Effective date: 1 July 2026
1. Who we are
This Privacy Policy explains how Ecom Vision Ltd (“Adfure”, “we”, “us” or “our”) collects, uses and protects your personal data when you use the Adfure platform and website at adfure.com (the “Service”).
Adfure is a multi-tenant, AI-powered advertising-management platform. It connects to your own advertising accounts (Meta, Google, TikTok, LinkedIn) and analytics accounts (Google Analytics 4) with your permission, in order to audit and optimize your advertising campaigns.
Data controller:
- Ecom Vision Ltd
- Bulgaria
- VAT / EIK: BG208156804
- Contact: office@adfure.com
2. Data we collect
We collect and process the following categories of data:
- Account and contact information — such as your name, email address, company name, and login credentials when you create an account.
- Connected advertising-account data (via OAuth) — when you connect your Meta, Google, TikTok, LinkedIn or Google Analytics 4 accounts, we access campaign structures, performance metrics, insights, creatives and related settings from those accounts (read and, where you authorize it, manage access) so we can audit and optimize your campaigns. We access this data using secure OAuth tokens; we do not ask for or store your passwords to those platforms.
- Usage and log data — technical information about how you use the Service, such as IP address, browser type, device information, pages viewed, actions taken, and timestamps.
- Communications — any information you provide when you contact us for support.
We do NOT collect or store payment card data. All payments are processed by our payment provider, Stripe. Your card details are entered directly with Stripe and are never seen or stored by Adfure.
3. Why we process your data and our legal bases (GDPR)
We process your personal data on the following legal bases under the EU General Data Protection Regulation (GDPR):
- Performance of a contract (Art. 6(1)(b)) — to provide the Service, connect to your ad accounts, run audits, generate recommendations, and manage your subscription.
- Legitimate interests (Art. 6(1)(f)) — to secure, maintain and improve the Service, prevent fraud and abuse, and communicate with you about the Service.
- Consent (Art. 6(1)(a)) — where you give us consent, for example to connect a specific advertising account via OAuth or to receive optional marketing messages. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — to comply with our legal and regulatory obligations, such as accounting and tax requirements.
4. Sub-processors and service providers
We rely on carefully selected third parties to operate the Service. These sub-processors may process your data on our behalf:
- Meta Platforms — access to your connected Meta (Facebook/Instagram) advertising data.
- Google — access to your connected Google Ads and Google Analytics 4 data.
- Anthropic — AI processing of campaign data to generate audits and recommendations. Data sent to the Anthropic API is not used to train its models.
- Stripe — payment processing and subscription billing.
- Stape — optional server-side tracking, where you enable it.
- OpenAI — AI image and creative generation. Data sent to the OpenAI API is not used to train its models.
- Cloudflare — content delivery, DNS, and security.
- Resend — transactional email delivery.
- Apify and Firecrawl — retrieval of public web data for competitor and market analysis.
- Klaviyo — email marketing and lifecycle messaging to our website leads and users.
- Hetzner — cloud hosting and infrastructure (located in the EU).
We also connect to TikTok and LinkedIn advertising platforms where you choose to link those accounts.
5. International transfers
Our hosting infrastructure (Hetzner) is located in the European Union. Some of our sub-processors (such as Anthropic, Stripe and Google) may process data outside the European Economic Area. Where data is transferred internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and adequacy decisions to protect your data.
6. Data retention
We retain your personal data for as long as your account is active and as necessary to provide the Service. If you close your account or request deletion, we will delete or anonymize your personal data within 30 days, except where we are required to retain certain records to comply with legal obligations (for example, accounting records). Connected-account tokens are revoked and deleted when you disconnect an account or delete your account.
7. Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access — to obtain a copy of the personal data we hold about you.
- Right to rectification — to correct inaccurate or incomplete data.
- Right to erasure — to request deletion of your personal data (“right to be forgotten”).
- Right to data portability — to receive your data in a structured, commonly used, machine-readable format.
- Right to object — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Right to restrict processing — to request that we limit the processing of your data in certain circumstances.
- Right to withdraw consent — where processing is based on consent.
You also have the right to lodge a complaint with your local data protection authority. In Bulgaria, this is the Commission for Personal Data Protection (CPDP).
8. How to exercise your rights
To exercise any of these rights, or if you have questions about this policy, contact us at office@adfure.com. To request deletion of your data, please see our Data Deletion Instructions. We will respond to your request within the timeframes required by law.
9. Cookies
Our website uses cookies and similar technologies to keep you signed in, remember your preferences, secure the Service, and understand how the Service is used. You can control cookies through your browser settings. Some cookies are strictly necessary for the Service to function; disabling them may affect your ability to use certain features.
10. Security
We take appropriate technical and organizational measures to protect your personal data, including encryption of data in transit, secure storage of OAuth tokens, per-tenant data isolation, and access controls. No method of transmission or storage is completely secure, but we work to protect your data using industry-standard practices.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact
Ecom Vision Ltd — Bulgaria — VAT/EIK BG208156804 — office@adfure.com
