End user privacy policy

This document provides information about our tracking and digital advertising technology platform. PeerClick (owned and developed by PeerClick Inc.) owns and develops tracking and digital advertising technology that enables advertisements (also called further ads) to appear within desktop and mobile websites, as well as within mobile applications. The intention of this document is to provide you transparent information how the PeerClick platform runs and how the data is processed, collected, and stored in the platform. We realize that some technical terms might sound complicated to you, so this document presents those terms in simple words as well as explains what the goal of data processing is. PeerClick Inc. is firmly committed to protecting the privacy of Internet’s users and fostering users’ confidence in online advertising and marketing. Accordingly, we are committed to observing applicable industry guidelines including those established by the Interactive Advertising Bureau and the General Data Protection Regulation (“GDPR”) by the European Union. We continue to evaluate enhanced ways to protect Internet users’ privacy while seeking to deliver relevant advertising and custom online experiences to those users on behalf of our customers. This document outlines PeerClick End User Policy and provides you clear notice about the user’s information we may collect and process online in connection with our services. I. Glossary Applicable laws: All the laws and regulations relevant to the collection, processing, and storage of data, especially all the data protection laws and the General Data Protection Regulation (EU) 2016/679 (GDPR). Ad exchange: This is a platform where people who can offer unsold ad placements meet people who want to buy those placements for their online advertisements. You can think about it as a digital marketplace with a sort of an auction called real-time bidding. However, a buyer can be anybody including other ad exchanges or platforms that sale advertisements to other companies / buyers. Ad server: By and large, a server where advertisements are stored, managed, and delivered to you as a website end user. It might also provide a reporting module to check how the advertisements perform. Cookie: They are small text files stored locally by a website or ad server. By storing certain information in a cookie, those web browsers or ad servers are able to remember your preferences and recognize websites visited and / or web browser used from one visit to another. To learn more about cookies and how to disable them, visit http://www.allaboutcookies.org. Customer: The party who submits an application on the registration page and uses the PeerClick platform. Domain name: It is a character string that helps you to easily go to a website without the necessity of remembering IP addresses. A domain name must be unique for all domain names available on the Internet. It allows you to navigate to a website and discover an online advertisement. Do Not Track (DNT): This is an option of the web browser that sends a request to a web application to disable tracking of an individual user. End user (visitor): This is a user of an Internet connected device, such as a visitor to a website, a user of a mobile app, or a user of an IoT device, or a visitor on an advertisement, landing page, or campaign. Geographic location: This is a piece of information where you are located based on an IP address. Precisely, this is a location of your device that is connected to the Internet and based on that we are able to define a country, region, city, and Internet Service Provider (ISP) your device is connected to. HTTP request header: The request header of HyperText Transfer Protocol. The HTTP protocol is used all around the world. Almost all content that shows up in the browser you see is transmitted to your computer (or other device connected to the Internet) over HTTP. For example, when you opened this policy in the browser, many HTTP requests have been sent. Each request contains an HTTP header in which there is information about the browser you use, the requested page, the server and much more. HTTP request parameters: The request parameters of HyperText Transfer Protocol are additional pieces of information transmitted from one device to the other that you might see in the address bar of your browser. They are in the form of name=value pairs separated from the URL by a ?. There might be more than one name=value pair, where each of them are separated by.. IP address: An Internet Protocol (IP) address is a set of numbers that each device has assigned to connect with other device over the Internet network. The IP address allows addressing and delivering the information to the right receiver. Every time a piece of information is sent, a device needs to communicate with other devices in a computer network to be able to deliver the message. Sending information in that context means every kind of activity such as surfing, exchanging emails, or downloading an application. The IP address is used to identify the device to which the message is supposed to be sent and find the best way to deliver it. Personal information / personal data: Any information relating to an identified or identifiable person as defined in article 4.1 of GDPR. Processing: Any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction (process, processes and processed shall have the same meaning). Referrer domain: In simple words, this is the address of a website that led you, as a visitor, to another page. Retargeting: A strategy of online targeted advertising when information is gathered to address visitor’s preferences based on their previous actions / choices. When you, as a visitor, go to one sort of websites, for example because you are looking for a pair of glasses, then the advertisement is displayed in front of you with glasses that you might possibly like. Request time: This is the time when a query to the PeerClick database is sent. Every time when you click an advertisement, the query request is made, so the PeerClick platform is able to store the information about the visit. User agent: Information about a device, operating system, web browser is being used to access a website. You (visitor): A person who can visit digital advertising campaigns on the Internet. II. What is PeerClick? PeerClick is a cloud-hosted analytics solution, designed for performance marketers and self-serve advertisers to track the progress and profitability of their online campaigns. In other words, the PeerClick platform enables our customers to make their online campaigns more efficient and profitable by analyzing the ad-related data and then, optimizing the campaign by addressing them in the most effective way. Thus, our customers collect different kinds of data about visitors’ activities on the Internet to reach the right audience and increase the performance of their online campaigns. PeerClick collects data about different activities of online visitors to allow its customers to address ads to the right audience and display more relevant advertisements on websites. Those visitors are Internet users who surf through the websites, send emails, communicate on social media and see those ads appearing in the content. To display the advertisement at the right time and in the right context, PeerClick processes the collected data to measure the ad effectiveness and coverage. All kinds of data are gathered for statistical and reporting purposes and processed collectively as records of certain information to produce a meaningful approach while running an online campaign. In the next sections, you can find out what information is stored in PeerClick and how it relates to your activities as a visitor. III. PeerClick’s Role in Processing Personal Information While our customers use PeerClick Tracker, we act as a customer’s data processor meaning that we process end user’s personal data on behalf of our customer under customer’s instructions under PeerClick Tracker Data Processing Agreement. IV. What Kind of Data Do We Collect and For What Purposes? In order to perform our services, we are intent on collecting and processing certain information about you and your device. Some of this information (including, for example, your IP addresses and certain unique device identifiers) may identify a particular computer or device and be considered as personal data in some jurisdictions, including the European Union. This kind of data enables us to provide aggregated reporting and analysis of the performance of our customer’s advertising campaigns. The PeerClick platform does not collect any data which by itself identifies an individual such as a name, address, phone number, email address. We also do not collect any “sensitive” or “special categories of personal data” as defined under the European data protection laws as well as personal data of children. IP Address An IP address is used to identify the device’s location as well as, to some extent, user’s location. Based on the IP address visitor’s country, region, city can be characterized and stored in the PeerClick platform. Moreover, some more technical specifications are processed such as Internet Service Provider (ISP) or mobile carrier and what type of the connection you use. This data is stored to adjust the online advertisements that are displayed on websites and identify automatic computer programs that might affect our customers’ reporting. In addition, the IP address is used to limit the number of times a visitor is exposed to a single advertisement. User Agent A user agent helps us to identify what kind of a device a visitor uses (TV, desktop, table, mobile phone) and which model it is. Even more, this piece of information is stored to establish device’s parameters such as browser and browser version, operating system, and operating system version. It also allows us to detect the automatic computer programs and fraud attempts. Additionally, the user agent is used to limit the number of times a visitor is exposed to a single advertisement. HTTP Request Header Information from HTTP request headers is used to determine a visitor’s language and referrer domain. That data is then used to present an appropriate advertisement to the end user. It is also stored for analytical purposes. HTTP Request Parameters The HTTP request parameters are used to transfer information from third-party services to the PeerClick platform and the other way round. Based on that, the PeerClick customers are able to find target audiences more effectively and message through appropriate channels. It is also stored for analytical purposes. Device ID A device ID is a unique identifier used to accurately measure actions taken by a specific device. It plays a role in personalization, distribution, and performance of the traffic sent to a visitor. The ID enables us to do cross-device matching meaning that the advertisement will be displayed only on one device that belongs to a particular user. It means that if you are an owner of more than one devices connected to the Internet, the IDs of those devices can help us to identify you, determine which advertisement was displayed on which device, and eliminate ad display repetitions for you. Request Time This is an exact date and time of interaction with PeerClick servers. It is used to present an appropriate advertisement to the end user. It is also stored for analytical purposes. Unique Identifier (UID) A unique identifier generated by the platform enables us to match registered events and control the frequency of those events in PeerClick. Note that our publisher partners may share with us additional demographic information, such as age or gender, in order to enable more accurate targeting. We do not use this information to maintain any kind of persistent user’s profile database. V. How Do We Collect Data? The PeerClick platform uses cookies and in some cases non-cookie technologies, to collect data associated with particular web browsers or devices that you, as a visitor, use. PeerClick uses both types of cookies: session cookies and persistent cookies. Those cookies are used not only to follow visitor’s activities, but also to improve visitor’s experience while surfing through the Internet websites. For example, they are used to identify how many times you have already seen an advertisement, so they allow to differentiate the content of the ad as well as adjust the offer to your current potential needs. Session cookies does not remain after closing a web browser and does not store any information afterward. Persistent cookies are stored locally on your device and may be used by your web browser on subsequent visits to any website. They are used to remember your preferences and personalize the ad content. In the tracking part of the advertising platform, we also use non-cookie technology such as pixels to set up the communication between your web browser and a server. PeerClick Tracker In the tracking part of the PeerClick platform the following technology is used to gather the data: Impression cookie: Some of our customers are only interested in displaying advertisements on websites, so the ads might be noticed by an end user. This type of advertising refers to impressions or ad views. The cookie helps us to monitor this type of activities. It is a session cookie, so it exists as long as your session lasts in your web browser. Conversion cookie: This is a cookie that allows to combine a display of an advertisement with a visitor’s actions that happen for a particular offer afterwards. Our customers may define what kind of an action the visitor should take upon to call the ad display successful. For example, they may offer a promotion of an app subscription – every time a visitor subscribes to a particular system, that action is registered as a successful event in the PeerClick platform. The cookie allows us to define wether the action happened or not for a particular visitor. That record allows us to measure visitor’s behavior and personalize the ads displayed on websites. It expires after 365 days. Lander cookie: This is a cookie associated with a visit on a displayed advertisement. It stores different pieces of information about the visit itself as well as other parameters such as a web browser type, web browser version, device ID. This data is only used for statistical and reporting purposes in the PeerClick platform. It expires after one day. Unique session cookie: It is used to detect whether a visit is the first visit of a visitor for a particular advertisement or not. It expires after one day. Opt-out cookie: This a cookie that is used for the opt-out option for PeerClick Tracker. It gives us information that you do not want to be tracked with desktop and mobile environments. It expires after at least 2 years. Tracking pixel: This is an invisible, very small (1 x 1) pixel tag that our customer can put on a website. When you as a visitor open a website where the tracking pixel is placed, the information is sent to PeerClick. Pixel tags are used in combination with cookies to track user’s activities while surfing through websites by a particular browser on a particular device. VI. For What Purposes We Use End User Data? The data collected and stored in the PeerClick platform is used to increase the ad relevance and adjust the ad display to the changing needs of the ad visitor. Particularly, the PeerClick data is used for: Cross-Device Matching To identify to how many devices a visitor is associated with to cut off ad display repetitions. Fraud Detection To monitor the quality of traffic for our customers and blacklist those sources that generate fake visits / clicks. Frequency Capping To limit the number of times a visitor is exposed to a single advertisement. Reporting, Analysis, and Optimization To measure the effectiveness of online ad campaigns what helps to address the advertisements to right audiences and based on the collected data improve the performance of the campaigns. Briefly, to determine how visitors respond to advertisements they see on the Internet. Retargeting To allow the PeerClick’s customers to address visitor’s preferences based on their previous actions / choices. VII. Legal Basis for Processing User Information If you are a European Union End user or GDPR applies to you under the Applicable Law, our legal basis for collecting and using the end user’s information described above will depend on the user’s information concerned and the specific context in which we collect it. We rely on your consent when we process your personal data in order to deliver end users targeted advertising and use cookies technology in connection with an end user’s device. If we rely on consent to collect and / or process end user’s information, we will obtain such consent in compliance with applicable laws. We may also use the end user’s personal data because of our legitimate interests to: Operate and improve our technology Enable standard advertising controls Prepare reports that summarize visitor’s activity Analyze and report on the advertisement’s performance (such as tracking views of ad as well as click-through rates on ads), campaign reporting, and campaign forecasting Protect, investigate, and deter against fraudulent, unauthorized, or illegal activity. If you have questions about or need further information concerning the legal basis on which we collect and use of this data, please contact us using the contact details provided under the Contact us section. VIII. How Long Do We Store Data? The collected data is stored using generally accepted security standards. The data retention in the PeerClick platform is 24 months starting from the day of the account registration. This data is used for reporting and analysis. When a customer removes their data from PeerClick, their storage and retention of data is governed by the Privacy Policy and applicable regulations. The process of removing the collected data from the PeerClick platform might take up to 1 month. IX. Your Choices and the Opt-Out Option The opt-out option is applicable for end users who see an online advertisement set by a customer. Visitors of advertisements that are a part of digital advertising (PeerClick) may choose either the opt-out or Do Not Track option. How to proceed when choosing the Do Not Track option is described in the next section. If you wish to opt out of being tracked with desktop and mobile website environments from the PeerClick platform, you should use the opt-out option. The PeerClick platform only processes data collected by its customers meaning that the PeerClick customers are obliged to deliver the opt-out option and make it accessible to you as a visitor to an online advertisement. PeerClick makes every effort to support its customers to provide such a solution for you, thus you can find below procedures how to make a request to opt out of being tracked. Because the domain name is set by each customer individually, you need to get in touch with the customer of the online advertisement to find out the correct domain name under which the online advertisement is set. Once the PeerClick customer replies with the domain name, you can provide the link in an address bar in your web browser to be able to opt out. Opting out of being tracked with desktop and mobile website environments from the tracking advertising part of the PeerClick platform is valid for at least 2 years for a web browser where the opt-out option has been set. The option can be enabled only for a particular web browser meaning that if you switch to other web browsers, clear cookies, or use a browser’s incognito mode, you need to go through the opt-out procedure once more. When the opt-out option expires, you need to repeat the same procedure to turn it on again. Opting out of being tracked with desktop and mobile website environments from the digital advertising part of the PeerClick platform is valid for at least 2 years for a web browser where the opt-out option has been set. The option can be enabled only for a particular web browser meaning that if you switch to start using other web browser, you need to go through the opt-out procedure once more. When the opt-out option expires, you need to repeat the same procedure to turn it on again. The Do Not Track Option If you wish to opt out of being tracked with desktop and mobile website environments from the digital advertising part of the PeerClick platform, you may use the Do Not Track option. This option does not work for the tracking part of the PeerClick Tracker. Desktop Website Environments If you wish to turn on the Do Not Track (DNT) option in your web browser for you desktop website environment, follow the steps: (Google Chrome web browser, version 66.0.3359.139, official build) From your web browser, select Menu (3 bars at top right of window). Select Settings and then scroll down to Advanced. Expand the Advanced section. In Privacy and security, find Send a “Do Not Track” request with your browsing traffic. Turn on the toggle. Click Confirm to activate the Do Not Track option in your web browser. (Safari web browser, version 11.1 (13605.1.33.1.4)) From the main menu in your web browser, select Safari > Preferences. Select Privacy and then Ask websites not to track me. Mobile Website Environments If you wish to turn on the Do Not Track (DNT) option in your web browser for you mobile website environment, follow the steps: (Android 7.1.2; Google Chrome web browser, version 66.0.3359.158, official build) From your web browser, tap Menu (3 bars at top right of window). Tap Settings and then swipe down to the Advanced section. Find and then, tap the Privacy option. Tap “Do Not Track”. Toggle the “Do Not Track” option to On. (iOS 11.1.1; Safari web browser) Go to Settings on your mobile device. Tap Safari and then swipe down to the Ask Websites Not To Track Me option. Toggle on the Ask Websites Not To Track Me option. X. European Data Subject Rights If you are a European Union end user or GDPR applies to you under the Applicable Law, you have certain rights and protections under the law regarding the collection, processing, and use of information about you. In particular, you have the right to: To request an access and obtain a copy of your data. To request a rectification (correct or complete information about you) or erasure (it is sometimes called ‘the right to be forgotten’ that applies in some circumstances). To restrict the processing end user information. If applicable, to the data portability. In certain circumstances, you may also have the right to object to the processing of end user’s information when personal data is processed on the basis of legitimate interests and there is no overriding legitimate interest for us to continue to process your personal data, or if your data is being processed for direct marketing purposes. If you have given us your consent to process your data, you have the right to withdraw your consent. The withdrawal of consent does not affect the compliance of the processing which was made on its basis before the withdrawal of consent. You have also the right to lodge a complaint with the Supervisory Authority in particular if you feel that PeerClick has not responded to your requests to solve a problem. If you would like to exercise any of these rights, please contact our data protection officer: support@peerclick.com. Please include information that will enable us to verify your identity within your request. In addition, you may also use our opt-out functionality described in point IX. Your Choices and Opt Out Option. XI. Information Transferred from Third-Party Services This policy does apply only to usage of the data by the PeerClick platform and does not explain the practices of other third-party advertisers or advertising networks. We do not control the privacy practices of such third parties, and you are obliged to get familiar with the privacy policies of those third parties when you use their services. We also inform you that we may disclose your information to the following categories of recipients: To our third-party services providers who provide data processing services that support the operation of our services (acting on our behalf), such as analytics providers, IT services providers (for example, cloud or host services providers). To our clients and partners to deliver interest-based advertising and other information describing, for example, location context and general statistical information. To any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) under applicable law, and (ii) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities. XII. Transfer of Personal Data Outside EEA We work with customers and partners throughout the world, including in the European Economic Area (EEA) as well as countries outside of the European Economic Area (EEA). In order to ensure that your personal data is adequately protected when transferred outside of the EEA, PeerClick: relies on EU-U.S. Privacy Shield Program – Privacy Shield is a “partial” adequacy decision, as, in the absence of a general data protection law in the U.S., only the companies committing to abiding by the binding Privacy Shield principles benefit from easier data transfer. In such cases your personal data will be transferred to the territory of USA in accordance with applicable laws, with appropriate safeguards in place, only to Privacy Shield certified vendors (according to the EU Commission Decision 2016/1250) or by using standard contractual clauses adopted by the European Commission (EU Commission Decision on standard contractual clauses for the transfer of Personal Data to processors established in third countries under Directive 95/46/EC (the “Model Contract Clauses”), or based on other applicable transborder data transfer mechanisms, or has entered into inter-company EU “model clause” agreements. You may contact us if you require a copy of the safeguards which we have put in place to protect your Data transferred outside of the EEA and your privacy rights in these circumstances. You may also learn more about: Privacy Shield Program here https://www.privacyshield.gov/Program-Overview and here https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/eu-us-privacy-shield_en. EU Commission Decision on standard contractual clauses for the transfer of personal data to processors established in third countries here https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32010D0087 and here https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en XIII. Security PeerClick uses various security technologies and procedures that help protect your personal information from unauthorized access, use, disclosure, alteration, or destruction. For example: Personnel: Only qualified and authorized employees are permitted to access personal information, and they may do so only for permitted business functions. Data Protection Officer: We appointed a Data Protection Officer who in particular watches over the security of your data, monitors our compliance with GDPR, and is a point of contact for you in all matters regarding Data protection; you can contact our Data Protection Officer via email: support@peerclick.com. Security Measures: We use encryption in the transmission of your personal information between your system and ours, and we use firewalls to help prevent unauthorized persons from gaining access to your personal information. Payments: All supplied sensitive / credit information is transmitted via Secure Socket Layer (SSL) technology and then, encrypted into our payment gateway providers database only to be accessible by those authorized with special access rights to such systems and are required to keep the information confidential. After a transaction, your private information (credit cards, social security numbers, financials, etc.) will not be stored on our servers. Additional Safeguards: We maintain physical, electronic, and procedural safeguards in connection with the collection, storage, and disclosure of your information. Our security procedures mean that we may request proof of your identity before we disclose personal information to you. Trusted Vendors: We rely only on vendors who ensure an appropriate level of security of your data. In this context, we use only secure cloud servers, including AWS cloud – a secure, private cloud platform. AWS participates in the EU-US Privacy Shield framework. Amazon Web Services is our processor. AWS Amazon cloud platform uses various security technologies and procedures to protect personal data and is compliant with third-party assurance frameworks such as ISO 27017 for cloud security, ISO 27018 for cloud privacy, PCI DSS Level 1, and SOC 1, SOC 2, and SOC 3. For more details please see AWS Amazon security and privacy policy at www.aws.amazon.com. XIV. Children Protecting children’s privacy is very important to PeerClick. Our platform is not intended for, designed to be used by, or targeted at children. We do not allow our partners and customers to send to us personal data of children as defined under GDPR. XV. Contact Us If there are any questions regarding this End User Privacy Policy, you may contact us using the information below: PeerClick Inc. General contact form: www.peerclick.com PeerClick’s Data Protection Officer contact: support@peerclick.com