Who we are
YourMarketingSuite (“YMS”, “we”, “us”, “our”) is a brand of Marketing Released B.V. (“MR”), Pauwenkamp 142, 3607GK, Maarssen, The Netherlands, registered at the Chamber of Commerce in The Netherlands under number 62865668.
This Privacy Policy explains what we do with personal data in connection with the YourMarketingSuite website at yourmarketingsuite.com and the marketing platform we provide to our customers (together, the “Service”).
We never sell personal data. We carry out all processing in compliance with the EU General Data Protection Regulation (“GDPR”).
The two roles we play
This is the most important thing to understand about how data works on this platform, because it changes who is responsible for what.
We are the controller for data about you: your visit to this website, your account, your billing details, and our correspondence with you. This policy governs that data.
We are a processor for the data you put into the platform about your own clients and their contacts. You decide what to collect, why, and for how long. You are the controller of that data, and you are responsible for having a lawful basis to hold it and to contact those people. We process it only on your documented instructions, which in practice means the actions you and your team take inside the platform.
If you are an end customer of one of our customers and you want your data corrected or deleted, contact the business you dealt with. They control that record, not us. We will help them action it.
What we collect
When you visit the website. Pages viewed, referring source, approximate location derived from IP address, device and browser type, language, screen size, session duration, and the identifiers set by the cookies you consent to. Our full cookie inventory is in the Cookie Policy.
When you start a subscription. Name, email address, billing address, country, company name, VAT or tax identifier where relevant, the plan you chose, and your payment and renewal history. Card details are collected and held by Stripe. We never see or store a full card number.
When you use the platform. Your login and session records, the sub-accounts you create, your configuration and settings, your support requests, and metered usage such as messages sent, calls placed and AI actions run. We need this usage record to bill you accurately and to enforce fair use.
Data you bring with you. Contacts, conversations, calendars, pipelines, files and anything else you or your clients load into a sub-account. We hold this on your behalf under the processor role described above.
Why we process it, and on what legal basis
- To provide the Service (performance of a contract): creating and running your account, delivering the platform, providing support, and keeping the thing online.
- To take payment and prevent fraud (contract, and legal obligation): processing subscriptions and usage charges, issuing invoices, meeting our accounting and tax obligations.
- To send service messages (contract): billing notices, security notices, changes to the Service and anything else you need to know as a customer. You cannot opt out of these while you hold an account, because they are part of the Service.
- To send marketing (consent, or legitimate interest where you are an existing customer): product news and offers. Every marketing email carries an unsubscribe link and we honour it.
- To understand and improve the Service (legitimate interest, and consent where cookies are involved): analytics, error monitoring and aggregate reporting.
- To protect the Service and defend our rights (legitimate interest): abuse detection, rate limiting, security investigations and legal claims.
Who else touches the data
We use a small number of providers to deliver the Service. Each is bound by a data processing agreement. This list changes as our stack changes, and this page is the current version.
- HighLevel, Inc. (LeadConnector) — the platform infrastructure the Service runs on, including the CRM, automation, messaging and calendar systems.
- Stripe, Inc. — payment processing, subscription billing and card storage.
- Twilio, Inc. — telephony and SMS delivery, where you use those features.
- Mailgun and equivalent providers — outbound email delivery, where you use those features.
- Cloudflare, Inc. — traffic routing, caching, DDoS protection and bot filtering.
- Analytics providers — aggregate web analytics on the marketing site, subject to your cookie consent.
- AI providers — where you use AI features, prompts and the content needed to answer them are processed by the relevant model provider under contract.
Third-party sites linked from the Service are not ours and are not covered by this policy.
Sending data outside the EEA
Several of the providers above are in the United States. Where personal data leaves the European Economic Area we rely on the transfer mechanisms the GDPR recognises: the EU-US Data Privacy Framework where the provider is certified, Standard Contractual Clauses otherwise, plus supplementary measures where a transfer risk assessment calls for them. Write to us if you want detail on a specific provider.
How long we keep it
- Account and platform data: for as long as your subscription is active.
- After you cancel: 30 days, so you can export or reactivate. After that the sub-accounts and their contents are deleted. Export anything you want to keep before the 30 days are up.
- Billing and tax records: 7 years, because Dutch law requires it.
- Marketing contact records: until you unsubscribe or ask us to erase them.
- Website analytics: in line with the retention set on each tool, listed in the Cookie Policy.
How we protect it
Access to production systems is restricted to the people who need it and protected by multi-factor authentication. Data is encrypted in transit. Sub-accounts are logically separated so one customer cannot reach another customer's records. We keep the number of providers small deliberately, because every extra vendor is another place data can leak from.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to people's rights, we will notify the Dutch Data Protection Authority within 72 hours and tell affected customers without undue delay.
Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, object to processing based on legitimate interest, or provide it in a portable format. You can withdraw consent at any time, which does not affect processing done before you withdrew it.
Email us and we will respond within one month. There is no charge unless a request is manifestly unfounded or excessive. If you are unhappy with our response you can complain to the Autoriteit Persoonsgegevens in the Netherlands or to the supervisory authority where you live.
Children
The Service is sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.
Changes to this policy
When we change this policy we update the date at the top. If a change materially affects your rights we will tell account holders by email before it takes effect.
How to reach us
For anything in this policy, including a rights request, email [email protected].
Controller
Marketing Released B.V. (YourMarketingSuite)
Pauwenkamp 142, 3607GK
Maarssen, The Netherlands
Chamber of Commerce: 62865668