Privacy Policy & Data Processing Agreement
This document serves as both our public-facing Privacy Policy and as the Data Processing Agreement (DPA) under GDPR Article 28 between Local Adboost ("Local Adboost Oy", "Processor") and you ("Controller") for data processed on your behalf through the Service.
A. Privacy Policy — visitors and users
Who we are
Local Adboost Oy, registered at Vuorikatu 16 A 2, 00100 Helsinki, Finland.
Company registration number: 3633155-7. VAT: FI36331557.
Data Protection contact: advertise@localadboost.com
What data we collect and why
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email, password | Account creation and login | Contract (Art. 6(1)(b)) | Until account deleted + 30 days |
| Business name, address, phone | Google Ads campaign setup | Contract (Art. 6(1)(b)) | Duration of contract + 1 year |
| Payment data (via Stripe) | Billing | Contract + legal obligation | 7 years (tax law) |
| Google Ads performance data | Reporting and optimisation | Contract (Art. 6(1)(b)) | Duration of contract + 1 year |
| Server logs (IP, browser) | Security and debugging | Legitimate interest (Art. 6(1)(f)) | 30 days |
Third-party sub-processors
- Google LLC — Google Ads API, Google Business Profile API (USA; EU SCCs)
- Stripe Inc. — Payment processing (USA; EU SCCs, PCI-DSS)
- OpenAI / Anthropic — AI-generated ad copy (USA; EU SCCs). Only business context (vertical, city, ad language) is transmitted — no personal data of your customers.
- [HOSTING PROVIDER] — Cloud infrastructure ([LOCATION])
Cookies
We use a session cookie to keep you logged in and a consent cookie to remember your cookie preferences. With your consent we load Google Tag Manager, which may set analytics and marketing cookies (for example Google Analytics and Google Ads conversion measurement). Stripe sets its own cookies during checkout (see Stripe Privacy Policy).
For marketing measurement we may send a SHA-256 hash of your email address to Google — never the plain email — but only if you accept marketing cookies. You can change your choices anytime via Cookie settings in the site footer.
Legal basis: necessary cookies — legitimate interest / contract; analytics and marketing cookies — consent (GDPR Art. 6(1)(a)).
Your rights (GDPR)
You have the right to access, rectify, erase, restrict, and port your data, and to object to processing based on legitimate interests. To exercise these rights email advertise@localadboost.com. You may also lodge a complaint with your national supervisory authority.
International transfers
Data is transferred to Google and Stripe in the USA under Standard Contractual Clauses (EU Commission Decision 2021/914). No other international transfers occur without equivalent safeguards.
B. Data Processing Agreement (GDPR Art. 28)
This section constitutes the DPA between you (Controller) and Local Adboost (Processor) for personal data processed on your behalf in connection with your Google Ads campaigns.
Subject matter and nature of processing
We process personal data to create and manage Google Ads campaigns, including: linking your Google Business Profile, provisioning call-tracking conversion actions, and reporting on campaign performance (clicks, calls, direction requests, store visits).
Categories of data subjects and personal data
Your potential and actual customers whose interactions are recorded via Google's conversion tracking (calls, direction clicks, store visits). Data held: aggregated conversion counts and campaign performance metrics — no individual-level customer records are stored in our systems.
Processor obligations
- Process personal data only on your documented instructions (this DPA and the Terms of Service).
- Ensure that persons authorised to process data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Art. 32).
- Assist you in responding to data subject requests within 72 hours of receipt.
- Notify you without undue delay (within 72 hours) of any personal data breach.
- Delete or return all personal data upon termination of the contract.
- Make available all information necessary to demonstrate compliance with Art. 28.
Sub-processors
We engage the sub-processors listed in Section A above. We will notify you at least 14 days before engaging a new sub-processor. You have the right to object; if we cannot accommodate the objection, you may terminate the contract without penalty.
Security measures (Art. 32)
- Encryption in transit (TLS 1.2+) and at rest
- Access controls and principle of least privilege
- API credentials stored as environment secrets, never in source code
- Regular dependency updates and vulnerability scanning
Audit rights
You may request an audit of our processing activities at most once per year, with 30 days' written notice. We may satisfy this right via a third-party certification or summary documentation.
Contact
Local Adboost Oy
Vuorikatu 16 A 2, 00100 Helsinki, Finland
Privacy: advertise@localadboost.com