Creative Factory Privacy Policy
How We Are 365 LLC handles personal data in the Creative Factory application.
Version 2.0 Effective 09/14/2026 Applies to Creative Factory only
What this covers
Creative Factory, the application that turns a retailer's published brochures into advertising images, as deployed for pilot and partner customers.
Whose data
The people who sign in to the application — staff of our partners, of participating retailers, and of We Are 365. Never the retailer's shoppers or end consumers.
Our role
Controller for operator account data; processor for the retailer content that operators work with.
Where
Google Cloud, us-central1 (Iowa, United States). Image generation by OpenAI in the United States.
Not done
No shopper data, no tracking, no advertising or analytics cookies, no model training, no sale of personal data, no connection to any advertising platform.
Contact
1 Scope of this notice
This notice applies only to the Creative Factory application. It does not cover the WeAre365 website, our publisher site network, or our advertising services, which are covered by the WeAre365 privacy policy at weare365.io/privacy-policy. Where an engagement is governed by a pilot or partner agreement and its data processing addendum, that agreement prevails over this notice as between us and the customer; this notice describes the processing to the individuals affected by it.
2 Who is responsible
Creative Factory is operated by We Are 365 LLC (trading as AdGoat), 800 SE 4th Ave, Hallandale Beach, FL 33009, United States. We Are 365 also has offices in Rosario and Buenos Aires, Argentina.
We Are 365 is responsible, as controller, for the processing of the account data of the people who sign in to the application (operators). The retailer content that operators work with — brochures, product data, logos, campaign copy — is processed on behalf of the customer, as processor, under the pilot or partner agreement and its data processing addendum.
Privacy contact: hello@weare365.io.
3 What the application does
Creative Factory reads a retailer's published brochures and the products tagged on them, lets an authorised operator select pages, products, logos and campaign copy, and generates advertising images in the formats the operator chooses. Every generated image is reviewed by the operator before download. Nothing is published automatically, no advertising platform is connected to the application, and the application writes nothing back to the retailer's or the publishing platform's systems.
The application has no consumer-facing component. It does not receive, build, buy or enrich shopper profiles, audience segments, identifiers or tracking data.
4 What personal data is processed
Operator account data
On sign-in the application receives from Google the account identifier and the email address of the person signing in. It records the first and last sign-in and which deployments the person has used. This is the only personal data the application collects about individuals, and it concerns partner and pilot staff.
Operator activity
Projects created by the operator (name, campaign type, target platforms, selected pages and products, headlines, brief, call-to-action, disclaimer, store context, sizes, status); review verdicts on generated creatives with the reviewer's email; and an operational log entry per generated creative containing the operator's email and account identifier, the texts typed into the free-text fields, product identifiers, the publication reference, token usage, cost and errors.
Technical request data
The hosting infrastructure's access logs record standard technical data such as IP address, user agent and timestamps.
Retailer content
Brochure pages selected by the operator, rasterised to images; product records read from the publishing platform (name, description, price, brand, availability, photo, webshop link and identifier); logos uploaded by the operator; and the retailer's brand guidance where provided. This content is the retailer's published marketing material. It contains personal data only if the retailer placed it there, or if an operator typed it into a free-text field.
No special categories of personal data, payment data or government identifiers are processed. The application is not directed to anyone under 18.
5 Where the data comes from
Google sign-in
The application sits behind Google Cloud Identity-Aware Proxy and has no public endpoint. Access is granted per deployment through a list maintained as infrastructure code. The application requests no OAuth scopes on the person's Google account and cannot read Gmail, Drive, Calendar, Contacts or any other Google service.
Publishing platform connection
Through the publishing platform's partner API, read-only, the application reads the content of retailers that enabled content sharing with We Are 365 in their own account: publications that are online or scheduled, their pages, and the products tagged on them. A second credential reads the location of the retailer's product feed. If the retailer has not enabled sharing, its catalogue does not load; if sharing is switched off, the content is no longer readable. The connection cannot access shopper or end-consumer data, viewing statistics, platform account users, or billing. Each deployment additionally carries a server-side allowlist of group ids; anything outside it is not served.
Operator input
Text typed into the application and files uploaded by the operator.
6 Purposes and legal bases
Operator account data is processed to authenticate requests, to keep each person's projects separate, to attribute review verdicts and generation cost, to monitor the service and to diagnose incidents. The legal bases are the performance of the agreement under which the person was given access, and our legitimate interest in the security and operation of the service.
Retailer content is processed solely to provide the service requested by the customer, on the customer's documented instructions.
We do not use any data from this application for our own analytics, benchmarking, product research, advertising, or for training or fine-tuning any model.
7 Use of artificial intelligence
Creative Factory generates images with OpenAI's image editing API (model gpt-image-2). For each creative the application sends: the prompt text it assembles, including the operator's brief, headlines, call-to-action, disclaimer, store context and the retailer's brand guidance; the selected brochure pages as images; the selected product images; and the logos. It does not send the operator's identity, email or account identifier, platform credentials, product links or project identifiers. The request carries no user identifier, cookies or forwarded headers; the OpenAI credential is held on the server and the browser never contacts OpenAI.
Under OpenAI's API terms, content sent to the API is not used to train OpenAI's models, and may be retained for up to 30 days for abuse monitoring. We Are 365 has executed OpenAI's Data Processing Addendum and has applied for Zero Data Retention on the endpoint in use, which removes that retention window. Customers will be informed of the outcome. OpenAI is the only AI provider used by the application.
8 Recipients
Recipient
What it receives, and why
Google Cloud
United States
Hosting, database, file storage, secrets, logs and sign-in. Everything stored by the application. Engaged under Google's data processing addendum with the EU Standard Contractual Clauses.
OpenAI
United States
Image generation, as described in section 7. Engaged under OpenAI's Data Processing Addendum with the EU Standard Contractual Clauses.
Publishing platform
Customer's own system
Source of retailer content. Receives read requests identified by group and publication ids only.
Retailer systems
Customer's own system
The retailer's content delivery network and, where configured, its SFTP server: product images and the product feed, read by our server.
GitHub
United States
Build pipeline. Source code only; no customer content and no personal data from the application.
The application contains no third-party analytics, advertising or tracking tools. We do not sell personal data and do not share it for cross-context behavioural advertising. Beyond the recipients above we disclose personal data only to our professional advisers under confidentiality, and where we are compelled by law — in which case we notify the customer unless legally prohibited. Any new provider is notified to customers in advance, in accordance with the applicable agreement.
9 Where data is stored, and international transfers
All storage and processing by We Are 365 takes place in Google Cloud region us-central1 (Iowa, United States), in a single project and region. OpenAI processes generation requests in the United States. An EU-region deployment can be provisioned for an engagement when agreed before onboarding.
Content read from the publishing platform is therefore transferred to the United States. Transfers of personal data from the EEA, the United Kingdom or Switzerland rely on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum and the Swiss annex where applicable, as set out in the data processing addendum for each engagement and in our agreements with the providers named in section 8.
Access to the underlying cloud project is limited to a small number of named We Are 365 staff, located in the United States and in Argentina. Argentina is recognised by the European Commission as providing an adequate level of data protection.
10 Retention and deletion
-
Operators can delete a project, or a single creative, at any time. Deletion is restricted to the project's owner and removes the project, its generation runs, every creative and its files.
-
Shared retailer assets (logos, rasterised pages) remain only while another project of the same retailer still uses them.
-
The brochure PDF is held in server memory for at most 15 minutes and is never stored. Product images are fetched from the retailer at each generation and never stored. The product feed and any credentials in its location are held in memory only.
-
Deleted files remain recoverable by We Are 365 for 7 days through the storage platform's soft-delete behaviour, after which they are gone.
-
Operational log entries expire automatically after 30 days. Google Cloud admin activity audit logs, which record configuration and permission changes rather than content, are retained for 400 days by the platform.
-
Unless the applicable agreement provides otherwise, the entire workspace is deleted within 30 days after the engagement ends, or earlier on the customer's written request, with written confirmation.
-
Deletion of a specific person's account record and projects is honoured on request.
Creatives that an operator has downloaded are held by that person on their own systems and are outside our control.
11 Security
Every request must pass Google's sign-in and is verified by the server against a token signed by Google. The browser holds no cloud credentials; all reads and writes go through the server, and no public or signed links to stored files exist. Credentials for the publishing platform and for OpenAI are stored in a secrets manager and never reach the browser. Uploaded files are validated before storage and stripped of metadata. Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256) by the hosting platform. Access to the application and to the cloud project is granted per named person and managed as infrastructure code, so every change carries a reviewer and a date.
We Are 365 does not hold an ISO 27001 certificate or a SOC 2 report at this time. Our controls are documented in a security assessment available to customers under confidentiality.
No system is perfectly secure. If a breach affecting customer data occurs, we notify the affected customer within 24 hours of becoming aware of it, and cooperate with any notification the customer must make to a regulator or to affected individuals.
12 Cookies
The application uses only strictly necessary cookies: the session cookies set by Google Cloud Identity-Aware Proxy to keep the person signed in, and a cookie that remembers the chosen interface language. No advertising or analytics cookies are used, and no consent banner is required for them.
13 Rights of individuals
Operators may request access to, rectification or deletion of their account data, restriction of or objection to its processing, and a copy of it in a portable format, by writing to hello@weare365.io. We respond within one month and may ask for information needed to verify identity. There is no charge.
Requests concerning retailer content are handled with the customer, who decides how that content is processed. If you send such a request to us, we forward it to the customer without undue delay and assist them in answering it.
Individuals in the European Union, the United Kingdom or Switzerland may also lodge a complaint with their local data protection authority. Where a United States state privacy law applies, individuals may request access to, correction of, or deletion of their personal data, and may appeal a refusal by replying to our decision. We do not sell personal data or use it for targeted advertising. We do not discriminate against anyone for exercising these rights.
14 Changes to this notice
This notice is updated when the application, its providers or its hosting change. The version number and effective date at the top indicate the current version. Customers are informed in advance of any change that materially weakens the protections described here.