Privacy Policy & Cookies
This English translation is provided for convenience. In case of any discrepancy, the Romanian version (Politica de confidențialitate și cookie-uri) prevails.
Version 2026-07.3 · Effective date: 25 July 2026. This version replaces version 1.0 of 6 October 2025 and describes the actual processing operations of the seenly.ad platform.
This Policy describes the personal data collection and processing practices for the websites seenly.ad and shop.seenly.ad and for the SaaS service provided by NOVA MASTERCLASS MARKETING SRL, in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable national legislation.
seenly.ad is a product feed management and paid advertising reporting platform, based on real profit. This Policy covers two distinct roles:
Data Controller: for the data of our direct customers — user accounts, billing data, communications, our own marketing — and for visitors to our public websites.
Data Processor: for the data that customers bring into the platform from their stores and advertising accounts (products, orders, marketing identifiers). These are governed in detail by the Data Processing Agreement (DPA).
1. IDENTITY OF THE CONTROLLER
Your data is processed by:
ETIENNE SOLUTIONS SRL (“Seenly”, “We”)
Registered office: Bucharest, Romania
Tax identification number (CUI): 40078645
Trade Register number: J2018015666403
Data protection e-mail: [email protected]
Given the B2B nature of our services, we mainly process data of representatives of legal entities. We nevertheless treat this information with the same security standards as any personal data.
2. WHAT DATA WE COLLECT AND HOW WE OBTAIN IT
We collect information in four ways: (A) directly from you, (B) automatically, through the use of the application, (C) through cookie-type technologies on the public websites and (D) from the platforms you connect to us.
2.1. Data provided directly
Identification and contact data: first name, last name, business e-mail address, phone number, job title, company name.
Authentication data: e-mail address, password (stored exclusively as a hash), two-factor authentication settings.
Financial data: billing address, VAT/tax identification number. We do not store full bank card details; these are processed exclusively by Stripe.
Proof of acceptance of the Terms: the accepted version, the date and the IP address.
Communications: the content of messages sent to support and of contact forms.
2.2. Data collected automatically in the application
Technical logs: IP address, browser type, operating system, access timestamp, errors encountered.
Usage data: login frequency, features accessed, report configurations, synchronisation and AI agent runs.
2.3. Data brought in from connected platforms (processor role)
Upon the customer’s instruction and with the customer’s authorisation, we retrieve from their accounts:
Product and feed data: titles, descriptions, images, prices, availability, identifiers (GTIN, SKU), purchase costs and margins entered by the customer.
Advertising performance data: campaigns, groups, spend, impressions, clicks, conversions, conversion values.
Order data: order number and value, products, status, date, currency, associated costs.
Marketing identifiers: parameters such as
gclid,wbraid,gbraid,fbclid, UTM tags, the anonymous visitor identifier generated by the Profit Tag, and events such as add-to-cart / begin checkout.The e-mail address of the store’s end customer: irreversibly transformed into a hash (SHA-256) at import, for lifetime value (LTV) calculation and for audience segments. We do not store it in clear text.
We do not request and do not intentionally process special categories of data (Art. 9 GDPR).
3. PURPOSES AND LEGAL BASES FOR PROCESSING
Purpose of processing | Legal basis (GDPR) |
Providing the Service: account creation, authentication, synchronisation of feeds and data, generation of reports. | Performance of the contract (Art. 6(1)(b)) |
Billing and financial management: issuing invoices, processing payments, accounting reporting. | Legal obligation (Art. 6(1)(c)) |
Security and service improvement: prevention of fraud and abuse, incident detection, error troubleshooting, measurement of feature usage. | Legitimate interest (Art. 6(1)(f)) |
Customer support: responding to requests, administrative notifications (maintenance, updates to the terms, invoices). | Performance of the contract (Art. 6(1)(b)) |
Commercial communications and newsletter: product news, usage tips, event invitations. | Consent (Art. 6(1)(a)), respectively legitimate interest for communications to existing customers, with a right to object in every message |
Analytics and advertising cookies on the public websites. | Consent (Art. 6(1)(a)) |
Measuring our own promotional activity: recording the channel a new account came from (the functional attribution cookie described in Section 4.2). | Legitimate interest (Art. 6(1)(f)), with a right to object |
4. COOKIE POLICY AND SIMILAR TECHNOLOGIES
4.1. What cookies are
A cookie is a small text file stored on your device, which allows us to keep your session active, to recognise you when you return to the website or to measure how the website is used.
4.2. Categories used
Essential (strictly necessary): required for the operation of the application — session cookie, security cookie (CSRF), cookies of the payment processor. These do not require prior consent.
Analytics (statistics): they help us understand how the website is used (Google Analytics 4, managed through Google Tag Manager). They are only activated after your consent.
Marketing (optional): used for campaign measurement and for displaying relevant advertising. They are only activated after your consent.
Functional, first-party attribution: a single first-party cookie,
seenly_attribution, placed on your first visit to our websites and kept for 30 days. It stores only the campaign parameters present in the address you accessed (utm_source, utm_medium, utm_campaign), the address of the entry page and the referring website, so that we can tell which channel the accounts created with us came from. It does not track you across other websites, is not read or shared by third parties and is not used to serve advertising. The related processing relies on our legitimate interest in measuring the effectiveness of our own promotional activity (Art. 6.1.f GDPR); you may object at any time by writing to [email protected], and the cookie can be refused or deleted from your browser settings.
4.3. Consent and its withdrawal
On your first visit to the public websites you are asked for consent to cookies that are not strictly necessary, through a consent banner (provided by CookieScript). Until an option is expressed, the consent signals transmitted to Google tools (Consent Mode v2) are set to “denied”, and analytics and advertising cookies are not activated. Essential cookies and the functional attribution cookie described in 4.2 are the exception: they do not track your activity outside our own websites and are not used for advertising.
You may change your mind at any time: your choice can be modified or withdrawn from the “Cookie settings” control available on the website, as easily as it was given. In addition, cookies already stored may be deleted from your browser settings. Withdrawing consent does not affect the lawfulness of processing carried out beforehand.
Refusing essential cookies may render the Platform non-functional (impossibility to log in).
4.4. Cookies inside the application
Inside the application (after login) we use essential cookies for the session and for security, as well as usage measurements necessary for providing and securing the Service, on the basis of the contract and of our legitimate interest. We do not use advertising cookies inside the application.
5. WHO HAS ACCESS TO YOUR DATA
We do not sell your data. We only share it with the partners strictly necessary for the operation of the service:
Hosting: the application and the database are hosted on infrastructure located in the European Union, together with the backups.
Network and security: Cloudflare (CDN, DNS, protection against attacks, e-mail routing).
Payment processor: Stripe — subscription processing. We do not store full card data.
Tax invoicing: SmartBill — issuing of invoices.
Artificial intelligence: OpenAI (feed optimisation, recommendations, AI agents) and Google (Gemini API — generation and editing of product images, when the feature is enabled). The data submitted is not used by these providers for model training.
E-mail: transactional e-mails and reports are sent through seenly.ad’s own e-mail server.
Traffic analytics on the public websites: Google (Google Analytics 4 and Google Tag Manager) and CookieScript (consent management), activated in accordance with Section 4.3.
Authorities: only where we are required to do so by law or by court order.
All our partners are contractually bound to observe the confidentiality and security of the data. The complete and up-to-date list is published on the Sub-processors page.
5.1. DATA SOURCES AND CONNECTED PLATFORMS (PROCESSOR ROLE)
The core functionality of seenly.ad involves connecting, at the customer’s request and with the customer’s authorisation, to the customer’s external accounts and platforms, in order to read performance and commerce data. In relation to this data, seenly.ad acts as Processor, while the customer remains Controller.
The platforms from which we may retrieve data (only upon the customer’s explicit connection/authorisation):
Advertising and analytics platforms: Google Ads, Google Analytics 4, Google Merchant Center, Google Search Console, Meta (Facebook/Instagram) Ads, TikTok Ads — campaign metrics, costs, conversions, products.
Ecommerce platforms: WooCommerce, Magento, Shopify, MerchantPro, Gomag and others — orders, values, statuses, products. This data may contain information about our customer’s end customers (e.g. e-mail address). The end customer’s e-mail address is irreversibly transformed into a hash (SHA-256) for lifetime value (LTV) calculation and is not stored in clear text.
E-mail marketing platforms: theMarketer, Klaviyo, Mailchimp, NewsMAN — campaign statistics and attributed revenue.
Transmission of data to platforms, upon the customer’s instruction. When the customer enables the corresponding features, the Platform transmits: product feeds to the destination channels (Google Merchant Center, Meta, TikTok, eMAG and others), conversion values based on order profit to Google Ads (profit loopback), and audience segments exported as hashed e-mail addresses. These transmissions stop as soon as the feature is disabled.
Security of the connections: the OAuth tokens and API keys provided by the customer are stored encrypted in the database. We use them exclusively to provide the features visible in the customer’s report and dashboard. We do not sell, rent or transfer this data to third parties for advertising purposes.
5.2. COMPLIANCE WITH GOOGLE API POLICIES (LIMITED USE)
seenly.ad’s use and transfer of information received from Google APIs (including the Google Ads API, the Google Analytics API, the Google Search Console API and the Google Merchant/Content API) adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
we use Google data exclusively to provide and improve features that are visible in the application’s interface (performance and profit reports, feed management);
we do not use Google data for serving advertisements, remarketing or personalised advertising;
we do not transfer and do not sell Google data to data brokers, advertising platforms or other third parties;
humans do not read Google data, except with the user’s explicit consent, for security purposes, to comply with applicable law, or in an aggregated/anonymised form for internal operations.
Similarly, we comply with the Meta Platform Terms and with the TikTok Marketing API Terms for the data retrieved from those platforms.
6. INTERNATIONAL DATA TRANSFERS
We prioritise storing data within the European Economic Area (EEA).
Where we use providers outside the EEA (for example, in the USA), we ensure that the transfer is lawful, relying on:
Adequacy decisions of the European Commission (for example, the EU-US Data Privacy Framework);
Standard Contractual Clauses (SCCs) approved by the European Commission, with supplementary measures where necessary.
7. DATA SECURITY
Encryption: data is encrypted in transit (HTTPS/TLS 1.2+); access tokens, API keys and secrets are encrypted in the database.
Access control: role-based access, isolation between customer accounts and two-factor authentication for administrative access.
Backups: performed regularly, to prevent data loss.
Passwords: not stored in clear text, but as a hash, with strong algorithms (bcrypt/argon2).
Minimisation: the e-mail addresses of end customers are stored exclusively as SHA-256 hashes.
Nevertheless, no method of transmission over the internet is completely secure. If you suspect that your account has been compromised, contact us immediately.
8. RETENTION PERIODS
Active account: the data is retained for the entire lifetime of the account.
After closure:
usage data, feeds, orders and reports are deleted 30 days after the account is closed;
billing data is retained for 10 years, in accordance with Romanian accounting legislation;
data used for commercial communications is deleted immediately upon unsubscribing.
The deletion of the account and of the associated data may also be requested directly from the application — see the Data Deletion page.
9. YOUR RIGHTS (GDPR)
As a data subject, you have the following rights:
Access: to request a copy of the data we hold about you.
Rectification: to correct inaccurate data.
Erasure (“the right to be forgotten”): to request the deletion of the data, if it is no longer necessary or if you withdraw your consent (except for data we are required by law to retain, for example tax records).
Restriction: to request the suspension of processing in certain cases.
Portability: to receive the data in a structured format (CSV/JSON).
Objection: to object to processing based on legitimate interest, including direct marketing.
Withdrawal of consent: at any time, as easily as it was given, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
To exercise any of these rights, send a request to [email protected]. We will respond within no more than 30 days.
Right to lodge a complaint. If you consider that we have infringed your rights, you may contact the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP): B-dul G-ral. Gheorghe Magheru 28-30, sector 1, Bucharest, postal code 010336; e-mail [email protected]; www.dataprotection.ro. You also have the right to bring proceedings before the competent courts.
For consumer protection matters, information about ANPC and alternative dispute resolution is available in Section 17 of the Terms & Conditions.
10. CUSTOMER DATA BROUGHT INTO THE PLATFORM (PROCESSOR ROLE)
For the data that the customer uploads or makes available to us by connecting its platforms (products, costs, orders, marketing identifiers, hashed e-mail addresses):
Seenly acts as Processor, while the customer is the Controller and is responsible for the existence of a legal basis.
We process this data exclusively on the basis of the customer’s documented instructions — the use of the features, the account settings and the DPA.
Human access to customer data is restricted to authorised personnel and takes place only for explicitly requested troubleshooting, for security purposes or to comply with applicable law.
We do not use customer data to train public artificial intelligence models.
11. AUTOMATED PROCESSING AND ARTIFICIAL INTELLIGENCE
The Platform automatically generates product labels, signals and recommendations, using configurable rules and, in certain features, artificial intelligence models of third-party providers (OpenAI; Google, for image generation). This processing concerns commercial data, not the profiling of natural persons, and does not produce legal effects on data subjects. The results are recommendations: the decision belongs to the customer.
12. UPDATES AND CONTACT
We reserve the right to amend this Policy. The current version and its effective date are permanently published on this page; any significant change will be notified by e-mail or in-app.
For any question regarding the processing of data:
E-mail: [email protected]
Address: NOVA MASTERCLASS MARKETING SRL, Bucharest, Romania.
