Privacy Policy
What personal data Katla collects, why we hold it, who else ever sees it, and how to get it back or have it deleted.
Who We Are
Katla ("we", "us", "our") operates the website katla.app, the Katla console, and the API, SDK, widget, CLI and MCP server that go with it. This policy explains what personal data we collect, why we collect it, who we share it with, and what you can ask us to do with it.
For your own account and the data you give us about your sites, we are the data controller. For the consent records your visitors leave through Katla on your websites, you are the controller and we are your processor: we handle that data on your instructions, under the Terms of Service, and for no purpose of our own.
Data We Collect
We collect the following categories of personal data:
- Account data — your name, email address and profile picture URL, received from our identity provider when you sign in. If you sign in with a Google account, that name, email address and profile picture come from Google.
- Team data — the teams you belong to, your role in them, and invitations you send or accept.
- Site and scan data — the domains you add, the ownership-verification records you place, and everything a scan finds on them: cookies, trackers, tags and page metadata.
- Consent records — the choices your website visitors make, together with a timestamp and the data needed to evidence the choice. Collected on your behalf, as your processor.
- Billing data — your plan, subscription status and invoices. Card details are entered with our payment processor and never reach our servers.
- Support and contact data — what you write to us through the contact form or by email, so we can reply.
- Technical logs — IP address, user agent and request metadata, kept briefly to keep the service running and to investigate abuse and errors.
- Integration data — what a connected third-party account exposes to us, described for Google in sections 05 to 08 below.
How We Use Your Data
We use personal data only to:
- Provide the service — run scans, classify what they find, generate policies, record consent and show it all back to you.
- Authenticate you and keep your account and team memberships secure.
- Bill you, if you are on a paid plan, and send the receipts and dunning notices that go with it.
- Send service email you cannot reasonably opt out of, such as security notices, and onboarding email you can unsubscribe from at any time.
- Answer support requests and reply to what you send us.
- Keep the service available and safe — rate limiting, abuse and fraud prevention, debugging and capacity planning.
- Meet legal, accounting and audit obligations.
Legal Basis for Processing
We rely on the performance of a contract (Article 6(1)(b) GDPR) to run your account and deliver the service, on our legitimate interests (Article 6(1)(f) GDPR) to keep the service secure and to improve it, on your consent (Article 6(1)(a) GDPR) for non-essential cookies and for connecting a third-party account such as Google Tag Manager, and on legal obligation (Article 6(1)(c) GDPR) where the law requires us to keep records.
Where we act as your processor for visitor consent records, the legal basis for that processing is yours to determine as the controller.
Google User Data We Access
Katla accesses Google user data in one place only: the optional Google Tag Manager installation, which you start yourself from the Install page of a site and which does nothing until you complete Google’s consent screen. If you never connect Google Tag Manager, Katla accesses no Google user data at all.
When you do connect it, we request these OAuth scopes and access exactly the data each one covers:
| Scope requested | Google user data this gives us access to |
|---|---|
| tagmanager.readonly | The names and IDs of your Tag Manager accounts, the web containers in the account you pick (name, container ID, public GTM-XXXXXX ID and configured domains), and the workspaces in the container you pick. |
| tagmanager.edit.containers | Permission to create, update and delete the single Custom HTML tag Katla installs in the workspace you pick, and to read back its ID. |
| tagmanager.edit.containerversions | Permission to create a container version from that workspace, and to read back its version ID. |
| tagmanager.publish | Permission to publish that version, which we do only if you tick the publish option on the last step of the wizard. |
| openid, email | The email address of the Google account that authorised the connection, read from the ID token Google returns. |
How We Use Google User Data
Google user data is used solely to perform the installation you asked for, and for nothing else. Specifically:
- Your account, container and workspace lists are used to render the picker in the install wizard so you can choose where the tag goes.
- The chosen account, container and workspace IDs are used to write one Custom HTML tag named "Katla consent", fired by Tag Manager’s built-in Consent Initialization – All Pages trigger so that consent defaults are set before any analytics or advertising tag runs. Nothing else in your container is read, changed or removed.
- The tag, trigger and version IDs Google returns are stored so that a later update or disconnect changes exactly what Katla created and leaves the rest of your container untouched.
- A container version is created, and published, only when you choose to publish from the wizard.
- The Google account email address is stored and shown in the console as a label, so you can tell which Google account a connection belongs to. It is never used to authenticate you or to authorise anything.
- The refresh token Google issues is stored encrypted with AES-256-GCM and used only to mint a short-lived access token when one of the actions above needs it. The access token itself is never stored.
Who We Share Google User Data With
We do not sell Google user data, we do not share or transfer it to any third party for advertising, analytics, profiling, credit assessment or lending purposes, and we do not use it to train, retrain or improve any artificial intelligence or machine learning model, whether our own or anyone else’s.
Google user data is transmitted back to Google’s own Tag Manager API to carry out the actions you asked for, and is otherwise disclosed only to:
- Our hosting and database provider, which stores the encrypted connection record on our behalf as a sub-processor and makes no other use of it.
- Katla personnel, and only where it is necessary to operate the service, investigate a security issue, or handle a support request you raised — and only for as long as that task requires.
- A competent authority, where disclosure is required by law and the request is valid; we will tell you unless we are legally barred from doing so.
Katla’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Keeping and Deleting Google User Data
Google user data is kept only while the connection exists. Disconnecting Google Tag Manager from the Install page removes the tag and trigger Katla created, revokes the refresh token with Google, and deletes the connection record — the account, container, workspace, tag and version IDs and the stored Google email address — from our database. Deleting the site or your account does the same.
You can also revoke Katla’s access at any time from your Google Account’s permissions page at myaccount.google.com/permissions. Doing so stops all further access immediately; ask us at privacy@katla.app if you also want the connection record removed on our side.
International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area. Where that happens, we rely on an adequacy decision or on Standard Contractual Clauses together with the additional safeguards those clauses require.
Data Retention
We keep personal data only as long as it is needed for the purpose it was collected for. Account, team and site data is kept while your account is open. Consent records are kept for as long as you keep them, since evidencing consent is the point of holding them, and are deleted when you delete them or close your account. Billing records are kept for as long as tax and accounting law requires. Technical logs are kept briefly. Google connection data follows section 08.
After you close your account we retain your data for a short period so you can export it, and then delete or anonymise it.
Data Security
We apply appropriate technical and organisational measures: encryption in transit, encryption at rest for credentials and third-party tokens, scoped access controls, least-privilege access for personnel, and audit logging of administrative actions. No system is perfectly secure, but we will notify you and the relevant supervisory authority of a personal data breach where the law requires it.
Your Rights
Under GDPR and comparable laws you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting processing already carried out. Under the CCPA/CPRA you additionally have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing — we do not sell or share personal data as those terms are defined.
Write to privacy@katla.app to exercise any of these rights. We reply within one month. If you are unhappy with our answer you may complain to your local data protection authority.
Children’s Privacy
Katla is a business tool and is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.
Changes to This Policy
We may update this policy to reflect changes to the service or to the law. Material changes are announced in the console or by email, and the effective date at the top of this page always tells you which version you are reading. Previous versions are available on request.
Contact
Questions about this policy, or about the personal data we hold: privacy@katla.app. Our Data Protection Officer can be reached at dpo@katla.app.