1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
smoox GmbH
represented by Managing Director Jörn Peter Rieberer
Weyerhofstr. 68
47803 Krefeld, Germany
Email: info@smoox.com
Data Protection Officer: Jörn Peter Rieberer, reachable at info@smoox.com.
2. Overview
We process personal data only to the extent necessary and in accordance with the GDPR and the German Federal Data Protection Act (BDSG). "Personal data" means all information relating to an identified or identifiable natural person. This policy applies to our website, our platform (dashboard) and our browser extension "CreativeRadar".
3. Your Rights
With respect to the personal data concerning you, you have the following rights against us:
- Right of access (Art. 15 GDPR),
- Right to rectification (Art. 16 GDPR),
- Right to erasure (Art. 17 GDPR),
- Right to restriction of processing (Art. 18 GDPR),
- Right to data portability (Art. 20 GDPR),
- Right to object to processing (Art. 21 GDPR),
- Right to withdraw consent (Art. 7 para. 3 GDPR).
To exercise these rights, an informal message to info@smoox.com is sufficient. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), e.g. the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
4. Hosting
Our website and platform are hosted by a service provider within the European Union: Host Europe GmbH, Hanseatenweg 8, 50130 Hürth, Germany. The provider processes server log files on our behalf (Art. 28 GDPR). The legal basis is our legitimate interest in the secure and efficient provision of the service (Art. 6 para. 1 lit. f GDPR).
5. Data Collection on the Website
Server Log Files
When the website is accessed, the provider automatically collects information in server log files that your browser transmits: browser type and version, operating system, referrer URL, hostname of the accessing device, time of the server request, and IP address. This data is not merged with other data sources. The legal basis is Art. 6 para. 1 lit. f GDPR (secure operation).
Contact
If you contact us by email, we process your details in order to handle your enquiry. The legal basis is Art. 6 para. 1 lit. b GDPR (pre-contractual/contractual) or lit. f GDPR (processing of enquiries).
6. Fonts
This website uses self-hosted fonts for consistent display. Font files are served exclusively from our own server. No connection to Google servers or other third parties is established; no IP address is transmitted to third parties. No consent is required for this.
7. Appointment Booking (Calendly)
We use Calendly (Calendly LLC, USA) for booking demo and introductory calls. When booking, Calendly processes the data you enter (e.g. name, email address, preferred time). The legal basis is Art. 6 para. 1 lit. b and lit. f GDPR. Data may be transferred to the USA; the basis for this is the EU Standard Contractual Clauses or the EU–US Data Privacy Framework. Details: calendly.com/privacy.
8. Browser Extension "CreativeRadar"
This section describes the data processing carried out by our browser extension. It also constitutes our privacy policy for publication in the Chrome Web Store.
8.1 Single Purpose
The extension serves a single purpose: detecting, capturing and documenting ad placements (ads/creatives) on websites to give marketing teams verifiable campaign visibility and quality assurance. The extension is a voluntary workplace tool provided by the employer or organisation.
8.2 Data Processed
- Captured ad creatives: image excerpts/screenshots of detected ads and associated technical metadata (e.g. ad format/size, publisher domain, timestamp, approximate geographic region).
- Account/assignment data: the identifier linked to your organisational account so that sightings can be assigned to the correct campaign.
- Technical operational data: diagnostic information required for stability and debugging.
Any text/image recognition (OCR) for quality-checking captured ad creatives is performed locally in the browser; no content is transmitted to external recognition services.
8.3 Data Explicitly NOT Processed
- no emails, messages, chats or content from web forms;
- no keystrokes, passwords or login credentials;
- no general browsing history or collection of browsing behaviour beyond ad detection;
- no access to CRM systems, internal applications or personal content of third parties;
- no sale or sharing of data for advertising or profiling purposes.
8.4 Permissions and Justification
| Permission | Why it is needed |
|---|---|
activeTab | Access to the active tab to detect and capture ad placements on the currently visited page. |
tabs | Retrieving tab information (e.g. page URL and title) to assign a sighting to the correct publisher context. |
scripting | Injecting the detection logic into the page to identify ads. |
storage | Storing settings and captured sightings locally in the browser. |
webRequest | Observing network/ad requests to technically identify ad placements. |
offscreen | Running local image/text recognition (OCR) in a background document – processing takes place in the user's browser. |
alarms | Scheduled background tasks (e.g. planned review and clean-up operations). |
host_permissions (<all_urls>) | Ad creatives can appear on any publisher domain; access is used exclusively for ad detection and is functionally limited to this purpose. |
8.5 Legal Basis
Processing is based on Art. 6 para. 1 lit. f GDPR (legitimate interest in campaign verification and quality assurance) and – in relation to our business customers – within the framework of a data processing agreement (Art. 28 GDPR). Where consent is required, processing is based on Art. 6 para. 1 lit. a GDPR.
8.6 Storage Location & Security
Processing and storage take place exclusively on servers within the European Union. Transmission is encrypted (TLS). Access is role-based and restricted.
8.7 Limited Use (Chrome Web Store)
The use of information collected via the extension complies with the Chrome Web Store User Data Policy including the Limited Use requirements. In particular, collected data is used exclusively for the single purpose stated above, is not sold to data brokers, is not used for third-party advertising or profiling, and is not accessed by humans except as necessary to provide the service, for security purposes, or to comply with legal obligations.
8.8 Organisational Control
The monitored campaigns, brands and contexts are defined by the deploying organisation. The extension can be disabled or removed at any time via the browser settings.
9. Platform & Dashboard
For use of the dashboard we process account and usage data of authorised persons (e.g. name, business email, role, activity logs). The legal basis is Art. 6 para. 1 lit. b GDPR (contract performance) or Art. 28 GDPR in relation to the client.
10. Recipients & Third Countries
Data is shared only with carefully selected processors (e.g. hosting providers) with whom agreements pursuant to Art. 28 GDPR are in place. Transfers to third countries take place only where an adequacy decision exists or appropriate safeguards (EU Standard Contractual Clauses) have been agreed. An up-to-date list of processors is available on request.
11. Retention Period
We retain personal data only for as long as necessary for the purposes stated or as required by statutory retention obligations. Captured ad creatives and records are retained for the period agreed with the client and then deleted or anonymised.
12. Changes to this Policy
We update this privacy policy whenever changes to processing or legal requirements make it necessary. The version published on this page at any given time is the applicable one.
