Skip to document
advardeGo to workspace

Legal

Privacy Policy

How we handle personal data, who can access it, and the choices and rights you have.

Effective 10 September 2026Last updated 5 October 2026
Terms of ServicePrivacy PolicyData Deletion Request

On this page

  1. Who is responsible for your data
  2. The information we process
  3. Where information comes from
  4. Purposes and legal bases
  5. Who receives information
  6. Connected AI clients and advertising data
  7. Cookies and browser storage
  8. International processing and transfers
  9. How long information is kept
  10. How we protect information
  11. Your rights and how to use them
  12. Automated decisions
  13. Children
  14. Questions and complaints
  15. Updates to this policy

Advarde is a product of BURO OPS AS, Norway.

1. Who is responsible for your data

Advarde is a product of BURO OPS AS, a Norwegian private limited company, organisation number 832 405 612. Our contact address is Anna Hagmans Gate 3K, 1511 Moss, Norway. In this policy, "we", "us", and "our" refer to BURO OPS AS.

We are the data controller for personal data used to run our website, manage accounts and subscriptions, communicate with you, and protect the Service. This policy covers visitors, account holders, invited team members, and people who contact us. It explains our processing under the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.

When a customer uses Advarde to process personal data in advertising, audience, or conversion information on its instructions, that customer or its client determines the purposes and acts as controller. We act as processor or subprocessor under the applicable data processing agreement. The customer's privacy notice explains that processing. This policy does not replace that notice or the agreement.

2. The information we process

  • Account and contact details: name, email address, password hash, email-verification status, account settings, and communications you send us.
  • Authentication and security information: session and access-token records, connected client permissions, sign-in and recovery events, and two-factor authentication information if enabled. We store passwords and supported access tokens as hashes, and supported provider credentials and authenticator secrets in encrypted form.
  • Workspace information: workspace name, membership, roles, invitations, inviter details, plan, usage, access decisions, and activity history identifying who performed an action.
  • Advertising and business information: connected account identifiers, account names, currency and time zone, credentials, campaigns, creatives, URLs, images, uploaded workbooks, targeting, budgets, performance reports, saved plans, and automation settings. Depending on the features you use, this can include audience identifiers, conversion setup and event information, and business outcome data. Business records can contain personal data.
  • Billing information: billing contact and business details, selected plan, subscription status, invoices, payment and customer identifiers, and limited payment-method details supplied by Stripe, such as card brand and last digits. Payment-card entry is handled by Stripe; our application server does not receive full card numbers or security codes.
  • Technical information: IP addresses used to serve requests and prevent abuse, browser and device information sent with requests, request identifiers, route, response status, timing, and service or security logs. Hosting and delivery providers may also process connection logs.
  • Support information: the issue you describe, correspondence, attachments you choose to send, and the account or workspace information needed to investigate.
  • Optional website measurement: with your permission, the source, campaign label and landing page that brought you to Advarde, selected website actions, and a browser measurement identifier. If you register, we can link these to your account, your first workspace, its first successful report or validated draft, and its current subscription status. This helps us understand which resources lead to useful product use. We do not collect uploaded workbook contents, advertiser report contents, or arbitrary URL parameters for this purpose. Directory measurement includes listing views, agency website clicks, comparison selections and links to Advarde. Verified agency owners can see aggregate counts of listing views and website clicks; they do not receive visitor identities or browsing histories. Ownership claim actions are recorded separately for account administration.

Please provide only information needed for the task. Advarde is not designed to hold medical records, other special-category data, criminal-offence data, or children's personal data. Do not include these in ads, uploads, or support requests. Use designated connection fields for credentials.

3. Where information comes from

We receive information directly from you when you register, use the Service, make a payment, or contact us. Your workspace administrator or colleague can provide your email address and role when inviting you. We receive account and advertising information from the providers you connect, payment updates from Stripe, and inputs from clients you authorise.

We also receive technical information from your browser and device. If you use a feature that imports files, retrieves a public webpage, or connects another reporting source, we process the information from that source to complete your request. Optional integrations only apply when available and enabled; this policy does not mean every described feature is enabled for your workspace.

4. Purposes and legal bases

When we act as controller, we use the following legal bases. Where the contract is with your employer or another organisation rather than with you personally, processing its representatives' data generally relies on our legitimate interests in providing and administering that business relationship.

How we use personal data when acting as controller
Purpose and dataLegal basis
Create accounts, authenticate users, provide workspace access and requested features using account, security, and workspace details.Performance of a contract with you (Article 6(1)(b)); legitimate interests in serving organisational customers and their users (Article 6(1)(f)).
Manage subscriptions, payments, invoices, and accounting using billing and account details.Contract; legitimate interests in administering business accounts; legal obligations for accounting and tax records (Article 6(1)(c)).
Respond to requests and send invitations, verification, recovery, billing, and essential service notices.Contract or legitimate interests in assisting users and maintaining the service relationship.
Prevent fraud and abuse, enforce permissions, investigate incidents, maintain reliability, and diagnose errors using technical, security, usage, and activity records.Legitimate interests in protecting customers and operating a secure, reliable Service; legal obligations where applicable.
Handle legal requests, resolve disputes, and establish or defend legal claims using the records relevant to the matter.Legal obligations; legitimate interests in protecting and exercising legal rights.
Send optional promotional communications or use optional tracking if introduced.Consent where required (Article 6(1)(a)); any legally permitted existing-customer marketing requires a separate assessment and an easy opt-out.

We assess legitimate interests against your rights and reasonable expectations. You can object to processing based on those interests. We do not treat accepting our Terms as consent to marketing or optional tracking. If a new purpose is incompatible with the original purpose, we will explain it and establish a valid legal basis before starting that processing.

Account credentials and required billing information are necessary to provide the corresponding service. You can choose not to provide optional details or connect a provider, but the associated feature may not work. Customer-controlled advertising data is processed on the customer's documented instructions; the customer determines its lawful basis.

5. Who receives information

We disclose information only as needed for the purposes described here, including to these recipients:

  • Your workspace: authorised members and administrators can see information according to their role, including your membership and relevant activity. An organisation manages its workspace even if you later leave it.
  • Advertising providers: OpenAI receives account requests, campaign changes, and other data needed for your connected advertising features. Other source providers, such as Google or Meta, receive relevant requests only if their optional integrations are enabled and connected. Their own terms govern their services.
  • AI assistants and MCP clients you authorise: these receive the data returned by the tools and resources they request within the access you grant.
  • Stripe: processes payment details, transactions, subscriptions, and related fraud-prevention information. Stripe may act as a processor or an independent controller depending on the activity. See Stripe's Privacy Policy.
  • Operational service providers: hosting, database, infrastructure, backup, email delivery, and support providers process the information needed to deliver their services on our behalf, subject to appropriate contractual and security requirements.
  • Google Fonts: our website loads fonts from Google's servers. This sends Google your IP address and technical request information, such as browser information and the referring website where supplied by the browser. See Google Fonts privacy information.
  • Professional advisers and authorities: accountants, legal advisers, auditors, courts, regulators, and other authorities where needed for their role, a legal obligation, or legal claims.
  • Business successors: relevant information may be disclosed in a financing, merger, restructuring, or sale, subject to confidentiality and data protection safeguards. We will notify you where responsibility for your data changes.

We do not sell personal data or provide it to third parties for their own unrelated advertising. You can contact us for further information about the service providers relevant to your account and any applicable subprocessor arrangements.

6. Connected AI clients and advertising data

Connecting an AI client allows it to access your selected workspace within the permissions you authorise. Tool requests and results can include personal data in account names, creatives, reports, activity, or other workspace content. The client may add that information to a conversation and process it under its provider's own retention, training, and privacy settings.

Advarde's MCP connection does not itself give us access to your entire conversation history. We receive the requests and information the client sends to our Service. Authorising an AI client does not give it your underlying advertiser API key through the normal tool workflow.

Review the client's terms and settings before connecting it. You can revoke Advarde tokens or OAuth access from MCP connections, and authorised workspace administrators can revoke workspace MCP access. Revocation stops future authorised access through those credentials; it does not delete information the client or advertising provider has already received. Request deletion from those providers separately where appropriate.

Advarde does not run its own general-purpose AI model training service. The data practices of the AI provider you choose are separate from ours. Do not submit unnecessary personal data in prompts or campaign content.

7. Cookies and browser storage

We use first-party cookies and browser storage to provide sign-in, recovery, navigation, and the workspace preferences you select. When our affiliate program is enabled, we also offer an optional referral cookie, described below. Separately, you can allow first-party website measurement. The current application does not include an Advarde advertising pixel or third-party audience analytics tracker. Third-party billing content and external font requests are described separately below and above.

Storage used by Advarde
ItemPurposeDuration
advarde_acquisitionWith your permission, remembers a measurement identifier, the first source, campaign label and landing page, and the most recent non-direct source across our website and app subdomain. Selected actions and workspace milestones are measured by Advarde.Up to 90 days from the first recorded visit; cleared on withdrawal.
advarde_measurement_choiceRemembers whether you allow or refuse optional website measurement.Up to one year.
advarde_affiliateWith your permission, remembers the referring affiliate and any referral click ID across our website and app subdomain. If you register, we save the referral against your account and first workspace to attribute qualifying subscriptions.The program's referral window, shown in the consent notice. Cleared when you withdraw the cookie choice.
advarde_affiliate_choiceRemembers whether you allow or refuse the optional affiliate cookie.Up to one year.
__Host-buro_sessionAuthenticates your signed-in browser. The development name is buro_session.Up to 7 days; cleared from the browser on sign-out. Access can be revoked earlier.
__Host-buro_login_recoveryAllows a secure sign-in attempt after password recovery. The development name is buro_login_recovery.Up to 10 minutes; cleared on successful sign-in.
Local storage for workspace, sign-out state, dashboard preferences, and report viewsRemembers your selected workspace and display choices and coordinates sign-out between tabs.Until replaced, cleared by the relevant app action, or removed from your browser. Some display preferences remain after sign-out.
Session storage for the return destinationReturns you to the requested page after authentication.Until the flow clears it or the browser tab's session ends.

Stripe payment components may use cookies, device information, and similar technologies to process payments and prevent fraud when billing features load. Details appear in Stripe's Cookie Policy. You can block or clear storage in your browser, although this may prevent sign-in, recovery, preferences, or payment features from working.

You can change your affiliate cookie choice on the affiliate cookie preferences page. Refusing does not prevent you from using Advarde. Withdrawing clears the browser's referral cookie. To stop future account-linked affiliate dispatch and new checkout attribution, use Privacy and your data in your signed-in account settings. This does not automatically remove records already sent to Partnero or Stripe, previously issued payment links, or accounting records for earlier commissions. After you allow referral tracking, we may register the referred visit with Partnero using the affiliate key and landing page path, and retain its click ID. After you verify a referred account, we may send Partnero that click ID, an account identifier, and your email address to confirm the signup. We use Partnero to validate affiliates and manage qualifying subscription attribution, commissions, and payouts through its Stripe integration. This can include subscription identifiers, billing contact information, transaction amounts, and refunds. Details are available in Partnero's privacy policy.

Open Measurement preferences to allow, refuse or withdraw optional website measurement. This choice is separate from affiliate tracking and does not affect access to Advarde. No optional measurement is recorded before you allow it. Withdrawal stops further measurement, clears the measurement cookie, and deletes the measurement records associated with its still-valid identifier. To withdraw account-linked measurement, including after that cookie has expired or was cleared, open measurement preferences in your signed-in workspace and choose Decline. Measurement records are kept for up to 180 days from consent, then removed by scheduled cleanup. They remain on Advarde's service and are not sent to an external analytics vendor.

When your browser sends Global Privacy Control, we treat it as a refusal of optional website measurement and affiliate tracking, even if you previously allowed them. Where we can identify your signed-in account, we also apply the account-level withdrawal above. This does not by itself erase records already held by other providers.

Storage strictly necessary to provide a service you request does not require cookie consent under the applicable exemption. If we introduce other non-essential analytics, marketing, or optional storage, we will describe it and obtain consent before using it where required. You will be able to refuse or withdraw that consent as easily as you give it.

Conversion pixels or tracking code that a customer installs on its own website are separate from Advarde's website storage. That customer is responsible for its visitor notices, consent controls, and lawful transmission of conversion or audience data.

8. International processing and transfers

BURO OPS AS is established in Norway, within the European Economic Area (EEA). Some providers, connected platforms, or authorised support operations may process personal data outside the EEA. A Norwegian business address does not mean all information is stored or accessed only in Norway.

Where we are responsible for a transfer outside the EEA, the transfer must have a valid basis under GDPR Chapter V. Depending on the recipient and destination, this may be a European Commission adequacy decision or approved Standard Contractual Clauses together with an assessment of the transfer and supplementary safeguards where necessary. We do not rely on accepting these Terms or this policy as general consent to international transfers.

Contact us for the destinations and safeguards applicable to your information, or to request a copy of relevant safeguards, with confidential material redacted where necessary. Your independently selected advertising or AI provider is responsible for the transfers it makes under its own service arrangement.

9. How long information is kept

We retain personal data for the period necessary for its purpose, taking account of whether an account is active, the customer's instructions, the sensitivity of the data, unresolved support or security issues, applicable legal claims, and statutory recordkeeping obligations. Different records have different purposes; ending a subscription does not automatically erase all of them.

  • Account and workspace records: for the service relationship and any period needed to complete closure, requested export or deletion, and outstanding obligations. Customer Content follows the customer's instructions and applicable data processing agreement.
  • Credentials and authentication: for the authorised connection or authentication purpose. Credentials can be revoked or expire earlier than related security records are deleted. The cookie lifetimes above describe browser access, not a promise that every related database record is deleted at that moment.
  • Support, activity, and security records: for resolving the request, maintaining security and accountability, and handling a relevant dispute or legal claim. Application audit records are normally removed after 365 days. Closed privacy-request records are normally removed two years after closure. A documented preservation need can suspend scheduled deletion. Support correspondence, provider logs and other records have separate periods determined by their purpose and status.
  • Invoices and required accounting records: normally five years after the end of the financial year under Norwegian bookkeeping rules, or longer where a specific legal requirement applies. This does not justify retaining unrelated workspace content for the same period.
  • Backups: deleting active data does not automatically erase existing backup copies. Those copies require separate expiry or deletion under the applicable retention decision and any lawful preservation requirement. Retained copies are restricted to recovery and legal requirements; applicable deletion and access-revocation instructions must be reapplied before restored data returns to ordinary use. We do not promise a fixed backup-deletion period where it has not been established.

When information is no longer needed, we delete it or irreversibly anonymise it. Contact us for the retention criteria and closure arrangements relevant to your records. We will explain any legal reason that prevents a requested deletion. Records held independently by connected providers follow their own policies.

10. How we protect information

Our application uses workspace access controls, role-based permissions, encrypted storage for supported sensitive credentials, hashed passwords and tokens, and security and activity records. Production authentication cookies use secure transport settings. Two-factor authentication and token revocation are available to help protect access. Our superadmin console requires two-factor authentication by default.

As of 22 September 2026, an initial client-side encrypted database backup to a separate server has passed upload and repository integrity checks. Isolated restoration, automated scheduling and backup-alert delivery are still being validated. This result does not establish encryption or recovery verification for every existing backup copy.

Access is limited according to responsibilities and permissions. Infrastructure operators and authorised providers may need privileged access to run the Service. We take appropriate technical and organisational measures considering the risks, but no internet service or storage system can guarantee absolute security.

If a personal data breach occurs, we will assess it and make notifications to affected customers, individuals, and authorities as required by applicable law and our data processing obligations. Contact us promptly if you believe your account or information has been compromised.

11. Your rights and how to use them

Subject to the conditions and exceptions in applicable law, you may:

  • Ask whether we process your personal data and request access and a copy.
  • Ask us to correct inaccurate data or complete incomplete information.
  • Request deletion when there is no longer a lawful reason to keep the data.
  • Request restriction of processing in the circumstances provided by law.
  • Receive data you provided in a structured, commonly used, machine-readable format, and request its transfer where the portability right applies to automated processing based on consent or contract.
  • Object to processing based on legitimate interests because of your particular situation. We must stop unless we demonstrate overriding lawful grounds or need the data for legal claims.
  • Object at any time to direct marketing, including profiling related to that marketing; we will stop using your data for that purpose.
  • Withdraw consent at any time where processing relies on consent, without affecting the lawfulness of processing before withdrawal.

Contact us using the details below and describe your request. We may ask for proportionate information to confirm identity or authority before disclosing or deleting data. Do not send a password or API key. Requests are normally free and answered within one month. If the law permits an extension because of complexity or the number of requests, we will explain the reason and extension within that first month.

Signed-in users can also open account settings to submit a privacy request, check its recorded status, or download basic account information. That download excludes credentials and is not a complete export of customer workspace content, support correspondence or records held by connected providers. Ask us for a scoped response if you need more information.

Some requests are subject to exceptions, including legal recordkeeping and other people's rights. If we cannot fulfil a request, we will explain why and how to complain. If the data belongs to a customer's advertising or other customer-controlled processing, contact that controller first; we will assist it with requests under our processing obligations.

For account closure or deletion, identify your account and any workspace you are authorised to manage. Cancelling billing, revoking a token, leaving a workspace, and deleting personal data are different actions. Your request does not automatically close other users' accounts or remove lawful business records controlled by your organisation.

To request deletion of data held by Advarde, including Facebook or Instagram data received through a Meta connection, follow our data deletion request form. Submit without signing in, then save your private status link to read updates and reply to our team.

12. Automated decisions

Advarde can execute advertising rules, prepare recommendations, and apply automated security or usage controls. These features act on campaign settings or protect service access. We do not use personal data as controller to make solely automated decisions about individuals that produce legal or similarly significant effects within the meaning of GDPR Article 22.

Contact us if an automated access control prevents you from using your account so we can review the issue. Customers are responsible for assessing the rules that apply to their own advertising decisions, profiling, and use of external AI systems.

13. Children

Advarde is a business service intended for adults aged 18 or older. We do not knowingly register children or seek their personal data. If you believe a child has provided personal data to us, contact us so we can investigate and delete it where appropriate.

14. Questions and complaints

You can contact us about privacy, personal data requests, security concerns, or this policy:

BURO OPS ASOrganisation number 832 405 612Anna Hagmans Gate 3K, 1511 Moss, Norwayharald@advarde.com

You also have the right to complain to a supervisory authority, particularly in the EEA country where you live or work or where you believe an infringement occurred. In Norway, this is Datatilsynet, the Norwegian Data Protection Authority. See how to complain to Datatilsynet. You do not have to obtain our permission or complete a dispute procedure before contacting an authority.

15. Updates to this policy

We may update this policy when our Service, processing, or legal obligations change. The date at the top identifies the current version. We will make material changes clear through the Service, email, or another appropriate notice before they apply where required. If a change requires consent, we will request it separately; continued use is not a substitute for that consent.

BURO OPS ASOrganisation number 832 405 612Anna Hagmans Gate 3K, 1511 Moss, Norwayharald@advarde.com
Terms of ServicePrivacy PolicyData deletion
© 2026 BURO OPS AS. Advarde is a product of BURO OPS AS.

Advarde is an independent platform, not endorsed by, affiliated with, or a representative of OpenAI, Inc.