Privacy policy
What we do with
your data.
Last updated: 1 August 2026
Privacy policy
This Privacy Policy explains how Bleep Digital, Tomi Toth s.p. ("Bleep Digital", "we", "us", "our") collects, uses, and protects personal data, and how we handle data accessed through Google APIs. It applies to our website at bleep-digital.com and to the services we provide to our clients.
1. Who we are (Data Controller)
Bleep Digital, poslovno svetovanje, Tomi Toth s.p.
Dekani 151, 6271 Dekani, Slovenia
Tax number (davčna številka): 44043597
Registration number (matična številka): 9000305000
Contact: info@bleep-digital.com
Or via the contact form.
For any question about this policy or your personal data, contact us using the details above.
2. What data we collect
a) Information you give us directly. When you contact us through our website form, we collect the information you provide — typically your name, the contact details you choose to share, and the content of your message. We use this only to respond to you and to discuss providing our services.
b) Information collected automatically. When you visit our website, limited technical data may be collected (such as IP address, browser type, device information, and pages visited) through cookies and similar technologies. See our Cookie Policy for details and for how to manage your preferences.
c) Data we process on behalf of clients (Google API data). When providing analytics, search, and advertising services to our clients, we access certain data through Google APIs, with the client's authorization. This is described in Section 4.
3. How we use your data and our legal basis (GDPR)
We process personal data under the EU General Data Protection Regulation (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2). We rely on the following legal bases:
- To respond to enquiries and provide services — performance of a contract, or steps taken at your request before entering a contract (Art. 6(1)(b) GDPR).
- To operate and secure our website — our legitimate interest in running and protecting our site (Art. 6(1)(f) GDPR).
- For non-essential cookies and analytics — your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
- To meet legal and accounting obligations — compliance with a legal obligation (Art. 6(1)(c) GDPR).
We do not sell your personal data, and we do not use it for advertising to you.
4. Google API data — access, use, and Limited Use
To deliver analytics, search-performance, and advertising services to our clients, our application accesses data from Google services only with the relevant account owner's explicit authorization, granted through Google's standard OAuth consent process. The account owner can revoke this access at any time via their Google Account security settings (myaccount.google.com/permissions).
Google services and scopes we may request:
- Google Search Console API (read-only) — to retrieve search-performance data (queries, impressions, clicks, positions) for websites the account owner controls, for reporting and optimization.
- Google Analytics API (read-only) — to retrieve website traffic and engagement metrics for reporting and analysis.
- Google Ads API (read and write) — to retrieve advertising performance data and, where the account owner authorizes it, to help create, review, and manage advertising campaigns on their behalf.
- Google Merchant Center / Content API for Shopping (read and, where authorized, write) — to retrieve and manage product and shopping-campaign data for clients who use Merchant Center.
How we use Google user data. We use data obtained through Google APIs solely to provide and improve the specific services requested by the account owner — namely reporting, analysis, search and advertising optimization, and campaign management. We access only the data needed for those purposes.
Limited Use commitment. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide or improve the user-facing features that are prominent in our application's requested experience.
- We do not transfer or sell Google user data for advertising, marketing, or other purposes, and do not use it for serving ads.
- We do not allow humans to read Google user data unless: (i) we have the account owner's explicit consent for specific data; (ii) it is necessary for security purposes (e.g. investigating abuse); (iii) it is necessary to comply with applicable law; or (iv) the data has been aggregated and anonymized.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
Processing tools. To deliver these services, authorized Google data is processed within secure third-party AI-assistant and analysis tools that we use to operate our business — currently Anthropic's Claude. We may use comparable tools from other established providers in future. In all cases, such processing is limited to delivering the client's requested service and is subject to the Limited Use commitments above — including that Google user data is never used to train or improve AI or machine-learning models.
5. How we share data
We do not sell personal data. We share it only:
- with service providers who help us operate (e.g. hosting, and the tools used to deliver client services), bound to protect it and use it only on our instructions;
- where required by law or to protect our legal rights;
- with the client on whose behalf we process their own Google data.
6. International transfers
Our website and the client websites we host are hosted within the European Union (with IONOS, in Germany), so hosting does not involve a transfer of data outside the European Economic Area. Where a specific service provider processes data outside the EEA — for example an AI-assistant tool based in the United States — we ensure an appropriate safeguard is in place, such as the European Commission's Standard Contractual Clauses or an adequacy decision. We review these safeguards as our tooling providers are confirmed.
7. How long we keep data
We keep personal data only as long as necessary for the purpose it was collected: enquiry data for as long as needed to handle your request and any resulting relationship; accounting records for the period required by Slovenian law; and Google API data only for as long as needed to provide the client's service, or until access is revoked.
8. Your rights (GDPR)
You have the right to access, correct, delete, or restrict processing of your personal data; to object to processing; to data portability; and to withdraw consent at any time. To exercise these rights, contact us using the details in Section 1. You also have the right to lodge a complaint with the Slovenian supervisory authority, the Information Commissioner (Informacijski pooblaščenec), www.ip-rs.si.
9. Data security
We take reasonable technical and organizational measures to protect personal data against loss, misuse, and unauthorized access, including secure hosting, restricted access, and encryption in transit.
10. Changes to this policy
We may update this policy from time to time. The current version is always available at bleep-digital.com, with the "last updated" date shown above.
Not legal advice. This is a submission-ready draft; have it reviewed before relying on it long-term.