Roles
For personal data in the content you or your AI put into Admode (“your personal data”, described in Annex 1), you are the controller and HV Digital AB is your processor. If you act for a client, you are their processor and we are your subprocessor.
These terms don’t cover the data we handle as a controller ourselves, such as your account, membership and logs. Our privacy policy covers those.
Your instructions
We process your personal data only to provide Admode as our terms describe and as you direct through it: what your AI asks Admode’s tools to do, and what you do in the dashboard. We process it otherwise only when EU or Member State law requires it, and then we tell you first unless that law forbids it.
If we think an instruction breaks data protection law, we tell you.
Confidentiality
Everyone who can access your personal data on our side is bound to keep it confidential.
Security
We protect your personal data with the measures in Annex 2. We may improve them over time, but never lower the overall protection.
Subprocessors
You allow us to use the subprocessors in Annex 3. We give them the same data protection duties as these terms, and we remain responsible for them.
We tell you by email at least 14 days before we add or replace a subprocessor. If you have a reasonable data protection objection, tell us within that time. If we can’t solve it, you can end your plan, and we refund what you paid for the rest of the period.
Transfers
Some subprocessors are outside the EU and EEA. We transfer your personal data there only with a lawful safeguard: an adequacy decision such as the EU–US Data Privacy Framework, or the European Commission’s standard contractual clauses with extra measures where needed. You authorise these transfers.
Helping you
Taking into account what we process and the information we have, we help you:
- answer people who use their data protection rights. The dashboard lets you find, download, correct and delete data yourself, and we pass on any request we receive for you;
- keep your personal data secure;
- handle personal data breaches;
- carry out data protection impact assessments and consult supervisory authorities, where you need to.
Personal data breaches
If a personal data breach affects your personal data, we tell you without undue delay, and within 48 hours of becoming aware of it, with what we know. We add details as we learn more, and we take steps to limit the harm.
At the end
You can download and delete your personal data at any time in the dashboard. When your plan ends, we keep it for 30 days so you can return or download it, then delete it automatically, unless the law requires us to keep it. Ask us and we delete it sooner. Deleted data can stay in backups until they’re overwritten.
Information and audits
We give you the information you reasonably need to show these terms are followed, for example answers to your security questionnaire. You can audit us, or have an independent auditor bound by confidentiality do it, once a year and with 30 days’ notice, at your own cost. An audit must not disturb Admode or expose other members’ data.
Liability and precedence
The liability rules in our terms of service apply to these terms. Where these terms and the terms of service differ about personal data, these terms apply.
Annex 1: the processing
- Subject
- Providing Admode to you.
- Duration
- While you have a plan, and the time in “At the end”.
- Nature
- Storing, organising, reading and showing your content; checking it with AI models; sending it to your AI app; deleting it.
- Purpose
- To build, check and keep your ad prompts, ad copy, research and brand content.
- Personal data
- Whatever your content holds, typically: names, usernames and words of people quoted from public reviews and forums; photos and videos showing people; names and contact details in brand material; and Meta ads data, which rarely holds personal data.
- People concerned
- Your customers and reviewers, people in your images, and your staff and contacts named in your content.
- Sensitive data
- Not intended. Don’t put special categories of personal data into Admode.
Annex 2: security measures
- Every connection uses HTTPS.
- Sign-in through Clerk, with Google or a one-time code sent by email. Every request to Admode’s tools checks the sign-in and an active plan.
- Each account reaches only its own brands.
- Prompts sent for checking aren’t stored. The AI models that run the checks are used under zero data retention.
- Prompts, sign-in tokens and email addresses are kept out of our application logs.
- Images, videos and other files reach your AI’s tools through signed links that expire within 24 hours.
- Admode runs in containers as an unprivileged user and writes nothing to disk; your content lives in the database, and the videos and images you upload in private file storage, reached only through signed links.
- Secrets are kept in the hosting platform’s settings, never in code.
- Limits and input checks protect Admode against abuse.
- Only the people who run Admode can access our systems.
Annex 3: subprocessors
| Subprocessor | What it does | Where |
|---|---|---|
| Railway Corporation | Hosting and the database | United States |
| Tigris Data, Inc. (through Railway) | Storing the videos and images you upload | United States |
| Clerk, Inc. | Sign-in | United States |
| Cloudflare, Inc. | Membership service | Global network |
| Google LLC (Google Workspace) | Email, when you send us content | Global |
| AI model provider | Runs Admode’s checks, under zero data retention | Outside the EU, with the safeguards above |
Write to support@admode.ai for the name of our AI model provider and its terms.