BelvaOS Policy

Privacy Policy

This policy explains how Belva Digital collects, uses, stores, shares, and protects information when BelvaOS is used for reporting, planning, campaign intelligence, source connection, analytics, exports, workflow collaboration, and related business operations.

Effective date

May 2026

Contact

info@belvadigital.com

Who we are and what this policy covers

BelvaOS is a workspace-based software product operated by Belva Digital. It is used by Belva team members and approved client users to connect approved marketing, advertising, analytics, planning, and measurement data sources; review performance; collaborate on plans and reports; and export results for legitimate business use.

This policy applies to personal data and account-level business data processed through BelvaOS websites, applications, APIs, workspaces, connected integrations, reporting flows, exports, operational support processes, and related product communications.

Information we collect

We collect account and workspace information such as names, work email addresses, organization details, workspace membership, roles, and authentication information required to sign users in and manage access securely.

We collect connector and integration data when users connect services such as Google Ads, Google Analytics 4, Google Search Console, Meta Ads, MediaPal, IPSOS AdWatch, spreadsheet imports, and other approved sources. This may include OAuth tokens, refresh tokens, account identifiers, manager or customer IDs, ad account metadata, property identifiers, currencies, labels, and selected sync settings.

We collect operational and reporting data such as campaign names, ad set or ad group names, creative metadata, dates, spend, impressions, clicks, conversions, conversion values, reach, attributed results, source health information, sync status, error messages, file metadata, uploaded documents, generated outputs, task activity, comments, and export activity.

We may also collect device, browser, request, audit, and product telemetry reasonably required for security, troubleshooting, fraud prevention, abuse prevention, session integrity, usage analytics, and service improvement.

How we use information

We use information to provide the BelvaOS service, authenticate users, authorize workspace access, connect approved data sources, sync source data, normalize and analyze reporting data, generate dashboards and summaries, support exports, maintain system integrity, and communicate with users about the service.

Where Google API Services data is involved, BelvaOS is intended to use that data only for the user-facing features disclosed in the product and this policy, and only within the scope presented to the user when access is requested. We do not request permissions for speculative future features, and we do not knowingly use Google user data in ways inconsistent with the published disclosures and user authorization.

BelvaOS currently uses connected ad-platform APIs primarily for reporting, analytics, planning, intelligence, and operational data workflows. Unless and until specific product features are launched and separately disclosed, BelvaOS does not rely on connected Google Ads or Meta Ads access to create, edit, pause, resume, or manage campaigns on a user's behalf.

Our legal bases for processing

Depending on the context, we process personal data because it is necessary to perform a contract or pre-contractual service requested by the customer or user, because we have legitimate interests in operating and securing BelvaOS, because we must comply with legal obligations, or because consent is required and has been obtained.

When a user connects a third-party platform, the user is responsible for ensuring they are authorized to grant that access and any legally required notices or permissions within their organization have been handled.

How we share data

Access to BelvaOS data is scoped by workspace membership, role-based permissions, and system controls. Internal Belva users and authorized external client users only see the workspaces and data sources they have been granted access to.

We may share data with infrastructure, hosting, storage, analytics, support, security, and professional service providers only to the extent reasonably necessary to host, secure, operate, troubleshoot, audit, support, or improve BelvaOS.

We may also disclose information where required by law, regulation, court order, lawful government request, corporate transaction, or to protect rights, safety, security, or the integrity of BelvaOS and its users.

We do not sell synced campaign performance data as a data broker, and we do not intentionally provide connected-platform data to unrelated third parties for surveillance, resale, or off-platform profiling inconsistent with the disclosed purpose of BelvaOS.

International transfers and storage locations

BelvaOS may process or store data in multiple jurisdictions depending on our infrastructure, service providers, support operations, or the location of authorized team members and customers. By using the service, users understand that data may be transferred across borders subject to appropriate safeguards and contractual protections where required.

If local law requires specific transfer mechanisms or supplemental safeguards for cross-border data movement, Belva Digital intends to use commercially reasonable measures to support those requirements.

Retention

We retain data only for as long as reasonably necessary for the purposes described in this policy, including providing the service, maintaining reporting continuity, meeting contractual expectations, resolving disputes, enforcing agreements, maintaining backups, and complying with legal, audit, accounting, and security obligations.

Retention periods vary by data type. Connected-source credentials, sync data, logs, uploaded documents, and generated outputs may remain available after a source is disconnected or a workspace relationship changes where continued retention is needed for lawful business, security, recordkeeping, or contractual reasons.

Security

BelvaOS applies access controls, encrypted secret handling, audit logging, environment separation, and other technical and organizational measures designed to protect data against unauthorized access, loss, misuse, alteration, and disclosure.

No system can guarantee absolute security. Users are responsible for protecting their devices, credentials, and workspace access, and for notifying Belva Digital promptly if they suspect unauthorized access or misuse.

Cookies, sessions, and local technologies

BelvaOS uses session cookies, security-related browser storage, and similar technologies necessary to sign users in, maintain sessions, secure requests, remember basic product state, and support analytics or operational features. Additional technologies may be used where needed for performance, fraud prevention, debugging, or lawful product measurement.

Where local law requires consent for non-essential cookies or similar technologies, Belva Digital intends to present and manage those choices in the relevant user experience.

Rights and choices by jurisdiction

Depending on the laws that apply, users and data subjects may have rights to be informed, access their data, correct inaccurate data, delete certain data, restrict or object to certain processing, withdraw consent where processing depends on consent, request portability where applicable, and complain to a regulator.

Users in the European Economic Area, United Kingdom, Switzerland, Kenya, California, and other jurisdictions with privacy rights may have additional rights under local law. We will review and respond to valid requests within the time required by applicable law, subject to identity verification, legal exceptions, and our role as controller or processor in the specific context.

Workspace customers may also have obligations to provide their own notices to their end users, employees, agencies, or clients where they act as controller of the underlying advertising or analytics data made available through BelvaOS.

Children

BelvaOS is a business product and is not directed to children. We do not intend BelvaOS to be used by children or to knowingly process children's personal data for child-directed experiences through the service.

Third-party platforms and customer responsibilities

Third-party platforms connected to BelvaOS remain governed by their own terms, policies, permissions, and technical controls. BelvaOS does not control the independent actions, outages, policy changes, or data accuracy of Google, Meta, MediaPal, IPSOS, spreadsheet providers, or other third-party services.

Customers and users are responsible for ensuring that their use of connected services through BelvaOS complies with the contracts, platform rules, disclosure obligations, and sector-specific laws that apply to them, including advertising, data protection, and marketing rules in the jurisdictions where they operate.

Changes to this policy and contact

We may update this policy from time to time to reflect product changes, legal requirements, or operational improvements. When required, we will provide updated notice through the service, through customer communications, or by updating the effective date on this page before materially new uses take effect.

Questions, requests, or concerns about this policy, data handling, or privacy rights can be sent to info@belvadigital.com.