1. Introduction
This Privacy Policy explains how Vector Labs B.V., trading as Far & Wide ("we," "us," or "our"), collects, uses, and protects your personal data when you visit our website at www.farandwide.io or use the Far & Wide platform and services, including a free scan you start without creating an account.
We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Dutch GDPR Implementation Act (Uitvoeringswet AVG, "UAVG").
Data Controller: Vector Labs B.V., Gustav Mahlerlaan 647, 1082MK Amsterdam, Netherlands. KVK number: 99771438. Email: hello@farandwide.io.
A note on our design principle: the Far & Wide platform is built to measure how AI answer engines describe companies and brands. It is designed to process public information about companies, brands and products — not personal data about individuals. The personal data we do handle is described below.
2. What Personal Data We Collect
We collect and process the following categories of personal data.
Information you provide directly:
- Name, work email address, company website, and country (if you applied to our earlier pilot programme; that application form has closed)
- The website address, brand details and answers you give when you start a free scan — including before you save an account; until you save it, the scan is linked to a temporary account held in your browser
- Account details for the platform (email address and a securely hashed password) if you create an account
- Email address and delivery details (when you place an order; deliverables are sent to this address)
- Brand name, brand website URL, competitors, and target market/region (necessary for configuring and delivering the Services — please keep personal data out of these fields)
- Files you upload (for example fact sheets, price lists or bios): we store them to draft facts about your brand for you to confirm. You can delete a file at any time; all files are deleted with your account
- Billing information (processed by our third-party payment processor; we do not store your payment card details, only the card brand and last four digits and the billing email)
- Name, company name, and any other information you voluntarily include in communications with us — contact forms, emails, and the support chat widget on our website (whatever you type into it, plus an email address if you give one)
Information collected automatically when you visit farandwide.io:
- IP address and approximate location (country/region)
- Browser type, device type, and operating system
- Pages visited, time spent on pages, and referring URL
- Cookies and similar tracking technologies (see Section 10)
Website-visitor signals from a site you connect (platform customers only): if you enable the AI-visibility log drain on your own website, we receive your server-log signals — including the visitor's IP address, user-agent, page path, and AI-engine referrer. This is described in Section 6. We set no cookie or pixel on your visitors; these signals come from your own server logs that you choose to stream to us.
3. Why We Process Your Data (Purposes and Legal Basis)
- Handling applications made to our earlier pilot programme and contacting you about them — Steps prior to entering into a contract, at your request (GDPR Art. 6(1)(b))
- Creating and operating your account, and processing and delivering your subscription or order (measurement, reports, and approved fixes) — Performance of a contract (GDPR Art. 6(1)(b))
- Sending order confirmations, delivery and account notifications — Performance of a contract (GDPR Art. 6(1)(b))
- Attributing AI-driven crawls and visits to a website you connect, so we can report which AI engines send you traffic — Legitimate interest (GDPR Art. 6(1)(f)); for this visitor data you are the controller and we act as your processor (see Section 6)
- Responding to your enquiries — Legitimate interest (GDPR Art. 6(1)(f))
- Sending marketing emails and newsletters — Your consent (GDPR Art. 6(1)(a))
- Improving our website and services through analytics — Legitimate interest (GDPR Art. 6(1)(f)); analytics cookies only with your consent
- Complying with legal and tax obligations — Legal obligation (GDPR Art. 6(1)(c))
- Preventing fraud and securing our website and platform — Legitimate interest (GDPR Art. 6(1)(f))
4. Marketing Communications
4.1. We only send marketing emails if you have given your explicit, freely given consent (opt-in). We never use pre-ticked checkboxes.
4.2. You can withdraw your consent at any time by clicking the "unsubscribe" link in any marketing email, or by contacting us at hello@farandwide.io.
4.3. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
4.4. We do not sell, rent, or share your email address with third parties for their marketing purposes.
5. AI Engines and How We Measure Visibility
To measure your AI visibility, the platform sends queries to third-party AI answer engines (such as those operated by OpenAI, Anthropic, Google, and Perplexity) and collects public web content and search results.
Each request contains only the question text plus the brand and company facts you configured. This pipeline is designed to exclude personal data: it works with public information about companies, brands and products, not with information about identifiable individuals. Please keep personal data out of your brand profile and any prompt.
Where an AI provider offers a model-training opt-out or commercial no-training terms, we operate with training on your submitted data disabled. Because these requests are designed to carry no personal data, they do not transfer personal data outside the EEA; the safeguards in Section 8 apply to any account or billing data that does.
6. Website-Visitor Signals From Sites You Connect
This section applies only if you are a platform customer and you choose to enable the AI-visibility log drain on your own website.
When enabled, your server logs stream to our EU-based hosting and database. These logs include your visitors' IP address and user-agent, the page path, and the AI-engine referrer. We use them solely to attribute AI-driven crawls and visits to your site and to report which AI engines are sending you traffic. Your dashboards show aggregated figures; the raw IP and user-agent are used internally only to match a visit to a conversion.
For this visitor data you are the data controller and we act as your processor under GDPR Article 28, as set out in our Data Processing Agreement (www.farandwide.io/data-processing-agreement). We process it only on your instructions and to produce your attribution reporting. Visitor IP addresses are kept readable for 30 days — long enough to verify crawlers and match a visit to a conversion — and are then replaced by a scrambled code that cannot be turned back into the address. The rest is kept for the life of your account so you can see your traffic history, and is deleted when you close your account (see Section 9).
Journalists, editors and website owners: when an AI engine cites a web page in an answer about one of our customers, we read that page and may note a business contact address it publishes (on the article, the author page or the site's contact page), so the customer can ask for a correction or a mention. We never invent or guess an address. Legal basis: legitimate interest (Article 6(1)(f)) — the address was published for this kind of contact. Nothing is sent without the customer's approval. Emails found on cited pages are cleared after 180 days, and a chosen contact is removed 12 months after we last checked the page. To see, correct or remove what we hold about you, or to ask not to be contacted, write to hello@farandwide.io.
7. Data From the Google Account You Connect (Search Console, Analytics and Gmail)
This section applies only if you are a platform customer and you choose to connect a Google account. Connecting is optional — the platform works without it — and you can disconnect or withdraw access at any time.
We ask for the narrowest Google permissions each feature needs, and for nothing else:
- Search Console, read-only (webmasters.readonly) — lists the properties your Google account may read, so that you can choose your own, and then reads that property’s search queries, impressions, clicks and average position. We use it to show how often AI crawlers and Google Search reach your pages, and to seed your audit and your drafted pages with the questions people actually search for.
- Google Analytics, read-only (analytics.readonly) — lists your GA4 properties, so that you can choose one, and then reads session and referrer reports for the property you chose. We use it to show whether a mention by an AI assistant turned into a real visit to your site.
- Gmail, send-only (gmail.send) — sends one outreach message that you wrote and approved, from your own address, at the moment you press send. This permission cannot read, search, label or delete anything in your mailbox, and we never do. The only thing it creates is the message itself, which you can see in your own Sent folder.
- Your email address (userinfo.email) — shows you which mailbox is connected, so that a message is never sent from an address you did not choose.
How we store and use it. Your authorisation is kept as a refresh token in an encrypted secrets vault, separate from the application database and reachable only by our server; the short-lived access tokens made from it are used for a single request and never stored. The figures we read for you — search queries, impressions, clicks, positions, sessions and referrers for the property you selected — are held with the rest of your platform data in our EU database, shown inside your account, and kept under the retention rules in Section 9. Where a language model drafts a page, report or outreach message for you, your own Search Console search terms and page text may be included in that request so the draft answers what your buyers really ask; it is used only to produce that output for you, and training on submitted data is disabled in our provider agreements. We do not sell Google user data, and we share it only with the provider categories in Section 8 that are needed to deliver the features above, for security purposes, or where the law requires it.
Limited Use. Far & Wide’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use, transfer or sell raw or derived user data received from Google APIs — including Google Workspace APIs — to create, train or improve generalised or foundational artificial-intelligence or machine-learning models, and we permit no third party to do so.
Your control. You can disconnect Search Console, Google Analytics or the sending mailbox in the portal at any time. Disconnecting stops all further use and erases the permission we stored for it — where one Google sign-in serves more than one of these, it is erased once the last of them is disconnected. You can also withdraw this application’s access in your own Google Account at myaccount.google.com/permissions, which immediately ends our ability to read your Search Console and Analytics data or to send from your mailbox. Closing your account erases the permissions we hold for every service you have connected, and the figures already collected go with it — see Sections 9 and 11.
8. Who We Share Your Data With
We may share your personal data with the following categories of recipients, only to the extent necessary:
- Payment processing — subscription and order billing. Receives the billing email plus the card brand and last four digits only; never full card numbers.
- Hosting, delivery and log ingestion — serves the website, platform and API routes, and ingests the AI-visibility log-drain signals.
- EU database, authentication and file storage — where accounts, brand data, runs, artifacts and visitor-signal tables are held.
- EU audit compute — runs the audit pipeline.
- Transactional email — delivery of sign-in links, password resets and account email.
- Customer-relationship management — customer communications, where used.
- Website and product analytics — website analytics and EU-hosted product analytics and session recordings, both consent-gated.
- Internal team notification — alerts our founders when someone requests a demo, or buys a plan before saving their account (the details given: name, email, company, plan).
- Support chat — when you use the chat widget, your message (and any email address you give) is answered with the help of an AI language-model provider and relayed to our founders through a messaging app so a person can reply. The messaging app and the language-model provider are outside the EEA; both receive the message text only, under Standard Contractual Clauses. Our product analytics counts chat events without linking them to your email. Do not put personal data about other people into the chat.
- AI processing (the models that draft and check) — the models we run to write and check your fixes and content. Where you connect a code repository, this is the only category that reads your page's own source, and that request stays inside the EEA (Sweden, France) on subscriptions held by Vector Labs B.V. under a company agreement; credentials are screened out before it is sent, and a file that is mostly secrets is withheld entirely. Page text and brand facts may be processed in the US (DPF / SCCs). Model training on submitted data is disabled.
- AI answer engines — the platforms we measure your brand against; requests are designed to carry no personal data.
- Data-collection and search-measurement providers — collect public web content and search results; designed to receive no personal data.
- Integrations you connect — your own accounts with services such as GitHub, WordPress, Webflow, Shopify, Wix, HubSpot, Vercel, Cloudflare, Google Search Console, Google Analytics, Gmail, LinkedIn and Reddit, connected only if you choose to. Each is used only for what that integration is for (checking and publishing the changes you approve, keeping a rollback copy, reading the reports you grant), never for another customer, and you can disconnect it at any time. Our Sub-processors page lists each one with the access it gives.
We deliberately keep the specific identity of our providers confidential to protect commercially sensitive detail of how the platform is built. GDPR permits disclosure of recipients by category (Articles 13-14). The full named list of these providers — each one's identity, location, and role, together with the transfer mechanism (EU Standard Contractual Clauses or the EU-US Data Privacy Framework) where personal data leaves the EEA — is available to platform customers on request (under NDA for enterprise accounts). We tell every platform customer at least 14 days before adding or replacing a sub-processor, and you may object (see our Data Processing Agreement, section 6).
We do not sell your personal data. When personal data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place, such as EU Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework for certified providers, or an adequacy decision by the European Commission. A Transfer Impact Assessment is available on request.
9. How Long We Keep Your Data
We keep your account and platform data — including your brand profiles, audit history, reports and the associated diagnostic and traffic records — for the life of your account, so that you can access your full history at any time. When you close your account we delete it, subject only to the periods below. You can also request earlier deletion of specific data at any time (see Section 11). The periods below are enforced automatically every night.
- Platform account, brand profiles, runs, reports and AI-visibility history — for the life of your account, then deleted on account closure
- Website-visitor signals from a site you connect — for the life of your account; visitor IP addresses are replaced by a scrambled code after 30 days
- Files you upload and the facts drafted from them — until you delete the file, and deleted on account closure
- Support conversations — 12 months, and deleted straight away if you close your account
- Pilot programme applications — at most two (2) years, or until you ask us to delete your application
- Accounts started without registering (a free scan or a purchase started before saving an account) that are never saved — deleted after 30 days, unless a plan was bought with them
- Order and billing records — 7 years (Dutch tax law requirement), held by our payment processor
- Records of your cookie choices — 36 months (a random identifier, your choice and the date; no IP address)
- Records of your agreement to our Terms, Data Processing Agreement and Privacy Policy — for the life of your account
- Email marketing consent records — until consent is withdrawn, plus 1 year for proof of consent
- Website analytics data (farandwide.io) — 26 months
- Publisher and journalist contact details — emails found on cited pages 180 days; a chosen contact 12 months after it was last checked
- Security / platform audit log of events — up to 24 months, including after account closure
After the retention period, data is securely deleted or anonymised.
10. Cookies
9.1. Our website uses cookies — small text files stored on your device — to ensure the website functions properly and to understand how visitors use our site.
Essential cookies are necessary for the website to function (e.g., session management, security). These do not require your consent.
Analytics cookies (from our analytics provider) help us understand how visitors interact with our website. These are only placed after you give your explicit consent via our cookie banner.
Marketing cookies (advertising-platform pixels) are used to measure the effectiveness of our advertising campaigns and to show you relevant ads on social platforms. These are only placed with your explicit consent.
9.2. You can change or withdraw your cookie preferences at any time through Cookie Settings — in the website footer, and in the platform's account menu and footer — or by adjusting your browser settings. We keep a record of each choice (a random identifier, your choice and the date, and your account if you are signed in — no IP address) for 36 months, so we can show what you agreed to.
9.3. For more information about specific cookies we use, see our cookie banner settings.
11. Your Rights Under the GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of access — You can request a copy of the personal data we hold about you.
- Right to rectification — You can ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — You can ask us to delete your data, subject to legal retention obligations.
- Right to restrict processing — You can ask us to limit how we use your data in certain circumstances.
- Right to data portability — You can request your data in a structured, commonly used, machine-readable format.
- Right to object — You can object to processing based on legitimate interest, including profiling. You can object to direct marketing at any time.
- Right to withdraw consent — Where processing is based on your consent, you can withdraw it at any time.
- Right to lodge a complaint — You have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): www.autoriteitpersoonsgegevens.nl.
To exercise any of these rights, please contact us at hello@farandwide.io. We will respond within one (1) month of receiving your request, as required by the GDPR. This period may be extended by two further months if the request is complex, in which case we will inform you.
12. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or destruction. These measures include:
- SSL/TLS encryption for all data in transit
- Encryption at rest for our managed database and compute storage
- Secure, PCI-DSS-compliant payment processing; we never store full card numbers
- Access controls limiting data access to authorised personnel only, with per-user row-level security on the platform database
- An append-only audit log of meaningful platform events
- Regular review of our data processing practices
No method of electronic transmission or storage is 100% secure. In the event of a personal-data breach, we will notify the supervisory authority and, where required, affected individuals in line with GDPR Articles 33-34. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at hello@farandwide.io.
13. AI-Generated Content
On paid plans, the platform produces AI-generated content (text) and site fixes. Content is always delivered as a draft and is published to your site — or, for connected code repositories, merged — only after your review and approval. You perform the editorial review and hold editorial responsibility for anything you publish under your brand. See Section 8a of our Terms & Conditions for how this maps to the EU AI Act transparency rules.
14. Children's Privacy
Our Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.
15. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. We encourage you to read the privacy policy of every website you visit.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Changes take effect upon publication on this page. The "Last updated" date at the top indicates when the most recent changes were made. For material changes, we will notify you by email or a prominent notice on our website.
17. Contact
If you have any questions about this Privacy Policy, wish to exercise your rights, or have a complaint about how we handle your data, please contact us:
- Email: hello@farandwide.io
- Company: Vector Labs B.V., trading as Far & Wide
- KVK number: 99771438
- Address: Gustav Mahlerlaan 647, 1082MK Amsterdam, Netherlands
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): www.autoriteitpersoonsgegevens.nl.
