01
Controller
TODO: Insert the legal entity acting as data controller, its registered address, registration details and privacy contact.
Customer organisations may act as controllers for campaign, customer or advertising data they submit to a workspace.
02
Data we collect
Depending on the features used, we process account data, workspace content, approved website sources, advertising platform information, campaign artefacts and technical records.
03
Account information
- Name and work email
- Password hash and authentication records
- Workspace memberships and roles
- Access, reset and security events
04
Website and project data
The service processes website URLs and approved page content, business briefs, evidence, business profiles, customer-avatar hypotheses, campaign strategy, creative and approvals supplied or generated within a workspace.
05
Advertising platform data
When a Meta account is connected, the service may process permitted business assets, ad-account identifiers, Page or Instagram identities, datasets, campaign objects, status, insights and delivery records.
06
Technical information
Security and operational logs may include timestamps, request metadata, device or browser information, job status, provider responses, error summaries and pseudonymous identifiers.
07
Purposes of processing
- Provide accounts, workspaces and requested campaign workflows
- Connect authorised providers and advertising assets
- Generate, validate, publish and measure campaign materials
- Protect the service, prevent abuse and troubleshoot failures
- Maintain auditability, data quality and user preferences
08
Legal bases
TODO for privacy counsel: Map each processing purpose to the appropriate legal basis, including contract, legitimate interests, consent and legal obligations, for the jurisdictions served.
09
Processors
The service may use hosting, database, storage, email, model, media and advertising-platform providers. TODO: Insert the approved processor list and links to current subprocessors.
10
International transfers
TODO: Document transfer locations, adequacy decisions, contractual safeguards and supplementary measures after provider and hosting regions are final.
11
Retention
Retention depends on the data category, workspace policy, legal requirements and operational need. The product supports retention rules, restricted-data deletion and audit-preserving tombstones where appropriate. TODO: Insert the customer-facing retention schedule.
12
Security
Controls include scoped access, protected sessions, encrypted provider credentials, restricted-data encryption, audit logging and isolated workspaces. No system can guarantee absolute security.
13
Your rights
Depending on applicable law, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, withdraw consent and complain to a supervisory authority. TODO: Insert the request channel and response procedure.
15
Third-party services
Connected services process data according to their own privacy notices and your account configuration. Only connect providers and assets you are authorised to use.
16
Changes
We will update the date above and provide additional notice where a material policy change requires it.
17
Contact
TODO: Insert the privacy contact, data-protection contact if applicable and supervisory-authority information.