Legal information

Privacy Policy

dashiox is a marketing-intelligence product for PPC specialists and agencies: it evaluates data from the accounts you connect and delivers structured analyses and findings. This policy describes how the dashiox service (the "service") processes personal data of users, people requesting access and anyone else who contacts us, and how it handles the data you give it access to in Google services (Meta and Sklik integrations are in preparation). We comply with Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll., on the processing of personal data.

Controller and contact

The controller of personal data is the operator of the service:

  • Pavel Hladný
  • Legal form: sole trader registered under the Czech Trade Licensing Act
  • Company ID (IČO): 02645351
  • Registered office: Nové sady 988/2, 602 00 Brno – Staré Brno, Česká republika
  • registered in the Trade Register kept by the Trade Licensing Office of the City of Brno
  • Privacy e-mail:

The operator is not a VAT payer.

For all data protection matters, including exercising your rights under this policy, contact us at the e-mail above or through the contact form. Security vulnerabilities are reported as described on the Security page.

Data protection officer

The operator has not appointed a data protection officer, as it is not required to do so under Art. 37 GDPR. Data protection questions are handled directly by the operator at the contact above.

Data we process

  • Account data: e-mail address, name (if you provide it), password hash (we never store the password itself), the two-factor authentication (TOTP) secret in encrypted form, account settings (language, colour mode), invitation details (who invited you and when, plan, validity); if you sign in with Google, also the Google account identifier (sub) — an existing account is linked to it only after the link is confirmed with the account password and an authenticator code. Because of the limit Google applies to unverified apps, we keep a consent register: a one-way fingerprint of the Google account identifier created with a secret key (HMAC) with the dates of the first and last sign-in, including sign-in attempts without an invitation; we keep the fingerprint even after the account is closed, at most until 12 months after Google verifies the app (legitimate interest).
  • Sign-in and session data: session identifier (stored in the database only as a hash), session creation and expiry time, IP address and browser identification of the session, records of failed sign-in attempts (to prevent abuse).
  • Technical and security logs: time and result of requests, error messages and an audit record of important actions (sign-ins, connecting and disconnecting platforms). Tokens and passwords are automatically masked in logs.
  • Data from connected platforms: data from the Google accounts you give us access to (e.g. campaign performance, website traffic, search results, product data). The Google scope is described in Google user data; Meta and Sklik integrations are in preparation (see Meta platform data). This data may contain personal data of you or your clients (e.g. the e-mail of the signed-in account, account names).
  • Client context: information you enter about your clients so that analyses can be evaluated in context – e.g. goals, target CPA or ROAS, margins, brand terms and notes.
  • Derived data: analysis results and findings the service produces from the data of connected platforms and the client context.
  • Access request (waitlist): e-mail, optionally name, company and message, language, time of consent and a fingerprint of the IP address (a one-way hash; we do not store the IP address itself).
  • Contact form: name, e-mail, message text, language, time of consent and a fingerprint of the IP address (a one-way hash).
  • Payment data: the service is free during the closed beta and processes no payments. Once paid plans are introduced, payments will be processed by the payment providers listed on the subprocessors page; we do not store card numbers.

Purposes and legal bases

Purpose Data Legal basis
Creating and managing an account based on an invitation, sign-in, providing the features of the service account, sign-in, data from connected platforms performance of a contract – Art. 6(1)(b) GDPR
Producing analyses and findings, delivering them to you in the portal and to the AI client you connect data from connected platforms, client context, derived data performance of a contract – Art. 6(1)(b) GDPR
Security of the service, abuse prevention, protection against attacks, audit record sign-in data, technical and security logs legitimate interest in secure operation – Art. 6(1)(f) GDPR
Handling a request for beta access and sending an invitation waitlist data consent – Art. 6(1)(a) GDPR and steps prior to entering into a contract – Art. 6(1)(b) GDPR
Replying to a question sent through the contact form or by e-mail contact form data legitimate interest in answering the question – Art. 6(1)(f) GDPR; for questions about an existing contract Art. 6(1)(b) GDPR
Compliance with legal obligations (accounting and tax once payments are introduced, cooperation with public authorities) account and billing data legal obligation – Art. 6(1)(c) GDPR
Protection of the operator's legal claims necessary account and communication data legitimate interest – Art. 6(1)(f) GDPR

Consent is the legal basis only where stated explicitly; you can withdraw it at any time by e-mail to , which does not affect the lawfulness of processing before the withdrawal. We do not use your data for marketing or profiling and we do not send commercial communications.

Google user data

This section describes how the service handles data it receives from Google APIs after you explicitly allow it on the Google consent screen (OAuth). Each user connects Google with their own consent; access is never shared between users. dashiox accesses Google Ads through its own Google Cloud project; each user signs in with their own Google account and grants access themselves. You grant access separately for each Google service and only to the extent you confirm. We receive: campaign structure, performance, search terms and budgets from Google Ads; traffic, conversion and e-commerce reports from Google Analytics 4; search queries and page performance from Search Console; product data and product status from Merchant Center; the tag, trigger and variable configuration from Tag Manager; the content of Google Sheets files you select yourself; and your Google account e-mail address.

Scopes we request and why

Scope What the service does with it
openid, email verifying your identity and the e-mail address of the Google account you sign in or connect data with
https://www.googleapis.com/auth/adwords reading the structure and performance of Google Ads campaigns as input for analyses and findings (e.g. search-term waste, budget pacing); making changes (e.g. adding a negative keyword) is coming soon and will happen only after your explicit approval – during the beta no changes are made
https://www.googleapis.com/auth/analytics.readonly reading Google Analytics 4 data (traffic, conversions, e-commerce) for analyses and measurement checks; read-only
https://www.googleapis.com/auth/webmasters.readonly reading Google Search Console data (queries, pages, index coverage) for SEO analyses; read-only
https://www.googleapis.com/auth/content reading and checking product data and product status in Google Merchant Center; changes are coming soon and will happen only after your explicit approval
https://www.googleapis.com/auth/tagmanager.readonly reading the Google Tag Manager configuration (tags, triggers, variables) to review measurement; read-only
https://www.googleapis.com/auth/drive.file (optional) access only to the individual Google Sheets files you select yourself (e.g. a media plan); we have no access to any other files in your Google Drive

How we use the data

  • We use data from Google APIs solely to provide the features you request: the service evaluates it (unified metric definitions, rules, thresholds, benchmarks and your client context) and produces analyses and findings for your accounts, which we deliver to you in the portal and to the AI assistant you connected yourself.
  • Analyses run at your request – from your AI assistant or in the portal. We do not read data in the background for any other purpose.
  • Changes in your accounts (writes) are coming soon: during the beta the service makes no changes. Once available, a change will be made only after your explicit approval of the specific proposal in the portal, and each executed action will be recorded in the audit log.
  • We do not use the data for advertising, profiling or creditworthiness assessment.
  • dashiox does not use Google user data, or any data aggregated, anonymized or derived from it, to develop, improve or train generalized or non-personalized AI or machine learning models. Data received from Google Workspace APIs (Google Drive) is not used for this purpose either.
  • Humans at the operator do not read Google user data, except in the cases permitted by the Limited Use requirements (see Limited Use disclosure).

Sharing and transfers

  • The AI client you connect: If you connect an AI assistant (such as Claude or ChatGPT), dashiox transfers analysis results derived from your Google data to that assistant only at your request and only to answer your query. dashiox does not make this transfer for the purpose of training AI models. How the AI provider handles the data is governed by your agreement and settings with that provider. The AI client is connected via the MCP protocol; only the result of the specific request is passed, never access tokens, raw account data or entire accounts. You can remove the AI client's access at any time by removing the connector in the AI client, or by asking us by e-mail (in the portal once available).
  • Necessary processors: otherwise we make the data available only to processors without whom the service cannot operate (in particular the hosting provider), and only to the extent necessary; see the subprocessors page.
  • We do not transfer data from Google APIs to anyone else except on your instruction as described above, or where necessary for security purposes (e.g. investigating abuse) or to comply with applicable law, or as part of a merger, acquisition or sale of assets of the operator – in that last case only with your prior explicit consent.

Storage and protection

  • Google access and refresh tokens are stored only in encrypted form (AES-256-GCM) and are automatically masked in logs.
  • All communication with the service and with Google APIs is encrypted (TLS).
  • We store: encrypted access tokens; data from Google APIs in a short-term cache for at most 24 hours; the analysis results and findings derived from it; and the audit record of approved actions. Retention periods are in Retention.
  • Data is stored with the hosting provider Hetzner Online GmbH, location: Finland (EU), Helsinki data centre.
  • Data of individual users and workspaces is logically separated and access to it is checked on every request.

Revoking access and deletion

  • Disconnect: you can ask us at any time to disconnect a Google account (by e-mail, or in the portal once connection management is available there); we revoke the tokens at Google and delete the connection together with the related cached data and the analysis results and findings derived from that source.
  • Remove access in your Google Account: you can remove the service's access at any time at https://myaccount.google.com/permissions; the service can no longer reach the data afterwards.
  • Account deletion: all account data is deleted as described on the Data Deletion page – we handle the request without undue delay, at the latest within 1 month, and physically delete the data within 30 days of the account deletion.
  • We plan to automatically disconnect connections unused for 90 days (with advance e-mail notice); until this is in place, you can ask us to delete any unused connection at any time.

Limited Use disclosure

dashiox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. dashiox's use and transfer of information received from Google APIs, including Google Workspace APIs, will adhere to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements. Another app in this sense also includes the AI client you connect.

In line with these requirements, in particular:

  • we use data from Google APIs only to provide or improve user-facing features that are visible in the user interface of the service and that you request yourself;
  • we do not sell data from Google APIs and do not transfer it to advertising platforms, data brokers or other information resellers;
  • we do not use data from Google APIs for serving ads, including retargeting, personalised or interest-based advertising, or for determining creditworthiness or for lending purposes;
  • we do not use data received from Google Workspace APIs (in the service only the optional drive.file scope for Google Sheets files you select yourself) to create, train or improve machine learning or artificial intelligence models beyond a model personalized solely for you and the feature you use;
  • humans at the operator do not read data from Google APIs, unless (a) you have given us your affirmative agreement for specific data in advance (e.g. when handling your support request), (b) it is necessary for security purposes (e.g. investigating a bug or abuse), (c) it is necessary to comply with applicable law, or (d) the data is aggregated and anonymised and used for internal operations in accordance with applicable law.

Meta platform data

The Meta integration (Facebook and Instagram ad accounts via the Meta Marketing API) is in preparation and is not available in the beta; the service does not process any Meta data yet. The same applies to Sklik (Seznam.cz). We will complete this section with a description of the data, purposes and deletion before the integration becomes available.

Contact form and access requests

  • Access request (waitlist): we process your e-mail, name and, where provided, company, website address, type of applicant (agency, in-house marketing, freelancer, other), the advertising and analytics platforms you use, the approximate number of accounts or clients you manage and the message you write to us, as well as the time of submission and of your consent. We process the data to assess your request for access to the closed beta, to decide the order of invitations and to send you an invitation; we may add an internal note about how the request was handled. We keep it until the invitation is sent or the request is declined, for no longer than 12 months from submission, and then delete it unless you become a user.
  • Contact form: we process the data to answer your question. We keep the message while it is being handled and then for no longer than 24 months in case of follow-up communication or the defence of legal claims.
  • We store only a one-way fingerprint (hash) of the sender's IP address to protect against spam; we do not store the IP address itself.
  • Submitting a form is voluntary, but without your data we cannot handle the request or question.

Recipients and processors

We make personal data available only to processors who operate the service for us (hosting; Google as processor for sign-in with a Google account via Google Sign-In / OpenID identity verification and for sending transactional e-mails via Google Workspace from a noreply address; and, once payments are introduced, processing payments), under a data processing agreement pursuant to Art. 28 GDPR. The current list is on the subprocessors page. Other recipients are the platform providers (currently Google; Meta and Sklik once their integrations are available) whose APIs the service calls on your instruction, and the AI client you connect yourself. We disclose data to public authorities only where required by law.

Transfers outside the EU/EEA

We primarily process data in the location stated in the list of subprocessors. Where a processor or recipient processes data outside the European Economic Area, this happens only with appropriate safeguards under Chapter V GDPR – an adequacy decision of the European Commission (e.g. the EU–US Data Privacy Framework for certified recipients) or standard contractual clauses approved by the European Commission. Platform providers (Google) and the AI clients you connect process data under their own terms and may process it outside the EEA.

Retention

Data Retention period
Account data for the lifetime of the account; after account deletion made inaccessible and physically deleted within 30 days at the latest
Sign-in sessions until sign-out or 7 days of inactivity
Tokens of connected platforms until disconnected or your account is deleted
Cache of platform data at most 24 hours
Analysis results and findings 24 hours; longer history only according to your plan and until you delete it, disconnect the source it comes from or delete your account
Client context (goals, margins, brand terms, notes) until you delete it or your account
Website crawl data (if you use the site-crawl feature) 30 days
Audit record and security logs 90 days
Access requests (waitlist) until invited or declined, at most 12 months
Contact messages while being handled, then at most 24 months
Backups deleted data disappears from backups no later than 30 days after deletion from the production system
Accounting records (once payments are introduced) for the period required by law (usually 10 years)

Your rights

Under the GDPR you have the right:

  • of access to your personal data and information about its processing (Art. 15);
  • to rectification of inaccurate data (Art. 16);
  • to erasure ("right to be forgotten", Art. 17) – see the Data Deletion page;
  • to restriction of processing (Art. 18);
  • to data portability of the data you provided, in a structured, machine-readable format (Art. 20);
  • to object to processing based on legitimate interest (Art. 21);
  • to withdraw consent at any time where processing is based on consent (Art. 7(3)).

Exercise your rights by e-mail to . We handle requests without undue delay, at the latest within 1 month of receipt (Art. 12(3) GDPR); in complex cases this period may be extended by two further months, of which we will inform you. We may ask you to verify your identity first.

Right to lodge a complaint

If you believe our processing infringes the law, you have the right to lodge a complaint with the supervisory authority: Úřad pro ochranu osobních údajů (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, https://uoou.gov.cz. You may also contact the supervisory authority of the EU member state of your residence or place of work. We would appreciate it if you contacted us directly first.

Automated decision-making

There is no automated decision-making or profiling that would produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). The analyses and change proposals prepared by the service are recommendations only; you decide whether to apply them.

Cookies

The service uses only strictly necessary cookies (sign-in, form protection, language choice) and no analytics or advertising cookies. See the Cookies page for details.

Changes to this policy

We may update this policy, for example when introducing new features or changing processors. We will inform you of material changes in advance by e-mail or in the portal. The current version and its effective date are shown below.