Aller au contenu
Kapitaine

Legal information

Security and GDPR

Agencies entrust Kapitaine with their clients' advertising access and results. This page summarizes how that data is hosted, isolated and logged. No certification is claimed that we do not hold: only what is actually in place.

Last updated: September 29, 2026

This is an English translation provided for convenience; the French version prevails. Read the French version.

Six concrete safeguards

  • Hosted in the European Union. The database, background processing and files are hosted in Amsterdam (Netherlands), backups included.
  • Agencies isolated in the database. PostgreSQL Row-Level Security: every query is filtered by the database itself. An agency cannot read another agency's data, even if there is a bug in the application code.
  • Ad platform tokens encrypted. Meta, Google, Canva and Google Drive access tokens are encrypted with AES-256-GCM before being stored. They are never displayed in the interface.
  • Two-factor authentication. One-time code (TOTP) from your authenticator app. Mandatory for agency administrators, available to everyone.
  • Audit log. Logins, connection or disconnection of an ad account, bulk publishing, role changes, exports: every sensitive action is recorded with its author.
  • Private files, 5-minute links. Creatives, brand kits and PDFs are kept in private storage. They are only served through signed links valid for 5 minutes, never through a public address.

Isolation

An agency cannot see another agency's data, and neither can a client. Most software filters data in its code. Kapitaine does too, but above all in the database itself, thanks to PostgreSQL Row-Level Security.

  • Every database connection carries the identity of the agency and the user. The database only returns the rows that belong to them.
  • A team member only sees the clients they are assigned to.
  • An end client only sees their own campaigns, reports, creatives and invoices.
  • If a query forgets a filter, the database returns zero rows rather than someone else's data.

Traceability

Every sensitive action leaves a trace, including support actions. When our support team needs to log in “as” a user to help you, the log records the real identity of the person acting, not just the account used.

  • Log kept by the platform and retained for 24 months.
  • When your agency opens a client's space (“view as client”), it is read-only, and the access is logged.
  • Sessions limited to 12 hours.
  • Actions recorded: logins, “log in as”, ad accounts connected or disconnected, bulk publishing, budgets, report publication, exports, role changes.

Access to ad platforms: only the permissions needed

Where a read-only permission exists, that is the one we request. You can revoke each access at any time, from Kapitaine or from the ad platform.

  • Google Drive (read-only): drive.file permission. Kapitaine only accesses the images and videos you choose in Google's picker window (drive.readonly only with your agency's own Google Cloud project). It does not modify or delete your files.
  • Canva (read-only): reading your designs and their information, to export them as PNG into the client's library.
  • Google Ads (used for reading): Google does not offer a read-only Google Ads permission. Kapitaine uses it solely to read campaigns and results: no changes are sent to your Google Ads accounts today.
  • Meta Ads (ads management): bulk publishing requires the ads_management permission. Every ad is created paused: nothing runs without your approval, and every publication is logged.

GDPR: your rights and your clients' rights

For your clients' data, your agency is the data controller and Kapitaine acts as a processor. For your agency account and this website, Kapitaine is the data controller.

  • Record of processing activities kept up to date, with purposes, legal bases and retention periods.
  • Full export of your agency's data in JSON format, in one click from Settings › Data (administrators only, recorded in the audit log).
  • Permanent deletion on request: immediate purge from the database, purge from backups within 30 days, recorded in the audit log.
  • No custom audience (list of individuals) is stored.
  • No advertising tracker or audience measurement tool in the app: only a session cookie.

Details are in the privacy policy and on the data deletion page.

Subprocessors: who hosts what

The complete list of providers that process data to operate Kapitaine.

SubprocessorRoleLocation
Railway CorporationDatabase, background processing (synchronization, alerts, reports) and file storageEU West region (Amsterdam, Netherlands)
Vercel Inc.Hosting of the kapitaine.com website and of the application's web interfaceVercel's global network; company established in the United States
Anthropic, PBC (Claude API)AI-assisted drafting of report commentary drafts and weekly summaries, based on aggregated campaign figuresCompany established in the United States
Transactional email provider (selection in progress)Sending of transactional emails (invitations, alerts, report notifications)European Union (selection criterion); its name will be published here as soon as it goes live

Found a vulnerability or have a security question?

Write to us at contact@kapitaine.com with the subject “Security”. Describe what you observed; please do not access other users' data or disrupt the service while carrying out your checks.