Privacy Policy
What data Beksa processes, why, where it is stored, who receives it and how to control it — including the data you connect from advertising platforms.
Effective: 5 September 2026
1What this document covers
Beksa is a service for managing advertising campaigns and creatives across several advertising platforms from one interface (the website beksa.app and the application). The data controller is the sole proprietor “Beksa”, Republic of Kazakhstan (“we”).
This Policy describes how we process data of the service's users — employees of customer companies who register and work in Beksa. We do not receive data about people who see the ads (audiences): advertising platforms give us campaign settings and aggregated metrics only.
By registering you confirm that you have read this Policy. It applies together with the Terms of Service.
2Data we process
- Account data: name, email address, password (stored only as an irreversible hash), email confirmation status, registration date.
- Organization and workspace data: company name, products and markets, dimensions (cities, prices, languages and others), offers, naming rules, text templates, the list of members and their roles.
- Advertising platform data that you connect: see section 3.
- Creative files: videos and images you upload for publishing, and their technical properties.
- Technical data: IP address, browser and device type, sign-in times, session identifiers, audit log entries (who changed what and when in the organization).
- Support correspondence: emails and attachments.
3Advertising platform data
Beksa works with Meta (Facebook and Instagram), Google Ads, TikTok for Business, Apple Search Ads and Yandex Direct. We receive platform data only after an organization administrator explicitly connects an account: through the platform's authorization dialog (OAuth), a system-user token, or an API key created in the platform's interface.
- What we receive: the list of accessible ad accounts and their details (name, identifier, currency, time zone); the structure of campaigns, ad groups and ads with their names, statuses, budgets and settings; creative identifiers and previews; aggregated performance metrics (spend, impressions, clicks, conversions).
- Why: to show everything in one interface, check names against your rules, publish creatives and copy that you prepared and confirmed yourself, and monitor the health of the connection.
- What we do not do: we do not sell this data, do not use it for our own advertising, do not build profiles of end users, do not share it with third parties other than the infrastructure sub-processors listed in section 6, and do not combine data of different customers.
- Access tokens are stored encrypted (AES-256-GCM); the encryption key is kept separately from the database.
- Disconnecting: when an ad account is disconnected or a connection is deleted, tokens are deleted immediately; mirrored campaign data is deleted within 30 days. You can also revoke access in the platform's own settings — the service will stop receiving data.
We comply with the platforms' API terms, including Meta Platform Terms and Developer Policies, the Google API Services User Data Policy (including the Limited Use requirements), TikTok for Business Developer Terms, Apple Search Ads API Terms and the Yandex Direct API terms. Use of information received from Google APIs is limited to features visible to the user in the Beksa interface.
4Purposes and legal bases
- Performance of our contract with you: registration, access to the service, connecting accounts, publishing, support.
- Legitimate interest: security of accounts and infrastructure, abuse prevention, keeping the audit log, improving the service based on aggregated, de-identified data.
- Consent: connecting advertising platforms (withdrawn by disconnecting the account), optional notifications.
- Legal obligations: retaining information required by the law of the Republic of Kazakhstan and responding to lawful requests of public authorities.
7International transfers
Our sub-processors' servers are located in the USA and the EU, so data is transferred outside the Republic of Kazakhstan. Transfers comply with personal data legislation: they rest on agreements with sub-processors containing data protection obligations, and data is encrypted in transit and at rest.
8Retention periods
| Data | Period |
|---|---|
| Account, organization, workspaces | While the account is active, then 30 days after deletion |
| Advertising platform data | While the account is connected, then 30 days; tokens are deleted immediately |
| Creative files | While the workspace exists or until you delete them |
| Audit log | 12 months |
| Technical security logs | 90 days |
| Backups | Up to 30 days |
| Support correspondence | 24 months |
9How we protect data
- Encryption in transit (TLS) and encryption of access tokens at rest (AES-256-GCM).
- Passwords are stored as scrypt hashes; sessions are revocable and bound to a device.
- Each organization's data is isolated; access is role-based; every change is written to the audit log.
- Rate limiting, a strict Content Security Policy, protective HTTP headers, regular dependency audits.
- More on the Security page.
10Your rights
You may request access to your data, its correction, deletion or restriction of processing, object to processing, receive a machine-readable copy and withdraw consent. Withdrawal does not affect the lawfulness of processing before it.
Send requests to support@beksa.app from the address linked to your account. We respond within 30 days and may ask you to verify your identity to protect the data. You may also lodge a complaint with the data protection authority of your country.
Deletion instructions are on the Data deletion page.
11Age
The service is intended for businesses and is not addressed to persons under 18. We do not knowingly collect children's data; if you become aware of such a registration, tell us and the account will be deleted.
12Changes to this Policy
We may update this Policy when the service or the law changes. We will notify you of material changes by email or in the application at least 14 days in advance. The current version is always available at beksa.app/en/privacy; the effective date is shown at the top.
13Contact
For data protection matters: support@beksa.app. The controller's legal details are below.