DocZone Ads Manager

DocZone Ads Manager

Privacy Policy

How DocZone Ads Manager handles Google Ads data, AI processing, and your privacy choices.

Last updated

01Operator and scope

This policy applies to DocZone Ads Manager and its public information website, ads.doczone.de. The operator is Sarina Ziayee, trading as Doczone, Friedrich-Lau-Str. 28, 40474 Düsseldorf, Germany. Privacy contact: legal@doczone.de. See our legal notice for full contact details.

Doczone is responsible for this website and agency contact administration. Client account data processed on a client's behalf is governed by that client's instructions and the applicable service and data-processing agreements. This policy does not replace a client's own privacy notice.

02Google user data we access

DocZone Ads Manager obtains data through the Google Ads API after an authorized operator grants Google OAuth access. It can access only Google Ads accounts available to that operator, including client accounts accessible through an authorized manager account. Depending on the requested task, it processes:

  • Account information: customer IDs and names, manager-account relationships, currency, and time zone.
  • Advertising configuration: campaigns, ads, assets, keywords, landing-page URLs, targeting, budgets, bidding, and conversion-action settings.
  • Reporting and research data: search terms, impressions, clicks, costs, conversion metrics, diagnostic information, and available keyword-planning data.
  • Authorization and working records: OAuth access and refresh tokens, task instructions, API errors, analysis, and records of account changes.

Search terms and account information can contain personal data. The application is not a patient record system. It does not request Gmail, Drive, Calendar, or Contacts permissions. Do not submit patient records or unnecessary personal information.

Google handles sign-in; the application does not receive your Google password. Its scope, https://www.googleapis.com/auth/adwords, permits both reads and account changes. Existing Google Ads permissions and the client's instructions determine permitted use; OAuth authorization is not a read-only permission. Visiting this public website does not grant access to your Google account.

03How we use Google user data

We use Google user data to provide the account-management functions requested by authorized agency operators for their clients:

  • Reporting: combine account and campaign identifiers with impressions, clicks, costs, and conversion metrics to explain campaign performance.
  • Campaign administration: inspect existing configuration, prepare instructed changes to campaigns, ads, keywords, targeting, budgets, or conversion settings, submit authorized changes to Google Ads, and check the results.
  • Keyword planning: review relevant keywords, search terms, search-demand estimates, and historical bid information when the API access level permits these requests.
  • Troubleshooting: use diagnostics, API errors, settings, and change records to investigate delivery, authorization, and conversion-reporting issues.
  • Maintain the connection: use OAuth tokens to authenticate authorized API requests and renew access without asking for a Google password.

Task-relevant information is also used for the AI assistance described below. We do not sell Google user data, use it for unrelated personal advertising profiles, or use it to train generalized AI models. Managing a client's advertising account is the requested service; it is not permission to reuse account data for unrelated purposes.

04AI assistance and recipients

Task-relevant Google Ads data, instructions, and analysis are processed by OpenAI in Doczone's AI-assisted workflow. This supports reporting and preparation of instructed account changes. Model training is disabled. Google user data is not used to train generalized AI models. OpenAI is the only AI provider used for this integration.

Google provides authentication and the Google Ads API. Authorized Doczone personnel and the relevant client can access records needed for the service. Data shared with service providers is limited to the authorized purpose and subject to the applicable contractual arrangements. We may disclose information where legally required or necessary to establish or defend legal claims.

Cloudflare hosts and protects this public information website. The website does not contain an Ads account connection or receive private Ads reports or OAuth tokens. Google user data is not sold, shared with other clients, or used for unrelated audience profiling.

05Where Google user data is stored

OAuth credentials and working records are stored in Doczone's private integration environment, separately from this public website. Reports or exports created for an authorized task can be retained in the agency's working records. Task inputs, selected Google Ads results, analysis, and conversation history can also be stored by OpenAI under the applicable service terms and settings.

This public website is hosted by Cloudflare and contains product information and legal notices. It does not store private Google Ads reports or OAuth tokens. Provider-held records and backups follow the applicable contractual retention and deletion procedures; we do not claim that all processing is limited to one country or that providers retain no data.

06How we protect Google user data

Access to the private integration environment and working records is restricted to authorized personnel. Google OAuth and existing Google Ads account permissions control which accounts the integration can access. Public pages and external API connections use HTTPS to protect information in transit.

Credentials are kept separate from this public information website. Our operating rules prohibit placing credentials in public code, AI prompts, or support messages. Operators must limit data in a task to what is needed for the authorized service and must not submit patient records. These controls reduce risk; they do not make an absolute guarantee against unauthorized access.

07Data retention and deletion

We retain Google user data only for as long as needed for the purposes described in this policy or to meet applicable legal obligations. Retention depends on the type of record:

  • OAuth credentials: retained while needed to maintain an authorized connection.
  • Reports, exports, instructions, and change records: retained as needed for the client engagement, handover, reconciliation, security, and applicable legal obligations.
  • AI task history and provider-held records: retention and deletion depend on the applicable provider service, contract, and workspace settings.

Agency-held records are deleted when their stated purposes and applicable retention obligations no longer require them. There is no single retention period for every record type. Local deletion or revoking Google access does not automatically erase provider history, backups, or previously exported records.

To request deletion, email legal@doczone.de with the subject DocZone Ads Manager data deletion. Identify the relevant Google Ads customer account and the records or connection concerned; do not send credentials or patient information. We may verify your authority before acting. Requests are handled across the relevant agency and provider systems, subject to applicable legal obligations and provider deletion procedures. Revocation is explained separately below.

08Website visits and contact

Cloudflare processes connection information needed to deliver and protect the site, such as IP address, requested URL, time, browser information, and security events. This is separate from the private Ads integration. See Cloudflare's privacy notice.

These pages contain no advertising pixels, Google Analytics, Google Tag Manager, marketing cookies, or third-party font embeds, and do not use browser storage to identify visitors. Any infrastructure security cookies are limited to their security purpose. If you email us, we use your address, message, and attachments to answer your request and retain necessary correspondence.

10Revocation, deletion, and rights

Remove DocZone Ads Manager in your Google Account connections to revoke its authorization. Client administrators can separately remove Doczone's Google Ads access. Revocation stops future access through that permission; it does not undo changes, pause campaigns, stop existing ad spend, or delete exported records.

For access, correction, deletion, restriction, portability, an objection, or withdrawal of consent, email legal@doczone.de. Include the account ID and your relationship to it, not credentials or patient information. We may verify your authority. Rights are subject to applicable legal conditions; withdrawing consent does not affect earlier lawful processing.

You may complain to a competent data-protection authority, including the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen. The application is not designed to make decisions about individuals with legal or similarly significant effects.

11Google data commitments and updates

DocZone Ads Manager's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements where applicable. Data is limited to the disclosed, authorized functions. Human access and onward transfers must be authorized or otherwise permitted by that policy.

Google user data is not sold or used for generalized AI training, unrelated advertising profiles, or creditworthiness decisions. We update this policy when processing changes and obtain any required authorization before materially new uses or sharing begin.

Privacy: legal@doczone.de
Application support: doczone.de@gmail.com