Data and privacy

Privacy,
explained.

How Digital Strategy Solutions handles website enquiries, authorized advertising information and AI-assisted processing.

Updated 13 September 2026

Who we are and what this policy covers

This policy is provided by Digital Strategy Solutions Limited, Unit B, 66/1 Main street, Gibraltar, GX11 1AA. Contact hello@digitalstrategysolutions.ai about privacy or write to that address. It covers this website, direct business enquiries, the existing reporting workflow and the intended processing of the DSS Ads Operations application.

DSS determines how it handles its own enquiries and business administration. When processing advertising information on an account holder's behalf, the engagement and applicable data-processing arrangements determine the parties' responsibilities and instructions. A customer's separate notice may also apply to information originally collected from its users.

Application status

The direct Google Ads API integration is in development. No direct account connection or production execution is active through it. Existing authorized reporting and analysis use separate tools. Descriptions of future direct-API processing do not mean it is already taking place.

Website visits and correspondence

This is a static informational site. It has no visitor accounts, contact form, Google sign-in, advertising pixels or analytics scripts added by DSS. Visiting it does not grant access to an advertising account. We do not add cookies for marketing or audience tracking.

Vercel processes technical request information to deliver and protect the site, which can include an IP address, requested URL, browser information and diagnostic logs. Hosting-provider practices are described in Vercel's privacy policy. Statements about DSS-added tracking do not mean that the hosting service receives no technical data.

If you contact us, we receive the name, email address, business details, message content and attachments you provide. We use them to answer, discuss or provide services, and maintain relevant correspondence. Business email uses Google Workspace. Please avoid sending passwords, payment credentials or sensitive personal records in an initial enquiry.

Advertising information and its sources

For an authorized task, DSS may receive data through a reporting provider, a customer-supplied export, access arranged by an account holder, or—once connected—the Google Ads API. The scope depends on the task and the permissions actually granted.

  • Account context: identifiers, names, currency, time zone and relevant authorized account relationships.
  • Campaign configuration: campaigns, ad groups, advertisements, assets, keywords, destinations, targeting, budgets, bids, statuses and measurement settings.
  • Performance and history: impressions, clicks, spend, conversions, reported conversion value, relevant search terms, placements, conversion definitions and change history.
  • Work products: analyses, classifications, report extracts, draft plans, implementation instructions and records needed to explain or verify the work.

Some reports, search queries, URLs or supplied files may contain personal information. We limit the material used for the task and remove unnecessary identifiers where practical. Redaction and pseudonymous identifiers reduce exposure but do not guarantee anonymity.

The described Ads integration does not request access to Gmail content, Google Drive files or unrelated Google account activity. Customer-list matching and uploads of individual customer identifiers are not part of the present integration. Introducing such a function would require appropriate assessment, authority and updated disclosures first.

Purposes and the basis for processing

Advertising information is used to deliver the agreed reporting, analysis, planning, measurement review and, when available and authorized, campaign implementation. Relevant records also support reconciliation, troubleshooting, security and explaining what work was performed.

For our own correspondence and administration, processing may be necessary to respond to a requested service or perform a contract, to meet a legal obligation, or for legitimate interests such as communicating with business contacts and protecting our systems. Where legitimate interests apply, they must be considered alongside the individual's rights. Where consent is the appropriate basis, it must be obtained and can be withdrawn.

For data handled on a customer's instructions, the customer is responsible for the necessary authority and lawful collection, and DSS must act within the applicable engagement and data-processing instructions. Access granted in Google does not by itself authorize every use or every disclosure to another provider.

DSS does not sell advertising-account data or use it to build unrelated personal profiles. Our use and transfer of information received from Google APIs must adhere to the Google API Services User Data Policy, including the Limited Use requirements where applicable. Before accessing a new type of Google user data or using it in a way or for a purpose not previously disclosed, we update this policy, notify affected users and obtain their consent as required by Google's policy. Necessary account and engagement authority is a separate requirement.

Who can receive information

Authorized DSS operators and service providers may process the information needed for the relevant work. The provider overview identifies Google, Supermetrics, Neon, Vercel, OpenAI and Anthropic and explains their different roles. For example, the public host receives website requests; a private reporting host can process reporting outputs; an AI service may receive selected task material when authorized.

Client information is not published on this website or made available to unrelated clients. Reports are shared only under an appropriate authorization and access arrangement. Provider services may retain technical records or content under their applicable product terms; using a provider does not make those records public.

Information may also be disclosed where required by law or necessary for a legitimate security investigation or legal claim, subject to applicable requirements. Requests for unnecessary information must not become a reason to disclose an entire account dataset.

AI-assisted processing

DSS uses AI tools to assist with analysis, development, drafting and preparation of work. OpenAI and Anthropic provide relevant tools, including Codex and Claude. If a task includes authorized AI processing of account material, selected report extracts, search-query text, instructions, classifications or drafts may be sent to the relevant provider. This processing takes place outside the local DSS workspace.

We seek to minimize the material provided and exclude secrets such as passwords, tokens, cookies and private keys. Material is not necessarily anonymous because names or account identifiers have been removed. An AI output may be incorrect and needs appropriate verification before being used for a consequential action.

Training and retention depend on the product. DSS does not train its own general-purpose models on advertising data. This notice does not claim that every AI product or subscription used in our wider workflow has identical retention or training settings. Some authorized analytical processing has created provider-held files or job records; deletion of a local copy does not establish deletion by the provider.

For the developing direct Ads integration, any disclosure of Google account-derived material to an AI service is conditional on authorization for that processing and verification that the product's data-use settings and terms are compatible with applicable Google data-use restrictions and the authorized purpose. It must not be enabled where those conditions cannot be established. This website does not authorize general-purpose model training or additional AI disclosures. Ask DSS about the specific processing proposed for your engagement before it begins.

Storage, security and processing locations

Current reporting uses restricted local working storage, selected records in a private Neon database, and authenticated internal reports hosted separately on Vercel. Business correspondence is held in Google Workspace. Reporting and AI providers can also process or retain task-related information. The public website has no advertising-account credentials, raw report files or reporting-database connection.

Existing controls include restrictions on local files, separation of source and reporting access, account-scope checks, database access restrictions and authentication for internal reports. Credentials and raw working artifacts are excluded from public releases. Controls described for the direct execution service remain implementation requirements until that service is connected and verified.

DSS is based in Gibraltar. Cloud, reporting, email and AI services may process information in other countries, including the United States; we do not promise that all information stays in Gibraltar or any one region. The applicable provider arrangements and any required transfer safeguards need to cover the processing used for an engagement. Contact DSS for information about the arrangements applicable to your data.

How long information is retained

Retention depends on why the information is held, its sensitivity, the engagement and applicable legal obligations. There is no single deletion period for every kind of record.

Enquiries and business records
Kept while responding, managing the relationship and meeting relevant administrative, contractual or legal record-keeping needs.
Source reports and analysis
Kept where needed to deliver the work, compare historical periods, reconcile results and support an appropriate record of the engagement. Some historical reporting records remain after the reporting period ends.
Access and operational records
Access should end when no longer authorized. Relevant records may still be needed to investigate an issue or explain work already performed. Removing access is not automatic deletion of saved data.
Provider records
Files, job state, logs and backups may follow the provider's applicable retention and deletion arrangements. We do not promise immediate erasure from every provider or backup when a request is received.

At the end of an engagement, or on a valid request, DSS must assess return or deletion of information within its control against the remaining purposes and obligations. Information retained for a necessary exception should be limited to that purpose. When information is no longer needed for a justified purpose, we delete it from systems we control or return it as agreed, subject to any necessary retention exception. Provider-held copies follow the applicable provider deletion processes. A request can ask for the retention rationale and any outstanding deletion steps.

Access, correction and deletion requests

Contact hello@digitalstrategysolutions.ai, or write to the company address, to request information about your data or seek access, correction, return or deletion. Identify the relationship or record involved and the action requested, without including passwords or excessive identity documents. We may need proportionate information to verify identity or account authority.

Where data is held on another organization's instructions, we may refer the request to that organization or help it respond. Applicable law may also provide rights to restrict or object to processing, obtain portable data, withdraw consent, and complain to a supervisory authority. Rights and exceptions depend on the circumstances; withdrawing consent does not affect processing that was lawful before withdrawal.

We will handle requests within the period required by applicable law and explain relevant limitations. You may contact the Gibraltar Regulatory Authority, the data-protection supervisory authority in Gibraltar, or another competent authority where applicable.

Stopping account access

An authorized account administrator can remove the relevant Google Ads user, service-account access or manager link. The correct step depends on how access was granted; a generic Google connected-app setting may not remove a separate Ads permission or manager relationship. DSS can help identify the applicable routes.

Notify DSS when withdrawing or changing operating authority so future work can stop within that scope. Revocation does not reverse changes already accepted by Google, recover spent budget, delete Google's own records or automatically erase copies previously retained by DSS or a provider. Request deletion or return separately where needed.

Changes to this policy

We update this policy when services or data practices change and show the revision date at the top. Material changes affecting an engagement must be brought to the relevant parties' attention. Updating a web page alone is not a substitute for obtaining the user consent required by Google's policy or any separate account and engagement authority.

Descriptions here explain the service and intended integration. They do not create advertising-account access, change an engagement's scope or confirm Google verification. See the application page for current availability and the terms of use for the website's role.

Company contact

Digital Strategy Solutions Limited
Unit B
66/1 Main street
Gibraltar
GX11 1AA

Email: hello@digitalstrategysolutions.ai

Keep the conversation clear

Questions about DSS?

For service, application or data-handling enquiries, contact hello@digitalstrategysolutions.ai. You can also write to our company address below.