Privacy Policy
How we handle personal data at Market Radar, under the EU General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertés).
Last updated: 7 October 2026
1. Who we are
Market Radar is operated by A Kind of Magic, a société par actions simplifiée (SAS) registered with the RCS of Grenoble under SIREN 935 246 132, intra-community VAT number FR22 935 246 132, with its registered office at 16B rue Charrel, 38000 Grenoble, France (“we”, “us”).
For any question about this policy or about your personal data, contact us at hello@trymarketradar.com.
We are the data controller for the personal data described below, within the meaning of Article 4(7) of the GDPR, except for the readers of your newsletters (see §3).
2. Data we collect
We collect personal data in four situations.
When you create an account or use the service. Your name, work email address and, if you sign in with Google, your Google profile name and picture; your workspace and its members; what you set up (the companies, websites and filters your radars watch, your newsletters and your logo); the names of your API keys and their first characters (the keys themselves are held by our sign-in provider); sign-in metadata and usage logs.
When you add readers to a newsletter. Their email addresses, whether they are subscribed, and whether each issue was delivered or bounced.
When you subscribe to a paid plan. Billing identity, billing address, VAT number where applicable, and payment metadata. We never see or store your card details: payments are handled by our payment provider (see §6).
When you visit our website. IP address, browser and device information, pages visited and referrer, in our hosting provider’s logs.
3. Your newsletters' readers
For the email addresses of the readers you add, you are the data controller and we are your data processor under Article 28 of the GDPR: we use them only to send the newsletters you set up. Every issue carries an unsubscribe link, and a reader who uses it receives no further issue of that newsletter. A reader who writes to us about their data is directed to you, and we help you answer.
4. Why we process your data and on what legal basis
Under Article 6 of the GDPR, every processing activity needs a legal basis. Ours are:
- Performance of the contract (Art. 6(1)(b)): running your account, running your radars and sending your newsletters, customer support, billing.
- Legitimate interests (Art. 6(1)(f)): securing the service, preventing fraud and abuse, improving the product, and limited B2B prospecting on professional contacts. You can object to processing based on legitimate interests at any time (see §8).
- Legal obligation (Art. 6(1)(c)): accounting, tax and other record-keeping obligations under French law.
- Consent (Art. 6(1)(a)): any marketing email to people who are not customers. Consent can be withdrawn at any time.
5. How long we keep your data
- Account data: for the duration of your subscription, then 36 months after the end of the contractual relationship for commercial follow-up, unless you ask us to delete it sooner.
- Readers’ email addresses: as long as you keep them in a newsletter, and deleted with your account.
- Billing and accounting records: 10 years, as required by Article L123-22 of the French Commercial Code.
- Server and security logs: up to 12 months.
6. Who we share your data with
We do not sell personal data. We share it only with the sub-processors strictly required to run the service, all bound by data-processing agreements under Article 28 of the GDPR:
- Clerk (sign-in, accounts and API keys): United States.
- Supabase (database and file storage): Singapore-based.
- Vercel (hosting of the website and the app, and background jobs): United States.
- Paddle (payments and subscriptions, merchant of record): United Kingdom, with EU and US group entities.
- Resend (sending newsletters and account emails): United States.
- OpenRouter (access to the AI models that judge, summarise and translate what your radars find, such as those of Anthropic, OpenAI and Google): United States.
To search, your radars send their queries (company names, keywords and website addresses) to search and data providers, among them Brave Search, NewsAPI.ai, Parallel and Apify. Those queries carry no personal data about you or your readers.
We may also disclose personal data to public authorities when required by law, subpoena or court order.
7. International transfers
Some of our sub-processors are located outside the European Economic Area, primarily in the United States. Where we transfer personal data outside the EEA, we rely on the EU-U.S. Data Privacy Framework where the recipient is certified, or on the European Commission Standard Contractual Clauses (decision 2021/914) with appropriate supplementary measures.
You can request a copy of the safeguards in place by writing to hello@trymarketradar.com.
8. Your rights
Under the GDPR and the French Data Protection Act, you have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectification of inaccurate or incomplete data (Art. 16).
- Erasure of your data, in the cases set out in Art. 17.
- Restriction of processing (Art. 18).
- Portability of the data you provided to us (Art. 20).
- Object to processing based on legitimate interests or for direct marketing (Art. 21).
- Withdraw consent at any time, where processing is based on consent.
- Define directives on the fate of your data after death, under Article 85 of the French Data Protection Act.
To exercise any of these rights, contact hello@trymarketradar.com. We will respond within one month, extendable by two months for complex requests.
If you believe your rights are not being respected, you can lodge a complaint with the French data-protection authority, the CNIL, at www.cnil.fr.
9. Cookies
We use only the cookies the service needs to work: those that keep you signed in and protect your session. They need no consent, and the service cannot run without them. We use no analytics or advertising cookies, so we show no cookie banner.
10. Security
We implement technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest, access controls, and regular review of our sub-processors. No system is perfectly secure; if a personal-data breach occurs, we will notify the CNIL within 72 hours where required, and you directly if the breach is likely to result in a high risk to your rights.
11. Automated decision-making
Market Radar uses large language models to judge, summarise and translate the stories your radars find. These systems decide what appears in a newsletter, not anything about a person: they do not produce legal effects or significantly affect you in a way that would qualify as automated individual decision-making under Article 22 of the GDPR.
12. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email to active subscribers at least 30 days before they take effect. The “last updated” date at the top of the page always reflects the current version.
13. Contact
Questions, rights requests, or data-protection complaints: hello@trymarketradar.com