Privacy Policy
Last updated: 5/10/2026
Privacy Policy
Last updated: 11 May 2026
1. Who we are
The data controller is ADSTIK INTERAKTIVE LTD ("Adstic", "we", "us"):
- Company UIC (EIK): 206749752
- VAT: BG206749752
- Registered office: 13 Yuri Venelin Str., floor 4, apt. 7, Varna 9000, Odesos district, Bulgaria
- Director: Vladimir Rosenov Vladimirov
- Email: contact@adstic.bg
2. Data we collect
2.1 Account data
- Email address and name
- Password (stored only as a cryptographic hash — never in plain text)
- Language and UI preferences
2.2 Payment data
Card details (number, CVV) never reach our servers — they are processed entirely by Stripe Inc. We only retain:
- Stripe Customer ID
- Subscription tier and payment history
- Billing details you entered yourself
2.3 Connected social accounts
When you connect a Facebook, Instagram, TikTok or YouTube account (via OAuth or your own developer app), we store:
- Access tokens and refresh tokens (encrypted at rest)
- Page/channel ID and public display name
- The list of granted permissions (scopes)
These tokens let us publish on your behalf and read engagement metrics. We never read personal messages outside your business pages' inbox.
2.4 Content you create
- Post drafts, ad campaigns, templates
- Uploaded images and videos
- AI-generated media assets
- Conversations with the AI assistant
2.5 Technical data
- IP address (for rate-limiting and abuse prevention)
- User-Agent (browser and device type)
- Action audit log inside the platform
3. Purposes and legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service | Contract performance |
| Processing payments | Contract performance |
| Service emails | Legitimate interest |
| Marketing emails | Consent (opt-in) |
| Security and abuse prevention | Legitimate interest |
| Tax and accounting compliance | Legal obligation |
4. Sub-processors we share data with
We use the following trusted vendors, each under a GDPR-compliant DPA:
| Vendor | Purpose | Region |
|---|---|---|
| Supabase Inc. | Database, auth, storage | EU (eu-central-1) |
| Stripe Inc. | Payments and invoicing | US + EU |
| Vercel Inc. | Front-end hosting | US + EU edge |
| Oracle Cloud | Back-end hosting | EU (Frankfurt) |
| Anthropic PBC | AI assistant (Claude) | US |
| OpenAI L.L.C. | AI assistant (GPT) | US |
| Meta Platforms | Publishing to Facebook/Instagram | US + EU |
| TikTok Pte. Ltd. | Publishing to TikTok | EU + SG |
| Google LLC | YouTube publishing, Google Analytics | US + EU |
We never sell personal data to third parties. Period.
5. Retention
| Data type | Period |
|---|---|
| Account + content | Until you delete your account |
| Social tokens | 90 days after subscription cancellation |
| AI chat history | 6 months since last activity |
| Security logs | 12 months |
| Accounting records | 10 years (Bulgarian Accountancy Act, Art. 12) |
6. Your rights (GDPR)
You have the right to:
- Access the data we hold about you
- Request correction of inaccurate data
- Request erasure ("right to be forgotten") — see Data Deletion
- Restrict processing
- Export your data in a machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent for marketing at any time
- Lodge a complaint with the Bulgarian Data Protection Commission
To exercise any of these rights, email contact@adstic.bg. We respond within 30 days.
7. Cookies
We use only:
- Session cookies — required for login
- Analytics cookies (Google Analytics) — only if you opt in via the banner
Details in our Cookie Policy.
8. Security
- Tokens and passwords are encrypted at rest (AES-256)
- All traffic is over TLS 1.2+
- Production data access is restricted to 2 people with MFA
- Encrypted off-site backups
In a serious incident we notify affected users and the Bulgarian Data Protection Commission within 72 hours.
9. Children under 16
The service is not intended for anyone under 16. If we learn we have collected data from a child, we delete it immediately.
10. Changes to this policy
Changes are announced on this page with an updated date. For material changes we also notify you by email.
11. Contact
For any privacy questions:
- Email: contact@adstic.bg
- Mail: 13 Yuri Venelin Str., floor 4, apt. 7, Varna 9000, Bulgaria