DK | Databehandling i Texta Data Hub (annonce- og marketingdata)

DANSK VERSION
Privatlivspolitik – Texta Data Hub
Senest opdateret: Juli 2026

§1 Dataansvar og roller

 

1.1. Denne privatlivspolitik beskriver behandlingen af oplysninger i Texta Data Hub (“Platformen”), der drives af Texta A/S, CVR-nr. 37639346, [ADRESSE] (“Texta”).

1.2. Texta behandler som udgangspunkt oplysningerne som databehandler på vegne af den kunde, der har forbundet sine marketingkonti til Platformen (“Kunden”), jf. databeskyttelsesforordningens (forordning (EU) 2016/679, “GDPR”) artikel 28. Kunden er dataansvarlig. Behandlingen er nærmere reguleret i den databehandleraftale, der er indgået mellem Kunden og Texta.

1.3. For oplysninger om Kundens egne brugere af Platformen (jf. §3.4) og for oplysninger, Texta behandler til egne administrations- og sikkerhedsformål (logning, misbrugsbekæmpelse), er Texta selvstændig dataansvarlig.

1.4. Henvendelser vedrørende denne politik rettes til [PRIVACY-EMAIL].

§2 Platformens funktion

 

2.1. Platformen indhenter, efter Kundens udtrykkelige autorisation via den enkelte platforms officielle godkendelsesflow (OAuth), data fra tredjeparts-marketingplatforme gennem disses officielle programmeringsgrænseflader (API’er) med henblik på rapportering, analyse og rådgivning over for Kunden.

2.2. Platformen er ved denne politiks seneste opdatering integreret med Meta Platforms (Facebook/Instagram annoncering) via Meta Marketing API med tilladelserne ads_read og business_management. Integration med yderligere platforme (f.eks. Google, TikTok, LinkedIn, Klaviyo) vil ske efter samme principper, og denne politik opdateres i så fald med angivelse af platform og datakategorier.

§3 Kategorier af oplysninger

 

3.1. Annoncestatistik (performancedata). Aggregerede kampagne-, annoncesæt- og annoncetal, herunder eksponeringer, rækkevidde, frekvens, klik, visninger, videovisninger, konverteringer (antal og værdi) og annonceomkostninger. Disse oplysninger er statistik på kampagne-/annonceniveau og udgør som udgangspunkt ikke personoplysninger, idet de ikke kan henføres til bestemte fysiske personer blandt annoncemodtagerne. Texta indhenter ikke oplysninger om de enkeltpersoner, der eksponeres for eller interagerer med Kundens annoncer.

3.2. Annonceindhold og -opsætning. Annoncetekster (primærtekst, overskrift, beskrivelse, call-to-action), links, henvisninger til billed- og videomateriale (URL’er og miniaturebilleder) samt kampagne- og annoncesætindstillinger, herunder målgruppekriterier (f.eks. aldersinterval, køn, geografi, interesser), placeringer, budstrategi og budget. Målgruppekriterier er Kundens opsætningsvalg og udgør ikke oplysninger om konkrete personer. I det omfang annoncemateriale undtagelsesvist indeholder personoplysninger (f.eks. billeder af identificerbare personer), behandles disse alene som led i opbevaring og visning på vegne af Kunden.

3.3. Adgangsnøgler (tokens). De tekniske adgangsnøgler, som marketingplatformen udsteder ved Kundens autorisation. Adgangsnøgler opbevares krypteret (jf. §8) og anvendes udelukkende til den i §2 beskrevne indhentning.

3.4. Brugeroplysninger. Navn, e-mailadresse, rolle og loginoplysninger for de af Kundens medarbejdere og øvrige brugere, der har adgang til Platformen, samt tekniske logoplysninger om disses handlinger (tidspunkt, handling, forbindelses-ID).

3.5. Platformen indhenter ikke indholdet af leadformularer (navn, e-mailadresse m.v. på Kundens leads) eller andet indhold, der vedrører identificerbare slutbrugere. Såfremt dette ændres, vil det forudsætte særskilt instruks fra Kunden, opdatering af databehandleraftalen og af denne politik.

§4 Formål og retsgrundlag

 

4.1. Oplysningerne behandles med følgende formål: (a) levering af rapportering, analyse og rådgivning til Kunden, (b) drift, sikkerhed og fejlfinding af Platformen, (c) dokumentation af autorisationer og behandlingshændelser samt (d) overholdelse af retlige forpligtelser.

4.2. For behandlinger hvor Texta er databehandler, sker behandlingen efter Kundens dokumenterede instruks i databehandleraftalen. Kundens retsgrundlag er opfyldelse af aftalen med Texta (GDPR art. 6, stk. 1, litra b) og/eller Kundens legitime interesse i analyse af egne marketingaktiviteter (GDPR art. 6, stk. 1, litra f).

4.3. For behandlinger hvor Texta er dataansvarlig (§1.3), er retsgrundlaget Textas legitime interesse i at administrere, sikre og dokumentere Platformens drift (GDPR art. 6, stk. 1, litra f) samt opfyldelse af retlige forpligtelser (GDPR art. 6, stk. 1, litra c).

4.4. Oplysninger indhentet på vegne af én kunde anvendes ikke i identificerbar form til andre kunders formål eller til Textas egne markedsføringsformål, og oplysninger sælges ikke. Ingen kunde har adgang til en anden kundes data, og ingen kunde kan gennem Platformens rapporter, analyser eller sammenligninger identificere eller udlede en anden kundes data.

4.5. Texta sammenstiller og anvender data på tværs af sin kundeportefølje i samlet, generaliseret form, f.eks. gennemsnitlige annoncepriser og nøgletal (CPM, CPC, ROAS m.v.) fordelt på branche, platform og periode, til brug for benchmarking, analyser, rådgivning og forbedring af Platformens ydelser. Sammenstillingen sker alene på grundlag af kampagnetal, der ikke udgør personoplysninger, og alene i aggregeret form med et fastsat minimumsantal kunder pr. gruppe, således at hverken den enkelte kunde, dennes kampagner eller nogen fysisk person kan identificeres eller udledes af det samlede datasæt. De nærmere vilkår fremgår af databehandleraftalen.

4.6. Texta kan anvende AI-baserede analyseværktøjer som led i Platformens rapportering og analyser, herunder på det i punkt 4.5 beskrevne samlede datasæt. Kunders data anvendes ikke til at træne AI-modeller, hverken Textas egne eller tredjeparters. AI-baseret analyse af en kundes egne data sker alene til brug for den pågældende kunde, og AI-baseret analyse på tværs af kunder sker alene på det samlede, generaliserede datasæt.

§5 Modtagere og underdatabehandlere

 

5.1. Oplysningerne videregives ikke til tredjemand, bortset fra de underdatabehandlere, Texta anvender til drift af Platformen:

UnderdatabehandlerYdelseRegion
CloudflareAPI-drift (Workers) med EU Regional ServicesEU
SupabaseDatabasehostingEU (Frankfurt)
Trigger.devPlanlagte baggrundsjobs (synkronisering, sletning)EU (Frankfurt)
UpstashMidlertidig cache og trafikstyringEU
AxiomTekniske driftslogs uden indholdsdata (90 dages opbevaring)EU

5.2. En opdateret liste med juridiske enheder og behandlingsbeskrivelser fremgår af databehandleraftalens bilag B.

5.3. Marketingplatformene (f.eks. Meta) er selvstændige dataansvarlige for deres egen behandling og er ikke underdatabehandlere for Texta.

§6 Tredjelandsoverførsler

 

6.1. Al lagring og behandling af oplysninger sker inden for EU/EØS (primært Frankfurt, Tyskland).

6.2. I det omfang en underdatabehandler er etableret uden for EU/EØS eller kan tilgå oplysninger derfra, sikres et gyldigt overførselsgrundlag efter GDPR kapitel V (EU-Kommissionens standardkontraktbestemmelser og/eller EU-U.S. Data Privacy Framework), jf. databehandleraftalens bilag C.6.

§7 Opbevaring og sletning

 

7.1. Oplysningerne opbevares i følgende perioder, hvorefter de slettes automatisk:

OplysningerOpbevaringsperiode
Rå annoncedata (statistik og annonceindhold)13 måneder fra indhentning
Normaliserede rapporttalKundeforholdets beståen + 12 måneder
Adgangsnøgler og forbindelsesoplysningerSlettes ved afbrydelse (senest 30 minutter efter)
Autorisations-/samtykkelogForbindelsens levetid + 3 år (dokumentation)
Revisionslog (pseudonymiseret)5 år
Tekniske driftslogs90 dage

7.2. En sletteanmodning efter §10 går forud for de anførte opbevaringsperioder, dog således at revisionsloggen, der alene indeholder pseudonymiserede identifikatorer uden mulighed for henførsel uden en særskilt opbevaret nøgle, bevares af dokumentationshensyn.

§8 Sikkerhed

 

8.1. Texta har gennemført passende tekniske og organisatoriske sikkerhedsforanstaltninger, jf. GDPR artikel 32, herunder: kryptering under transmission og i hvile; supplerende applikationslagskryptering af adgangsnøgler (AES-256-GCM) med kundespecifikke nøgler afledt af en hovednøgle i et krypteret nøglelager; logisk adskillelse af kundedata med adgangskontrol på rækkeniveau (row-level security), der ved fejlkonfiguration ikke udleverer data (fail-closed); tofaktorautentifikation og rollebaseret adgangsstyring; append-only revisionslogning; samt løbende adgangsgennemgang. De aftalte minimumsforanstaltninger fremgår af databehandleraftalens bilag C.2.

§9 Registreredes rettigheder

 

9.1. Registrerede har efter GDPR kapitel III ret til indsigt, berigtigelse, sletning, begrænsning af behandling, dataportabilitet og indsigelse.

9.2. Anmodninger vedrørende oplysninger, som Texta behandler på vegne af en kunde, rettes til den pågældende kunde som dataansvarlig. Texta bistår Kunden med besvarelsen i overensstemmelse med databehandleraftalen. Anmodninger vedrørende oplysninger, hvor Texta er dataansvarlig, rettes til [PRIVACY-EMAIL].

§10 Instruks for datasletning

 

10.1. Sletning af de oplysninger, Platformen har indhentet fra en forbundet marketingkonto, kan begæres på en af følgende måder:

a) Afbrydelse i Platformen (anbefalet). Log ind på [DASHBOARD-URL], vælg Forbindelser, vælg den relevante forbindelse og aktivér Afbryd og slet data. Adgangsnøglen slettes straks og senest inden for 30 minutter, hvorefter sletning af de indhentede oplysninger gennemføres efter §7.

b) Fjernelse af adgang hos platformen. For Meta: gå til Facebook-indstillinger → Business Integrations, find Textas app og vælg Fjern. Meta fremsender herved automatisk en sletteanmodning til Texta (data deletion callback), hvorefter adgangsnøglen slettes og sletning igangsættes som under litra a. Meta udsteder en bekræftelseskode, hvormed anmodningens status kan følges.

c) Skriftlig henvendelse. Anmodning kan fremsendes til [PRIVACY-EMAIL] fra en e-mailadresse tilknyttet kundeforholdet med angivelse af “Sletteanmodning”. Texta bekræfter modtagelsen og gennemfører sletningen uden unødig forsinkelse og senest 30 dage efter modtagelsen.

10.2. Sletningen omfatter adgangsnøgler, rå annoncedata (statistik og annonceindhold), normaliserede rapporttal, cachelagrede data og forbindelseslogs. §7.2 finder tilsvarende anvendelse for revisionsloggen.

§11 Klageadgang

 

11.1. Klage over Textas behandling af personoplysninger kan indgives til Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk.

§12 Ændringer

 

12.1. Denne politik ajourføres ved ændringer i Platformens databehandling, herunder ved tilslutning af nye marketingplatforme eller ændrede datakategorier. Den til enhver tid gældende version er tilgængelig på [URL]. Væsentlige ændringer varsles over for Kunden.

UK | Data processing in Texta Data Hub (advertising and marketing data)

ENGLISH VERSION
Privacy Policy – Texta Data Hub
Last updated: July 2026

§1 Controllership and roles

 

1.1. This privacy policy describes the processing of information in Texta Data Hub (the “Platform”), operated by Texta A/S, Danish company reg. no. (CVR) 37639346, [ADDRESS] (“Texta”).

1.2. Texta generally processes the information as a processor on behalf of the client that has connected its marketing accounts to the Platform (the “Client”), cf. Article 28 of Regulation (EU) 2016/679 (the “GDPR”). The Client is the controller. The processing is further governed by the data processing agreement concluded between the Client and Texta.

1.3. For information about the Client’s own users of the Platform (cf. §3.4) and for information processed by Texta for its own administration and security purposes (logging, abuse prevention), Texta acts as an independent controller.

1.4. Enquiries regarding this policy should be directed to [PRIVACY-EMAIL].

§2 Function of the Platform

 

2.1. Following the Client’s explicit authorization through the respective platform’s official consent flow (OAuth), the Platform retrieves data from third-party marketing platforms through their official application programming interfaces (APIs) for the purpose of reporting, analytics and advisory services to the Client.

2.2. As of the latest update of this policy, the Platform integrates with Meta Platforms (Facebook/Instagram advertising) via the Meta Marketing API using the ads_read and business_management permissions. Integrations with additional platforms (e.g. Google, TikTok, LinkedIn, Klaviyo) will follow the same principles, in which case this policy will be updated to state the platform and data categories concerned.

§3 Categories of information

 

3.1. Advertising statistics (performance data). Aggregated campaign, ad-set and ad-level figures, including impressions, reach, frequency, clicks, views, video views, conversions (count and value) and ad spend. This information constitutes statistics at campaign/ad level and does not, as a rule, constitute personal data, as it cannot be attributed to specific natural persons among the ad audiences. Texta does not retrieve information about the individuals exposed to or interacting with the Client’s ads.

3.2. Ad content and configuration. Ad copy (primary text, headline, description, call-to-action), links, references to image and video assets (URLs and thumbnails), and campaign and ad-set settings, including audience criteria (e.g. age range, gender, geography, interests), placements, bidding strategy and budget. Audience criteria are the Client’s configuration choices and do not constitute information about specific individuals. To the extent ad creative exceptionally contains personal data (e.g. images of identifiable persons), such data is processed solely as part of storage and display on behalf of the Client.

3.3. Access tokens. The technical access credentials issued by the marketing platform upon the Client’s authorization. Access tokens are stored encrypted (cf. §8) and are used exclusively for the retrieval described in §2.

3.4. User information. Name, email address, role and login details of the Client’s employees and other users with access to the Platform, together with technical log data concerning their actions (time, action, connection ID).

3.5. The Platform does not retrieve the contents of lead forms (names, email addresses etc. of the Client’s leads) or other content relating to identifiable end users. Any change to this would require a separate instruction from the Client and an update of the data processing agreement and of this policy.

§4 Purposes and legal basis

 

4.1. The information is processed for the following purposes: (a) provision of reporting, analytics and advisory services to the Client, (b) operation, security and troubleshooting of the Platform, (c) documentation of authorizations and processing events, and (d) compliance with legal obligations.

4.2. Where Texta acts as processor, processing is carried out on the Client’s documented instructions under the data processing agreement. The Client’s legal basis is performance of its agreement with Texta (GDPR Art. 6(1)(b)) and/or the Client’s legitimate interest in analysing its own marketing activities (GDPR Art. 6(1)(f)).

4.3. Where Texta acts as controller (§1.3), the legal basis is Texta’s legitimate interest in administering, securing and documenting the operation of the Platform (GDPR Art. 6(1)(f)) and compliance with legal obligations (GDPR Art. 6(1)(c)).

4.4. Information retrieved on behalf of one client is not used in identifiable form for other clients’ purposes or for Texta’s own marketing purposes, and information is never sold. No client has access to another client’s data, and no client can identify or derive another client’s data through the Platform’s reports, analyses or comparisons.

4.5. Texta compiles and uses data across its client portfolio in combined, generalized form, e.g. average advertising prices and key figures (CPM, CPC, ROAS etc.) by industry, platform and period, for the purposes of benchmarking, analytics, advisory services and improvement of the Platform’s services. Such compilation is based solely on campaign statistics that do not constitute personal data, and solely in aggregated form with a fixed minimum number of clients per group, such that neither the individual client, its campaigns nor any natural person can be identified or derived from the combined dataset. Further terms are set out in the data processing agreement.

4.6. Texta may use AI-based analytics tools as part of the Platform’s reporting and analytics, including on the combined dataset described in section 4.5. Client data is not used to train AI models, whether Texta’s own or third parties’. AI-based analysis of a client’s own data is performed solely for the benefit of that client, and AI-based analysis across clients is performed solely on the combined, generalized dataset.

§5 Recipients and sub-processors

 

5.1. The information is not disclosed to third parties, except to the sub-processors engaged by Texta for the operation of the Platform:

Sub-processorServiceRegion
CloudflareAPI hosting (Workers) with EU Regional ServicesEU
SupabaseDatabase hostingEU (Frankfurt)
Trigger.devScheduled background jobs (synchronization, deletion)EU (Frankfurt)
UpstashShort-lived cache and traffic managementEU
AxiomTechnical operations logs without payload data (90-day retention)EU

5.2. An up-to-date list including legal entities and processing descriptions is set out in Annex B of the data processing agreement.

5.3. The marketing platforms (e.g. Meta) are independent controllers of their own processing and are not sub-processors of Texta.

§6 Third-country transfers

 

6.1. All storage and processing of information takes place within the EU/EEA (primarily Frankfurt, Germany).

6.2. To the extent a sub-processor is established outside the EU/EEA or may access information from outside the EU/EEA, a valid transfer mechanism under Chapter V of the GDPR is ensured (the European Commission’s Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework), cf. Annex C.6 of the data processing agreement.

§7 Retention and deletion

 

7.1. The information is retained for the following periods, after which it is deleted automatically:

InformationRetention period
Raw advertising data (statistics and ad content)13 months from retrieval
Normalized reporting figuresDuration of the client relationship + 12 months
Access tokens and connection detailsDeleted upon disconnection (within 30 minutes)
Authorization/consent logLifetime of the connection + 3 years (documentation)
Audit log (pseudonymized)5 years
Technical operations logs90 days

7.2. A deletion request under §10 takes precedence over the retention periods stated above, save that the audit log, which contains only pseudonymized identifiers that cannot be attributed without a separately stored key, is retained for documentation purposes.

§8 Security

 

8.1. Texta has implemented appropriate technical and organizational security measures, cf. Article 32 GDPR, including: encryption in transit and at rest; additional application-layer encryption of access tokens (AES-256-GCM) using client-specific keys derived from a master key held in an encrypted secret store; logical segregation of client data through row-level security that fails closed in the event of misconfiguration; two-factor authentication and role-based access control; append-only audit logging; and periodic access reviews. The agreed minimum measures are set out in Annex C.2 of the data processing agreement.

§9 Rights of data subjects

 

9.1. Data subjects have the rights of access, rectification, erasure, restriction of processing, data portability and objection under Chapter III of the GDPR.

9.2. Requests concerning information processed by Texta on behalf of a client should be directed to that client as controller. Texta assists the Client in responding in accordance with the data processing agreement. Requests concerning information for which Texta is the controller should be directed to [PRIVACY-EMAIL].

§10 Data deletion instructions

 

10.1. Deletion of the information retrieved by the Platform from a connected marketing account may be requested in any of the following ways:

a) Disconnection in the Platform (recommended). Log in at [DASHBOARD-URL], select Connections, choose the relevant connection and activate Disconnect and delete data. The access token is deleted immediately and no later than within 30 minutes, after which deletion of the retrieved information is carried out in accordance with §7.

b) Removal of access at the platform. For Meta: go to Facebook Settings → Business Integrations, locate Texta’s app and select Remove. Meta thereby automatically transmits a deletion request to Texta (data deletion callback), upon which the access token is deleted and deletion is initiated as under (a). Meta issues a confirmation code by which the status of the request can be tracked.

c) Written request. A request may be submitted to [PRIVACY-EMAIL] from an email address associated with the client account, marked “Deletion request”. Texta will confirm receipt and carry out the deletion without undue delay and no later than 30 days after receipt.

10.2. Deletion comprises access tokens, raw advertising data (statistics and ad content), normalized reporting figures, cached data and connection logs. §7.2 applies correspondingly to the audit log.

§11 Complaints

 

11.1. Complaints regarding Texta’s processing of personal data may be lodged with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, DK-2500 Valby, www.datatilsynet.dk.

§12 Amendments

 

12.1. This policy is updated in the event of changes to the Platform’s data processing, including the connection of new marketing platforms or changed data categories. The current version is available at [URL]. Material changes will be notified to the Client.

Bliv ringet op