Privacy Policy
Last updated: April 22, 2026
1. Who We Are
HAT2AI (https://creatadv.online) is a product of CreatADV SMPC, which acts as the Data Controller under the General Data Protection Regulation (GDPR).
- Company: CreatADV SMPC
- Address: Markou Mpotsari 3, Galatsi, Athens, Greece 11146
- Email: info@creatadv.com
- Phone: +302110125230
- VAT: EL801645582
- Data Protection Officer (DPO) / Privacy Contact: info@creatadv.com
2. What Data We Collect
2.1 Account Data
When an account is created, we store:
- Username, hashed password (bcrypt), full name, email address
- User role (admin, employee, client)
- Language preference
2.2 Google Business Profile (via GBP API)
When you connect your Google Business Profile, we collect via OAuth 2.0 authorization:
- Reviews (reviewer name, rating, comment, date)
- Performance statistics (impressions, clicks, calls, direction requests)
- Business profile information
2.3 Meta Ads (via Graph API)
When you connect your Meta Ads account, we collect via OAuth 2.0 authorization:
- Campaign performance data (impressions, clicks, spend, CPC, CTR)
- Audience demographics (aggregated)
- Ad creatives metadata
2.4 Google Ads (via REST API)
When you connect your Google Ads account, we collect via OAuth 2.0 authorization:
- Campaign performance data (impressions, clicks, spend, conversions)
- Keyword data
- Audience demographics (aggregated)
2.5 TikTok Ads (via Marketing API)
When you connect your TikTok Ads account, we collect via OAuth 2.0 authorization:
- Campaign performance data
- Audience insights
2.6 LinkedIn Ads (via Marketing API)
When you connect your LinkedIn Ads account, we collect via OAuth 2.0 authorization:
- Campaign performance data
- Professional audience demographics
2.7 Traffic Analytics
We process server-side traffic statistics from AWStats:
- Aggregate visitor counts, page views, countries, browsers
- No personal visitor data is stored
2.8 AI Chatbot
When the AI Chatbot feature is used, we collect:
- Conversation logs (visitor messages, AI responses)
- Lead information (name, email, phone — voluntarily provided by visitor)
- Session metadata (IP country, device type, browser)
- Conversations use the client's own API key or CreatADV managed key
2.9 AI Visibility & Monitoring
AI platform query results (how your business appears on ChatGPT, Gemini, Claude, Perplexity). No personal data is involved.
2.10 WooCommerce (Shop Manager)
When you connect your WooCommerce store, we collect via WooCommerce REST API:
- Product catalog, order data
- Customer information (name, email, city, country)
2.11 Cookies
Our platform uses session cookies strictly for authentication purposes. We do not use tracking cookies, third-party analytics cookies, or advertising cookies.
3. How We Use Data
We use collected data exclusively to:
- Provide advertising analytics and AI-powered recommendations
- Generate performance reports
- Monitor AI visibility across platforms
- Operate AI chatbot on client websites
- Track order deliveries (Shop Manager)
- Monitor competitor pricing (Shop Manager)
- Send notifications and alerts
- Improve our services
4. Data Sharing
We do NOT sell personal data.
We do NOT share data with third parties except:
- AI API providers (Anthropic/Claude, OpenAI, Google Gemini, Perplexity) — data sent only as needed for specific features
- Payment processors (Stripe) — for payment processing (see 4.1 below)
- Email delivery services — for notifications
All API communications use encrypted connections (HTTPS/TLS).
4.1 Payment Processing — Stripe
We process your payments through Stripe Payments Europe, Ltd. (4 Dublin Landings, North Wall Quay, Dublin 1, D01 V4A3, Ireland).
Data we share with Stripe:
- Full name / company name
- Contact email
- Billing address (street, city, postal code, country)
- VAT number (if provided)
- Order amount and description
- IP address (for fraud detection)
Data we do NOT have access to:
- Card number
- CVV / security code
- Card expiry date
- Cardholder name
Stripe is an independent data controller for payment data it collects. It retains data according to its Privacy Policy and the PCI-DSS Level 1 framework.
Stripe Customer ID: For customers who have completed at least one payment, we store the unique Stripe Customer ID (cus_xxx) to facilitate future purchases without re-entering details.
Payment data retention: We retain order records (order number, products, amounts, billing details) for 10 years, as required by Greek tax law (Greek Book-Keeping Code, Art. 13).
Legal basis (GDPR): Payment processing is necessary for the performance of the service purchase contract (Article 6(1)(b) GDPR) and compliance with legal obligations (Article 6(1)(c) GDPR — tax law).
5. Data Storage & Security
- Data stored on SiteGround Cloud servers in Europe
- API tokens encrypted using AES-256-CBC
- Passwords hashed using PHP password_hash (bcrypt)
- Database access restricted to application only
- Regular backups maintained by hosting provider
6. Data Retention
- Account data: Retained while account is active, deleted on request
- Advertising data: Retained for the subscription period + 12 months for historical reporting
- Chatbot conversations: Retained during active subscription, archived after cancellation
- AI Monitoring results: Retained indefinitely for trend tracking
- Traffic data: Retained indefinitely for historical comparison
7. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the right to:
- Access your data
- Rectification of inaccurate data
- Erasure ("right to be forgotten")
- Data portability
- Restrict processing
- Object to processing
- Withdraw consent
Contact us: info@creatadv.com
Supervisory authority: Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ) — www.dpa.gr
8. Meta Platform Data
We use Meta's Graph API to access advertising data.
- Data deletion requests can be submitted via our callback URL:
https://creatadv.online/api/meta-data-deletion.php
- Users can also request data deletion by contacting info@creatadv.com
9. Google API Data
We use Google APIs (Ads, Business Profile) in compliance with Google API Services User Data Policy.
- We only access data authorized by the user via OAuth consent
- Data is not used for purposes other than providing our services
10. Changes to This Policy
Last updated: April 22, 2026
We may update this policy; changes will be posted on this page.