PRIVACY
Privacy policy.
How Datastera s.r.o. processes personal data, both for our own website and on behalf of the clients whose measurement and advertising we operate.
In plain terms: when you contact us, we use your details only to reply and follow up. On this website, analytics and advertising tags load only after you consent. When clients engage us, we process data on their behalf as a processor; when we connect to Google services via OAuth we access only what is needed to run and report on the client’s own advertising, we never sell Google user data, and access can be withdrawn at any time. The full detail is below.
- 01
Who we are
The data controller for this website is Datastera s.r.o., IČO 08670790, with registered office at Hůrská 381, Kyje, 198 00 Praha 9, Czech Republic, registered with the Municipal Court in Prague, file C 322952. For data we process on behalf of clients (for example campaign and measurement data in their advertising and analytics accounts), the client is the controller and Datastera acts as a processor under their instructions. You can reach us about any privacy matter at macas@datastera.com.
- 02
Data we process
We process two broad categories of data. First, data you give us directly: your name, email, company and the content of your message when you contact us or request an audit. This data is used only to respond and to manage the resulting business relationship. Second, data we process on behalf of clients in the course of running their measurement and advertising: website event and usage data, advertising performance data, and related identifiers, strictly within the scope each client authorises. We do not ask for or intentionally collect special categories of personal data.
- 03
Cookies, analytics & marketing tags (Consent Mode v2)
On our own website, non-essential cookies and analytics or advertising tags (such as Google Analytics 4 and Google Ads) are loaded only after you give consent. We use Google Consent Mode v2, which keeps these tags in a denied state by default and only enables data collection once you have accepted, so no non-essential data is collected beforehand. You can change or withdraw your choice at any time, and essential cookies needed to operate the site are always limited to what is strictly necessary.
- 04
Google Ads API & OAuth data handling
When we operate a client’s Google Ads account, we connect to the Google Ads API using Google OAuth and access only the accounts the client has explicitly authorised, linked under our single Google Ads manager account (MCC). Google user data obtained through these APIs is used solely to manage, optimise and report on that client’s own advertising. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we do not sell Google user data, we do not transfer or use it for advertising or any purpose other than the agreed service, we do not allow humans to read it except where you explicitly consent, for security or to comply with law, and we do not use it to train generalised AI models. Access is revocable at any time and we delete the data when access is withdrawn or it is no longer needed.
- 05
Server-side tracking
Where we implement server-side tracking for a client, it runs first-party and privacy-consciously: collection is still governed by the visitor’s consent, only the data needed for measurement and advertising is forwarded, and identifiers or fields that are not required are minimised or discarded. Server-side processing does not bypass consent; it applies the same consent signals as client-side tags.
- 06
How we share data: processors & sub-processors
We do not sell personal data. We share data only with service providers that help us deliver the service: principally Google (Google Ads, Analytics, BigQuery and related services), and cloud, pipeline and communication tooling, each acting under contract and only on our or the client’s instructions. Where Datastera acts as a processor for a client, these are sub-processors engaged under the relevant data-processing terms with appropriate safeguards in place.
- 07
International transfers
Some of our providers (for example Google) may process data outside the European Economic Area. Where that happens, the transfer is protected by an appropriate safeguard under the GDPR, typically the European Commission’s Standard Contractual Clauses or an approved adequacy framework, so that your data continues to enjoy an equivalent level of protection.
- 08
Legal basis for processing
We rely on the following GDPR legal bases: your consent for non-essential cookies, analytics and marketing tags, and for any optional communications; the performance of a contract (or steps taken at your request before entering one) for handling enquiries and delivering services; and our legitimate interest in operating, securing and improving our website and business, balanced against your rights. For data we process on behalf of clients, the legal basis is determined by the client as controller, and we process it under their documented instructions.
- 09
Data retention
We keep personal data only as long as needed for the purpose it was collected for. Enquiry and contact data is kept for the duration of the conversation and any resulting relationship, and afterwards only as long as needed for legitimate business or legal reasons (such as accounting obligations). Data we process on behalf of clients is retained according to the agreement with that client and is deleted on request, when the engagement ends, or when access is withdrawn.
- 10
Your rights & how to complain
Under the GDPR you have the right to access your personal data and to request its rectification, erasure or restriction, the right to object to processing and to data portability, and the right to withdraw consent at any time without affecting prior processing. To exercise any of these, contact us at macas@datastera.com and we will respond within the statutory time limits. Where Datastera processes data on behalf of a client, please direct requests to that client as controller, and we will assist them. You also have the right to lodge a complaint with the Czech supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz), or with the authority in your country of residence.
- 11
Contact
For any question about this policy or about how we handle data, contact Datastera s.r.o. at macas@datastera.com or by post at Hůrská 381, Kyje, 198 00 Praha 9, Czech Republic. We may update this policy from time to time; the date above shows when it was last reviewed.