Privacy Policy
Last updated: July 16, 2026
1. Data Controller
Under the UK GDPR (Data Protection Act 2018) and the EU GDPR (Regulation (EU) 2016/679), the data controller of your personal data is:
- Company: Prongine Technologies Ltd (a limited company registered with Companies House in the United Kingdom)
- Contact: [email protected]
- Supervisory authority: ICO (Information Commissioner’s Office, United Kingdom)
2. Personal Data We Collect
| Category | Example data | Purpose of collection |
|---|---|---|
| Account data | First name, surname, e-mail; if you sign in with Google, Facebook or Microsoft, the relevant provider’s account identifier; if you register with your own password, your password (stored hashed in the Keycloak authentication infrastructure, not in the Kampanya+ database) | Account creation, authentication |
| Store/business data | Company name, address, tax number | Invoicing, subscription management |
| Payment data | Stripe customer ID (NO raw card data) | Subscription billing |
| Contact messages | Your name, e-mail address, company/store name and message content submitted via the contact form; your phone number if you write to us via WhatsApp | Answering your enquiries, providing support |
| Security data | reCAPTCHA Enterprise interaction signals, IP address, browser information (only when the contact form is submitted) | Bot and spam protection |
| Usage data | Browser type, page views (Google Analytics 4, subject to consent; Cloudflare Web Analytics, cookieless and aggregated) | Statistics, error diagnosis |
| Advertising/conversion data | Cross-device identifier, demographic segment (age range, gender), interest segment, audience membership | Advertising performance measurement, remarketing; only if marketing consent is given |
| Content data | Designs, product names, images | Provision of the Service |
Social sign-in (Google, Facebook, Microsoft): If you sign in to the Service with one of these providers, authentication is carried out through Keycloak (an open-source identity and access management system running on our own infrastructure). Only basic profile information (name, e-mail, provider-specific account ID) is received from the provider; the password of your provider account is never transmitted to Kampanya+ or Keycloak at any stage and remains entirely within the provider’s own systems. The provider’s own privacy policy (Google, Meta/Facebook, Microsoft) additionally applies to this processing.
3. Legal Bases for Processing
- Performance of a contract (Art. 6(1)(b) GDPR): providing the Service and invoicing.
- Legal obligation (Art. 6(1)(c) GDPR): tax legislation and Stripe KYC.
- Legitimate interests (Art. 6(1)(f) GDPR): security logs, fraud prevention, bot/spam protection on the contact form (reCAPTCHA Enterprise), and the prevention of spam and abuse through verification of the validity of e-mail addresses (MyEmailVerifier).
- Consent (Art. 6(1)(a) GDPR): optional analytics and marketing cookies (Google Ads, Google Signals), inclusion in advertising audiences and optional marketing communications (if any). You may withdraw your consent at any time via the cookie preference banner; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. Who Do We Share Your Data With?
Your data is shared only with the following Data Processors:
-
Stripe Payments Europe Ltd.: payment processing.
-
Google LLC (Google Analytics 4 + Consent Mode v2 + optional Google Ads/Google Signals):
Analytics (default, opt-in): anonymous site usage statistics. By design of the GA4 product architecture, IP addresses are not stored permanently: IP addresses of EU users are not logged, and for non-EU users the IP is used only briefly for geolocation (country/city) and then discarded. The Google Analytics script is initialised at page load with Consent Mode v2; if analytics consent has not been given, no cookies are created and only cookieless/anonymous “ping” signals (country, device type, page view) are transmitted to Google, with no individual user profile being created. If consent is given, full analytics is activated with the
_gaand_ga_<container-id>cookies.Marketing (opt-in, off by default): If you give marketing consent, Google Ads (conversion measurement, remarketing) and Google Signals (cross-device user recognition, demographic and interest reporting) are activated. In that case, Google uses age range, gender and interest data derived from your signed-in account in statistical reports and advertising audiences. Without consent these features remain inactive; all advertising cookies (
ad_storage,ad_user_data,ad_personalization) remaindenied.GA4 Advertising Features in use: Remarketing with Google Analytics, Google Display Network impression reporting, Google Analytics demographics and interests reporting (Google Signals), Google Ads conversion measurement.
Sensitive category statement: Kampanya+ complies with the Google Ads Sensitive Category Restrictions; it does not create advertising audiences, or conduct interest-based advertising, based on sensitive data such as health status, financial hardship, religious belief, political opinion or sexual orientation.
EU User Consent Policy: No personal data is processed and no advertising cookies are set for EU/EEA/UK users without explicit, prior consent (details).
No identity merging: We do not combine advertising and analytics data received from Google with any information capable of identifying a person (PII; for example e-mail, full name, phone number).
Data transfers: Data is transferred to the USA under the EU-US Data Privacy Framework (DPF) and the EU Standard Contractual Clauses (SCC).
Opt-out methods (in addition to withdrawing consent via the banner):
- adssettings.google.com: disable Google ad personalisation
- tools.google.com/dlpage/gaoptout: Google Analytics Opt-out Browser Add-on
- myactivity.google.com: view/delete your data
- networkadvertising.org/choices: NAI Consumer Choice
For details, see the Cookie Policy §2.2 and §2.3.
-
Google LLC (reCAPTCHA Enterprise): used to protect the contact form against bot and spam submissions. reCAPTCHA is loaded only on the contact page, at the time the form is submitted; in this context, the IP address and browser interaction signals are evaluated by Google. If you are signed in to a Google account in your browser, loading the reCAPTCHA script may cause Google to set or read its own account security/session cookies (
SID,HSID,SSID,APISID/SAPISID,__Secure-1PSID/__Secure-3PSIDand similar__Secure-prefixed variants,NID,AEC) on thegoogle.comdomain; these cookies are managed not by Kampanya+ but directly by Google, for its own account security purposes, and we have no access to their contents. For details, see the Cookie Policy §2.1.1. The Google Privacy Policy and Terms of Service apply. -
Google LLC, Meta Platforms Ireland Ltd., Microsoft Ireland Operations Ltd. (social sign-in providers): If you choose to sign in to the Service with your Google, Facebook or Microsoft account, authentication is carried out by redirecting to these providers via Keycloak; only basic profile information (name, e-mail, account ID) is received from the provider. See §2.
-
Cloudflare, Inc.: site traffic is served through Cloudflare (CDN, DDoS and security protection). In addition, Cloudflare Web Analytics collects cookieless, aggregated page view statistics; this tool uses no cookies or browser storage, creates no individual user profiles and performs no fingerprinting.
-
Hetzner Online GmbH: server hosting. Your data is hosted in EU (Germany) data centres.
-
Resend (Resend, Inc.): the transactional e-mail service used to deliver contact form messages to our team by e-mail.
-
MyEmailVerifier: an e-mail verification service used to verify the validity of e-mail addresses (detection of invalid, temporary/disposable or spam-originated addresses); in this context only the e-mail address is processed, and it is not retained on the service’s side after verification is complete. The service is GDPR compliant and holds SOC 2 Type II certification; see the MyEmailVerifier Privacy Policy.
-
Meta Platforms Ireland Ltd. (WhatsApp): If you choose to write to us via WhatsApp, your phone number and message content are transmitted through the WhatsApp infrastructure; see the WhatsApp Privacy Policy.
All third-party processors are contracted under the GDPR and the EU Standard Contractual Clauses (SCC).
5. Retention Periods
- Account data: for as long as the subscription is active, plus 90 days after account deletion.
- Invoice and payment records: as required by statutory retention obligations; at least 6 years under United Kingdom tax legislation, or for any longer period prescribed by the legislation of the relevant country.
- Contact messages: for as long as necessary to answer and follow up your enquiry, up to a maximum of 2 years.
- Usage/log data: in anonymised form, for a maximum of 12 months.
- Advertising cookies and audience membership: between 90 days and 13 months in accordance with Google standards; first-party cookies are deleted automatically when consent is withdrawn.
6. Your GDPR Rights
You have the following rights (Art. 15-22 GDPR):
- To access your data and request a copy
- To request rectification or erasure
- To request restriction of processing
- To receive your data in a portable format (data portability)
- To object to processing
- To withdraw consent
- To lodge a complaint with the competent data protection authority
For your requests: [email protected]; we respond within 1 month at the latest (for complex requests this period may be extended to the extent permitted by the GDPR; in that case we will inform you).
We do not carry out decision-making or profiling based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
7. Data Security
- All traffic is encrypted via HTTPS.
- Authentication is handled through Keycloak (an open-source identity and access management infrastructure); social sign-in with Google, Facebook and Microsoft is supported. If you register with your own password, your password is not stored in the Kampanya+ database; it is stored only in Keycloak’s own credential store, hashed with an industry-standard algorithm.
- Data is hosted in EU (Germany) data centres.
- Database access follows the principle of least privilege.
- Regular security updates and dependency scans are carried out.
8. Cookies
For details of our use of cookies, please see our Cookie Policy page.
9. Children’s Data
The Service is not directed at persons under the age of 18. We do not knowingly collect data from minors.
10. Changes to This Policy
We may update this policy from time to time. We will notify material changes by e-mail at least 30 days before publication.
This Policy may be published in multiple languages. In the event of any conflict between language versions, the English text prevails.
11. Contact
For data protection enquiries: [email protected]