English
EN English
RO Romanian
Security

Your data, handled with care

We build ProtectAds as enterprise-grade software. Here are the technical and organisational measures we use to protect your data and your visitors’ data, in line with the GDPR.

Encryption in transit

All communications are encrypted with TLS/HTTPS between your browser and the platform.

Passwords stored hashed

Passwords are kept exclusively in encrypted/hashed form — never in plain text.

Need-to-know access

Access to data is controlled and strictly limited to those who need it.

Backups & monitoring

Periodic backups and continuous monitoring of our systems.

72-hour breach notification

In case of a risky breach, we notify the authority (ANSPDCP) within 72 hours, per GDPR.

Secure payments (Stripe)

Payments are processed by Stripe in line with PCI-DSS. We do not store your full card data.

Privacy

GDPR-aligned, by design

  • Processing under Regulation (EU) 2016/679 (GDPR)
  • We do not process special categories of data (art. 9 GDPR)
  • Targeted third-party IPs are deleted within 90 days of subscription end
  • Data Processing Agreement (DPA, art. 28 GDPR) included in our Terms
Read the Privacy Policy

Infrastructure & sub-processors

We work with trusted providers, under contracts that ensure GDPR compliance:

  • Hosting & cloud infrastructure (e.g. Amazon Web Services)
  • Payments: Stripe (PCI-DSS)
  • E-mail & communication: Brevo
  • Transfers outside the EEA only with adequate safeguards (Ch. V GDPR)

Frequently asked questions

Is my data secure?

Yes. Security is fundamental to how ProtectAds is built. All data is encrypted in transit (TLS) and at rest, hosted on enterprise-grade European infrastructure, and protected by strict access controls and monitoring.

Internally we follow the principle of least privilege, and we collect only the data we need to detect fraud — nothing more.

Are you GDPR compliant?

Yes. ProtectAds is built around GDPR best practices. We process only the minimum data required to identify invalid traffic, we're transparent about what we collect, and we never sell your data or your visitors' data.

IP and device signals are used solely for fraud detection, and our infrastructure is hosted within the EU.

Where is my data stored?

Your data is stored on secure, enterprise-grade servers located within the European Union.

Keeping data in the EU supports GDPR compliance and data-residency requirements, and our infrastructure is backed by a 99.9% uptime commitment so your protection is always on.

Do you share my data with third parties?

No. We never share or sell your advertising data, and we don't trade it for any purpose.

The only third parties involved are the infrastructure and payment providers strictly required to run the service — for example, our hosting provider and Stripe for payments — and each is used only for its specific, necessary function.

See all FAQs

Found a security issue?

Get in touch and we’ll look into it as quickly as possible, depending on complexity.