Privacy Policy for NXTLI Ads Connector
Effective date: 3 September 2026
Last updated: 3 September 2026
This Privacy Policy explains how NXTLI BV (“NXTLI”, “we”, “us”, or “our”) processes information through NXTLI Ads Connector (the “Connector”).
This policy applies specifically to the Connector. Other NXTLI services and websites may be covered by separate privacy notices.
1. About NXTLI Ads Connector
NXTLI Ads Connector is an internal, business-to-business data connector used by NXTLI to retrieve advertising data from Meta’s Marketing API for clients that have authorized NXTLI to access their Meta ad accounts.
The Connector authenticates through an NXTLI-controlled system user within the NXTLI Meta Business account. A client or its authorized administrator must grant this system user access to the relevant client ad account.
The Connector does not have a public Facebook Login flow and is not offered directly to consumers.
NXTLI Ads Connector is read-only. It retrieves data for reporting, analytics, integration, and campaign-monitoring purposes. It does not create, change, pause, publish, or delete campaigns, ad sets, advertisements, creatives, or other Meta business assets.
2. Information We Process
Depending on the data streams enabled for a client, the Connector may process the following information:
Connection and authorization information:
Meta Business and ad-account identifiers, the NXTLI system-user identifier, access tokens, granted permissions, and connection settings required to authenticate API requests.
Ad-account information:
Account name, account identifier, status, currency, time zone, and related business-account metadata.
Campaign information:
Campaign, ad-set, advertisement, and creative identifiers and names; delivery status; objectives; schedules; budgets; bids; attribution settings; targeting configurations; and creative metadata or assets made available through the selected streams.
Performance and insights information:
Metrics such as impressions, reach, clicks, spend, frequency, actions, conversion metrics, attribution results, and configured reporting breakdowns.
Technical and operational information:
Synchronization times, connection and job identifiers, status information, API responses, error information, and other logs needed to operate, secure, and troubleshoot the Connector.
The exact fields processed depend on the Airbyte streams and reporting fields configured for the relevant client.
3. Information Outside the Connector’s Current Scope
NXTLI Ads Connector is not configured to retrieve:
- Lead-ad submissions;
- Custom audiences;
- Customer lists;
- Contact information belonging to individual leads or audience members; or
- Unrelated Facebook profile information.
The Connector does not collect browser information, cookies, or consumer-device information because it has no public user interface. The webpage on which this policy is published may be subject to NXTLI’s general website and cookie notices.
If NXTLI materially expands the Connector’s scope in the future, this Privacy Policy will be updated before the additional processing begins.
4. Meta Permissions
For its current functionality, the Connector requests only the following Meta permissions:
ads_read:
Used to read authorized ad-account, campaign, ad-set, advertisement, creative, and advertising-performance data.
business_management:
Used to identify and access Meta Business assets and ad accounts expressly assigned to the NXTLI system user. The Connector does not use this permission to modify a client’s business assets.
The Connector is not configured to request or use the ads_management permission.
NXTLI accesses only ad accounts that a client or its authorized administrator has expressly granted to the NXTLI system user. Neither permission is used to create, update, pause, publish, or delete Meta campaigns, advertisements, creatives, or business assets.
5. Why We Process Information
NXTLI processes the information described above to:
- Authenticate with Meta and maintain the authorized connection;
- Retrieve and consolidate Meta advertising data for the relevant client;
- Provide reporting, analytics, campaign monitoring, and related services requested by the client;
- Transfer data into the agreed NXTLI-managed data environment;
- Monitor synchronization jobs and investigate errors;
- Maintain the reliability and security of the Connector; and
- Respond to access, export, and deletion requests.
NXTLI does not use Connector data to advertise to individuals, create consumer profiles, sell data, or provide data to unrelated third parties for their own marketing purposes.
6. Privacy Roles and Legal Bases
For advertising data processed on a client’s instructions, the client is normally the data controller and NXTLI acts as its data processor or service provider.
NXTLI processes this data only to provide the contracted services and in accordance with the client’s instructions. Each client is responsible for ensuring that it has the authority and an appropriate legal basis to grant NXTLI access to its Meta ad accounts and instruct NXTLI to process the data.
Where NXTLI determines the purpose and means of processing limited administrative, security, connection-management, or request-handling information, NXTLI acts as the controller.
Depending on the circumstances, this processing is necessary to perform or administer the client contract and/or is based on NXTLI’s legitimate interests in providing, securing, documenting, and maintaining the reliability of the Connector.
7. How Information Is Processed and Stored
NXTLI uses a self-hosted Airbyte environment running on a server in the Netherlands to retrieve data from Meta’s Marketing API.
The retrieved data is transferred to NXTLI-controlled Google Cloud infrastructure configured in the European Union.
Airbyte is operated by NXTLI within its own environment and is not given independent rights to use client data. Google Cloud provides infrastructure and storage services to NXTLI under contractual data-protection obligations. Meta processes information as the source platform in accordance with its own terms and privacy policies.
Access to Connector data is limited to authorized NXTLI personnel and authorized representatives of the relevant client who require access for the purposes described in this policy.
NXTLI may disclose information where required by law, a binding legal process, or a competent authority, or where reasonably necessary to protect the security and legal rights of NXTLI, its clients, or others.
NXTLI does not sell or rent Connector data.
8. Security
NXTLI applies reasonable technical and organizational safeguards appropriate to the nature of the data. These include:
- Access restrictions and least-privilege controls;
- Protection of authentication credentials and access tokens;
- Encryption in transit and at rest where supported by the infrastructure; and
- Operational monitoring and logging.
No method of transmission or storage is completely secure. NXTLI therefore reviews its safeguards and limits access and retention to what is necessary for the Connector’s stated purposes.
9. Retention and Deletion
NXTLI retains imported Meta advertising data and connection information for the duration of the relevant client relationship, unless the client instructs NXTLI to delete it earlier and deletion is consistent with the applicable contract and law.
When the partnership ends:
- The client may request an export of its data during the offboarding process;
- After any requested export, NXTLI deletes the imported Meta advertising data and Connector credentials; or
- If no export is requested, NXTLI deletes the data directly.
In all cases, Connector data is deleted no later than 30 days after termination of the partnership.
NXTLI does not retain backups of Connector data beyond this 30-day period. Operational Airbyte job logs are normally retained for no more than 30 days.
This retention rule applies to data imported through the Connector and its credentials. NXTLI may separately retain contracts, invoices, correspondence, or records of completed requests where required by applicable law or covered by another NXTLI privacy notice. Such records are not used as Connector data.
10. How to Request Access, Export, or Deletion
A client, authorized representative, or other person whose information may be included in Connector data may request access, correction, export, restriction, or deletion by emailing:
simon@nxtli.com
Please use the subject line:
NXTLI Ads Connector privacy request
The request should include:
- The name of the client organization;
- The relevant Meta Business or ad-account identifier, if known;
- The nature of the request; and
- Contact information through which NXTLI can verify the requester’s identity and authority.
Requests are handled by Simon Veerman.
NXTLI may request additional information where reasonably necessary to verify the requester’s identity, authority, and connection to the relevant account.
Where NXTLI processes the data on behalf of a client acting as controller, NXTLI may refer the request to that client and will assist the client in responding.
NXTLI will respond within the period required by applicable law. A valid deletion request will normally be completed within 30 days unless applicable law requires or permits specific information to be retained. Termination-related deletion will always follow the schedule described in Section 9.
Clients may also stop further data collection by:
- Asking NXTLI to disable the relevant Airbyte connection; and/or
- Removing the NXTLI system user’s access to the relevant ad account through Meta Business settings.
11. Data-Protection Rights
Subject to the conditions and exceptions in applicable law, individuals may have the right to:
- Access their personal data;
- Correct inaccurate or incomplete personal data;
- Request deletion or restriction of processing;
- Receive certain personal data in a portable format; and
- Object to certain processing.
Where the relevant client is the controller, these rights should normally be exercised through that client. NXTLI will provide reasonable assistance to the client. Questions and requests may also be sent directly to NXTLI using the contact information below.
Individuals may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or another competent supervisory authority.
NXTLI does not use Connector data to make automated decisions about individuals that produce legal or similarly significant effects.
12. Changes to This Privacy Policy
NXTLI may update this Privacy Policy to reflect changes to the Connector, legal requirements, or NXTLI’s processing practices.
The current version will remain available through the public privacy-policy URL. The effective date at the beginning of this policy will be revised when material changes are made.
13. Contact
NXTLI BV
Attn: Simon Veerman
Keurenplein 41
1069 CD Amsterdam
Noord-Holland
The Netherlands
Email: simon@nxtli.com
