International transfers
Where personal data is transferred outside the EEA, appropriate safeguards are relied on — Standard Contractual Clauses and equivalent mechanisms required by GDPR.
Subprocessors
A limited number of vetted subprocessors are used for hosting, authentication, payment processing and email delivery. Each is bound by contractual data protection obligations consistent with GDPR.
Retention
Personal data is retained only as long as necessary to provide the service, comply with legal obligations and resolve disputes. When an account is deleted, associated personal data is removed within a reasonable period.
How audience data is stored
Identifiers in audiences are stored as salted hashes, not raw values. There is no cookie sync and no cross-device merging, and audiences are never shared between advertisers. See Audiences: retargeting and suppression.
European operation
The platform is headquartered in Europe and built and operated under EU standards, and is designed to meet IAB International and IAB Europe standards.
For your own compliance documentation, you'll likely need to record us as a processor and reference these safeguards. Contact support if your legal team needs specifics.
Related: GDPR: who is the controller? · Data subject rights