Privacy and cookies

Privacy & Cookie Statement

This statement explains which data Roby Monitor uses, why, how long it is retained and which choices visitors and customers have.

Last updated: 13 July 2026

1.Who is responsible?

Roby Monitor provides Roby Monitor and is responsible for the personal data described here. Contact us at support@robymonitor.com.

2.Data we process

  • Account, organization, role and security information, including login events and optional two-factor authentication.
  • Company profiles, website URLs, prompts, public website findings, AI-provider responses, reports and action-item status.
  • Billing contact details, orders, subscriptions, promotion use and invoice records. Full payment-card details remain with the payment provider.
  • Support messages, email-delivery status, technical logs, rate-limit events and security audit trails.
  • Consent-based website measurement. Currently configured providers: none.

3.Why and on what basis

  • To provide the contract: accounts, audits, reports, monitoring, support and billing.
  • To comply with legal and tax obligations, including invoice administration.
  • For legitimate security and reliability interests: abuse prevention, incident investigation, capacity planning and service diagnostics.
  • With consent only: non-essential analytics, Clarity, Meta Pixel or custom measurement pixels. Refusing analytics does not restrict the service.

4.AI providers and other recipients

A paid audit sends the configured measurement prompt and relevant company context to the AI providers enabled for the customer’s plan. Hosting, database, email, payment and monitoring suppliers process only what is needed for their service. Provider availability and models are recorded with the audit. Where data is processed outside the EEA, we require an applicable transfer mechanism and supplier safeguards.

5.Retention

  • Raw AI responses are removed or replaced by a retention marker after 90 days by default.
  • Normalized audit evidence and immutable report snapshots are retained for up to 730 days by default, subject to the customer contract and configured retention policy.
  • Completed queue jobs are retained for 90 days and webhook events for 180 days by default.
  • Account and support data is removed or anonymized when no longer needed, unless an unresolved claim or legal duty requires retention.
  • Invoices and core financial administration are kept for the applicable Dutch statutory period, generally seven years.

6.Cookies and similar technologies

Necessary cookies support authentication, security, checkout, language and region preferences. Language preferences may remain for one year; short-lived security and funnel cookies use a shorter period. The analytics choice is stored for 180 days. Non-essential trackers load only after an explicit opt-in and can be disabled later with the Analytics settings button.

7.Your choices and rights

  • Request access, correction, deletion, restriction or a portable copy where the law provides these rights.
  • Object to processing based on legitimate interests and withdraw consent at any time without affecting earlier lawful processing.
  • Complain to the Dutch Data Protection Authority or another competent supervisory authority.
  • We may ask for proportionate identity verification before acting on a request.

8.Security and changes

We use tenant authorization, encrypted stored secrets, private report downloads, rate limiting, security headers, audit logging and controlled retention. No online service can promise zero risk. We update this statement when processing materially changes and show the revision date on this page.