How we handle your data
Cezium Ads moves hashed audience identifiers from Salesforce Marketing Cloud to advertising platforms. Hashing happens inside Marketing Cloud; Cezium never receives raw contact data and does not store hashed identifiers. Cezium stores only your configuration, connection tokens, sync and audit logs, and aggregated campaign metrics. This page states exactly what is stored, for how long, who processes it, and what happens when you leave.
Last Updated: September 24th, 2026
Cezium Ads (“Cezium”, “we”, “our”) provides a plug-and-play integration between Salesforce Marketing Cloud and advertising platforms (Meta Ads, Google Ads, X Ads, TikTok Ads, Snapchat Ads, Pinterest Ads, LINE Ads, LinkedIn Ads).
This Privacy Policy describes how we handle data when you use Cezium Ads or visit our website.
1. Data We Collect
1.1. Data You Provide
- Contact information (name, email, company, role): when you sign up, request a demo, or contact support.
- Support and communication records
1.2. Data Processed Through the Cezium Ads Integration
Cezium Ads facilitates audience activation and campaign syncing between Salesforce Marketing Cloud and advertising platforms.
To do this, we process certain data strictly as a processor acting on your instruction.
We process:
- Hashed marketing contact identifiers (e.g., email, phone)
- Hashing is performed inside Salesforce Marketing Cloud before the data flows through Cezium systems.
- We never receive or process raw identifiers.
- We do not attempt to re-identify hashed values.
- Configuration metadata (audience mappings, field mappings)
- Authentication tokens connecting Salesforce Marketing Cloud and ad platforms
- Sync logs and events (status, timestamps, API responses)
- Aggregated campaign performance metrics (impressions, clicks, conversions, spend)
We do not store or access your raw marketing contact data.
We act as a processor on your documented instructions under our Data Processing Agreement. Users and permissions are inherited from Salesforce Marketing Cloud; Cezium keeps no separate user directory.
1.3. Website Analytics
We collect standard analytics data when you visit cezium.store:
- IP address
- Browser/device details
- Page activity
This is used to improve our site.
2. How We Use Data
We use data to:
- Enable and operate the Cezium Ads integration
- Process hashed identifiers for audience matching
- Manage authentication between systems
- Display performance reporting
- Provide customer support
- Enhance reliability and security
We never sell customer data or use your data for our own advertising.
3. Data Sharing
We may share limited information with:
- Ad platforms, but only hashed identifiers, metadata, and configuration you define
- Salesforce Marketing Cloud, as required for processing
- Service providers (hosting, logging, analytics)
- Regulators, when legally required
We never share raw marketing contact data.
4. Data Retention and Deletion
4.1. What we store, and for how long
- Raw identifiers (emails, phone numbers, names): never received. Hashing is performed in Salesforce Marketing Cloud before data reaches Cezium.
- Hashed identifiers: processed in memory during a sync, not written to storage.
- Configuration (audience, field, Business Unit and ad-account mappings): retained for the life of your subscription, encrypted at rest.
- Connection tokens (Marketing Cloud, ad platforms): retained encrypted for the life of your subscription. You can revoke them at any time from Marketing Cloud or the ad platform; revocation stops syncs immediately.
- Sync logs (status, timestamps, API responses): 90 days, then deleted automatically.
- Audit logs (who changed which mapping or connection, and when): 12 months.
- Aggregated campaign metrics: not personal data; retained for the life of your subscription.
- Backups: encrypted at rest, retained 30 days, then expired automatically.
4.2. When your subscription ends
Within 30 days of termination we delete your configuration and connection tokens. Sync logs expire on their normal 90-day schedule. Backups expire within a further 30 days, so nothing remains after 60 days. Because Cezium holds no raw or hashed contact data, there is no audience data to return or destroy; your audiences remain in Marketing Cloud and the ad platforms under your control. Written confirmation of deletion is available on request to privacy@cezium.store.
5. Data Security
We use industry-standard safeguards:
- Encryption in transit and at rest
- Secure token storage
- Zero raw contact data retention
- Role-based access controls
- Continuous monitoring
6. Where Data Is Processed and by Whom
Cezium Ads runs on Google Cloud, in EU and US regions. Google Cloud is our sub-processor for hosting, storage and logging. A current list of any additional sub-processors is available on request. All sub-processors are bound by Data Processing Agreements; transfers outside the EU/UK rely on Standard Contractual Clauses (SCCs). A signed DPA is available on request.
7. Your Rights
Depending on your region (EU/UK/California/etc.), you may:
- Request access, correction, or deletion
- Request data portability
- Object to certain processing
- Request restrictions
Contact privacy@cezium.store to exercise your rights.
We acknowledge requests within 5 business days and fulfil them within 30 days. Requests about individual contacts should be made in Salesforce Marketing Cloud and the ad platform, where the data lives; Cezium retains nothing about individual contacts to access or delete.
7A. Security Incidents
If we confirm a security incident affecting your data, we notify affected customers without undue delay and no later than 72 hours after confirmation, stating what happened, which data was involved, and the steps taken.
8. Children’s Privacy
Cezium is a B2B product not intended for children under 16.
We do not knowingly collect children’s data.
9. Policy Updates
We may update this Privacy Policy from time to time.
Changes will be posted with a new “Last Updated” date.