PRIVACY POLICY
Introduction and Scope
- This Privacy Policy ("Policy") describes how Botan App Limited ("Company", "we", "us", or "our") handles data in connection with the API Client and its use of the YouTube Data API v3 and the Google Ads API. It is published in support of, and applies to, our use of Google API Services. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- The API Client is an internal automation service used exclusively by our MarTech automation engineering team. It is not a public-facing product, it is not distributed to third parties, it is not publicly accessible, and it has no external end users. Our relationship with YouTube is exclusively that of an advertiser distributing original content.
- If you have any questions regarding this Policy, please contact us at finance@botanapp.com.
Data We Access and Process
The API Client performs a single function: publishing finished video files to YouTube channels that we own and/or operate, via the videos.insert method of the YouTube Data API v3. It does not collect personal data from any individual and it does not maintain user accounts.
- Google account credentials and authorization data.
To publish videos to channels, the API Client authenticates using OAuth 2.0. In this process we handle authorization credentials (OAuth tokens, including access and refresh tokens) associated with the Google accounts that own and/or operate and administer our YouTube channels. These credentials are used solely to authorize uploads to channels and are not used for any other purpose.
- Content we upload.
The content processed by the API Client consists exclusively of finished advertising video creatives produced in-house, together with the video metadata we assign to them at upload (such as title, description, and privacy status). All such content is owned by us or by the Clients on whose behalf we act, and is uploaded to channels we own and/or operate.
- Data we do NOT access.
The API Client calls no read or discovery endpoints. It does not call videos.list, search.list, channels.list, commentThreads.list, captions, the YouTube Analytics API, or any other read or discovery endpoint. It does not access, list, aggregate, store, or display content, metadata, comments, statistics, or any other data belonging to any channel, video, or user that we do not own and operate. It does not access personal information of YouTube viewers or of any other YouTube users.
How We Use Data
- We use the data described above solely for the following purposes:
- To authenticate and authorize uploads of video creatives to YouTube channels;
- To publish those creatives as Unlisted videos, so that they are not publicly searchable and are usable only as ad assets;
- To obtain the resulting video identifier and reference it when creating or updating Demand Gen ad groups and video ads through the Google Ads API.
- We do not use Google user data for advertising profiling, we do not sell it, we do not transfer it to data brokers or other third parties, and we do not use it to train, develop, or improve generalized or standalone machine learning or artificial intelligence models. Use of YouTube data is limited to the operations expressly described in this Policy.
Data Sharing and Disclosure
- The API Client is not distributed to third parties and is not publicly accessible. We do not share OAuth credentials or any Google API data with third parties, except with infrastructure and processing providers strictly necessary to operate the service (for example, our self-hosted workflow orchestration environment and the storage from which finished creatives are retrieved), and except where disclosure is required by applicable law. Any such providers act under agreements that restrict their use of data to the provision of services to us.
Data Retention and Security
- OAuth credentials are retained only for as long as necessary to operate the API Client and are revocable at any time through the associated Google account. Video creatives, once uploaded, reside on our YouTube channels and are managed by us in the ordinary course of our advertising operations. We apply administrative, technical, and organizational safeguards appropriate to an internal automation service, including restricting access to the API Client and its credentials to authorized members of our engineering team.
Revoking Access and Data Deletion
- The Google accounts that own our channels can revoke the API Client’s access at any time through the Google Account permissions page (https://myaccount.google.com/permissions). Upon revocation, the corresponding OAuth tokens cease to function and are deleted from our systems. Authorization credentials may also be deleted on request by contacting us at the address below.
International Data Transfers
- Botan is established in the Republic of Cyprus (European Union). Because the service relies on Google API Services, limited data (such as OAuth authorization data and the content we upload) may be processed by Google on infrastructure located outside the EU, including in the United States. Where such transfers occur, they are carried out under appropriate safeguards recognized under applicable data protection law.
Your Rights
- Where applicable data protection law (including the EU General Data Protection Regulation) grants rights over personal data, these may include the right to access, rectify, or erase data, to restrict or object to its processing, and to data portability. Given the internal, upload-only nature of the API Client, the only personal data we hold in this context is the authorization data of our own account holders. To exercise any right, contact us at the address below; you also have the right to lodge a complaint with a supervisory authority.
Google API Services User Data Policy – Limited Use
- Botan’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Consistent with those requirements, information obtained through Google APIs is used only to provide and improve the specific, user-facing functionality described in this Policy and is not used for any other purpose.
Children’s Privacy
- The API Client is an internal engineering tool with no external users and is not directed to children. It does not knowingly collect personal information from children.
Changes to This Policy
- We may update this Privacy Policy from time to time. Any changes will be posted at the URL where this Policy is published, with an updated effective date.
Contact Information
Registered office: Archiepiskopou Makariou III, 95 Charitini Building, 1st floor, Flat/office 102, 1071 Nicosia, Cyprus
Website: https://botanappltd.com
Contact email: finance@botanapp.com