Privacy policy for KRADS Tool

§1. General provisions

The data controller is Klinika Reklamy Paweł Wechmann ul. Złotników 7B/9 73-110 Stargard NIP: 955-188-28-39 (hereafter “the Controller”, “We”). On matters of personal data protection you can reach us by e-mail at kontakt@klinikareklamy.pl. Where this policy refers to data protection law, it means the EU GDPR (Regulation (EU) 2016/679). This policy describes ONLY the application KRADS Tool that we use to manage Google Ads accounts. The rules covering the website klinikareklamy.pl, its forms and cookies are described in a separate https://klinikareklamy.pl/polityka-prywatnosci/.

§2. What this application is

KRADS Tool is a tool for managing Google Ads accounts internally: our own accounts and client accounts we have been granted access to. The application runs locally, on our own computers. It is not a web service, there is no registration, we do not make it available to anyone outside, and there are no users other than us. The application connects to Google’s APIs directly from our computer, on our own credentials and within our own Google Cloud project. We do not use an intermediary that would make requests to Google on behalf of many parties.

§3. What data from Google services we process

The application uses above all Google Ads data on the accounts we have access to. That covers information about an account’s structure and settings, such as campaigns, ad groups, ads, keywords, exclusions, targeting settings and budgets, and data about campaign performance, among them impressions, clicks, costs, conversions and conversion value. The application also allows changes to be made on those accounts, in line with the work we carry out. Depending on what is needed, the application may also use other Google services:

• Google Analytics 4: data and reports on traffic and conversions for linked websites.

• Google Merchant Center: product data, including statuses and prices.

• Google Sheets and Google Drive: access to selected files, to import and export information used while managing campaigns.

• Google Tag Manager: access to container configuration, to make the changes we are asked for.

Access to these services is optional and requires the relevant permissions. The full scope of permissions is shown on Google’s consent screen while the application is being authorised.

What the application does not take

The application does not take the advertiser’s end-customer personal data, contact details from forms, or the contents of mail. Nor does it take audience lists or remarketing data that would allow specific individuals to be identified.

§4. Purposes and legal bases

Data from Google services serves only the running and optimisation of advertising campaigns on the accounts we have access to: analysing results, diagnosis, preparing recommendations and reports, and making changes to campaigns. We use it for no other purpose: in particular we do not profile individuals on the basis of it and we do not build marketing databases from it.

https://www.edpb.europa.eu/system/files/documents/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_en.pdf

§5. Access credentials

Authorisation happens through OAuth 2.0. The client id, client secret, refresh token and developer token are stored only in the configuration directory on our own computer and are not sent anywhere other than to Google’s services. The application does not ask for the password to a Google account and never receives one. Only people we have authorised have access to the computers the application runs on.

§6. Where the data is stored

Data that has been fetched is held on our computers: in a local query cache, in the accounts’ configuration files, and in reports and summaries saved to disk. To prepare analyses and recommendations we use an assistant built on a language model, to which we pass the data needed for the analysis at hand; we do not pass it access credentials. We apply appropriate organisational and technical measures, including access control on the devices, to protect that data against unauthorised access.

§7. Recipients of the data

We do not sell, rent or disclose data fetched from Google services to third parties for marketing purposes. We do not use an intermediary that would make requests to Google on behalf of many parties. Data concerning a client’s account is made available to that client in the form of reports and summaries, because it concerns their account. Data may also be disclosed to bodies authorised under the law.

§8. How long the data is kept

Data fetched from Google services is kept for as long as the engagement covering that advertising account lasts, and is deleted when it ends, together with the application’s local files. Reports handed to a client remain at that client’sdisposal.

§9. Withdrawing access

The owner of a Google account can withdraw the application’s access at any time at https://myaccount.google.com/permissions. Once access is withdrawn, the application loses the ability to fetch data and to make changes on that account.

§10. The rights of the people the data concerns

To the extent that the data processed is personal data, there are rights to access it, to have it rectified, erased or its processing restricted, to object, to data portability, and to lodge a complaint with a supervisory authority. Requests are received at kontakt@klinikareklamy.pl, and the supervisory authority is Paweł Wechmann.

§11. Compliance with Google’s policies

This application’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Google’s verification review looks for its own affirmation, word for word, so keep the sentence below exactly as it stands, in particular “to any other app”, which is the half a reworded version usually loses: Use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

§12. Changes to this privacy policy

We reserve the right to change this policy where that is required by law, by a change in the permissions the application asks for, or by a change in how it works. The current version is always available at https://klinikareklamy.pl/krads-tool-application-privacy-policy/, and the header states the date it takes effect.

§13. Contact

Klinika Reklamy Paweł Wechmann ul. Złotników 7B/9 73-110 Stargard NIP: 955-188-28-39. E-mail: kontakt@klinikareklamy.pl.