Found by AI

Privacy Policy

Last updated: July 2026

Found by AI is operated by AlphaLux Marketing ApS (“Company”, “we”, “us”), a company registered in Copenhagen, Denmark. We are committed to protecting your personal data and your privacy in accordance with the EU General Data Protection Regulation (GDPR) and applicable Danish data protection legislation.

This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding your personal information.

1. Data Controller

AlphaLux Marketing ApS Copenhagen, Denmark Email: [email protected]

2. Scope: When We Are Controller and When We Are Processor

We supply our programme to agency partners, who resell it to their own clients. This affects our role under the GDPR:

  • We are the data controller for personal data relating to visitors to this website, to people who contact us, and to the business contacts at our partners. This policy describes that processing.
  • We are a data processor for personal data that a partner or their client places into the platform in the course of the programme. In that case the partner is the controller, our processing is governed by the data processing agreement in their partner agreement, and their own privacy notice applies. If you are a client of one of our partners, please direct data requests to that partner in the first instance; we will assist them in responding.

3. Data We Collect

As controller, we collect the following categories of personal data:

  • Contact and account information: Name, email address, phone number (optional), company name, role, and business URL when you contact us, submit a form, or are given access to the platform under a partner agreement.
  • Usage data: Pages visited, features used, time spent on pages, and interaction patterns to help us improve the Service.
  • Technical data: IP address, browser type, device type, operating system, and referral source, collected automatically through standard web technologies.
  • Partner billing data: Business billing address, VAT/company registration number, contact details for accounts payable, and payment references, used to invoice partners and record payment. We invoice partners directly; we do not operate a card checkout on this website and do not collect or store payment card details.
  • Communications: Records of correspondence when you contact us via email, forms, or other channels.

We process your personal data for the following purposes:

  • To provide the programme (legal basis: performance of contract) — including running AI-answer monitoring, producing and publishing content, delivering reporting, and administering partner and client access to the platform.
  • To communicate with you (legal basis: legitimate interest / consent) — including responding to inquiries, sending service updates, and providing relevant information about the programme.
  • To improve our Service (legal basis: legitimate interest) — including analyzing usage patterns, conducting research, and developing new features.
  • To invoice and collect payment (legal basis: performance of contract) — including issuing invoices to partners, managing accounts receivable, and preventing fraud.
  • To comply with legal obligations (legal basis: legal obligation) — including bookkeeping and tax reporting, regulatory compliance, and responding to lawful requests.

5. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account data: Retained for the duration of the account and up to 12 months after deletion, to allow for reactivation.
  • Usage data: Retained in anonymized form for up to 24 months for analytics purposes.
  • Accounting and invoicing records: Retained for 5 years as required by Danish accounting legislation.
  • Marketing data: Retained until you withdraw consent or unsubscribe.

Data we process on behalf of a partner is retained for the period set out in that partner’s data processing agreement, and is deleted or returned on termination in accordance with it.

6. Your Rights

Under the GDPR, you have the following rights:

  • Right of Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request correction of inaccurate or incomplete data.
  • Right to Erasure: You can request deletion of your personal data where there is no compelling reason for continued processing.
  • Right to Restrict Processing: You can request that we limit how we use your data.
  • Right to Data Portability: You can request your data in a structured, commonly used, machine-readable format.
  • Right to Object: You can object to processing based on legitimate interests, including direct marketing.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. Where we act as processor for a partner, we will forward your request to that partner and support them in answering it.

You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) at datatilsynet.dk.

7. Cookies

We use cookies and similar technologies for the following purposes:

  • Essential cookies: Required for the Service to function properly (e.g., session management, authentication, and the anti-abuse check on our forms). These do not require consent.
  • Analytics cookies: Used to understand how visitors interact with this website. We use Google Analytics for this, which sets cookies and similar identifiers in your browser.

You can manage or block cookies at any time through your browser settings, and you can opt out of Google Analytics using the browser add-on Google provides for that purpose.

8. Sub-Processors and Third-Party Services

Running this website and the programme requires a small number of external providers. Each is engaged to perform a specific function for us, and each sees only the data that function requires. The providers we use are:

Infrastructure and storage

  • Hetzner (Germany) — server hosting and the infrastructure the platform runs on. Data held in the platform resides on these servers.
  • Cloudflare — delivery of this website (CDN), object storage for uploaded assets — which includes editor profile photographs — and the certificates that serve partner and client custom domains. Cloudflare also provides the anti-abuse check on our forms, which inspects technical data such as IP address.
  • GitHub — storage of the published article files. Those files carry author and editor bylines, so they contain the personal data of the named author or editor.
  • Supabase / GoTrue — authentication and account identity: the credentials, email addresses and identifiers behind partner and client logins.

Communications

  • Resend — delivery of transactional email, including account invitations, service notifications and report emails. Resend processes the recipient’s name and email address.

Analytics

  • Google Analytics — measurement of how visitors use this website, using cookies and similar identifiers. It processes technical and usage data, including IP address and browsing behaviour on this site. See section 7 on cookies.

AI model providers

  • OpenAI, Google, Anthropic and Perplexity — used in two ways: to generate and evaluate content for the programme, and to put buying questions to AI assistants so that we can observe how those assistants answer. What we send is brand, product and market information together with the drafts being worked on; a draft may carry the byline of the author or editor assigned to it.

Other categories

We also use providers for statutory bookkeeping and invoicing, and we may engage professional advisers such as accountants or lawyers, who are bound by professional confidentiality.

We do not sell your personal data to third parties. Where a provider processes personal data on our behalf, we engage them as a sub-processor for that defined purpose only. Data transfers outside the EU/EEA are only made with appropriate safeguards in place, such as Standard Contractual Clauses. The list above is accurate as at the “Last updated” date; a current list of our sub-processors, including any subsequent additions or changes, is available to partners on request.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit (TLS/SSL), encryption at rest, access controls, regular security reviews, and employee training.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a prominent notice on the Service. The “Last updated” date at the top reflects the most recent revision.

11. Contact

For any questions or concerns about this Privacy Policy or our data practices, contact us at:

AlphaLux Marketing ApS Copenhagen, Denmark Email: [email protected]