Privacy Policy
Last updated: July 12, 2026 | Effective: July 12, 2026
1. Introduction
AdLuxy B.V. ("AdLuxy," "we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, share, and protect information when you use our website (adluxy.com), our advertiser platform, our ambassador application, and our AI-powered advertising backpack technology.
AdLuxy B.V. is registered in the Netherlands (Chamber of Commerce number pending) with its principal office at Keizersgracht 520, 1017 EK Amsterdam, Netherlands. We act as the data controller for the personal data processed through our services.
This policy complies with the European General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Dutch Implementation Act (Uitvoeringswet AVG), the ePrivacy Directive, and applicable data protection laws in all jurisdictions where we operate, including the UK GDPR, UAE Federal Decree-Law No. 45 of 2021, and the California Consumer Privacy Act (CCPA).
2. Data We Collect
2.1 Website Visitors
When you visit adluxy.com, we may collect:
- Device and browser information (user agent, screen resolution, operating system)
- IP address (anonymized after collection)
- Pages visited, time spent, and referral source
- Cookie identifiers (with your consent; see Section 8)
2.2 Advertisers & Business Contacts
When you request a demo, create an account, or contact us:
- Name, email address, phone number, company name
- Billing information (processed by our PCI-compliant payment processor)
- Campaign data (creatives, targeting preferences, budgets)
- Communication records (emails, support tickets)
2.3 Ambassadors
When you apply to become an AdLuxy ambassador:
- Full name, date of birth, email, phone number, address
- Government-issued ID (for identity verification, stored securely and deleted after verification)
- Bank account or payment details (for compensation)
- GPS location data during active campaign shifts (with explicit consent)
- Shift schedules, earnings, and performance metrics
2.4 AI & Computer Vision Data (Public Audience)
This section describes how our backpack-mounted AI system processes visual data from the surrounding environment. This is central to our privacy-by-design approach.
Our Privacy Commitment for AI/Computer Vision
- 1.No facial recognition. Our AI does not identify individuals. We do not build, store, or use facial recognition databases.
- 2.On-device processing only. All computer vision processing happens on the NVIDIA Jetson module inside the backpack. Raw camera frames are never transmitted, uploaded, or stored beyond the device.
- 3.Aggregate data only. The AI produces only aggregate, anonymous statistics: estimated audience count, approximate demographic distribution (age range, gender), dwell time, and direction of gaze. These statistics cannot be used to identify any individual.
- 4.No images stored. Camera frames are processed in real-time and immediately discarded from memory. No photographs or video recordings of the public are retained.
- 5.No tracking. We do not track individuals across time or space. Each detection event is independent and anonymous.
The only data transmitted from the backpack to our servers is: timestamp, GPS coordinates of the backpack, aggregate audience count, aggregate demographic breakdown, and which creative was displayed. This data constitutes anonymous, aggregate statistics under GDPR and does not qualify as personal data.
3. Legal Basis for Processing
Under GDPR Article 6, we process personal data based on:
- Contract performance (Art. 6(1)(b)): Processing necessary to fulfill our contracts with advertisers and ambassadors.
- Legitimate interest (Art. 6(1)(f)): Website analytics, fraud prevention, and service improvement, balanced against your rights. Our AI processing of public spaces falls under legitimate interest as it produces only anonymous aggregate data.
- Consent (Art. 6(1)(a)): Marketing communications, non-essential cookies, and ambassador GPS tracking during shifts.
- Legal obligation (Art. 6(1)(c)): Tax records, anti-money laundering checks, and regulatory compliance.
4. How We Use Your Data
- To provide, operate, and improve our advertising platform and services
- To process payments and manage advertiser and ambassador accounts
- To send campaign reports, analytics, and performance data to advertisers
- To manage ambassador shifts, routes, and compensation
- To respond to your inquiries and provide customer support
- To send marketing communications (only with your consent)
- To detect and prevent fraud, abuse, and security incidents
- To comply with legal obligations and enforce our terms
- To conduct research and development for product improvement
5. Data Sharing & Third Parties
We do not sell your personal data. We share data only with:
- Cloud infrastructure providers (AWS, hosted in EU region eu-west-1) for data storage and processing
- Payment processors (Stripe) for secure payment handling
- Analytics tools (Google Analytics 4, with IP anonymization enabled) for website performance
- Advertisers receive only aggregate, anonymous campaign performance data — never individual-level data
- Legal authorities when required by law, court order, or to protect our rights
- Professional advisors (lawyers, auditors) bound by confidentiality obligations
All third-party processors are bound by Data Processing Agreements (DPAs) compliant with GDPR Article 28. We do not transfer personal data outside the EEA unless adequate safeguards are in place (Standard Contractual Clauses or adequacy decisions).
6. Data Retention
- Website analytics: 26 months (anonymized IP)
- Advertiser account data: Duration of contract + 7 years (legal obligation)
- Ambassador personal data: Duration of engagement + 5 years (employment law)
- Ambassador ID verification documents: Deleted within 30 days of verification
- Campaign performance data: 3 years (anonymized aggregate data)
- Contact form submissions: 12 months
- Camera frames: Not retained. Processed in real-time and immediately discarded on-device.
7. Your Rights Under GDPR
If you are in the EEA, UK, or a jurisdiction with equivalent privacy laws, you have the right to:
- Access your personal data and receive a copy (Art. 15)
- Rectify inaccurate or incomplete data (Art. 16)
- Erase your data ("right to be forgotten") in certain circumstances (Art. 17)
- Restrict processing in certain circumstances (Art. 18)
- Data portability — receive your data in a structured, machine-readable format (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent at any time, without affecting prior processing (Art. 7(3))
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority
To exercise any of these rights, contact our Data Protection Officer at [email protected]. We will respond within 30 days as required by GDPR.
8. Cookies & Tracking
Our website uses cookies. Upon your first visit, you will see a cookie consent banner allowing you to accept or reject non-essential cookies. Essential cookies required for website functionality are set without consent, as permitted under the ePrivacy Directive.
- Essential cookies: Session management, security, preferences (no consent required)
- Analytics cookies: Google Analytics 4 with IP anonymization (consent required)
- Marketing cookies: For measuring campaign effectiveness (consent required)
You can change your cookie preferences at any time through the cookie settings link in our website footer, or by clearing cookies in your browser settings.
9. Data Security
We implement industry-standard technical and organizational measures to protect your data, including:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Multi-factor authentication for platform access
- Regular security audits and penetration testing
- Role-based access controls with least-privilege principle
- Encrypted backpack-to-cloud communication channels
- On-device AI processing to minimize data exposure
- Automated vulnerability scanning and patch management
10. Children's Privacy
Our services are not directed at children under 16. We do not knowingly collect personal data from children. If we discover that we have inadvertently collected data from a child under 16, we will delete it promptly. Our AI audience detection does not specifically target or identify children — it produces only aggregate anonymous counts.
11. International Transfers
AdLuxy primarily stores and processes data within the European Economic Area (EEA), using AWS eu-west-1 (Ireland). Where data is transferred outside the EEA (for example, to service providers in the US or UAE), we ensure appropriate safeguards through Standard Contractual Clauses (SCCs) approved by the European Commission, or rely on adequacy decisions where available.
12. California Residents (CCPA)
If you are a California resident, you have additional rights under the CCPA, including the right to know what personal data we collect, the right to delete your data, and the right to opt out of the sale of personal data. We do not sell personal data. To exercise your CCPA rights, contact [email protected].
13. Data Protection Officer
Our Data Protection Officer can be reached at:
Data Protection Officer
AdLuxy B.V.
Keizersgracht 520, 1017 EK Amsterdam, Netherlands
Email: [email protected]
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users and through a prominent notice on our website at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
15. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
- Email: [email protected]
- General: [email protected]
- Address: Keizersgracht 520, 1017 EK Amsterdam, Netherlands
- Supervisory Authority: Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl