We work with our clients' accounts and data. This is how we protect them.
Principles
- Least privilege. We request only the permissions each service needs and, wherever possible, read-only access.
- Client-owned accounts. Everything is created in the client's name; we access as invited users and revoke access when we finish.
- Protected credentials. Keys and application passwords are stored encrypted or in protected local storage, never in shared documents or in code.
- Supervised AI. AI tools execute and measure; a person reviews before anything significant is published or changed.
- No training. Client data is not used to train generalised AI models or shared with third parties for their own purposes.
Data from Google and Meta APIs
Our internal tools access Google Ads, Google Analytics, Search Console, Tag Manager, Business Profile and Meta solely for the accounts of clients who have granted us access, and only to produce reports, measure and manage their campaigns and content. Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
GDPR
- For data from our website and our own clients, MDE HUB, S.L. is the data controller.
- For data we process on a client's behalf, we act as data processor (Art. 28 GDPR) and sign a data processing agreement (DPA), available on request.
- We use providers (hosting, email, analytics, AI) acting as sub-processors with GDPR safeguards; some are outside the EEA and rely on the EU-US Data Privacy Framework or standard contractual clauses.
Retention and deletion
We keep each client's data for the duration of the service and delete it when it ends or on request. See Data deletion.
Incidents
If we detect an incident affecting a client's data, we notify the client without undue delay so it can meet its own notification duties.
Contact
For any security or privacy matter: info@ekualia.com.