Legal
Privacy Policy
Last updated: 31 August 2026
1. Controller
DEEPWERK UG (haftungsbeschränkt), Hafenweg 16, 48155 Münster, Germany, operates ADWERK and is responsible for the processing described in this policy. Contact us at imprint@adwerk.ai.
2. Data we process
- Account data such as name, email address, profile image and login information.
- Meta connection data such as the Facebook user ID and public profile, Page, business and ad-account identifiers, Page metadata, recent Page content used for the identity preview, granted permissions and access tokens.
- Project data such as product URLs and information, uploaded source material, generated creatives, campaign settings and research results.
- Advertising data such as campaign, ad-set and ad identifiers, status, budget and performance metrics returned by the Meta Marketing API.
- Payment and subscription references, credit balances and transaction status.
- Security and technical data such as session identifiers, IP address, browser information, timestamps and diagnostic logs.
3. How and why we use data
We process data to provide and secure the service, authenticate users, generate and manage advertising creatives, display eligible Meta assets, publish ads only after the user confirms the settings, retrieve campaign performance, process payments, support users and comply with legal obligations.
Where the GDPR applies, the legal bases are performance of a contract (Article 6(1)(b)), consent or the authorization initiated by the user (Article 6(1)(a)), legitimate interests in operating and securing the service (Article 6(1)(f)), and legal obligations (Article 6(1)(c)).
4. Meta Platform data
ADWERK requests only the Meta permissions needed for the connected-user workflow. The app uses the selected Page identity and ad account to build ads; it does not publish ordinary Page posts. Tokens are stored server-side and are never shown to other users. Existing campaigns and ads remain in the customer's Meta account when the ADWERK connection is removed.
Meta processes data under its own terms and privacy policy. Users can remove ADWERK in Meta's Business Integrations settings or disconnect Meta from ADWERK Settings at any time.
5. Service providers and recipients
We disclose data only as needed to providers that help us operate ADWERK, including hosting and database, object storage, email, authentication, AI generation and research, analytics, payment processing, and Meta when the user connects or publishes. Providers act under contractual safeguards or their own responsibility where applicable. We do not sell personal data.
6. International transfers
Some providers may process data outside the European Economic Area. Where required, we use an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism and apply appropriate safeguards.
7. Retention and deletion
We keep account and project data while the account is active and only as long as necessary for the purposes above. A user can delete their personal ADWERK account from Settings. Organization-owned data may remain available to other organization members. Users can disconnect the organization's Meta grant separately or request deletion of organization data. We may retain limited payment, tax, fraud-prevention and audit records where law or legitimate interests require it. Backups and technical logs expire on their normal retention cycle.
See our data deletion instructions for the exact steps.
8. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and you may withdraw consent without affecting earlier processing. You may also complain to a competent data protection authority. Contact us at imprint@adwerk.ai to exercise a right.
9. Security and changes
We use access controls, encrypted transport, restricted server-side token handling and other proportionate safeguards. No system can guarantee absolute security. We may update this policy when the service or law changes and will publish the revised date on this page.