01Who we are
Adducta is a paid advertising service operated from Toronto, Ontario, Canada. We plan, buy and manage advertising on Google, Facebook, Instagram and Bing for our clients, capture the enquiries that advertising produces, and tell the client which of those people are worth calling.
Written questions about privacy go to privacy@adducta.com. Anything else goes to hello@adducta.com. We answer both.
02Which role we are in
We handle personal information in two different capacities, and which one applies decides who is answerable to you. This distinction is not paperwork. It is the difference between us deciding what happens to your information and a client of ours deciding it.
| Situation | Who decides | Who to ask |
|---|---|---|
| You visit adducta.com or send us the enquiry form | We do. It is our site and our sales enquiry. | Us, at privacy@adducta.com |
| You fill in a form on a landing page we built and run for one of our clients | The client does. They are advertising their own business, and they decide what happens to the enquiry. | The business you contacted, first. Write to us as well and we will pass it on and act on their instruction. |
| You are a client of ours, or work for one | We do, for your account, your billing and the security of the service. | Us |
In the middle row we are a service provider acting on the client's documented instructions. We do not use those enquiries for our own purposes, we do not add them to any list of ours, and we hand them back or delete them when the client tells us to or when the relationship ends. Where the law makes us answer you directly regardless of that arrangement, we do.
03What we collect
Visiting adducta.com
This page loads nothing from anyone else. No analytics, no advertising pixel, no fonts or scripts from another company's servers. We set no cookies of our own. Our network provider, Cloudflare, may set a cookie that tells its systems your browser is not a bot; it carries no profile of you and we cannot read anything else with it.
One small script runs, and it does one thing. If you arrived from an
advertisement, the platform adds an identifier to the link
(gclid, gbraid or wbraid from
Google, fbclid from Facebook or Instagram,
msclkid from Bing), together with the campaign tags whoever
built the link chose to add (utm_source and its relatives).
That script keeps those values in your browser's local storage for 90
days, alongside a random identifier it generates so that a form you send
later can be joined to the click that brought you. If your arrival
carried one of those identifiers, it also sends us:
- the click identifier and campaign tags themselves
- the random visitor identifier, which is a random number and is not derived from anything about you or your device
- which page you landed on
- the host name of the site you came from, never the full address. A full referring URL routinely carries somebody's search terms or a session token belonging to another site. None of that is ours to hold, and the host name answers the only question we ask of it
If you arrived without a click identifier, by typing the address or from a bookmark, that request is never sent. There is no page-view tracking here at all. We do not record what you read, how far you scrolled or how long you stayed.
Your IP address reaches our server the way it reaches every server on the internet. We use it to rate limit, so that one machine cannot flood the form, and we do not store it.
Sending the enquiry form on adducta.com
The form asks for your name and an email address, and optionally your company and a message. All four are stored, along with the attribution described above if your browser was holding any. We also record how long the form was open before it was sent and whether a field invisible to people was filled in, both of which exist only to tell an automated submission from a person.
When an enquiry arrives, a notification goes to our own team over Telegram containing your name, your email address and the first 400 characters of your message, so that somebody sees it within minutes rather than at the end of the day. Telegram is named in section 6 for that reason.
Landing pages we run for a client
When you fill in a form on a page we operate for one of our clients, we collect what that form asks for. Typically that is a name, an email address, a phone number and whatever you wrote, plus the attribution described above. It goes to the business you were contacting. We hold it so that they can read it, and so the advertising that produced it can be measured. See section 2 for who is answerable to you about it, and section 5 for the grade an AI model proposes on it.
Signing in to the dashboard or the operator console
Accounts hold a name, an email address and a password we never see in readable form: authentication is handled by our provider, which stores a hash rather than the password itself. Every sign-in, sign-out and failed attempt is recorded with the time, the email address that was tried, the IP address and the browser's user agent string. Failed attempts are kept precisely because an address somebody tried is the evidence of an attack on your account.
Every action an operator of ours takes inside the console is written to an audit log: who did it, what they touched and when.
Email you send us
We run our own mailboxes on adducta.com. Messages to and from them are stored encrypted, and are read by the people who work here. Nothing else happens to them: they are not scanned to build a profile and not used to target advertising.
04Why we use it
Canadian law asks us to identify our purposes and to limit collection to them. Ours are short, and there is nothing collected below that does not serve one of them.
| Purpose | What it uses |
|---|---|
| Answering you | The enquiry you sent and the email address you gave for a reply. |
| Delivering the service to our client | Enquiries captured on their pages, so that the business you contacted can call you back. |
| Knowing which advertising worked | The click identifier and campaign tags, joined to the enquiry they produced. This is the whole reason attribution exists: without it a client pays for advertising nobody can measure. |
| Telling a good enquiry from a bad one | The content of the enquiry, graded as described in section 5, so a client phones the people worth phoning. |
| Improving the service in aggregate | Counts and averages only, such as what a qualified enquiry costs in a given area. Never anything identifying, never data from one client shown to another, and never a figure drawn from so few cases that an individual could be worked out from it. |
| Keeping accounts and the service secure | Sign-in history, the audit log, and IP addresses used for rate limiting. |
| Billing and the law | Invoices, spend records and the accounting records Canadian tax law requires us to keep. |
Where the law asks for a legal basis by name, ours are: performing a contract, for clients and for the service they buy; consent, for the enquiry you chose to send us; and our legitimate interest in measuring our own advertising, securing our systems and preventing abuse, which we have weighed against the very small amount of information those uses need. You can withdraw consent at any time, as described in section 14.
05Automated grading, and its limits
Our service exists to tell a client which enquiries deserve a phone call. To do that, an AI model reads each enquiry and proposes a grade of hot, warm, cold, or not a genuine enquiry, with its reasoning. What it is shown is the name, the email address, the phone number and the message from the enquiry, along with which campaign and search term produced it and which business it is for.
The model does not decide anything. It writes a recommendation into a record, and a person applies it or overrules it. Every disagreement between the two is logged, which is both how we check the model's honesty and how we know when it is drifting. No consequence for you follows from the model's opinion alone.
The model is operated by Anthropic, in the United States, through their commercial API. Under the terms we use them on, what we send is not used to train their models. You may ask us what the model said about your enquiry, ask a person to look at it again, and object to the grading altogether: write to privacy@adducta.com.
06Who else sees it
We do not sell personal information, and we do not disclose it to anybody not named here, except where the law compels us or where you ask us to. Every company below works for us under contract, on our instructions, for the purpose stated and nothing else.
| Who | What reaches them | What for |
|---|---|---|
| Click identifiers, and the fact that an enquiry arrived and how it was graded. Where a client has enabled it and the platform requires it, an email address or phone number in irreversibly hashed form. | Running and measuring advertising on Google. | |
| Meta | The same, for Facebook and Instagram. | Running and measuring advertising on Meta. |
| Microsoft | The same, for Bing. | Running and measuring advertising on Bing. |
| Anthropic | The content of an enquiry and its campaign context, as described in section 5. | Proposing a grade for a person to apply. |
| Supabase | Everything stored, as our database and sign-in provider. | Holding the data and authenticating accounts. |
| Cloudflare | The requests your browser makes to our sites. | Serving the site and blocking attacks on it. |
| Our hosting and email providers | Whatever is stored on the servers and in the mailboxes they run for us. | Running the service and our email. |
| Telegram | The operational alerts described in section 3, including the name, email address and first 400 characters of an enquiry sent to us through adducta.com. | Reaching our own team within minutes of something happening. |
When a government asks
- We check that the request is lawful before we answer it: who is asking, under which law, and whether it actually reaches us and the data they have named.
- We challenge one that is not. An overbroad or unlawful demand is refused or narrowed, with legal advice where the stakes warrant it, rather than quietly satisfied because arguing is expensive.
- We disclose the minimum the law requires and nothing beside it. A request naming one person does not become an export of a table.
- We write down what happened. What was asked, by whom, under what authority, what we handed over, and who decided. That record is what makes the three commitments above auditable rather than decorative.
We will tell you that your information was requested unless the law forbids us from saying so. We have never received a national security request, and if that ever stops being true this paragraph changes.
If the business is ever sold or merged, personal information may pass to the buyer, who would be bound by this policy until they tell you otherwise. We would tell you before that happened.
07Advertising, measurement and your choices
We buy advertising for our clients, and we measure it. Measuring means telling the platform that a click it sold turned into an enquiry, and how good that enquiry was. It is done by sending back the identifier the platform itself put in the link, and where the platform supports it and the client has enabled it, an email address or phone number converted into an irreversible hash before it leaves our systems. The platform can match that hash against one it already holds; it cannot be turned back into your details, by them or by anyone else.
We do not build advertising audiences out of the people who enquire, and we do not retarget you across the internet on our own behalf. Where a client asks for advertising to be shown again to people who visited their site, that is set up inside that client's own advertising account, using only that client's own data.
Turning it off
- Google: personalised advertising can be switched off at myadcenter.google.com.
- Meta: advertising preferences live in the settings of your Facebook or Instagram account.
- Microsoft: account.microsoft.com/privacy/ad-settings.
- Across many advertisers at once: youradchoices.ca in Canada, or optout.aboutads.info.
- What we hold: clearing your browser's storage for adducta.com removes the click identifier and the random visitor number from your device. To remove what has already reached us, see section 15.
08Data we receive from Google
With the permission of the advertiser who owns the account, our software signs in to Google Ads through Google's own authorisation flow and reads and writes that account: campaigns, budgets, keywords, spend and conversion results. We use that access to run the advertising we were hired to run, and for nothing else.
Adducta's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: we do not sell Google user data; we do not use it for advertising other than the advertising in the account it came from; we do not allow humans to read it except where the account owner has asked us to, where it is necessary for security or to comply with the law, or where the data has been aggregated and made anonymous; and we do not transfer it except as needed to provide the service, to comply with the law, or as part of a merger or sale about which the account owner would be told.
09Data we receive from Meta
With the permission of the business that owns the account, our software connects to Meta's advertising tools to create and manage advertising on Facebook and Instagram, to read how it performed, and to send back the fact that an advertisement produced an enquiry.
Information we receive from Meta is used only to provide that service to the business it belongs to. We do not sell it, we do not transfer it to any data broker or advertising network, and we do not combine it with data belonging to another of our clients. We keep it only while we are running that account's advertising, and delete it when the business asks us to or when we stop working for them, whichever comes first.
If you are a member of the public rather than an advertiser: what Meta passes to us about you is the click identifier described in section 3. To have it removed, follow section 15, which is the deletion route Meta requires us to publish.
10How long we keep it
Everything has an end date. Where a period below is longer than you would like, section 15 still applies: you can ask for deletion sooner, and we will do it unless the law requires us to keep the record.
| What | How long | Why that long |
|---|---|---|
| Click identifiers and campaign tags | 90 days | The window the advertising platforms allow a conversion to be reported in. Holding it longer would keep a record of a person past the point where it could be used for anything. |
| An enquiry sent to us through adducta.com | 24 months after our last exchange with you | A sales conversation that goes quiet often restarts. After two years it has not. |
| An enquiry captured for a client | While we work for that client, plus 12 months, or sooner if they instruct us | It is their record, kept so their business can act on it. Their instruction ends it earlier. |
| Account details and sign-in history | 12 months after the account is closed | Long enough to investigate a compromise that is noticed late. |
| Operator audit log | 24 months | It is the record of what we did with your data, and deleting it early would remove the evidence that would answer a complaint. |
| Invoices and financial records | At least six years | Canadian tax law. This is the one category we cannot delete on request. |
11Where it is held
Our servers and our database are with providers in North America. Some of the companies in section 6 process data in the United States, and some operate globally. That means information about you may be stored or handled outside the province or country you live in, and while it is there it is subject to the laws of that place, including lawful access by courts and law enforcement.
We use providers who commit contractually to protecting it to a standard comparable to Canadian law, and we hold them to that. If you would like to know which country a specific category of your information sits in, ask and we will tell you.
12How it is protected
- Everything travels over encrypted connections, and our database is reachable only through our own API rather than from the open internet.
- Separation between clients is enforced by the database itself, not by application code remembering to filter. Every query runs as the person who made the request, and a query that reaches for another client's row returns nothing.
- Mail we hold is encrypted where it is stored.
- Access is granted to named operators deliberately and withdrawn the same way. Having a login is not enough on its own.
- Every operator action is logged, and repeated failed sign-ins lock an account and raise an alert.
- Passwords are never stored in a form anybody, including us, can read.
No system is perfect, and a policy that claimed otherwise would be worth less than this sentence. If personal information we hold is lost or taken and there is a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and tell you directly, as Canadian law requires, and we will tell you what was taken rather than that "an incident occurred".
13What we never do
These are commitments, not descriptions of current practice that might quietly change. If any of them ever stops being true, this policy changes first and you are told, as described in section 17.
- We do not sell personal information, and we do not trade or rent it.
- We do not use one client's data to advertise another. Data collected on a business's site may be used to advertise that business and no one else. It is also a platform policy violation, and the penalty falls on every account we manage at once, so this one protects our clients from each other and from us.
- We do not build advertising audiences that mix clients together.
- We do not track behaviour on adducta.com. No analytics, no session recording, no heatmaps.
- We do not send you marketing because you sent us an enquiry. We reply to what you wrote. Anything else needs you to ask for it, and every message we do send carries a way to stop it.
- We do not let a model decide anything about you on its own. See section 5.
14Your rights
Wherever you live, you can ask us for all of the following, and we will not charge you for it or treat you differently for asking.
- See it. A copy of what we hold about you, and an account of who we have disclosed it to.
- Correct it. If something is wrong, tell us and we will fix it.
- Delete it. See section 15.
- Take it with you. A copy in a structured, machine-readable file.
- Withdraw consent. At any time, for anything we do on the basis of consent. Some of what we do is necessary to provide a service you asked for, and we will tell you plainly if withdrawing means we can no longer provide it.
- Object to the grading described in section 5, and ask for a person to review it.
- Complain, to us first and to a regulator if we do not resolve it. See section 18.
Write to privacy@adducta.com. We answer within 30 days. If a request is complicated enough to need longer, we will tell you before the 30 days are up and say why. We may need to confirm you are who you say you are before we act, and we will ask for the least that establishes it.
If your enquiry was sent through a client's landing page, the business you contacted decides what happens to it. Ask them, and ask us too: we will forward the request, act on it as far as we are permitted to, and tell you who has it.
15Deleting your data
This section is our data deletion instruction, and it is the address to give any platform that asks where our deletion route is.
How to have your data deleted
- Email privacy@adducta.com with the subject Data deletion request.
- Tell us the email address or phone number you used, and where you contacted us: adducta.com, or the name or web address of the business whose page you filled in.
- We confirm receipt within 5 working days, and may ask one question to make sure we are deleting the right person's record.
- We delete within 30 days and write to tell you what was deleted and what, if anything, we had to keep and why.
If you reached us through a Facebook or Instagram advertisement, this is the same route. There is no Facebook account to disconnect: what we hold from Meta is the click identifier described in section 3, and the request above removes it.
What gets deleted, and what cannot
Deleted means deleted: the record is removed from our database, not hidden behind a flag. That covers your enquiry, the grade and reasoning attached to it, the click identifier and campaign tags, and any correspondence in our mailboxes.
Two things survive a deletion request, and it is fairer to say so here than to discover it later:
- Invoices and accounting records, which Canadian tax law requires us to keep for at least six years. These identify our client, and your enquiry is not part of them.
- Counts and totals that no longer identify anybody, such as how many enquiries a campaign produced. Once your record is gone, nothing in those figures points back to you, and removing a number from a total would falsify our client's own reporting.
An enquiry captured on a client's landing page belongs to that client. We will always delete our copy on request. Whether the business you contacted also deletes theirs is their decision, and we will tell you who they are so you can ask.
Clearing the site data for adducta.com in your browser removes the click identifier and the random visitor number from your own device immediately, without asking anybody.
16Children
Adducta is sold to businesses. Neither this site nor anything we run for a client is directed at children, and we do not knowingly collect information from anybody under 16. If you believe a child's information has reached us, write to privacy@adducta.com and we will delete it without asking you to prove anything.
17Changes to this policy
When this policy changes, the date and version at the top change with it. If a change means we would use information we already hold for something materially different from what is written here, we will ask before doing it rather than announcing it afterwards. We keep the previous versions and will send you one on request.
18Contact, and how to complain
Privacy questions, access requests and deletion requests go to our privacy officer at privacy@adducta.com. Everything else goes to hello@adducta.com. We are in Toronto, Ontario, Canada, and our full contact details are on the contact page.
Complain to us first, because we can usually fix it faster than anybody else. If we do not resolve it, you can take it to the Office of the Privacy Commissioner of Canada at priv.gc.ca. Residents of Quebec may also go to the Commission d'accès à l'information du Québec. If you are in the United Kingdom or the European Economic Area, you may complain to your own supervisory authority.