Privacy Policy

This Privacy Policy explains how Nimblet, a product of YOYABA GmbH, collects, processes, and protects personal data. Nimblet is a B2B SaaS analytics platform for ad creative teams. We follow the EU General Data Protection Regulation (GDPR).

Controller

YOYABA GmbH
Barmbekerstraße 6a, 22303 Hamburg, Germany
Email: info@yoyaba.com

Data Protection Officer

Mauß Datenschutz GmbH
Neuer Wall 10, 20354 Hamburg, Germany
Email: info@datenschutzbeauftragter-hamburg.de
Phone: +49 40 999 99 52-0

Data we collect

We process the following categories of personal and operational data to deliver the service:

CategoryDataSourcePurposeLegal basis
AccountName, email, profile pictureGoogle OAuthAuthenticationArt. 6(1)(b)
Ad accountCampaigns, ads, creatives, performance metricsLinkedIn / Meta APICore productArt. 6(1)(b)
Media assetsAd images and videosLinkedIn / Meta API → GCSDisplay in libraryArt. 6(1)(b)
AI analysisAd creative image URLs, copy and prompts sent to our AI model provider (via OpenRouter)User-triggeredCreative scoringArt. 6(1)(b)
Sessionnimblet_session cookieBrowserLogin persistenceArt. 6(1)(b)
Beta gatenimblet_access_code cookieBrowserBeta access (removed when beta ends)Art. 6(1)(f)
InvitationsInvitee emailUser inputTeam accessArt. 6(1)(b)
BillingBilling contact (name, email), subscription status, invoice metadataUser input / StripePaid-plan billingArt. 6(1)(b), (c)

Data we do NOT collect

  • No analytics, tracking pixels, or advertising profiles.
  • No full payment card data. Payments for paid plans are processed by Stripe; your card details go directly to Stripe and never touch our servers. We store only the billing contact, subscription status, and invoice metadata.
  • No lead-level advertising data. Conversion and pixel data is processed in aggregate only (per-ad, per-day counts and values); we do not ingest names, emails, or other identifiers of ad audiences.
  • AI analysis is optional and bring-your-own-key: it runs only when your workspace supplies its own model-provider API key.

Sub-processors

We engage a small set of third-party processors to operate the service (EU cloud hosting, ad-platform APIs, AI model routing, competitor web scraping, payment processing, transactional email). The current list - with each processor’s purpose, the data involved, its location, and the transfer safeguard - is published at /subprocessors. For processing on behalf of business customers, see our Data Processing Agreement.

Data retention

  • Account data (name, email, profile picture): deleted within 30 days of account deletion. Legal basis Art. 6(1)(b); statutory retention obligations remain reserved.
  • Ad-account data, creative media, and derived analysis: deleted within 90 days of disconnecting the source ad account or deleting the workspace.
  • After a paid subscription ends, organization data is kept read-only for 90 days (so you can rejoin without data loss), then deleted with prior notice. Earlier deletion on request.
  • Billing and invoice records: retained for the statutory commercial and tax retention periods under German law (up to 10 years, Art. 6(1)(c)).
  • OAuth access/refresh tokens: deleted on disconnect.
  • AI usage and generation logs: retained up to 12 months for billing and audit, then deleted.
  • Access-request (waitlist) data: deleted within 12 months if no account is created.
  • Session cookie: 7 days.
  • Backups: overwritten on a rolling cycle (within ~35 days).

You can request earlier deletion at any time (see User rights).

User rights (GDPR Art. 15–22)

You have the right to access, deletion, portability, correction, restriction, and objection regarding your personal data. To exercise any of these rights, contact info@yoyaba.com. We respond within 30 days.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Our competent authority is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI)
Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany
datenschutz-hamburg.de

Cookies

Nimblet uses only strictly necessary cookies. We do not set marketing or analytics cookies, so no consent banner is shown.

CookiePurposeDurationType
nimblet_sessionAuthentication7 daysStrictly necessary
nimblet_oauth_stateOAuth CSRF protection10 minutesStrictly necessary
nimblet_access_codeBeta gate7 daysStrictly necessary

International transfers

Application data is hosted in the EU (Google Cloud region europe-west1). Some of our sub-processors are based in, or have parent entities in, the United States (Google, Meta, LinkedIn, OpenRouter, Firecrawl, Stripe, Resend). Where personal data is transferred outside the EU/EEA, the transfer is governed by EU Standard Contractual Clauses or another mechanism recognized under Art. 46 GDPR. The safeguard applied to each processor is set out in our sub-processor list.

Last updated: 2026-07-22