1. Introduction
This Privacy Policy explains how Vector Labs B.V., trading as Far & Wide ("we," "us," or "our"), collects, uses, and protects your personal data when you visit our website at www.farandwide.io, apply for our pilot programme, or use the Far & Wide platform and services.
We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Dutch GDPR Implementation Act (Uitvoeringswet AVG, "UAVG").
Data Controller: Vector Labs B.V., Gustav Mahlerlaan 647, 1082MK Amsterdam, Netherlands. KVK number: 99771438. Email: hello@farandwide.io.
A note on our design principle: the Far & Wide platform is built to measure how AI answer engines describe companies and brands. It is designed to process public information about companies, brands and products — not personal data about individuals. The personal data we do handle is described below.
2. What Personal Data We Collect
We collect and process the following categories of personal data.
Information you provide directly:
- Name, work email address, company website, and country (when you apply for our pilot programme through the form on our website)
- Account details for the platform (email address and a securely hashed password) if you create an account
- Email address and delivery details (when you place an order; deliverables are sent to this address)
- Brand name, brand website URL, competitors, and target market/region (necessary for configuring and delivering the Services — please keep personal data out of these fields)
- Billing information (processed by our third-party payment processor; we do not store your payment card details, only the card brand and last four digits and the billing email)
- Name, company name, and any other information you voluntarily include in communications with us (e.g., contact forms, emails)
Information collected automatically when you visit farandwide.io:
- IP address and approximate location (country/region)
- Browser type, device type, and operating system
- Pages visited, time spent on pages, and referring URL
- Cookies and similar tracking technologies (see Section 9)
Website-visitor signals from a site you connect (platform customers only): if you enable the AI-visibility log drain on your own website, we receive your server-log signals — including the visitor's IP address, user-agent, page path, and AI-engine referrer. This is described in Section 6. We set no cookie or pixel on your visitors; these signals come from your own server logs that you choose to stream to us.
3. Why We Process Your Data (Purposes and Legal Basis)
- Processing your pilot programme application and contacting you about it — Steps prior to entering into a contract, at your request (GDPR Art. 6(1)(b))
- Creating and operating your account, and processing and delivering your subscription or order (measurement, reports, and approved fixes) — Performance of a contract (GDPR Art. 6(1)(b))
- Sending order confirmations, delivery and account notifications — Performance of a contract (GDPR Art. 6(1)(b))
- Attributing AI-driven crawls and visits to a website you connect, so we can report which AI engines send you traffic — Legitimate interest (GDPR Art. 6(1)(f)); for this visitor data you are the controller and we act as your processor (see Section 6)
- Responding to your enquiries — Legitimate interest (GDPR Art. 6(1)(f))
- Sending marketing emails and newsletters — Your consent (GDPR Art. 6(1)(a))
- Improving our website and services through analytics — Legitimate interest (GDPR Art. 6(1)(f)); analytics cookies only with your consent
- Complying with legal and tax obligations — Legal obligation (GDPR Art. 6(1)(c))
- Preventing fraud and securing our website and platform — Legitimate interest (GDPR Art. 6(1)(f))
4. Marketing Communications
4.1. We only send marketing emails if you have given your explicit, freely given consent (opt-in). We never use pre-ticked checkboxes.
4.2. You can withdraw your consent at any time by clicking the "unsubscribe" link in any marketing email, or by contacting us at hello@farandwide.io.
4.3. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
4.4. We do not sell, rent, or share your email address with third parties for their marketing purposes.
5. AI Engines and How We Measure Visibility
To measure your AI visibility, the platform sends queries to third-party AI answer engines (such as those operated by OpenAI, Anthropic, Google, and Perplexity) and collects public web content and search results.
Each request contains only the question text plus the brand and company facts you configured. This pipeline is designed to exclude personal data: it works with public information about companies, brands and products, not with information about identifiable individuals. Please keep personal data out of your brand profile and any prompt.
Where an AI provider offers a model-training opt-out or commercial no-training terms, we operate with training on your submitted data disabled. Because these requests are designed to carry no personal data, they do not transfer personal data outside the EEA; the safeguards in Section 7 apply to any account or billing data that does.
6. Website-Visitor Signals From Sites You Connect
This section applies only if you are a platform customer and you choose to enable the AI-visibility log drain on your own website.
When enabled, your server logs stream to our EU-based hosting and database. These logs include your visitors' IP address and user-agent, the page path, and the AI-engine referrer. We use them solely to attribute AI-driven crawls and visits to your site and to report which AI engines are sending you traffic. Your dashboards show aggregated figures; the raw IP and user-agent are used internally only to match a visit to a conversion.
For this visitor data you are the data controller and we act as your processor under GDPR Article 28. We process it only on your instructions and to produce your attribution reporting. It is kept for the life of your account so you can see your traffic history, and is deleted when you close your account (see Section 8).
7. Who We Share Your Data With
We may share your personal data with the following categories of recipients, only to the extent necessary:
- Payment processing — subscription and order billing. Receives the billing email plus the card brand and last four digits only; never full card numbers.
- Hosting, delivery and log ingestion — serves the website, platform and API routes, and ingests the AI-visibility log-drain signals.
- EU database, authentication and file storage — where accounts, brand data, runs, artifacts and visitor-signal tables are held.
- EU audit compute — runs the audit pipeline.
- Transactional email — delivery of sign-in links, password resets and account email.
- Customer-relationship management — customer communications, where used.
- Website and product analytics — website analytics and EU-hosted product analytics and session recordings, both consent-gated.
- Internal team notification — alerts our founders when a new pilot application is submitted (the application's name, email, website and country are relayed).
- AI answer engines — the platforms we measure your brand against; requests are designed to carry no personal data.
- Data-collection and search-measurement providers — collect public web content and search results; designed to receive no personal data.
We deliberately keep the specific identity of our providers confidential to protect commercially sensitive detail of how the platform is built. GDPR permits disclosure of recipients by category (Articles 13-14). The full named list of these providers — each one's identity, location, and role, together with the transfer mechanism (EU Standard Contractual Clauses or the EU-US Data Privacy Framework) where personal data leaves the EEA — is available to platform customers in our Data Processing Agreement and on request (under NDA for enterprise accounts). We notify enterprise account holders before adding a new sub-processor category.
We do not sell your personal data. When personal data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place, such as EU Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework for certified providers, or an adequacy decision by the European Commission. A Transfer Impact Assessment is available on request.
8. How Long We Keep Your Data
We keep your account and platform data — including your brand profiles, audit history, reports, the associated diagnostic and traffic records, website-visitor signals, and support conversations — for the life of your account, so that you can access your full history at any time. When you close your account we delete this data, subject only to the legal minimums below. You can also request earlier deletion of specific data at any time (see Section 10).
- Platform account, brand profiles, runs, reports, AI-visibility history, website-visitor signals (including IP and user-agent), and support conversations — kept for the life of your account, then deleted on account closure
- Pilot programme applications — for the duration of the pilot programme and at most two (2) years, or until you ask us to delete your application
- Order and billing records — 7 years (Dutch tax law requirement)
- Email marketing consent records — until consent is withdrawn, plus 1 year for proof of consent
- Website analytics data (farandwide.io) — 26 months
- Contact form enquiries — 1 year after last communication
- Security / platform audit log of events — up to 24 months, including after account closure
After the retention period, data is securely deleted or anonymised.
9. Cookies
9.1. Our website uses cookies — small text files stored on your device — to ensure the website functions properly and to understand how visitors use our site.
Essential cookies are necessary for the website to function (e.g., session management, security). These do not require your consent.
Analytics cookies (from our analytics provider) help us understand how visitors interact with our website. These are only placed after you give your explicit consent via our cookie banner.
Marketing cookies (advertising-platform pixels) are used to measure the effectiveness of our advertising campaigns and to show you relevant ads on social platforms. These are only placed with your explicit consent.
9.2. You can change your cookie preferences at any time through our cookie settings on the website, or by adjusting your browser settings.
9.3. For more information about specific cookies we use, see our cookie banner settings.
10. Your Rights Under the GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of access — You can request a copy of the personal data we hold about you.
- Right to rectification — You can ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — You can ask us to delete your data, subject to legal retention obligations.
- Right to restrict processing — You can ask us to limit how we use your data in certain circumstances.
- Right to data portability — You can request your data in a structured, commonly used, machine-readable format.
- Right to object — You can object to processing based on legitimate interest, including profiling. You can object to direct marketing at any time.
- Right to withdraw consent — Where processing is based on your consent, you can withdraw it at any time.
- Right to lodge a complaint — You have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): www.autoriteitpersoonsgegevens.nl.
To exercise any of these rights, please contact us at hello@farandwide.io. We will respond within one (1) month of receiving your request, as required by the GDPR. This period may be extended by two further months if the request is complex, in which case we will inform you.
11. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or destruction. These measures include:
- SSL/TLS encryption for all data in transit
- Encryption at rest for our managed database and compute storage
- Secure, PCI-DSS-compliant payment processing; we never store full card numbers
- Access controls limiting data access to authorised personnel only, with per-user row-level security on the platform database
- An append-only audit log of meaningful platform events
- Regular review of our data processing practices
No method of electronic transmission or storage is 100% secure. In the event of a personal-data breach, we will notify the supervisory authority and, where required, affected individuals in line with GDPR Articles 33-34. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at hello@farandwide.io.
12. AI-Generated Content
On paid plans, the platform produces AI-generated content (text) and site fixes. Content is always delivered as a draft and is published to your site — or, for connected code repositories, merged — only after your review and approval. You perform the editorial review and hold editorial responsibility for anything you publish under your brand. See Section 8a of our Terms & Conditions for how this maps to the EU AI Act transparency rules.
13. Children's Privacy
Our Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.
14. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. We encourage you to read the privacy policy of every website you visit.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Changes take effect upon publication on this page. The "Last updated" date at the top indicates when the most recent changes were made. For material changes, we will notify you by email or a prominent notice on our website.
16. Contact
If you have any questions about this Privacy Policy, wish to exercise your rights, or have a complaint about how we handle your data, please contact us:
- Email: hello@farandwide.io
- Company: Vector Labs B.V., trading as Far & Wide
- KVK number: 99771438
- Address: Gustav Mahlerlaan 647, 1082MK Amsterdam, Netherlands
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): www.autoriteitpersoonsgegevens.nl.
