GDPR Compliance
Last updated: July 12, 2026 | Effective: July 12, 2026
1. Our GDPR Commitments
AdLuxy B.V. is committed to protecting your personal data in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). As a company registered in the Netherlands and operating across the European Economic Area (EEA), we treat data protection as a fundamental right. Our commitments include:
- Data minimisation -- We collect only the data that is strictly necessary for the purpose stated at the point of collection.
- Purpose limitation -- Personal data is processed only for the specific, explicit, and legitimate purposes for which it was collected.
- Transparency -- We clearly explain what data we collect, why, and how long we keep it.
- Security by design -- We implement appropriate technical and organisational measures to protect data at every stage of processing.
- Privacy by default -- Our systems are configured to process the minimum amount of personal data necessary.
- Accountability -- We maintain records of processing activities and conduct regular data protection impact assessments (DPIAs).
2. Data We Collect and Why
| Data Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email, company, phone | Account creation, communications, billing |
| Campaign data | Ad creatives, targeting zones, schedules | Campaign delivery and reporting |
| Ambassador data | Name, location, availability, earnings | Ambassador programme management, payments |
| Analytics data | Aggregate audience demographics, impression counts | Campaign performance reporting |
| Website usage | Pages visited, referral source, device type | Website improvement, marketing attribution |
| Payment data | Billing address, payment method (processed by Stripe) | Order fulfilment, invoicing |
3. Legal Basis for Processing
Under the GDPR, we must have a valid legal basis for each type of data processing. The legal bases we rely on are:
- Contract performance (Art. 6(1)(b)) -- Processing necessary to fulfil our contractual obligations to you, such as delivering campaigns, managing ambassador payouts, and processing orders.
- Consent (Art. 6(1)(a)) -- When you actively opt in to marketing emails, analytics cookies, or demo bookings. You can withdraw consent at any time.
- Legitimate interest (Art. 6(1)(f)) -- For website security, fraud prevention, basic analytics, and product improvement, where our interests do not override your rights.
- Legal obligation (Art. 6(1)(c)) -- Tax records, accounting data, and regulatory compliance requirements.
4. Data Retention Periods
| Data Type | Retention Period | Basis |
|---|---|---|
| Account data | Duration of account + 12 months | Contract / Legitimate interest |
| Campaign analytics | 24 months after campaign ends | Contract / Legitimate interest |
| Payment and invoicing data | 7 years (Dutch tax law) | Legal obligation |
| Marketing consent records | Duration of consent + 3 years | Legal obligation / Accountability |
| Website analytics | 26 months (Google Analytics default) | Consent |
| Computer vision data (on-device) | Not retained -- processed in real time on-device | N/A |
| Demo requests | 6 months | Consent |
5. Your Rights
Under the GDPR, you have the following rights with respect to your personal data:
Right of Access (Art. 15)
Request a copy of all personal data we hold about you. We will respond within 30 days.
Right to Rectification (Art. 16)
Request correction of inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Request deletion of your personal data when it is no longer needed or you withdraw consent.
Right to Data Portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON/CSV) and transfer it to another service.
Right to Restriction (Art. 18)
Request that we restrict processing of your data in certain circumstances while we resolve disputes.
Right to Object (Art. 21)
Object to processing based on legitimate interests, including profiling and direct marketing.
To exercise any of these rights, email us at [email protected] with the subject "GDPR Request". We will verify your identity and respond within 30 days.
6. Data Protection Officer
Our appointed Data Protection Officer (DPO) is responsible for overseeing compliance with this policy and the GDPR.
AdLuxy B.V.
Keizersgracht 520, 1017 EK Amsterdam, Netherlands
Email: [email protected]
Phone: +31 20 123 4567
7. Complaint Procedure
If you believe your data protection rights have been violated, you have the right to:
- Contact us first -- Email [email protected]. We aim to resolve all complaints within 30 days.
- Lodge a complaint with a supervisory authority -- If you are not satisfied with our response, you can file a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (AP): autoriteitpersoonsgegevens.nl.
- Seek judicial remedy -- You have the right to an effective judicial remedy if you consider that your rights under the GDPR have been infringed.
8. AI and Computer Vision Privacy
AdLuxy uses edge AI and computer vision on our advertising backpacks to detect audience demographics and count impressions. This section explains our privacy-first approach to these technologies.
8.1 On-Device Processing
All AI inference happens locally on the device (NVIDIA Jetson Orin Nano). Camera frames are processed in real time on-device and are never recorded, stored, or transmitted. No images or video leave the backpack hardware at any point.
8.2 No Personally Identifiable Information (PII)
Our AI models detect aggregate demographic categories (estimated age range, gender distribution) and count people. They do not perform facial recognition, identity matching, or any form of individual tracking. No biometric data is collected or stored. The output is purely statistical: "12 people passed, estimated 60% female, average age range 25-34."
8.3 Data That Reaches Our Servers
Only aggregated, anonymised statistics are transmitted from the backpack to our cloud servers. These statistics include impression counts, dwell time averages, demographic distributions, and GPS coordinates of the device. No raw imagery, facial data, or individual-level tracking data is transmitted.
8.4 DPIA for AI Processing
We have conducted a full Data Protection Impact Assessment (DPIA) for our AI processing pipeline, as required under GDPR Article 35 for high-risk processing. The DPIA confirms that our edge-processing approach minimises privacy risk to individuals.
9. International Data Transfers
AdLuxy primarily processes data within the EEA. Where data is transferred outside the EEA (for example, to AWS data centres), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection. We do not transfer personal data to countries without an adequacy decision unless appropriate safeguards are in place.
10. Changes to This Policy
We review and update this GDPR compliance page regularly. Material changes will be communicated through our website and, where applicable, by email to registered users. The "Last updated" date at the top of this page reflects the most recent revision.