This policy explains how Advertify processes user personal data in compliance with Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll. on personal data processing.
1. Data controller
The data controller is:
- Ondřej Brabec, self-employed individual (OSVČ)
- Business ID (IČO): 19356382
- Registered seat: Bolevecká 1409/6, 301 00 Plzeň, Czech Republic
- E-mail: podpora@advertify.cz
The controller has not appointed a Data Protection Officer (DPO) as it is not required to do so under GDPR.
2. Categories of data processed
In connection with use of the Service, we process the following categories of personal data:
- Registration data: e-mail address, password (stored hashed), name, company name.
- OAuth tokens: access and refresh tokens for connected Meta Ads and Google Ads accounts (stored encrypted). The Service uses these tokens to connect to your ad accounts and read data about campaigns, ads and metrics. The Service does not perform any write operations (it does not manage, pause or modify campaigns) without your explicit consent.
- Ad account data: identifiers and names of connected accounts, campaign performance metrics.
- Billing data: processed by Stripe (Business ID, billing address, payment history); we only access metadata.
- Operational and analytical data: login logs, IP address, browser type, in-app behaviour for diagnostics and improvement.
- Communications: content of e-mail or chat communication with support.
3. Purposes and legal bases of processing
- Service provision (sign-in, data sync, dashboard), legal basis: performance of contract (Art. 6(1)(b) GDPR).
- Payment processing and invoicing, performance of contract and legal obligation (Czech Acts No. 235/2004 and 563/1991).
- Operational communication (registration confirmation, alerts, billing), performance of contract.
- Marketing communication (newsletters, tips), consent, which can be withdrawn at any time.
- Service improvement and error diagnostics, legitimate interest of the controller (Art. 6(1)(f) GDPR).
- Compliance with legal obligations (accounting, tax, responses to authorities), legal obligation.
4. Recipients and third-party processors
To operate the Service we use vetted sub-processors that provide adequate data-protection guarantees:
- Supabase, Inc. (US / EU regions), database hosting, authentication, edge functions. Privacy: https://supabase.com/privacy
- Stripe Payments Europe, Ltd. (Ireland), payment processing. Privacy: https://stripe.com/privacy
- Anthropic PBC (US), AI interface (Claude API) for generating AI recommendations. Privacy: https://www.anthropic.com/legal/privacy
- Google LLC (US / EU), Google Ads API and Google OAuth. Privacy: https://policies.google.com/privacy
- Meta Platforms Ireland Ltd. (Ireland), Meta Marketing API and Facebook OAuth. Privacy: https://www.facebook.com/privacy/policy
- Lovable AB (Sweden), development and hosting platform. Privacy: https://lovable.dev/privacy
- Resend, Inc. (US), transactional e-mail delivery. Privacy: https://resend.com/legal/privacy-policy
We do not sell personal data to third parties. Data obtained from Google or Meta APIs is not used for ad targeting, retargeting or sale to data brokers.
Handling of Google User Data
Advertify obtains and processes data from the Google Ads API within the scope of permissions the user grants during OAuth authorization. Use and transfer of this data is governed by the Google API Services User Data Policy, including the Limited Use requirements.
Which Google OAuth scopes we request
Advertify requests the following Google OAuth scope:
- https://www.googleapis.com/auth/adwords, access to the user's Google Ads data. This scope allows reading, editing, creating and deleting data in the user's Google Ads account.
What Google data we process and what we do with it
- Reading data, performance metrics of campaigns, ad groups and ads (spend, conversions, clicks, impressions, CTR, CPC, ROAS), ad creative content (headlines, descriptions), identifiers and names of connected accounts.
- Campaign changes (write operations), based on the user's explicit consent, Advertify may perform changes in the user's Google Ads account: pausing and reactivating campaigns and ads, editing budgets, editing targeting, creating new campaigns and ads, deleting campaigns and ads. Every such operation requires explicit user confirmation before it is executed.
- OAuth tokens, access and refresh tokens stored encrypted in the database.
- Profile data, email address and basic profile information used to identify the account.
Sub-processors who receive Google data
- Supabase, Inc., database hosting where Google data is stored. (https://supabase.com/privacy)
- Anthropic PBC, AI model provider (Claude API). Selected campaign metadata is sent to generate AI recommendations and change suggestions. Anthropic does not use the data to train its AI models. (https://www.anthropic.com/legal/privacy)
- Resend, Inc., sending transactional emails. Resend does NOT receive any Google Ads data, only email addresses for notifications. (https://resend.com/legal/privacy-policy)
Limited Use, what we do NOT do with Google data
In accordance with the Google API Services User Data Policy, Advertify commits to the following restrictions:
- We do not use Google user data to serve ads to users.
- We do not sell Google user data to third parties, data brokers, or advertising networks.
- We do not use Google user data for ad targeting or retargeting outside the scope of the application's features.
- We do not use Google user data to train or improve generalized AI/ML models, neither ours nor those of our sub-processors.
- We do not use Google user data for any purpose other than providing user-facing features of the application (campaign analysis, AI recommendations, campaign management with user consent, reporting, notifications).
- Human access to Google user data is limited to: (a) operations performed with user consent, (b) security purposes (investigating abuse, security incidents), (c) complying with legal obligations, (d) processing aggregated anonymized data for internal operations.
How we protect Google data
- OAuth tokens are stored encrypted in the database.
- All data transfer happens over HTTPS/TLS.
- Access to data is protected by Row Level Security (RLS) at the database level.
- Changes to the Google Ads account (write operations) require explicit user confirmation before execution.
- Production access to data is restricted and logged.
Your rights regarding Google data
- Revoke Advertify's access at any time in your Google account settings: https://myaccount.google.com/permissions
- Disconnect the linked Google Ads account in Settings → Connected accounts inside the Advertify app.
- Request deletion of all data by emailing podpora@advertify.cz, data will be deleted within 30 days.
Use of Google user data by Advertify is governed by the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
5. Retention period
- Active account data: for the duration of the contractual relationship.
- After account deletion: data and OAuth tokens are deleted within 30 days at the latest.
- Accounting and invoicing documents: 10 years as required by Czech accounting and VAT law.
- Security logs: maximum 90 days.
- Marketing consent: until consent is withdrawn, no longer than 5 years from last activity.
6. Your rights under GDPR
As a data subject you have the following rights:
- right of access to personal data (Art. 15 GDPR);
- right to rectification of inaccurate data (Art. 16 GDPR);
- right to erasure ("right to be forgotten", Art. 17 GDPR);
- right to restriction of processing (Art. 18 GDPR);
- right to data portability in a machine-readable format (Art. 20 GDPR);
- right to object to processing based on legitimate interest (Art. 21 GDPR);
- right to withdraw consent at any time (where processing is based on consent);
- right to lodge a complaint with the Czech supervisory authority, Office for Personal Data Protection (www.uoou.cz).
We handle requests without undue delay, and in any case within 30 days of receipt.
7. Cookies
The Service uses only necessary and functional cookies. Details are available in our separate Cookies Policy at /cookies.
8. International data transfers
Some of our processors (Supabase, Stripe, Anthropic, Google, Meta, Resend) may process data outside the European Economic Area, in particular in the United States. Such transfers are always carried out under appropriate GDPR safeguards, typically EU Standard Contractual Clauses or EU-U.S. Data Privacy Framework certification.
9. Security and breach notification
We adopt appropriate technical and organizational measures to protect personal data, encryption in transit (TLS) and at rest, controlled access, separation of production environments, regular backups and Row Level Security at the database layer.
In the event of a personal data breach posing a risk to the rights and freedoms of natural persons, we will notify the supervisory authority (ÚOOÚ) without undue delay, and where feasible within 72 hours. If the breach poses a high risk, we will also notify affected users directly by e-mail.
10. Automated decision-making and profiling
The Service uses AI recommendations (Claude API) to generate textual advice for campaign optimization. This does not constitute automated decision-making with legal effects within the meaning of Art. 22 GDPR, all recommendations are informational only and the final decision always rests with the user.
11. Changes to this Privacy Policy
This policy may be updated from time to time. Material changes will be communicated by e-mail or in-app notice. The current version is always available at advertify.cz/privacy.
Contact
For data protection queries, requests for access, deletion or portability, please contact us at podpora@advertify.cz.