Privacy policy
Last updated 10 August 2026
Randstad connects your Google Ads accounts, reports on them, and uses the search terms that converted there to decide what to work on for SEO. This page describes what the product stores about you, why it stores it, where that data goes, and what you can ask us to do about it.
Who is responsible for your data
The operator of Randstad is the controller of the personal data described here. Questions about anything on this page go to support@randstad-ads.com, which is read by a person.
We have not appointed a data protection officer. If that changes, this section will name one.
What we collect
Five categories, listed in full. We buy no data about you from anyone.
Account data
Your name, your email address, a hash of your password rather than the password itself, your timezone and your locale. You give us these when you sign up, and you can change all of them in settings.
Workspace data
What you create inside a workspace: workspace and project names, members and invitations, report definitions and schedules, SEO projects, content briefs and drafts, and the settings attached to them.
Google Ads data
Campaigns, ad groups, keywords, search terms, conversions and their metrics, read through the official Google Ads API for the accounts you connect and stored in the EU. We scrape no page, and we never ask for your Google password.
Usage and audit records
Sign-in history, including IP address and user agent, and an audit record of who did what in a workspace and when. The audit record is append-only: the database refuses to change or delete a row once it has been written.
Email delivery records
Which message went to which address, when it was sent, and what the email provider said in reply. This is how we can tell you whether a scheduled report reached your client.
Your Google credentials
Connecting a Google Ads account gives us an OAuth refresh token. It is stored envelope-encrypted: the token is encrypted with a key of its own, and that key is encrypted with a master key held outside the database. The token is never displayed anywhere in the product.
The token is used for one thing: reading and writing the Google Ads data covered by the scope you granted. It reaches nothing else in your Google account.
Disconnect a Google account in the product and we revoke our access with Google and delete the stored token. You can also revoke it from your Google account's own permissions page, and the connection stops working straight away.
Why we process each category, and on what legal basis
Under Article 6 of the GDPR, four bases cover everything on this page.
Performing our contract with you
Account data, workspace data and Google Ads data are processed because the product cannot run without them. Without your Google Ads data there is no report to send and no converting search terms to research from.
Legitimate interests
Sign-in history, audit records and email delivery records let us investigate a security incident, answer who changed a setting, and tell you whether a report was delivered. What we keep is limited to what those questions need.
Consent
Email that is not about running your account, such as product announcements, is sent only if you opt in. You can withdraw that at any time and it does not affect your access to the product.
Legal obligation
Billing and tax records are kept because tax law requires them. Our payment provider is the merchant of record and holds the originals; what we store is a mirror.
Where your data is processed
Everything the product stores is held in a single EU region. Tenant isolation is enforced by the database through row-level security rather than by application code alone, so one workspace's rows are not reachable from another workspace's queries.
AI features are the exception
When you use keyword analysis, content briefs and drafts, anomaly explanations or the assistant, the text involved is sent to Anthropic and processed outside the EU. Anthropic offers no EU processing region, so this is not a setting we can change. This page makes no claim about how long Anthropic keeps a request. When that is settled, it will be stated here.
What goes to Anthropic is advertising data and text you wrote: keyword terms and the search volumes Google's API returned for them, campaign names, the evidence behind an anomaly, brief outlines, page content, and your conversation turns with the assistant. The product has no field that asks for your own customers' personal data, but a brief or an assistant message carries whatever you type into it, so do not put it there.
Paddle is the merchant of record. Card details are entered on Paddle's own checkout and never reach us: we store no card number, no expiry date and no security code at any point. Paddle holds the payment method and issues the invoice. What we keep is the subscription's state and the invoice metadata Paddle sends back to us.
Sub-processors
We do not publish a sub-processor register yet. Until we do, the four below are the complete set.
The hosting provider that runs our servers and database in the EU region.
Anthropic, for the AI features described above.
Paddle, as merchant of record, once checkout opens.
The outbound email provider that delivers scheduled reports, invitations and account email.
Adding one is a change to this page, not a quiet swap.
How long we keep things
The retention page lists every window: what is kept, for how long, and whether it is deleted outright or simply stops working. Those figures are generated from the same constants the deletion sweeps read, so the page cannot say one thing while the sweeps do another. We link to it instead of repeating the numbers here, because a second copy would eventually disagree with the first.
Read the retention page
Two things that page does not cover. The first is audit records. They are append-only, the database refuses both an update and a delete on them, and they outlive the account that created them. A record of who changed what is worth little if the person who did it can remove it.
The second is backups. We keep thirty nightly copies, so a row you delete can survive in a backup for up to 30 days, until the copy holding it is pruned. Backups are restored only in full, only in a disaster, and are never used to retrieve one record. That 30-day window is the honest bound on any deletion we promise.
Your rights under the GDPR
The GDPR gives you the following. None of them cost anything to use.
Access
Ask what we hold about you and receive a copy of it.
Rectification
Have anything wrong corrected. Your name, email, timezone and locale you can already change yourself in settings.
Erasure
Ask us to delete your personal data. Two limits apply, and they are stated here instead of raised after you ask. Audit records stay, for the reason given above. Invoices held by our payment provider are kept for as long as tax law requires.
Restriction
Ask us to stop processing your data while a dispute about it is being settled.
Portability
Receive the data you gave us in a machine-readable format. Report data is already exportable as CSV and XLSX from inside the product.
Objection
Object to processing we base on legitimate interests. We will stop unless we can show grounds that override yours.
Complaint to a supervisory authority
Complain to the data protection authority in your country. You do not have to come to us first, though we would rather have the chance to fix the problem.
Email support@randstad-ads.com to exercise any of these. We will confirm that we received the request, may ask for enough information to be sure it is really yours, and will answer within one month, as Article 12 requires. There is no self-service button for this yet. A person handles each request.
Cookies
Two cookies, both needed for the product to work. One, adsight_session, keeps you signed in. The other, adsight_csrf, carries a CSRF token, so that a form submitted from another site cannot act as you.
There is no advertising cookie, no third-party analytics cookie, and nothing that follows you to another site. That is also why no consent banner appears: there is nothing here for consent to apply to.
Changes to this policy
When this policy changes we update this page and change the date at the top. For a change that materially affects how we handle your data, we email workspace owners before it takes effect rather than relying on you to notice.
We do not publish an archive of earlier versions yet. That is a gap, and it is named here.
If anything on this page is unclear or does not match what the product does, that is a bug in the page. Tell us at support@randstad-ads.com.