Skip to content
Legal

Privacy Policy

Last updated September 2026

This policy describes what personal data flows through the platform, why, on what legal basis, how long we keep it, and the rights you have

1. Who we are

ADSPIRO LTD ("Adspiro", "we") is a company registered in England and Wales under company number 17444318, with its registered office at 4th Floor Office, 205 Regent Street, London, W1B 4HB, United Kingdom.

Adspiro is the controller for the personal data described in this policy. Where we process personal data on a partner’s documented instructions — the data a supply or demand partner passes to us to run their campaigns and inventory — we act as a processor under the data protection terms in our Terms of Service.

For any question about this policy or about your personal data, write to connect@adspiro.io.

2. Data we process

  • Bid stream data: pseudonymous identifiers, device and connection signals, coarse geolocation, and contextual metadata transmitted in OpenRTB bid requests
  • Cookie sync data: a randomly generated identifier stored in our first-party adxuid cookie, and its mapping to a buyer’s own identifier. Where the GDPR applies and consent for that purpose is absent, neither is created — see our Cookies Policy
  • Consent signals: IAB TCF v2.2 strings, US Privacy / GPP strings, and other regulatory flags passed by supply partners
  • Operational data: account, billing, and technical contact information for partner organizations
  • Website data: the name, work email, company, role and message you submit through our contact form, together with the IP address and browser user agent the submission came from

3. How we use data, and on what legal basis

  • Performance of a contract (Art 6(1)(b) UK GDPR) — operating partner accounts, clearing auctions, reconciling delivery, and invoicing
  • Legitimate interests (Art 6(1)(f)) — running and securing the platform, pre-bid invalid-traffic and brand-safety controls, investigating abuse, producing reporting, and answering enquiries sent to us. Our interest is to operate and protect the exchange; we balance it against your interests each time
  • Legal obligation (Art 6(1)(c)) — keeping accounting and tax records and responding to lawful requests
  • Consent (Art 6(1)(a)) — where advertising is personalised on the basis of consent, that consent is collected from the end user by the publisher or its consent management platform and passed to us as a TCF or GPP signal

4. Consent and privacy signals

We pass and honour the consent and regulatory signals surfaced by our supply partners — TCF v2.2, GPP and US Privacy strings — end to end through the auction. Where a valid legal basis is not present, the corresponding bid request is not processed for personalized advertising. We do not build cross-context behavioral profiles for our own marketing purposes and we do not sell personal data.

5. How long we keep data

  • Contact form messages, including the IP address and user agent: 24 months
  • Server and access logs: 90 days
  • Raw bid stream data: 30 days, after which it is aggregated or anonymised
  • Cookie sync identifiers: the adxuid cookie lasts 365 days; the mapping to a buyer’s identifier is kept for 30 days
  • Billing and accounting records: 6 years, as required by UK tax law

6. Who we share data with

Amazon Web Services, Inc. hosts and processes data for us in the US East (N. Virginia) region under a data processing agreement. We do not use any other third-party processor at this time, and this section is updated when that changes.

Beyond that, we disclose personal data only to professional advisers bound by confidentiality, and to authorities where we are legally required to do so.

7. International transfers

Our infrastructure is located in the United States. Personal data transferred out of the United Kingdom is transferred under the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s Standard Contractual Clauses, supported by a transfer risk assessment. A copy of the safeguards in place is available on request from connect@adspiro.io.

8. Your rights

Depending on the circumstances, you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw consent at any time where processing relies on consent — withdrawal does not affect processing carried out before it.

  • To exercise any of these rights, write to connect@adspiro.io. Because bid stream data is pseudonymous and typically originates with a publisher, we will route a verified request to the appropriate controller and assist in fulfilling it
  • You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk

9. Security

We encrypt data in transit with TLS, keep the exchange data tier on private subnets reachable only from the application layer, enforce least-privilege access with per-role permissions and audit logging, and monitor our infrastructure. No method of transmission or storage is perfectly secure, but we hold ourselves to a standard we can evidence.

10. Changes to this policy

We may update this policy from time to time. The date above always shows the current version, and we notify partners of material changes through the channels agreed in their commercial order.

Questions about this document? Contact connect@adspiro.io