Information on the processing of personal data pursuant to Art. 13 and 14 GDPR.
This is a business website presenting our advertising services. We keep data collection minimal: we run no advertising pixels, no third-party analytics trackers and no cookie-based profiling on this site. The processing that does occur is described below.
This website is hosted by Netlify, Inc. (San Francisco, USA). When you visit the site, Netlify processes technical connection data (IP address, date and time, requested page, browser and operating system information) in server logs as far as technically required to deliver the site and to ensure its security and stability.
Transfers to the USA are based on the EU standard contractual clauses. Log data is not merged with other data sources by us.
Our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
This site loads fonts from Google Fonts (Google Ireland Limited). When a page loads, your browser connects to Google servers to retrieve the font files, which discloses your IP address to Google. Details: policies.google.com/privacy
Our legitimate interest in a consistent presentation of the site (Art. 6(1)(f) GDPR).
To schedule calls and manage business contacts we use HubSpot (HubSpot, Inc., USA, with EU data hosting options). If you book a call or contact us through a HubSpot element on this site, the data you enter (name, e-mail address, chosen time slot, any message) is processed in our HubSpot account to arrange and follow up on the conversation.
Transfers to the USA are based on the EU standard contractual clauses.
Pre-contractual measures at your request (Art. 6(1)(b) GDPR) and our legitimate interest in managing business enquiries (Art. 6(1)(f) GDPR).
If you contact us directly, we process the data you provide to handle your enquiry. We delete enquiry data when it is no longer needed, unless statutory retention duties apply.
Art. 6(1)(b) GDPR for pre-contractual and contractual communication, otherwise Art. 6(1)(f) GDPR.
The pages under /oauth/ serve as technical redirect targets for authorizing our software integrations with advertising platforms (for example TikTok and Snapchat marketing APIs). These pages display an authorization code contained in the page address so that it can be transferred into our systems by our own staff.
The pages themselves do not store, transmit or log any data; the code is shown in your browser only. These pages are used exclusively by Demandgap for its own platform authorizations.
Demandgap manages advertising accounts (including Google Ads, Microsoft Advertising, Meta, LinkedIn, TikTok and Snapchat) on behalf of its clients. In doing so we access campaign, performance and audience data through the official interfaces (APIs) of these platforms, acting on the instructions of the respective client under data processing terms.
We use this data solely to set up, manage, optimise and report on the client's advertising, we do not sell it, and we do not combine it with data from this website. Retention follows the client agreement and the applicable platform terms.
We operate a Meta application named Demandgap (Meta App ID 997887849284720). It is a server-to-server tool that connects to the Meta Marketing API using a Meta System User access token.
The app offers no consumer login and collects no data from members of the public. We use it solely to manage advertising campaigns and produce performance reporting for advertising accounts that our clients own and have explicitly granted us access to.
Performance of our contract with each client (Art. 6(1)(b) GDPR) and the legitimate interests of us and our clients in operating and reporting on their advertising efficiently (Art. 6(1)(f) GDPR).
Through the Meta Marketing API, and only for advertising accounts our clients have authorized us to manage, we access:
We do not seek or store the personal profiles, contact details or private messages of individual consumers who see or interact with our clients' ads. Where the API returns any personal data, such as a Page administrator's name, we process it only to operate the client's advertising and we minimise what we retain.
Any data we receive from Meta ("Platform Data") is used only in accordance with the Meta Platform Terms and Developer Policies and the permissions our clients grant. We do not sell Platform Data, do not use it for advertising unrelated to the client it belongs to, and do not transfer it except as described in this policy.
We do not sell your data. Platform Data is accessible only to Christoph Schachner and Valentin Schulz, the two operators who deliver the service.
We use the following categories of processors under written data-processing terms: hosting and site delivery (Netlify, Inc.), CRM and scheduling (HubSpot, Inc.), and the official advertising platform interfaces themselves (Google, Microsoft, Meta, LinkedIn, TikTok, Snap). Each processor is bound to process data only on our instructions.
We share data with public authorities only where legally required.
Where a processor is located outside the European Economic Area, we rely on an adequacy decision or the EU Standard Contractual Clauses to safeguard the transfer.
We retain Platform Data only as long as necessary to provide the service to the relevant client. We delete it without undue delay when it is no longer needed, when a client engagement ends, when Meta requests deletion, or when deletion is required by law.
You may request deletion of any data we hold about you or your business at any time by emailing office@demandgap.com with the subject "Data deletion request". We will confirm the request, delete the relevant data without undue delay, and instruct our processors to do the same.
Clients may also request deletion by revoking our access in their Meta Business Manager, after which we remove any retained copies.
We protect access credentials and Platform Data with access controls, encryption in transit, and least-privilege access limited to the operators who need it.
You have the right to:
To exercise these rights, contact office@demandgap.com. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at).
We update this policy when our website or our processing changes. The current version is always available at this address.