Privacy Statement
LimiaData respects your privacy. This privacy statement explains which personal data may be processed when you visit this website, contact LimiaData or enter into a business relationship with LimiaData.
1. Controller
LimiaData is a trade name of Stanislav Samko.
2. Personal data processed
LimiaData may process the following personal data:
- name, company name and business contact details;
- email address and phone number if you provide them;
- information you include in emails, requests, proposals or project communication;
- invoice and administration data, where relevant;
- basic technical website data processed by hosting providers, such as IP address, browser type and time of visit.
3. Purposes and legal basis
LimiaData processes personal data to respond to messages, prepare proposals, perform services, manage client relationships, send invoices, maintain administration and comply with legal obligations. Depending on the situation, this is based on steps before entering into an agreement, performance of an agreement, legitimate interests in operating and protecting the business and website, and/or legal obligations.
Optional website analytics is separate. It only starts after you actively choose Allow analytics and is based on your consent. You can withdraw or change that choice at any time.
Private demo-access account management, security logging and limited usage auditing are based on LimiaData's legitimate interests in protecting and evaluating the invitation-only demo and managing assigned access, and where applicable on steps requested before entering into an agreement.
4. Website analytics and campaigns
Optional LimiaData analytics is off until you allow it. If you consent, LimiaData uses its own first-party analytics layer, hosted on Netlify and backed by PostgreSQL, to understand website use and campaign performance. The analytics may include pages viewed, visit times, traffic source or campaign, country, device class, browser/operating system, page language, a broad screen-size bucket, visible engagement time and selected website interactions.
After consent, LimiaData creates a random session identifier and a random browser identifier. The browser identifier supports returning-visit measurement and first-touch attribution. The analytics database does not store raw IP addresses as analytics identifiers, city, or exact screen dimensions. Netlify may still process technical request information, including IP addresses, where needed for hosting, security and function delivery; those raw IP addresses are not copied into LimiaData's analytics database.
Direct-contact alerts sent through Telegram are deliberately minimal and do not include browser IDs, country/browser details or full visitor journeys. Scheduled Telegram briefings use aggregate analytics and suppress detailed dimensions when the sample is too small. Detailed analytics events follow the 90-day deletion cycle described under Retention below.
Withdrawing analytics permission stops future optional analytics after the page reloads and removes the analytics identifiers stored in your browser/session. It does not automatically erase historical server-side analytics records already collected under your earlier consent; those records expire under the retention period above. You can also contact LimiaData to exercise your data-protection rights.
Private demo access
LimiaData may provide individually assigned access to a private, read-only Intelligence demo. For these accounts, LimiaData processes the viewer name, username, account status and expiry, login/session timestamps and a limited activity trail such as dashboard sections viewed, period changes and selected meaningful actions. This is used to secure the private environment, manage access and understand which parts of the demo are useful. The Control Center does not record mouse movements, hover history, typed content or raw IP addresses in its demo-access audit database.
Invited demo viewers receive aggregate analytical views. Individual recent/live visitor traces and session-level contact detail are restricted to the administrator and are not exposed through Viewer access. Demo-viewer activity is kept separate from public website analytics. Detailed demo-access audit entries are deleted after 90 days. Access can be disabled at any time and account records can be removed when they are no longer needed.
5. Sharing personal data and service providers
LimiaData does not sell personal data. Data is shared only where needed for service delivery, administration, legal/professional support or website operation. Netlify is used for website hosting, serverless functions and database services. Telegram is used only for minimal internal contact alerts and aggregate analytics briefings. LimiaData does not send Telegram analytics browser IDs or detailed visitor journeys.
Where personal data would be processed outside the EEA, appropriate contractual and international-transfer safeguards must be in place for that processing.
6. Retention
Personal data is kept no longer than necessary for the purpose for which it was collected, unless a longer period is legally required. Detailed website analytics event rows are automatically deleted once they are more than 90 days old. Cleanup runs once per day, so deletion normally happens in the next daily cleanup cycle (within about 24 hours after the 90-day point). Provider-managed backups, where applicable, may follow a separate infrastructure retention cycle and are not used for routine analytics. Administration and invoice data may be kept for the legally required tax retention period.
7. Security
LimiaData takes reasonable technical and organisational measures to protect personal data against loss, misuse and unauthorised access.
8. Your rights
You may request access, correction, deletion, restriction or transfer of your personal data. You may also object to processing in certain situations. To exercise your rights, contact hello@limiadata.nl.
9. Complaints
If you have a privacy concern, please contact LimiaData first. You also have the right to lodge a complaint with the competent supervisory authority, such as the Dutch Autoriteit Persoonsgegevens.
10. Changes
This privacy statement may be updated when services, website functionality or legal requirements change.
Last updated
4 September 2026