Privacy Policy
1. Who we are
Skaitmenos grupė MB ("Supercom", "we", "us") is a marketing agency registered in Lithuania under company number 304330781, with its registered office at Latvių st. 58.
For questions about this policy or to exercise your rights, contact us at info@supercom.io. We have not appointed a Data Protection Officer, as we are not required to under Art. 37 GDPR; you can raise any data-protection matter using that address. As we are established within the European Union, we are not required to appoint a representative under Art. 27 GDPR.
2. Scope
This policy covers:
- supercom.io — our public website.
- tools.supercom.io — the Supercom Ads Tool, an internal application used by our staff to analyse publicly available competitor advertising and to upload advertising creatives into ad accounts our clients have authorised us to manage. The tool is not open to the public and has no self-registration.
3. Our role under the GDPR
We act in two distinct roles, and your rights differ depending on which applies:
- Controller — for data about visitors to supercom.io, people who contact us, and the Supercom staff accounts that can sign in to the Ads Tool. We decide why and how this data is processed.
- Processor — for personal data contained in our clients' advertising accounts, which we access and process only on the documented instructions of the client who controls that account. Where we act as a processor, the client is the controller and their own privacy policy governs the processing. Our processing is governed by a data processing agreement with each client.
4. What we process, and why
4.1 Website visitors (we are controller)
supercom.io is a marketing website. We do not run analytics, advertising pixels, or tracking cookies on it, and we do not build profiles of visitors. We do not set any cookies that require consent.
The site loads a small number of third-party resources that are necessary to display it and to let you book a call. When your browser requests these resources, the provider receives technical connection data — principally your IP address, browser type, and the time of the request — which it may process to deliver the content and to keep its service secure:
- Google Fonts (Google LLC) — web fonts.
- Content delivery networks (jQuery / jsDelivr) — JavaScript libraries used to run the page.
- Cal.com — the "Book a call" scheduling widget. If you choose to book a call, the name, email address, and any message you enter are processed by Cal.com and sent to us so we can arrange the meeting.
Purpose: to display the website, deliver its content securely, and let you contact us. Legal basis: legitimate interest (Art. 6(1)(f)) in operating and securing our website; for booking a call, the taking of steps at your request prior to entering into a business relationship (Art. 6(1)(b)). Retention: enquiry and booking details are kept for up to 24 months after our last contact with you, unless a client relationship forms, in which case they are kept for the duration of that relationship.
4.2 Ads Tool user accounts (we are controller)
For each member of Supercom staff authorised to use the tool we store: email address, a cryptographically hashed password (scrypt — we never store passwords in readable form), an access role, and a session timestamp. We log failed sign-in attempts, including timestamp and originating IP address, to detect and block brute-force attacks.
Purpose: access control and security. Legal basis: legitimate interest (Art. 6(1)(f)) in securing a system that can write to client advertising accounts. Retention: account data is kept for as long as the person is authorised to use the tool and deleted within 90 days of their authorisation ending; security logs of failed sign-in attempts are kept for 12 months.
4.3 Competitor advertising data (we are controller)
The tool collects advertising that is already public from the Meta Ad Library and equivalent public sources: ad creative, ad copy, run dates, delivery countries, and the public landing pages those ads point to. It also captures screenshots of public landing pages to detect changes.
This data concerns businesses, not consumers. It may incidentally contain personal data where an advertisement features an identifiable individual (for example a founder or a spokesperson appearing in a creative).
Purpose: competitive analysis for our clients. Legal basis: legitimate interest (Art. 6(1)(f)) in analysing publicly published commercial communications. Retention: kept for as long as it supports an active client engagement and deleted or anonymised within 12 months after that engagement ends.
4.4 Client advertising accounts (we are processor)
When a client authorises us, the tool accesses their advertising accounts on Meta and TikTok to read campaign structures and to create advertisements. We do not access, export, or process customer lists, custom audiences, or any end-user personal data held in those accounts.
Access is granted by the client through the platform's own authorisation flow and can be revoked by the client at any time, directly on the platform, without involving us.
4.5 Advertising creatives
Creative files (video and image) are streamed from the client's storage through our server to the advertising platform in memory only. They are not written to disk, not stored on our hosting provider, and not stored in our database. Once the upload to the platform completes, no copy remains in our systems.
5. Advertising platform data — TikTok and Meta
Where we connect to the TikTok Marketing API or the Meta Marketing API on behalf of a client:
- We request only the minimum permissions needed to list advertising accounts and campaigns, upload creative assets, and create advertisements.
- Every advertisement we create is created in a paused state and does not deliver until a human explicitly activates it in the platform's own advertising manager. Our software contains no capability to enable, unpause, or edit an existing advertisement.
- Access tokens are stored encrypted at rest, are accessible only to our server, and are never exposed to a web browser.
- We do not sell, rent, or share platform data with any third party, and we do not use it for any purpose other than delivering the service to the client whose account it came from.
- We do not use platform data to build user profiles, to train machine learning models, or for any form of advertising targeting outside the client's own account.
- When a client revokes our access, or when our relationship with a client ends, the stored tokens for that account are deleted.
Our use of information received from TikTok and Meta adheres to their respective developer and platform terms, including their limited-use requirements.
6. Who we share data with
We use the following service providers ("sub-processors"). Each is bound by contract to process data only on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting | European Union (Frankfurt) |
| Supabase | Database (competitor data, user accounts, access tokens) | European Union (Frankfurt) |
| Google LLC | Google Drive / Sheets — reading creative files and campaign plans | European Union / USA |
| Anthropic PBC | AI analysis of public competitor advertising copy to generate written briefs | USA |
| Slack Technologies | Internal notifications to our team | European Union / USA |
| Meta Platforms | Advertising delivery and public ad library data | European Union / USA |
| TikTok / ByteDance | Advertising delivery | European Union / USA |
We do not sell personal data. We disclose data to authorities only where legally required.
Note on AI processing: the text of public competitor advertisements is sent to Anthropic's API to generate analytical briefs. Client account data, creative files, and personal data are not sent.
7. International transfers
Our application hosting and database are located in the European Union (Frankfurt). Some of the other providers above are established in the United States and may process data there. Where personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–U.S. Data Privacy Framework, together with any additional safeguards those transfers require. You may request a copy of the relevant safeguards at info@supercom.io.
8. Security
We apply, among other measures: encrypted transport (HTTPS) throughout; hashed passwords; signed, expiring session cookies with server-side revocation; rate limiting and lockout on repeated failed sign-in attempts; role-based access control so that analytical users cannot reach advertising upload functions; protections against server-side request forgery on any address our system fetches; and a strict content security policy. Access to production systems is limited to named administrators.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by Art. 33–34 GDPR.
9. Your rights
Under the GDPR you have the right to access your personal data, to rectify it, to erase it, to restrict or object to its processing, to data portability, and to withdraw consent where processing is based on consent. Where we process data as a processor on a client's behalf, please direct your request to that client; if you send it to us, we will forward it to them.
Requests to info@supercom.io. We respond within one month. You also have the right to lodge a complaint with your local supervisory authority — in Lithuania, the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt.
10. Retention
We keep personal data only as long as necessary for the purposes described above. The periods for each category are:
| Category | Retention period |
|---|---|
| Website enquiries and call bookings | Up to 24 months after our last contact with you, unless a client relationship forms. |
| Ads Tool staff account data | For as long as the person is authorised; deleted within 90 days of their authorisation ending. |
| Security logs (failed sign-in attempts) | 12 months. |
| Competitor advertising data | For the duration of the client engagement it supports; deleted or anonymised within 12 months after that engagement ends. |
| Client platform access tokens | Deleted when the client revokes access or the relationship ends. |
| Advertising creatives | Not retained — processed in memory only during upload (see section 4.5). |
Where we are required to keep certain records for longer to meet a legal obligation (for example accounting or tax records), we retain those for the period the law requires.
11. Children
Our services are directed at businesses. We do not knowingly process the personal data of children.
12. Changes
We may update this policy. The current version is always published on this page, and the date at the top reflects when it last changed. Where a change is material and we hold your contact details, we will also notify you by email.
13. Contact
Skaitmenos grupė MB
Latvių st. 58
info@supercom.io