Security & data trust

Built to be trusted with your clients’ data.

You’re connecting accounts that aren’t just yours — they’re your clients’. Here’s exactly how that data is accessed, handled, and kept.

ALREADY VETTED BY THE PLATFORMS YOU TRUST

The hardest security reviews in marketing? We’ve already passed them.

Before any channel will hand a third-party app access to client advertising data, it puts that app through a formal review. AdellaInsight went through those reviews — with Meta, Google, and the other channels we connect — and was approved to access client data through our own proprietary application. You don’t have to take our word for how seriously we treat data access. The platforms already did.

How it’s built

The architecture, not just a promise.

ACCESS

Read-only by default

AdellaInsight reads the data it needs to analyze and reports back. It doesn’t change anything in your ad accounts unless you explicitly grant and turn on that access — the default is look, not touch.

ISOLATION

Every client, walled off

Each client lives in its own isolated workspace. One client’s data is never blended with another’s — the cross-contamination that breaks single-brand tools at the agency layer can’t happen here.

ENCRYPTION

Encrypted, in transit and at rest

Data is encrypted moving between systems (TLS in transit) and while stored (encryption at rest).

CONTROL

You decide what’s client-visible

Every widget and report is yours to show or keep internal. Nothing reaches a client’s screen unless you choose to put it there.

ACCESS CONTROL

Role-based, need-to-know

Access to data is role-based and limited to a need-to-know basis — scoped to what each person and system actually requires to do the work.

MONITORING

Logged and monitored

Systems are monitored and access is logged, so unusual activity is caught early and there’s a clear record of who touched what.

What the AI actually sees

Aggregated metrics. Never raw customer records.

The intelligence runs on AI models — and we’re precise about what they receive. AdellaInsight sends only the compressed, aggregated marketing metrics needed for analysis: spend, performance, trends. It does not send raw customer records, individual-level rows, or personal information. The AI providers operate under no-training agreements, so your data is never used to train any model.

Ownership

Your data is yours. Always.

We hold your data to do the work you’re paying for — nothing else. It’s never sold, never used to train models, and never shared across customers. You can export it at any time, and you can have it deleted.

Compliance & data protection

Enterprise-grade by design.

We build to the standards your security and legal teams expect — documented processor obligations, a DPA for business customers, and safeguards that travel with your data.

GDPR-aligned SOC 2 in progress ISO 27001 principles OWASP
GDPR

Documented processor obligations

When we process data on your behalf, we act on documented instructions and support GDPR Articles 32–36 — security, breach notification, and DPIAs.

DPA

Data Processing Agreement

A DPA is available for every business customer — covering scope, subprocessors, security commitments, and international-transfer safeguards.

SUBPROCESSORS

Vetted, and listed on request

Every subprocessor meets strict data-protection standards under a data processing agreement. The current list is available on request.

TRANSFERS

Safeguards across borders

For data moving outside the EEA or UK, we rely on Standard Contractual Clauses and equivalent legal transfer mechanisms.

YOUR RIGHTS

Data subject requests, supported

Access, correction, deletion, portability, and objection — we help you respond to data subject requests on your timeline.

BREACH

Notification within 72 hours

If a breach occurs, we notify affected customers without undue delay — aiming for 72 hours, with the detail you need to meet your obligations.

Read the full data processing & compliance policy

The questions a security team asks.

Are you SOC 2 or ISO 27001 certified?
We align our security practices with SOC 2 and ISO 27001 principles and follow OWASP guidelines, with a SOC 2 program in progress. Alongside that, the major ad platforms have reviewed and approved our app for client-data access, and the architecture above is how the product is actually built. Audit detail is available to your security team on request.
Can AdellaInsight change things in my ad accounts?
Not by default. Access is read-only unless you explicitly grant and enable change permissions. Automated execution is something you turn on deliberately, account by account — never the starting state.
Does my clients’ data get mixed together?
No. Each client is a separate, isolated workspace. Data is never blended across clients or across customers.
Is my data used to train AI models?
No. Your data is used to do your analysis and nothing else — the AI providers we use operate under no-training agreements.
Do you offer a Data Processing Agreement (DPA)?
Yes. We provide a DPA for business customers, covering scope of processing, subprocessors, security commitments, and international-transfer safeguards. See the data processing & compliance policy or ask us for one.
Where is my data processed, and how are international transfers handled?
AdellaInsight may process data globally. For data moving outside the EEA or UK, we use Standard Contractual Clauses and equivalent safeguards, backed by vendor risk assessments.
What happens if there’s a data breach?
We notify affected customers without undue delay — aiming for 72 hours in line with GDPR expectations — and give you the detail you need to meet your own obligations.
Who can I talk to about a security review?
Email admin@adellainsight.com and we’ll walk your team through access scopes, data flow, and handling.

Still have questions?

Bring your toughest security questions.

We’d rather earn the trust than ask for it. Talk to us before you connect a thing.