Privacy Policy

Last Updated: 2025. 11. 27. Effective Date: 2025. 11. 27.

1. Introduction

Aetheos Kft. ("we," "us," or "our"), a company registered in Hungary with headquarters at 7633 Pécs Szigeti út 57/B 1, operates the Aetheos application ("App").

We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App. Our services are designed primarily for Business Entities (B2B) but are also available to individual users.

By using our App to connect your business pages, create ad accounts, and manage ad campaigns via the Meta (e.g. Facebook, Instagram, Whatsapp, Messenger) Platform, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

We collect comprehensive information to facilitate account creation, campaign management, payment processing, and the continuous improvement of our services. This includes:

A. Account & Business Profile Information

To provide a tailored B2B experience, we collect a broad range of data regarding your professional identity and business operations:

B. Meta Platform Data (Facebook & Instagram)

To provide our services, our App interacts with the Meta Graph API and Marketing API. With your explicit consent, we collect the following "Platform Data":

C. Financial & Transaction Information

When you connect payment methods or conduct business through our App:

D. Usage & Behavioral Insights

We automatically collect data on how you interact with our App to improve our product and user experience:

E. Ad Interaction Data (Deep Links & Redirects)

Our services include the generation of deep links (e.g., smart URLs) for your ad assets. When a target user clicks on an ad containing our deep link:

F. Cookies & Local Storage

3. How We Use Your Information

We use the collected data for the following specific purposes:

A. Core Service Provision

B. Service Optimization & Product Development

We use Usage Data, Behavioral Insights, and Aggregated Metrics to:

C. Security & Fraud Prevention

D. Your Role vs. Our Role (Controller vs. Processor)

It is important to distinguish between your data and your customers' data:

4. How We Share Your Information

We do not sell your personal data, Ad Interaction Data, or Meta Platform Data to third parties. We only share information in the following circumstances:

5. Your Data Rights (GDPR & Global)

As a Hungarian company, we adhere to the General Data Protection Regulation (GDPR). Regardless of where you are located globally, we extend these rights to you:

To exercise these rights, please contact our Data Protection Officer (DPO) at: [email protected]. Or use the following google form:
https://docs.google.com/forms/d/e/1FAIpQLSczDXTPiXWEb8rRyyteRbQSBuHH0sactQiuU4I2cINjRosghw/viewform?usp=header

6. Notice to California Residents (CCPA/CPRA)

If you are a resident of California, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information:

To exercise your rights under the CCPA/CPRA, please contact us at [email protected] with the subject line "CCPA Request." Or use the following google form:
https://docs.google.com/forms/d/e/1FAIpQLSczDXTPiXWEb8rRyyteRbQSBuHH0sactQiuU4I2cINjRosghw/viewform?usp=header

7. Data Retention and Deletion

We adhere to a data retention policy designed to comply with legal obligations while ensuring the continuity and improvement of our services.

A. Retention Periods

  1. Active Account Data: We retain your Personal Data, Business Profiles, and Platform Data for as long as your account remains active and the data is necessary to provide our services.
  2. Legal & Financial Records (5-8 Years): To comply with Hungarian accounting laws (Act C of 2000 on Accounting) and the Civil Code, we retain billing information, invoices, and contractual data for a period of 8 years. We also retain data necessary for legal defense for the duration of the general statute of limitations (typically 5 years) after the termination of our contract.
  3. Anonymized Analytical Data (Indefinite): To support our legitimate interest in product development, machine learning training, and business analytics, we retain aggregated, de-identified, and anonymized data indefinitely. This data is stripped of all personal identifiers (such as User IDs or Names) and cannot be used to identify you personally. It is used exclusively to improve our algorithms and automated targeting systems.

B. How to Request Data Deletion (Meta Requirement)

In compliance with Meta’s Platform Terms, you may request the deletion of your personal data through the following methods:

  1. Online Form (Recommended): Submit a request immediately via our dedicated Data Deletion Request Form at: 
    https://docs.google.com/forms/d/e/1FAIpQLSczDXTPiXWEb8rRyyteRbQSBuHH0sactQiuU4I2cINjRosghw/viewform?usp=header
  2. In-App: Go to [Settings > Delete Account] within our App.
  3. Facebook Settings:
  1. Email Request: Email [email protected] with the subject "Data Deletion Request." We will process your request within 30 days.

Upon deletion, we will remove your User ID, Access Tokens, and personal information from our active databases. As stated above, anonymized and aggregated data that has been permanently de-identified will be retained for service improvement purposes.

8. International Data Transfers

Our servers are located in [Location, e.g., the European Economic Area (EEA)]. If you access our App from outside the EEA, your information may be transferred to, stored, and processed in a country that may not have the same data protection laws as your jurisdiction. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure the safety of cross-border data transfers.

9. Security

We implement industry-standard security measures (e.g., SSL encryption, secure token storage, and access controls) to protect your data. However, no method of transmission over the internet is 100% secure.

10. Children's Privacy

Our Services are intended for a general audience and business users. We do not knowingly collect, solicit, or maintain personal information from children under the age of 13 (or 16 in certain jurisdictions, including the EU). If we become aware that we have collected personal data from a child under the relevant age without parental consent, we will take steps to delete that information.

11. Governing Law

This Privacy Policy and any disputes arising out of or related to it shall be governed by and construed in accordance with the laws of Hungary, without regard to its conflict of law principles.

12. Contact Us

If you have questions about this Privacy Policy, please contact us at:

Aetheos Kft. Szigeti út 57/B 1 Pécs 7633, Hungary Email: [email protected]