Skip to content

Privacy

These policies explain how Noomera GmbH operates the maitiq website and service. Questions can be sent to contact@maitiq.com.

Last updated: 24 August 2026

Your analytics state

Stored choice
No stored choice — regional default
Region classification
EEA / conservative default

Controller and scope

Noomera GmbH, Switzerland, is controller for maitiq's website, lead handling, accounts, billing, and its own security records. Contact: contact@maitiq.com. For Google Ads data processed to deliver the service, the client is controller and Noomera GmbH is processor under the service agreement and data-processing terms. This notice covers the public website and product.

Website contact requests

The contact form sends the work email, spend band, locale, and any optional name, company, or job-title details to contact@maitiq.com through a Zoho Mail account provisioned in the EU data centre and sends a localized confirmation to the requester through the same service. The application database stores only a SHA-256 email hash, an HMAC network hash, the spend band, locale, delivery state, and non-identifying enrichment flags; it does not store the raw email, name, company, or job title.

Technical logs and funnel measurement

Web servers process IP address, request time, path, user agent, response status, and security events to operate and protect the service. The contact funnel records deduplicated HMAC identifiers and event names without storing a raw browser identifier. On the public website, Google Tag Manager container GTM-5QZM7LW4 and Google Analytics 4 property G-8CQSVRG6XK load in advanced Consent Mode. Analytics storage defaults to denied in EEA countries; until a visitor allows it, Google receives cookieless measurements and does not receive an analytics cookie identifier. Analytics storage defaults to granted in Switzerland and other non-EEA countries, with a quiet notice and one-click opt-out. GA4 receives public page paths, locale, pricing views, free-audit CTA clicks, contact-funnel step names, classified form errors, contact outcomes, and bounded first-touch campaign tokens. The same container and property load in the authenticated B2B workspace without a blocking banner to measure route patterns, hashed control identities, bounded first-touch campaign tokens, and the pseudonymous local-user UUID. An administrator can resolve that UUID inside maitiq; Google never receives the username or email. Workspace events never contain account names, Google customer or account IDs, keyword text, proposal content, or email addresses. Google may also process standard connection and browser metadata, including IP address and device information, under its applicable analytics terms. Advertising storage, advertising user data, and ad personalization remain denied everywhere. The public-site choice is stored in the browser and can be changed from the footer or privacy page.

Product data and roles

Product data can include user and account identifiers, encrypted Google OAuth refresh tokens, Google Ads account structure and performance data, uploaded native reports, workflow evidence, proposals, decisions, applied-action audit records, generated reports, support messages, and operational logs. Google Ads remains the client's own Google service. Noomera processes this data only to provide, secure, support, and document the contracted service.

Purposes and legal grounds

Processing supports requested contact and audit steps, contract setup and performance, account connection, configured workflows, evidence-backed proposals, human decisions, separately authorized implementation, reporting, support, fraud prevention, security, and legal compliance. Under the GDPR where it applies, the grounds are steps requested before or under a contract, legitimate interests in operating and securing the service, consent where specifically requested, and legal obligations.

Service providers and international transfers

Core production hosting and processing are in Switzerland. Zoho Mail handles early-lead email in its EU data centre and may use approved support or subprocessors under contractual safeguards. Google processes data in the client's own Google Ads service. A configured AI inference provider may process anonymised account-derived signals outside Switzerland; no personal or customer-identifying data is sent for inference. Where a destination lacks an adequate protection level, contractual clauses and supplementary safeguards are used.

AI-assisted processing

Parts of the public site's content were produced with AI assistance. New collection articles are editorially reviewed with AI assistance. Product wording or advisory analysis that used AI is labelled where displayed. AI output is decision support: it cannot approve a proposal, set deterministic controls, or remove the human decision and separate authorization required before a Google Ads change.

Sharing, transfer, and disclosure of Google user data

maitiq does not sell Google user data, does not share it for advertising purposes, and does not transfer it to data brokers or independent third parties. Google user data obtained through Google APIs or a connected Google Ads account is disclosed only to: authorized users of the client’s own workspace; Noomera GmbH personnel bound by confidentiality on a need-to-know basis; and the infrastructure provider hosting our systems in Switzerland, acting as a processor under contract. Anonymised, aggregated signals derived from account data — containing no personal data and no customer-identifying information — may be processed by a configured AI inference provider; Google user data itself is never provided to AI providers. Disclosure to authorities occurs only where the law requires it. maitiq’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect sensitive and Google user data

Sensitive data, including Google user data and OAuth credentials, is protected by specific technical and organisational mechanisms: all transport is encrypted using TLS; Google OAuth refresh tokens are encrypted at rest with a dedicated application encryption key; contact identifiers are stored as cryptographic hashes rather than raw values; production systems run in Swiss data centres with role-based, least-privilege access restricted to authorized personnel; every change to a connected account follows the audited proposal, decision, and applied-action path; and backups are access-controlled. Clients can revoke access at any time by disconnecting Google Ads, which invalidates the stored token; associated Google user data is then deleted in line with the retention section. Suspected incidents are assessed and notified as required by applicable law.

Retention

Raw lead emails and related mailbox correspondence are retained for up to 24 months unless they become part of a customer record or must be kept for a legal claim. Hashed contact and funnel records are retained for up to 24 months. Routine web logs are retained for up to 90 days. Uploaded evidence and generated reports are deleted within 90 days after the engagement ends unless the client requests earlier deletion or a contract requires longer. Workspace records, proposals, decisions, audit records, and security evidence are retained during the engagement and for up to 12 months afterward; records required by Swiss accounting or other law are kept for the applicable statutory period.

Security and access

Access is role-based and limited to authorized people. Secrets and OAuth refresh tokens are encrypted at rest; transport is encrypted; changes follow the proposal, decision, and applied-action audit path. Clients can disconnect Google Ads access, and Noomera reviews subprocessors and security measures appropriate to the risk. No internet service is risk-free, and incidents are assessed and notified as required by applicable law.

Your rights

You may ask whether personal data about you is processed and request access, correction, deletion, restriction, objection, or portability where applicable. You may withdraw consent without affecting earlier lawful processing and complain to the Swiss FDPIC or, where the GDPR applies, your competent EU/EEA authority. Requests go to contact@maitiq.com. Identity may be verified, and legal retention duties or overriding claims can limit deletion.

Contact and changes

Privacy questions and rights requests go to Noomera GmbH at contact@maitiq.com. Material changes to processing, recipients, destinations, analytics, or retention will be reflected here before they take effect where advance notice is required. Client-specific processing instructions, subprocessors, deletion, and audit support are governed by the service agreement and data-processing terms.

Get a free audit of your account.

We run a free, read-only audit on your own evidence. You receive the gaps we can support, the proposed actions, and the evidence behind them. Nothing will be changed.

  • Your own connected or uploaded evidence
  • Visible workflow coverage
  • Plain-language rationale
  • No Google Ads changes during the audit