Adspenta

Legal

Privacy Policy

Last updated: [date] · Version 1.0 · Written to be read, not to be survived.

1. Who is responsible for your data

The controller for the data described here is [Legal entity name, the operator of Adspenta], [Registered address]. You can reach us at hello@adspenta.com.

Where you use Adspenta to manage ad accounts for your own clients, you are the controller of that ad-account data and we act as your processor. The subprocessor list and a Data Processing Agreement are available for your clients' procurement.

2. What we collect

Account and user data

The name and email address of each person on your team who has a login, your agency's name, the tenant they belong to, their role, and the timestamps of their sessions. If you pay us, the billing details needed for that.

Ad account data, read through the Meta and Google APIs

Only what is needed to notice that something is drifting and to propose a fix:

  • Structure. Campaigns, ad sets, ads, their names, status and schedules.
  • Budgets. Daily and lifetime budgets, bid settings, and their history.
  • Performance metrics. Spend, impressions, clicks, results, cost per result, frequency and click-through rate, aggregated by day.
  • Creatives. Ad-level metadata and delivery figures, so creative fatigue can be detected.
  • Account state. Disapprovals, delivery limits, learning-phase status.

We do not receive, request or store individual-level data about the people who see or click your clients' ads. Adspenta reads aggregate ad-account reporting. It has no customer lists, no audience members, no personal data of end consumers.

Usage and audit logs

What happened in the product: reads, findings, proposals, approvals, declines, take-backs, executions, verifications, blocked actions, logins and operator access. These carry a timestamp and the person responsible, and they are append-only.

3. Why, and on what legal basis

WhatWhy, and the basis under the GDPR
Account and user dataTo give your team logins and run the service you asked for. Performance of a contract (Art. 6(1)(b)).
Ad account dataTo read, detect, propose, execute what you approve, verify and report. Performance of a contract, and for your clients' data, on your instructions as processor.
Audit ledger and access logSo every change and every access can be accounted for afterwards, by you and by your clients. Legitimate interest (Art. 6(1)(f)) in an accountable, non-repudiable record, and a contractual promise we make to you.
Billing recordsInvoicing and tax. Legal obligation (Art. 6(1)(c)).
Security and error logsKeeping the service up and finding abuse. Legitimate interest (Art. 6(1)(f)).

We do not sell data, we do not run advertising of our own on it, and we do not use one customer's data to improve anything another customer sees.

4. How long we keep it

CategoryRetention
Ad account dataWhile the account is connected, and deleted within 30 days of disconnection, termination, or a deletion request.
Proposals, findings, reportsSame as above: deleted within 30 days.
Account and user dataWhile you have an account, and deleted within 30 days of closing it.
Audit ledger and access logRetained, anonymised. Your account and user data are stripped out and the record that an action happened remains. See data deletion.
Billing recordsAs long as tax law requires, then deleted.
BackupsRolling, encrypted, overwritten within 30 days.

5. Where it is stored

In the European Union. The service runs on infrastructure operated by Hetzner Online GmbH, primarily in Helsinki, Finland, with Germany as the secondary region. Backups are encrypted and stored off the machine that produced them.

Requests to Anthropic's language models are the one processing step that may be performed outside the EU; what is sent is described below and in the subprocessor list.

International transfers

One transfer leaves the European Economic Area: language-model requests to Anthropic PBC, in the United States. The lawful basis for that transfer is [to confirm: Standard Contractual Clauses under Commission Decision 2021/914, and reliance on the EU-US Data Privacy Framework where the receiving entity is certified]. The transfer mechanism actually signed will be named here, with its date, before the entity starts trading.

What crosses the border is a snapshot of ad-account metrics, described in section 6. It contains no personal data of end consumers, because we do not hold any. Everything else stays on EU infrastructure.

6. Who else processes it

We use a small number of subprocessors, listed in full and dated on the subprocessors page:

  • Hetzner Online GmbH. Hosting and infrastructure, Finland and Germany.
  • Anthropic PBC. Language-model requests. What is sent is a snapshot of ad-account metrics: campaign names, budgets, spend, results and the other figures you can see on your own screen, so the model can explain them or draft an update. No personal data of end consumers is sent, because we do not hold any. The model cannot call the ad platforms and cannot execute anything.
  • [email provider, to be chosen] for transactional email, once chosen.
  • [backup storage, to be chosen] for off-site encrypted backups, once chosen.

We will name each of these here before it starts processing anything, and the subprocessor page carries the date of every change.

7. Platform data from Meta and Google

Data obtained through the Meta and Google advertising APIs is used only to provide this service to you: to read your accounts, detect problems, propose changes, execute the ones you approve, verify them, and report on them.

We do not sell it. We do not share it with advertisers or data brokers. We do not use it to build, enrich or target audiences for anyone. We do not combine one customer's platform data with another's. We do not use it to train models.

Access tokens are encrypted at rest and bound to the connection they belong to. Disconnecting an account revokes the token with the platform and deletes our copy.

8. How we protect it

  • Each agency's data is separated in the database itself, by row-level security, so a query that forgets to filter returns nothing rather than someone else's data.
  • Platform access tokens are encrypted and bound to their connection.
  • Data is encrypted in transit, and backups are encrypted at rest.
  • Our own staff have no route to your campaign data; the access an operator does have is logged and shown to you.
  • Two independent security audits have looked at all of the above; the findings are in the changelog.

The plain-English version, with more detail, is on the security page.

9. Cookies and tracking

This marketing site sets no cookies. It loads no analytics, no advertising pixels, no tag manager, no social or video embeds, no chat widget and no third-party fonts: the two typefaces are served from this domain. Nothing on these pages reports your visit to anyone else.

The product sets one cookie. When you sign in at app.adspenta.com, a single strictly necessary session cookie keeps you signed in. It holds a session identifier and nothing else. It is not used for analytics, profiling or advertising, and it is not shared with anyone.

There is no consent banner, on purpose. Consent under the ePrivacy rules is required for cookies that are not strictly necessary for a service you asked for. We do not set any, so there is nothing to ask you about, and a banner asking you to agree to nothing would be theatre.

If that ever changes, the non-essential cookie will be named here first, it will be off until you turn it on, and the site will ask before it is set.

10. Your rights

If you are in the EU or the UK you have the right to ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, and to have it sent to another provider in a portable form. Where we rely on legitimate interest, you can object and we will either stop or explain why we cannot.

Write to hello@adspenta.com. We answer within 30 days. Deleting an account is described step by step on the data deletion page.

If you are unhappy with how we have handled it, you have the right to lodge a complaint with a supervisory authority. You may complain to the authority in the EU country where you live or work, or where you think the problem happened. Ours will be the Romanian authority, the National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, telephone +40 318 059 211, dataprotection.ro. It becomes our lead authority once the operating entity is registered in Romania, which is [pending: entity not yet registered].

11. Contact, and whether we have a DPO

We are not required to appoint a Data Protection Officer, and we have not appointed one. Rather than leave that unsaid: privacy questions go to hello@adspenta.com and are answered by the people who built the system, not by a ticket queue.

Postal address for formal notices: [Legal entity name and registered address].

Version history

VersionDate and what changed
1.0[date]. First published version.