Privacy Policy
This policy explains what data the AutoProcess platform accesses, why it accesses it, how it is stored and shared, and how it is removed. It includes specific disclosures for data accessed through Google APIs.
Last updated 20 September 2026
Who we are
Autoprocess Ltd is a company registered in England and Wales, company number 16700982. We build and operate operations systems for businesses. In this policy, “we” and “us” mean Autoprocess Ltd, and “the platform” means the software described on our platform page.
For any question about this policy or the data we hold, contact faraaz@autoprocessgroup.com.
Who this policy covers
The platform is operated on behalf of the businesses we work with. It is not offered for public sign-up. The people who authorise access are the owners or administrators of their own advertising and CRM accounts.
Google user data we access
With the explicit authorisation of the account holder, and using Google OAuth, the platform accesses the following through Google APIs:
- Google Ads account structure: manager and client account identifiers, campaigns, ad groups, ads, keywords and search terms.
- Conversion action configuration, so an outcome is recorded against the correct conversion action.
- Advertising performance data such as spend, impressions, clicks and conversions.
- Google click identifiers (for example gclid and gbraid) captured when a visitor arrived from a Google advert.
We do not request access to Gmail, Google Drive, Google Calendar, Contacts or any other Google service outside the advertising APIs described here.
How we use Google user data
The data above is used only to:
- Report offline conversion events, meaning a value, currency, timestamp and click identifier, back to the advertising account where that click originated.
- Identify the correct account and conversion action to report against.
- Produce reporting for the account holder showing which advertising produced real business outcomes.
- Diagnose and correct faults in the connection, such as failed or stale synchronisations.
We do not use Google user data for advertising, for profiling, for training generalised machine learning models, or for any purpose unrelated to delivering the service to the account holder it came from. We do not sell it.
Limited Use
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Other data we access
Where a business connects them, the platform also reads from their Meta advertising accounts (campaigns, ad sets, ads and datasets, plus Meta click identifiers) and from their CRM (the record of an enquiry becoming an opportunity, its stage, and its value where present). The same rules in this policy apply to that data.
Personal data
The reporting path does not require names, email addresses or telephone numbers, and those are not sent to advertising platforms. A click identifier identifies a click, not a person.
Where a business's CRM records contain personal data and the platform necessarily encounters it, we act as a processor on that business's instructions. They remain the controller of their own customer data. We do not use it for our own purposes.
How data is stored
- Data is held in managed cloud infrastructure with encryption in transit and at rest.
- Access credentials and tokens are stored as secrets, never in application code and never in a browser.
- Access is restricted to the people who need it to operate and support the service.
- Activity is logged so that what the platform did, and when, can be inspected.
Who we share data with
We do not sell data and we do not share it with third parties for their own purposes. Data is shared only with:
- The advertising platforms themselves, when reporting an outcome back to the account it came from.
- Infrastructure providers used to run the service, acting on our instructions under contract.
- Anyone we are legally required to disclose to.
One business's data is never exposed to another business through the platform.
Retention and deletion
Data is kept for as long as we operate the service for the business it belongs to, plus a reasonable period afterwards for reconciliation. Authorisation can be withdrawn at any time from within the account holder's own Google, Meta or CRM settings, and the platform stops immediately when it is.
On written request we will delete the data we hold for a business, except anything we are required to retain by law.
Your rights
Where UK or EU data protection law applies, individuals have rights of access, correction, erasure, restriction, objection and portability. If the data concerns a customer of a business we work with, that business is the controller and the request is best directed to them. We will support them in answering it. You may also complain to the UK Information Commissioner's Office.
Changes
If this policy changes, the revised version is published on this page with a new date at the top.
