Last updated: 27 September 2026
The controller for data processing on ravenbi.com is WEBMIND SOLUTIONS S.R.L., Str. Miniș nr. 8, bl. PM91, sc. B, et. 1, ap. 63, Sector 3, Bucharest, Romania (full identification in the Imprint). Contact for privacy matters: the e-mail address published in the Imprint.
Account data: name, work e-mail, password (stored hashed), language, organization name, chosen markets and seats, timestamp of terms acceptance. When you sign up through an external identity provider (single sign-on), we receive your name and e-mail address from that provider. Billing data: processed by an external payment service provider; we do not store card numbers. We keep subscription status, plan and invoicing metadata. Usage data: server logs (IP address, timestamps, requested pages) for security and operation; session data for login. Attribution: on your first visit we keep the traffic source (UTM parameters and the domain you came from — not the full address, so not your search query) in the current session, to understand how customers find us. It is kept only until the session ends; if you create an account, the value is copied into your account. E-mails: we send transactional e-mails (account, password, trial, billing) and — for active accounts — product digests, delivered via an external e-mail delivery provider. You can disable non-essential e-mails in the Alert Center.
We also process publicly accessible content (e.g. website texts, advertisements, including embedded media content) by transmitting it to specialized AI service providers in order to analyse, classify and describe such content in an automated manner. In addition, we process business contact data that we collect from generally accessible public sources (e.g. company websites, public registers). In individual cases, this may include business-related personal data of employees of companies (for example, email addresses in the format [email protected]).
The platform focuses on analysing the commercial and advertising activities of enterprises. It is designed to evaluate publicly accessible advertising and marketing measures of companies and to provide corresponding market and competitive information to professional users. The platform does not build behavioural profiles of consumers and does not track individual natural persons across different services or devices.
Due to the nature of publicly available advertising material, personal data may nevertheless appear on the platform, for example:
Where such personal data is displayed on the platform, we only process it for the purposes described. Data subjects can exercise their rights (including rectification and erasure) in accordance with the procedures set out in this Privacy Policy.
Contract performance (Art. 6(1)(b)): account, subscription, support, transactional e-mail. Legitimate interest (Art. 6(1)(f)): security logging, fraud prevention, first-party attribution, product improvement. Legal obligation (Art. 6(1)(c)): invoicing and tax retention. Consent (Art. 6(1)(a)) where specifically requested.
The processing of publicly accessible market data and advertising activities of enterprises – including any personal data contained therein, where applicable – is based on our legitimate interests pursuant to Article 6(1)(f) GDPR. Our legitimate interest is to create transparency regarding publicly accessible advertising and marketing activities of companies and to enable our professional customers to conduct structured market and competition analysis.
Data subjects have the right to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them which is based on Article 6(1)(f) GDPR (Article 21 GDPR). Further information on the right to object and on how to exercise your rights can be found in the relevant section of this Privacy Policy.
We disclose personal data in accordance with the applicable legal requirements and only to carefully selected recipients. These include, in particular, the following categories of recipients:
All service providers that process personal data on our behalf are carefully selected and are bound by data processing agreements in accordance with Article 28 GDPR.
Some of the above service providers are located in, or process data in, countries outside the European Union or the EEA, in particular the United States of America. Where an adequacy decision of the European Commission exists for the respective third country, the transfer is based on that decision. In all other cases, we ensure that appropriate safeguards within the meaning of Article 46 GDPR are in place before any transfer takes place, for example by concluding the EU Standard Contractual Clauses.
We do not sell personal data to third parties. Upon request, and within the framework of an access request pursuant to Article 15 GDPR, we will provide data subjects with information on the specific identity of the recipients and service providers involved.
Account data for the duration of the contract plus statutory retention periods (invoicing data typically 10 years). Server logs are rotated on a short cycle. Attribution lives only in the session; the copy kept in an account you open is deleted 60 months after sign-up.
For the remaining categories the period is 60 months, after which the data is deleted automatically: advertising materials that may contain identifiable people (counted from the last observed delivery — the material is deleted, the structured analysis remains, as it contains no personal data); business contact details collected for outreach (from collection); reports received through the public form (from the date we replied). Deletion is carried out by an automated run, not by hand.
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent — write to the contact address in the Imprint. You may also complain to a supervisory authority.
Without your consent we use strictly necessary cookies only (session, CSRF protection, language). These do not require your consent, because the site does not work without them.
For anything beyond that we ask for your consent through a banner on your first visit. Rejecting is as easy as accepting, and the analytics toggle starts off. You can change your mind at any time under "Cookie settings" in the footer. Your choice is kept in a first-party cookie (rb_consent, 6 months) — that one is strictly necessary, because otherwise we would have to ask you on every page.
Google Analytics 4. We use Google Analytics (provided in the European Economic Area by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to understand how the site and the application are used. The tool runs in "consent mode": analytics cookies are written to your device only after an explicit "yes", and storage for advertising and personalisation stays off in all cases.
If you decline, or do not answer, nothing is written to or read from your device. The page does, however, still send Google cookieless signals carrying no identifier: the page visited, the language, the device type and the IP address, from which Google derives an approximate location and which it does not keep in reports. The legal basis is our legitimate interest in knowing how much and in what way the site is used (Art. 6(1)(f) GDPR); you may object at any time by writing to the address in the Imprint. Google may also process these data in the United States, under the conditions described in section 5.
In addition, we keep a cookieless counter on our own server: we count visits per combination of day, page, language, market, source and device type. We store neither the IP address nor the user agent, and there is no row per visitor — this count cannot identify you.
We do not use third-party advertising trackers on this site, and we do not store attribution long-term on your device.
We send service e-mails relating to your account (for example address verification, password, billing and trial notices) and product e-mails you have subscribed to (for example the weekly digest and watchlist alerts).
For every e-mail we send, we record the delivery status reported back to us: accepted, delivered, rejected by the receiving server (bounce), reported as spam, or unsubscribed. We need this to operate the service — an account verification e-mail that never arrives locks you out of your account — and to stop sending to addresses that reject our mail.
We do not use tracking pixels and we do not measure whether our e-mails are opened. No invisible image is embedded in any e-mail we send.
In our product e-mails only — the weekly digest and watchlist alerts — links are routed through a redirect on our own domain, so that we can see which content is useful and improve it. Service e-mails relating to your account contain no measurement of any kind beyond the delivery status described above. The redirect records that a link was followed and sends you straight on to the page; we do not use it to build advertising profiles and we do not pass it to third parties for their own purposes.
Legal basis: Article 6(1)(f) GDPR — our legitimate interest in deliverable communication and in improving our own product e-mails.
Product e-mails contain an unsubscribe link, which is never routed through the redirect. You may also object at any time using the contact address in the Imprint; delivery status will continue to be recorded, because it is necessary for operating the service.
We store only the recipient address, the subject line, the time and the delivery status — not the content of the e-mail. These records are deleted after 12 months, or sooner: if you delete your account, they are deleted with it.