Privacy Policy — Ajaska Google Ads API integration
Last updated: September 28, 2026
This privacy policy explains how Ajaska GmbH ("Ajaska", "we", "us") handles data when our internal application Ajaska accesses the Google Ads API. It applies to the application described at ajaska.de/google-ads-api. For our public websites, see our general Datenschutzerklärung (German).
1. Controller
Ajaska GmbH
Weißenseestraße 101
81539 Munich, Germany
E-mail: info@ajaska.de
Commercial register: Amtsgericht München, HRB 256435
Managing directors: Sören Zschoche, Julian Weber, Philipp Weber
2. Google user data we access
When an authorized Ajaska employee connects a Google account through Google's OAuth consent screen, Ajaska requests the Google Ads API scope (https://www.googleapis.com/auth/adwords). With this authorization, Ajaska accesses:
- Account information: Google Ads customer IDs, account names, currency and time zone of the Google Ads accounts the Ajaska group owns or manages.
- Campaign structure: names, IDs and status of campaigns, ad groups, ads and keywords.
- Performance metrics: impressions, clicks, cost, conversions, conversion value and related aggregated statistics.
- Keyword planning data: keyword ideas, historical search volume, competition and bid estimates, and forecasts.
- OAuth credentials: the access and refresh token issued by Google for the connected account.
Ajaska does not access Gmail, Google Drive, contacts, calendar or any other Google service. It does not read the name, e-mail address or other profile data of the connecting Google user beyond what the OAuth flow itself requires. Google Ads reports contain only aggregated advertising statistics. They contain no personal data about people who saw or clicked our ads.
3. How we use Google user data
We use the data exclusively for these internal purposes:
- importing performance reports into our internal reporting system, so we can measure cost, revenue, profit and ROI of our own advertising;
- researching and planning keywords and campaigns for our own websites and brands.
We do not use Google user data for advertising to the user. We do not use it for credit or lending decisions, and we do not use it for any purpose unrelated to the features above.
4. Sharing and disclosure
We do not sell, rent or trade Google user data. We do not transfer it to third parties, with these exceptions:
- hosting and infrastructure providers that process data on our behalf under a data processing agreement (Art. 28 GDPR) and only as needed to run the application;
- where required by applicable law or a binding order of a court or authority;
- in connection with a merger, acquisition or sale of assets, where the data stays subject to this policy.
Only employees of the Ajaska group who need the data for the purposes above can access it.
5. Limited Use disclosure
Ajaska's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use Google user data only to provide and improve the user-facing features described in this policy;
- we do not transfer Google user data to others except as described in section 4, as needed for security, or to comply with applicable law;
- we do not use or transfer Google user data for serving advertisements, including retargeting or personalized ads;
- we do not allow humans to read Google user data, except with the user's consent, for security purposes, to comply with applicable law, or where the data is aggregated and used for internal operations;
- we do not use Google user data to develop, improve or train generalized AI or machine-learning models.
6. Storage and security
We store Google Ads data and OAuth tokens on access-restricted servers. Data is sent only over encrypted connections (TLS), and OAuth tokens are stored encrypted. Only authorized staff can access the data, protected by individual accounts. We keep security measures in line with Art. 32 GDPR.
7. Retention and deletion
We keep imported reporting data as long as we need it for our internal reporting, accounting and statutory retention obligations. We delete OAuth tokens as soon as the Google account is disconnected or access is revoked. You can revoke Ajaska's access to your Google account at any time at myaccount.google.com/permissions. You can also ask us to delete data associated with your Google account by e-mailing info@ajaska.de. We will act on such requests within 30 days unless the law requires us to keep the data longer.
8. Legal basis
We process the data on the basis of our legitimate interest in measuring and planning our own advertising (Art. 6(1)(f) GDPR). Where the data concerns our employees, we also rely on Art. 6(1)(b) GDPR together with Section 26 BDSG.
9. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). You also have the right to lodge a complaint with a supervisory authority, for example the Bavarian State Office for Data Protection Supervision (BayLDA). To exercise your rights, contact info@ajaska.de.
10. Changes
We may update this privacy policy when the application or legal requirements change. The current version is always available at this address.
