Privacy Policy
This Privacy Policy explains how Nimblet, a product of YOYABA GmbH, collects, processes, and protects personal data. Nimblet is a B2B SaaS analytics platform for ad creative teams. We follow the EU General Data Protection Regulation (GDPR).
Controller
YOYABA GmbH
Barmbekerstraße 6a, 22303 Hamburg, Germany
Email: info@yoyaba.com
Data Protection Officer
Mauß Datenschutz GmbH
Neuer Wall 10, 20354 Hamburg, Germany
Email: info@datenschutzbeauftragter-hamburg.de
Phone: +49 40 999 99 52-0
Data we collect
We process the following categories of personal and operational data to deliver the service:
| Category | Data | Source | Purpose | Legal basis |
|---|---|---|---|---|
| Account | Name, email, profile picture | Google OAuth | Authentication | Art. 6(1)(b) |
| Ad account | Campaigns, ads, creatives, performance metrics | LinkedIn / Meta API | Core product | Art. 6(1)(b) |
| Media assets | Ad images and videos | LinkedIn / Meta API → GCS | Display in library | Art. 6(1)(b) |
| AI analysis | Ad creative image URLs, copy and prompts sent to our AI model provider (via OpenRouter) | User-triggered | Creative scoring | Art. 6(1)(b) |
| Session | nimblet_session cookie | Browser | Login persistence | Art. 6(1)(b) |
| Beta gate | nimblet_access_code cookie | Browser | Beta access (removed when beta ends) | Art. 6(1)(f) |
| Invitations | Invitee email | User input | Team access | Art. 6(1)(b) |
| Billing | Billing contact (name, email), subscription status, invoice metadata | User input / Stripe | Paid-plan billing | Art. 6(1)(b), (c) |
Data we do NOT collect
- No analytics, tracking pixels, or advertising profiles.
- No full payment card data. Payments for paid plans are processed by Stripe; your card details go directly to Stripe and never touch our servers. We store only the billing contact, subscription status, and invoice metadata.
- No lead-level advertising data. Conversion and pixel data is processed in aggregate only (per-ad, per-day counts and values); we do not ingest names, emails, or other identifiers of ad audiences.
- AI analysis is optional and bring-your-own-key: it runs only when your workspace supplies its own model-provider API key.
Sub-processors
We engage a small set of third-party processors to operate the service (EU cloud hosting, ad-platform APIs, AI model routing, competitor web scraping, payment processing, transactional email). The current list - with each processor’s purpose, the data involved, its location, and the transfer safeguard - is published at /subprocessors. For processing on behalf of business customers, see our Data Processing Agreement.
Data retention
- Account data (name, email, profile picture): deleted within 30 days of account deletion. Legal basis Art. 6(1)(b); statutory retention obligations remain reserved.
- Ad-account data, creative media, and derived analysis: deleted within 90 days of disconnecting the source ad account or deleting the workspace.
- After a paid subscription ends, organization data is kept read-only for 90 days (so you can rejoin without data loss), then deleted with prior notice. Earlier deletion on request.
- Billing and invoice records: retained for the statutory commercial and tax retention periods under German law (up to 10 years, Art. 6(1)(c)).
- OAuth access/refresh tokens: deleted on disconnect.
- AI usage and generation logs: retained up to 12 months for billing and audit, then deleted.
- Access-request (waitlist) data: deleted within 12 months if no account is created.
- Session cookie: 7 days.
- Backups: overwritten on a rolling cycle (within ~35 days).
You can request earlier deletion at any time (see User rights).
User rights (GDPR Art. 15–22)
You have the right to access, deletion, portability, correction, restriction, and objection regarding your personal data. To exercise any of these rights, contact info@yoyaba.com. We respond within 30 days.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Our competent authority is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI)
Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany
datenschutz-hamburg.de
Cookies
Nimblet uses only strictly necessary cookies. We do not set marketing or analytics cookies, so no consent banner is shown.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
nimblet_session | Authentication | 7 days | Strictly necessary |
nimblet_oauth_state | OAuth CSRF protection | 10 minutes | Strictly necessary |
nimblet_access_code | Beta gate | 7 days | Strictly necessary |
International transfers
Application data is hosted in the EU (Google Cloud region europe-west1). Some of our sub-processors are based in, or have parent entities in, the United States (Google, Meta, LinkedIn, OpenRouter, Firecrawl, Stripe, Resend). Where personal data is transferred outside the EU/EEA, the transfer is governed by EU Standard Contractual Clauses or another mechanism recognized under Art. 46 GDPR. The safeguard applied to each processor is set out in our sub-processor list.
Last updated: 2026-07-22