GDPR: who is the controller?

This is the compliance question your legal team will ask first, so it's worth being precise.

The split

  • For your account data — name, email, billing, authentication — we act as the data controller.
  • For end-user data processed through the platformwe act as a data processor.
  • For the advertising data you collect and process through your White Label DSP instance — you are the controller.

What being the controller means for you

You are responsible for your own lawful basis, notices and consents toward end users. This is not something the platform can discharge on your behalf, and it applies to any audience data you import — see Importing audiences from a DMP or CSV.

In practice you need:

  • A privacy notice covering your advertising activity, under your own brand.
  • A lawful basis for the processing you carry out.
  • A consent mechanism where consent is the basis you rely on.
  • A route for end users to exercise their rights against you.

Lawful bases we rely on for our own processing: contract (providing the service and billing), legitimate interests (security, monitoring, platform improvement, fraud prevention, service updates), consent (optional analytics and marketing, where required), and legal obligation (tax, accounting and statutory requirements).

This article explains how the platform is structured — it is not legal advice. Take your own advice on your obligations as controller.

Related: Data transfers, subprocessors and retention · Data subject rights

Sep 7, 2026

Not finding what you're looking for? Contact Us Directly