How Max handles your customers' data
You are the controller of your customers' personal data. AdsEye is your processor, and acts only on your written instructions. The full data processing agreement covers what Article 28 of the UK GDPR requires; this is its schedule for Max.
What Max processes
- From your CRM: the stage each enquiry reaches (enquiry, qualified, booked, won), its date and value, and the click ID the ad platform left on the enquiry.
- Email addresses and phone numbers, which are hashed (SHA-256) as they arrive. The plain versions are never stored.
- Your ad accounts' campaign settings and results.
Why
To tell each ad platform which of its clicks became customers, so it finds more people like them, and to report your results to you.
Who receives it
- Google, Meta and LinkedIn, when they run your ads: hashed identifiers and click IDs only, through their conversion APIs.
- Cloudflare, which runs Max. Its database is held in Western Europe.
- Anthropic, whose model helps Max read your results. It receives campaign numbers, never your customers' details.
- Resend, which sends Max's emails to you.
How long
Conversion records are kept for 13 months, then deleted. When you leave, we delete your data within 30 days unless the law requires otherwise, and give you an export first if you ask.
Security
Platform tokens are encrypted. Sign-in is by one-time email link. Every change and every upload is recorded in an audit log you can read under Activity.
Your privacy notice
Your own privacy notice needs to tell your customers that you share this information with ad platforms to measure advertising. We can suggest wording.
The company behind AdsEye, named in the final version