Privacy Policy
Last updated: 23 August 2026
This Privacy Policy explains how Rosenheinrich Software Solutions (“we”, “us”, or “our”) collects, uses, processes, and protects personal data when you access or use AdsDoneEasy, visit our website, or interact with our services. It provides comprehensive disclosures under the European General Data Protection Regulation (GDPR), the UK GDPR, the Swiss Federal Act on Data Protection (FADP), United States state privacy laws (including the California Consumer Privacy Act as amended by the CPRA), and international data protection standards.
1. Data Controller and Contact Information
The data controller responsible for the processing of personal data under this policy is:
Phillip Rosenheinrich
trading as Rosenheinrich Software Solutions
Destouchesstr. 3, 80803 München, Germany
Email: phillip@rosenheinrich.com
VAT ID (USt-IdNr.): DE463239564
If you have questions regarding data privacy or wish to exercise your statutory rights, you may contact us at the address above or via email at phillip@rosenheinrich.com.
2. Categories of Personal Data We Process
Depending on how you interact with AdsDoneEasy, we collect and process the following categories of personal and business data:
- Account & Identity Information: Email address, authentication tokens, user identifiers generated via Amazon Cognito, and role assignments.
- Subscription & Billing Data: Subscription tier, trial status, Stripe customer ID, payment timestamps, and invoice records. Payment card details are processed directly by our certified payment processor (Stripe) and are never stored on our servers.
- Project & Campaign Input: Business domain, website content retrieved during automated website analysis, product/offer descriptions, commercial angle preferences, target keywords, ad copy drafts, negative keyword lists, target geographical regions, and configured daily budget limits.
- Google Ads Integration Data: Scoped OAuth 2.0 authorization tokens (stored securely in encrypted parameter storage), Google Ads Customer ID, campaign IDs, ad group IDs, deployment statuses, and operational performance metrics synchronized from your Google Ads account.
- Technical & Server Logs: IP address, request timestamps, HTTP method, requested URI, referrer, user-agent string, and error codes necessary for network security, DDoS prevention, rate limiting, and server operation.
- Operational & Telemetry Data: Sanitized event categories, operation outcomes, duration measurements, Web Vitals, error codes, in-app route names, and a one-way hashed account pseudonym. Operational telemetry excludes email addresses, raw IP addresses, user-agent strings, campaign copy, or free-text inputs.
- First-Party & Optional Analytics Data: Page views and active visible engagement time on authenticated product surfaces linked only to your hashed account pseudonym. On public marketing pages, temporary session engagement is recorded only upon your explicit consent in our cookie banner.
- Customer Support Records: Support ticket categories, subjects, communication history, service level tier, and associated email addresses. Support records are stored as plaintext and must not contain unnecessary sensitive data.
3. Purposes and Legal Bases for Processing (GDPR & Global)
We process personal data only for specific, explicit, and legitimate purposes under the following legal bases:
- Performance of Contract (Art. 6(1)(b) GDPR): To deliver, operate, and maintain the AdsDoneEasy SaaS platform; manage user accounts; generate campaign drafts; deploy and sync campaigns in your Google Ads account; process subscription payments; and provide customer support.
- Compliance with Legal Obligations (Art. 6(1)(c) GDPR): To comply with statutory accounting, tax, commercial retention, and financial reporting obligations (such as § 147 AO and § 257 HGB under German law).
- Legitimate Interests (Art. 6(1)(f) GDPR): To protect system security, detect and prevent fraud or abusive activity, diagnose technical errors, improve platform stability, optimize system performance, and establish or defend legal claims.
- Consent (Art. 6(1)(a) GDPR / § 25 TDDDG): For optional marketing website analytics, Google Tag Manager / GA4 integration, and non-essential cookies, which remain entirely inactive until you provide affirmative consent in our cookie settings.
4. Third-Party Service Providers and Sub-Processors
We partner with carefully vetted service providers (sub-processors) who process data strictly under contractual data processing agreements (DPAs) with standard technical and organizational security measures:
- Amazon Web Services (AWS EMEA SARL / Amazon.com, Inc.): Cloud hosting, compute (AWS Lambda), managed database (Amazon DynamoDB), authentication (Amazon Cognito), and secrets management (AWS SSM Parameter Store) located in the primary AWS Region eu-central-1 (Frankfurt, Germany).
- Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (USA): Payment processing, subscription management, tax calculation, and billing administration for software licenses.
- OpenAI, L.L.C. (USA): Large Language Model (LLM) processing for website text analysis, keyword clustering, ad copy generation, and automated quality checks. Processed via enterprise zero-data-retention APIs; customer inputs and ad copy are never used to train foundation models.
- DataForSEO OÜ (Estonia, company number 14502291): Keyword search volume, cost-per-click (CPC) metrics, and keyword data, as well as retrieval of publicly accessible content from the customer-provided website where required for website analysis.
- Google LLC (USA): Google Ads API integration for campaign creation, authorization management, and performance data synchronization.
5. International Data Transfers and Safeguards
Our primary infrastructure is hosted within the European Union (Frankfurt, Germany). Where data is transferred to, or accessed from, service providers located outside the European Economic Area (EEA), Switzerland, or the UK (such as the United States), we ensure an adequate level of data protection.
Transfers to the United States rely on the EU-U.S. Data Privacy Framework (DPF) adequacy decision, the UK Extension to the EU-U.S. DPF, the Swiss-U.S. DPF, and/or Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Art. 46(2)(c) GDPR, supplemented by technical safeguards including end-to-end encryption.
6. Data Retention and Self-Service Deletion
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with statutory retention requirements.
Active Account Data: Retained for the duration of your active subscription and account lifecycle.
Self-Service Account Deletion: You can permanently delete your account directly in Settings at any time after cancelling active subscriptions in Billing. Upon deletion, personal profile information, campaign drafts, credentials, and support tickets are immediately purged or permanently anonymized.
Support Tickets & Communications: Active tickets are retained while open. Resolved support tickets and activity logs expire and are permanently deleted exactly 12 months after resolution.
Telemetry & Logs: Raw technical server logs are automatically deleted after 30 days. Raw operational telemetry events expire after 90 days. Aggregated statistical data is retained for 13 months.
Statutory Retention: Financial records, billing invoices, and tax-relevant transaction records are retained for mandatory statutory periods (up to 10 years pursuant to commercial and tax law).
7. Your Rights under European, UK, and Swiss Data Protection Laws
If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following statutory rights under the GDPR, UK GDPR, and Swiss FADP:
- Right of Access (Art. 15 GDPR): Obtain confirmation as to whether your personal data is processed and receive a copy of your data.
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal data.
- Right to Erasure / Right to be Forgotten (Art. 17 GDPR): Request deletion of your personal data when it is no longer required or where processing is unlawful.
- Right to Restriction of Processing (Art. 18 GDPR): Request limitation of processing under specific legal conditions.
- Right to Data Portability (Art. 20 GDPR): Receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21 GDPR): Object to data processing based on legitimate interests (Art. 6(1)(f) GDPR).
- Right to Withdraw Consent (Art. 7(3) GDPR): Withdraw previously granted consent at any time with future effect.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a competent data protection supervisory authority. For Bavaria, Germany, this is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
8. United States State Privacy Disclosures (California CCPA/CPRA, VA, CO, CT, UT, TX)
This section provides supplemental disclosures required under United States state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), and Texas Data Privacy and Security Act (TDPSA).
Notice at Collection: We collect the categories of personal information identified in Section 2 for the commercial and business purposes described in Section 3.
No Sale of Personal Information: We do NOT sell your personal information to third parties for monetary or other commercial consideration.
No Sharing for Cross-Context Behavioral Advertising: We do NOT share or disclose your personal information to third parties for cross-context behavioral advertising.
Sensitive Personal Information: We do not collect, process, or disclose sensitive personal information for the purpose of inferring characteristics about consumers.
Your Rights under US State Privacy Laws: Depending on your state of residence, you have the Right to Know/Access specific pieces of personal information, the Right to Delete, the Right to Correct inaccuracies, the Right to Opt-Out of automated profiling or targeted advertising, and the Right to Non-Discrimination for exercising your privacy rights.
California “Shine the Light” (Civil Code § 1798.83): We do not disclose personal information to third parties for their direct marketing purposes.
Global Privacy Control (GPC): We recognize and honor browser-based Global Privacy Control (GPC) signals as valid opt-out requests for optional analytics on our website.
To exercise your privacy rights, submit a request via email to phillip@rosenheinrich.com or use our in-app self-service settings.
9. Children’s Privacy (COPPA & Global Standards)
AdsDoneEasy is strictly a B2B SaaS platform intended exclusively for business professionals, sole proprietors, and authorized corporate representatives aged 18 and older.
We do not knowingly collect, solicit, or process personal data from individuals under 18 years of age (or under 16/13 where applicable). If we become aware that an individual under the required age has provided personal data, we will immediately delete that information from our servers.
10. Technical and Organizational Data Security Measures
We implement rigorous Technical and Organizational Measures (TOMs) pursuant to Art. 32 GDPR to safeguard personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access:
All communication with our servers is encrypted in transit using Transport Layer Security (TLS 1.2 and TLS 1.3).
Data stored in databases and parameter stores is encrypted at rest using AES-256 encryption.
Access to infrastructure, databases, and backend services is governed by strict Least-Privilege Identity and Access Management (IAM) controls, multi-factor authentication (MFA), and audit logging.
Google Ads OAuth tokens are isolated, encrypted, and accessible solely by automated backend workers during explicit user operations.
11. Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect technological developments, operational enhancements, or statutory changes. The “Last updated” date at the top indicates when the policy was most recently revised.
Material changes will be communicated via appropriate in-app notifications or email notices prior to taking effect.