Infrastructure and encryption
Izeme applies technical measures to protect information in transit and at rest, including encrypted connections via HTTPS/TLS across the website and application.
- Encrypted communications between the browser and our services.
- Protection of credentials and sensitive data stored on the platform.
- Access controls and periodic review of security best practices.
Data protection and compliance
Personal data is processed in accordance with the General Data Protection Regulation (GDPR) and applicable European law.
For purposes, legal bases, rights and retention, see our Privacy Policy. To request account or data deletion, use the Data deletion page.
Security architecture
The platform is designed with layered security controls aligned with common B2B SaaS practices and advertising API provider requirements:
- HTTPS/TLS to encrypt communications between clients and Izeme services.
- OAuth 2.0 authentication for integrations, with explicit user consent on the provider screen.
- Encrypted storage of OAuth access and refresh tokens while the integration remains active.
- Role-based access control (RBAC) and least-privilege principles for authorized personnel and internal systems.
- Multi-tenant architecture with logical isolation per organization (tenant): one agency’s data is not accessible to another.
- Separation of environments and operational privileges to reduce incident impact.
- Regular backups of production environments.
- Operational monitoring of availability, errors and abuse signals.
- Audit logs oriented to traceability of relevant administrative access and actions.
This model reduces the risk of cross-account access and simplifies permission management per organisation.
Integrations and OAuth
Connections to external providers (Google Ads, Meta Ads, TikTok Ads, Google Calendar and others) use OAuth 2.0 and require explicit user consent.
- Users own the accounts they connect; Izeme acts as an authorized tool.
- Access tokens are stored in encrypted form.
- Integrations can be revoked at any time from app.izeme.io or from the provider account.
Technical details on the Integrations and Product pages.
Incident management
Izeme maintains an internal process for responding to security or availability incidents, aimed at containing impact and protecting customers:
- Detection: monitoring of alerts, access anomalies and abuse or service-failure signals.
- Investigation: analysis of scope, affected systems and possible data exposure.
- Containment: revocation of compromised tokens, credential rotation and access restriction where appropriate.
- Recovery: service restoration from backups and verification of operational integrity.
- Notification: communication to users and authorities when required by applicable law (including the GDPR).
To report a security incident, contact immediately: admin@izeme.io
Legal documentation
You can review our policies and terms at any time:
Contact
For security or data protection enquiries, contact Izeme at: admin@izeme.io
