Privacy Policy
Last updated: 22 July 2026
This Privacy Policy explains how Serann Limited, a company registered in England & Wales (Company No. 13457476; registered office 182-184 High Street North, Office 16521, East Ham, London, E6 2JA, United Kingdom), trading as Ad-Efficiency ("we", "us", "our"), collects, uses and protects personal data when you use our website, the Ad-Efficiency ads automation platform and our MCP (Model Context Protocol) connector (together, the "Service").
We are the data controller for personal data relating to our website, your account, lead and billing information. For the advertising-platform data that you (or your agency) connect to the Service, we act as a data processor on your documented instructions and process that data solely to deliver the Service to you. Business and agency customers can request a Data Processing Agreement (DPA) at privacy@ad-efficiency.com. For any questions about this policy, contact us at the same address.
1. What we collect
- Account information you provide directly: name, work email, company, country, role, and any information you submit through our contact or audit-request forms.
- Lead-form data: information you submit when requesting a free audit, joining the waitlist or contacting sales, including answers to qualifying questions. Where present in the URL you arrived from, this also includes the click identifiers and campaign parameters described in Section 11 (for example gclid, wbraid, gbraid, utm_source, utm_medium, utm_campaign, utm_term, utm_content and the landing page).
- Advertising platform data, for users who connect an advertising account (Google Ads, Meta Ads, TikTok Ads, Microsoft Advertising, Amazon Ads, Google Analytics 4, Google Merchant Center, Shopify, etc.). Accessed strictly via each platform's official API under OAuth scopes you explicitly authorise. This may include:
- Account, campaign, ad group, ad and asset structure;
- Performance metrics (impressions, clicks, spend, conversions, CPA, ROAS);
- Budgets, bids, bidding strategies and pacing data;
- Search terms, negative keywords and audience configuration;
- Change history, recommendations and diagnostic data returned by the platform.
- Usage & technical data: IP address, browser type, device information, pages viewed, actions taken in the Service, and server logs required for security and troubleshooting.
2. Why we collect it
We process personal data to:
- Deliver free audits and reports you request;
- Provide, operate and maintain the Service, including continuous monitoring, anomaly detection, proposed optimisations and approval-gated changes to connected ad accounts;
- Communicate with you about your account, support requests and material product changes;
- Comply with legal obligations and defend legal claims;
- Improve the Service (aggregated / de-identified analysis only, see Section 4 on Limited Use).
3. Legal bases (UK GDPR / EU GDPR)
- Contract, to provide the Service you have signed up for or requested.
- Legitimate interests, to operate, secure and improve the Service, and to communicate with existing customers about their account. We balance these interests against your rights.
- Consent, for OAuth connections to advertising platforms and for any non-essential cookies. You can withdraw consent at any time.
- Legal obligation, for tax, accounting and lawful requests from authorities.
4. Google API Services User Data Policy, Limited Use
Ad-Efficiency's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, in relation to Google user data obtained via Google APIs (including Google Ads API, Google Analytics API and Google Merchant Center API):
- We only use Google user data to provide and improve user-facing features that are prominent in the Service (audits, reports, monitoring, and proposed / approved optimisations of your own ad accounts).
- We do not sell Google user data.
- We do not use Google user data for serving advertisements, including retargeting, personalised or interest-based advertising.
- We do not allow humans to read Google user data, except (a) with your explicit consent for specific data; (b) for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) where the data (including derivatives) has been aggregated and is used for internal operations in accordance with applicable law.
- We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with your prior notice.
Google OAuth scopes we request
When you connect a Google account, we request only the scopes listed below. Each scope is used solely to deliver the user-facing features described above.
https://www.googleapis.com/auth/adwords, to read campaign structure and performance from your Google Ads account for audits, monitoring and reporting. Google offers only one permission level for this API, worded "see, edit, create and delete", with no read-only alternative. Our code contains no write operations against Google Ads.https://www.googleapis.com/auth/analytics.readonly, to read GA4 property lists and channel, session and conversion reports for the properties you select. This scope is read-only by definition.https://www.googleapis.com/auth/content, to read Merchant Center account lists and product status for Shopping advertisers. We read product statuses only and do not modify listings.openidandhttps://www.googleapis.com/auth/userinfo.email, to identify the signing-in user and bind the connection to the correct workspace. Only the verified email address is stored; no other profile data is retained.
Refresh tokens are encrypted at rest before storage, and you can revoke access at any time from the Ad-Efficiency console or from your Google account settings at myaccount.google.com/permissions.
5. Meta and other advertising platforms
Data accessed through Meta (Facebook / Instagram) APIs, TikTok Marketing API, Microsoft Advertising API, Amazon Ads API, and any other connected platform is handled under the equivalent commitments: used only to deliver user-facing features of the Service, never sold, never used for advertising outside your own accounts, and never accessed by humans except with your consent, for security, or as required by law. We comply with each platform's Developer Terms and Platform Policies.
6. Retention
- Advertising platform tokens and cached data are deleted when you disconnect the platform in your dashboard or when your account is closed.
- Account and billing records are retained for the duration of your relationship with us and for up to 6 years afterwards where required by UK tax and accounting law.
- Lead-form submissions from prospects who do not become customers are retained for up to 24 months, then deleted or anonymised.
- Backups are rotated and purged within 30 days of the corresponding production deletion.
- You may request deletion at any time (see Section 10 and our Data Deletion page).
7. Subprocessors
We rely on a small number of vetted subprocessors to operate the Service, including:
- Hostinger (EU cloud hosting, Paris, France), primary application hosting and encrypted token store;
- Google (Google Ads API, Google Analytics API, Google Merchant Center API), advertising and analytics data accessed on your behalf under your OAuth authorisation;
- Managed database and object storage providers;
- Email delivery and transactional messaging providers;
- PostHog (EU region, Ireland), product and website analytics;
- Google (Google Analytics 4 and Google Ads), website analytics and advertising measurement, separate from the Google APIs used to access customer ad accounts listed above;
- Lovable, hosting and delivery of the marketing website at ad-efficiency.com, which processes technical delivery and platform telemetry data;
- AI model providers used to generate reports and recommendations, these providers are contractually restricted from training their models on your data.
Each subprocessor is bound by a written data processing agreement with confidentiality and security obligations. Our current list of named subprocessors is available on request from privacy@ad-efficiency.com.
8. International transfers
Some subprocessors may process data outside the UK / EEA. Where this happens, transfers are protected by appropriate safeguards, including the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision covering the destination country.
9. Security and data residency
Where your data is hosted. Our primary application infrastructure at app.ad-efficiency.com and the encrypted store that holds your advertising-platform connection tokens are hosted in the European Union, in a data centre in Paris, France, operated by our hosting subprocessor Hostinger. Only encrypted connection tokens are stored; we do not copy your campaign data into our systems, we read it on demand via each platform's official API when you or your approved automation ask us to.
The marketing website at ad-efficiency.com is hosted separately by our subprocessor Lovable and is not part of the EU application hosting described above.
We use industry-standard measures to protect personal data, including encryption in transit (TLS) and at rest, least-privilege access controls, audit logging of privileged actions, and regular review of our security posture. No system is perfectly secure; we will notify affected users and the ICO within statutory deadlines if a personal data breach is likely to affect your rights.
10. Your rights
Under UK GDPR and EU GDPR you have the right to:
- Access the personal data we hold about you;
- Ask us to rectify inaccurate data;
- Ask us to erase your data (see /data-deletion);
- Restrict or object to certain processing;
- Data portability, receive a machine-readable copy of data you provided;
- Withdraw consent at any time (without affecting prior lawful processing);
- Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.
To exercise any of these rights, email privacy@ad-efficiency.com. We will respond within 30 days.
11. Cookies and website tracking
We use essential cookies required for the site and product to function (session, security, load balancing), and a small number of analytics and advertising measurement tools. None of these tools stores anything on your device until you accept in the cookie banner. Where required by law, we ask for your consent before setting any non-essential cookies.
The tools we run on this website are listed below. If you decline, no cookies are set and nothing is stored on your device, and the exact loading behaviour of each tool is described in the table and the notes below. You can withdraw consent at any time using the "Cookie settings" link in the site footer. Declining or withdrawing consent does not reduce your access to the site.
| Provider | Purpose | Set only after consent | Typical retention |
|---|---|---|---|
| PostHog (EU region, eu.i.posthog.com) | Product and website analytics. Before consent, PostHog runs in a cookieless, memory-only mode and sets no cookies. After consent, it sets a ph_* cookie to recognise returning visits. | Yes, for the cookie. The cookieless mode runs from first visit. | Up to 12 months |
| Google Analytics 4 | Website analytics via gtag.js. Sets _ga and _ga_* cookies. | Cookies: yes. The tag script itself loads for all visitors but stores nothing until you accept. | Up to 24 months |
| Google Ads | Conversion measurement and remarketing via gtag.js. Sets _gcl_* cookies. | Cookies: yes. The tag script itself loads for all visitors but stores nothing until you accept. | Up to 90 days |
We use Google Consent Mode v2 in advancedconfiguration. The Google tag now loads for every visitor, but every storage and advertising consent signal starts set to denied. Until you accept, the tag stores nothing on your device and no analytics or advertising cookies are set.
Before consent the tag may send cookieless pings to Google that contain no identifiers and cannot be used to recognise you. Google uses these only to produce aggregate, modelled measurement. If you accept, the consent signals are updated to granted and the cookies described in the table above are set. If you decline, or withdraw consent later using "Cookie settings", the signals stay or return to denied and no cookies are set.
We made this choice so we can measure our advertising performance in aggregate without tracking people who have not agreed to be tracked.
Enhanced conversion measurement
If you accept cookies and then submit one of our forms, we send Google a one-way SHA-256 hash of your email address alongside the conversion event. The hash is computed in your browser before anything is sent, so your actual email address is never transmitted to Google. Google uses the hash only to match the conversion to an existing signed-in Google user and improve the accuracy of our advertising measurement. If you decline cookies, nothing is sent at all.
Purpose: measuring the effectiveness of our own advertising. Legal basis: your consent, which you can withdraw at any time.
Click identifiers and campaign parameters
When you arrive from an advertisement or a tagged link, the URL may contain a click identifier (gclid, wbraid orgbraid) or campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content). We store these, together with the page you landed on, in your browser's local storage under the key ae_attribution for up to 90 days, after which they expire automatically.
If you then submit an enquiry form, these values are attached to your enquiry so we can tell which advertisement or campaign it came from. They contain no directly identifying information on their own. We may later send Google the fact that an enquiry became a qualified lead or a customer, using the click identifier only, so that our advertising measurement reflects real business outcomes rather than form fills.
Purpose: advertising attribution and measurement. Legal basis: your consent for the browser storage, and our legitimate interest in understanding which marketing works for the record attached to your enquiry. Retention: 90 days in your browser, and alongside your enquiry record for the lead retention period already stated in Section 6.
12. Children
The Service is a B2B product and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. Material changes will be announced in-product or by email at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the current version.
14. Contact
Serann Limited, trading as Ad-Efficiency
Company No. 13457476, Registered in England & Wales
Registered office: 182-184 High Street North, Office 16521, East Ham, London, E6 2JA, United Kingdom
Email: privacy@ad-efficiency.com