Skip to main content

Privacy Policy

Last updated: August 24, 2026

At Adverizeo, we are committed to protecting your privacy and ensuring transparency in how we collect, use, and safeguard your personal information. This Privacy Policy explains our practices when you use our AI-powered advertising platform ("Service"), designed to align with the General Data Protection Regulation (GDPR), the ePrivacy Directive, and other applicable data protection laws.

1. Controller Information

The data controller for your personal information is:

Adverizeo

Email: privacy@adverizeo.com

2. What Personal Information We Collect

We collect the following categories of personal information:

Identifiers and Contact Information

  • Name, email address, phone number
  • Postal address, company name, job title

Commercial and Transaction Information

  • Payment and billing details (processed securely via Stripe; we do not store full card numbers)
  • Subscription plan, license details, and transaction history
  • Eligibility information (e.g., SME verification)

Professional and Demographic Information

  • Occupation, job function, expertise
  • Company details (size, industry) — inferred from company name or provided directly

Analytics and Electronic Network Activity

  • IP address, browser type, device ID, operating system
  • Pages visited, time spent, features used
  • Referral source (e.g., search engine, ad campaign)
  • Cookies and similar tracking technologies (see our Cookie Policy)

User-Generated Content and Inputs

  • Brand descriptions, product details, ad prompts (text, images)
  • Generated ad content, campaign settings, audience segments
  • Metadata (e.g., timestamps, file types)

Sensitive Personal Information (Where Required)

We do not intentionally collect sensitive data (e.g., race, health, biometrics). However, if your inputs include such data, we will:

  • Process it only as instructed by you (as Controller)
  • Delete it when no longer needed
  • Seek consent where legally required

3. How We Use Your Information

We process your personal information for the following purposes and legal bases under GDPR:

PurposeLegal Basis (GDPR Art. 6)
Provide and operate the ServicePerformance of contract
Process payments and billingPerformance of contract
Respond to support requestsLegitimate interests
AI model training on your contentConsent (opt-in only — off unless you enable it)
Send service-related communicationsLegitimate interests
Marketing (newsletters, offers)Consent (opt-in)
Detect fraud, abuse, or security threatsLegitimate interests / Legal obligation

4. How We Analyze Your Content to Deliver Features

Our AI tools analyze your content (e.g., product descriptions, images) to generate multilingual, compliant ads. This includes:

  • Text analysis for tone, keywords, and language translation
  • Image recognition to suggest ad layouts (no facial recognition or biometrics used)
  • Automated compliance checks (e.g., GDPR, advertising standards)

This analysis is a core part of how the Service generates ads for you and cannot be selectively disabled while still using those features. It does not include facial recognition or biometric analysis. Separately, and unlike this content analysis, we do not use your Input Data or Generated Content to train AI models unless you explicitly opt in to that specific use — see Section 8 of our Terms of Service.

5. Client Reporting and Aggregate Ad-Performance Benchmarking

Agencies and marketers using our AI Client Report feature can upload ad performance exports (e.g., Meta, LinkedIn, Google Ads CSV files) for their own end-clients to generate branded reports and AI-assisted commentary. These uploads are aggregate account metrics — spend, impressions, clicks, conversions — not individual personal data about anyone the ads reached.

By default, an end-client's uploaded metrics are used only for that end-client's own report. Separately, and only where the agency has explicitly opted a specific end-client in, that end-client's anonymized, aggregate metrics may be pooled with other opted-in clients' data to compute platform-wide, industry-level ad performance benchmarks (e.g., typical cost-per-acquisition or click-through rate ranges for a given ad platform and industry) shown elsewhere in the Service. This benchmarking use is never implied by uploading a report alone — it requires the separate, explicit opt-in.

  • Benchmark figures are computed only from a pooled group of multiple opted-in clients, never from — or attributable to — a single client's data alone.
  • Opting an end-client out stops that client's data from contributing to future benchmark calculations immediately.
  • Deleting an end-client record permanently removes their uploaded metrics and reports (cascading deletion), including from any pending benchmark calculation.

AI-generated commentary in these reports is AI-assisted review of the numbers you or your client provided, not a certification, audit, or legal guarantee of ad platform policy compliance.

6. Sharing Your Information

We may disclose your personal information to:

Within the Adverizeo Group

For internal administration, support, and service delivery.

With Third-Party Service Providers (Processors)

  • Hosting: Railway (Netherlands/EU)
  • File Storage: Amazon Web Services (AWS S3, EU region)
  • Payments: Stripe (PCI-compliant)
  • Email: Mailgun
  • Analytics: Plausible (privacy-first)
  • AI Models: OpenAI, Anthropic (with data processing agreements)

See our Subprocessors page for the full, current list. We require all processors to comply with GDPR via Data Processing Agreements (DPA).

With Third-Party Data Controllers (With Consent or Legitimate Basis)

  • Advertising partners (e.g., Google Ads, Meta) — only if you enable ad integration
  • Google Ads Integration: When you choose to connect your Google Ads account, we request limited, read-only access to your campaign performance data (e.g., impressions, clicks, conversions, cost) via the Google Ads API. This data is used solely to populate your Adverizeo analytics dashboard and power our AI performance recommendations. We do not use this API to make automated changes to your Google Ads campaigns, bids, budgets, or settings. You can revoke this access at any time through your Google Account security settings.
  • Social media platforms — if you use social sign-on or share ads directly
  • Businesses you're affiliated with (e.g., if you use a corporate email)

For Legal and Safety Reasons

  • To comply with court orders, subpoenas, or government requests
  • To prevent fraud, illegal activity, or protect our rights and users
  • In connection with a merger, acquisition, or sale of assets

7. International Data Transfers

Your data may be transferred outside the EEA, including to:

  • United States (e.g., our AI providers, OpenAI and Anthropic)

We ensure adequate protection via:

  • EU Standard Contractual Clauses (SCCs) with all subprocessors
  • Data Processing Agreements (DPA) that incorporate SCCs

A copy of our SCCs is available upon request.

8. Data Retention

We retain your data only as long as necessary:

  • Account data: Until deletion request or 2 years after inactivity
  • Generated ads: As long as your account is active
  • Logs and analytics: Up to 12 months
  • Payment records: 7 years for tax compliance
  • Support tickets: 2 years

After retention periods, data is securely deleted or anonymized.

9. Your Data Subject Rights (GDPR Articles 15–22)

You have the right to:

  • Access: Request a copy of your data
  • Rectification: Correct inaccurate information
  • Erasure: Request deletion ("right to be forgotten")
  • Restriction: Limit processing in certain cases
  • Data Portability: Receive your data in a structured format
  • Object: Object to processing based on legitimate interests
  • Withdraw Consent: At any time, without affecting prior processing

To exercise these rights, contact us at privacy@adverizeo.com. We respond within 30 days.

10. Security of Your Information

We implement industry-standard safeguards:

  • Encryption in transit (TLS) and at rest
  • Secure authentication (password hashing)
  • Regular penetration testing and vulnerability scanning
  • Access controls and audit logs
  • Employee training on data protection
  • Incident response plan for data breaches

In the event of a breach likely to result in a risk to your rights, we will notify you and the relevant supervisory authority within 72 hours, as required by law.

11. Children's Privacy

Our Service is not intended for individuals under 16. We do not knowingly collect data from children. If we become aware of such collection, we will delete it promptly. Schools or educators wishing to use Adverizeo for students must contact us for a DPA and parental consent framework.

12. Updates to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Last updated" date will be revised. Material changes will be communicated via:

  • Email to registered users
  • In-app notification
  • Posting on this page

We encourage you to review this policy periodically.

13. How to Contact Us

For privacy-related questions, requests, or complaints:

Adverizeo

Email: privacy@adverizeo.com

If unresolved, you have the right to lodge a complaint with your local data protection supervisory authority.

Your trust is our priority. We are committed to transparency, accountability, and the highest standards of data protection.