Who is responsible for your information
AdsXpo is currently operated under licence by BiznesXpo. The specific BiznesXpo legal entity identified in your order form, service agreement, invoice, payment instruction or account notice is generally the controller or responsible party for account administration, contracting, billing, fraud prevention, security and support data.
When we process campaign, audience, customer or client information only on your documented instructions, you may be the controller or responsible party and the operator may act as a processor or service provider. The applicable data-processing terms govern that relationship.
Questions and privacy requests may be sent to legal@adsxpo.com. We may need to verify your identity and authority before acting on a request.
Information we collect
Account and identity information may include your name, work email, password hash, Google account identifier, organisation, role, phone number, profile details, country, business registration details, beneficial-owner details and verification documents where required.
Commercial and transaction information may include subscriptions, invoices, funding requests, payment references, payer and beneficiary details, currencies, balances, allocations, processing and commission fees, refunds, chargebacks and reconciliation records. We do not intentionally store complete payment-card credentials when a regulated payment provider handles them.
Advertising operations information may include platform names, account identifiers, Business Portfolio or Manager IDs, Business Center IDs, Organisation IDs, invited email addresses, categories, account names, reporting timezones, landing-page links, creative-asset links, campaign instructions, spend and performance data, approvals and support notes.
Communications and content may include support tickets, emails, feedback, files, comments, call notes and information you submit about clients or authorised users.
Security and device telemetry
We collect technical and security records such as IP address, user agent, device and browser characteristics, request identifiers, timestamps, authentication method, successful and failed sign-ins, one-time-code events, password-reset activity, session creation and revocation, permission changes, administrative actions, rate-limit events and suspected misuse.
We minimise and redact event metadata before storage and avoid placing passwords, authentication tokens, one-time codes, card details or other secrets in security logs. Access to security records is restricted to authorised personnel with a legitimate operational, support, fraud-prevention or legal need.
AdsXpo uses real-time WebSocket connections after sign-in to deliver workspace invalidations and security-event updates. Connection metadata may include the authenticated account, connection time, network address and disconnection or error information. WebSockets do not replace your browser’s authentication controls and do not themselves grant access to data outside your authorised workspace.
How information is obtained
We receive information directly from you, your organisation, invited team members, clients for whom you are authorised to act, connected advertising platforms, payment and banking providers, identity providers such as Google, support interactions and automated use of the service.
We may also receive public business information, sanctions or fraud-risk indicators, provider account status and verification results from lawful third-party sources. We do not treat a risk signal as conclusive without proportionate review where a decision could materially affect you.
Why we use information
We use information to create and administer accounts; authenticate users; record legal acceptance and privacy choices; provision and manage advertising accounts; receive, allocate and reconcile funding; calculate fees; provide reports; process support; send service communications; and fulfil your instructions.
We also use information to secure the platform, detect fraud and account compromise, enforce permissions and acceptable-use rules, investigate disputes, protect users and providers, maintain audit trails, improve reliability, measure performance and comply with legal, tax, accounting, sanctions and regulatory obligations.
Where permitted, we may create aggregated or de-identified statistics designed not to identify a person or customer. We do not use customer campaign content to train a general-purpose public AI model unless a separate written agreement and appropriate notice permit it.
Lawful bases
Depending on your location and the processing activity, we rely on performance of a contract, steps requested before entering a contract, compliance with legal obligations, legitimate interests in operating and securing a business platform, consent for optional technologies or communications, and the establishment, exercise or defence of legal claims.
Our legitimate interests include preventing fraud, maintaining security, improving the service, supporting customers, reconciling payments and protecting AdsXpo, BiznesXpo, connected providers and other users. We assess these interests against the rights and reasonable expectations of affected individuals.
Where consent is the required basis, you may withdraw it prospectively through the available controls or by contacting us. Withdrawal does not affect processing already carried out lawfully.
Advertising, payment and identity providers
Connected providers such as Meta, Google, TikTok, Snapchat, X, LinkedIn, banks, payment processors, foreign-exchange services and identity providers process information under their own terms and privacy notices. Their independent decisions and practices are outside our direct control.
We disclose only the information reasonably necessary to validate ownership, invite authorised users, provision or manage accounts, process and reconcile funding, respond to disputes, investigate risk or meet provider requirements. A provider may combine data it receives with information it already holds about you under its own notice.
Other recipients
We may disclose information to vetted providers supporting cloud hosting, databases, caching, real-time messaging, email, authentication, analytics activated with consent, customer support, document storage, security, fraud prevention, professional advice, accounting and compliance. They may process information only for contracted purposes and must apply appropriate safeguards.
Authorised companies within BiznesXpo operations may receive information where necessary to serve an account across countries, provide support, manage billing or conduct security and compliance functions.
We may disclose information to regulators, courts, law-enforcement authorities, banks, providers, insurers, advisers or affected parties where reasonably necessary to comply with law, protect rights and safety, investigate fraud, enforce an agreement or respond to a valid legal process. We review requests and disclose only what is reasonably required.
If the business, platform or relevant assets are reorganised, financed, sold or transferred, information may be disclosed under confidentiality safeguards and transferred to a successor that assumes the applicable privacy obligations.
International processing
AdsXpo supports users, infrastructure and providers in multiple countries. Personal information may therefore be stored or processed outside the country where it was collected, including locations with different privacy laws.
Where required, we use recognised contractual safeguards, adequacy decisions, transfer risk assessments, access controls, data minimisation and other organisational or technical measures. You may contact us for information about safeguards relevant to your account, subject to confidentiality and security limitations.
Retention
Account and organisation records are generally retained while the account is active and for a reasonable period afterwards to support reactivation, disputes and legal obligations. Contract, invoice, tax, payment and reconciliation records may be retained for the period required by applicable accounting and financial laws.
Authentication and security events are retained for a period proportionate to fraud prevention, incident investigation and audit needs. Support communications, consent evidence and legal acceptances are retained while relevant to the relationship and applicable limitation periods.
Campaign and platform data may be refreshed, aggregated or deleted when no longer needed, subject to provider availability, contractual requirements, backups and unresolved disputes. Backup copies are isolated and expire according to controlled schedules rather than being used for ordinary business operations.
We may retain information longer where required by law, a legal hold, sanctions or fraud investigation, or to establish, exercise or defend claims. We securely delete or de-identify information when the applicable purpose and retention period end.
Security safeguards and incidents
We use administrative, technical and organisational measures designed to protect personal information, including role-based access, password hashing, short-lived access tokens, refresh-token controls, optional email two-factor authentication, encryption in transit, request identifiers, audit records, rate limiting, secure development practices and restricted production access.
No online service can guarantee absolute security. You must use unique passwords, protect email accounts and devices, keep user access current and contact us promptly if you suspect compromise.
We maintain processes to assess, contain, investigate and document suspected incidents. Where applicable law requires notification to a regulator, responsible party or affected person, we will provide notice within the required timeframe and include available information appropriate to the risk.
Automated risk signals and human review
Automated systems may flag unusual sign-ins, repeated failures, suspicious funding, prohibited links, inconsistent identifiers, rate-limit breaches or other risk indicators. A flag may temporarily delay or restrict an action while we request information or review the circumstances.
We do not intend to make solely automated decisions that produce legal or similarly significant effects where applicable law gives you a right to human involvement. You may contact support to request review of a material restriction, subject to security, provider and legal requirements.
Your choices and rights
Depending on applicable law, you may have rights to be informed, access personal information, correct inaccuracies, request deletion, restrict or object to processing, receive portable data, withdraw consent, challenge certain automated decisions and complain to a privacy regulator.
Rights are not absolute. We may retain or withhold information where necessary to protect another person, preserve security, comply with law, maintain privileged material, complete a transaction or establish, exercise or defend legal claims. We will explain a lawful refusal where permitted.
You may update many account details in Settings. For other requests, contact legal@adsxpo.com and identify the account and organisation concerned. We may ask for verification and, where you act for a client or employee, evidence of authority.
Regional information
United Kingdom and European Economic Area: where applicable, you may complain to your local supervisory authority and have the rights provided by the UK GDPR or EU GDPR. The relevant contracting entity will identify any required representative or data-protection contact in account documentation.
South Africa: where the Protection of Personal Information Act applies, you may request access or correction and complain to the Information Regulator. The applicable BiznesXpo entity acts as the responsible party for its own purposes and uses operators subject to appropriate security obligations.
Nigeria: where the Nigeria Data Protection Act and related requirements apply, you may exercise applicable data-subject rights and lodge a complaint with the Nigeria Data Protection Commission. Any required registration or data-protection compliance classification is handled by the applicable operating entity.
California: where the California Consumer Privacy Act applies, eligible residents may request access, correction or deletion and information about categories of collection and disclosure, without unlawful discrimination. AdsXpo is not currently designed to sell personal information or share it for cross-context behavioural advertising. If that practice changes, we will update this Policy and provide required choices.
Cookies and similar technologies
We use essential cookies and device storage for authentication, security, consent evidence and core service delivery. Optional preference, analytics or marketing technologies remain subject to the choices described in the Cookie Policy and consent interface where required.
You can reopen Cookie settings from the public-site footer. Blocking necessary storage may prevent sign-in or core functions from working correctly.
Children
AdsXpo is a business service and is not directed to children. You must be at least 18 years old to create an account. Do not submit children’s personal information unless it is strictly necessary for a lawful campaign, you have appropriate authority and the relevant platform and law permit the processing.
Changes and contact
We may update this Policy to reflect legal, product, provider, organisational or security changes. We will publish the current date and provide additional notice where a change is material or consent is required.
For privacy questions, complaints or requests, email legal@adsxpo.com. You may also use the contact page. If we cannot resolve a concern, you may contact the competent privacy authority in your jurisdiction.
Questions about this document?
Contact our legal and compliance team at legal@adsxpo.com or use the contact page.