Advarde is a product of BURO OPS AS, Norway.
Privacy request · No sign-in required
1. Data we can delete
After verifying your request and any required authority, we will delete the eligible data within the agreed scope, or irreversibly anonymize it where appropriate. This covers the following categories where we hold them. You can request all eligible account data, an authorized workspace closure, or selected records without closing your account.
- Account and sign-in data. Profile name and email, sign-in credentials, MFA and recovery data, sessions, verification links, invitations, memberships, preferences, and API or MCP access grants.
- Connected services and imported data. Stored connection credentials and account identifiers; imported advertising, analytics, spreadsheet and performance data, including Facebook and Instagram data received through Meta; saved copies derived from those imports.
- Campaigns, creatives and planning. Local campaign drafts, creative assets and delivery links, builds, change proposals, targeting and campaign settings, conversion setups, experiments, business outcomes, competitor research, and saved planning records.
- Automation and reporting. Automation policies, evaluations and actions, optimization settings, runs and feedback, account snapshots and issues, standards, reports, schedules, notifications, and local usage records that are not needed for billing or claims.
- Support and communications. Support correspondence, feedback requests and comments, internal account or workspace notes, and queued or stored messages, except portions that must be kept for a specific legal, financial or dispute purpose.
- Marketing and referral data. Identifiable acquisition journeys and events, campaign attribution, marketing preferences, and nonessential referral details. Financial commission and settlement evidence is reviewed separately.
- Workspace and organization data. Workspace name, onboarding data, team access, account connections, settings, and the eligible workspace content listed above, when the organization has authorized deletion.
- Other copies held on our behalf. Relevant exports, working files, archives and processor-held copies within the approved scope. Restricted backups follow their retention cycle, with deletions reapplied after a restore.
We review related and derived copies, not just the original connection. Disconnecting an integration or revoking a token alone does not complete a deletion request. We will describe what was deleted, anonymized or retained in the outcome.
2. Records we may need to retain
Deletion excludes records that we must keep under applicable law or that remain necessary for a specific lawful purpose. We retain only the relevant information, limit its use and access, and delete or anonymize it when the retention basis ends.
- Accounting, tax and financial records: invoices, receipts, payment and refund records, tax information, subscription transaction history, balances, commission or payout records, and information needed to reconcile them. Norwegian bookkeeping retention requirements apply where relevant. This does not justify keeping every profile, marketing record or campaign simply because you were a paying customer.
- Disputes and legal claims: relevant contracts, accepted terms, transaction or authorization evidence, correspondence and other records necessary to establish, exercise or defend a specific actual or reasonably anticipated claim, including chargebacks and payment disputes.
- Legal duties and preservation orders: information subject to a statutory obligation, valid legal process, regulatory requirement or documented preservation hold.
- Necessary security and accountability records: limited evidence needed to investigate fraud or security incidents, prevent abuse, and demonstrate how we handled a privacy request, where a valid legal basis still applies. We minimize personal identifiers and content where possible.
These are case-specific exceptions, not indefinite retention of all your data. Our response will explain the retained categories, the reason and applicable retention period or criteria. Where possible, we delete the remaining eligible data while retaining only the records covered by the exception.
3. What happens after you submit
- Receipt: the form records your request and provides a reference and private status link. Save that link; we do not automatically send it by email.
- Review: we confirm the data involved, verify identity proportionately where needed, and check any representative or workspace authority. We may arrange a separate verification step using a known account or contact. The link and a typed email address do not by themselves prove ownership.
- Action: we delete or anonymize eligible records, review legal and financial exceptions, and coordinate relevant processor-held copies. If your organization controls the data, we refer the request to its authorized contact and assist them.
- Outcome: we publish an explanation on your private request page, including any retained records and remaining steps. You can reply there while the case is open. Check the page for questions and updates.
4. Response times and backups
We respond without undue delay, normally within one calendar month of receipt. The receipt shows our response target; it is not a promise that every backup or external record will be erased by that date. Where applicable law permits an extension, we explain the reason and revised timing within the original response period. Any shorter applicable requirement takes precedence.
Deleted data may remain in restricted backups pending separate expiry or deletion under the applicable retention decision and any lawful preservation requirement. Creating a new backup does not by itself erase older copies. Such copies are not returned to ordinary use, and deletion and access-revocation instructions must be reapplied before restored data returns to service. We will explain backup handling relevant to your request without promising a retention period we cannot substantiate.
5. Shared workspaces and external services
A personal request does not authorize deletion of another person's data or an entire organization. We can remove eligible personal data while preserving lawful shared records; whole-workspace deletion needs the organization's authorized instruction.
Deleting Advarde data does not automatically stop live advertising, cancel a paid subscription, settle unpaid amounts, or delete records independently held by OpenAI Ads, Meta, Google, Stripe, your AI client or another provider. Tell us if you also want account closure or help arranging subscription cancellation. Live campaigns and provider accounts must be managed through their own controls and deletion procedures.
For Meta, you can remove Advarde in Facebook's Apps and Websites settings or Business Integrations. To delete previously imported Facebook or Instagram data held by Advarde, use the form above and identify the relevant service or account. You can submit even after disconnecting or losing access to Advarde.
Information already irreversibly anonymized so it cannot identify you may remain as aggregate statistics. Removing browser cookies or local files on your own devices is separate from deleting our server records.
6. Help and privacy rights
The request form is the primary way to submit and track a deletion request. If you cannot use it, you may send a written request to BURO OPS AS, Anna Hagmans Gate 3K, 1511 Moss, Norway. Other valid privacy requests are still recognized; use of this form is not a condition of exercising your rights.
Our Privacy Policy explains retention, contact details and your rights. If we cannot fulfill part of your request, we explain the reason and available remedies. You can complain to Datatilsynet or another competent supervisory authority and seek a judicial remedy.