Your accounts remain yours. We work inside systems you control, with named access and only the minimum permissions the work needs. Everything is documented so it can be handed over.
Our role
When we access personal data in your ad platforms, analytics, CRM, data warehouse or automations, we act as your Data Processor, processing personal data on behalf of you as the Data Fiduciary (DPDP Act) or Data Controller (GDPR, UAE and KSA PDPL). We process that data only on your documented instructions and only for the engagement.
For our own business contacts, we are the controller. That data is covered by our Privacy Policy.
Principles we work by
| Principle | What it means in practice |
|---|---|
| Purpose limitation | Data is used only for the scoped engagement, never for our own marketing or for other clients |
| Data minimisation | We ask for the least access and the smallest dataset that will do the job |
| Accuracy | Source mapping and reconciliation are part of every measurement build |
| Storage limitation | Working copies are deleted on a defined schedule, and data is returned or deleted at the end |
| Security | Named access, MFA, encryption and documented offboarding |
| Accountability | Decisions, access and changes are logged in the engagement record |
Access to your accounts
- We work inside accounts that you own, through named user or partner access, for example Meta Business Manager partner access, Google Ads manager-account links and GA4 or CRM user roles.
- We do not ask for, share or store account passwords. MFA is required on every account we use.
- Access follows least privilege. Admin rights are requested only when a specific task needs them, and are downgraded afterwards.
- At the end of an engagement, we remove our access within 7 days of handover, and confirm this in writing.
Customer lists and audiences
- You confirm that you have a lawful basis, and any consent required, to use customer data for marketing and to upload it to advertising platforms.
- Customer lists are uploaded through the platforms' own tools, which hash identifiers (such as SHA-256) before matching.
- We do not keep customer lists after the upload or analysis is complete. Working copies are deleted within 30 days.
- We never combine one client's data with another client's data.
Security measures
| Area | Measures |
|---|---|
| Identity | Unique named accounts, multi-factor authentication, and SSO where available |
| Devices | Full-disk encryption, screen lock, automatic updates and endpoint protection |
| Transfer | Encrypted in transit (TLS); no raw personal data sent as open email attachments |
| Storage | Client-controlled workspaces preferred; our own storage uses access-controlled, encrypted cloud services |
| Automations | Secrets kept in platform credential stores, never in code or documents; logs cleared of personal data where possible |
| People | Confidentiality undertakings and data handling guidance for everyone who works on an engagement |
Sub-processors
We use a small number of vetted providers, and only where the scope requires them:
- Cloud hosting and security.
- Workspace and email.
- Automation platforms, such as Make.com or n8n.
- Data warehousing, such as Google BigQuery.
- AI model providers under business or API terms that do not train on customer inputs.
A current list is available on request. Where a DPA is signed, we will notify you before adding a new sub-processor that handles your personal data.
AI safeguards
Personal data is only sent to AI services under business terms that prohibit training on customer inputs, and only when the task needs it. Where practical, we anonymise or aggregate data first. A person reviews AI-assisted outputs before they drive a consequential decision.
International transfers
Data may be processed in India and in the countries where your platforms and our sub-processors operate. We follow Section 16 of the DPDP Act for transfers from India. We use Standard Contractual Clauses (or the UK Addendum) for EU and UK data, and the applicable transfer conditions under the UAE and KSA PDPL.
Breach notification
If we become aware of a personal data breach affecting your data, we will contain it, assess the impact, and notify you without undue delay, and in any event within 48 hours. We will also provide the information you need to meet your own obligations, such as notifying the Data Protection Board of India, CERT-In within its required timeline, or an EU supervisory authority within 72 hours.
Data subject requests and audits
We will promptly forward any request we receive from your customers or users, and help you respond. We will provide reasonable information to show compliance. Once a year, with 30 days' notice and at your cost, we can support an audit or a written questionnaire.
Return and deletion
At the end of an engagement, we return or delete personal data processed for you within 30 days, unless the law requires us to keep it. We will confirm deletion in writing on request.
Data Processing Agreement
A Data Processing Agreement, including Standard Contractual Clauses for EU and UK data, is available on request and can be signed alongside your engagement agreement. Email alex@yerid.ai.



