How we collect, use, share, and protect information across the Adzeela digital out-of-home advertising platform, API services, and Adzeela Player for Samsung Tizen TVs.
Draft status: Legal and operational review required before publicationEffective date: August 7, 2026Last updated: August 7, 2026
AZDEELA ("AZDEELA," "we," "us," or "our") operates the Adzeela digital out-of-home advertising platform, including the Adzeela web application, API services, and Adzeela Player for Samsung Tizen TVs (collectively, the "Services"). This Privacy Policy explains what information we collect, how we use it, when we share it, how we protect it, and the choices available to individuals who use or interact with the Services.
Legal review notice: This is a technical first draft based on the current application implementation. It is not legal advice and is not a substitute for review by qualified privacy counsel in each market where AZDEELA operates. Complete all [INSERT] and [CONFIRM] fields before publishing.
Privacy representative / DPO[INSERT NAME OR STATE "NOT APPLICABLE" AFTER REVIEW]
For privacy questions, requests, or complaints, contact [email protected]. We may request information needed to verify the identity and authority of a person making a request.
2. Services covered by this policy
This policy applies to:
The Adzeela web application and dashboards.
The Adzeela API, authentication, real-time connections, and storage services.
This policy does not automatically apply to third-party websites, payment pages, video hosts, mapping services, or other services linked from or used by the Services. Those providers publish their own privacy notices.
3. Information we collect
The exact information collected depends on the role a person has and the features used.
3.1 Account and identity information
When an account is created or managed, we may collect:
Name.
Email address.
Phone number, if provided.
Avatar URL or profile image, if provided.
Account role, status, agency, promoter, advertiser, territory, or partner association.
Invitation and registration information.
Password credentials in protected form. We store password hashes rather than plaintext passwords.
We do not intentionally collect a user's password in readable form.
3.2 Business, campaign, and content information
Depending on the account role and workflow, we may collect:
Agency, advertiser, promoter, territory, venue, and screen details.
Campaign names, descriptions, brands, objectives, targeting, schedules, budgets, and related configuration.
Creative names, content types, file names, media metadata, destination URLs, and review notes.
Uploaded images and videos used as advertising or promoter content.
Loop, slot, screen-layout, queue, announcement, and playback configuration.
Contact person, contact number, and contact email included in barter or advertising workflows.
Territory invitations and related email addresses.
Do not upload personal information, confidential information, or third-party content unless you have the legal right and appropriate notice or consent to do so.
3.3 Promoter and profile information
Promoter workflows may collect additional profile information such as:
Business and profile details.
Optional alternate phone number.
Optional address.
Optional date of birth.
Optional gender.
Territory and business associations.
Only provide optional profile information when it is necessary for the relevant business relationship or service feature. [CONFIRM WHETHER DATE OF BIRTH AND GENDER ARE ENABLED IN PRODUCTION AND WHETHER THEY ARE REQUIRED.]
3.4 Screen and location information
For screen management, we may collect:
Screen name and serial number.
Venue name and descriptive location.
Screen resolution and orientation.
Latitude and longitude, when an operator provides or selects a screen location.
Time zone, announcement text, tags, and layout configuration.
Screen approval, availability, heartbeat, and operational status.
The location features are intended to describe the placement of an advertising display or venue. They are not intended to continuously track a TV viewer's physical location.
3.5 Samsung Tizen device information
When Adzeela Player runs on a Samsung Tizen TV, it may collect:
The Samsung TV device identifier (DUID), when the platform makes it available.
A SHA-256 hash derived from that identifier for screen registration and pairing.
A locally generated random UUID fallback if the platform identifier is unavailable.
Browser or runtime user-agent information.
Display resolution, orientation, color depth, language, hardware concurrency, and device-memory information when available to the web player.
Local storage data used to preserve the screen identity and support offline playback.
Player session, connectivity, synchronization, heartbeat, playback, and impression events.
The raw Samsung DUID is not intentionally sent to the AZDEELA API by the Tizen wrapper; the wrapper hashes the identifier and sends the resulting device identifier to the web player for screen bootstrap. The hash is used to identify a registered screen, not to identify a TV viewer by name.
3.6 Usage, playback, and analytics information
We may collect operational and usage information such as:
Login and authentication events.
Screen registration, pairing, approval, connection, and heartbeat events.
Online/offline transitions and cache synchronization state.
Actions taken in campaign, creative, screen, loop, queue, wallet, and administration workflows.
Error, diagnostic, and security information needed to operate and protect the Services.
This data is associated primarily with accounts, screens, campaigns, creatives, or operational records. [CONFIRM WHETHER SERVER ACCESS LOGS RETAIN IP ADDRESSES, REQUEST HEADERS, OR OTHER NETWORK IDENTIFIERS AND ADD THE APPLICABLE RETENTION PERIOD.]
3.7 Wallet and payment information
The platform includes wallet and payment workflows. We may collect and retain:
Wallet owner and account association.
Amount, currency, balance, held amount, spent amount, and ledger entries.
Commission, revenue-share, and settlement-related records where applicable.
Payment credentials such as full card numbers should be handled by the payment provider rather than stored by AZDEELA. [CONFIRM THIS AGAINST THE PRODUCTION PAYMENT INTEGRATION AND CONTRACTS.]
3.8 Support and communications
If you contact us, we may collect:
Your name, email address, phone number, and the contents of your message.
Account, screen, campaign, payment, or technical details needed to investigate the request.
Attachments or other information that you voluntarily provide.
Please do not include passwords, access tokens, payment-card numbers, or other unnecessary sensitive information in support requests.
3.9 Cookies, local storage, and similar technologies
We use technologies necessary to provide and secure the Services, including:
HTTP-only, secure authentication cookies for access and refresh sessions.
Local storage for a Tizen screen's fallback device UUID and player bootstrap state.
Browser storage and cache mechanisms for offline manifests and media playback.
Session and security data used to authenticate requests, revoke sessions, prevent abuse, and maintain service reliability.
[CONFIRM WHETHER THE WEB APPLICATION USES ANY NON-ESSENTIAL ANALYTICS, ADVERTISING, OR TRACKING COOKIES. IF SO, ADD A COOKIE-CONSENT SECTION AND COOKIE TABLE.]
4. How we use information
We use information for the following purposes:
Create, authenticate, maintain, and secure accounts.
Provide role-based access to dashboards and workflows.
Register, pair, approve, monitor, and operate advertising screens.
Deliver manifests, creatives, announcements, queue information, and layouts to authorized players.
Cache and synchronize content for offline-capable playback.
Schedule, review, approve, reject, deliver, and report advertising and promoter content.
Process wallet, payment, ledger, commission, and settlement workflows.
Provide analytics, impression reporting, playback reporting, diagnostics, and operational monitoring.
Respond to support requests and communicate about the Services.
Detect, prevent, investigate, and respond to fraud, misuse, security incidents, and violations of our terms.
Comply with legal, accounting, tax, regulatory, court, and law-enforcement obligations.
Improve the reliability, security, accessibility, and performance of the Services.
We do not use the Samsung Tizen device identifier to identify a TV viewer as a named individual. It is used to associate a player installation with a registered screen.
5. Legal bases for processing
Where privacy law requires a legal basis, we generally rely on one or more of the following:
Contract: to create accounts, provide the requested Services, operate screens, manage campaigns, and perform wallet or payment workflows.
Legitimate interests: to secure the Services, prevent abuse, maintain reliability, provide operational telemetry, and improve the platform, balanced against individual privacy rights.
Legal obligation: to maintain accounting, payment, tax, audit, fraud-prevention, and legally required records.
Consent: where required for optional communications, non-essential cookies, or other optional processing.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that occurred before withdrawal or processing based on another lawful basis.
6. How we share information
We may share information in the following circumstances:
6.1 Service providers
We use vendors and infrastructure providers to operate the Services. Depending on the production configuration, these may include:
Cloud hosting, database, cache, monitoring, and security providers.
S3-compatible object storage, including Cloudflare R2 in production or MinIO in local development, for advertising media and related assets.
Payment providers, including Xendit where enabled, for payment checkout and payment-status processing.
OpenStreetMap/Nominatim or another configured geocoding provider for operator-entered location searches.
YouTube or another media provider when an advertiser intentionally uses an externally hosted creative or embedded video.
Email, support, communications, and notification providers if enabled in the production deployment.
Providers may process information on our instructions, under their own terms, or as independent controllers where applicable. [INSERT PRODUCTION VENDOR LIST, PROCESSOR AGREEMENTS, AND DATA-LOCATION DETAILS.]
6.2 Business users and screen operators
Information may be visible to authorized advertisers, agencies, promoters, territory partners, and administrators when needed to operate the platform. Advertising creative and campaign information may be displayed on screens according to the configured campaign and screen permissions.
6.3 Legal and safety disclosures
We may disclose information where reasonably necessary to:
Comply with applicable law, legal process, or a valid governmental request.
Protect the rights, safety, property, and security of AZDEELA, users, the public, or the Services.
Investigate fraud, abuse, security incidents, or violations of agreements.
Enforce our terms and protect against legal claims.
6.4 Corporate transactions
Information may be transferred as part of a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality and legal protections.
We do not disclose personal information to third parties for their own direct marketing purposes unless this policy is updated and any legally required choice or consent is provided.
7. International transfers
AZDEELA and its service providers may process information in countries other than the country where it was collected. Where required, we use appropriate safeguards for cross-border transfers, which may include contractual protections, adequacy decisions, consent, or another legally recognized mechanism.
[INSERT PRIMARY HOSTING COUNTRY/COUNTRIES AND THE TRANSFER MECHANISMS USED FOR EACH RELEVANT REGION.]
8. Data retention
We retain information only for as long as reasonably necessary for the purposes described in this policy, including providing the Services, resolving disputes, enforcing agreements, maintaining security, and meeting legal, accounting, tax, and regulatory requirements.
The final production policy must include or link to an approved retention schedule. Complete the following before publication:
Information type
Proposed retention rule
Status
Account and profile data
While the account is active, plus [PERIOD] after closure
[CONFIRM]
Authentication and security records
[PERIOD] based on security and legal requirements
[CONFIRM]
Screen registration and DUID hash
While the screen is registered, plus [PERIOD] after de-registration
[CONFIRM]
Heartbeat, playback, and impression data
[PERIOD] for reporting, billing, and audit needs
[CONFIRM]
Campaign and creative records
[PERIOD] after campaign completion or account closure
[CONFIRM]
Payment, wallet, ledger, and tax records
[PERIOD] required by accounting and applicable law
[CONFIRM]
Support communications
[PERIOD] after resolution
[CONFIRM]
Backups
Deleted or overwritten according to the backup rotation of [INSERT PROVIDER/POLICY]
[CONFIRM]
When information is no longer required, we delete it, anonymize it, or securely isolate it where deletion is not immediately possible.
9. Security
We use reasonable technical and organizational safeguards appropriate to the nature of the information and the risks involved. Current implementation safeguards include:
Password hashing rather than plaintext password storage.
HTTP-only and secure authentication cookies.
Short-lived access tokens and refresh-token rotation/revocation controls.
Role-based authorization for protected platform operations.
Presigned upload and download URLs for object storage.
Input validation and allowlists for supported media types.
HTTPS-only production configuration for the Tizen player and web application.
Rate limiting and security logging for selected API operations.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we will investigate and respond to suspected incidents as required by applicable law.
If you believe your account or information has been compromised, contact [email protected] promptly.
10. Your privacy rights
Depending on your location and applicable law, you may have rights to:
Know whether we process your personal information.
Request access to personal information we hold about you.
Request correction of inaccurate or incomplete information.
Request deletion or erasure, subject to legal and operational exceptions.
Request restriction of processing.
Object to processing based on legitimate interests or direct marketing.
Request portability of certain information.
Withdraw consent where processing is based on consent.
Opt out of certain marketing, sale, or sharing activities where applicable.
Lodge a complaint with the relevant data-protection authority.
To make a request, email [email protected] with the subject line Privacy Request. We may need to verify your identity before responding. We will not discriminate against you for exercising a privacy right.
10.1 European Economic Area, United Kingdom, and Switzerland
Where applicable, individuals in these regions may exercise rights under the GDPR, UK GDPR, or Swiss data-protection law. Requests may include access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also complain to your local supervisory authority.
[CONFIRM WHETHER AZDEELA HAS AN EU/UK REPRESENTATIVE OR DATA PROTECTION OFFICER OBLIGATION.]
10.2 Philippines
Where applicable, individuals may exercise rights under the Philippines Data Privacy Act and related regulations, including rights to access, correction, erasure or blocking where applicable, objection, data portability where applicable, and complaint. The AZDEELA privacy contact is [email protected].
[CONFIRM THE RESPONSIBLE PHILIPPINES PRIVACY OFFICER AND THE CURRENT COMPLAINT/ESCALATION DETAILS.]
10.3 South Korea
For users in South Korea, AZDEELA will provide the rights and disclosures required by applicable Korean privacy law and Samsung distribution requirements. Requests may be sent to [email protected].
[CONFIRM KOREA-SPECIFIC REPRESENTATIVE, DISCLOSURE, RETENTION, AND CROSS-BORDER TRANSFER REQUIREMENTS.]
10.4 Saudi Arabia and the United Arab Emirates
For users in Saudi Arabia and the United Arab Emirates, AZDEELA will apply the rights, notices, consent requirements, and cross-border transfer safeguards required by applicable local law.
[CONFIRM LOCAL REPRESENTATIVE, PROCESSING REGISTER, TRANSFER MECHANISM, AND COMPLAINT DETAILS FOR EACH MARKET.]
10.5 United States and other jurisdictions
Residents of jurisdictions with additional privacy laws may have further rights, including rights concerning access, deletion, correction, opt-out of targeted advertising or sale/sharing, and appeal. AZDEELA will provide the notices and mechanisms required by the law applicable to the individual and the relevant processing.
[CONFIRM WHETHER AZDEELA IS SUBJECT TO US STATE PRIVACY LAWS AND ADD THE REQUIRED NOTICE-AT-COLLECTION AND OPT-OUT DETAILS.]
11. Children's privacy
The Services are business and digital-out-of-home advertising tools and are not directed to children. We do not knowingly request or collect personal information from children in violation of applicable law. If you believe a child has provided personal information to us, contact [email protected] so we can investigate and take appropriate action.
12. Third-party services and links
The Services may use or link to third-party services, including payment providers, object storage, mapping/geocoding services, video hosts, and external websites. Their privacy practices are governed by their own notices. AZDEELA is not responsible for the privacy or security practices of third-party services that it does not control.
Before publication, add a production vendor list and links to the applicable provider privacy notices:
We may update this Privacy Policy when the Services, processing practices, vendors, or legal requirements change. We will publish the updated version through the Services and update the effective date. Where required, we will provide additional notice or request consent.