Last updated 21 September 2026
Privacy Policy
Who we are
boldify (boldify.ai) is operated by DIVEX S.R.L., Splaiul Independenței nr. 202B, camera 42, Sector 6, Bucharest, Romania; tax identification number (CUI) 49953093; Trade Register number J2024008045403 (“we”, “us”). You can reach us at hello@divex.ai.
We are the controller of the personal data described here about visitors of boldify.ai, people who join the early-access list and people who use a boldify account. For data that our customers collect about the visitors of their own websites with boldify’s attribution tools, the customer is the controller and we act as its processor (see “Attribution data” below).
What we collect
Visiting boldify.ai. The public website uses no analytics, advertising or tracking cookies. Our hosting provider records technical request data (IP address, browser user agent, time and address of the request) to deliver the site and protect it from abuse.
Early-access list. If you ask for early access we keep your email address to contact you about access to boldify.
Your account. Your name and email address. We sign you in with one-time links sent by email. For each signed-in session we store the IP address and browser user agent it started from, and your browser keeps a session cookie that keeps you signed in and a cookie that remembers the last workspace you opened. Both are strictly necessary for the app to work.
Workspace content. What you and your team enter: brand profile, competitors, topics, tracked websites and settings. API keys you create are stored only as a hash.
Market data. For the companies a workspace follows, boldify collects publicly available information: web pages, RSS feeds, YouTube videos, Reddit posts, search results and rankings, and ads published in the Meta Ad Library. It is information about businesses, but it can include the names of people or their public posts. We use it only to produce that workspace’s analysis.
Attribution data (on behalf of our customers)
Customers can measure which marketing brings them leads by adding the boldify script to their website or by sending events from their own servers.
- The script stores nothing and sends nothing until the visitor consents through the customer’s consent tool.
- With consent, it keeps a random visitor identifier in a first-party cookie and in the browser’s local storage for up to 13 months, and records the pages visited, the referring site, campaign tags (UTM), ad click identifiers, the device type, browser and operating system, and the country derived from the IP address. The IP address itself is not stored.
- Server events carry the customer’s own lead identifiers, lead status, revenue and, for websites without the script, where the visit came from (landing page, referrer, campaign tags). They do not need names or email addresses, and we ask customers not to send them.
For this data the customer decides why and how it is processed, and we process it only on the customer’s instructions under our Terms. If you visited one of our customers’ websites, please contact that company first; we will help it answer your request.
Why we use it, and on what legal basis
- To provide boldify to you and your team — performance of our contract (Art. 6(1)(b) GDPR).
- To contact you about early access — your consent (Art. 6(1)(a)), which you can withdraw at any time.
- To keep the service secure, prevent abuse and analyse public information about companies — our legitimate interests (Art. 6(1)(f)).
- To meet legal obligations, such as accounting and tax records — Art. 6(1)(c).
We do not sell personal data and we do not use it for advertising.
AI processing
boldify uses AI models to summarise, classify and compare market data. We send these providers the market content being analysed, not your account details. The results are suggestions for people to review; boldify makes no automated decisions that have legal or similarly significant effects on anyone.
Who processes data for us
- Vercel Inc. — hosting of the website and the app (EU region, Frankfurt).
- netcup GmbH — the server that hosts our database, in Vienna, Austria, which we administer ourselves.
- Trigger.dev — background jobs that collect and analyse market data.
- Cloudflare, Inc. — storage of page snapshots and ad images.
- Resend (Plus Five Five, Inc.) — sign-in and notification emails.
- Anthropic PBC and Voyage AI — AI analysis of market content.
To collect market data we also query DataForSEO, the YouTube Data API (Google), Reddit and the Meta Ad Library with company names, website addresses and keywords, not with data about you.
Some providers are based in the United States. Transfers there rely on the EU–U.S. Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses.
How long we keep it
- Account data: while your account exists, and deleted within 30 days after it is closed.
- Sessions: they expire 30 days after your last activity; sign-in links expire after 15 minutes.
- Early-access list: until you get access or ask us to remove you.
- Attribution data: as long as the customer keeps it in its workspace, and deleted within 30 days after the workspace is closed.
- Records we must keep by law (for example invoices): for the period the law requires.
Your rights
You can ask us to access, correct, delete, restrict or port your personal data, object to processing based on our legitimate interests, and withdraw consent at any time. Write to hello@divex.ai; we answer within one month. You can also complain to the Romanian data protection authority, ANSPDCP (dataprotection.ro), or to the authority where you live.
Deleting your data
To delete your account and its data, email hello@divex.ai from the address you sign in with, with the subject “Delete my data”. We confirm the deletion within 30 days.
boldify’s Meta app is used only by our team to read the public Meta Ad Library. It does not offer Facebook Login and stores no data from anyone’s Facebook account. If you have connected it to your Facebook account, you can remove it at any time in Facebook under Settings → Apps and websites.
Security
Data travels over encrypted connections. Access to the database is limited by per-workspace access rules, and only the people who run boldify can reach production systems.
Children
boldify is a service for businesses and is not directed at anyone under 16.
Changes
When this policy changes we update the date at the top. If a change is significant, we tell account holders by email before it applies.