Privacy Policy

What data Beksa processes, why, where it is stored, who receives it and how to control it — including the data you connect from advertising platforms.

Effective: 5 September 2026

1What this document covers

Beksa is a service for managing advertising campaigns and creatives across several advertising platforms from one interface (the website beksa.app and the application). The data controller is the sole proprietor “Beksa”, Republic of Kazakhstan (“we”).

This Policy describes how we process data of the service's users — employees of customer companies who register and work in Beksa. We do not receive data about people who see the ads (audiences): advertising platforms give us campaign settings and aggregated metrics only.

By registering you confirm that you have read this Policy. It applies together with the Terms of Service.

2Data we process

  • Account data: name, email address, password (stored only as an irreversible hash), email confirmation status, registration date.
  • Organization and workspace data: company name, products and markets, dimensions (cities, prices, languages and others), offers, naming rules, text templates, the list of members and their roles.
  • Advertising platform data that you connect: see section 3.
  • Creative files: videos and images you upload for publishing, and their technical properties.
  • Technical data: IP address, browser and device type, sign-in times, session identifiers, audit log entries (who changed what and when in the organization).
  • Support correspondence: emails and attachments.

3Advertising platform data

Beksa works with Meta (Facebook and Instagram), Google Ads, TikTok for Business, Apple Search Ads and Yandex Direct. We receive platform data only after an organization administrator explicitly connects an account: through the platform's authorization dialog (OAuth), a system-user token, or an API key created in the platform's interface.

  • What we receive: the list of accessible ad accounts and their details (name, identifier, currency, time zone); the structure of campaigns, ad groups and ads with their names, statuses, budgets and settings; creative identifiers and previews; aggregated performance metrics (spend, impressions, clicks, conversions).
  • Why: to show everything in one interface, check names against your rules, publish creatives and copy that you prepared and confirmed yourself, and monitor the health of the connection.
  • What we do not do: we do not sell this data, do not use it for our own advertising, do not build profiles of end users, do not share it with third parties other than the infrastructure sub-processors listed in section 6, and do not combine data of different customers.
  • Access tokens are stored encrypted (AES-256-GCM); the encryption key is kept separately from the database.
  • Disconnecting: when an ad account is disconnected or a connection is deleted, tokens are deleted immediately; mirrored campaign data is deleted within 30 days. You can also revoke access in the platform's own settings — the service will stop receiving data.

We comply with the platforms' API terms, including Meta Platform Terms and Developer Policies, the Google API Services User Data Policy (including the Limited Use requirements), TikTok for Business Developer Terms, Apple Search Ads API Terms and the Yandex Direct API terms. Use of information received from Google APIs is limited to features visible to the user in the Beksa interface.

4Purposes and legal bases

  • Performance of our contract with you: registration, access to the service, connecting accounts, publishing, support.
  • Legitimate interest: security of accounts and infrastructure, abuse prevention, keeping the audit log, improving the service based on aggregated, de-identified data.
  • Consent: connecting advertising platforms (withdrawn by disconnecting the account), optional notifications.
  • Legal obligations: retaining information required by the law of the Republic of Kazakhstan and responding to lawful requests of public authorities.

5Cookies and local storage

We use strictly necessary technologies only. There are no advertising, analytics or third-party cookies on beksa.app.

NamePurposeDuration
bk_session / __Host-bk_sessionSession cookie: confirms that you are signed in. HttpOnly, Secure.30 days, extended while active
beksa.themeA browser localStorage entry: your light or dark theme choice.Until cleared by the browser

Should analytics tools ever be introduced, they will run only with your explicit consent, and this Policy will be updated.

6Who receives the data

We do not sell personal data. Data is shared only to operate the service:

RecipientPurposeLocation
Vercel Inc.Hosting of the website and application, server-side code execution, storage of uploaded creative files (Vercel Blob)USA, EU
Neon Inc.PostgreSQL databaseUSA (us-east-1)
Resend Inc.Transactional email: address confirmation, password reset, invitationsUSA
Cloudflare Inc.DNS and inbound email routingGlobal
Advertising platformsReceive what you publish through the service — creatives, copy, names, settings — on your instructionsPer platform terms

Data is disclosed to public authorities only on the basis of a legally binding request. In case of a business reorganization, data may pass to a successor on the same terms.

7International transfers

Our sub-processors' servers are located in the USA and the EU, so data is transferred outside the Republic of Kazakhstan. Transfers comply with personal data legislation: they rest on agreements with sub-processors containing data protection obligations, and data is encrypted in transit and at rest.

8Retention periods

DataPeriod
Account, organization, workspacesWhile the account is active, then 30 days after deletion
Advertising platform dataWhile the account is connected, then 30 days; tokens are deleted immediately
Creative filesWhile the workspace exists or until you delete them
Audit log12 months
Technical security logs90 days
BackupsUp to 30 days
Support correspondence24 months

9How we protect data

  • Encryption in transit (TLS) and encryption of access tokens at rest (AES-256-GCM).
  • Passwords are stored as scrypt hashes; sessions are revocable and bound to a device.
  • Each organization's data is isolated; access is role-based; every change is written to the audit log.
  • Rate limiting, a strict Content Security Policy, protective HTTP headers, regular dependency audits.
  • More on the Security page.

10Your rights

You may request access to your data, its correction, deletion or restriction of processing, object to processing, receive a machine-readable copy and withdraw consent. Withdrawal does not affect the lawfulness of processing before it.

Send requests to support@beksa.app from the address linked to your account. We respond within 30 days and may ask you to verify your identity to protect the data. You may also lodge a complaint with the data protection authority of your country.

Deletion instructions are on the Data deletion page.

11Age

The service is intended for businesses and is not addressed to persons under 18. We do not knowingly collect children's data; if you become aware of such a registration, tell us and the account will be deleted.

12Changes to this Policy

We may update this Policy when the service or the law changes. We will notify you of material changes by email or in the application at least 14 days in advance. The current version is always available at beksa.app/en/privacy; the effective date is shown at the top.

13Contact

For data protection matters: support@beksa.app. The controller's legal details are below.

Legal details

Sole proprietor “Beksa”
Republic of Kazakhstan · registered 25 July 2026