Privacy Policy

26 April 2026

1. Who we are

This Privacy Policy describes how Narron B.V. (“Narron”, “we”, “us”), a private limited company established in the Netherlands, processes personal data in connection with our website narron.io and the Narron Brand Intelligence Platform (collectively, the “Services”).

Narron is the controller of the personal data described in this policy within the meaning of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).

Contact:
Narron B.V.
Address: [TBD — registered office]
KvK (Dutch Chamber of Commerce) number: [TBD]
Email: hello@narron.io

2. What this policy covers

This policy applies to (a) visitors of narron.io, (b) people who contact us by email or through the website, (c) people invited to access our investor materials, and (d) users of the Narron platform (e.g. lens.narron.io). For platform customers, additional contractual terms and a Data Processing Agreement may apply.

3. Personal data we process

We may process the following categories of data:

  • Identification and contact data you provide voluntarily, e.g. when you email us, request a demo, or are invited to view investor materials (name, business email, company, role).
  • Technical data automatically collected by our hosting provider, such as IP address, user-agent and access timestamps, retained in standard server logs for security and abuse-prevention purposes.
  • Preference data stored locally in your browser (e.g. language and theme preference) via localStorage. This data does not leave your device.
  • Investor-deck access data for the time-limited HMAC tokens used to gate access to confidential materials, including the email address the link was issued to and access timestamps.
  • Platform data processed when you use the Narron platform, including data about brands, public web content, and individuals named in publicly available sources, as further described in section 7.

We do not knowingly collect special categories of personal data (GDPR Art. 9) and do not target our Services at children.

4. Purposes and legal bases

  • Responding to your enquiries — legitimate interest (GDPR Art. 6(1)(f)) in operating our business; performance of pre-contractual steps at your request (Art. 6(1)(b)).
  • Security, fraud prevention, and service operation — legitimate interest (Art. 6(1)(f)) in keeping the Services available, secure, and free from misuse.
  • Compliance with legal obligations, including responding to lawful requests from authorities (Art. 6(1)(c)).
  • Investor-deck access control — legitimate interest in protecting confidential business information.
  • Platform service delivery to customers — performance of a contract (Art. 6(1)(b)) and, for the processing of personal data appearing in public sources analysed by the platform, our customers’ legitimate interests (Art. 6(1)(f)) subject to the safeguards described in section 7.

5. Cookies and similar technologies

narron.io uses strictly necessary browser storage (localStorage) to remember your language and theme preference. We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that profile individual visitors at the time of publication. If we introduce optional analytics or marketing technologies in the future, we will request your consent first where required by Dutch implementation of the ePrivacy Directive (Telecommunicatiewet art. 11.7a).

6. Recipients and processors

We share personal data only with carefully selected service providers who act as processors on our behalf under written agreements compliant with GDPR Art. 28. These currently include:

  • Hosting and DNS: Hostinger International Ltd. (EU/EEA infrastructure where available) for narron.io.
  • Application hosting: Google Ireland Ltd. (Firebase Hosting / Cloud Firestore) for lens.narron.io.
  • Email: our business email provider for inbound correspondence sent to addresses on the narron.io domain.

We do not sell personal data, and we do not share personal data with third parties for their own marketing purposes.

Where personal data is transferred outside the European Economic Area, we rely on European Commission adequacy decisions or, where none applies, on the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) supplemented by additional safeguards as required by the case-law of the Court of Justice of the European Union.

7. AI processing and the EU AI Act

The Narron platform is an AI system in the sense of the EU AI Act (Regulation (EU) 2024/1689). It processes publicly available content from the open web, including social media, news media, and outputs of generative AI systems, in order to measure how brands and their representatives are described, ranked, and recommended.

In doing so, the platform may incidentally process personal data about identifiable persons mentioned in those public sources (e.g. company executives, journalists, public figures commenting on a brand). We rely on:

  • Legitimate interests of our customers in understanding their public perception, balanced against the rights and freedoms of data subjects (GDPR Art. 6(1)(f) and Art. 14(5)(b) where information was not collected directly from the data subject);
  • Source minimisation — we use only sources that are already publicly accessible and that data subjects can reasonably expect to be analysed;
  • Human oversight — every action that materially affects communications about a brand or person is reviewed and approved by a human before publication. The platform does not publish autonomously and is not used for automated decision-making producing legal or similarly significant effects on individuals (GDPR Art. 22);
  • Transparency — content generated or substantially altered by AI on behalf of a customer is identifiable as such in line with Art. 50 of the EU AI Act once applicable.

Individuals may exercise their rights under section 9 in respect of this processing.

8. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected:

  • Email correspondence — typically for the duration of our commercial relationship plus a reasonable period afterwards for legal and accounting purposes.
  • Server logs — typically up to 90 days, except where longer retention is necessary for security investigations.
  • Investor-deck access data — for the validity period of the access link and a short audit window thereafter.
  • Platform data — as agreed with the relevant customer in the applicable contract or DPA.

9. Your rights

Subject to the conditions set out in the GDPR, you have the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict (Art. 18), and port (Art. 20) your personal data, to object to processing based on legitimate interests (Art. 21), and to withdraw any consent you have given (Art. 7(3)). You may exercise these rights at any time by emailing hello@narron.io.

You also have the right to lodge a complaint with a supervisory authority. In the Netherlands the competent authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

10. Security

We apply technical and organisational measures appropriate to the risk, including transport encryption (HTTPS), access controls, and time-limited HMAC tokens for confidential materials. No system can be guaranteed fully secure; please report any suspected vulnerability to hello@narron.io.

11. Changes

We may update this policy from time to time to reflect changes in our Services or in the law. The “Last updated” date at the top of this page indicates when it was last revised. Where changes are material we will take reasonable steps to bring them to your attention.

Narron