1. Data Controller
Marketing Research Systems S.R.L. (“KEIX”, “we”, “us”), Via Antonio Santangelo Fulci 14/a, 95127 Catania (CT), Italy. VAT / P. IVA 04616530871.
Contact email for any privacy matter, including data deletion requests: admin@keix.com.
Data Protection Officer: dpo@keix.com.
2. What this policy covers
This policy applies to two distinct services operated by Marketing Research Systems S.R.L.:
- The public website www.keix.com — marketing pages, the blog, contact and newsletter forms.
- The KEIX platform at app.keix.com — the authenticated application in which registered users connect data sources, build analyses and dashboards, and configure automated actions. This is the application that requests access to your Google Account.
3. Types of data we collect
Depending on which service you use, KEIX collects the following categories of personal data:
3.1 Account data
- Identity and contact data: name, email address, profile picture, company name and role.
- Authentication data: password hash, or the identifier of the third-party account you sign in with (for example your Google Account).
- Billing data: billing address, VAT number and subscription details. Card details are handled by our payment provider and never reach KEIX servers.
3.2 Data you connect to the platform
The KEIX platform is a data platform: its purpose is to let you bring your own business data into a workspace, analyse it and act on it. That data — including any personal data it contains — is processed by KEIX on your behalf and under your instructions. You remain the controller of the data you upload or connect; KEIX acts as processor.
This includes data retrieved from third-party services you choose to connect, such as Google Drive, Google Sheets, Google Calendar, Gmail, Google Business Profile and Google Ads. Section 5 describes that access in detail.
3.3 Usage data
- Technical data: IP address, browser type and version, device and operating system, language settings.
- Interaction data: pages visited, features used, session statistics, timestamps and error logs.
- Trackers and cookies, as described in our Cookie Policy and controlled by your consent preferences.
4. Why we process your data
- To create and administer your account and to authenticate you.
- To provide the platform's features — connecting data sources, running analyses, rendering dashboards and executing the automated actions you configure.
- To bill you and to comply with tax and accounting obligations.
- To provide support, and to send service communications about your account or material changes to the service.
- To keep the service secure: detecting and investigating abuse, fraud and unauthorised access.
- To measure and improve the website, using analytics, where you have consented.
- To send marketing communications, only where you have subscribed; you can unsubscribe at any time.
5. Google user data
This section explains, specifically and exhaustively, how the KEIX platform accesses, uses, stores and shares data obtained through Google APIs. It applies whenever you connect a Google Account to KEIX.
Every Google connection is optional and user-initiated. KEIX never accesses your Google Account unless you have explicitly connected it and granted consent on Google's consent screen, and you can revoke that consent at any time (see 5.5).
5.1 Which Google data KEIX requests, and why each scope is needed
KEIX requests the following OAuth scopes. They are grouped exactly as Google classifies them.
Non-sensitive scopes
- openid, .../auth/userinfo.email, .../auth/userinfo.profile — used solely to let you create a KEIX account and sign in with Google. We store your Google email address, name and profile picture in order to identify your account, display it in the interface and send service communications. This data is never used for advertising.
- .../auth/business.manage — lets KEIX read the listings, reviews and performance insights of the Google Business Profile locations you authorise, so that they can be used as a data source in your workspace, and publish updates or reply to reviews on those locations when you have explicitly configured an action that does so. KEIX never posts to your Business Profile on its own initiative.
Sensitive scopes
- .../auth/calendar — reads events from the calendars you select, so that scheduling and activity data can feed your analyses and dashboards; creates or updates events only when you configure an automated action that does so. It is used for no other purpose.
- .../auth/spreadsheets — reads the Google Sheets you select as a data source, and writes results, exports and refreshed tables back to the specific sheets you designate as an output.
- .../auth/adwords — reads campaign, cost and performance data from the Google Ads accounts you authorise, so that marketing performance can be combined with your other business data in dashboards and reports. Changes are written to Google Ads only when you explicitly configure an action to do so.
- .../auth/gmail.send — sends email on your behalf, from your own address, for messages you have configured: survey and questionnaire invitations, scheduled reports and alerts triggered by your workflows. KEIX never sends email from your account for its own purposes, and never emails your contacts other than as part of a send you have set up.
Restricted scopes
The two scopes below are classified by Google as restricted. KEIX applies the Limited Use requirements to them in full (see 5.6).
- .../auth/drive — used to read the files you select in Google Drive (spreadsheets, CSV files, documents) so they can be used as data sources in your workspace, and to write exports and generated reports back to the folders you choose as an output destination. Although the scope granted by Google covers your Drive, KEIX reads and writes only the files and folders you have explicitly selected inside the platform; it does not enumerate, index or process the rest of your Drive.
- .../auth/gmail.readonly — used to read the messages and settings of the mailbox you connect, so that business information contained in email — such as orders, confirmations, invoices and supplier communications — can be extracted into structured data in your workspace. KEIX processes only the messages that match the filters and criteria you configure, and does not read the rest of your mailbox.
5.2 How we use Google user data
- Google user data is used exclusively to provide and improve the specific features you have explicitly configured in your KEIX workspace.
- We do not sell, rent or trade Google user data.
- We do not use Google user data for advertising, ad targeting or audience building of any kind.
- No KEIX personnel reads your Google user data, except: with your explicit prior consent (for example when you ask for support on a specific connection); where strictly necessary for security purposes, such as investigating abuse or a suspected breach; where required to comply with applicable law; or where the data has been aggregated and anonymised and is used for internal operations.
5.3 How we store and protect Google user data
- Data you send from your browser to our systems is transmitted over an encrypted connection (TLS 1.2 or higher); traffic between our own internal systems is not currently encrypted in transit.
- Data is encrypted in transit (TLS) and stored on infrastructure located in the European Union; volume-level encryption at rest is planned.
- OAuth access and refresh tokens are stored on our infrastructure, are never exposed to the browser and are never written to application logs.
- Access to production systems is restricted to a limited number of authorised personnel bound by confidentiality obligations, and is logged.
- Our production infrastructure and data storage are located in the European Union.
5.4 How we share Google user data
We do not sell Google user data and we do not transfer it to any other application. It is disclosed only in the following cases:
- To sub-processors strictly necessary to operate the service — cloud hosting and infrastructure providers — bound by written data processing agreements and prohibited from using the data for their own purposes.
- Where we are legally required to do so by a valid order of a competent authority.
- To a third party you have explicitly instructed us to send it to, through a feature you configured.
5.5 Retention, revoking access and deletion
- Google user data is retained only for as long as the corresponding connection is active and the data is needed to provide the features you use.
- You can disconnect any Google connection at any time from within KEIX, in Settings → Connections. Disconnecting revokes the token and deletes the data cached from that connection within 30 days.
- You can also revoke KEIX's access directly from your Google Account at https://myaccount.google.com/permissions. Access stops immediately; cached data is deleted within 30 days.
- If you delete your KEIX account, all Google user data associated with it is deleted within 30 days, except where a longer retention period is imposed by law.
- You can request deletion of your data at any time by writing to admin@keix.com. We respond within 30 days.
5.6 Limited Use disclosure
KEIX's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can read that policy at https://developers.google.com/terms/api-services-user-data-policy
6. Legal basis for processing
- Performance of a contract — for account creation, provision of the platform and billing.
- Consent — for analytics and marketing cookies, newsletter subscriptions, and for each Google connection you authorise. Consent can be withdrawn at any time.
- Legitimate interest — for service security, abuse prevention and the defence of our legal rights.
- Legal obligation — for accounting, tax and other statutory record-keeping.
7. Mode and place of processing
7.1 Methods of processing
We take appropriate technical and organisational security measures to prevent unauthorised access, disclosure, modification or destruction of data. Processing is carried out using computers and IT tools, following organisational procedures strictly related to the purposes indicated in this policy.
7.2 Place
Production compute and databases are in the European Union (Germany and Finland, Hetzner). Some of the providers listed in section 8 are established outside the EU; those transfers rely on the EU-U.S. Data Privacy Framework where the provider is certified, and on Standard Contractual Clauses otherwise. See section 8 for the place of processing of each provider.
7.3 Retention
Unless stated otherwise in this document, personal data is processed and stored for as long as required by the purpose it was collected for, and may be retained longer where an applicable legal obligation requires it. In particular: data from contact and demo-request forms is kept for 24 months; newsletter subscriber data is kept until you unsubscribe, and a subscription pending confirmation is deleted after 7 days if not confirmed; blog administrator accounts are kept until the account is removed; data you connect to the platform is retained for as long as you instruct, since KEIX acts as processor for that data (see section 3.2). Retention of Google user data is covered specifically in section 5.5.
8. Third-party services
Cloudflare
Edge network, hosting (Cloudflare Pages) and object storage (Cloudflare R2), provided by Cloudflare, Inc. Cloudflare filters all traffic to this website and to the platform; R2 stores workflow result artifacts and database backups, which may contain personal data. Personal data processed: trackers, IP address, usage data, and any personal data contained in stored artifacts and backups. Place of processing: Cloudflare's default jurisdiction (not EU-committed); edge processing is global. Transfers rely on Cloudflare's Data Processing Addendum and Standard Contractual Clauses.
Google Analytics 4
Google Analytics 4 runs only after you enable the 'measurement' category in the cookie banner (Consent Mode v2; IP addresses are anonymised). Personal data processed: usage data, number of users, session statistics, trackers. Place of processing: United States.
Google APIs
Google Drive, Google Sheets, Google Calendar, Gmail, Google Business Profile and Google Ads, provided by Google LLC, are accessed by the platform on your behalf when you connect them. This access is governed in full by section 5 of this policy.
Postmark
Transactional email delivery — account verification, password reset and other service emails — provided by Postmark (ActiveCampaign / Wildbit). Personal data processed: recipient email address, message content. Place of processing: United States, under a Data Processing Addendum and Standard Contractual Clauses.
Resend
Site emails — password-reset messages for the platform and newsletter subscription confirmation — provided by Resend. Personal data processed: recipient email address, message content. Place of processing: United States, under a Data Processing Addendum and Standard Contractual Clauses.
Stripe
Payment processing for platform subscriptions and for purchases made directly on this website, provided by Stripe. Personal data processed: payment and billing details, name, email address. Place of processing: European Union and United States, under Stripe's standard Data Processing Agreement.
Hetzner
Hosting and compute for our production infrastructure, provided by Hetzner Online GmbH. All platform data is processed and stored on this infrastructure. Place of processing: Germany and Finland (European Union).
Zitadel
Identity and authentication, self-hosted by us on our own infrastructure. Personal data processed: login identity, session and permission data. Place of processing: Germany and Finland (European Union), on the Hetzner infrastructure listed above.
Anthropic
Some AI features of the platform (for example document analysis and AI-assisted actions) send the relevant content to Claude, provided by Anthropic. Personal data processed: any personal data contained in the content you submit to that AI feature. Place of processing: United States, under a Data Processing Addendum and Standard Contractual Clauses.
Google Gemini
Some AI features of the platform send the relevant content to Gemini, provided by Google LLC. Personal data processed: any personal data contained in the content you submit to that AI feature. Place of processing: United States, under a Data Processing Addendum and Standard Contractual Clauses.
Fathom
Call transcripts and AI-generated summaries, provided by Fathom and connected to the platform only when you choose to do so. Personal data processed: call recordings, transcripts and participant names. Place of processing: United States.
Mapbox
Map tiles rendered in the platform interface, provided by Mapbox. Personal data processed: location coordinates displayed on the map; typically no other personal data. Place of processing: United States.
Brave Search
Web search used by the platform's AI assistant when you ask it to find a dataset, provided by Brave. Personal data processed: the text of your search query, which may contain personal data you typed. Place of processing: United States.
mailinput.com
Real-time email address verification on certain platform forms, provided by mailinput.com. Personal data processed: the email address you are typing, sent to this service as you type. Place of processing: not yet confirmed by the provider.
BulkGate
SMS delivery, provided by BulkGate. Personal data processed: recipient phone number, message content. Place of processing: Czech Republic (European Union).
Meta / Telegram
Messaging integrations — WhatsApp Business API, Facebook, Instagram and Telegram — that you connect to the platform at your own instruction, provided by Meta Platforms, Inc. and by Telegram. Personal data processed: message content and contact identifiers you route through the channel you connect. Place of processing: depends on the provider; governed by your own connection to each service and its own terms.
9. Your rights
Under the GDPR, and to the extent permitted by law, you have the right to:
- Access your personal data and obtain a copy of it.
- Rectify inaccurate or incomplete data.
- Erase your data (“right to be forgotten”).
- Restrict processing of your data.
- Object to processing carried out on the basis of legitimate interest.
- Data portability — receive your data in a structured, machine-readable format and have it transmitted to another controller.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali.
10. How to exercise your rights
Send your request to admin@keix.com. Requests are free of charge and are answered as soon as possible, and in any case within one month of receipt.
11. Deleting your data
You can delete your data in three ways, depending on what you want removed:
- Disconnect a single data source — in the platform, under Settings → Connections. Data cached from that source is deleted within 30 days.
- Delete your account — in the platform, under Settings → Account. All personal data and all data obtained through connected services is deleted within 30 days, except where a longer retention period is imposed by law.
- Ask us — write to admin@keix.com and we will carry out the deletion and confirm it to you within 30 days.
12. Children
KEIX is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We may update this privacy policy at any time by publishing the new version on this page and updating the date at the top. Where changes affect processing carried out on the basis of your consent, we will collect fresh consent where required. We encourage you to review this page periodically.
Data Controller
Marketing Research Systems S.R.L.
Via Antonio Santangelo Fulci 14/a, 95127 Catania (CT), Italy
Email: admin@keix.com
P. IVA: 04616530871