Legal

GDPR and UK GDPR

Effective date: 22 August 2026

This page explains how Insyt, operated by Galco FZ-LLC, United Arab Emirates, meets its obligations under the EU General Data Protection Regulation (GDPR) and the UK GDPR for users in the European Economic Area and the United Kingdom. It supplements our Privacy Policy.

Our roles: controller and processor

We act in two distinct roles, and it matters which one applies.

Insyt as controller. For your Insyt account data (your name, email, login details, billing information, support correspondence, and usage of our own service), we decide how and why the data is processed. For this data, Insyt is the data controller.

Insyt as processor. For the advertising and analytics data we access from your connected Google Ads, Google Analytics and Google Tag Manager accounts, you (or your client) are the controller and we process that data only on your instructions: to run audits, generate recommendations, and apply the fixes you approve. We do not use this data for our own purposes.

Lawful bases

As a controller, we process personal data on these bases: contract (Article 6(1)(b)) to provide the service, manage your account and process billing; legitimate interests (Article 6(1)(f)) to secure the service, prevent fraud and abuse, and improve our product; consent (Article 6(1)(a)) for connecting Google accounts, non-essential cookies, and marketing email; and legal obligation (Article 6(1)(c)) for tax and accounting records. As a processor, we act on your documented instructions under our data processing terms.

Your rights and how to exercise them

If you are in the EU or UK, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (the right to be forgotten).
  • Restrict processing in certain circumstances.
  • Data portability: receive your data in a structured, commonly used, machine-readable format.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent at any time, without affecting processing before withdrawal.
  • Not be subject to solely automated decisions with legal or similarly significant effects. Insyt's AI generates recommendations, but no change is applied to your accounts without your human approval.

To exercise any right, email hello@tryinsyt.com with the subject "Data request". We will verify your identity, respond within one month, and complete export or deletion requests within 30 days. There is no fee for reasonable requests. If your request concerns data we process on behalf of an agency or other business (where they are the controller), we will refer the request to them and assist them in responding.

You also have the right to lodge a complaint with your local supervisory authority, such as the ICO in the UK or your national data protection authority in the EU. We would appreciate the chance to resolve your concern first at hello@tryinsyt.com.

Data Processing Agreement (DPA)

We offer a Data Processing Agreement incorporating the requirements of Article 28 GDPR to all business customers, including agencies processing client data through Insyt. The DPA covers our obligations as your processor: processing only on instructions, confidentiality, security measures, subprocessor management, assistance with data subject requests, breach notification, and deletion or return of data at the end of the engagement. To receive and execute our DPA, email hello@tryinsyt.com.

Subprocessors

We use the following subprocessors to deliver the service:

  • Supabase: database and authentication hosting (United States / EU).
  • Railway: application hosting (United States).
  • Stripe: payment processing (United States / global).
  • Resend: transactional email (United States).
  • Google: access to your connected Google Ads, Analytics and Tag Manager accounts (United States / global).
  • Anthropic: AI analysis of advertising data to generate audit results (United States).

Each subprocessor is bound by a data processing agreement with obligations equivalent to those we owe you. We will notify DPA customers before adding or replacing a subprocessor and give you the opportunity to object.

International transfers

Insyt operates from the United Arab Emirates, and our subprocessors are primarily in the United States. Where personal data of EU or UK users is transferred to us or our subprocessors, we rely on the European Commission's Standard Contractual Clauses (2021), supplemented for UK data by the UK International Data Transfer Addendum. We also apply supplementary measures, including encryption in transit and at rest and strict access controls, and we assess each transfer for risks under local law.

Security measures

We implement appropriate technical and organizational measures under Article 32, including TLS encryption in transit, encryption at rest, encrypted storage of Google access credentials, role-based access controls, least-privilege access for staff, logging and monitoring, and vendor due diligence. Details of our current measures are available in our DPA.

Breach notification

If we become aware of a personal data breach affecting data we control, we will notify the competent supervisory authority within 72 hours where required, and affected individuals without undue delay when the breach is likely to result in a high risk to them. Where we act as your processor, we will notify you without undue delay after becoming aware of a breach affecting your data, with the information you need to meet your own notification obligations.

Data retention and deletion

We keep personal data only as long as needed for the purposes described in our Privacy Policy. Google user data is deleted within 30 days of disconnecting an account or deleting your Insyt account. Billing records are retained as required by UAE law. See our Your Data page for the practical steps.

EU and UK representatives

Because we serve users in the EU and UK from outside those regions, we are subject to the GDPR's provisions on representatives (Article 27). Contact hello@tryinsyt.com for the current contact details of our EU and UK representatives.

Contact

For any GDPR question or request: hello@tryinsyt.com. Galco FZ-LLC, Dubai, United Arab Emirates.