Legal
Advertising services privacy notice
Draft — pending legal review
1. Who this notice is for
This notice is for end users whose device data reaches us through a publisher we represent, and for the publishers and buyers who need to describe our processing in their own notices. It is written for the advertising side of our business only. See the website privacy notice for enquiries, marketing email and site analytics.
2. Our role
We receive a bid request from a publisher, its SSP or its mediation partner, and pass it to demand partners that may bid. Depending on the contract in place we act as an independent controller or as a processor for that data. The role that applies is set out in the data processing terms signed with each partner, and a Data Processing Addendum is published at /dpa.
3. Data in a bid request
- Pseudonymous identifiers: mobile advertising IDs, publisher-supplied IDs and session identifiers.
- Device and connection data: IP address, user agent, device model, OS, carrier.
- Approximate location, derived from IP or supplied at reduced precision.
- App bundle ID or page domain, content category, placement and ad format.
- Consent and privacy signals, and auction metadata such as prices and outcomes.
We do not receive or ask for names, email addresses, phone numbers, precise GPS coordinates or payment data in a bid request.
4. Purposes and legal bases
Selecting and delivering an ad, measuring delivery, and detecting fraud and invalid traffic. Where consent is required in the end user's jurisdiction we act on the signal passed to us by the publisher and do not process the request for advertising without it. Where legitimate interests apply, the assessment sits with the publisher and is recorded in our agreement. Fraud and ad quality controls rest on legitimate interests and legal obligation.
5. Consent and choice signals we honour
We read and pass on the IAB TCF string, Global Privacy Platform strings including the US sections, the US Privacy string, the Global Privacy Control signal and the regs.coppa flag. A request that arrives without the consent its jurisdiction requires is not processed for personalised advertising. We do not sell or share personal information for cross-context behavioural advertising, and we do not use sensitive personal information to infer characteristics.
6. Retention
Request-level records containing identifiers are kept only as long as they are needed to serve, bill and troubleshoot, then deleted or reduced to aggregate counts that identify no device or person. Aggregated reporting is kept for the commercial period it covers.
7. Recipients and transfers
Bid requests are passed to the demand partners connected to the publisher's supply, and to the sub-processors listed at /sub-processors for hosting, serving and logging. Transfers out of the EEA or the UK rely on the Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum, with a transfer risk assessment. Transfers from other jurisdictions rely on the mechanism that jurisdiction requires.
8. Your rights, and how to use them
Because we hold only pseudonymous identifiers, we usually need the advertising ID or the privacy string from the device to find the records that relate to you. Send a request to contact@omniad.ai and we will tell you what we need and confirm the outcome in writing. Where we act as processor we forward the request to the publisher that controls the data.
- EU and UK GDPR: access, rectification, erasure, restriction, portability, objection, and no solely automated decisions with legal or similarly significant effects. You may complain to your supervisory authority, or the ICO in the UK.
- California, CCPA and CPRA: know, delete, correct, and opt out of sale, sharing and targeted advertising. We honour Global Privacy Control and the GPP US strings.
- Hong Kong, PDPO: data access and correction requests under the six Data Protection Principles of Cap. 486, answered within 40 days.
- Singapore, PDPA: access, correction and withdrawal of consent.
- Japan, APPI: stated utilisation purpose, consent for third-party and cross-border provision, and records of that provision. Where identifiers are personally referable information we confirm the recipient holds consent.
- South Korea, PIPA: separate itemised consent for collection, third-party provision and cross-border transfer, with retention stated per purpose.
- India, DPDP Act 2023: notice and consent or a legitimate use, withdrawal of consent, access, correction, erasure and grievance redress.
- Australia, Privacy Act 1988: the Australian Privacy Principles, including access and correction. Complaints may go to the OAIC.
9. Changes and contact
Material changes are published on this page with a new date. Questions about this notice, and requests relating to bid stream data, go to contact@omniad.ai.
