Skip to content
whitead audit
Home

Privacy Policy

Last updated: June 12, 2026

This Privacy Policy explains how Whitead Audit (hereinafter the "Service", "we", "us"), operated by FOP Mazurenko Danyil Oleksandrovych, collects, uses, stores, and protects your personal data when you use our SaaS tool for Google Ads auditing. We comply with the General Data Protection Regulation (GDPR) and applicable data protection legislation.

By using Whitead Audit, you confirm that you have read this Policy and agree to the data processing practices described herein.

1. What data we collect

We only collect data necessary to provide the Google Ads audit service:

  • Account data: email, name, username, expertise level — provided by you during registration.
  • Google Ads data: campaign metrics, ad settings, spending history. Your Google Ads data is accessed through the official Google Ads API. We only read your data — we never create, edit, pause, or delete anything in your account. The Google Ads API does not offer a separate read-only permission, so Google's authorization screen shows full access; our application performs read-only operations only, and this is enforced by automated tests.
  • Audit data: audit reports, action plans, AI-generated recommendations — created by our Service based on your advertising data.
  • Technical data: IP address, browser type — stored in server logs only. We do not use analytics trackers and do not monitor your on-site behavior.

2. Purpose and legal basis

We process your data on the following legal bases under the GDPR:

PurposeLegal basis
Providing the service: conducting Google Ads audit, generating recommendationsPerformance of a contract, Art. 6(1)(b) GDPR
Account management: registration, authenticationPerformance of a contract, Art. 6(1)(b) GDPR
Service improvement: analyzing audit qualityLegitimate interest, Art. 6(1)(f) GDPR

3. Cookies and local storage

We only use strictly necessary cookies and local storage data for the Service to function:

  • Language preference (cookie) — stores your selected interface language.
  • JWT authentication token (localStorage) — enables login to your account.
  • Theme preference (localStorage) — stores your selected theme (light or dark).

We do not use analytics cookies, tracking cookies, or advertising cookies. No third-party trackers are installed on our site.

4. Data sharing with third parties

We only share data with partners necessary for the Service to operate:

PartnerPurpose
VercelFrontend hosting
Application server (EU, Germany)Backend hosting
GoogleAds API, OAuth authentication
OpenAITo generate the written analysis, we send your advertising data — including campaign, ad group, keyword and search-term text, ad text, final URLs and performance metrics — to OpenAI. It is processed solely to produce your report and is not used to train OpenAI's models, per OpenAI's API data-usage terms.
Plata by MonoPayment processing (coming soon)
Redis (managed queue & cache, EU)Runs background audit processing.
Email delivery (SMTP relay)Sends transactional emails such as login and account notices.

We do not sell your data to third parties and never will.

5. Data retention

We keep your account and audit data for as long as your account is active. When you delete your account (Settings → Profile → Delete Account) or ask us to, we delete your data. Some aggregated, anonymized records that no longer identify you may be retained.

6. Your rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access: obtain a copy of the personal data we process about you.
  • Right to rectification: correct inaccurate or incomplete data.
  • Right to erasure: request deletion of your personal data.
  • Right to restrict processing: restrict the processing of your data under certain conditions.
  • Right to data portability: receive your data in a structured, commonly used format.
  • Right to object: object to the processing of your data based on legitimate interest.
  • Right to lodge a complaint: file a complaint with a data protection supervisory authority.

Account deletion: you can delete your account under Settings → Profile → Delete Account. Deletion cascades to all your data: audits, reports, recommendations, and action plans.

To exercise any of these rights, contact us at support@whitead.digital. We will respond within 30 days.

7. Data security

We implement appropriate technical and organizational measures to protect your data:

  • TLS encryption for all connections between your browser and our servers.
  • OAuth tokens encrypted using the Fernet algorithm.
  • Role-based access control.
  • Daily database backups.
  • We only read your Google Ads data — we never create, edit, pause, or delete anything in your account, and this is enforced by automated tests.

8. International data transfers

Application servers are hosted in the EU (Germany). Our frontend and CDN run on Vercel (EU/US). The database and cache are managed services hosted in the EU. For data transfers outside the European Economic Area, we use Standard Contractual Clauses (SCC) under the GDPR to ensure an adequate level of protection for your data.

9. Changes to this Policy

We may update this Privacy Policy from time to time. The updated version will be published on this page with a new "Last updated" date. In the event of significant changes, we will notify you by email to the address associated with your account.

10. Contact information

Data Controller: FOP Mazurenko Danyil Oleksandrovych