Our service
CTG WELLNESS SDN BHD operates Content & Ads Studio, a restricted team workspace for planning content, managing creative files, reviewing submissions, saving advertising settings and carrying out authorized advertising operations. Its Meta integration is named Content Creator Agent.
This policy covers the workspace and its integrations. It does not replace Meta’s or Notion’s privacy notices, or those of businesses advertising through the workspace.
Information we handle
Connection credentials are handled on the server, not shown in ordinary team pages. Uploaded content may contain personal information: upload only information you have authority to use. Avoid unnecessary identity documents, customer contact lists or medical records. This is not a medical-record service.
- Account and access information: team names, email addresses, account identifiers, password hashes, login sessions and project permissions, for sign-in and administration.
- Content: Task names, dates, categories, assigned creators, notes, copywriting, headlines, images and videos, for planning, collaboration and production.
- Review and operation records: submission snapshots, decisions, timestamps and change records, for accountability, recovery and avoiding duplicate operations.
- Connected Meta information: authorized advertising account, Page and Instagram identifiers; Campaign, Ad Set and Ad settings; messaging destinations and authorization information, to read selected settings and carry out approved operations.
- Delivery information: advertising status and aggregate performance such as spend, impressions, CPM, reported actions, purchase values and ROAS, where connected.
- Essential session cookies and technical request or diagnostic information, to maintain sessions and investigate failures.
Cookies and security
We use essential cookies for sign-in and sessions. Sessions currently expire after 12 hours; account records are not deleted when a session expires.
Controls include HTTPS for the deployed service, password hashing, project-based access checks and server-side credential handling. No internet service can guarantee absolute security. Do not share passwords or integration tokens.
Retention
We retain content and operational records to provide the service and resolve outstanding work. The current version does not automatically erase every upload, operation record or backup after a fixed period.
Moving a Task to the recycle bin hides it from normal work views; it does not erase all associated data. Revoking a connection limits future access but does not by itself erase previous copies.
For a verified deletion request, we identify relevant account data, content, attachments, operational copies and backups. Information no longer needed will be deleted or de-identified as appropriate. Any exceptional retention must have a specific applicable basis, be limited in scope and duration, and be explained to the requester. Recovery or audit needs do not justify indefinite retention of identifiable data.
Your requests and choices
Email jiazhen.theadspert@gmail.com to request access, correction, a copy of information, deletion or help withdrawing a connection authorization. We may request proportionate information to verify identity and authority. Never send passwords, tokens or full identity documents in an initial request.
Our Data Deletion Instructions explain what to include and how to follow up. Deleting Studio records does not automatically stop or delete an ad on Meta or erase records independently held by a provider.
Changes and contact
The published policy shows its effective date. Material changes to data uses or providers will be communicated before they apply where required. Contact jiazhen.theadspert@gmail.com with questions.