Privacy policy
This policy explains how Datadeft Kft. handles personal data in connection with panzerotti.be, audit enquiries, public website audits, and related business communication.
1. Controller
Datadeft Kft. is the controller for personal data collected through this website, email enquiries, commercial communication, billing, and the delivery of the public website audit service unless a separate written data processing agreement says otherwise.
- Legal name
- Datadeft Kft. (Datadeft Korlátolt Felelősségű Társaság)
- Company registration number
- 07-09-032404
- VAT number
- HU29306862 (tax number 29306862-2-07)
- Registered office
- Barack dűlő 49, 2473 Vál, Hungary
- Contact
- hello@panzerotti.be
2. Data we process
We process only the data needed to operate the website, respond to enquiries, perform agreed audit work, and meet legal obligations.
- Website access data: IP address, user agent, requested URL, referrer, timestamp, and security logs generated by hosting infrastructure.
- Enquiry data: name, email address, company, message content, requested public URL, and any information you choose to send to us.
- Audit data: public URLs, publicly visible page content, metadata, headings, links, schema, performance readings, screenshots or snippets, tool output, and findings.
- Business data: proposal, contract, invoice, payment, tax, and account records where a client relationship is created.
- Connected Google Ads data: where a client connects a Google Ads account, read-only reporting data retrieved through the Google Ads API. This covers campaign, ad group, and account identifiers and names, and performance metrics such as spend, impressions, clicks, and conversions. See section 10.
The first audit is intended for public pages. Please do not send passwords, customer records, analytics exports, or other confidential datasets unless we have agreed the scope and safeguards in writing.
3. Purposes and legal bases
4. Cookies and local storage
The landing page does not use advertising cookies. The theme switcher stores a light or dark theme preference in your browser local storage. This preference stays on your device and is not sent to Panzerotti as a separate tracking identifier.
5. Sharing and processors
We do not sell personal data. We share data only where needed for the purposes above, including with:
- hosting and infrastructure providers, including AWS EMEA SARL for the public website infrastructure;
- email, business operations, accounting, and professional service providers;
- public authorities, courts, or advisers where required by law or necessary to protect legal rights.
Service providers may process data only for the purposes we instruct and must protect it with appropriate contractual and technical safeguards.
6. Retention
- Website logs are kept only as long as needed for security, troubleshooting, and operational records.
- Enquiry data is normally kept for up to 24 months after the last meaningful contact unless a client relationship starts.
- Audit reports and findings are normally kept for the term agreed with the client, then for a reasonable period for support, evidence, and legal record keeping.
- Accounting and tax records are kept for the period required by applicable law.
7. International transfers
We aim to use providers and infrastructure in the European Union or European Economic Area where practical. If personal data is transferred outside the EU or EEA, we use appropriate safeguards such as adequacy decisions, standard contractual clauses, and contractual security commitments.
8. Your rights
Subject to GDPR conditions and limitations, you may request access, rectification, erasure, restriction, portability, or objection to processing. Where processing is based on consent, you may withdraw consent at any time.
To exercise your rights, contact hello@panzerotti.be. You may also contact the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) if you believe your data protection rights have been infringed.
9. Security
We use technical and organisational measures appropriate to the nature of the data, including access control, encryption in transit, least-privilege access, and secure handling of audit materials. No internet service can guarantee absolute security, but we work to keep the data we handle limited and protected.
10. Connected advertising accounts (Google user data)
As part of our "Spend Lens" reporting feature, a client may connect their Google Ads account so we can show them their own advertising performance. This section explains how we handle Google user data and reflects our commitments under the Google API Services User Data Policy, including its Limited Use requirements.
- How access is granted. A client explicitly grants our reader identity read-only user access to their own Google Ads account. We never ask for or hold a client's Google password, and we cannot create, modify, delete, or manage campaigns, budgets, or any other entity. Our access is limited to reading reporting data.
- What we access. Only Google Ads reporting data needed to produce the client's own performance reporting: account, campaign, ad group, and ad or keyword identifiers and names, and metrics such as spend, impressions, clicks, and conversions, retrieved through read-only reporting queries.
- How we use it. Solely to display and analyse the connecting client's own advertising performance back to that client within Spend Lens. We do not use Google user data for advertising, and we do not use it to train generalised or standalone artificial-intelligence or machine-learning models.
- How we store it. Google Ads reporting data is stored as the connecting client's own private reporting projections in our access-controlled infrastructure, encrypted in transit, under least-privilege access. It is kept only as long as the client's connection is active or as needed to provide the service, and is removed on disconnection or request.
- Sharing. We do not sell Google user data and do not transfer it to third parties, except to the infrastructure providers that host the service on our behalf under appropriate safeguards, or where required by law. The data is shown only to the client who owns the connected account.
- Revoking access. A client can remove our read-only access at any time from within their Google Ads account, and can ask us to deregister their account and delete the associated stored reporting data. Removing access stops all further data retrieval.
Last updated: 23 August 2026