Legal documents

Privacy policy

Last updated · 13 August 2026 · version 1.0

This policy explains how Thor Ads processes the personal data of those who visit the site and those who use the platform. It is written to be read: where the law requires a formula, the formula is there, but the meaning is explained first.

1. Data controller

The controller is KeplerByte S.r.l., with registered office at Via dei Marmorari, 94 41057 Spilamberto MO - Italy, VAT no. IT04140180367. For any question about your data you can write to privacy@heythor.ai.

2. Data we process

Contact and account data (name, email, company, encrypted credentials); billing data handled by the payment provider; platform usage data (technical logs, actions performed in the product); data imported from your advertising accounts and your sales systems.

3. Purposes and legal basis

Providing the service and managing the contract (Art. 6.1.b GDPR); tax and accounting obligations (Art. 6.1.c); security, abuse prevention and product improvement (Art. 6.1.f, legitimate interest); commercial communications and measurement cookies only with your consent (Art. 6.1.a), revocable at any time.

4. Data from advertising platforms

When you connect Google Ads, Meta or TikTok via OAuth, we receive the campaign data and aggregated metrics necessary for the service. We do not receive or process lists of end users or personal audiences. Access tokens are stored encrypted and can be revoked at any time.

5. Use of artificial intelligence

The AI features send model providers only the data needed for the individual request. The providers act as data processors and do not use this data to train models. No decision with legal effects is taken automatically: every action on your campaigns requires your approval.

6. Retention

Account and product data for the duration of the relationship and [period] after termination; tax documents for ten years, as required by Italian law; technical logs for [period]. When the account is closed, imported data is deleted or anonymized within [period].

7. Processors and transfers

We use hosting, payment, email and AI model providers, appointed as processors under Art. 28 GDPR. The up-to-date list is available on request. For transfers outside the European Economic Area we apply the European Commission's standard contractual clauses.

8. Security

Encryption in transit and at rest for platform credentials, data isolation per workspace, access logged and limited to staff who need it, periodic backups.

9. Your rights

You can request access, rectification, erasure, restriction, portability and objection by writing to privacy@heythor.ai. We reply within thirty days. If you believe the processing violates the GDPR you can lodge a complaint with the Garante per la protezione dei dati personali (the Italian data protection authority) or with your local supervisory authority.

10. Measurement and Tag Manager

The site uses Google Tag Manager to load Google Analytics 4. In aggregate they collect pages viewed, where visitors come from, and the steps of the purchase journey. They run only with your consent to the Statistics category: without it, Google receives anonymous signals with no cookies and no identifiers. The downstream controller is Google Ireland Limited; data may be transferred to the United States under standard contractual clauses and the Data Privacy Framework. When you start a purchase, the Analytics technical identifier is sent to Stripe along with the order, to attribute the conversion correctly.

11. Consent record

Every choice made on the cookie banner is recorded: a random identifier generated in your browser, the categories enabled, the policy version, the date, your IP address without its last part, and the browser used. The legal basis is the obligation to demonstrate consent (article 7.1 GDPR). The record is deleted after two years.

For any question about your data, write to privacy@heythor.ai.

Draft to be validated with legal counsel before publication · fields in square brackets must be filled in