Privacy Policy
Last updated: August 2026
1. Data controller
Distilo is operated from the Netherlands. Whichever domain you reach us on, the controller of your personal data is the Dutch entity below, and the GDPR applies.
| Company name | Leonardo Christino |
| Chamber of Commerce (KvK) | 89650166 |
| VAT ID | NL004750027B58 |
| Contact | contact@distilo.nl |
| Data protection contact | privacy@distilo.nl |
2. What personal data we collect
2.1 Contact form (/contact)
- Name, email address, company name, size (number of customers)
- Areas of interest (churn, overdue payments, revenue, channel, losses, segmentation)
- Optional message
Legal basis: performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR).
2.2 Newsletter
- Email address
Legal basis: consent (Art. 6(1)(a) GDPR). You can unsubscribe at any time.
2.3 Technical data
- PARAGLIDE_LOCALE cookie: stores your language preference. Duration: 400 days. Strictly necessary for the site to work.
- PostHog (product analytics in your browser): usage events, identification of logged-in users, and session recording on specific screens (creating an analysis and viewing a report). Enabled only with your consent (see the cookie banner); until then we set no cookies and record nothing about how you browse the site. Hosted in the European Union (Frankfurt). You can change your choice at any time using the control at the top of this page.
- Service records (our servers, not your browser): when an analysis runs, our systems record which account it belongs to, that it ran, how long it took, whether it succeeded, and the error if it did not. Payment events from our payment provider are recorded the same way, as are the safety checks that run around each analysis. These records identify your account by an internal identifier, never by name or email address, and nothing is stored on your device. We keep them because we cannot deliver an analysis, repair a failed one or refund it without knowing whose it was.
Legal basis: consent (Art. 6(1)(a) GDPR, and Art. 11.7a of the Dutch Telecommunications Act for storing information on your device) for product analytics and session recording in your browser. Performance of our contract with you (Art. 6(1)(b) GDPR) for the records of the analyses you asked us to run, their failures, and the payments behind them. Legitimate interest (Art. 6(1)(f) GDPR) for strictly necessary cookies and for the safety and quality checks around each analysis, where our interest is in keeping the service secure and working; you may object to that last part at any time using the same control at the top of this page, and we act on it without asking why. Our assessment of that balance is written down and available on request.
2.4 Data we do NOT collect
- We use no advertising cookies and no cross-site tracking
- We use no Google Analytics, Facebook Pixel or ad networks
- We do not collect payment card data (payments are handled by our payment provider, which we never see card details from)
3. Purposes of processing
- Responding to contact requests and commercial proposals
- Sending communication about our services (newsletter, with consent)
- Improving the performance and user experience of the website
- Running the analyses you ask for, and detecting and repairing the ones that fail
- Complying with legal obligations
4. Sharing of data
Your data may be shared with:
| Third party | Purpose | Location | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Website, application and database hosting (the Convex backend runs self-hosted on this infrastructure) | Germany (European Union) | Processor within the EU; DPA |
| PostHog | Product analytics and session recording in your browser (only with consent); records of your analyses, their failures and the safety checks around them, sent from our servers | European Union (Frankfurt) | DPA; data stays within the EU, no transfer outside the EEA |
| Anthropic PBC | The language model that writes your analysis. It processes the business data you provide; where a Shopify store is connected, customer identifiers are pseudonymised before they leave the store and no name, email address, phone number or postal address is ever sent | United States | Processor; Anthropic's data processing agreement, incorporating Module Two and Module Three Standard Contractual Clauses. Anthropic does not use content submitted through its commercial API to train its models |
| OpenAI, L.L.C. | Alternative language model for the same job, selected per analysis. Same data, same pseudonymisation | United States | Processor; OpenAI's data processing addendum, incorporating Standard Contractual Clauses. OpenAI does not use content submitted through its API to train its models |
| Google Cloud (Vertex AI) | Alternative language model for the same job, selected per analysis. Same data, same pseudonymisation | United States | Processor; Google Cloud Data Processing Addendum, incorporating Standard Contractual Clauses. Google does not use customer content to train its models |
| Stripe Payments Europe, Ltd (Ireland) | Payment processing and subscription billing. We never receive card details. | Ireland, with processing in the United States | Independent controller for payment data; EU-US Data Privacy Framework + Standard Contractual Clauses |
| AhaSend B.V. (Netherlands, KvK 99533111) | Transactional email: sign-up confirmation, password reset, report-ready notices | European Economic Area | Processor within the EEA; DPA with Module Two SCCs |
| Cloudflare, Inc. | Authoritative DNS and forwarding of mail sent to our @distilo addresses | United States, global edge | EU-US Data Privacy Framework, with Standard Contractual Clauses as fallback |
We do not sell, rent or trade your personal data.
5. Transfers outside the EEA
Website and application data, including contact form and newsletter data, is stored on servers in Germany (Hetzner Online GmbH); product analytics is hosted in the European Union (Frankfurt) and transactional email is handled within the EEA (AhaSend B.V., Netherlands). None of the platform data leaves the EEA.
Three functions do involve the United States. Payment processing (Stripe) and our DNS plus inbound mail forwarding (Cloudflare) are both certified under the EU-US Data Privacy Framework (European Commission adequacy decision, July 2023, Art. 45 GDPR), with Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a fallback.
The third is the language model that writes your analysis. The business data in your uploaded files is processed in the United States by the model provider listed in the table above. That transfer rests on Standard Contractual Clauses (Art. 46(2)(c) GDPR) in that provider's data processing agreement. The provider does not use your content to train its models.
The table above names every model provider we may route an analysis to, including ones we do not use today. We put a data processing agreement in place with a provider before sending it any customer data, and we update this page before adding a provider that is not already listed.
6. Retention periods
| Data | Retention |
|---|---|
| Contact form data | For as long as the commercial relationship lasts, or until you ask for deletion |
| Newsletter email | Until you unsubscribe or ask for deletion |
| Necessary cookies | PARAGLIDE_LOCALE: 400 days |
| Uploaded spreadsheets | Until you delete the file, the analysis or the account. Nothing expires on its own. |
| Analyses and generated reports | Until you delete the analysis or the account. |
| Service records (that an analysis ran, what it cost, whether it succeeded) | Deleted together with the analysis or the account. |
| Record that the account was deleted | Kept, identified by an internal id only, never by name or email. |
7. Your rights (Art. 15-22 GDPR)
You have the following rights:
- Right of access (Art. 15): ask which data we process about you
- Right to rectification (Art. 16): have inaccurate or incomplete data corrected
- Right to erasure (Art. 17): request deletion of your personal data
- Right to restriction (Art. 18): have the processing of your data restricted
- Right to data portability (Art. 20): receive your data in a structured format
- Right to object (Art. 21): object to processing based on legitimate interest
- Rights regarding automated decision-making (Art. 22): not be subject to automated decisions
- Right to withdraw consent (Art. 7(3)): at any time, without affecting the lawfulness of processing before withdrawal
To exercise your rights, email privacy@distilo.nl. We respond within 1 month (Art. 12(3) GDPR).
If your rights are not respected, you can lodge a complaint with the Dutch data protection authority (Autoriteit Persoonsgegevens) via autoriteitpersoonsgegevens.nl.
8. Security
We take appropriate technical and organisational measures to protect your data, including: encryption in transit (HTTPS/TLS), restricted access control, and security monitoring by our infrastructure providers.
9. Changes
This privacy policy may be updated from time to time. The date of the last change is always shown at the top of this page. We recommend reviewing this page periodically.
10. Contact
For questions about this privacy policy or the processing of your data:
Privacy: privacy@distilo.nl
General: contact@distilo.nl