Privacy Policy

Version 1Effective July 7, 2025

Effective date: 2026-05-12
Version: 1.0

This Privacy Policy explains how Martez (operated by Raphael Kagermeier, sole proprietor doing business as Performromance) collects, uses, stores and shares personal data when you use the Martez service ("Martez", the "Service") or visit our marketing website. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Austrian Data Protection Act (Datenschutzgesetz, "DSG"), and the Google API Services User Data Policy.

If you only want to know what we do with data we receive from Google APIs (in particular Google Ads), jump to Section 3 — Google API Services and Limited Use.


1. Who we are

The controller of your personal data within the meaning of Art. 4(7) GDPR is:

Raphael Kagermeier (sole proprietor, doing business as Performromance)
Neubaugasse 24
8020 Graz
Austria

  • Email: office@performromance.com
  • Phone: +43 680 2200968
  • VAT ID: ATU76150157
  • Supervisory authority: Magistrat der Landeshauptstadt Graz
  • Chamber: Wirtschaftskammer Steiermark

Data Protection Officer. As a sole proprietor we are not required to appoint a formal Data Protection Officer under Art. 37 GDPR, and we have not appointed one voluntarily. For any data-protection question or request, please contact us directly at the address above.

As the controller is established within the European Union (Austria), no representative under Article 27 GDPR is required.


2. Scope of this policy

This policy applies to:

  • Personal data of individuals who register for or use the Martez application (account holders and their team members);
  • Third-party data that you, as a Martez customer, choose to import into the Service through integrations such as Google Ads, Meta Ads, Matomo, Digistore24 and KlickTipp;
  • Visitors to our marketing website.

When you import third-party data through an integration, you act as the data controller with respect to that data and Martez acts as your data processor. When you are an account holder or marketing-site visitor, Martez acts as the controller.


3. Google API Services and Limited Use

This section describes specifically how Martez handles data received from Google APIs when you connect a Google Ads account through OAuth.

3.1 Limited Use disclosure (canonical Google language)

> Martez's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3.2 OAuth scopes we request

When you connect a Google Ads account to Martez, we request the following scopes:

| Scope | What it is for |
|---|---|
| openid | Identifies you to Martez via a signed Google ID token, so we can link the connection to your Google identity. |
| email | Lets Google include your verified email address in the ID token, so we can show you which Google account is connected and contact you about that connection. |
| https://www.googleapis.com/auth/adwords | Read data from the Google Ads accounts you select, so Martez can import campaign, ad-group and ad performance data for attribution and cost analytics. Google does not offer a separate read-only variant of this scope; Martez exercises it read-only in practice (see clarification below). |

We do not request Google's profile scope, Drive scope, Gmail scope or any other Google scope.

Martez exercises the adwords scope read-only. We do not currently send any write/mutate calls (campaign creation, ad updates, bidding changes, etc.) to the Google Ads API. Should this change, we will update this Privacy Policy and notify connected Customers in advance.

3.3 What Google data we actually receive

After you grant consent, Martez calls the Google APIs to receive:

  • From Google's OpenID Connect endpoints: your Google account identifier (sub claim), your verified email address (email_verified == true) and the issuer/audience metadata required to validate the ID token.
  • From the Google Ads API at connect time: the list of Google Ads accounts accessible to you (customers:listAccessibleCustomers) and, for each selected account, the customer ID, descriptive name, currency code, time zone, manager flag, test-account flag and status.
  • From the Google Ads API during synchronization: campaign, ad-group and ad metadata (ID, name) and performance metrics (cost_micros, impressions, clicks).

We do not request, store or process any other categories of Google user data.

3.4 How we use Google data (sole purpose)

We use Google user data only to provide the Martez service to the customer who connected the account. Concretely:

  • We display your Google Ads accounts so you can select which ones to import into a Martez project.
  • We import campaign, ad-group, ad and spend records into your project so that Martez can calculate attribution, ROAS and our proprietary Average Cost per Contributing Touchpoint (ACpCT) metric for the campaigns you run.
  • We store the OAuth refresh and access tokens we receive so we can continue to fetch updates on your behalf without asking you to log in again on every sync (legal basis: Article 6(1)(b) GDPR — performance of the contract under which the Customer connected the Google Ads account).

3.5 Limited Use commitments

In line with the Limited Use requirements, we explicitly commit:

  • No advertising. We do not use Google user data for advertising, retargeting or to build advertising audiences.
  • No selling. We do not sell Google user data.
  • No AI/ML training. We do not use Google user data to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models, whether operated by Martez or by any third party.
  • No human reading. No human at Martez reads Google user data, except in any of the following narrowly defined cases: (a) you explicitly request support that requires us to look at the data; (b) we need to investigate a suspected security incident or abuse of the Service; (c) we are compelled to do so by applicable law (for example, a binding court order); (d) the data has been aggregated or de-identified so that it is no longer linked to an individual or to a specific Google account.
  • No transfers to third parties. We do not transfer Google user data to third parties, except to the sub-processors listed in Section 7 — Sub-processors where strictly necessary to operate the Service, and always under written processor agreements.

3.6 Revocation and disconnect

You can disconnect Martez from your Google account at any time, in either of two ways:

3.7 Deletion of Google-derived data

For deletion timelines triggered by termination of the Service or your Martez account (rather than by a written deletion request), see Terms of Service §15.

When you disconnect a Google Ads integration:

  • We immediately clear the OAuth refresh and access tokens we hold for that integration; Martez can no longer call the Google Ads API on your behalf.
  • The campaign, ad-group, ad and spend records we have already imported remain in your Martez project so that historical reporting is preserved, until you delete the project, delete the specific records, or submit a deletion request to office@performromance.com.
  • Upon a written deletion request, we delete the Google-derived data we hold within 30 days, except where we are required by law to retain specific records for longer (in which case we restrict processing instead).

4. Data we collect (other than Google data)

4.1 Account and personal data we collect as controller

| Category | Examples | Source |
|---|---|---|
| Identity & contact data | Name, email address, password hash, profile preferences | You, at sign-up |
| Authentication metadata | IP address at sign-in, session timestamps, multi-factor authentication state | Automatically, on use |
| Billing data | Invoice address, VAT number, payment status (we do not store full card numbers) | You, on subscribing |
| Support data | Email correspondence, error reports you choose to send | You, when you contact us |
| Diagnostic data | Server log files (IP, request path, user agent, status code, latency) | Automatically, on use |

4.2 Customer-imported data we process as processor

When you connect an integration, you instruct Martez to import data from a third-party platform into your project. The categories vary by integration but typically include:

| Integration | Categories imported |
|---|---|
| Google Ads | Customer/campaign/ad-group/ad metadata, cost, impressions, clicks (see Section 3) |
| Meta Ads | Campaign/ad-set/ad metadata, cost, impressions, clicks |
| Matomo | Visitor IDs, pageview events, goal/conversion events, UTM parameters, referrer URLs |
| Digistore24 | Order/transaction records, payment status, gross/net amounts |
| KlickTipp | Subscriber identifiers, tag/list membership, event timestamps |

This data may indirectly identify an individual (for example, a Matomo Visitor ID linked to a UTM-tagged click). You remain the controller of this data; Martez processes it on your documented instructions under a Data Processing Agreement.

4.3 Marketing website

When you visit our marketing website we process technical connection data (IP address, user agent, time of request) for the purpose of delivering the page, securing the site and producing aggregate statistics. See Section 11 — Cookies and marketing-site analytics.


5. Legal bases per processing purpose

We process personal data only where one of the legal bases in Art. 6(1) GDPR applies. The mapping below covers every processing purpose described in this policy.

| Purpose | Legal basis (Art. 6(1) GDPR) | Notes |
|---|---|---|
| Creating and operating your Martez account | (b) Contract | Necessary to perform the SaaS subscription you have entered into with us. |
| Authenticating you (login, MFA, session management) | (b) Contract | Necessary to provide the Service. |
| Storing the OAuth refresh/access tokens for an integration you connect | (b) Contract | The only way to deliver the integration feature you have requested. |
| Fetching Google Ads / Meta Ads / Matomo / Digistore24 / KlickTipp data on your instruction | (b) Contract (between Martez and you) and Art. 28 GDPR (between you and Martez, as your processor, vis-à-vis the data subjects in the imported data) | We act on your documented instructions. |
| Calculating ACpCT, ROAS, attribution and other analytics for your project | (b) Contract | Core product functionality you have subscribed to. |
| Sending transactional emails (sign-up confirmation, password reset, billing notices, integration health alerts) | (b) Contract | Necessary to deliver and administer the Service. |
| Sending product update emails to existing customers about features they already use | (f) Legitimate interest | Our legitimate interest in informing customers about the Service they pay for; you can opt out at any time. |
| Server log files for failure analysis and security | (f) Legitimate interest | Our legitimate interest in keeping the Service operational and secure; retention strictly limited (see Section 8). |
| Error and exception tracking via Sentry | (f) Legitimate interest | Our legitimate interest in detecting and fixing software defects. |
| Issuing invoices and meeting accounting obligations | (c) Legal obligation | Austrian Federal Fiscal Code (BAO) and Commercial Code (UGB) require retention of business records. |
| Responding to data-subject requests, regulator requests, court orders | (c) Legal obligation | Compliance with GDPR and other applicable law. |
| Marketing-site analytics (Matomo, anonymized) | (f) Legitimate interest or, where required, (a) Consent | Where the law requires consent (e.g. non-essential cookies), we ask for it via the cookie banner. |

We do not rely on consent (Art. 6(1)(a) GDPR) as the legal basis for any processing of Google user data; we rely on the contract you enter into with us when you sign up for Martez and connect the integration.


6. Recipients and disclosures

Martez does not sell personal data of any kind, to any party, under any circumstance.

We share personal data only with:

  • The sub-processors listed in Section 7, strictly to operate the Service;
  • Your own team members and project collaborators, to the extent you grant them access in Martez;
  • Professional advisers (accountants, lawyers) under confidentiality, where required;
  • Public authorities, where we are legally compelled.

We never sell personal data.


7. Sub-processors

We engage the following sub-processors to operate Martez. All sub-processors are bound by written data-processing agreements that impose obligations equivalent to those in this policy.

| Provider | Role | Hosting region | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services EMEA SARL (AWS Lambda, RDS PostgreSQL, S3) | Application compute, database, file storage | eu-central-1 (Frankfurt, Germany) | EU hosting; AWS EU Data Boundary; EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor) for any incidental support access from outside the EEA |
| Amazon CloudFront | Content delivery network for public static assets | Global edge network | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); no Google user data is served via CDN |
| Resend (Resend.com Inc.) | Transactional email delivery | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor) |
| Sentry (Functional Software Inc.) | Application error and exception tracking | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); Google user data is excluded from error payloads |
| Slack Technologies LLC | Internal health-alert notifications | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); only operational metadata (e.g. "sync failed for project X"), no Google user data, is sent |
| Matomo (InnoCraft Ltd. / self-hosted instance) | Marketing-site analytics (consent-gated) and Customer-connectable in-app integration | EU (self-hosted on AWS eu-central-1 for the marketing-site instance; Customer-controlled location for Customer-connected instances) | EU hosting for the marketing-site instance; for Customer-connected instances, the Customer determines the location and any transfer mechanism. EU SCCs (Art. 46 GDPR) apply to any incidental support access from outside the EEA. |

We do not transfer Google user data to any sub-processor for AI/ML training, advertising, or any purpose other than operating the Service.


8. International transfers

Personal data is stored in the European Union (AWS eu-central-1, Frankfurt). Where we use sub-processors established outside the EEA (currently the United States), we rely on the 2021 EU Standard Contractual Clauses (EU SCCs, Commission Implementing Decision (EU) 2021/914), Art. 46 GDPR, as the transfer mechanism. The applicable module is:

  • Module 2 (Controller-to-Processor) for our relationship with Resend, Sentry, Slack and CloudFront.

We do not currently rely on the EU–US Data Privacy Framework adequacy decision as the sole transfer mechanism; SCCs apply in any case.

Where required, we apply supplementary technical measures, including encryption in transit (TLS 1.2+) and at rest, and we restrict the categories of data sent to non-EEA sub-processors as described in Section 7.

For each non-EEA transfer, Martez has performed a Transfer Impact Assessment consistent with EDPB Recommendations 01/2020 on supplementary measures, considering the legal regime of the recipient country and the supplementary technical, contractual, and organizational measures applied.


9. Retention

We retain personal data only as long as necessary for the purpose for which it was collected, or as required by law. The table below sets out our standard retention periods.

| Category | Retention period |
|---|---|
| Account data (name, email, password hash, preferences) | For the lifetime of the account; deleted within 30 days after you close the account |
| OAuth refresh and access tokens (for any integration, including Google) | Until you disconnect the integration; cleared immediately on disconnect |
| Google-derived campaign / ad-group / ad / spend records | Until you delete the project, delete the records, or submit a deletion request; deleted within 30 days of a request |
| Other integration data (Meta, Matomo, Digistore24, KlickTipp) | Same as above |
| Support correspondence | 24 months after the ticket is closed |
| Server log files | 30 days |
| Sentry error events | 90 days |
| Billing records and invoices | 7 years (Austrian Federal Fiscal Code, § 132 BAO) |
| Backups | Rolling 35 days, after which data is overwritten |

If you request deletion of data that is also held in a backup, we will restrict processing of that data and let it expire from the backup rotation, rather than restoring backups to delete a single record.


10. Your rights

Subject to the conditions in the GDPR, you have the following rights with respect to your personal data:

  • Right of access (Art. 15 GDPR) — to obtain confirmation of whether we process personal data about you, and a copy of that data.
  • Right to rectification (Art. 16 GDPR) — to have inaccurate or incomplete data corrected.
  • Right to erasure (Art. 17 GDPR), also known as the "right to be forgotten".
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR) — to receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21 GDPR) to processing based on legitimate interests, including direct-marketing purposes.
  • Right to withdraw consent (Art. 7(3) GDPR), where processing is based on consent; withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Right not to be subject to automated decision-making producing legal or similarly significant effects (Art. 22 GDPR). Martez does not carry out any such automated decision-making.

To exercise these rights, contact us at office@performromance.com. We respond to requests within one month of receipt (extendable by up to two further months for complex requests, in which case we will inform you within the first month).

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority for us is:

> Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
> Barichgasse 40–42
> 1030 Wien
> Austria
> Phone: +43 1 52 152-0
> Email: dsb@dsb.gv.at
> Web: https://www.dsb.gv.at

You may also complain to the supervisory authority in your EU country of residence or workplace.


11. Security

We apply the following technical and organizational measures (Art. 32 GDPR) to protect personal data:

  • Encryption in transit: TLS 1.2 or higher for all connections to Martez and to upstream APIs.
  • Encryption at rest: OAuth tokens and other sensitive integration credentials are stored using Laravel's encrypted casts, keyed by the application's APP_KEY. Database and object-storage volumes are encrypted at rest by AWS (AES-256).
  • Access controls: Role-based access in the application; production database and infrastructure access restricted to the operator (sole proprietor) over SSH/IAM with multi-factor authentication; principle of least privilege.
  • Tenancy isolation: Every record is scoped to a Martez project; cross-project access is blocked at the ORM and query level.
  • Backups: Automated, encrypted, retained on a 35-day rolling schedule and tested periodically for restore.
  • Logging and monitoring: Application errors are tracked in Sentry; access to production infrastructure is logged.
  • Patching: Operating system, runtime and library dependencies are updated regularly; security advisories are reviewed on receipt.

We have not obtained SOC 2, ISO 27001 or any equivalent third-party certification. We do not claim such certification.

In the event of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify the Austrian Data Protection Authority within 72 hours of becoming aware of the breach (Art. 33 GDPR) and, where the risk is high, notify affected individuals without undue delay (Art. 34 GDPR).


12. Cookies and marketing-site analytics

On the Martez application (*.martez.app and equivalent domains) we use only strictly necessary cookies for authentication, session management and security. No tracking cookies are set in the application.

On our marketing website (performromance.com and equivalent marketing domains) we operate our own self-hosted Matomo instance for first-party analytics. The Matomo tracking script and any associated non-essential cookies load only after you grant consent through our cookie banner (our consent-management mechanism). You can withdraw consent at any time by re-opening the cookie banner from the page footer; we will then stop loading the Matomo tag and clear any non-essential cookies it set on your device.

Matomo is also offered as a Customer-connectable in-app integration: a Customer may connect its own Matomo instance to a Martez Project in order to import its analytics data for attribution and reporting. In that role Matomo is processed as Customer Data under Section 4.2 and listed as a sub-processor in Section 7. The Customer's own Matomo instance is independent of the marketing-site instance described above; the two share only the underlying open-source software.

We do not use Google user data in any cookie or marketing-site analytics tool.

> [TODO — before publication: itemized cookie register]
>
> Austrian DSB guidance and TKG §165 require an itemized list of cookies set on the application and the marketing site, split into "strictly necessary" (no consent required) and "consent-gated" categories. The list should include for each cookie: name, purpose, duration, origin (first-party / third-party processor).
>
> This must be completed by auditing the running application (browser dev-tools → Application → Cookies, on both martez.app and the marketing site) before this Privacy Policy is published.


13. Children

Martez is a business-to-business product and is not directed at children. We do not knowingly collect personal data from individuals under the age of 14. Austrian DSG §4(4) sets the digital-consent age at 14. If you believe a child has provided personal data to us, please contact office@performromance.com and we will delete the data.


14. Changes to this policy

We may update this Privacy Policy from time to time. The "Effective date" at the top of the policy reflects the date of the most recent version. For material changes (for example, adding a new category of data, a new sub-processor that receives Google user data, or a new processing purpose), we will notify account holders by email at the address associated with the account at least 14 days before the change takes effect.

Previous versions of this policy are available on request.


15. Contact

For any question, request or complaint regarding this Privacy Policy or our processing of your personal data, contact us at:

Raphael Kagermeier (Performromance)
Neubaugasse 24, 8020 Graz, Austria
Email: office@performromance.com
Phone: +43 680 2200968