Privacy Policy
Last Updated: 2025. 11. 27. Effective Date: 2025. 11. 27.
1. Introduction
Aetheos Kft. ("we," "us," or "our"), a company registered in Hungary with headquarters at 7633 Pécs Szigeti út 57/B 1, operates the Aetheos application ("App").
We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App. Our services are designed primarily for Business Entities (B2B) but are also available to individual users.
By using our App to connect your business pages, create ad accounts, and manage ad campaigns via the Meta (e.g. Facebook, Instagram, Whatsapp, Messenger) Platform, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect comprehensive information to facilitate account creation, campaign management, payment processing, and the continuous improvement of our services. This includes:
A. Account & Business Profile Information
To provide a tailored B2B experience, we collect a broad range of data regarding your professional identity and business operations:
- Identity Data: Name, email address, phone number, and professional role/title.
- Corporate Identity: Business name, registration details, tax identification numbers (e.g., VAT IDs), and business summaries.
- Digital Presence: URLs to your business websites, social media profiles, and other digital touchpoints.
- Brand Assets & Visual Materials: Logos, color palettes, ad creatives, images, and other visual branding materials you upload or link to our system.
- Operational Data: General information about your business vertical, target markets, and strategic goals.
B. Meta Platform Data (Facebook & Instagram)
To provide our services, our App interacts with the Meta Graph API and Marketing API. With your explicit consent, we collect the following "Platform Data":
- User Identity: Your Facebook User ID, name, and profile picture (to verify your identity and link your Business Manager).
- Business Assets: Information about the Facebook Pages, Instagram Business Accounts, and Business Managers you administer (e.g., IDs, Names, Access Tokens, etc.).
- Ad Account Data: Technical details of ad accounts we create or manage on your behalf (e.g., Ad Account IDs, Currency, Timezone, Funding Source).
- Aggregated Performance Metrics: Statistical data regarding the performance of your campaigns (e.g., Reach, Impressions, Clicks, Spend, CPM, CTR).
- Clarification: We do not receive the personal Facebook profiles or identities of individuals who view or click your traffic ads, unless they explicitly submit a Lead Gen form.
C. Financial & Transaction Information
When you connect payment methods or conduct business through our App:
- Payment Details: We collect data necessary to process payments, such as credit card tokens (via secure third-party processors, etc.), bank account details, and billing addresses.
- Transaction History: Records of your invoices, payments, and subscription status.
- Spending Habits: Data regarding your advertising budget allocation and historical spending patterns.
D. Usage & Behavioral Insights
We automatically collect data on how you interact with our App to improve our product and user experience:
- Engagement Metrics: Information about how you use our services, including features accessed, time spent on specific pages, click patterns, and session duration.
- Behavioral Trends: Analysis of your navigation paths and workflow preferences within the dashboard.
- Device & Connection Data: IP address, browser type, operating system, and device identifiers.
E. Ad Interaction Data (Deep Links & Redirects)
Our services include the generation of deep links (e.g., smart URLs) for your ad assets. When a target user clicks on an ad containing our deep link:
- Redirection Data: The user is momentarily routed through our servers before being instantly redirected to your specified destination URL.
- Technical Logs: During this process, we automatically log technical data required to execute the redirect, including the user's IP Address, User Agent (e.g., browser/device type), Timestamp, and Referring URL.
F. Cookies & Local Storage
- Dashboard Session: We use cookies or local storage tokens solely within our App’s dashboard to maintain your secure login session and preferences.
- Ad Tracking: We do not place tracking cookies on the end-user's device during the deep link redirection process. Any cookies set on the final destination page are governed by your own privacy policy.
3. How We Use Your Information
We use the collected data for the following specific purposes:
A. Core Service Provision
- Account Management: To create, configure, and link Meta Ad Accounts to your Business Manager.
- Campaign Execution: To publish ads, manage budgets, and optimize ad performance via the Meta Marketing API.
- Deep Linking Service: To process ad clicks via our servers, ensuring users are correctly routed to your content (e.g., opening your mobile app or website specific content).
- Financial Processing: To manage your subscriptions, process ad spend payments, and generate invoices.
B. Service Optimization & Product Development
We use Usage Data, Behavioral Insights, and Aggregated Metrics to:
- Product Improvement: Analyze user behavior (e.g., heavily used features, drop-off points, etc.) to design better interfaces and new functionalities.
- Automated Targeting: Analyze historical performance and spending trends to refine our internal algorithms, allowing our system to suggest better targeting parameters.
- Machine Learning: Train our models using non-personally identifiable data to make our ad optimization logic smarter and more cost-effective.
- Note: We do not use specific customer lists or sensitive data to build cross-client user profiles in violation of Meta’s data commingling policies.
C. Security & Fraud Prevention
- Bot Detection: We use Ad Interaction Data (e.g., IPs/User Agents) to detect and filter out invalid traffic (bots) before they reach your landing page.
- Compliance: To verify legitimate use of the Meta Platform and prevent abuse of our ad accounts.
D. Your Role vs. Our Role (Controller vs. Processor)
It is important to distinguish between your data and your customers' data:
- Our Role as Controller: We act as the Data Controller for the information you provide to us directly (e.g., your account details, billing info, and business profile) to manage your account and improve our services.
- Our Role as Processor: When you use our App to upload your own customer lists (e.g., for Custom Audiences) or manage ads targeting your own users, You act as the Data Controller and we act as the Data Processor.
- Your Responsibility: You warrant that you have obtained all necessary consents and legal rights to collect and use your customers' data before uploading it to our App or the Meta Platform. We process this data solely on your instructions to execute your ad campaigns.
4. How We Share Your Information
We do not sell your personal data, Ad Interaction Data, or Meta Platform Data to third parties. We only share information in the following circumstances:
- With Meta (Third-Party Disclosure): Your data is inherently shared with Meta (e.g., Facebook/Instagram, etc.) as necessary to execute ad campaigns and manage pages on the platform.
- Service Providers: We may share data with trusted third-party vendors who assist us in operating our infrastructure (e.g., cloud hosting providers like AWS/Google Cloud, payment processors, etc.). These partners are bound by confidentiality agreements and GDPR data processing addendums.
- Legal Requirements: If required by Hungarian law or valid legal process (e.g., court order).
5. Your Data Rights (GDPR & Global)
As a Hungarian company, we adhere to the General Data Protection Regulation (GDPR). Regardless of where you are located globally, we extend these rights to you:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request correction of inaccurate data.
- Right to Erasure ("Right to be Forgotten"): You can request that we delete your personal data and associated Platform Data.
- Right to Restriction: You can ask us to pause processing your data.
- Right to Data Portability: You can request your data in a structured, machine-readable format.
- Right to Withdraw Consent: You may revoke our App’s permissions at any time via your Facebook Settings.
To exercise these rights, please contact our Data Protection Officer (DPO) at: [email protected]. Or use the following google form:
https://docs.google.com/forms/d/e/1FAIpQLSczDXTPiXWEb8rRyyteRbQSBuHH0sactQiuU4I2cINjRosghw/viewform?usp=header
6. Notice to California Residents (CCPA/CPRA)
If you are a resident of California, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information:
- Right to Opt-Out of Sale or Sharing: We do not sell your personal information for monetary value. However, the use of certain tracking technologies for "cross-context behavioral advertising" may be defined as "sharing" under California law. You have the right to opt-out of this sharing.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- Right to Limit Use of Sensitive Personal Information: You may limit our use of your sensitive personal information to that which is necessary to perform the services.
To exercise your rights under the CCPA/CPRA, please contact us at [email protected] with the subject line "CCPA Request." Or use the following google form:
https://docs.google.com/forms/d/e/1FAIpQLSczDXTPiXWEb8rRyyteRbQSBuHH0sactQiuU4I2cINjRosghw/viewform?usp=header
7. Data Retention and Deletion
We adhere to a data retention policy designed to comply with legal obligations while ensuring the continuity and improvement of our services.
A. Retention Periods
- Active Account Data: We retain your Personal Data, Business Profiles, and Platform Data for as long as your account remains active and the data is necessary to provide our services.
- Legal & Financial Records (5-8 Years): To comply with Hungarian accounting laws (Act C of 2000 on Accounting) and the Civil Code, we retain billing information, invoices, and contractual data for a period of 8 years. We also retain data necessary for legal defense for the duration of the general statute of limitations (typically 5 years) after the termination of our contract.
- Anonymized Analytical Data (Indefinite): To support our legitimate interest in product development, machine learning training, and business analytics, we retain aggregated, de-identified, and anonymized data indefinitely. This data is stripped of all personal identifiers (such as User IDs or Names) and cannot be used to identify you personally. It is used exclusively to improve our algorithms and automated targeting systems.
B. How to Request Data Deletion (Meta Requirement)
In compliance with Meta’s Platform Terms, you may request the deletion of your personal data through the following methods:
- Online Form (Recommended): Submit a request immediately via our dedicated Data Deletion Request Form at:
https://docs.google.com/forms/d/e/1FAIpQLSczDXTPiXWEb8rRyyteRbQSBuHH0sactQiuU4I2cINjRosghw/viewform?usp=header - In-App: Go to [Settings > Delete Account] within our App.
- Facebook Settings:
- Go to your Facebook profile and navigate to Settings & Privacy > Settings.
- Click on Apps and Websites.
- Find Aetheos app in the list and click Remove.
- This action will automatically trigger a notification to our system to delete your associated user tokens and identifiers.
- Email Request: Email [email protected] with the subject "Data Deletion Request." We will process your request within 30 days.
Upon deletion, we will remove your User ID, Access Tokens, and personal information from our active databases. As stated above, anonymized and aggregated data that has been permanently de-identified will be retained for service improvement purposes.
8. International Data Transfers
Our servers are located in [Location, e.g., the European Economic Area (EEA)]. If you access our App from outside the EEA, your information may be transferred to, stored, and processed in a country that may not have the same data protection laws as your jurisdiction. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure the safety of cross-border data transfers.
9. Security
We implement industry-standard security measures (e.g., SSL encryption, secure token storage, and access controls) to protect your data. However, no method of transmission over the internet is 100% secure.
10. Children's Privacy
Our Services are intended for a general audience and business users. We do not knowingly collect, solicit, or maintain personal information from children under the age of 13 (or 16 in certain jurisdictions, including the EU). If we become aware that we have collected personal data from a child under the relevant age without parental consent, we will take steps to delete that information.
11. Governing Law
This Privacy Policy and any disputes arising out of or related to it shall be governed by and construed in accordance with the laws of Hungary, without regard to its conflict of law principles.
12. Contact Us
If you have questions about this Privacy Policy, please contact us at:
Aetheos Kft. Szigeti út 57/B 1 Pécs 7633, Hungary Email: [email protected]