Back to webblitz.ai

Trust & Security

Last reviewed: 2026-08-20 · Raw Response Labs UG (haftungsbeschränkt) · HRB 284973 B, Amtsgericht Charlottenburg

Webblitz measures your brand's AI visibility from the outside — from publicly available AI answers and public web pages. No feature requires access to your CRM, your shop, or your analytics. Optional connections like Slack and Google Search Console are made individually, by opt-in — read-only, and only for your own data; credentials are stored AES-256-encrypted, bound to your workspace, and you can disconnect them at any time.

Architecture: outside-in

What comes in

  • Public AI answers about your brand
  • Public content from your website
  • Your account data (email, name)
  • What you actively enter or upload

Opt-in only

  • Slack — connected by you, via OAuth, disconnectable at any time
  • Google Search Console — connected by you, via OAuth, read-only, disconnectable at any time
  • Future channels (CMS publishing, social) follow the same rule

What never comes in

  • Your CRM
  • Your shop backend
  • Your web analytics
  • Payment data (lives with the payment provider)

Data retention

Data lives as long as your workspace or account — with these automatic limits:

AI answer full texts and source snippets12 months
Chats and agent memories24 months or until account deletion
Search Console history (only with a connected property)12 months
IP addresses (rate limiting)48 hours
Application logs and email delivery log90 days
Uploadsdeleted with your workspace
Guest sessions48 hours (7 days with saved email), including all analysis data
Database backupsrotate out after 7 days — deletions reach backups too

Deletion and export are self-service: in Settings you can export your data as JSON and delete your account entirely — including workspaces, files, and your login.

Subprocessors & recipients

Complete list, last reviewed 2026-08-20. Third-country transfers are safeguarded by EU Standard Contractual Clauses and, where certified, the EU-US Data Privacy Framework.

Subprocessors (process personal data on our instruction)

ServicePurposeDataRegionTransfer
Google Cloud Platform (Cloud Run, Cloud SQL, Cloud Storage)
Google Ireland Ltd.
Hosting, database, file storageAll application dataEU — europe-west1 (Belgium)Cloud Data Processing Addendum; SCCs + EU-US Data Privacy Framework
Firebase Authentication
Google
Login and identity (email/password, Google sign-in)Email address, name, authentication identityUSA (per Google: run only from US data centers)Firebase Data Processing and Security Terms; SCCs + DPF
Google Gemini API (paid tier)
Google
AI analysis and generation (answer analysis, drafts, embeddings, chat)Prompts, AI answers, scraped public website content, user inputs and uploadsGlobal endpoints — no region commitmentGoogle processor terms for paid Gemini API; SCCs + DPF
OpenAI API
OpenAI, L.L.C.
Visibility measurement on ChatGPTTracking prompt text only (may contain publicly known names)USASCCs (modules 2+3)
Anthropic API
Anthropic, PBC
Visibility measurement on ClaudeTracking prompt text onlyUSASCCs; DPA incorporated into Commercial Terms
Perplexity API
Perplexity AI, Inc.
Visibility measurement on PerplexityTracking prompt text onlyUSASCCs (modules 2+3)
DataForSEO
DataForSEO OÜ (Estonia)
Google AI Overview measurement, keyword dataPrompt texts as search keywords, keyword listsEU seat (Estonia); infrastructure EU/USASCCs / adequacy; DPA incorporated into their ToS
Resend
Plus Five Five, Inc.
Email delivery and inbound email processingRecipient addresses, email content; account metadata stored in the US regardless of sending regionUSA (EU sending region optional)SCCs + EU-US Data Privacy Framework (certified)
Sentry
Functional Software, Inc.
Error tracking (errors only — no session replays, no performance tracing)Exceptions, request contextUS region today; migration to the EU org (de.sentry.io) plannedSCCs + EU-US DPF
PostHog
PostHog, Inc.
Product analytics — loads only after cookie consentUsage events, email, name (after consent)EU Cloud (eu.posthog.com, AWS Frankfurt)SCCs where applicable

Opt-in channels (connected by you)

ServicePurposeDataRegionTransfer
Google Search Console (customer-connected)
Google Ireland Ltd.
Read-only: which pages Google serves, and whether a finished draft went livePage URLs, impressions, clicks, average position of the customer's own siteEU/US — Google infrastructureCustomer's own Google account; scope webmasters.readonly, revocable
Slack
Slack Technologies / Salesforce
Notifications and two-way chat into YOUR Slack workspace — only if you connect itMetrics, suggestions, message texts of the connected workspace; bot token stored AES-256-GCM-encrypted, workspace-boundUSASCCs (Slack DPA)

Independent controllers

ServicePurposeDataRegionTransfer
Polar (checkout & billing)
Polar Software Inc.
Merchant of record for the checkout — independent controller for payment data; card data stays with Polar/Stripe, never with usEmail, customer reference, plan; payment details only at PolarUSASCCs (no DPF certification)

Recipients without personal data

ServicePurposeDataRegionTransfer
Google Knowledge Graph API
Google
Brand entity checkBrand name onlyGlobal
Unsplash
Unsplash (Getty Images)
Image search for article draftsSearch terms onlyNo commitment— (no DPA offered)

15 entries · Last reviewed: 2026-08-20

Hosting & regions

Application and database run in the Google Cloud region europe-west1 (Belgium); the file store is non-public and served only through access-checked application routes. For visibility measurement we query the tracked AI platforms (OpenAI, Anthropic, Google, Perplexity) via their official APIs — only the prompt text is transmitted. AI processing via the Gemini API uses global endpoints without a region commitment; the applicable processor terms are linked in the table above.

Opt-in connections

Only you connect your channels — individually, via OAuth, per workspace. Credentials are stored AES-256-GCM-encrypted and cryptographically bound to your workspace; you can disconnect any channel at any time. Without a connection, no access exists.

Data processing & contracts

Questions about data processing (Art. 28 GDPR)? Talk to us: hello@webblitz.ai — we work directly with your legal team.

Contracting party and controller:

Raw Response Labs UG (haftungsbeschränkt)

Urbanstr. 71, 10967 Berlin, Germany

HRB 284973 B, Amtsgericht Charlottenburg

Imprint · Privacy policy

Product and service: two clearly separated offerings

Webblitz (SaaS)

Webblitz (the SaaS product) works outside-in. No access to your systems, no integration required. Everything on this page describes the product.

rawResponse Labs full service

When the rawResponse Labs team implements inside your systems (e.g. Shopify), that happens exclusively under a separate engagement with a defined scope and its own DPA. That access is part of the service contract — never part of the product.

For the collection and analysis of public market data, Raw Response Labs UG is the controller under the GDPR. Our customers are independent controllers for how they use the analysis results in their own processes. For data customers bring into the platform themselves (e.g. via opt-in integrations), we act as a processor under the DPA.

Notice for individuals in analyzed content

Who this concerns

Webblitz analyzes how AI systems (e.g. ChatGPT, Perplexity, Gemini) talk about brands in public. Those AI answers and the public web sources they cite can contain names of people — founders, authors, or quoted experts in their public roles. This notice addresses those people.

Where the data comes from

Exclusively from publicly available sources: public answers of AI systems and publicly reachable web pages those answers cite. We do not collect data about these individuals from any other source, and we do not merge data across sources into person profiles.

What we process it for

The sole purpose is measuring brand visibility in AI systems. Individuals are not the subject of the analysis; their names are part of the analyzed public content. No profiling of individuals takes place, and no person-level analytics are offered.

Legal basis

Legitimate interest (Art. 6(1)(f) GDPR) — our interest and our customers' interest in monitoring public AI statements about brands. The balancing test is documented internally; safeguards: limited retention, no person profiles, processing of public content only. Because individually informing every incidentally mentioned person would be disproportionate, information is provided through this public notice (Art. 14(5)(b) GDPR).

How long

AI answer full texts and captured source content are deleted automatically after 12 months. After that, only aggregated visibility metrics without personal reference remain.

Your rights

Affected individuals can object to the processing and request access or erasure: hello@webblitz.ai. We review every request and remove the relevant content within a reasonable period, unless legal retention obligations require otherwise.

Frequently asked questions

Does Webblitz need access to our internal systems?

No. Webblitz measures AI visibility exclusively from the outside: from publicly available AI answers and public web pages. No feature requires access to CRM, shop backend, or web analytics. Optional connections — Slack and Google Search Console — are made individually via OAuth and can be disconnected at any time. We read Search Console only if you grant it, and only for your own pages.

Is Webblitz built GDPR-compliant?

Webblitz is operated by Raw Response Labs UG (haftungsbeschränkt), Berlin. Application and database run in the EU (Google Cloud region europe-west1, Belgium). Webblitz requires no integration with customer systems; personal data is essentially limited to users' account data. Deletion and data export are available as self-service.

Where does Webblitz store data?

Application and database run in the Google Cloud region europe-west1 (Belgium). Database backups are retained for 7 days — deleted data leaves backups after at most 7 days.

What personal data does Webblitz process?

Users' account data (email address, name), billing references from the payment provider, and content users actively enter or upload. Public AI answers and web pages can contain names that are publicly mentioned there; Webblitz uses them solely for visibility measurement and does not enrich them.

Does Webblitz offer a data processing agreement (DPA)?

For questions about data processing under Art. 28 GDPR, reach us at hello@webblitz.ai — we work directly with your legal team.

What happens to our data when we cancel?

Deleting a workspace removes all associated data — including uploaded files; backups rotate out after at most 7 days. Account deletion additionally removes all workspaces, files, and the login identity.

© 2026 Raw Response Labs UG (haftungsbeschränkt). All rights reserved.
Trust & Security — webblitz.ai | webblitz.ai