Version 1 — Effective July 7, 2025
Effective date: 2026-05-12
Version: 1.0
This Privacy Policy explains how Martez (operated by Raphael Kagermeier, sole proprietor doing business as Performromance) collects, uses, stores and shares personal data when you use the Martez service ("Martez", the "Service") or visit our marketing website. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Austrian Data Protection Act (Datenschutzgesetz, "DSG"), and the Google API Services User Data Policy.
If you only want to know what we do with data we receive from Google APIs (in particular Google Ads), jump to Section 3 — Google API Services and Limited Use.
The controller of your personal data within the meaning of Art. 4(7) GDPR is:
Raphael Kagermeier (sole proprietor, doing business as Performromance)
Neubaugasse 24
8020 Graz
Austria
Data Protection Officer. As a sole proprietor we are not required to appoint a formal Data Protection Officer under Art. 37 GDPR, and we have not appointed one voluntarily. For any data-protection question or request, please contact us directly at the address above.
As the controller is established within the European Union (Austria), no representative under Article 27 GDPR is required.
This policy applies to:
When you import third-party data through an integration, you act as the data controller with respect to that data and Martez acts as your data processor. When you are an account holder or marketing-site visitor, Martez acts as the controller.
This section describes specifically how Martez handles data received from Google APIs when you connect a Google Ads account through OAuth.
> Martez's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google Ads account to Martez, we request the following scopes:
| Scope | What it is for |
|---|---|
| openid | Identifies you to Martez via a signed Google ID token, so we can link the connection to your Google identity. |
| email | Lets Google include your verified email address in the ID token, so we can show you which Google account is connected and contact you about that connection. |
| https://www.googleapis.com/auth/adwords | Read data from the Google Ads accounts you select, so Martez can import campaign, ad-group and ad performance data for attribution and cost analytics. Google does not offer a separate read-only variant of this scope; Martez exercises it read-only in practice (see clarification below). |
We do not request Google's profile scope, Drive scope, Gmail scope or any other Google scope.
Martez exercises the adwords scope read-only. We do not currently send any write/mutate calls (campaign creation, ad updates, bidding changes, etc.) to the Google Ads API. Should this change, we will update this Privacy Policy and notify connected Customers in advance.
After you grant consent, Martez calls the Google APIs to receive:
sub claim), your verified email address (email_verified == true) and the issuer/audience metadata required to validate the ID token.customers:listAccessibleCustomers) and, for each selected account, the customer ID, descriptive name, currency code, time zone, manager flag, test-account flag and status.cost_micros, impressions, clicks).We do not request, store or process any other categories of Google user data.
We use Google user data only to provide the Martez service to the customer who connected the account. Concretely:
In line with the Limited Use requirements, we explicitly commit:
You can disconnect Martez from your Google account at any time, in either of two ways:
For deletion timelines triggered by termination of the Service or your Martez account (rather than by a written deletion request), see Terms of Service §15.
When you disconnect a Google Ads integration:
| Category | Examples | Source |
|---|---|---|
| Identity & contact data | Name, email address, password hash, profile preferences | You, at sign-up |
| Authentication metadata | IP address at sign-in, session timestamps, multi-factor authentication state | Automatically, on use |
| Billing data | Invoice address, VAT number, payment status (we do not store full card numbers) | You, on subscribing |
| Support data | Email correspondence, error reports you choose to send | You, when you contact us |
| Diagnostic data | Server log files (IP, request path, user agent, status code, latency) | Automatically, on use |
When you connect an integration, you instruct Martez to import data from a third-party platform into your project. The categories vary by integration but typically include:
| Integration | Categories imported |
|---|---|
| Google Ads | Customer/campaign/ad-group/ad metadata, cost, impressions, clicks (see Section 3) |
| Meta Ads | Campaign/ad-set/ad metadata, cost, impressions, clicks |
| Matomo | Visitor IDs, pageview events, goal/conversion events, UTM parameters, referrer URLs |
| Digistore24 | Order/transaction records, payment status, gross/net amounts |
| KlickTipp | Subscriber identifiers, tag/list membership, event timestamps |
This data may indirectly identify an individual (for example, a Matomo Visitor ID linked to a UTM-tagged click). You remain the controller of this data; Martez processes it on your documented instructions under a Data Processing Agreement.
When you visit our marketing website we process technical connection data (IP address, user agent, time of request) for the purpose of delivering the page, securing the site and producing aggregate statistics. See Section 11 — Cookies and marketing-site analytics.
We process personal data only where one of the legal bases in Art. 6(1) GDPR applies. The mapping below covers every processing purpose described in this policy.
| Purpose | Legal basis (Art. 6(1) GDPR) | Notes |
|---|---|---|
| Creating and operating your Martez account | (b) Contract | Necessary to perform the SaaS subscription you have entered into with us. |
| Authenticating you (login, MFA, session management) | (b) Contract | Necessary to provide the Service. |
| Storing the OAuth refresh/access tokens for an integration you connect | (b) Contract | The only way to deliver the integration feature you have requested. |
| Fetching Google Ads / Meta Ads / Matomo / Digistore24 / KlickTipp data on your instruction | (b) Contract (between Martez and you) and Art. 28 GDPR (between you and Martez, as your processor, vis-à-vis the data subjects in the imported data) | We act on your documented instructions. |
| Calculating ACpCT, ROAS, attribution and other analytics for your project | (b) Contract | Core product functionality you have subscribed to. |
| Sending transactional emails (sign-up confirmation, password reset, billing notices, integration health alerts) | (b) Contract | Necessary to deliver and administer the Service. |
| Sending product update emails to existing customers about features they already use | (f) Legitimate interest | Our legitimate interest in informing customers about the Service they pay for; you can opt out at any time. |
| Server log files for failure analysis and security | (f) Legitimate interest | Our legitimate interest in keeping the Service operational and secure; retention strictly limited (see Section 8). |
| Error and exception tracking via Sentry | (f) Legitimate interest | Our legitimate interest in detecting and fixing software defects. |
| Issuing invoices and meeting accounting obligations | (c) Legal obligation | Austrian Federal Fiscal Code (BAO) and Commercial Code (UGB) require retention of business records. |
| Responding to data-subject requests, regulator requests, court orders | (c) Legal obligation | Compliance with GDPR and other applicable law. |
| Marketing-site analytics (Matomo, anonymized) | (f) Legitimate interest or, where required, (a) Consent | Where the law requires consent (e.g. non-essential cookies), we ask for it via the cookie banner. |
We do not rely on consent (Art. 6(1)(a) GDPR) as the legal basis for any processing of Google user data; we rely on the contract you enter into with us when you sign up for Martez and connect the integration.
Martez does not sell personal data of any kind, to any party, under any circumstance.
We share personal data only with:
We never sell personal data.
We engage the following sub-processors to operate Martez. All sub-processors are bound by written data-processing agreements that impose obligations equivalent to those in this policy.
| Provider | Role | Hosting region | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services EMEA SARL (AWS Lambda, RDS PostgreSQL, S3) | Application compute, database, file storage | eu-central-1 (Frankfurt, Germany) | EU hosting; AWS EU Data Boundary; EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor) for any incidental support access from outside the EEA |
| Amazon CloudFront | Content delivery network for public static assets | Global edge network | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); no Google user data is served via CDN |
| Resend (Resend.com Inc.) | Transactional email delivery | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor) |
| Sentry (Functional Software Inc.) | Application error and exception tracking | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); Google user data is excluded from error payloads |
| Slack Technologies LLC | Internal health-alert notifications | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); only operational metadata (e.g. "sync failed for project X"), no Google user data, is sent |
| Matomo (InnoCraft Ltd. / self-hosted instance) | Marketing-site analytics (consent-gated) and Customer-connectable in-app integration | EU (self-hosted on AWS eu-central-1 for the marketing-site instance; Customer-controlled location for Customer-connected instances) | EU hosting for the marketing-site instance; for Customer-connected instances, the Customer determines the location and any transfer mechanism. EU SCCs (Art. 46 GDPR) apply to any incidental support access from outside the EEA. |
We do not transfer Google user data to any sub-processor for AI/ML training, advertising, or any purpose other than operating the Service.
Personal data is stored in the European Union (AWS eu-central-1, Frankfurt). Where we use sub-processors established outside the EEA (currently the United States), we rely on the 2021 EU Standard Contractual Clauses (EU SCCs, Commission Implementing Decision (EU) 2021/914), Art. 46 GDPR, as the transfer mechanism. The applicable module is:
We do not currently rely on the EU–US Data Privacy Framework adequacy decision as the sole transfer mechanism; SCCs apply in any case.
Where required, we apply supplementary technical measures, including encryption in transit (TLS 1.2+) and at rest, and we restrict the categories of data sent to non-EEA sub-processors as described in Section 7.
For each non-EEA transfer, Martez has performed a Transfer Impact Assessment consistent with EDPB Recommendations 01/2020 on supplementary measures, considering the legal regime of the recipient country and the supplementary technical, contractual, and organizational measures applied.
We retain personal data only as long as necessary for the purpose for which it was collected, or as required by law. The table below sets out our standard retention periods.
| Category | Retention period |
|---|---|
| Account data (name, email, password hash, preferences) | For the lifetime of the account; deleted within 30 days after you close the account |
| OAuth refresh and access tokens (for any integration, including Google) | Until you disconnect the integration; cleared immediately on disconnect |
| Google-derived campaign / ad-group / ad / spend records | Until you delete the project, delete the records, or submit a deletion request; deleted within 30 days of a request |
| Other integration data (Meta, Matomo, Digistore24, KlickTipp) | Same as above |
| Support correspondence | 24 months after the ticket is closed |
| Server log files | 30 days |
| Sentry error events | 90 days |
| Billing records and invoices | 7 years (Austrian Federal Fiscal Code, § 132 BAO) |
| Backups | Rolling 35 days, after which data is overwritten |
If you request deletion of data that is also held in a backup, we will restrict processing of that data and let it expire from the backup rotation, rather than restoring backups to delete a single record.
Subject to the conditions in the GDPR, you have the following rights with respect to your personal data:
To exercise these rights, contact us at office@performromance.com. We respond to requests within one month of receipt (extendable by up to two further months for complex requests, in which case we will inform you within the first month).
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority for us is:
> Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
> Barichgasse 40–42
> 1030 Wien
> Austria
> Phone: +43 1 52 152-0
> Email: dsb@dsb.gv.at
> Web: https://www.dsb.gv.at
You may also complain to the supervisory authority in your EU country of residence or workplace.
We apply the following technical and organizational measures (Art. 32 GDPR) to protect personal data:
APP_KEY. Database and object-storage volumes are encrypted at rest by AWS (AES-256).We have not obtained SOC 2, ISO 27001 or any equivalent third-party certification. We do not claim such certification.
In the event of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify the Austrian Data Protection Authority within 72 hours of becoming aware of the breach (Art. 33 GDPR) and, where the risk is high, notify affected individuals without undue delay (Art. 34 GDPR).
On the Martez application (*.martez.app and equivalent domains) we use only strictly necessary cookies for authentication, session management and security. No tracking cookies are set in the application.
On our marketing website (performromance.com and equivalent marketing domains) we operate our own self-hosted Matomo instance for first-party analytics. The Matomo tracking script and any associated non-essential cookies load only after you grant consent through our cookie banner (our consent-management mechanism). You can withdraw consent at any time by re-opening the cookie banner from the page footer; we will then stop loading the Matomo tag and clear any non-essential cookies it set on your device.
Matomo is also offered as a Customer-connectable in-app integration: a Customer may connect its own Matomo instance to a Martez Project in order to import its analytics data for attribution and reporting. In that role Matomo is processed as Customer Data under Section 4.2 and listed as a sub-processor in Section 7. The Customer's own Matomo instance is independent of the marketing-site instance described above; the two share only the underlying open-source software.
We do not use Google user data in any cookie or marketing-site analytics tool.
> [TODO — before publication: itemized cookie register]
>
> Austrian DSB guidance and TKG §165 require an itemized list of cookies set on the application and the marketing site, split into "strictly necessary" (no consent required) and "consent-gated" categories. The list should include for each cookie: name, purpose, duration, origin (first-party / third-party processor).
>
> This must be completed by auditing the running application (browser dev-tools → Application → Cookies, on both martez.app and the marketing site) before this Privacy Policy is published.
Martez is a business-to-business product and is not directed at children. We do not knowingly collect personal data from individuals under the age of 14. Austrian DSG §4(4) sets the digital-consent age at 14. If you believe a child has provided personal data to us, please contact office@performromance.com and we will delete the data.
We may update this Privacy Policy from time to time. The "Effective date" at the top of the policy reflects the date of the most recent version. For material changes (for example, adding a new category of data, a new sub-processor that receives Google user data, or a new processing purpose), we will notify account holders by email at the address associated with the account at least 14 days before the change takes effect.
Previous versions of this policy are available on request.
For any question, request or complaint regarding this Privacy Policy or our processing of your personal data, contact us at:
Raphael Kagermeier (Performromance)
Neubaugasse 24, 8020 Graz, Austria
Email: office@performromance.com
Phone: +43 680 2200968