This policy explains how Regents Inc dba Gushwork ("Gushwork", "we", "us") handles information in Plethos, our managed Meta lead ads service for US businesses ("clients"), including the Plethos app on Meta. It applies alongside our website privacy policy. Where they differ, this policy governs data we receive from Meta.
1. Who we are
Regents Inc dba Gushwork
16192 Coastal Hwy, Lewes, DE 19958, United States
Privacy and data requests: admin@gushwork.ai
Sales: growth@gushwork.ai · Phone: +1 (888) 451 5522
2. Data we get from Meta
When a client connects Plethos through Facebook Login for Business ("Continue with Facebook"), or shares assets with Gushwork as a partner, and while that access is active, we receive:
| Data | Details |
|---|---|
| The person who connects | Facebook user ID and name. |
| Business assets | IDs and names of the client's business portfolio, Pages, Instagram accounts, ad accounts and datasets that the client selects, and Page details such as category, contact information and call-to-action button. |
| Advertising data | Campaigns, ad sets, ads, creative, instant forms, budgets, targeting settings, ad review status, account status, spending limit and payment status, and results such as spend, reach, clicks and leads. |
| Leads | Answers people submit in the client's lead forms, such as name, email, phone number, company and answers to form questions. |
| Access tokens | Tokens that let Plethos act only on the assets the client selected. They expire and are renewed every 60 days while the client stays connected. |
We do not receive the client's payment card details. Ads are paid for between the client and Meta.
3. Other data
- The client's brief: services, offers, buyers, locations, brand material and approvals.
- The client's website and SEO data, where Gushwork provides SEO services or the client shares it.
- Contact details of the client's team: names, emails and phone numbers.
4. Why we use it
We use the data only to provide Plethos to the client it belongs to:
- Running that client's ads: creating, launching, monitoring and improving campaigns and instant forms, and checking account health.
- Managing that client's Page: completing Page details and the call-to-action button, and publishing posts the client has agreed to.
- Delivering that client's leads to the destinations they choose, and scoring them for that client's own follow-up.
- When the client switches it on, sending lead outcomes (such as "qualified") back to that client's own Meta dataset to improve their ads.
- Reporting results to that client.
- Keeping the service secure and meeting legal obligations and Meta's platform terms.
5. Who we share it with
- The client's chosen destinations only: the email addresses, SMS numbers or CRM the client sets up to receive leads and reports.
- Service providers that process data only on our instructions, only to provide their service, and under written terms that require them to protect it and delete it when we stop using them: Amazon Web Services (hosting, storage and encryption), email and SMS providers that deliver leads and reports, and error tracking with personal data removed.
- Authorities, where the law requires it.
We never:
- sell data we receive from Meta, or share it for others' advertising;
- use one client's data or leads for another client or for Gushwork's own marketing;
- send data we receive from Meta to AI model providers, or use it to train AI models. Ad creative is drafted from the client's own brief;
- use data we receive from Meta to discriminate against people, to make decisions about eligibility for housing, employment, insurance, education, credit, government benefits or immigration, or for surveillance;
- combine one client's data with another client's, or build shared audiences across clients.
6. How long we keep it
| Data | Kept for |
|---|---|
| Leads | 90 days after delivery to the client. |
| Advertising data and results | The length of the client's contract. |
| Access tokens | Until the client disconnects Plethos or the contract ends, and replaced every 60 days while connected. |
| Audit logs of actions taken in the client's accounts | 12 months, for security and to answer the client's questions. |
| Everything above, when a client disconnects or leaves | Deleted within 30 days, except records we must keep by law, such as invoices. Scheduled jobs enforce these periods automatically. |
7. Security
- Data is stored on Amazon Web Services in the United States, encrypted at rest with managed keys. Access tokens and lead contact details are encrypted again with a separate key.
- Data is encrypted in transit with TLS 1.2 or higher.
- Access tokens and our app secret are kept in a secrets manager and are never placed in browser code, web addresses or logs.
- Only staff who work on a client's account can reach its data, using single sign-on with multi-factor authentication. Access is reviewed regularly and removed the day someone leaves. Staff do not keep Meta data on laptops or phones.
- Systems are scanned for vulnerabilities on every change and tested at least once a year. Access to data is logged, monitored and reviewed.
- If a security incident affects a client's data, we notify the client without undue delay, and Meta where its data is involved.
To report a security issue, see Security.
8. Your choices and rights
Disconnecting
Remove Plethos at any time in Facebook: Settings & privacy › Settings › Business integrations › Plethos › Remove. We stop receiving data immediately and delete your data within 30 days. If you shared assets with Gushwork as a partner instead, remove Regents Inc in Business Settings › Users › Partners.
Deleting your data
Follow the steps on our data deletion page.
US state privacy rights
Depending on your state, including California, Colorado, Connecticut, Virginia and others, you may have the right to know what personal information we hold about you, to access, correct or delete it, and to opt out of its sale or use for targeted advertising. We do not sell personal information from Plethos. To use these rights, email admin@gushwork.ai. We will verify your request and will not discriminate against you for making it. An authorized agent may make a request for you. If we deny your request, you can appeal by replying to our decision.
If you submitted a lead form on a client's ad, the client is responsible for your information once delivered to them. You can also contact us, and we will delete your details from Plethos and let the client know.
9. Children
Plethos is a service for businesses. It is not directed to children under 13, and we do not knowingly collect their personal information. If you believe we have, email admin@gushwork.ai and we will delete it.
10. Changes to this policy
We will post changes here and update the effective date. We will email active clients about material changes before they take effect. Use of Plethos is also subject to the Plethos Terms.
11. Contact
Regents Inc dba Gushwork
16192 Coastal Hwy, Lewes, DE 19958, United States
Privacy and data requests: admin@gushwork.ai
Sales: growth@gushwork.ai · Phone: +1 (888) 451 5522