Legal
Privacy Policy
Effective date: 2026-08-10
Controller: Definitely Mabe AB (org. nr 556836-0688), Sweden. Contact:
mathias@d-ma.be
This policy describes how Definitely Mabe AB handles personal data: as a company, in client engagements, and through this website. The last section covers our Google Ads API application specifically, and applies in addition to everything above it.
Who is responsible
Definitely Mabe AB (org. nr 556836-0688), Stockholm, Sweden, is the data controller for the personal data described in this policy. We have not appointed a data protection officer; we are not required to. Questions go to mathias@d-ma.be.
What we hold, and why
Business contacts. Names, work email addresses, phone numbers and job titles of people at client and prospective client organisations, together with our correspondence with them. The legal basis is legitimate interest in conducting and administering a business relationship, or the performance of a contract where one exists.
Engagement records. Agreements, statements of work, time records, invoices and the deliverables themselves. The legal basis is performance of a contract, and for the accounting records, a legal obligation — Swedish bookkeeping law requires them to be kept for seven years.
Client data we are given access to. In the course of an engagement we may be granted access to systems containing personal data belonging to a client's own customers or employees. In that situation the client is the controller and we act as processor on their documented instructions, under the terms of the engagement agreement and a data processing agreement where one is required.
Website visitors. This site sets no cookies, runs no analytics or advertising scripts, and has no forms. Our web server records standard request logs, including IP address and user agent, for security and operation; those are retained briefly and are not used to profile anyone. The legal basis is legitimate interest in operating the site securely.
Email. If you write to us, we hold your message and address in order to reply and to keep a record of the exchange.
Who we share it with
We do not sell personal data and we do not share it for anyone else's marketing. It is shared only with service providers who process it on our behalf — email and file hosting, accounting, and payment processing — each under a contract, and with authorities where the law requires it. Personal data is held within the EU/EEA.
How long we keep it
Business correspondence and contact records are kept for the duration of the relationship and a reasonable period afterwards. Accounting records are kept for seven years, as Swedish law requires. Data we hold as a processor for a client is deleted or returned at the end of the engagement, on their instruction.
Your rights
Under the GDPR you may request access to the personal data we hold about you, its correction or erasure, restriction of or objection to our processing, and portability where it applies. Where processing rests on consent, you may withdraw that consent at any time. Write to mathias@d-ma.be and we will respond within one month.
If you consider that we have handled your personal data improperly you may lodge a complaint with the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), imy.se.
The Google Ads API application
This section applies to the OAuth application registered under the Google Cloud project
dm-ads-automation, our internal advertising tooling. It is described in full at
Google Ads automation.
Scope requested
The application requests exactly one OAuth scope:
https://www.googleapis.com/auth/adwords
No other Google API scope is requested by this application.
What data is accessed
No Google Ads API integration has been deployed. Our developer token holds Basic access, granted 1 September 2026, and the only requests made against a production Google Ads account are access-level diagnostics: no advertising data has been processed or stored, and nothing in any account has been created or modified. This notice describes what the application is designed to access once that changes, so that the commitments below are on record before any data is handled rather than after.
As designed, the application will read — and, where a person has explicitly approved the specific change, write — advertising performance and campaign data from Google Ads accounts a client has granted us access to administer. That means campaign, ad group, keyword and search-term performance; account structure; and change history.
No end-user personal data is collected through this application. The application does not access, store, or process personal data belonging to our clients' website visitors or customers. Offline conversion uploads (where used) consist of an anonymous click identifier, an order value, a currency, and a timestamp — no name, email, address, or other personal identifier is transmitted.
Where data is stored
Data read from Google Ads is stored in a private, access-controlled repository used exclusively inside Definitely Mabe AB. It is not stored in any public or shared location.
How data is used
Data is used solely to analyse and manage the advertising account a client has granted us access to, on their behalf and under their engagement with us. Data is:
- Not sold to any third party
- Not shared with any third party outside the engagement it was collected for
- Held within the EU/EEA
- Not used to advertise to the data subject or any other party
- Not used as training data for any machine-learning model, internally or externally
Data retention
Data is retained for the duration of the client engagement and a reasonable period afterward for record-keeping, then deleted. Clients may request deletion at any time.
Changes to this policy
If how we handle personal data changes — including the scope of what the Google Ads API application does — this policy will be updated to match before the change takes effect, and the effective date above will change with it.
Contact
Questions about this policy: mathias@d-ma.be