Legal · AZDEELA

AZDEELA Privacy Policy

How we collect, use, share, and protect information across the Adzeela digital out-of-home advertising platform, API services, and Adzeela Player for Samsung Tizen TVs.

Draft status: Legal and operational review required before publication Effective date: August 7, 2026 Last updated: August 7, 2026

AZDEELA ("AZDEELA," "we," "us," or "our") operates the Adzeela digital out-of-home advertising platform, including the Adzeela web application, API services, and Adzeela Player for Samsung Tizen TVs (collectively, the "Services"). This Privacy Policy explains what information we collect, how we use it, when we share it, how we protect it, and the choices available to individuals who use or interact with the Services.

Legal review notice: This is a technical first draft based on the current application implementation. It is not legal advice and is not a substitute for review by qualified privacy counsel in each market where AZDEELA operates. Complete all [INSERT] and [CONFIRM] fields before publishing.

1. Controller and contact information

  • Data controller / sellerAZDEELA
  • Privacy contact[email protected]
  • Registered address2402 Arellano Ave. Malate Manila
  • Country of registrationPhilippines
  • Privacy representative / DPO[INSERT NAME OR STATE "NOT APPLICABLE" AFTER REVIEW]

For privacy questions, requests, or complaints, contact [email protected]. We may request information needed to verify the identity and authority of a person making a request.

2. Services covered by this policy

This policy applies to:

  • The Adzeela web application and dashboards.
  • The Adzeela API, authentication, real-time connections, and storage services.
  • Adzeela Player running on Samsung Tizen TVs.
  • Screen registration, pairing, playback, campaign, creative, queue, promoter, territory, wallet, and analytics workflows.
  • Support communications relating to the Services.

This policy does not automatically apply to third-party websites, payment pages, video hosts, mapping services, or other services linked from or used by the Services. Those providers publish their own privacy notices.

3. Information we collect

The exact information collected depends on the role a person has and the features used.

3.1 Account and identity information

When an account is created or managed, we may collect:

  • Name.
  • Email address.
  • Phone number, if provided.
  • Avatar URL or profile image, if provided.
  • Account role, status, agency, promoter, advertiser, territory, or partner association.
  • Invitation and registration information.
  • Password credentials in protected form. We store password hashes rather than plaintext passwords.

We do not intentionally collect a user's password in readable form.

3.2 Business, campaign, and content information

Depending on the account role and workflow, we may collect:

  • Agency, advertiser, promoter, territory, venue, and screen details.
  • Campaign names, descriptions, brands, objectives, targeting, schedules, budgets, and related configuration.
  • Creative names, content types, file names, media metadata, destination URLs, and review notes.
  • Uploaded images and videos used as advertising or promoter content.
  • Loop, slot, screen-layout, queue, announcement, and playback configuration.
  • Contact person, contact number, and contact email included in barter or advertising workflows.
  • Territory invitations and related email addresses.

Do not upload personal information, confidential information, or third-party content unless you have the legal right and appropriate notice or consent to do so.

3.3 Promoter and profile information

Promoter workflows may collect additional profile information such as:

  • Business and profile details.
  • Optional alternate phone number.
  • Optional address.
  • Optional date of birth.
  • Optional gender.
  • Territory and business associations.

Only provide optional profile information when it is necessary for the relevant business relationship or service feature. [CONFIRM WHETHER DATE OF BIRTH AND GENDER ARE ENABLED IN PRODUCTION AND WHETHER THEY ARE REQUIRED.]

3.4 Screen and location information

For screen management, we may collect:

  • Screen name and serial number.
  • Venue name and descriptive location.
  • Screen resolution and orientation.
  • Latitude and longitude, when an operator provides or selects a screen location.
  • Time zone, announcement text, tags, and layout configuration.
  • Screen approval, availability, heartbeat, and operational status.

The location features are intended to describe the placement of an advertising display or venue. They are not intended to continuously track a TV viewer's physical location.

3.5 Samsung Tizen device information

When Adzeela Player runs on a Samsung Tizen TV, it may collect:

  • The Samsung TV device identifier (DUID), when the platform makes it available.
  • A SHA-256 hash derived from that identifier for screen registration and pairing.
  • A locally generated random UUID fallback if the platform identifier is unavailable.
  • Browser or runtime user-agent information.
  • Display resolution, orientation, color depth, language, hardware concurrency, and device-memory information when available to the web player.
  • Local storage data used to preserve the screen identity and support offline playback.
  • Player session, connectivity, synchronization, heartbeat, playback, and impression events.

The raw Samsung DUID is not intentionally sent to the AZDEELA API by the Tizen wrapper; the wrapper hashes the identifier and sends the resulting device identifier to the web player for screen bootstrap. The hash is used to identify a registered screen, not to identify a TV viewer by name.

3.6 Usage, playback, and analytics information

We may collect operational and usage information such as:

  • Login and authentication events.
  • Screen registration, pairing, approval, connection, and heartbeat events.
  • Manifest retrieval and synchronization events.
  • Creative playback facts, campaign impressions, popup impressions, completion state, and timing information.
  • Online/offline transitions and cache synchronization state.
  • Actions taken in campaign, creative, screen, loop, queue, wallet, and administration workflows.
  • Error, diagnostic, and security information needed to operate and protect the Services.

This data is associated primarily with accounts, screens, campaigns, creatives, or operational records. [CONFIRM WHETHER SERVER ACCESS LOGS RETAIN IP ADDRESSES, REQUEST HEADERS, OR OTHER NETWORK IDENTIFIERS AND ADD THE APPLICABLE RETENTION PERIOD.]

3.7 Wallet and payment information

The platform includes wallet and payment workflows. We may collect and retain:

  • Wallet owner and account association.
  • Amount, currency, balance, held amount, spent amount, and ledger entries.
  • Payment attempt status and timestamps.
  • Payment provider name, provider reference, provider payment ID, checkout URL, and webhook event metadata.
  • Commission, revenue-share, and settlement-related records where applicable.

Payment credentials such as full card numbers should be handled by the payment provider rather than stored by AZDEELA. [CONFIRM THIS AGAINST THE PRODUCTION PAYMENT INTEGRATION AND CONTRACTS.]

3.8 Support and communications

If you contact us, we may collect:

  • Your name, email address, phone number, and the contents of your message.
  • Account, screen, campaign, payment, or technical details needed to investigate the request.
  • Attachments or other information that you voluntarily provide.

Please do not include passwords, access tokens, payment-card numbers, or other unnecessary sensitive information in support requests.

3.9 Cookies, local storage, and similar technologies

We use technologies necessary to provide and secure the Services, including:

  • HTTP-only, secure authentication cookies for access and refresh sessions.
  • Local storage for a Tizen screen's fallback device UUID and player bootstrap state.
  • Browser storage and cache mechanisms for offline manifests and media playback.
  • Session and security data used to authenticate requests, revoke sessions, prevent abuse, and maintain service reliability.

[CONFIRM WHETHER THE WEB APPLICATION USES ANY NON-ESSENTIAL ANALYTICS, ADVERTISING, OR TRACKING COOKIES. IF SO, ADD A COOKIE-CONSENT SECTION AND COOKIE TABLE.]

4. How we use information

We use information for the following purposes:

  • Create, authenticate, maintain, and secure accounts.
  • Provide role-based access to dashboards and workflows.
  • Register, pair, approve, monitor, and operate advertising screens.
  • Deliver manifests, creatives, announcements, queue information, and layouts to authorized players.
  • Cache and synchronize content for offline-capable playback.
  • Schedule, review, approve, reject, deliver, and report advertising and promoter content.
  • Process wallet, payment, ledger, commission, and settlement workflows.
  • Provide analytics, impression reporting, playback reporting, diagnostics, and operational monitoring.
  • Respond to support requests and communicate about the Services.
  • Detect, prevent, investigate, and respond to fraud, misuse, security incidents, and violations of our terms.
  • Comply with legal, accounting, tax, regulatory, court, and law-enforcement obligations.
  • Improve the reliability, security, accessibility, and performance of the Services.

We do not use the Samsung Tizen device identifier to identify a TV viewer as a named individual. It is used to associate a player installation with a registered screen.

5. Legal bases for processing

Where privacy law requires a legal basis, we generally rely on one or more of the following:

  • Contract: to create accounts, provide the requested Services, operate screens, manage campaigns, and perform wallet or payment workflows.
  • Legitimate interests: to secure the Services, prevent abuse, maintain reliability, provide operational telemetry, and improve the platform, balanced against individual privacy rights.
  • Legal obligation: to maintain accounting, payment, tax, audit, fraud-prevention, and legally required records.
  • Consent: where required for optional communications, non-essential cookies, or other optional processing.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that occurred before withdrawal or processing based on another lawful basis.

6. How we share information

We may share information in the following circumstances:

6.1 Service providers

We use vendors and infrastructure providers to operate the Services. Depending on the production configuration, these may include:

  • Cloud hosting, database, cache, monitoring, and security providers.
  • S3-compatible object storage, including Cloudflare R2 in production or MinIO in local development, for advertising media and related assets.
  • Payment providers, including Xendit where enabled, for payment checkout and payment-status processing.
  • OpenStreetMap/Nominatim or another configured geocoding provider for operator-entered location searches.
  • YouTube or another media provider when an advertiser intentionally uses an externally hosted creative or embedded video.
  • Email, support, communications, and notification providers if enabled in the production deployment.

Providers may process information on our instructions, under their own terms, or as independent controllers where applicable. [INSERT PRODUCTION VENDOR LIST, PROCESSOR AGREEMENTS, AND DATA-LOCATION DETAILS.]

6.2 Business users and screen operators

Information may be visible to authorized advertisers, agencies, promoters, territory partners, and administrators when needed to operate the platform. Advertising creative and campaign information may be displayed on screens according to the configured campaign and screen permissions.

6.3 Legal and safety disclosures

We may disclose information where reasonably necessary to:

  • Comply with applicable law, legal process, or a valid governmental request.
  • Protect the rights, safety, property, and security of AZDEELA, users, the public, or the Services.
  • Investigate fraud, abuse, security incidents, or violations of agreements.
  • Enforce our terms and protect against legal claims.

6.4 Corporate transactions

Information may be transferred as part of a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality and legal protections.

We do not disclose personal information to third parties for their own direct marketing purposes unless this policy is updated and any legally required choice or consent is provided.

7. International transfers

AZDEELA and its service providers may process information in countries other than the country where it was collected. Where required, we use appropriate safeguards for cross-border transfers, which may include contractual protections, adequacy decisions, consent, or another legally recognized mechanism.

[INSERT PRIMARY HOSTING COUNTRY/COUNTRIES AND THE TRANSFER MECHANISMS USED FOR EACH RELEVANT REGION.]

8. Data retention

We retain information only for as long as reasonably necessary for the purposes described in this policy, including providing the Services, resolving disputes, enforcing agreements, maintaining security, and meeting legal, accounting, tax, and regulatory requirements.

The final production policy must include or link to an approved retention schedule. Complete the following before publication:

Information typeProposed retention ruleStatus
Account and profile dataWhile the account is active, plus [PERIOD] after closure[CONFIRM]
Authentication and security records[PERIOD] based on security and legal requirements[CONFIRM]
Screen registration and DUID hashWhile the screen is registered, plus [PERIOD] after de-registration[CONFIRM]
Heartbeat, playback, and impression data[PERIOD] for reporting, billing, and audit needs[CONFIRM]
Campaign and creative records[PERIOD] after campaign completion or account closure[CONFIRM]
Payment, wallet, ledger, and tax records[PERIOD] required by accounting and applicable law[CONFIRM]
Support communications[PERIOD] after resolution[CONFIRM]
BackupsDeleted or overwritten according to the backup rotation of [INSERT PROVIDER/POLICY][CONFIRM]

When information is no longer required, we delete it, anonymize it, or securely isolate it where deletion is not immediately possible.

9. Security

We use reasonable technical and organizational safeguards appropriate to the nature of the information and the risks involved. Current implementation safeguards include:

  • Password hashing rather than plaintext password storage.
  • HTTP-only and secure authentication cookies.
  • Short-lived access tokens and refresh-token rotation/revocation controls.
  • Role-based authorization for protected platform operations.
  • Presigned upload and download URLs for object storage.
  • Input validation and allowlists for supported media types.
  • HTTPS-only production configuration for the Tizen player and web application.
  • Rate limiting and security logging for selected API operations.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we will investigate and respond to suspected incidents as required by applicable law.

If you believe your account or information has been compromised, contact [email protected] promptly.

10. Your privacy rights

Depending on your location and applicable law, you may have rights to:

  • Know whether we process your personal information.
  • Request access to personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion or erasure, subject to legal and operational exceptions.
  • Request restriction of processing.
  • Object to processing based on legitimate interests or direct marketing.
  • Request portability of certain information.
  • Withdraw consent where processing is based on consent.
  • Opt out of certain marketing, sale, or sharing activities where applicable.
  • Lodge a complaint with the relevant data-protection authority.

To make a request, email [email protected] with the subject line Privacy Request. We may need to verify your identity before responding. We will not discriminate against you for exercising a privacy right.

10.1 European Economic Area, United Kingdom, and Switzerland

Where applicable, individuals in these regions may exercise rights under the GDPR, UK GDPR, or Swiss data-protection law. Requests may include access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also complain to your local supervisory authority.

[CONFIRM WHETHER AZDEELA HAS AN EU/UK REPRESENTATIVE OR DATA PROTECTION OFFICER OBLIGATION.]

10.2 Philippines

Where applicable, individuals may exercise rights under the Philippines Data Privacy Act and related regulations, including rights to access, correction, erasure or blocking where applicable, objection, data portability where applicable, and complaint. The AZDEELA privacy contact is [email protected].

[CONFIRM THE RESPONSIBLE PHILIPPINES PRIVACY OFFICER AND THE CURRENT COMPLAINT/ESCALATION DETAILS.]

10.3 South Korea

For users in South Korea, AZDEELA will provide the rights and disclosures required by applicable Korean privacy law and Samsung distribution requirements. Requests may be sent to [email protected].

[CONFIRM KOREA-SPECIFIC REPRESENTATIVE, DISCLOSURE, RETENTION, AND CROSS-BORDER TRANSFER REQUIREMENTS.]

10.4 Saudi Arabia and the United Arab Emirates

For users in Saudi Arabia and the United Arab Emirates, AZDEELA will apply the rights, notices, consent requirements, and cross-border transfer safeguards required by applicable local law.

[CONFIRM LOCAL REPRESENTATIVE, PROCESSING REGISTER, TRANSFER MECHANISM, AND COMPLAINT DETAILS FOR EACH MARKET.]

10.5 United States and other jurisdictions

Residents of jurisdictions with additional privacy laws may have further rights, including rights concerning access, deletion, correction, opt-out of targeted advertising or sale/sharing, and appeal. AZDEELA will provide the notices and mechanisms required by the law applicable to the individual and the relevant processing.

[CONFIRM WHETHER AZDEELA IS SUBJECT TO US STATE PRIVACY LAWS AND ADD THE REQUIRED NOTICE-AT-COLLECTION AND OPT-OUT DETAILS.]

11. Children's privacy

The Services are business and digital-out-of-home advertising tools and are not directed to children. We do not knowingly request or collect personal information from children in violation of applicable law. If you believe a child has provided personal information to us, contact [email protected] so we can investigate and take appropriate action.

12. Third-party services and links

The Services may use or link to third-party services, including payment providers, object storage, mapping/geocoding services, video hosts, and external websites. Their privacy practices are governed by their own notices. AZDEELA is not responsible for the privacy or security practices of third-party services that it does not control.

Before publication, add a production vendor list and links to the applicable provider privacy notices:

  • [INSERT CLOUD/HOSTING PROVIDER PRIVACY NOTICE]
  • [INSERT OBJECT STORAGE PROVIDER PRIVACY NOTICE]
  • [INSERT PAYMENT PROVIDER PRIVACY NOTICE]
  • [INSERT MAPPING/GEOCODING PROVIDER PRIVACY NOTICE]
  • [INSERT VIDEO HOST PRIVACY NOTICE, IF ENABLED]

13. Changes to this policy

We may update this Privacy Policy when the Services, processing practices, vendors, or legal requirements change. We will publish the updated version through the Services and update the effective date. Where required, we will provide additional notice or request consent.

14. Contact

For privacy questions, requests, or complaints:

Publication checklist

  • Insert effective date and last-updated date.
  • Insert registered company address and country of registration.
  • Confirm the privacy representative / DPO position.
  • Confirm whether promoter date-of-birth and gender fields are active in production.
  • Confirm server access-log fields, IP handling, and retention.
  • Confirm the production payment provider and payment-data boundary.
  • Confirm production hosting, storage, database, monitoring, email, and analytics vendors.
  • Confirm hosting countries and cross-border transfer mechanisms.
  • Complete the retention schedule.
  • Complete Philippines, Korea, Saudi Arabia, UAE, EEA/UK/Swiss, and US-specific reviews as applicable.
  • Add links to third-party privacy notices.
  • Publish the policy at a stable HTTPS URL linked from the web application and Seller Office submission.
  • Have qualified privacy counsel review and approve the final policy.

Implementation evidence used for this draft

  • Tizen DUID access, hashing, and local UUID fallback: apps/tizen/index.html, apps/tizen/src/device-id.js.
  • Tizen player configuration and production URL: apps/tizen/config.json.
  • Device pairing metadata: apps/web/app/composables/useScreenPairing.ts.
  • Device fingerprint handling: apps/web/app/composables/useDeviceFingerprint.ts.
  • Account fields: apps/api/src/modules/auth/models/user.model.ts.
  • Authentication cookies and token behavior: apps/api/src/modules/auth/auth.cookies.ts, apps/api/src/modules/auth/auth.service.ts.
  • Screen, location, and heartbeat behavior: apps/api/src/modules/screen/.
  • Wallet and payment-attempt records: apps/api/src/modules/wallet/.
  • Object storage and presigned URLs: apps/api/src/modules/storage/storage.service.ts.
  • Geocoding and OpenStreetMap/Nominatim use: apps/api/src/modules/geo/geo.service.ts.
  • Web player heartbeat, synchronization, and playback facts: apps/web/app/composables/useScreenPlayer.ts.

Questions about your data?

Our privacy team reviews every request. Email us with the subject line "Privacy Request" and we will respond as required by applicable law.

Contact [email protected]

© AZDEELA. All rights reserved. This document is a draft pending legal review.