Product Privacy Notice
Last Updated: 30 June 2026
Introduction
This product privacy notice (“Product Privacy Notice”) explains how Insider One’s products and services (the “Products”) collect, use, and otherwise process information — including personal data — on behalf of the digital marketers, website owners, leading brands, and other businesses that subscribe to the Products (“Customers”), in respect of the Customers’ online users, visitors, and clients (“End Users”). in accordance with the Customer’s instructions
At a glance: Insider One provides the Products to its Customers on a software-as-a-service basis. In respect of End User personal data processed through the Products, the Customer is the data controller and Insider One acts only as a data processor (and, where applicable under U.S. state privacy laws, as a service provider), processing personal data solely on the Customer’s documented instructions. Insider One does not sell End User personal data and does not use it for its own independent purposes.
This Product Privacy Notice applies to the Insider One group of companies (collectively, “Insider One”, “we”, “us”, or “our”). It is intended to help Customers and End Users understand how the Products operate and how the associated processing affects the rights and interests of End Users. Because the Products are integrated with Customers’ own websites, applications, and systems, this Product Privacy Notice should be read together with each Customer’s own privacy policy or notice.
This Product Privacy Notice provides a clear overview of:
-
the Products and services we provide;
-
our role and the roles of the parties;
-
the information we process and the sources of that information;
-
cookies, tags, JavaScript tags, and similar technologies we use;
-
the purposes and legal grounds for processing;
-
how we share information and engage sub-processors;
-
international data transfers;
-
data subject and consumer rights, and how they are exercised;
-
security and data retention; and
-
how this Product Privacy Notice may change.
Definitions
In this Product Privacy Notice, the following terms have the meanings set out below:
-
“Applicable Data Protection Laws” means all data protection and privacy laws applicable to the processing of personal data under this notice, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Turkish Law on the Protection of Personal Data No. 6698 (KVKK), the Singapore Personal Data Protection Act 2012 (PDPA), and applicable U.S. state privacy laws, in each case as amended or replaced from time to time.
-
“Customer” means a business that subscribes to the Products.
-
“DPA” means the data processing agreement entered into between Insider One and the relevant Customer.
-
“End User” means an online user, visitor, or client of a Customer whose personal data is processed through the Products.
-
“Personal data” means any information relating to an identified or identifiable individual, as defined under Applicable Data Protection Laws.
-
“Products” means the Insider One products and services described in this notice.
-
“Sub-processor” means a third party engaged by Insider One to process personal data on behalf of Customers.
-
“Websites” means Customers’ websites and applications with which the Products are integrated.
Scope and Relationship to Other Documents
This Product Privacy Notice applies solely to personal data that Insider One processes on behalf of, and on the documented instructions of, Customers in Insider One’s capacity as a data processor when providing the Products.
This Product Privacy Notice does not apply to:
-
personal data for which Insider One acts as a data controller in respect of its own business operations, website, marketing, and recruitment, which is addressed in Insider One’s separate Privacy Policy available at https://insiderone.com/privacy-policy/; or
-
any Customer’s own collection, use, or processing of personal data, which is governed by that Customer’s own privacy policy or notice.
Where Insider One processes personal data on a Customer’s behalf, that processing is governed by the data processing agreement entered into between Insider One and the relevant Customer (the “DPA”). In the event of any conflict between this Product Privacy Notice and the applicable DPA, the DPA shall prevail in respect of the relationship between Insider One and that Customer.
Roles of the Parties
In respect of personal data processed through the Products:
-
the Customer is the data controller, and determines the purposes and means of the processing; and
-
Insider One is the data processor, and processes personal data only on the documented instructions of the Customer, except where otherwise required by applicable law, in which case Insider One will inform the Customer of that legal requirement before processing unless prohibited from doing so by law.
We provide the Products on a software-as-a-service (SaaS) basis. We do not sell, rent, or share End User personal data. We do not use End User personal data for our own independent purposes except as permitted under the applicable DPA or required by law.
Services We Provide
The Products offer Customers a broad set of features across the customer lifecycle — from acquisition to activation, retention, and revenue — including:
-
automated personalization and content optimization;
-
A/B and multivariate testing;
-
features supporting website conversion optimization;
-
targeted and omnichannel personalized messaging directed to End Users;
-
a data architecture enabling integrations with Customer and third-party enterprise systems; and
-
agentic digital marketing solutions.
We perform these services, and process the underlying data, on the instructions of each Customer, which also includes the workflows in the following link: https://academy.insiderone.com/.
Information We Process
To deliver real-time predictive segmentation, the Products process the following categories of information on behalf of Customers:
-
Personal data of End Users, meaning information relating to identified or identifiable individuals, including:
-
contact information, where Customers provide it to us directly, or through the Products; and
-
technical and online identifiers, including IP addresses of End Users’ devices provided by Customers when End Users access or visit Customers’ websites or applications (“Websites”).
-
-
Usage and device information made available to us or collected through End Users’ interaction with the Websites, including referring URL, timestamp, browser type and language, device type, mobile carrier, operating system, screen parameters, color depth, Java capability, internet connection type, browser cookie settings, pages viewed, last login time, last app update date, time of visit, products viewed, added to cart, or purchased, quantity, price, and purchase identifiers, and custom page data defined by Customers.
Inferred information, where — subject to applicable laws governing cookies and similar technologies, and the consent preferences expressed by End Users where required — the Products may infer additional attributes from End Users’ Website activity, search terms, and information collected through cookies and local storage, including postal code, country, state, time zone, weather, temperature, and proximity to a shipping location.
Certain Product features may utilize artificial intelligence technologies, including third-party foundation models, solely to provide and improve functionalities requested by Customers. Insider One does not use Customer personal data to train general-purpose AI models.
We ask Customers not to instruct us to process, and not to transmit to the Products, any special categories of personal data (such as data revealing health, racial or ethnic origin, religious beliefs, or biometric data) except where expressly agreed in the applicable DPA and supported by appropriate safeguards.
Cookies, Tags, and Similar Technologies
The Products, subject to applicable laws governing cookies and similar technologies, and the consent preferences expressed by End Users where required, collect information using cookies, JavaScript tags, pixels, local storage, and similar technologies when End Users access the Websites. Cookies are small data files stored on a device that allow a website to recognize information about an End User’s visit. The Products may use both session cookies (which expire when the browser is closed) and persistent cookies (which remain until deleted).
We also use JavaScript tags to trigger a sequence of events, including reading or setting a first-party cookie, and to help Customers tailor, analyze, manage, report on, and optimize the End User experience on the Websites.
Where required by Applicable Data Protection Laws, non-essential cookies and similar technologies are deployed only after the relevant consent has been obtained. Responsibility for obtaining and managing End User consent rests with the Customer as data controller. End Users may manage cookies through their browser settings or, where available, through the consent management tools made available on the Websites.
Purposes and Legal Grounds for Processing
Subject to the Service/Subscription and Data Processing Agreements, we process personal data on behalf of Customers for the following purposes:
-
To provide the Products and services to Customers and fulfil our contractual obligations, including analyzing End User data and generating content recommendations for Customers to use across their communications, campaigns, and interactions with End Users;
-
to understand the needs and interests of End Users on behalf of the relevant Customer;
-
to provide, operate, and improve AI-enabled features and functionalities requested by Customers, including generating predictions, recommendations, content, and optimization insights;
-
to facilitate integrations and interoperability with Customer-selected third-party platforms, systems, and service providers;
-
to support, maintain, secure, monitor, and troubleshoot the Products and services;
-
to conduct aggregated and de-identified analytics to improve, maintain, and enhance the Products and services;
-
to investigate, prevent, and address violations of applicable terms and policies, security incidents, disputes, and to comply with applicable law, regulation, governmental authority, subpoena, or similar legal process; and
-
to monitor system performance and network capacity, test and fix systems, and develop and implement system upgrades.
Automated Processing and Profiling
The Products may use artificial intelligence and machine learning to support segmentation, personalization, and predictive analytics. These features may involve profiling on behalf of, and as configured by, the relevant Customer.
Certain Product features may utilize artificial intelligence technologies, including third-party foundation models, solely to provide and improve functionalities requested by Customers. Insider One does not use Customer personal data to train general-purpose AI models unless expressly agreed.
Where any processing involves a decision based solely on automated means that produces legal or similarly significant effects on an End User, responsibility for establishing the legal ground, providing transparency, and implementing safeguards (including the right to obtain human intervention, to express a point of view, and to contest the decision) rests with the Customer as data controller. Insider One will provide the Customer with reasonable assistance to meet those obligations.
Where Insider One develops or improves its Products, models, or services, it does so only using aggregated and de-identified data that does not identify any End User, unless otherwise expressly permitted under the applicable DPA.
How We Share Information and Sub-Processors
We do not sell, rent, or share End User personal data with third parties for their own purposes. We disclose End User personal data only:
-
to sub-processors engaged to provide hosting, infrastructure, analytics, and related services in support of the Products, each of which is bound by written terms imposing data protection obligations no less protective than those in the applicable DPA;
-
to the relevant Customer and persons authorized by that Customer;
-
where required to comply with applicable law, a subpoena, court order, regulatory inquiry, or similar legal process, or where we reasonably believe disclosure is necessary to protect our rights, the safety of any person, or to investigate fraud; and
We engage sub-processors under a general authorization model. A current list of sub-processors is publicly available on our website (https://insiderone.com/legal/subprocessors/).
International Data Transfers
We operate globally, depending on the product that Customers use, we may transfer personal data to sub-processors in countries other than the country in which it was collected. Where personal data is transferred across borders, we rely on a recognized adequacy decision or, in its absence, on appropriate safeguards. Insider One’s security personnel may process Customer information solely to ensure the security of Customers and its End Users. Technical support personnel may process Customer information only where authorized by the relevant Customer for support purposes.
Depending on the relevant transfer scenario, Insider One rely on local regulations, including but not limited to the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, KVKK Standard Contractual Clauses, Binding Corporate Rules where applicable, or other legally recognized transfer mechanisms, in each case supplemented by appropriate technical measures such as encryption and data minimization.
A copy of the relevant safeguards relied upon for a particular transfer may be requested by the Customer, contacting [email protected].
Data Subject and Consumer Rights
Subject to Applicable Data Protection Laws, End Users may have rights to access, rectify, erase, or port their personal data, to restrict or object to its processing, to withdraw consent, and to opt out of the sale or sharing of personal data or of certain automated processing.
Because Insider One processes End User personal data as a data processor, requests from End Users should be directed to the relevant Customer as data controller. Customers can fulfill this request through its InOne Panels. Where an End User submits a request to us directly, we will, unless prohibited by law, promptly inform the relevant Customer and provide reasonable assistance to enable the Customer to respond, and we will not respond to the request ourselves except on the Customer’s instructions or as required by law.
End Users who wish to opt out of cookie- or tag-based collection should follow the instructions made available on the Websites, may use browser or device privacy settings (including “Limit Ad Tracking” on iOS and opt-out of interest-based advertising on Android), or may use a third-party tag management service to disable our tag on the Websites.
Data Retention
We retain personal data processed on behalf of a Customer only for as long as necessary to provide the Products, in accordance with the applicable DPA and the Customer’s documented instructions, and to comply with our legal obligations. Upon expiry or termination of the relevant Customer agreement, we will, or return the personal data, and delete existing copies, except to the extent retention is required by the DPA and applicable law.
Security Measures
We maintain technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including:
-
encryption of personal data in transit and at rest;
-
role-based access controls and multi-factor authentication;
-
monitoring, logging, and security analytics;
-
vulnerability and patch management;
-
business continuity and disaster recovery; and
-
privacy-by-design and data-minimization practices.
Further detail on our security programs and certifications is available in our Security Overview, and a current list of sub-processors is publicly available in our Trust Center.
We maintain an incident management program and will notify affected Customers of any personal data breach affecting their End User data without undue delay in accordance with the applicable DPA, and will provide reasonable assistance and information to support the Customer’s own notification obligations. We continue to invest in threat detection and prevention technologies and to train our personnel on incident response procedures.
Governance
We maintain a Security, Privacy and Compliance Committee comprising data protection, legal, and security specialists responsible for supporting our compliance with Applicable Data Protection Laws. Questions regarding our data protection practices may be directed to [email protected].
Changes to this Product Privacy Notice
This Product Privacy Notice applies to the Insider One group companies. We may update this Product Privacy Notice from time to time to reflect changes to our Products, services, or applicable legal requirements. Any updates will be published on this page. Nothing in this Product Privacy Notice modifies or limits the protections applicable under the relevant Service/Subscription Agreement, DPA, or other contractual commitments entered into with Customers.
— You can also visit https://academy.insiderone.com/docs/insider-one-trust-center