Privacy Policy
Last updated: 14 July 2026
This Privacy Policy describes how Humans Systems (operating as "Humans Systems", "we", "us") collects, uses, stores, and protects personal data when you visit humanssystems.com, when you engage our services, and when we access data on your behalf from connected marketing platforms such as Meta (Facebook and Instagram), Google, TikTok, and LinkedIn.
The data controller for this policy is Julien Delbauve, operating under Humans Systems. Contact: julien@humanssystems.com.
1. Scope
This policy applies to:
- Visitors of humanssystems.com.
- Clients who engage Humans Systems for services.
- Data accessed by Humans Systems from third-party platforms (Meta, Google, TikTok, LinkedIn, analytics providers, CRMs, and similar) on behalf of clients who have authorized that access.
2. Information We Collect
2.1. From visitors of humanssystems.com
- Server logs containing IP address, browser user agent, request timestamp, and requested URL. Retained for 30 days for security and abuse prevention.
- A theme preference stored in your browser's localStorage (light or dark). This never leaves your device.
- No third-party analytics or tracking cookies are installed on this site.
2.2. From clients and prospects
- Identification and contact data: name, business email, company, role.
- Communication content: emails, meeting notes, briefs you share with us.
- Billing data processed by Stripe: name, billing address, VAT number, payment method metadata. Humans Systems does not store raw card data.
2.3. From connected marketing platforms
When you authorize Humans Systems to connect to your marketing platform accounts (Meta, Google Ads, TikTok Ads, LinkedIn Ads, analytics, CRMs), we access only the data scopes you grant. The specific data accessed depends on the services contracted with you. See Section 3 for the Meta-specific disclosure.
3. Meta Platform Data
This section describes how Humans Systems handles data accessed from Meta Platforms (Facebook, Instagram, WhatsApp Business, and related properties owned by Meta Platforms, Inc.) via the Meta Marketing API, Graph API, and Conversions API.
3.1. What Meta data we access
With the explicit authorization of the Meta Business or Ad Account owner, Humans Systems may access the following data categories through Meta's APIs:
- Ad account metadata: account name, account ID, currency, time zone, business association.
- Campaign, ad set, and ad configuration data: names, objectives, budgets, targeting parameters, bid settings, creative references, schedule.
- Performance and insights data: impressions, reach, frequency, clicks, CTR, CPM, CPC, conversions, conversion value, video metrics, attribution data, breakdowns by placement, device, age and gender (in aggregate form only).
- Pixel and Conversions API event metadata: event names, event counts, deduplication status. Humans Systems does not access personally identifiable user-level event payloads unless a client has explicitly contracted us to operate their server-side tagging.
- Page assets associated with the Business Account: page name, page ID, post insights in aggregate form, posted creatives.
- Business asset relationships: business users, agency partnerships, asset groups, permissions.
3.2. Permissions we request
Depending on the contracted services, Humans Systems may request the following Meta permissions: ads_read, ads_management, business_management, pages_read_engagement, pages_show_list, read_insights, and catalog_management. We never request scopes broader than what is required to deliver the contracted services.
3.3. Why we access Meta data
Humans Systems accesses Meta Platform Data solely to deliver services contracted by the account owner. These services include: automated campaign creation and bulk ad uploading, account audits and health checks, performance reporting, creative fatigue detection, budget pacing analysis, and scheduled optimization tasks. Meta Platform Data is processed in the context of the specific engagement only and is never used to train machine learning models or for any other purpose outside the contracted scope.
3.4. How Meta data is stored
- Real-time queries: most data is processed transiently in response to a client request (a prompt, a scheduled task, a report build) and is not persisted beyond the response.
- Historical reporting: when a client requests time-series reporting, aggregated performance metrics may be stored in a dedicated client data warehouse (Google BigQuery) under the client's own Google Cloud project or, when explicitly agreed, under a Humans Systems project on behalf of the client.
- Authentication tokens: access tokens are stored encrypted at rest with industry-standard encryption and are scoped to the specific Business Account that issued them.
- No raw user-level personal data from Meta (such as user names, profile pictures, or contact info of audience members) is collected or stored unless contractually required and explicitly disclosed to the client.
3.5. Retention of Meta data
- Transient query data: not retained.
- Aggregated performance metrics in a client data warehouse: retained for the duration of the engagement, then deleted within 30 days of contract termination unless the client requests retention for legal or historical purposes.
- Authentication tokens: revoked and deleted within 30 days of the end of the engagement, or sooner upon client request.
- Backups: any incidental backups are purged within an additional 30 days.
3.6. Sharing of Meta data
Humans Systems does not sell Meta Platform Data. We do not share it with advertising networks, data brokers, or any third party for monetization purposes. Meta Platform Data is shared only with the sub-processors listed in Section 6 and only to the extent strictly necessary to deliver the contracted services. Meta Platform Data is never combined with data from a different client's account.
3.7. Compliance with Meta's Platform Terms
Humans Systems processes Meta Platform Data in accordance with the Meta Platform Terms, the Developer Policies, and any applicable Meta Business Tools Terms. Our use of Meta Platform Data is limited to the purposes disclosed in this policy and agreed with the account owner.
3.8. How to revoke Humans Systems' access to your Meta data
You may revoke our access at any time by:
- Removing Humans Systems from your Meta Business Manager: Business Settings → Users → Partners (or Business Settings → Apps), then remove the Humans Systems app.
- Removing the Humans Systems integration from your personal Facebook account: Settings → Business Integrations.
- Writing to julien@humanssystems.comwith the subject line "Meta data access revocation". We will confirm revocation and delete all stored Meta Platform Data associated with your account within 30 days.
4. How We Use Personal Data
- To deliver the services you have contracted us to perform.
- To communicate with you about the engagement, scoping, or support.
- To process billing and invoicing through Stripe.
- To secure our infrastructure and prevent abuse.
- To comply with legal obligations, including tax and accounting record-keeping under Spanish and EU law.
We do not use personal data for advertising, profiling, automated decision-making with legal effect, or training machine learning models.
5. Legal Basis (GDPR)
For visitors and clients in the European Economic Area, our legal bases for processing personal data are: (a) performance of a contract, when you engage our services; (b) legitimate interest, for security, abuse prevention, and direct B2B communication; (c) legal obligation, for tax and accounting; (d) consent, where you have explicitly granted permission for a specific purpose, such as authorizing access to a Meta Business Account.
6. Sub-processors
Humans Systems uses the following sub-processors to deliver services. Each is bound by a data processing agreement or equivalent contractual safeguards. We share only the data strictly required for the listed purpose.
- Vercel — website hosting and serverless compute for humanssystems.com.
- Stripe — payment processing for client invoicing.
- Brevo — transactional email delivery (magic links, receipts, service communications).
- Google Cloud Platform — data warehousing (BigQuery), object storage, and scheduled execution for client reporting workloads.
- Supabase — application database and encrypted secrets vault (storage of platform access tokens).
- Markifact — workflow execution platform used to operate marketing automations for clients who have chosen Markifact-based delivery.
- Anthropic and OpenAI — AI inference for prompt-based automations. Provider terms apply. Both providers are configured to not retain prompt data for training. Client data passes through these providers only when the engagement explicitly requires AI-generated outputs.
A current list of sub-processors is available on request by writing to julien@humanssystems.com.
7. International Data Transfers
Some of our sub-processors are located outside the European Economic Area (notably in the United States). When personal data is transferred outside the EEA, the transfer is protected by Standard Contractual Clauses approved by the European Commission, or by another legally recognized transfer mechanism.
8. Your Rights
If you are a resident of the European Economic Area, the United Kingdom, or another jurisdiction granting equivalent rights, you have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your personal data (right to be forgotten).
- Request restriction of processing in certain circumstances.
- Object to processing based on legitimate interest.
- Request portability of data you have provided to us.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, write to julien@humanssystems.comwith the subject line "Data Subject Request". We will respond within 30 days.
9. Data Deletion Requests
You can request deletion of all personal data we hold about you, including Meta Platform Data, by writing to julien@humanssystems.comwith the subject line "Data Deletion Request".
Upon receipt of a valid request, we will:
- Confirm receipt within 5 business days.
- Revoke any access tokens granted to us by your platform accounts.
- Delete operational and historical data stored in our systems within 30 days.
- Purge incidental backups within an additional 30 days.
- Retain only the records required by law (notably accounting and tax records, retained for the legally mandated period in Spain and the European Union).
10. Security
We implement reasonable technical and organizational measures to protect personal data, including TLS encryption in transit, encryption at rest for credentials and tokens, restricted access based on the principle of least privilege, and routine review of access logs. No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the competent supervisory authority within the timeframes required by applicable law.
11. Government and Public Authority Data Requests
If Humans Systems receives a request from a public authority, law enforcement, or government body for personal data or Platform Data we process:
- Legality review. Every request is reviewed for legal validity, jurisdiction, and proper legal basis before any response is given. Where necessary, we seek independent legal counsel.
- Challenging unlawful requests. If a request appears unlawful, overbroad, or improperly served, we will reject it or challenge it through the available legal channels before disclosing any data.
- Data minimization. If disclosure is legally required, we disclose only the minimum data strictly necessary to comply with the specific request, and nothing more.
- Documentation. We keep an internal record of every request received, the legal reasoning applied, the parties involved, and our response.
- Notification. Where legally permitted, we will notify the affected client before disclosing their data.
Where the request concerns Platform Data obtained from a third-party platform (such as Meta), we will additionally redirect the authority to the platform where appropriate and handle the request in accordance with that platform's terms.
12. Cookies
humanssystems.com does not set tracking cookies. The only client-side storage we use is a theme preference (light or dark) stored in your browser's localStorage. No analytics, no advertising pixels, no third-party scripts that profile you across sites.
13. Children
Our services are intended for businesses and professionals. We do not knowingly collect personal data from individuals under 16 years of age. If you believe a minor has provided personal data to us, please contact us so we can delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The current version is always available at this URL with the "Last updated" date at the top. Material changes will be communicated to active clients by email at least 30 days before taking effect.
15. Contact
For any privacy question, data subject request, or to revoke our access to your connected platforms:
Also see our terms of service and data deletion instructions.