Privacy Policy
RocketCode values your privacy. Below we explain which personal data we process, why, who we share it with and what rights you have. We process data in accordance with the General Data Protection Regulation (GDPR). Last updated: 24 June 2026.
1. Who we are
The data controller responsible for the processing is:
- RocketCode B.V.
- Gouwzee 3B, 3891 GH Zeewolde, the Netherlands
- Chamber of Commerce (KvK) number: 81418574
- Email: [email protected]
- Phone: +31 85 212 77 14
For privacy-related questions you can contact us at [email protected].
2. No cookies or tracking
This privacy policy applies to our entire website, including rocketcode.io and the ai.rocketcode.io subdomain. Our website places no cookies and contains no tracking scripts or analytics tags in your browser. We do not track your behaviour and therefore do not show a cookie banner.
The landing pages on ai.rocketcode.io process data exclusively server-side. This means no tracking runs in your browser: only when you submit a form yourself do we receive and process the data you entered on our own server (see below).
3. What data we process
Data you provide via a form
When you complete a contact or request form on our website (for example the AI Opportunity Scan), we process the data you provide. This may include:
- Name
- Company name
- Website
- Email address
- Phone number
- The content of your question or message (for example what you want to use AI for)
Data via LinkedIn ads (Lead Gen Forms)
If you respond to one of our LinkedIn ads through a built-in form (Lead Gen Form), we receive the data you submit through that LinkedIn form, typically your name, business email address, company name, job title, optionally your phone number and your answer to our question. For those forms LinkedIn is itself a data controller; please see LinkedIn's privacy policy for how they handle your data.
Campaign and attribution data
To measure which ad or campaign led to a request, when you submit a form we read a click identifier from the URL server-side, where present: the Google click ID (gclid), the LinkedIn click ID (li_fat_id) and any UTM campaign labels (source, medium, campaign). We link this data to your request for campaign analysis. We do not place any cookies for this purpose.
4. Purposes and legal bases
We process your data for the following purposes, with the corresponding legal basis under the GDPR:
- Handling your request or question and contacting you. Legal basis: performance of or steps prior to a contract, and our legitimate interest in responding to your request.
- Delivering the agreed services. Legal basis: performance of the contract.
- Measuring and improving the effectiveness of our advertising campaigns. Legal basis: legitimate interest (efficient marketing).
- Complying with legal obligations (for example record-keeping). Legal basis: legal obligation.
5. Who we share data with
We do not sell your data. We do engage service providers (processors) that process data on our behalf, under a data processing agreement:
- Hosting: our servers and data are located within the EU by default.
- Notion (Notion Labs, Inc.): our CRM in which we record requests and contact details.
- Slack (Slack Technologies / Salesforce): internal notification of a new request.
- Google Ads (Google Ireland Ltd.): for conversion measurement we pass only the click ID (gclid), the conversion name and the timestamp. No personal data such as name or email is sent.
- LinkedIn (LinkedIn Ireland): for advertising and, in the case of Lead Gen Forms, collecting your request.
Some of these parties are based outside the European Economic Area (in particular in the United States). For such transfers we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
6. How long we keep data
We do not keep your data longer than necessary for the purposes set out above. Requests that do not result in a collaboration are kept for a maximum of 24 months after the last contact. Data related to an assignment or to our records is kept for as long as necessary and as long as statutory retention periods require (a 7-year retention obligation applies to financial records).
7. Security
We take appropriate technical and organizational measures to protect your data. Traffic with our website is encrypted via HTTPS, access to data is limited to those who need it, and sensitive settings and keys are stored in a protected manner.
8. Your rights
You have the right to access, rectify or erase your personal data. You can also object to the processing, ask us to restrict the processing, and receive the data you provided yourself in a commonly used format (data portability). Send your request to [email protected]. We will respond within the statutory period of one month.
If you disagree with how we handle your data, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via autoriteitpersoonsgegevens.nl.
9. Changes
We may update this privacy policy. The most current version is always available on this page, with the date of the last change shown at the top.