Privacy Policy
Last updated: 3 October 2026
Digital Cortex Ads Platform ("the Platform", app.digitalcortex.rs) is an internal advertising analytics tool operated by Digital Cortex Media d.o.o., Boška Buhe 16, 18300 Pirot, Serbia ("we"). It is used by our agency staff and by clients we invite, to measure the results of advertising campaigns we manage for them. Contact: info@digitalcortex.rs.
1. Data we process
- Platform users: name, e-mail address and a hashed password, used only to sign in and control access.
- Advertising account data: campaign, ad group, ad and creative names and performance metrics (spend, impressions, clicks, conversions) from Google Ads and Meta accounts that the account owner has connected.
- Website analytics data collected on our clients' websites with their consent mechanism: pseudonymous visitor and session identifiers, pages viewed, traffic source and ad click identifiers (e.g. gclid, fbclid), and orders or form submissions. E-mail addresses and phone numbers are stored hashed (SHA-256) where used for matching.
2. Google user data
When a user connects a Google Ads account, the Platform requests the https://www.googleapis.com/auth/adwords scope. We use it only to:
- read campaign structure and performance reports of the Google Ads accounts the user has access to, and
- upload offline / enhanced click conversions (orders and leads) to those accounts when the client enabled this.
The OAuth refresh token is stored encrypted (AES-256-GCM) and can be revoked at any time from the Platform (Integrations → Disconnect) or from Google Account permissions. We do not use Google user data for advertising to the user, we do not sell it, and we do not transfer it to third parties except as necessary to provide the Platform's features, to comply with law, or with the user's consent. Humans at Digital Cortex read this data only to provide the service to the client it belongs to or for security and legal reasons.
Digital Cortex Ads Platform's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Meta data
Meta (Facebook/Instagram) advertising metrics are read with a Business Manager system-user token supplied by the account owner. Conversion events may be sent to the Meta Conversions API only for visitors who gave marketing consent.
4. Storage, retention and security
Data is stored on servers in the European Union (Hetzner, Germany). Raw tracking events and IP addresses / user agents are deleted after a limited period (by default 30 days for IP/user agent). Aggregated reporting data is kept for the duration of the client relationship. Access is restricted per client and per role.
5. Your rights
You may request access, correction or deletion of your personal data by writing to info@digitalcortex.rs. Website visitors of our clients should first contact the website operator, which is the data controller for that site; we act as its processor.