Surfaced ("we", "us", "our") is a product of EXPX, registered in the Netherlands. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Dutch data protection law.
Last updated: 28 March 2026
EXPX is the data controller for the personal data processed through getsurfaced.ai. For questions about this policy or your data, contact us at privacy@getsurfaced.ai.
When you sign up, we collect:
When you use our platform, we collect:
When you submit a contact inquiry, we collect:
Payments are processed by Stripe. We do not store credit card numbers. Stripe acts as an independent data controller for payment data. See Stripe's Privacy Policy.
We process your data under the following GDPR legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing the service (account, scans, content) | Contract performance (Art. 6(1)(b)) |
| Processing payments | Contract performance (Art. 6(1)(b)) |
| Analytics cookies (GA4, PostHog) | Consent (Art. 6(1)(a)) |
| Marketing cookies (Google Ads, LinkedIn) | Consent (Art. 6(1)(a)) |
| Responding to contact inquiries | Legitimate interest (Art. 6(1)(f)) |
| Security, fraud prevention | Legitimate interest (Art. 6(1)(f)) |
We share data with the following processors, all under appropriate safeguards:
| Processor | Purpose | Location |
|---|---|---|
| Supabase (AWS) | Database, authentication | EU (Frankfurt) |
| Vercel | Hosting, edge functions, analytics | Global CDN (US entity, SCCs) |
| Stripe | Payment processing | US (SCCs + DPF) |
| Google (GA4, Ads, GTM) | Analytics, advertising | US (DPF certified) |
| PostHog | Product analytics | EU (Frankfurt) |
| Advertising conversion tracking | US (SCCs) | |
| Upstash | Background job queue, caching | EU (Frankfurt) |
| OpenAI / OpenRouter | AI content generation | US (DPA in place) |
For US-based processors, we rely on EU-US Data Privacy Framework (DPF) certification and/or Standard Contractual Clauses (SCCs) as the legal transfer mechanism under GDPR Chapter V.
As an EU/EEA data subject, you have the right to:
To exercise any of these rights, email privacy@getsurfaced.ai. We will respond within 30 days.
When you first visit our site, a cookie consent banner appears with three options:
You can change your preferences at any time via the "Cookie Settings" link in the website footer. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
We use Google Consent Mode v2 to ensure that analytics and advertising tags respect your choices in real time.
We protect your data through:
Surfaced is not intended for use by anyone under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will delete it promptly.
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
We may update this policy from time to time. Material changes will be communicated via email or a notice on our platform. The "Last updated" date at the top reflects the most recent revision.
Questions? Contact us at privacy@getsurfaced.ai or visit our contact page.