Advarde is a product of BURO OPS AS, Norway.
1. Who is responsible for your data
Advarde is a product of BURO OPS AS, a Norwegian private limited company, organisation number 832 405 612. Our contact address is Anna Hagmans Gate 3K, 1511 Moss, Norway. In this policy, "we", "us", and "our" refer to BURO OPS AS.
We are the data controller for personal data used to run our website, manage accounts and subscriptions, communicate with you, and protect the Service. This policy covers visitors, account holders, invited team members, and people who contact us. It explains our processing under the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.
When a customer uses Advarde to process personal data in advertising, audience, or conversion information on its instructions, that customer or its client determines the purposes and acts as controller. We act as processor or subprocessor under the applicable data processing agreement. The customer's privacy notice explains that processing. This policy does not replace that notice or the agreement.
2. The information we process
- Account and contact details: name, email address, password hash, email-verification status, account settings, and communications you send us.
- Authentication and security information: session and access-token records, connected client permissions, sign-in and recovery events, and two-factor authentication information if enabled. We store passwords and supported access tokens as hashes, and supported provider credentials and authenticator secrets in encrypted form.
- Workspace information: workspace name, membership, roles, invitations, inviter details, plan, usage, access decisions, and activity history identifying who performed an action.
- Advertising and business information: connected account identifiers, account names, currency and time zone, credentials, campaigns, creatives, URLs, images, uploaded workbooks, targeting, budgets, performance reports, saved plans, and automation settings. Depending on the features you use, this can include audience identifiers, conversion setup and event information, and business outcome data. Business records can contain personal data.
- Billing information: billing contact and business details, selected plan, subscription status, invoices, payment and customer identifiers, and limited payment-method details supplied by Stripe, such as card brand and last digits. Payment-card entry is handled by Stripe; our application server does not receive full card numbers or security codes.
- Technical information: IP addresses used to serve requests and prevent abuse, browser and device information sent with requests, request identifiers, route, response status, timing, and service or security logs. Hosting and delivery providers may also process connection logs.
- Support information: the issue you describe, correspondence, attachments you choose to send, and the account or workspace information needed to investigate.
- Optional website measurement: with your permission, the source, campaign label and landing page that brought you to Advarde, selected website actions, and a browser measurement identifier. If you register, we can link these to your account, your first workspace, its first successful report or validated draft, and its current subscription status. This helps us understand which resources lead to useful product use. We do not collect uploaded workbook contents, advertiser report contents, or arbitrary URL parameters for this purpose. Directory measurement includes listing views, agency website clicks, comparison selections and links to Advarde. Verified agency owners can see aggregate counts of listing views and website clicks; they do not receive visitor identities or browsing histories. Ownership claim actions are recorded separately for account administration.
Please provide only information needed for the task. Advarde is not designed to hold medical records, other special-category data, criminal-offence data, or children's personal data. Do not include these in ads, uploads, or support requests. Use designated connection fields for credentials.
3. Where information comes from
We receive information directly from you when you register, use the Service, make a payment, or contact us. Your workspace administrator or colleague can provide your email address and role when inviting you. We receive account and advertising information from the providers you connect, payment updates from Stripe, and inputs from clients you authorise.
We also receive technical information from your browser and device. If you use a feature that imports files, retrieves a public webpage, or connects another reporting source, we process the information from that source to complete your request. Optional integrations only apply when available and enabled; this policy does not mean every described feature is enabled for your workspace.
4. Purposes and legal bases
When we act as controller, we use the following legal bases. Where the contract is with your employer or another organisation rather than with you personally, processing its representatives' data generally relies on our legitimate interests in providing and administering that business relationship.
| Purpose and data | Legal basis |
|---|---|
| Create accounts, authenticate users, provide workspace access and requested features using account, security, and workspace details. | Performance of a contract with you (Article 6(1)(b)); legitimate interests in serving organisational customers and their users (Article 6(1)(f)). |
| Manage subscriptions, payments, invoices, and accounting using billing and account details. | Contract; legitimate interests in administering business accounts; legal obligations for accounting and tax records (Article 6(1)(c)). |
| Respond to requests and send invitations, verification, recovery, billing, and essential service notices. | Contract or legitimate interests in assisting users and maintaining the service relationship. |
| Prevent fraud and abuse, enforce permissions, investigate incidents, maintain reliability, and diagnose errors using technical, security, usage, and activity records. | Legitimate interests in protecting customers and operating a secure, reliable Service; legal obligations where applicable. |
| Handle legal requests, resolve disputes, and establish or defend legal claims using the records relevant to the matter. | Legal obligations; legitimate interests in protecting and exercising legal rights. |
| Send optional promotional communications or use optional tracking if introduced. | Consent where required (Article 6(1)(a)); any legally permitted existing-customer marketing requires a separate assessment and an easy opt-out. |
We assess legitimate interests against your rights and reasonable expectations. You can object to processing based on those interests. We do not treat accepting our Terms as consent to marketing or optional tracking. If a new purpose is incompatible with the original purpose, we will explain it and establish a valid legal basis before starting that processing.
Account credentials and required billing information are necessary to provide the corresponding service. You can choose not to provide optional details or connect a provider, but the associated feature may not work. Customer-controlled advertising data is processed on the customer's documented instructions; the customer determines its lawful basis.
6. Connected AI clients and advertising data
Connecting an AI client allows it to access your selected workspace within the permissions you authorise. Tool requests and results can include personal data in account names, creatives, reports, activity, or other workspace content. The client may add that information to a conversation and process it under its provider's own retention, training, and privacy settings.
Advarde's MCP connection does not itself give us access to your entire conversation history. We receive the requests and information the client sends to our Service. Authorising an AI client does not give it your underlying advertiser API key through the normal tool workflow.
Review the client's terms and settings before connecting it. You can revoke Advarde tokens or OAuth access from MCP connections, and authorised workspace administrators can revoke workspace MCP access. Revocation stops future authorised access through those credentials; it does not delete information the client or advertising provider has already received. Request deletion from those providers separately where appropriate.
Advarde does not run its own general-purpose AI model training service. The data practices of the AI provider you choose are separate from ours. Do not submit unnecessary personal data in prompts or campaign content.
8. International processing and transfers
BURO OPS AS is established in Norway, within the European Economic Area (EEA). Some providers, connected platforms, or authorised support operations may process personal data outside the EEA. A Norwegian business address does not mean all information is stored or accessed only in Norway.
Where we are responsible for a transfer outside the EEA, the transfer must have a valid basis under GDPR Chapter V. Depending on the recipient and destination, this may be a European Commission adequacy decision or approved Standard Contractual Clauses together with an assessment of the transfer and supplementary safeguards where necessary. We do not rely on accepting these Terms or this policy as general consent to international transfers.
Contact us for the destinations and safeguards applicable to your information, or to request a copy of relevant safeguards, with confidential material redacted where necessary. Your independently selected advertising or AI provider is responsible for the transfers it makes under its own service arrangement.
9. How long information is kept
We retain personal data for the period necessary for its purpose, taking account of whether an account is active, the customer's instructions, the sensitivity of the data, unresolved support or security issues, applicable legal claims, and statutory recordkeeping obligations. Different records have different purposes; ending a subscription does not automatically erase all of them.
- Account and workspace records: for the service relationship and any period needed to complete closure, requested export or deletion, and outstanding obligations. Customer Content follows the customer's instructions and applicable data processing agreement.
- Credentials and authentication: for the authorised connection or authentication purpose. Credentials can be revoked or expire earlier than related security records are deleted. The cookie lifetimes above describe browser access, not a promise that every related database record is deleted at that moment.
- Support, activity, and security records: for resolving the request, maintaining security and accountability, and handling a relevant dispute or legal claim. Application audit records are normally removed after 365 days. Closed privacy-request records are normally removed two years after closure. A documented preservation need can suspend scheduled deletion. Support correspondence, provider logs and other records have separate periods determined by their purpose and status.
- Invoices and required accounting records: normally five years after the end of the financial year under Norwegian bookkeeping rules, or longer where a specific legal requirement applies. This does not justify retaining unrelated workspace content for the same period.
- Backups: deleting active data does not automatically erase existing backup copies. Those copies require separate expiry or deletion under the applicable retention decision and any lawful preservation requirement. Retained copies are restricted to recovery and legal requirements; applicable deletion and access-revocation instructions must be reapplied before restored data returns to ordinary use. We do not promise a fixed backup-deletion period where it has not been established.
When information is no longer needed, we delete it or irreversibly anonymise it. Contact us for the retention criteria and closure arrangements relevant to your records. We will explain any legal reason that prevents a requested deletion. Records held independently by connected providers follow their own policies.
10. How we protect information
Our application uses workspace access controls, role-based permissions, encrypted storage for supported sensitive credentials, hashed passwords and tokens, and security and activity records. Production authentication cookies use secure transport settings. Two-factor authentication and token revocation are available to help protect access. Our superadmin console requires two-factor authentication by default.
As of 22 September 2026, an initial client-side encrypted database backup to a separate server has passed upload and repository integrity checks. Isolated restoration, automated scheduling and backup-alert delivery are still being validated. This result does not establish encryption or recovery verification for every existing backup copy.
Access is limited according to responsibilities and permissions. Infrastructure operators and authorised providers may need privileged access to run the Service. We take appropriate technical and organisational measures considering the risks, but no internet service or storage system can guarantee absolute security.
If a personal data breach occurs, we will assess it and make notifications to affected customers, individuals, and authorities as required by applicable law and our data processing obligations. Contact us promptly if you believe your account or information has been compromised.
11. Your rights and how to use them
Subject to the conditions and exceptions in applicable law, you may:
- Ask whether we process your personal data and request access and a copy.
- Ask us to correct inaccurate data or complete incomplete information.
- Request deletion when there is no longer a lawful reason to keep the data.
- Request restriction of processing in the circumstances provided by law.
- Receive data you provided in a structured, commonly used, machine-readable format, and request its transfer where the portability right applies to automated processing based on consent or contract.
- Object to processing based on legitimate interests because of your particular situation. We must stop unless we demonstrate overriding lawful grounds or need the data for legal claims.
- Object at any time to direct marketing, including profiling related to that marketing; we will stop using your data for that purpose.
- Withdraw consent at any time where processing relies on consent, without affecting the lawfulness of processing before withdrawal.
Contact us using the details below and describe your request. We may ask for proportionate information to confirm identity or authority before disclosing or deleting data. Do not send a password or API key. Requests are normally free and answered within one month. If the law permits an extension because of complexity or the number of requests, we will explain the reason and extension within that first month.
Signed-in users can also open account settings to submit a privacy request, check its recorded status, or download basic account information. That download excludes credentials and is not a complete export of customer workspace content, support correspondence or records held by connected providers. Ask us for a scoped response if you need more information.
Some requests are subject to exceptions, including legal recordkeeping and other people's rights. If we cannot fulfil a request, we will explain why and how to complain. If the data belongs to a customer's advertising or other customer-controlled processing, contact that controller first; we will assist it with requests under our processing obligations.
For account closure or deletion, identify your account and any workspace you are authorised to manage. Cancelling billing, revoking a token, leaving a workspace, and deleting personal data are different actions. Your request does not automatically close other users' accounts or remove lawful business records controlled by your organisation.
To request deletion of data held by Advarde, including Facebook or Instagram data received through a Meta connection, follow our data deletion request form. Submit without signing in, then save your private status link to read updates and reply to our team.
12. Automated decisions
Advarde can execute advertising rules, prepare recommendations, and apply automated security or usage controls. These features act on campaign settings or protect service access. We do not use personal data as controller to make solely automated decisions about individuals that produce legal or similarly significant effects within the meaning of GDPR Article 22.
Contact us if an automated access control prevents you from using your account so we can review the issue. Customers are responsible for assessing the rules that apply to their own advertising decisions, profiling, and use of external AI systems.
13. Children
Advarde is a business service intended for adults aged 18 or older. We do not knowingly register children or seek their personal data. If you believe a child has provided personal data to us, contact us so we can investigate and delete it where appropriate.
14. Questions and complaints
You can contact us about privacy, personal data requests, security concerns, or this policy:
BURO OPS ASOrganisation number 832 405 612Anna Hagmans Gate 3K, 1511 Moss, Norwayharald@advarde.comYou also have the right to complain to a supervisory authority, particularly in the EEA country where you live or work or where you believe an infringement occurred. In Norway, this is Datatilsynet, the Norwegian Data Protection Authority. See how to complain to Datatilsynet. You do not have to obtain our permission or complete a dispute procedure before contacting an authority.
15. Updates to this policy
We may update this policy when our Service, processing, or legal obligations change. The date at the top identifies the current version. We will make material changes clear through the Service, email, or another appropriate notice before they apply where required. If a change requires consent, we will request it separately; continued use is not a substitute for that consent.