1. Introduction
To Better Digital SASU (“Adsap”, “we”, “us”, “our”), a French Société par Actions Simplifiée Unipersonnelle registered in Paris, France, operates the Meta and Google Ads advertising automation platform available at adsap.ai (the “Platform”). This Privacy Policy explains how we collect, use, share, and protect personal data when you use the Platform. It applies to all users of our services, including our website, web application, and MCP integration with supported AI assistants.
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the French Loi Informatique et Libertés, and applicable data protection legislation.
2. Data Controller
The data controller for personal data collected through the Platform for account management purposes is:
48 rue Sauffroy, 75017 Paris, France
Email: jeremy@adsap.ai
When we process advertising campaign data, audience data, or creative assets on your behalf via the Meta Marketing API, we act as a Data Processor under your instructions. This relationship is governed by our Data Processing Agreement (DPA), available upon request.
3. Data We Collect
3.1 Account Data (Controller)
When you create an Adsap account, we collect your email address, name, and authentication credentials. If you subscribe to a paid plan, our payment processor (Stripe) collects billing information on our behalf. We do not store credit card numbers on our servers.
3.2 Meta Advertising Data (Processor)
When you connect your Meta ad account via OAuth, we access and cache advertising data including campaign structures, ad set configurations, ad creatives, performance metrics, audience definitions, and pixel event data. This data is processed solely to provide you with the Platform’s automation and reporting services. We store encrypted OAuth access tokens and refresh tokens to maintain your Meta connection.
3.3 Google Ads Advertising Data (Processor)
If you connect a Google Ads account via OAuth (adwords scope), we access and cache your accessible account list (account ID, name, currency, time zone) and advertising data including campaign structures and performance metrics (impressions, clicks, cost, conversions). This data is processed solely to provide you with the Platform’s reporting and campaign management services. We store encrypted Google OAuth tokens to maintain the connection. We do not sell Google Ads data or use it for advertising unrelated to your own accounts.
3.4 Google Drive Data (Processor)
If you connect Google Drive, we request file-scoped access (drive.file scope) limited to the specific files you explicitly select through Google’s file picker, to transfer creative files (images and videos) to your Meta ad account. We do not modify or delete files in your Drive. Creative files are streamed from Google Drive to Meta and are not permanently stored on our infrastructure. We store your Google OAuth tokens to maintain the connection.
3.5 AI Processing Data
The Platform connects to third-party AI assistants via the MCP (Model Context Protocol) framework. You choose which assistant to connect— currently Claude (Anthropic), ChatGPT (OpenAI) or Perplexity (Perplexity AI).
In this model your assistant connects to Adsap, using your own subscription with that provider. Your instructions and the resulting ad parameters (campaign names, targeting criteria, ad copy, budget values) are processed by that provider under their terms and your account settings with them, which Adsap does not control. Adsap sends no data to any assistant you have not connected.
Separately, Adsap’s AI ad copyfeature calls Anthropic’s API directly under Adsap’s commercial agreement. Data sent through that feature is not used to train AI models.
3.6 Usage and Technical Data
We collect standard usage data such as IP addresses, browser type, pages visited, and feature usage to improve the Platform and ensure security. We use analytics tools to understand how users interact with the Platform.
3.7 Website Forms and Free Tools (Controller)
When you use a free tool on adsap.ai (for example the ad volume calculator) and ask us to email you a report, we collect your email address, the inputs you entered (such as your monthly ad budget), the resulting spend tier, the time of your request, your browser’s user agent, a salted hash of your IP address, and any campaign parameters present in the page URL. We use this data to deliver the report you requested (contract, Art. 6(1)(b)) and to protect the form against abuse (legitimate interest, Art. 6(1)(f)). Only if you tick the optional box do we use your email address to send occasional creative testing tips from Adsap (consent, Art. 6(1)(a)); you can withdraw that consent at any time via the link in each email or by writing to jeremy@adsap.ai. Report emails are delivered through Resend and lead records are stored in our Supabase database in the European Union. See section 9 for retention. If you have accepted marketing cookies, a hashed (SHA-256) version of your email address is also passed to Meta and Google Ads so that the request can be attributed to the advertisement that brought you here (advanced matching and enhanced conversions); this never happens without that consent, and the hash is not used by our analytics.
4. Legal Bases for Processing
We process personal data on the following legal bases under GDPR Article 6:
Contract performance (Art. 6(1)(b)): Processing your account data and Meta and Google Ads advertising data is necessary to provide you with the Platform’s services under our Terms of Service.
Legitimate interest (Art. 6(1)(f)): Usage analytics, security monitoring, and fraud prevention are carried out under our legitimate interest in maintaining and improving the Platform.
Consent (Art. 6(1)(a)): Where required, such as for optional cookies or marketing communications, we obtain your explicit consent.
Legal obligation (Art. 6(1)(c)): We may process data as required by French law, including tax and accounting obligations.
5. How We Use Your Data
We use your data to provide, maintain, and improve the Platform, including: managing your account and subscription; connecting to and syncing with your Meta ad accounts; executing campaign creation, modification, and pausing operations via the Meta Marketing API; caching performance metrics for reporting dashboards; transferring creative files from Google Drive to Meta; processing AI-assisted operations via the MCP integration with your chosen AI assistant; communicating service updates and support responses; and ensuring security and preventing abuse.
6. Data Sharing and Subprocessors
We do not sell your personal data. We share data only with the following categories of recipients, each acting under contractual obligations and appropriate safeguards:
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase | Database hosting, authentication, edge functions | EU (Ireland) | GDPR DPA, EU hosting |
| Meta Platforms | Advertising API (campaign management, insights) | US / EU | EU-US Data Privacy Framework, Meta Business Tools Terms |
| Anthropic | AI ad copy generation via Claude API (Adsap-paid) | US | Commercial API terms, no model training on user data, SCCs |
| Anthropic, OpenAI or Perplexity AI | AI assistant you connect via MCP (Claude, ChatGPT or Perplexity) | US | Governed by the subscription and terms you hold directly with that provider |
| Drive API (creative file access), OAuth | US / EU | EU-US Data Privacy Framework, SCCs | |
| Stripe | Payment processing | US / EU | PCI DSS, GDPR DPA, SCCs |
| Vercel | Website and app hosting | US / EU | GDPR DPA, SCCs |
| Resend | Transactional and lifecycle email delivery | US | GDPR DPA, SCCs |
| Hostinger | VPS hosting | EU | EU hosting, GDPR DPA |
The table above is our current subprocessor list and is updated whenever it changes. We will notify you of any material changes, and you may object to a new subprocessor within 30 days of notification.
7. AI-Specific Disclosures
Adsap enables conversational ad management through third-party AI assistants (Claude, ChatGPT or Perplexity) using the MCP framework, and uses Anthropic’s API directly for AI ad copy generation. The following applies to AI processing:
Two distinct flows: When you use the MCP connector, your assistant provider processes your data under the subscription you hold with them. When you use Adsap’s AI ad copy feature, Adsap sends data to Anthropic’s API under Adsap’s own commercial agreement. The protections below differ accordingly.
No model training (AI ad copy): Data Adsap sends to Anthropic’s API is not used to train or fine-tune AI models, governed by Anthropic’s commercial API agreement. For the MCP connector, whether your conversations are used for training is governed by your own agreement and settings with your assistant provider— review their policy and your account settings if this matters to you.
Transient processing: AI interactions are processed in real-time. Assistant providers may retain traffic for a limited period for safety monitoring under their own terms; Anthropic’s commercial terms provide for up to 30 days.
No automated decision-making: The Platform does not make fully automated decisions with legal or similarly significant effects (GDPR Article 22). All ad creation and budget changes require explicit user approval before execution.
Data minimization: We transmit only the data necessary for the requested operation (e.g., campaign parameters, targeting criteria, ad copy). We do not send your full account data or billing information to the AI.
8. International Data Transfers
Your primary data is hosted within the European Union (Supabase EU region, Ireland). Some data is transferred to the United States when interacting with Meta’s Marketing API, Anthropic’s Claude API, the AI assistant you connect (Anthropic, OpenAI or Perplexity AI), Stripe’s payment API, and Resend’s email delivery API. These transfers are protected by Standard Contractual Clauses (SCCs) as approved by the European Commission, and where applicable, the EU-US Data Privacy Framework. We have conducted Transfer Impact Assessments (AITD) as recommended by the CNIL for each US-based subprocessor.
9. Data Retention
Account data: Retained for the duration of your active subscription plus 30 days after account deletion to allow for reactivation.
Meta advertising data cache: Campaign structures and performance metrics are cached and refreshed periodically. Cached data is permanently deleted when you delete your workspace or account, or sooner upon request.
Google Ads advertising data cache: Campaign structures and performance metrics are cached and refreshed periodically. Cached data is permanently deleted when you delete your workspace or account, or sooner upon request.
OAuth tokens: Meta and Google OAuth tokens are stored encrypted and deleted immediately upon disconnection or account termination.
Billing records: Retained for 10 years as required by French commercial and tax law (Code de commerce).
Audit logs: Platform activity logs are retained for 12 months for security and debugging purposes.
Website leads: Email addresses and inputs collected through free tools on adsap.ai are kept for 24 months after your last interaction, or until you withdraw consent or ask us to delete them, whichever comes first.
10. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
Access (Art. 15): Request a copy of the personal data we hold about you.
Rectification (Art. 16): Request correction of inaccurate personal data.
Erasure (Art. 17): Request deletion of your personal data, subject to legal retention obligations.
Restriction (Art. 18): Request restriction of processing in certain circumstances.
Portability (Art. 20): Receive your personal data in a structured, machine-readable format.
Objection (Art. 21): Object to processing based on legitimate interest.
Withdraw consent (Art. 7): Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at jeremy@adsap.ai. We will respond within 30 days.
11. Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including: encryption at rest and in transit (TLS 1.2+); row-level security (RLS) policies on all database tables to enforce tenant isolation; OAuth 2.1 authentication for all API integrations; encrypted storage of all third-party access tokens; rate limiting and abuse prevention on all API endpoints; regular security assessments including third-party penetration testing; and audit logging of all sensitive operations.
12. Cookies
The Platform uses strictly necessary cookies for authentication and session management. We use analytics cookies only with your consent. You can manage cookie preferences through your browser settings or our cookie consent banner when applicable.
13. Children’s Privacy
The Platform is a B2B service not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from minors.
14. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), the French supervisory authority: cnil.fr.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered address or through a prominent notice on the Platform at least 30 days before taking effect. Continued use of the Platform after the effective date constitutes acceptance of the updated policy.
16. Contact
For any questions about this Privacy Policy or our data practices, contact us at:
48 rue Sauffroy, 75017 Paris, France
Email: jeremy@adsap.ai
Website: adsap.ai