ADVIGATOR S.R.L., Via Martiri Triestini 9, 20148 Milan, Italy, VAT IT12112650960, is the controller for the personal data described in this policy. You can reach us at legal@advigator.com.
1. Two different roles
Read this first, because it determines which document applies to you.
As a controller — for personal data about the people who visit our website, open an account, pay our invoices and contact our support. We decide why and how that data is processed. This policy covers that role.
As a processor — for the data inside a customer’s Advigator account: their advertising campaigns, customer-directed user records, the changes made in their Amazon Ads accounts. There, our customer decides why and how, and we act on their instructions. That role is governed by the Data Processing Agreement, not by this policy. If you are an employee of an Advigator customer and want to exercise rights over data held in your employer’s account, contact your employer; we will forward any request we receive.
Recruitment is described separately in the Applicant Privacy Notice.
2. What we collect and why
2.1 Website visitors
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| IP address, browser and device information, pages viewed, referring URL | Serving the site, security, abuse and bot prevention | Legitimate interest in operating and protecting the site |
| Advertising and campaign identifiers passed in the URL (utm parameters, gclid, fbclid, rdt_cid, li_fat_id, referral and affiliate codes) | Understanding which channels bring visitors, attributing referrals and affiliate commissions | Consent where set through advertising cookies; otherwise legitimate interest in measuring our own marketing |
| Cookie and tracker data | As set out in the Cookie Policy | Consent, except for strictly necessary cookies |
| Email address, if you subscribe to the newsletter or book a meeting | Sending the content you asked for, arranging the meeting | Consent |
2.2 Account holders and authorised users
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, password (stored as a salted hash), preferred language and reporting currency | Creating and operating your account, authentication | Performance of the contract |
| Sign-in timestamps, sign-in IP addresses, active session records including device and browser | Keeping the account secure, letting you see and revoke your own sessions, investigating suspicious access | Performance of the contract; legitimate interest in security |
| Record of your acceptance of our terms, with version, timestamp and IP address | Proving which version of the agreement applies | Legal obligation; legitimate interest in establishing the contract |
| Product usage events inside the dashboard, linked to your user identifier and email | Finding defects, understanding which features are used, improving the product | Legitimate interest in improving a service we provide to you |
| Support conversations and their content | Answering you, and keeping a record of what was agreed | Performance of the contract |
| Application error reports, which may incidentally contain your identifier or IP address | Diagnosing and fixing faults | Legitimate interest in a reliable and secure service |
Where you act for a corporate customer rather than contracting personally, account administration and support rely on our legitimate interests in serving that organisation, rather than a contract with you personally. Device access by non-essential trackers requires consent where applicable, even when subsequent processing has a separate legal basis. Required account fields are needed to provide access; marketing choices are optional.
2.3 Billing contacts
Company name, billing address, VAT or tax identification number, invoice and payment history, and a payment method token held by our payment processor. We use it to charge for the Services, to issue invoices, and to meet tax and accounting obligations. The legal basis is performance of the contract and compliance with legal obligations. We never receive or store full payment card numbers.
2.4 Prospects and business contacts
If you give us your details at an event, through a form, or in a sales conversation, we process your name, business contact details and the content of our exchanges to follow up, on the basis of our legitimate interest in responding to enquiries and managing business relationships. Electronic marketing requires consent where applicable law requires it; B2B status alone is not an exemption. You can object at any time, and every marketing email carries an unsubscribe link.
2.5 Data about other people
If you provide personal data about another person — for example an Authorised User, billing contact, colleague or referral — you must be authorised to do so and give that person any notice required by law. Do not provide personal data that is unnecessary for the relevant business purpose.
3. Automated decisions
We do not make decisions producing legal or similarly significant effects about individuals by purely automated means. Marketing and usage analysis can involve grouping interests or behaviour; this is distinct from making a legally significant decision about you. The Services do make automated decisions about advertising bids, budgets and targets on our customers’ instructions — those decisions concern campaigns and products, not people, and they are described in the AI Transparency Notice.
4. Who we share data with
We share personal data with the service providers listed on our sub-processor page, which states each provider’s role, location and transfer mechanism. In summary, we use providers for hosting, backups, payments, transactional email, customer support, product analytics, error monitoring, and content delivery and bot protection.
We also disclose personal data:
- to professional advisers (lawyers, accountants, auditors) under a duty of confidentiality;
- to a buyer or successor in the event of a merger, acquisition or reorganisation, on notice to you;
- to public authorities where we are legally required to do so. We assess every request, disclose only what is legally required, and notify affected customers unless we are legally prohibited from doing so.
We may use and disclose relevant personal data where reasonably necessary to establish, exercise or defend legal claims, enforce our agreements, investigate fraud or misuse, or protect the rights, property and safety of Advigator, our customers or others. This does not permit unrelated use of the data or override applicable legal safeguards.
We do not sell Customer Personal Data processed on behalf of customers or use it for cross-context behavioural advertising. On the marketing website, advertising partners may receive identifiers and browsing/conversion information through permitted trackers. Depending on their use and the applicable law, this can constitute “sharing”, targeted advertising or a “sale” even without a monetary payment. Cookie preferences and applicable opt-out rights govern that separate activity. Marketing providers include Meta, Reddit, OpenAI, Partnero, newsletter and booking providers identified in the provider register. We receive data directly from you, your browser, your organisation, authorised platforms and the business contacts or referrals you interact with.
5. International transfers
We are established in Italy, but the production platform is hosted in the United States and most of our providers also process data outside the EEA. For those transfers we use applicable adequacy decisions or appropriate safeguards such as Standard Contractual Clauses and necessary supplementary measures. The instrument depends on the actual recipient and processing; the DPA explains onward-transfer responsibilities. Details for each provider are on the sub-processor page. You can request a copy of the safeguards by writing to legal@advigator.com.
6. How long we keep data
The full schedule is in the Data Retention and Deletion Policy. In summary: independent-controller account records for the life of the account and 90 days after operational closure; Customer content follows the separate transition, retrieval and deletion schedule; invoices and accounting records for 10 years, as required by Italian law; security and authentication logs for 12 months; session records for 90 days; support conversations for 3 years after the last message; marketing contact data until you object or after 24 months of inactivity.
7. Your rights
Depending on where you are, you have some or all of the following rights: to be told what we process and to get a copy of it; to have inaccurate data corrected or incomplete data completed; to have data erased; to restrict processing; to data portability; to object to processing based on our legitimate interests, including direct marketing; to withdraw consent at any time without affecting processing already carried out; and not to be discriminated against for exercising a right.
Where required, we communicate a correction, erasure or restriction to each recipient to whom the relevant personal data was disclosed, unless this is impossible or requires disproportionate effort. We will identify those recipients to you on request where applicable law requires it.
How to exercise them. Write to legal@advigator.com. We will acknowledge within 5 business days and respond within the deadline applicable to your request. For GDPR requests this is one month, with an extension of up to two further months where legally justified and notified within the first month. Other jurisdictions have different deadlines and extension rules. We do not charge for this. We may ask for information to verify your identity, and we will use it only for that purpose. You may use an authorised agent where the law allows it.
Complaints. You can complain to a supervisory authority. In Italy that is the Garante per la protezione dei dati personali. In the UK, the Information Commissioner’s Office. In the EEA, the authority where you live or work. In India, the Data Protection Board of India. We would rather hear from you first.
8. Region-specific information
European Economic Area, United Kingdom and Switzerland. This policy is written to meet Articles 13 and 14 GDPR. The contact point for all data protection matters is legal@advigator.com. You may ask for information about the legitimate interests and safeguards relevant to your data.
United States. Where US state privacy laws apply, the categories of personal information we collect include identifiers and contact information; commercial and billing information; Internet or other electronic network activity; professional or business information; communications with us; and limited inferences used for marketing attribution or service improvement. Sections 2 and 4 describe the relevant sources, purposes and categories of recipients; retention is explained in section 6. We do not use account credentials or other sensitive personal information to infer characteristics. Rights may include access, deletion, correction, portability, opt-out of sale/sharing or targeted advertising and, where provided by law, an appeal or a list of recipients. Write to legal@advigator.com with your jurisdiction and request. If we deny a request, we explain the reason and any applicable appeal process and regulator contact. We respond to appeals within the applicable statutory deadline. Opt-out requests do not require the same identity verification as access to confidential records. We honour legally applicable browser opt-out preference signals, such as Global Privacy Control, for the sale/sharing they cover; cookie settings provide a separate way to manage device-based tracking. These rights depend on the applicable statute and our role.
Brazil. Where the Brazilian Lei Geral de Proteção de Dados (LGPD) applies, Advigator is the controlador for the processing described in this policy. Sections 2, 4 and 6 describe the categories and sources of personal data, purposes, recipients and retention periods. Depending on the activity, processing is based on consent, performance of or steps towards a contract, compliance with a legal or regulatory obligation, the regular exercise of rights, or legitimate interests assessed against your fundamental rights and freedoms.
Subject to the conditions and exceptions in the LGPD, you may request confirmation of processing; access; correction; anonymisation, blocking or deletion of unnecessary, excessive or unlawfully processed data; portability; information about sharing and the consequences of withholding consent; withdrawal of consent; review of a decision based solely on automated processing that affects your interests; and a complaint to the Autoridade Nacional de Proteção de Dados (ANPD). You may act through an authorised representative. Where the LGPD requires it, we provide a simplified response immediately or a complete access response within 15 days. Submit requests to legal@advigator.com; identity verification is proportionate to the request.
Informações sobre transferências internacionais para titulares no Brasil
Quando a LGPD for aplicável, os dados pessoais descritos nesta Política poderão ser transferidos do Brasil para a Itália, outros países do Espaço Econômico Europeu, o Reino Unido, os Estados Unidos e os demais países indicados no registro de fornecedores. As transferências servem às finalidades descritas nesta Política, incluindo hospedagem, segurança, suporte, cobrança, comunicações, análise de uso e publicidade autorizada. A duração do tratamento segue a seção 6 e a Política de Retenção e Exclusão.
O mecanismo aplicável depende do destinatário e da operação e deve atender ao artigo 33 da LGPD e à regulamentação da ANPD. Ele poderá incluir decisão de adequação, cláusulas-padrão contratuais da ANPD ou outro mecanismo legalmente permitido. Quando forem utilizadas cláusulas contratuais, o titular poderá solicitar uma cópia a legal@advigator.com, observados os segredos comercial e industrial. Os fornecedores recebem apenas os dados necessários às respectivas finalidades e ficam sujeitos às responsabilidades contratuais e às medidas de segurança aplicáveis. As medidas gerais estão descritas na Visão Geral de Segurança.
O titular pode exercer os direitos indicados acima pelo canal legal@advigator.com e pode apresentar petição à ANPD. A Advigator é o controlador responsável: ADVIGATOR S.R.L., Via Martiri Triestini 9, 20148 Milan, Italy.
India. For individuals in India, Advigator is a Data Fiduciary for the processing described in this policy, where the DPDP Act applies. The Act and Rules have phased commencement; statutory rights and duties apply from their respective effective dates. We accept privacy requests in the meantime under our stated process. Where applicable, you may access, correct, complete, update and erase your personal data, nominate another person to exercise your rights, and raise a grievance. The contact for grievances and for questions about processing is legal@advigator.com; we acknowledge within 72 hours and respond within 30 days. Where available under the applicable provisions, after exhausting the required grievance process you may complain to the Data Protection Board of India. Consent, where it is the basis for processing, may be withdrawn at any time with the same ease with which it was given.
9. Children
The Services are sold to businesses and are not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe we have, write to legal@advigator.com and we will delete it.
10. Security
We describe our technical and organisational measures in the Security Overview. To report a vulnerability or a suspected incident, follow the Vulnerability Disclosure Policy.
11. Changes
We will post any change on this page and update the version and date at the top. For changes that materially affect how we use your personal data, we will notify account holders by email at least 30 days in advance.
12. Contact
ADVIGATOR S.R.L., Via Martiri Triestini 9, 20148 Milan, Italy — legal@advigator.com.