Privacy Policy
Last updated: 24 September 2026
This policy explains which personal data Hipereach handles, where it comes from, what it is used for, when it is deleted and what you can ask of us. It is written for the people we actually deal with: visitors to this website, people who email us, staff at the brands we work with, and anyone who wants to know what happens to data when we run advertising on TikTok, Facebook and Instagram.
The EU General Data Protection Regulation (GDPR) applies, together with the data protection law of the country where the company is registered. In this policy, "we" and "us" mean Hipereach.
If you only have a minute, the table in section 2 lists every kind of personal data we hold and where each one comes from. The sections after it go into detail.
1. Who we are and what this policy covers
Hipereach is an independent performance marketing company. We plan, buy and optimize paid social advertising on TikTok and on Meta's platforms (Facebook and Instagram), for brands we own, whose products we sell ourselves, and for brand partners: companies that sell their own products or services and pay us for results agreed in writing before a campaign starts.
The policy applies in five situations:
- visits to hipereach.com, this website;
- email correspondence with us, including inquiries that never turn into work;
- business relationships with brand partners and suppliers, and the people at those companies we deal with;
- ad accounts we manage on TikTok and Meta, whether they belong to us or to a brand partner, and the data the platforms provide about them;
- landing pages of our own brands, and the conversion measurement connected to them.
What TikTok or Meta do with data about the people who use their apps is outside this policy; each platform answers for that under its own privacy policy. Landing pages of a brand partner, including any we build and host for it, carry that partner's notice, because the partner decides what its pages collect. Personal data of our own employees and contractors is handled under their employment or service terms and is outside this document.
2. Personal data we handle and its sources
Most of what we work with every day is not personal data at all: budgets, bids, video files, and totals of impressions, clicks and conversions. The personal data we do handle falls into the seven groups below, each listed with the place it comes from.
| Category | Examples | Where it comes from |
|---|---|---|
| Website technical data | IP address, browser user agent, requested URL, time of the request | Your browser, recorded by our hosting provider |
| Correspondence | Name, email address, company, job title, the content of messages and attachments | You, when you write to us, or a colleague who introduces you |
| Business relationship data | Signatories, billing contacts, invoicing details, notes from calls | You or your employer, during onboarding and the relationship |
| Ad account contacts | Name and business email of the contact person on an ad account we manage, where shown | The advertising platform, once access is granted |
| Spark Ads creators | Public account name and the post the creator authorized for use in an ad | The creator, through TikTok |
| Own-brand customer lists | Email addresses or phone numbers of customers who agreed to it, hashed before upload | The stores and sign-up forms of our own brands |
| Landing page events | Event name and time, event ID, hashed identifiers, as listed on each page | Visitors to our own-brand landing pages |
Special categories of personal data (health, religious beliefs, political opinions and the others listed in Article 9 GDPR) are never requested, and none of our audience settings are built on them.
3. This website
hipereach.com is a set of static pages. It sets no cookies, writes nothing to your browser's storage, and loads no analytics, advertising pixels, social media widgets, embedded videos or externally hosted fonts. Text appears in fonts already installed on your device. The only script is a few lines of our own code that open and close the menu on small screens and print the current year in the footer.
There is no contact form. People reach us by email, so nothing typed on the site is sent anywhere.
Like any web server, the one that delivers these pages records each request: the IP address it came from, the browser's user agent string, the URL requested and the time. Our hosting and content delivery provider keeps these access logs for 30 days and then deletes them. They are looked at only when something needs investigating, such as a burst of abusive requests or an outage. Nobody uses them to count visitors or to recognize someone who comes back.
The legal basis is our legitimate interest in running a secure and available website (Article 6(1)(f) GDPR). Our Cookie Policy has more on the absence of cookies and tags.
4. Email and business contacts
When you write to hello@hipereach.com, we receive your email address, your name as it appears in the message, what you wrote and anything you attached. People often add a company name, a job title, a phone number or a description of the product they want to advertise. The whole thread is kept, so that whoever on our side picks it up next can see what has already been said.
If a conversation turns into work, a few more details join the file: who signs the agreement, who receives invoices, who approves creatives and who gets the weekly summary. For a brand partner this is usually a handful of named people.
This data is used to answer you, to prepare and perform agreements, to send the reports and invoices an agreement calls for, and to keep accounting records. Your address does not go on a mailing list. It is not passed to anyone for their own marketing either. Our email provider stores the mailbox on our behalf under a data processing agreement.
No law obliges you to give us personal data. To sign an agreement with us, though, we need the names of the people signing it and the billing details an invoice requires. Without them we cannot enter into the agreement.
5. Data from advertising platforms
Everything in this section applies equally to our own ad accounts and to those of brand partners.
How access is granted
Most campaigns run from our own verified ad accounts. When a brand partner prefers its campaigns to run in its own ad account, the partner's administrator gives us access in one of two ways: by adding us as a partner in TikTok Business Center or Meta Business Manager, or by authorizing our internal tools on the platform's own authorization page. Either way, the partner chooses which ad accounts we can reach. In Business Center and Business Manager the partner also sets our role, for example whether we may edit campaigns or only view reports. Access can be withdrawn at any time, as explained at the end of this section.
What we receive
Through the platform's tools and official interfaces, we receive:
- ad account details: name and ID, currency, time zone, status, balance, the business account it belongs to, and, where the platform shows them, the name and business email of the account's contact person;
- campaign structure and settings: campaigns, ad groups (ad sets on Meta) and ads, with their budgets, bids, schedules, optimization goals and targeting settings such as countries, languages, age ranges and placements;
- aggregated performance data: spend, impressions, clicks, click-through rate, CPM, conversions, cost per result and video views, split by day, country and placement;
- creative assets and their review status: the videos, images and ad text in the account, destination URLs, and the outcome of the platform's ad review, including the reason for any rejection;
- measurement setup: which pixel and conversion events are configured and how many events each one has recorded.
This data describes ads and how they performed. It does not identify individual TikTok, Facebook or Instagram users. A line in a report says how often an ad was shown in a country and how many clicks it got; it does not say who saw or clicked it, and nothing we receive would let us find out.
The contact details on an ad account are the exception. They belong to the people who administer the account, and we handle them as business contact data (see Email and business contacts). When a creator authorizes us to run one of their TikTok posts as a Spark Ad, we also see that post and the public account name attached to it. Both are used for that ad only, and the creator can end the authorization whenever they choose.
What it is used for
Platform data is used to set up, run and optimize campaigns; to review results every working day; to write the weekly summary for brand partners and the monthly reconciliation of spend and conversions; to check creatives and destinations against advertising policies; and to calculate what a brand partner owes under a pay-on-results agreement, including when an invoice is disputed.
Limits we apply
- Platform data is never sold, rented or handed to third parties. A brand partner sees data from its own campaigns and ad accounts, never another partner's.
- No profiles of TikTok, Facebook or Instagram users are built, and our work does not involve reading users' profiles, followers, messages or comments.
- Platform data is not combined with other sources to identify people or to recognize them across services.
- None of it is used to train machine-learning or other AI models.
- Nothing is collected by scraping the platforms' websites or apps.
Each platform's terms of service, advertising policies and data terms (including the terms for pixels and conversion data) apply to everything above. Where those terms are stricter than this policy, the stricter rule wins.
Credentials and ending access
The credentials that let our internal tools work in an ad account are stored encrypted on our servers, never in a browser, and are used only for the accounts they were granted for. A brand partner can end our access by removing us in TikTok Business Center or Meta Business Manager, by removing the authorization in the platform's account settings, or by emailing us. Once we know access has ended, the stored credentials are deleted within 24 hours. Reporting data we already hold is then kept only as set out in How long we keep data; a partner who wants it deleted sooner can follow the steps on our data deletion page.
6. What we send to advertising platforms
Running ads also means sending data the other way. We send TikTok and Meta:
- campaign settings and later changes to them, such as a new budget, a different bid, a schedule or a paused ad. Each change is made by a named member of our team, or by a rule someone on the team set up with explicit thresholds, and it is written to our change log;
- creatives: videos, images, ad text and the destination URL of each ad;
- customer lists of our own brands, limited to customers who agreed to this use, with email addresses or phone numbers hashed with SHA-256 before upload. The platform matches the hashes against its own users to form an audience and tells us only its approximate size, not who matched;
- server-side conversion events from our own landing pages, described in the next section.
Under the GDPR a hashed email address or phone number counts as pseudonymized data. It is still personal data, and everything in this policy applies to hashed lists as well. The raw file used to build a list is deleted within 7 days of the upload.
A brand partner's customer list is never uploaded on our initiative. If a partner, as controller of that list, instructs us in writing to upload it, we act as its processor on the terms Article 28 GDPR requires, and the same hashing and deletion rules apply.
7. Own-brand landing pages and measurement
Our own brands sell through landing pages that we build and host. Those pages are separate from this website. Each one has its own privacy notice and, where needed, a cookie notice, naming the brand and describing what the page collects. Orders and sign-ups made there are covered by that notice rather than by this policy.
To learn which ads lead to a sale or a sign-up, a landing page may use the TikTok Pixel or the Meta Pixel in the browser. It may also send the same events from our server through the TikTok Events API or the Meta Conversions API. Each event carries its name (a completed purchase or a submitted form, for example), its time, an event ID so that the platform can drop the duplicate when the pixel and the server report the same conversion, and identifiers hashed before they leave our server. The page's notice lists the exact fields.
In the EU, advertising pixels need the visitor's consent, and our pages ask for it before any pixel loads. Server-side events follow the same choice: when a visitor declines measurement where consent is required, neither the pixel nor the server sends anything. Consent can be withdrawn on the page at any time, which stops further events.
For the collection and transmission of this event data, the platforms' terms may make us joint controllers with TikTok or Meta for that step, while each platform is responsible for its own processing afterward. The notice on each landing page sets out that arrangement.
8. Purposes and legal bases
Each use of personal data rests on one of the legal bases in Article 6(1) GDPR.
| Purpose | Personal data | Legal basis |
|---|---|---|
| Delivering and securing this website | Access logs | Art. 6(1)(f), legitimate interests: keeping the site available and protected against abuse |
| Answering inquiries | Correspondence, contact details | Art. 6(1)(b), steps taken at your request before a contract; Art. 6(1)(f) where you write for a company |
| Preparing and performing agreements with brand partners and suppliers | Business contact data, billing details, correspondence | Art. 6(1)(b), contract; Art. 6(1)(f) for staff of a partner who are not themselves party to it |
| Managing ad accounts, reporting and reconciliation | Ad account contacts, change logs | Art. 6(1)(f), legitimate interests in performing our agreements and running our own ad accounts |
| Running a creator's post as a Spark Ad | Public account name, the authorized post | Art. 6(1)(b), our agreement with the creator; where there is none, Art. 6(1)(f), running an ad the creator authorized |
| Audiences built from own-brand customer lists | Hashed email addresses or phone numbers | Art. 6(1)(a), the customer's consent |
| Conversion measurement on own-brand landing pages | Event data, hashed identifiers, cookies set by the pixel | Art. 6(1)(a), consent where the law requires it; otherwise Art. 6(1)(f) |
| Accounting, tax and requests from authorities | Contracts, invoices, related correspondence | Art. 6(1)(c), legal obligation |
| Answering privacy requests | Your request, our reply, details used to confirm who you are | Art. 6(1)(c), our obligations under Articles 12 to 22 GDPR |
| Establishing or defending legal claims | The records relevant to the claim | Art. 6(1)(f), legitimate interests |
Where we rely on legitimate interests, we have weighed them against your interests and rights. You can ask for that assessment, and you can object to the processing (see Your rights).
The table does not cover a brand partner's customer list uploaded on the partner's written instruction. There we act as the partner's processor, and the legal basis is the partner's to establish as controller.
9. Who receives personal data
Personal data goes only to the recipients below, and only as far as each one needs it.
- The providers that host this website and the servers of our internal tools, as processors under data processing agreements.
- Our email provider, which stores the company mailbox, also as a processor.
- Any other service provider we use for administration, such as accounting or file storage software, again only as a processor under a written agreement and only for the data its service needs.
- TikTok and Meta, for ad delivery and measurement. They receive the campaign settings, creatives, hashed lists and conversion events described above and process them under their own terms and privacy policies, in several respects as independent controllers.
- Brand partners, who receive reports on their own campaigns. The figures in those reports are aggregated and contain no data about individual people.
- Professional advisors such as accountants, auditors and lawyers, who are bound by confidentiality.
- Courts, public authorities and law enforcement, when a law or a binding order requires it. A request is checked for a legal basis before anything is disclosed.
- A buyer or successor, should the business ever be sold or merged, bound by the commitments in this policy.
Nobody on this list pays us for personal data, and none of it is sold to anyone else or handed over for someone else's marketing. Our income comes from our own brands' sales and from brand partners paying for agreed results.
10. Transfers outside the EEA
Some of our service providers, and both advertising platforms, may process personal data outside the European Economic Area (EEA), including in the United States. Such a transfer relies either on an adequacy decision of the European Commission (Article 45 GDPR), for example the decision covering US companies certified under the EU-US Data Privacy Framework, or on the Commission's standard contractual clauses (Article 46(2)(c) GDPR) together with any additional measures the transfer needs.
You can ask us for a copy of the safeguards that apply to a given transfer. Commercial terms may be redacted, but the data protection clauses will not be. TikTok and Meta describe their own transfer mechanisms in their privacy policies.
11. How long we keep data
Personal data is kept only as long as its purpose requires. After that it is deleted, or reduced to figures that no longer relate to anyone.
| Data | How long we keep it |
|---|---|
| Website access logs | 30 days, then deleted by the hosting provider |
| Inquiries that do not lead to work | Until the question is answered and any follow-up is closed, then deleted |
| Contact data and correspondence with brand partners and suppliers | For the length of the relationship, then until open invoices and reconciliations are settled |
| Contracts, invoices and accounting records | For the period that accounting and tax law requires |
| Credentials for access to an ad account | Until access is removed; deleted within 24 hours after we learn of the removal |
| Ad account details, campaign structure, reporting data and change logs | While we have access to the ad account, and up to 24 months after access ends for reconciliation, invoicing disputes and accounting, then deleted |
| Raw customer files for own-brand audiences | Deleted within 7 days of upload |
| Hashed audiences in an ad account | Kept only while the audience is in use, then deleted in the ad account. Anyone who withdraws consent is removed from the audience |
| Conversion events from own-brand landing pages | As stated in the landing page's notice; the platforms keep event data under their own terms |
| Privacy requests and our replies | As long as needed to show how the request was handled |
If a legal hold applies, for example during a dispute or an inquiry by an authority, the data concerned is kept until the matter is closed and then deleted on the schedule above.
12. How we protect data
The measures below cover this website, the company mailbox and the internal tools our team uses to manage ad accounts.
- All connections to this website and to our internal tools are encrypted with HTTPS (TLS).
- Ad account credentials are encrypted at rest and kept server-side. Backups are encrypted too.
- Staff sign in to our internal tools, the mailbox and the platforms' business accounts with two-factor authentication.
- Access follows least privilege: an analyst can read reports but cannot change a budget.
- Every change to a campaign, budget or ad goes into a change log with the person or rule responsible, the time, and the old and new values.
- When someone leaves the team, their access to our tools, the mailbox and the ad platforms is removed the same day.
- Processors are bound by agreements that include confidentiality and security obligations.
If a personal data breach happens, we contain it first and then assess the risk. Affected brand partners are informed without undue delay, and so is TikTok or Meta when data received from that platform is involved. Where Article 33 GDPR applies, we notify the competent supervisory authority within 72 hours of becoming aware of the breach, and where the risk to people is high we tell them directly, as Article 34 requires. Every breach is recorded, including those that need no notification.
13. Your rights
Articles 15 to 22 GDPR give you the right to:
- access the personal data we hold about you and receive a copy (Article 15);
- have inaccurate data corrected or incomplete data completed (Article 16);
- have data erased, for example when we no longer need it or you withdraw consent (Article 17);
- restrict processing while a question about accuracy or lawfulness is being resolved (Article 18);
- receive data you gave us in a structured, machine-readable format, or have it sent to another controller, where the processing is based on consent or contract and carried out by automated means (Article 20);
- object at any time, on grounds relating to your situation, to processing based on legitimate interests (Article 21);
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you (Article 22).
After correcting or erasing data, we tell the recipients it was shared with, unless that proves impossible or involves disproportionate effort (Article 19). Consent can be withdrawn at any time; withdrawal does not affect processing that took place before it (Article 7(3)).
How to make a request
Email hello@hipereach.com with the subject line "Privacy request" and say what you would like. No special wording is needed. A request sent with the subject "Data deletion request", as our data deletion page suggests, is handled the same way. If your email does not show that the data is yours, we will ask for the minimum needed to confirm it, and nothing more. Each request is acknowledged within two business days and completed within 30 days. Article 12(3) allows two further months for an unusually complex request; if we need that time, you hear so within the first 30 days, with the reason. Requests are free; only a manifestly unfounded or excessive request may be refused or charged a reasonable fee, and we would explain why (Article 12(5)).
If you saw one of our ads on TikTok, Facebook or Instagram, we do not know who you are. The platforms decide who sees an ad within the settings we choose, and what they send back to us are totals, so we cannot find you in our data (Article 11). The platforms can. The ad settings in your account on each app show why an ad was shown and let you change how ads are personalized. If something does link you to data we hold, for example because you are a customer of one of our brands, tell us and we will act on it.
Brand partners who want to end our access to an ad account or have account data deleted will find the steps on our data deletion page.
Complaints
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live, where you work or where you believe the infringement took place (Article 77 GDPR). You do not need to contact us first, although we would welcome the chance to look at the problem.
The authority for the country of our registered office is the Commission nationale de l'informatique et des libertés (CNIL), www.cnil.fr.
14. Children
Our services are for businesses, and this website is written for the people who run them. We do not knowingly collect personal data from children.
Campaigns we run do not target anyone under 18. Age settings start at 18 in every market, including where a platform would allow a younger audience. If you believe a child has sent us personal data, tell us and it will be deleted.
15. Automated decision-making
No decision that produces legal effects for a person, or affects them in a similarly significant way, is made by us on the basis of automated processing alone.
Automated rules do play a part in campaign management, and they act on ads, not people. A typical rule pauses an ad group once it has spent twice its target cost per result without a conversion. Each rule is set up by a named member of our team with explicit thresholds, and every action it takes is logged.
Which person sees a given ad is decided by the platform's own delivery system, within the settings we choose. TikTok and Meta explain how that works in their privacy policies and in the ad settings of their apps.
16. Changes to this policy
This policy changes when our practices change or the law requires it, and the date at the top of the page changes with it. If an update affects how we handle brand partners' data, those partners hear about it by email before it takes effect. A corrected typo or a fixed link is not announced. Earlier versions are available on request.
17. Contact
For anything about personal data, email hello@hipereach.com with the subject "Privacy request". Post can go to Hipereach, 166 ter rue d'Aguesseau, 92100 Boulogne-Billancourt, France. Privacy requests are handled by the part of our team responsible for operations and compliance. Our hours are Monday to Friday, 09:00 to 18:00 (CET), and we reply in English and French.
Company details are in our Legal Notice, and the rules for using this website are in our Terms of Service.