GDPR transparency
Privacy Notice
This notice explains how Apptastic Tech processes personal data for AdOperator accounts, website use, billing, support, security and service operation.
1. Controller and contact
For account, website, billing, security and business-contact processing, the controller is Apptastic Tech Sp. z o.o., ul. Piłsudskiego 74/320, 50-020 Wrocław, Poland, VAT/TAX ID PL8971890288, KRS 0000892270. Privacy requests: contact@adoperator.ai with the subject “Privacy request”.
When a business customer submits and controls personal data through its tenant, that customer is normally the controller and Apptastic Tech acts as processor under the data-processing addendum.
2. Data categories
- identity, business contact, account, role, invitation and authentication data;
- subscription, invoice, payment-status and token-consumption data;
- campaign configurations, prompts, outputs, creatives and integration metadata submitted by authorized users;
- technical, browser, IP, security, audit and support logs;
- support requests and business communications;
- website analytics and cookie data where enabled and lawfully collected.
3. Purposes and legal bases
- Service and accounts
- Contract performance under GDPR Article 6(1)(b), and legitimate interests for business-user administration.
- Billing and records
- Legal obligations under Article 6(1)(c), and legitimate interests in claims and business records.
- Security and abuse
- Legitimate interests under Article 6(1)(f), balanced against user rights, and legal obligations where applicable.
- Support and issue diagnosis
- Contract performance and legitimate interests; processor instructions apply to customer-controlled data.
- Service improvement
- Aggregated or reliably de-identified analytics. If data remains identifiable, we perform a lawful-basis and balancing assessment.
- Model training
- Identifiable customer content is used for cross-customer training only with a separately documented lawful basis, transparent notice and explicit contractual opt-in where required.
4. When our staff may view campaign data and creatives
Authorized personnel may access campaign data, prompts, outputs and creatives only when reasonably necessary to provide requested support, investigate a reported issue, maintain or secure the service, prevent fraud or abuse, comply with law, or follow the customer's documented instructions. Access is limited by role and need, subject to confidentiality duties, and should be logged where technically appropriate.
We may use aggregated or reliably de-identified usage and performance information to improve reliability, safety, metering and agent performance. We do not use identifiable campaign data or creatives to train or fine-tune a model for cross-customer use without explicit, specific opt-in authorization.
5. Recipients and subprocessors
Data may be disclosed to authorized personnel and to hosting, cloud, database, email, security, support, payment and AI/service providers only as necessary and under appropriate contracts. See our current Subprocessors page.
6. International transfers
Where personal data is transferred outside the EEA, we use a valid GDPR Chapter V mechanism such as an adequacy decision or Standard Contractual Clauses, together with supplementary safeguards where required.
7. Retention
We keep account and tenant data for the subscription and a limited period needed for export, deletion, security and legal claims. Billing and tax records are retained for statutory periods. Security and support logs are retained according to risk and operational need. Backups are isolated and deleted through ordinary secure rotation. An order form or data-processing addendum may specify stricter periods.
8. Rights
Depending on the processing, individuals may request access, correction, erasure, restriction, portability, objection and withdrawal of consent. We may verify identity. Requests can be sent to contact@adoperator.ai.
You may complain to the President of the Polish Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland, or another competent EEA authority.
9. Automated functions and security
AdOperator uses AI-assisted recommendations and actions in campaign operations. Customers are expected to provide competent human oversight for material decisions. We use risk-based technical and organizational measures, but no service can guarantee absolute security.
10. Changes
We will show the effective date of material changes. A new purpose requiring consent or other authorization will not be introduced merely by updating this notice.