Privacy Policy
Last updated: July 17, 2026
This policy explains how SEO VISION IT S.R.L. processes personal data in connection with the admetriva.com website and the Admetriva platform, and the rights you have under Regulation (EU) 2016/679 (GDPR).
1. Controller and contact details
The controller for the processing described in the "Admetriva as controller" section is SEO VISION IT S.R.L., registered office at Bd. Alexandru Lăpușneanu nr. 179, bl. S5, sc. D, ap. 80, Constanța, România, Sole Registration Code (CUI) 37176228, Trade Register No. J13/539/2017, registered on 08.03.2017, email contact@admetriva.com. You can contact us on any data-protection matter at contact@admetriva.com or by post at the registered office above.
2. Scope
This policy covers: (a) the public website admetriva.com; (b) the Admetriva application (app.admetriva.com), including user accounts, workspaces and projects; (c) the data imported from the platforms connected by customers (Google, Meta and, in the future, TikTok); (d) the public contact and data-request forms.
3. Our roles under the GDPR
3.1. SEO VISION IT S.R.L. as controller
We are the controller for data we process for our own purposes: platform user accounts, the operation and security of the website and application, contact and request forms, support, invoicing, administrative and security logs, and our own communications.
3.2. SEO VISION IT S.R.L. as processor
For the data imported on the customer's behalf from the accounts it connects — Google Ads, Google Merchant Center, Meta Ads, Meta Catalog and, in the future, TikTok: campaigns, products, catalogs, metrics, conversions and other commercial data — the customer is the controller and we act as its processor, strictly on the customer's instructions as embodied in the platform features it uses. The customer is responsible for ensuring it has the right to connect those accounts and to entrust us with the processing.
4. Categories of data processed
4.1. Data you provide directly
- account data: name, email address, password (stored exclusively as a hash), company/workspace name;
- the customer company's details entered in the platform (name, invoicing details where required);
- messages submitted through the contact and data-request forms (name, email, company, message content);
- support data: the content of requests and correspondence with us.
4.2. Data collected automatically
- IP address, browser type (user agent), session data and technical access, error and security logs;
- technical request identifiers (request IDs) and synchronisation journals, used for error diagnosis.
4.3. Data from connected platforms (as processor)
- Google identifiers: Google Ads Customer ID, Merchant Center account ID, campaign and product identifiers;
- Meta identifiers: Business Portfolio ID, ad account ID, catalog ID, product identifiers (product IDs, retailer IDs);
- catalog attributes: titles, descriptions, prices, availability, images, SKU, GTIN, MPN, categories;
- performance data: campaigns, impressions, clicks, costs, conversions and conversion values, search terms, diagnostics;
- OAuth tokens (stored encrypted), together with the granted permissions (scopes);
- promotions configured in the platform, creative assets and — if you use the AI features — generation prompts and parameters.
4.4. Invoicing data
Data required to issue invoices (company name, address, tax code, payment history) — processed for contract performance and to comply with tax obligations.
Data sources: you (directly), the platforms you connect (through their official APIs, within the granted permissions) and our systems (automatically generated logs).
5. Purposes and legal bases
- providing the SaaS service (account, workspaces, projects, synchronisation, reports, analyses): performance of the contract (Art. 6(1)(b) GDPR);
- synchronising and reporting data from connected platforms: performance of the contract, in our capacity as processor;
- platform security and abuse prevention (logs, rate limiting, incident detection): our legitimate interest in protecting the service and customer data (Art. 6(1)(f));
- support and service communications (operational notifications, replies to requests): contract performance and legitimate interest;
- invoicing and accounting records: legal obligation (Art. 6(1)(c));
- optional marketing about our own service: your consent (Art. 6(1)(a)), withdrawable at any time without affecting the service;
- handling GDPR requests: legal obligation.
6. Google API data and Meta Platform data
Admetriva's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Google data is used solely to provide and improve the user-facing features requested by the user, is not sold, is not used for advertising, and is not read by humans except in the permitted cases (consent, security, legal obligations, aggregated/anonymised internal operations).
Data received through Meta Platform APIs is used in accordance with the Meta Platform Terms, exclusively for the features requested by the customer (catalog import, diagnostics, metrics). The same principles will apply to the TikTok integration once available.
Important: Admetriva never asks for your Google or Meta account password — authorisation happens exclusively through OAuth; OAuth tokens are stored encrypted; we do not sell customer data; one customer's data is never used for another customer's campaigns; each project's data is logically isolated from other projects and customers.
7. Revoking access and disconnecting platforms
You can disconnect an integration at any time from your project's settings in Admetriva. Additionally, you can revoke the application's access directly from your Google Account (myaccount.google.com → Security) or from Meta Business Settings (Integrations). After revocation we no longer import new data from that account; data already imported remains in the platform until deleted in accordance with the "Data Deletion" page.
8. Artificial-intelligence features
If you enable the AI features (for example promotional text or image generation), the data strictly necessary for the generation (e.g. product titles, prices, your brief) may be transmitted to the AI provider you selected in your project settings. AI features are disabled by default; we do not transmit data to AI providers unless you have enabled these features. Generated materials are stored in the platform together with their provenance (provider, prompt, parameters).
9. Recipients and sub-processors
We do not sell or rent personal data. Data may be accessed by the following categories of recipients, strictly to the extent necessary:
- the hosting infrastructure provider of the application and databases (the servers Admetriva runs on);
- Google (Google LLC / Google Ireland Ltd.) — when the platform communicates through the Google Ads and Merchant APIs, on your instruction;
- Meta Platforms Ireland Ltd. — when the platform communicates through the Meta APIs, on your instruction;
- the email service provider — for transactional messages (service notifications, password reset);
- artificial-intelligence providers (for example OpenAI, Google Gemini or Anthropic) — only if you have explicitly enabled the AI features, and only for the data required by the requested generation;
- professional advisers (accounting, legal) and public authorities — where required by law.
We enter into Art. 28 GDPR data-processing agreements with our processors. The concrete list of active sub-processors is available on request at contact@admetriva.com.
10. International transfers
Data is stored and processed primarily within the European Union. Certain communications with connected platforms or AI providers may involve transfers outside the EU/EEA (for example to the USA). Such transfers take place only with appropriate safeguards under Chapter V GDPR: adequacy decisions (including the EU-US Data Privacy Framework, where applicable) or the European Commission's Standard Contractual Clauses.
11. Retention
- account data: for the lifetime of the account and a reasonable period after closure, as needed for operational wind-down and the defence of legal claims;
- data imported from platforms: for the duration of the project/contract or until deletion requested by the customer;
- OAuth tokens: until disconnection or revocation, when they are invalidated;
- contact and data requests: as long as necessary for resolution and to demonstrate compliance;
- financial-accounting documents: for the statutory periods under Romanian tax and accounting law;
- technical and security logs: short, purpose-proportionate periods.
Backups are retained for a limited time and removed through the normal backup rotation; data deleted from active systems may temporarily persist in backups until the rotation completes.
12. Information security
We apply appropriate technical and organisational measures, including: encryption in transit (TLS) and at-rest encryption of secrets and OAuth tokens; passwords stored exclusively as hashes; role-based access controls with logical isolation of data per project and customer; rate limiting; security logging; content sanitisation; separated environments and restricted access to production data. No measure can guarantee absolute security; we will notify incidents in accordance with our legal obligations.
13. Your rights under the GDPR
You have the following rights, exercisable free of charge at contact@admetriva.com or through the "Data Deletion" page:
- access to your data and information about the processing;
- rectification of inaccurate or incomplete data;
- erasure ("right to be forgotten"), under Art. 17 GDPR;
- restriction of processing;
- objection to processing based on legitimate interest, including direct marketing;
- portability of the data you provided, processed automatically under contract or consent;
- withdrawal of consent at any time, without affecting prior processing;
- lodging a complaint with the Romanian supervisory authority ANSPDCP (anspdcp.ro) or with your local supervisory authority, and addressing the courts.
We reply within one month at the latest, with the statutory extension possible for complex requests. For requests concerning data we process as a processor, we may forward the request to the customer-controller and will assist in its resolution.
Erasure may be limited by legal obligations (e.g. retaining accounting documents), security needs, the existence of backups (until their rotation) and the establishment, exercise or defence of legal claims. We will inform you transparently of any such limitation.
14. Minors
The service is intended exclusively for professionals and is not directed at minors. We do not knowingly collect data of persons under 18; if we become aware of such collection, we delete the data.
15. Changes to this policy
We may update this policy to reflect the evolution of the service or of legislation. The current version and the date of the last update are displayed on this page; significant changes will be announced through the platform or by email.
16. Contact
For any data-protection question: contact@admetriva.com or SEO VISION IT S.R.L., Bd. Alexandru Lăpușneanu nr. 179, bl. S5, sc. D, ap. 80, Constanța, România.