Privacy Policy

Last updated: 1 August 2026

1. Who We Are

Imroz Solutions and Services (imrozsolutions.com) is a white-label technical execution partner for marketing agencies. When you contact us or visit our website, we act as the data controller for the personal information you provide.

Contact: business@imrozsolutions.com

2. What Data We Collect

We collect only the minimum data needed to respond to your enquiry and improve our website:

We do not collect payment information, sensitive personal data, or data from children under 16 through this website. For data processed on behalf of clients, see Section 10.

3. How We Use Your Data

Purpose Legal Basis (GDPR Art. 6)
Responding to your enquiry Legitimate interest / pre-contractual steps (Art. 6(1)(b))
Website analytics & improvement Consent (Art. 6(1)(a))
Legal obligations Legal obligation (Art. 6(1)(c))

4. Data Sharing

We do not sell or rent your personal data. We may share it with:

5. Cookies

We use the following cookies:

Cookie Type Purpose Duration
imroz_cookie_consent Functional Stores your cookie consent choice 1 year
_ga, _ga_* Analytics (optional) Google Analytics — tracks page visits anonymously 2 years
csrftoken Strictly necessary CSRF security token for form submissions Session

You can withdraw analytics consent at any time using the cookie settings link in our footer.

6. Data Retention

Enquiry data (name, email, message) is retained for up to 2 years after last contact, then deleted. Analytics data is retained per Google Analytics defaults (14 months).

7. Your Rights (GDPR)

If you are located in the EEA, UK, or Switzerland, you have the right to:

To exercise any of these rights, email business@imrozsolutions.com. We will respond within 30 days.

8. International Transfers

Our application servers are hosted in India (AWS Asia Pacific — Mumbai region). Static files and media assets are stored in the United States (AWS US East region) and delivered through Amazon CloudFront's global content delivery network. Any transfer of personal data to third parties (e.g. Google Analytics) is covered by Standard Contractual Clauses or equivalent safeguards.

9. Changes to This Policy

We may update this policy occasionally. The "last updated" date at the top will always reflect the most recent version. Continued use of the site after changes constitutes acceptance.

10. Client Advertising & Marketing Platform Data

When we manage advertising or analytics accounts on behalf of a client, we access data from third-party marketing platforms — including Meta (Facebook, Instagram, WhatsApp), Google Ads, Google Analytics, and Google Search Console. This section explains how we handle that data.

Our Role

For this data we act as a data processor (service provider), not a data controller. The client owns the accounts and the data; we process it only on their documented instructions, for the purpose of managing and reporting on their campaigns. This differs from Section 1, where we are the controller for data you submit directly to us.

How We Get Access

We do not take ownership of client accounts. Clients grant us access through their own platform accounts — for example, partner access within their Meta Business Portfolio, or user-level access in Google Ads. Access is granted by the client and can be revoked by the client at any time, without our involvement.

What We Access

Data Purpose
Campaign, ad set and ad performance metrics Reporting, optimisation
Aggregated audience and demographic insights Targeting and analysis
Page, profile and account-level insights Organic and paid performance reporting
Ad creative, copy and campaign settings Campaign management
Lead form submissions (name, email, phone, form responses) Delivery to the client
Conversion and website analytics events Measurement and attribution

Lead Data

Where a client runs lead generation campaigns, we may access contact details submitted by people responding to those ads. This data belongs to the client. We transfer it to the client's designated system (CRM, email, or spreadsheet) and retain no working copy beyond 30 days. We never contact these individuals on our own behalf.

What We Do Not Do

Retention & Deletion

We retain client platform data only for the duration of the engagement. When an engagement ends, or a client revokes our access or requests deletion, we delete all locally stored copies, reports and exports within 30 days. Data that remains inside the client's own platform accounts is unaffected — it always belonged to them.

Security

Access credentials and API tokens are stored encrypted, are limited to authorised personnel, and are never shared outside our organisation. Access to client accounts is protected by two-factor authentication.

Platform Compliance

Our handling of this data complies with the Meta Platform Terms and Developer Policies, and with the Google Ads API and Google API Services User Data policies, including their limited-use requirements. Individuals whose data appears in a client's advertising account should contact that client, as the data controller, to exercise their rights. Enquiries sent to business@imrozsolutions.com will be forwarded to the relevant client.

11. Contact & Complaints

For any privacy-related queries, contact us at business@imrozsolutions.com.

If you believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection authority.