Privacy statement

Last updated: October 2, 2026

Vintoo helps B2B teams decide which companies to approach. This statement explains which personal data we process, where it comes from, why, how long we keep it and what your rights are. It applies to customers and users of Vintoo, to people who work at companies in our reports and to visitors of our website.

1. Who we are

Vintoo is a service of Greenwolf Holding B.V., Chamber of Commerce number 92298001, Nijmegen, the Netherlands. We are the controller for the processing described here, unless stated otherwise. We have not appointed a data protection officer. For questions and requests, email info@vintoo.nl.

2. In short

  • People at companies in our reports: we use public information about your work to write reports for our customers. We never contact you and we do not sell lists. See sections 3 to 7.
  • Customers and users: we process your account and organization data to provide Vintoo. See sections 8 and 9.
  • Website visitors: we use cookies that the website needs and statistics that do not identify you. See section 10.
  • Forms: if you fill in our questionnaire or opt-out form, we use your answers to handle them. See section 11.

3. If you work at a company in one of our reports

Our customers are B2B teams. They add companies they are considering approaching. For each company, Vintoo writes a report: whether it makes sense to approach the company now, why, and who the likely decision-makers are, at most three people. The customer reads the report and decides whether to contact the company. Vintoo itself never contacts you.

A report is about a company. To name decision-makers we do use information about people in their professional role. For a sole proprietorship, information about the company can also be personal data.

4. Which data we use and where it comes from

We use business information only, and for people only information about their work:

  • company information from the company's own website, which we visit as VintooBot, from the Dutch Chamber of Commerce register, from archived versions of the website in the Internet Archive, from Google search results (through SerpAPI) and from Google Maps (through Outscraper). Of reviews we keep only the text and the date, not the name of the reviewer;
  • the company page and posts on LinkedIn, collected through Apify;
  • public professional profiles of employees on LinkedIn, collected through Apify: name, job title, headline, summary, work experience, skills and profile photo;
  • work email address and work phone number of decision-makers, only when the customer asks for them, through FullEnrich, which searches its own and partner data sources. We never look up private email addresses.

5. Why we may do this

We rely on legitimate interest (article 6(1)(f) GDPR): the interest of our customers and ourselves in approaching companies selectively and relevantly, instead of sending mass messages. We weighed this interest against your privacy and limit the impact as follows:

  • we only use information about your work that you or your employer made public;
  • we only research a company when a customer adds it;
  • a report shows at most three contact persons, and contact details are only looked up when the customer asks for them;
  • we do not send messages and do not sell or share lists;
  • you can object easily, see section 7.

6. Who sees it and how long we keep it

A report is only shown to the customer who requested it, and processed by the service providers in section 13. The customer is responsible for its own use of the report and must tell you where it got your details, at the latest when it first contacts you.

A report, including the employee profiles we used for it, stays available to the customer as long as its organization keeps the report. Temporary copies of public source data expire after at most 90 days.

7. Objecting and opting out

  • For a whole company: use the opt-out form. After you confirm by email, we no longer write new reports about the company for any customer. With an email address on the company's own domain this starts right away; otherwise we check the request by hand.
  • For yourself: email info@vintoo.nl with your name and the link to your LinkedIn profile. We remove your data from our systems and from the reports in which you appear, and let the customers concerned know. We respond within one month.

8. Customers and users

When you use Vintoo, we process:

  • account data: name, email address, password (stored as a hash), your profile photo if you sign in with Google, language and sign-in sessions;
  • organization data: company name, website, country, your offering and ideal customer profile, team members and their roles;
  • usage data: the prospects you add, your reports, notes and pipeline stages, API keys and connections with AI assistants (stored as hashes), webhook deliveries and logs of API and MCP use;
  • billing data: plan, credit use and invoice details. Payments are handled by Stripe; we do not store card details.

9. How we use customer data and how long we keep it

We use this data to provide Vintoo and to support you (performance of the agreement), to bill and keep our records (legal obligation), and to keep Vintoo secure and improve it (legitimate interest). Our team receives internal notifications about account activity in Slack.

We keep account data as long as your account exists; email us to delete it. Organization data and reports stay until an owner deletes the organization. Logs of webhook deliveries are deleted after 30 days and logs of AI assistant use after 180 days. We keep invoices for 7 years, as required by Dutch tax law.

10. Website, cookies and statistics

We use cookies that are strictly necessary: a sign-in cookie that keeps you logged in, and a cookie that remembers your language for one year. In your browser we also store a few preferences, such as your last report options. These do not need consent.

To see how our website is used, we use Visitors.now, which counts visits without cookies and without storing your IP address, and our own analytics tool, which records clicks and scrolling on pages. We use these statistics only to improve the website and do not share them.

To suggest a language and country, we look up the country of your IP address through IPinfo; we do not store your IP address for this. To protect against abuse, our servers keep IP addresses for a short time to limit the number of requests.

11. Questionnaire and opt-out form

If you fill in our questionnaire, we store your name, company, role, email address and answers, to learn from them and, if you ask for it, to contact you. We keep them until you ask us to delete them.

If you use the opt-out form, we store the company name, website, your name, email address and reason, to handle the request and to keep the exclusion working. We keep this as long as the exclusion applies.

Our team receives a notification of both forms in Slack.

12. AI and profiling

Reports are written with AI models from Anthropic and OpenAI, and with classification models from TypeSafe AI. They receive the information from section 4 and the customer's organization profile. Anthropic and OpenAI do not use data sent through their API to train their models and keep it for a limited time.

Choosing the likely decision-makers from public profiles is a form of profiling. It does not lead to decisions with legal or similarly significant effects for you: a report is advice to the customer, and the customer decides. AI can make mistakes. If information about you is wrong, let us know and we will correct it.

13. Service providers and transfers

Our servers and database are located in Amsterdam, the Netherlands. We use these service providers:

  • DigitalOcean (United States, servers in Amsterdam): hosting of our servers and database;
  • Anthropic and OpenAI (contracted through Ireland, processing in the United States): AI models that write reports;
  • TypeSafe AI (United States): classification models;
  • Apify (Czech Republic, processing in the United States): collecting public LinkedIn information;
  • SerpAPI (United States): Google search results;
  • Outscraper: Google Maps information and reviews;
  • FullEnrich (United States, storage in the EU): work email addresses and phone numbers;
  • Stripe (Ireland and United States): payments and invoices;
  • Resend (United States): sending emails;
  • Slack (Ireland, processing in the United States): internal notifications for our team;
  • IPinfo (United States): the country of an IP address;
  • Google (Ireland and United States): signing in with a Google account, if you choose to;
  • Visitors.now (United States, data stored in Germany): website statistics.

14. Processing outside the EEA

Several of these service providers are based in the United States or process data there. For providers certified under the EU-US Data Privacy Framework, such as DigitalOcean, Stripe, Resend and Slack, we rely on that framework; for the others, on the standard contractual clauses of the European Commission. We do not sell personal data.

15. Security

We take appropriate measures to protect personal data, such as encrypted connections, hashed passwords and API keys, separation of data per organization and limited access for our staff. If a data breach occurs, we act as the law requires.

16. Your rights and complaints

You can ask us for access to your data, correction, deletion, restriction or a copy in a usable format, and you can object to processing based on legitimate interest. Email info@vintoo.nl. We may ask you to confirm your identity and respond within one month. If a request concerns a report of one of our customers, we involve that customer.

Not satisfied with how we handle your data? Let us know. You can also file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

17. Changes

We update this statement when Vintoo or the law changes. The date at the top shows the current version. We inform customers of important changes by email.