The parties
Where AdMindra processes personal data on a customer's behalf, the customer is the controller and 3on Reklambyrå & Webbyrå AB, org.nr 556825-0566, is the processor. This page describes that processing. The data processing agreement is 3on's own, Personuppgiftsbiträdesavtal (in Swedish), under 3on's general terms; where the two differ, the agreement decides. A signed copy is available on request from support@admindra.com.
What we process, and why
- Campaign material — ad text, images, landing page content. To create and publish advertising the customer approves.
- Tracking events from the customer's website or store. To measure what advertising produced.
- Advertising data from connected Meta and Google accounts. To report results and suggest changes.
- Influencer applications submitted through campaign pages. To let the customer review and answer applicants.
- Proposals — the proposal, the buyer's name, email address and phone number, their comments, and how they accepted it: a typed or drawn signature, an email code, or BankID, which confirms their name and personal identity number. To let the customer send a proposal and the buyer accept it, and to keep a sealed copy of what was accepted.
Processing lasts for the duration of the agreement. When it ends, the customer chooses within 30 days whether their data is returned or deleted; without a choice it may be deleted then, and it is deleted within 90 days at the latest, unless the law requires it to be kept.
Categories of subprocessor
- Hosting and database (EU region where available).
- AI providers, for generating ad text, images and analyses.
- Advertising platforms the customer has connected.
- Email delivery, for transactional messages.
- SMS delivery, for text messages the customer sends, such as proposal links and reminders.
- Electronic signing with BankID, for proposals a buyer signs with BankID.
The current list of named subprocessors, with where each one processes data, is at 3on.se/avtal/underbitraden. A new or replaced subprocessor is added to that list at least 10 days before it is used, unless security or operations require a faster change. To be told by email, write to info@3on.se.
Security
- Access tokens are stored server-side and are never exposed to the browser.
- Access to customer data is scoped per workspace and checked on every request.
- Actions taken on a customer's platforms are written to an audit log.
Deletion
See Delete your data for how to remove a Meta connection and everything attached to it, automatically or by asking us.