Your accounts remain yours. We work inside systems you control, with named access and only the minimum permissions the work needs. Everything is documented so it can be handed over.

Our role

When we access personal data in your ad platforms, analytics, CRM, data warehouse or automations, we act as your Data Processor, processing personal data on behalf of you as the Data Fiduciary (DPDP Act) or Data Controller (GDPR, UAE and KSA PDPL). We process that data only on your documented instructions and only for the engagement.

For our own business contacts, we are the controller. That data is covered by our Privacy Policy.

Principles we work by

Access to your accounts

  • We work inside accounts that you own, through named user or partner access, for example Meta Business Manager partner access, Google Ads manager-account links and GA4 or CRM user roles.
  • We do not ask for, share or store account passwords. MFA is required on every account we use.
  • Access follows least privilege. Admin rights are requested only when a specific task needs them, and are downgraded afterwards.
  • At the end of an engagement, we remove our access within 7 days of handover, and confirm this in writing.

Customer lists and audiences

  • You confirm that you have a lawful basis, and any consent required, to use customer data for marketing and to upload it to advertising platforms.
  • Customer lists are uploaded through the platforms' own tools, which hash identifiers (such as SHA-256) before matching.
  • We do not keep customer lists after the upload or analysis is complete. Working copies are deleted within 30 days.
  • We never combine one client's data with another client's data.

Security measures

Sub-processors

We use a small number of vetted providers, and only where the scope requires them:

  • Cloud hosting and security.
  • Workspace and email.
  • Automation platforms, such as Make.com or n8n.
  • Data warehousing, such as Google BigQuery.
  • AI model providers under business or API terms that do not train on customer inputs.

A current list is available on request. Where a DPA is signed, we will notify you before adding a new sub-processor that handles your personal data.

AI safeguards

Personal data is only sent to AI services under business terms that prohibit training on customer inputs, and only when the task needs it. Where practical, we anonymise or aggregate data first. A person reviews AI-assisted outputs before they drive a consequential decision.

International transfers

Data may be processed in India and in the countries where your platforms and our sub-processors operate. We follow Section 16 of the DPDP Act for transfers from India. We use Standard Contractual Clauses (or the UK Addendum) for EU and UK data, and the applicable transfer conditions under the UAE and KSA PDPL.

Breach notification

If we become aware of a personal data breach affecting your data, we will contain it, assess the impact, and notify you without undue delay, and in any event within 48 hours. We will also provide the information you need to meet your own obligations, such as notifying the Data Protection Board of India, CERT-In within its required timeline, or an EU supervisory authority within 72 hours.

Data subject requests and audits

We will promptly forward any request we receive from your customers or users, and help you respond. We will provide reasonable information to show compliance. Once a year, with 30 days' notice and at your cost, we can support an audit or a written questionnaire.

Return and deletion

At the end of an engagement, we return or delete personal data processed for you within 30 days, unless the law requires us to keep it. We will confirm deletion in writing on request.

Data Processing Agreement

A Data Processing Agreement, including Standard Contractual Clauses for EU and UK data, is available on request and can be signed alongside your engagement agreement. Email alex@yerid.ai.