Security & data trust
Built to be trusted with your clients’ data.
You’re connecting accounts that aren’t just yours — they’re your clients’. Here’s exactly how that data is accessed, handled, and kept.
The hardest security reviews in marketing? We’ve already passed them.
Before any channel will hand a third-party app access to client advertising data, it puts that app through a formal review. AdellaInsight went through those reviews — with Meta, Google, and the other channels we connect — and was approved to access client data through our own proprietary application. You don’t have to take our word for how seriously we treat data access. The platforms already did.
How it’s built
The architecture, not just a promise.
Read-only by default
AdellaInsight reads the data it needs to analyze and reports back. It doesn’t change anything in your ad accounts unless you explicitly grant and turn on that access — the default is look, not touch.
Every client, walled off
Each client lives in its own isolated workspace. One client’s data is never blended with another’s — the cross-contamination that breaks single-brand tools at the agency layer can’t happen here.
Encrypted, in transit and at rest
Data is encrypted moving between systems (TLS in transit) and while stored (encryption at rest).
You decide what’s client-visible
Every widget and report is yours to show or keep internal. Nothing reaches a client’s screen unless you choose to put it there.
Role-based, need-to-know
Access to data is role-based and limited to a need-to-know basis — scoped to what each person and system actually requires to do the work.
Logged and monitored
Systems are monitored and access is logged, so unusual activity is caught early and there’s a clear record of who touched what.
What the AI actually sees
Aggregated metrics. Never raw customer records.
The intelligence runs on AI models — and we’re precise about what they receive. AdellaInsight sends only the compressed, aggregated marketing metrics needed for analysis: spend, performance, trends. It does not send raw customer records, individual-level rows, or personal information. The AI providers operate under no-training agreements, so your data is never used to train any model.
Ownership
Your data is yours. Always.
We hold your data to do the work you’re paying for — nothing else. It’s never sold, never used to train models, and never shared across customers. You can export it at any time, and you can have it deleted.
Compliance & data protection
Enterprise-grade by design.
We build to the standards your security and legal teams expect — documented processor obligations, a DPA for business customers, and safeguards that travel with your data.
Documented processor obligations
When we process data on your behalf, we act on documented instructions and support GDPR Articles 32–36 — security, breach notification, and DPIAs.
Data Processing Agreement
A DPA is available for every business customer — covering scope, subprocessors, security commitments, and international-transfer safeguards.
Vetted, and listed on request
Every subprocessor meets strict data-protection standards under a data processing agreement. The current list is available on request.
Safeguards across borders
For data moving outside the EEA or UK, we rely on Standard Contractual Clauses and equivalent legal transfer mechanisms.
Data subject requests, supported
Access, correction, deletion, portability, and objection — we help you respond to data subject requests on your timeline.
Notification within 72 hours
If a breach occurs, we notify affected customers without undue delay — aiming for 72 hours, with the detail you need to meet your obligations.
The questions a security team asks.
Still have questions?
Bring your toughest security questions.
We’d rather earn the trust than ask for it. Talk to us before you connect a thing.