early deletion of your data under Article 17, subject to any applicable legal retention requirements.
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, MetricVault AI will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR.
Where a breach is likely to result in a substantial risk to your rights and freedoms, we will also notify you directly without undue delay, as required by Article 34 GDPR. The notification will describe the nature of the breach, the consequences, the measures we have taken or propose to take, and contact information for further questions.
12. Cookies and Consent
We use cookies and similar tracking technologies on our website and platform. For EEA, UK, and Swiss users, we request your consent for non-essential cookies (analytics and marketing) via our cookie banner before placing them on your device.
You may withdraw cookie consent at any time through the cookie settings accessible in the footer of our website. For full details on cookies, their names, durations, and purposes, see our Cookie Policy at metricvaultai.com/legal#cookies.
13. Updates to This Document
We may update this GDPR & Data document from time to time as our Platform evolves or as applicable law changes. The 'Last Updated' date at the top of this document reflects the most recent revision. We will notify EEA, UK, and Swiss users of material changes by email.
14. Contact for Data Protection Matters
All data protection and GDPR-related inquiries should be directed to:
- Email: hello@metricvaultai.com
- Phone: +1 (305) 563-5051
- Post: MetricVault AI, Hollywood, FL 33020, USA
We aim to respond to all data protection inquiries within five business days.
GDPR is not just a compliance checkbox for us. It reflects the standard we hold ourselves to for all users, regardless of where they are in the world. We believe you should always know what happens to your data, and always be able to control it.
The MetricVault AI Team · Hollywood, FL · July 2026
