Did you really read it?

Terms & conditions

Terms & conditions | Causality Engine

Privacy Policy

Causality Engine B.V.
Last Updated: November 6, 2025
Effective Date: November 6, 2025


1. Introduction

Causality Engine B.V. ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your information in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Dutch implementation of the ePrivacy Directive 2002/58/EC.

As stated in GDPR Article 13(1), we are required to provide you with transparent information about how we process your personal data:

"Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information: (a) the identity and the contact details of the controller..."

This Privacy Policy fulfills that obligation and provides you with comprehensive information about your rights and our data processing practices.


2. Data Controller

Causality Engine B.V.
Registered in the Netherlands
Chamber of Commerce (KVK): 92226892
VAT: NL865944039B01
Email: privacy@causalityengine.ai
Website: https://causalityengine.ai

For questions about this Privacy Policy or your personal data, please contact us at privacy@causalityengine.ai.


3. Supervisory Authority

You have the right to lodge a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority), the independent supervisory authority responsible for data protection in the Netherlands.

Contact Information:
Autoriteit Persoonsgegevens
Postbus 93374
2509 AJ Den Haag
The Netherlands
Phone: +31 70 888 85 00
Email: info@autoriteitpersoonsgegevens.nl
Website: https://www.autoriteitpersoonsgegevens.nl/en


4. What Personal Data We Collect

We collect and process the following categories of personal data:

4.1 Information You Provide Directly

  • Contact Information: Name, email address, company name, phone number
  • Account Information: Username, password (encrypted), company details
  • Communication Data: Messages, support requests, feedback
  • Marketing Preferences: Newsletter subscriptions, communication preferences

4.2 Information Collected Automatically

  • Technical Data: IP address, browser type, device information, operating system
  • Usage Data: Pages visited, time spent on pages, click patterns, referral sources
  • Cookie Data: See Section 6 (Cookies and Tracking Technologies)

4.3 Attribution Analytics Data

  • E-commerce Data: Shopify store performance metrics, order data, revenue attribution
  • Marketing Data: Ad spend, campaign performance, channel attribution, ROAS metrics
  • Customer Journey Data: Touchpoint interactions, conversion paths, funnel analytics

Note: We process this data on behalf of our clients (as a data processor). Our clients remain the data controllers for their customers' personal data.


5. Legal Basis for Processing

Under GDPR Article 6(1), we process your personal data based on the following lawful bases:

5.1 Consent (Article 6(1)(a))

"Processing is lawful only if and to the extent that at least one of the following applies: (a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes..."

We rely on your consent for:
- Marketing communications (newsletters, promotional emails)
- Non-essential cookies and tracking technologies
- Optional data collection for product improvements

You may withdraw your consent at any time by contacting us at privacy@causalityengine.ai or using the unsubscribe link in our emails.

5.2 Contract Performance (Article 6(1)(b))

"(b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract..."

We process your data to:
- Provide our attribution analytics software
- Manage your account and subscription
- Deliver customer support
- Process payments and billing

5.3 Legal Obligation (Article 6(1)(c))

"(c) processing is necessary for compliance with a legal obligation to which the controller is subject..."

We process your data to comply with:
- Tax and accounting regulations
- Anti-money laundering requirements
- Legal requests from authorities

5.4 Legitimate Interests (Article 6(1)(f))

"(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject..."

We rely on legitimate interests for:
- Website security: Protecting against fraud, abuse, and security threats
- Service improvement: Analyzing usage patterns to enhance our software
- Business operations: Internal administration, record-keeping, and quality assurance

We have conducted a Legitimate Interest Assessment (LIA) in accordance with EDPB Guidelines 1/2024 to ensure our processing does not override your rights and freedoms.


6. Cookies and Tracking Technologies

We use cookies and similar technologies in accordance with Article 5(3) of the ePrivacy Directive:

"The storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent..."

6.1 Essential Cookies (No Consent Required)

  • Session cookies: Maintain your login state and security
  • Security cookies: Prevent fraud and protect against attacks
  • Load balancing cookies: Ensure optimal performance

6.2 Analytics Cookies (Consent Required)

  • Google Analytics 4: Website traffic analysis, user behavior tracking
  • Hotjar: Heatmaps, session recordings, user feedback
  • Mixpanel: Product analytics, feature usage tracking

6.3 Marketing Cookies (Consent Required)

  • Meta Pixel: Facebook/Instagram ad targeting and conversion tracking
  • LinkedIn Insight Tag: LinkedIn ad targeting and analytics
  • Google Ads: Remarketing and conversion tracking

6.4 Managing Your Cookie Preferences

You can manage your cookie preferences through:
- Our cookie consent banner (first visit)
- Your browser settings (block/delete cookies)
- Our Cookie Policy page: https://causalityengine.ai/cookie-policy

For more information about cookies, visit https://www.aboutcookies.org.


7. How We Use Your Personal Data

We process your personal data for the following purposes:

7.1 Service Delivery

  • Provide access to our attribution analytics platform
  • Process and analyze your e-commerce and marketing data
  • Generate attribution reports and insights
  • Deliver customer support and technical assistance

7.2 Communication

  • Send transactional emails (account updates, billing, security alerts)
  • Respond to your inquiries and support requests
  • Send marketing communications (with your consent)
  • Conduct customer satisfaction surveys

7.3 Improvement and Development

  • Analyze usage patterns to improve our software
  • Develop new features and functionality
  • Conduct research and analytics
  • Test and optimize our services

7.4 Security and Compliance

  • Detect and prevent fraud, abuse, and security threats
  • Comply with legal obligations and regulatory requirements
  • Enforce our Terms & Conditions
  • Protect our legal rights and interests

8. Data Sharing and Third-Party Services

We share your personal data with the following categories of recipients, as permitted under GDPR Article 13(1)(e):

8.1 Service Providers (Data Processors)

We work with trusted third-party service providers who process data on our behalf:

All processors are bound by Data Processing Agreements (DPAs) in accordance with GDPR Article 28.

8.2 Business Partners

8.3 Legal and Regulatory Authorities

We may disclose your data to:
- Law enforcement agencies (when legally required)
- Tax authorities (for compliance purposes)
- Courts and tribunals (in legal proceedings)

8.4 International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA). We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions under GDPR Article 45
  • Privacy Shield successor frameworks (where applicable)

For more information about our data transfers, contact privacy@causalityengine.ai.


9. Data Retention

In accordance with GDPR Article 13(2)(a), we retain your personal data for the following periods:

"The controller shall provide the data subject with the following further information necessary to ensure fair and transparent processing: (a) the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period..."

9.1 Retention Periods

Data Category Retention Period Legal Basis
Account data Duration of contract + 7 years Tax and accounting obligations
Analytics data 26 months GDPR recital 65 (reasonable period)
Marketing data Until consent withdrawn + 30 days Consent withdrawal processing
Support tickets 3 years after resolution Legitimate interest (quality assurance)
Financial records 7 years Dutch tax law requirements
Cookie data See Cookie Policy ePrivacy Directive

9.2 Deletion

After the retention period expires, we securely delete or anonymize your personal data in accordance with GDPR Article 17 (Right to erasure).


10. Your Rights Under GDPR

Under Chapter 3 of the GDPR, you have the following rights:

10.1 Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, access to that data.

GDPR Article 15(1): "The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data..."

How to exercise: Email privacy@causalityengine.ai with subject "Data Access Request"

10.2 Right to Rectification (Article 16)

You have the right to correct inaccurate or incomplete personal data.

GDPR Article 16: "The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her..."

How to exercise: Update your account settings or contact privacy@causalityengine.ai

10.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You have the right to request deletion of your personal data in certain circumstances.

GDPR Article 17(1): "The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay..."

How to exercise: Email privacy@causalityengine.ai with subject "Deletion Request"

Note: This right is not absolute. We may retain data if required by law or for legitimate purposes (e.g., tax obligations).

10.4 Right to Restriction of Processing (Article 18)

You have the right to restrict processing of your personal data in certain circumstances.

GDPR Article 18(1): "The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies..."

How to exercise: Email privacy@causalityengine.ai with subject "Restriction Request"

10.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format.

GDPR Article 20(1): "The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format..."

How to exercise: Email privacy@causalityengine.ai with subject "Data Portability Request"

Format: We provide data in JSON or CSV format.

10.6 Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

GDPR Article 21(1): "The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her..."

How to exercise: Email privacy@causalityengine.ai or use the unsubscribe link in marketing emails.

10.7 Right to Withdraw Consent (Article 7)

Where processing is based on consent, you have the right to withdraw that consent at any time.

GDPR Article 7(3): "The data subject shall have the right to withdraw his or her consent at any time..."

How to exercise: Email privacy@causalityengine.ai or update your preferences in your account settings.

10.8 Right to Lodge a Complaint (Article 77)

You have the right to lodge a complaint with the Autoriteit Persoonsgegevens (see Section 3).

GDPR Article 77(1): "Every data subject shall have the right to lodge a complaint with a supervisory authority..."

10.9 Response Time

We will respond to your requests within one month of receipt, as required by GDPR Article 12(3). In complex cases, we may extend this by two additional months and will inform you of the extension.


11. Data Security

We implement appropriate technical and organizational measures to protect your personal data, as required by GDPR Article 32:

"The controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk..."

11.1 Technical Measures

  • Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access controls: Role-based access control (RBAC) and multi-factor authentication (MFA)
  • Firewalls: Network segmentation and intrusion detection systems
  • Monitoring: 24/7 security monitoring and automated threat detection
  • Backups: Regular encrypted backups with disaster recovery procedures

11.2 Organizational Measures

  • Staff training: Regular data protection and security awareness training
  • Access policies: Strict need-to-know access policies
  • Vendor management: Due diligence on all third-party processors
  • Incident response: Data breach notification procedures (see Section 12)
  • Privacy by design: Data protection integrated into product development

12. Data Breach Notification

In the event of a personal data breach, we will comply with GDPR Article 33 and Article 34:

Article 33(1): "In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority..."

Article 34(1): "When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay."

We will:
1. Notify the Autoriteit Persoonsgegevens within 72 hours (if required)
2. Notify affected individuals without undue delay (if high risk)
3. Document all breaches in our internal breach register
4. Take measures to mitigate the breach and prevent recurrence


13. Children's Privacy

Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@causalityengine.ai.

This complies with GDPR Article 8 regarding the conditions for children's consent in relation to information society services.


14. Automated Decision-Making and Profiling

We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you, as defined in GDPR Article 22.

Our attribution analytics software provides insights and recommendations, but all business decisions are made by human users of our platform.


15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. We will:

  • Post the updated policy on this page
  • Update the "Last Updated" date at the top
  • Notify you of material changes via email (if you have an account)
  • Obtain new consent if required by law

We encourage you to review this Privacy Policy periodically.


16. Contact Information

For questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

Data Protection Contact:
Causality Engine B.V.
Email: privacy@causalityengine.ai
Website: https://causalityengine.ai

Supervisory Authority:
Autoriteit Persoonsgegevens
Website: https://www.autoriteitpersoonsgegevens.nl/en
Email: info@autoriteitpersoonsgegevens.nl
Phone: +31 70 888 85 00


17. Legal References

This Privacy Policy is based on and complies with:

For the full text of these regulations, please visit the linked resources.


Last Updated: November 6, 2025
Version: 1.0


© 2025 Causality Engine B.V. All rights reserved.

Ready to uncover
your hidden revenue?

Causality Engine | Wait-list signup