Privacy Policy
We want to offer the user a safe and reliable browsing experience and service on our website with the domain https://www.exoclick.com, from now on, the “Platform” or the “Website“. We have therefore implemented the present Privacy Policy that complies with the security measures required by the European Data Protection Regulation 679/2016, of 27 April, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, “GDPR”), and by the Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (“LOPDGDD”), with the objective of protecting your privacy and being transparent with the use of your personal data.
As stated in the Legal Notice, the owner of the Platform and Controller of the processing of your personal data is:
- Owner of the Platform & Controller: EXOCLICK, S.L. (henceforth, “EXOCLICK”).
- Registered office: C/ Marina, 16-18, 08005, Barcelona, Spain.
- NIF/VAT: B-64355506.
- E-mail: privacy@exoclick.com
- Commercial Registry Data: Barcelona, Volume 39063, Page 160, Sheet B-336819, 1st Inscription.
- Data Protection Officer (DPO): dpo@exoclick.com
This Privacy Policy only regulates the processing of personal data that takes place by the access, navigation, and use of the Platform. The processing of personal data that derives from the use of other services offered on the Platform shall be fully governed by the specific conditions provided in each case. For instance, the contractual relationship between EXOCLICK and the Publishers/Advertisers and the related data processing issues are governed by the Terms & Conditions, the Data Processing Agreement (“DPA”), and any other applicable agreement.
For anything you may need as a user, you can contact us at the aforementioned e-mail or registered office.
1. IAB – TCF APPROVED VENDOR
EXOCLICK participates in the IAB Europe Transparency & Consent Framework (“TCF”) and complies with its Specifications and Policies. EXOCLICK’s identification number within the framework is 997. As EXOCLICK has implemented TCF, we are GDPR-compliant when serving ads. Our clients can rest assured that we are constantly monitoring the evolving guidance and legislation.
Under the TCF v2.2, EXOCLICK can gather data on the legal bases of “Consent” or “Legitimate Interest”, when applicable. To this end, a full explanation of the purposes that embrace the Legitimate Interest and Consent can be found in section 2. e of this Privacy Policy.
2. HOW DOES EXOCLICK COLLECT YOUR PERSONAL DATA?
a. Collection of data from legal entities or professionals
If you are a user contacting us but acting on behalf of a legal entity or if you are an independent professional, we will also collect your data for the provision of the requested service and may also process them for commercial purposes when you authorize us to do so, for example, by validating this policy.
Categories of personal data we collect:
- Identification data such as your name and email address.
b. Through our corporate emails
Through the following email addresses the user will be able to write to us and/or request the information they consider necessary to clarify doubts related to our services:
– help@exoclick.com: In order to receive more information about our services.
– dpo@exoclick.com: In order to resolve any questions about data protection and exercise of rights you can contact our DPO.
Categories of personal data we collect:
- Identification data such as your name and email address.
c. Social Networks
We may collect your data through your user profile in the social networks that we use from Facebook, Twitter, LinkedIn, YouTube, or Instagram, which are detailed in section 10 of this policy.
d. Behavior and Habits on the Website
It is also possible that we collect information about your behavior on our Website through cookies, so the user can consult our Cookies Policy if needed.
Categories of personal data we collect:
- Identification data such as the IP address.
e. Online forms
By means of our contact form, signup form, CV form, or any other online form on our Website, we will collect the data that are indicated and that are necessary to be able to send us your request or consultation.
Categories of personal data we collect:
- Identification data (name and surname, IP address, email address, address, and telephone)
- Transaction data (bank account number or similar)
f. Provision of service: end-user
EXOCLICK helps its Advertisers promote their products and services. To do this, we enable Advertisers to customize their campaigns for the specific audiences they intend to reach, which in turn means that the end user will find advertisements on Publishers’ websites. Therefore, we may process the personal data of the end user obtained through their browsing information archive files, as informed via the cookies policies of the websites of each of the Publishers (websites that show our advertising banners or other ad formats).
We regulate these processing under a DPA with our Advertisers and Publishers which complies with the different aspects of the GDPR and applicable data protection law. The data obtained is:
f.1. When an end user browses the website of a Publisher using our technologies, we collect the following data, among others, to recognize the end user’s browser and assign to it the data that we collect, without identifying the end user. ExoClick acts as a joint controller together with its Publishers. Thus, the collection of personal data takes place on their respective websites that we do not control. As such, our DPA also provides that they are responsible for disclosing to end users the presence of our technologies (Cookies used by the Ad Server) on their websites, and, when appropriate, for obtaining end users’ consent to the collection and use of their data. In this regard, we inform you that we take the necessary steps to contractually obtain proof of such consent from the end user, and, where appropriate, we reserve the right to audit our Publishers to ensure that they properly collect such consent.
Categories of personal data collected from our Publishers’ websites:
- Operating system;
- URL of website displaying our ads;
- Referral URL;
- Browser information;
- Country, time zone, and locale settings (country and preferred language); and
- IP address
f.2. Also, when offering our programmatic services to our Advertisers, the ad exchanges (“Partners”) will make device-level information available to us in the form of “Bid Request Data”. It is important to understand that all information processed is solely at the device level and cannot, by itself, be used to identify a natural person in the real world.
Once we receive a Bid Request Data, we will help Advertisers decide how much to bid on displaying an advertisement based on a variety of factors. Whenever our Advertiser has the highest bid to display an advertisement, it will win the bid request and the end user will see its advertisement.
Partners often provide EXOCLICK with device-level data that they have collected about end users. EXOCLICK uses this information to create models that help the Advertiser determine what sort of end users it should target with advertisements.
Categories of personal data collected from our Partners:
Bid Request Data:
- Advertising IDs (IDFA/GAID);
- Device characteristics;
- Operating system;
- Network carrier information;
- Browser information;
- Country, time zone, and locale settings (country and preferred language);
- City- and/or country-level geolocation data; and
- IP address
Impression data:
- When an Advertiser wins a bid and has its advertisement displayed to the end user, EXOCLICK collects information related to this transaction including the Advertising ID (IDFA/GAID) which was shown in the ad.
2. WHAT IS THE PURPOSE FOR THE PROCESSING OF YOUR PERSONAL DATA?
The purpose of data collection in all the sections mentioned in the previous point is to maintain direct and personalized contact with our users. In this way, we will use your information to manage and respond to requests, and the provision of information and services of the entity.
In no case will the user receive information from third parties without having informed and requested their prior consent, thus ensuring compliance with the limits of the law.
We will send you information about our company, its actions, events, collaborations with third parties, commercial actions, and/or any other initiative related to EXOCLICK depending on the type of consent that, in any case, you provide us.
The purposes of data processing by the means set out in point 1 will be, in detail, the following:
a. Respond to queries or requests for information that the user may make.
b. Send information that is considered to be of interest to the user.
c. Inform of novelties that we may implement in the Platform.
d. Notify promotional agreements that EXOCLICK has subscribed with other entities or collaborating companies, all this to offer the user of the Platform, if applicable, certain functionalities or services similar to those previously acquired with EXOCLICK.
e. Provide our services to clients (end users).
e.1. EXOCLICK can process or access to end user´s personal data on the basis of “Legitimate Interest” for the following purposes:
e.2. EXOCLICK can only drop a cookie on the end user’s browser with their prior “Consent” if they are located in the European Economic Area. The end user’s Consent will be collected by the Publisher who operates the websites and/or mobile app end user´s use.
3. WHO CAN BE THE RECIPIENTS OF YOUR PERSONAL DATA?
As already established in the previous points, EXOCLICK will not provide users’ data to third parties, understood as third parties that are not directly related to the user or that do not carry out a function on behalf of or commissioned by the service provider or data controller, that is, EXOCLICK.
We also inform you that your data may be communicated to those third parties when there is a legal obligation to do so.
Then, your data will be communicated to those entities that provide a service to EXOCLICK when acting as Data Processors. In those cases, EXOCLICK has subscribed to confidentiality and data processing agreements with them according to the requirements under GDPR and privacy applicable law.
In addition to this, and in order to have advertising inventories on which to display ads, EXOCLICK participates with its Partners in real-time auctions (often called “Real-Time Bidding”) on marketplaces. To do this, EXOCLICK may synchronize the identifiers with those used by these marketplaces in order to participate in the auction by sending a bid and the advertising EXOCLICK wishes to display. This means that EXOCLICK must communicate to these marketplaces the identifier used to recognize the end user’s browser or device without ever being able to identify them.
We inform you that our servers are usually located in the European Union, and we generally hire service providers also located within the European Economic Area or in countries that have been declared with an adequate level of protection.
If we need to use external service providers that require the communication of personal data outside the European Union or in countries that have not been declared with an adequate level of protection, we will ensure that we guarantee the security and legitimacy of the processing of your data by means of adequacy decisions, standard clauses, binding corporate rules, exceptions or any other instrument approved by the supervisory authority that provides adequate guarantees for the performance of the international transfer of data.
4. GROUNDS FOR LAWFULNESS OF THE PROCESSING
In compliance with the requirements of the GDPR and the LOPDGDD, and in accordance with our internal policies, when you provide us with your express and specific consent in any form or similar, or when you write to our contact email, you are expressly agreeing that we can process the data for the purpose or request that you have indicated.
With this/these action(s), you are freely and unequivocally declaring to us that you agree that we may process your data according to the purposes mentioned in the previous sections.
The acceptance that your data will be processed for the purposes referred to in this policy is always revocable, without retroactive effect, in accordance with the provisions of current legislation; therefore, you have the right to withdraw your consent at any time, without affecting the lawfulness of the treatment that had already been carried out based on your prior consent.
We also may process your personal data on the basis of a fulfillment of a contract, legitimate interest, and legal obligation.
5. IAB – TCF APPROVED VENDOR
EXOCLICK participates in the IAB Europe Transparency & Consent Framework (“TCF”) and complies with its Specifications and Policies. EXOCLICK’s identification number within the framework is 997. As EXOCLICK has implemented TCF, we are GDPR-compliant when serving ads. Our clients can rest assured that we are constantly monitoring the evolving guidance and legislation.
Under the TCF v2.2, EXOCLICK can gather data on the legal bases of “Consent” or “Legitimate Interest”, when applicable. To this end, a full explanation of the purposes that embrace the Legitimate Interest and Consent can be found in section 2. e of this Privacy Policy.
6. WHAT ARE YOUR DATA PROTECTION RIGHTS?
The GDPR and the LOPDGDD have implemented legal guarantees that allow the user to exercise rights and actions related to the processing of their data. EXOCLICK offers this legal guarantee, whereby, at any time and/or when considered appropriate, the user may exercise the following rights:
- Access to your personal data.
- Rectify inaccurate or incomplete personal data.
- Request the erasure of your personal data when, among other reasons, the data is no longer necessary for the purposes for which they were collected.
- Obtain from EXOCLICK the restriction of data processing when any of the conditions set out in data protection law are met.
- Request the portability of your personal data or transfer your personal data to another Data Controller (when applicable).
- Object to the processing of your personal data, in accordance with the circumstances set out in data protection legislation.
- File a complaint before the relevant Supervisory Authority (www.aepd.es) when you consider that EXOCLICK has violated the applicable data protection law.
- Where a processing operation is based on your consent, you may withdraw your consent at any time. For the purposes of unsubscribing from marketing communications, you may exercise your right to revoke your consent at any time of such data processing, by clicking the unsubscribe link at the bottom of the communication submitted or by submitting your request for revocation to privacy@exoclick.com. Nevertheless, the withdrawal of your consent to this processing will not affect the lawfulness of the processing carried out prior to that moment.
- Disable EXOCLICK’s services (end-user) in all ads based on legitimate interest.
- Withdrawal of the consent given with regard to EXOCLICK’s services (end-user).
In order to exercise your data protection rights, you may contact EXOCLICK at privacy@exoclick.com or at their registered office: Please note that these rights may be limited and/or nuanced in some circumstances by local law.
7. RESPONSIBILITY OF THE USER
The user:
- Warrants that they are over 18 years old when accessing and using the Platform. The registration and use of the Platform is only for data subjects over 18.
- Warrants that the personal data they provide to EXOCLICK are true, exact, complete, and updated. In this sense, the user is responsible for the truthfulness of all the data they communicate and will provide updated information, when necessary, in a way that responds to their actual situation.
- Warrants that they have informed third parties, where applicable, whose data have been provided to EXOCLICK, of the aspects contained in this Privacy Policy. The user also guarantees that they have obtained their authorization to provide their data to EXOCLICK.
- Will be held liable for false or inaccurate information provided through the Platform and for direct or indirect damages which may be caused to EXOCLICK or to third parties in this regard.
- All personal data requested are mandatory unless expressly stated otherwise so that the refusal to provide them will result in the impossibility of providing the service.
8. DATA SECURITY
In order to ensure the security of our Platform, we have integrated a security system that allows us to maintain the confidentiality and integrity of the data of our users that have been sent or collected through the means mentioned in the first point.
Thus, those responsible for this Website maintain the security levels of data protection required by the GDPR and the LOPDGDDD and have established all the technical means at their disposal to prevent the loss, misuse, alteration, unauthorized access, and theft of data provided by the user through the Platform.
Notwithstanding the foregoing, as a user of our Website, you understand, accept, and understand that security measures on the Internet are not impregnable and that, therefore, you are obliged to adopt the necessary security measures that allow you to trust the veracity of our Website, in which you are entering your data. We will also do our best to always ensure the privacy and security of your personal data, using the utmost diligence and implementing the necessary measures.
Therefore, we inform the user that he/she shall be solely responsible for the security measures implemented in relation to the protection of his/her data; EXOCLICK shall not be liable for situations where the user has not implemented the corresponding security measures, nor for the consequences thereof, as well as for causes or damages caused by third parties unrelated to EXOCLICK, including fortuitous and/or force majeure cases.
In accordance with what has been established above, EXOCLICK cannot guarantee that unauthorized third parties may have knowledge of the type, conditions, characteristics, and circumstances of the use that users make of the services and functionalities offered on the web page; or that they may access or manipulate the messages and communications of any type that users disseminate or make available to third parties through these services and functionalities. However, as a measure, some conditions of use have been provided in our Legal Notice.
Regarding end-user personal data, we would like to emphasize that we have appropriate technical and organizational security measures in place to protect your data against loss, alteration, unauthorized access, or any other unlawful form of processing. In particular, as mentioned above, we have contractual measures in place that enable us to obtain sufficient audit rights and evidence to ensure, where possible, that our Publishers process data appropriately and in compliance with the applicable data protection rules.
9. FOR HOW LONG WILL EXOCLICK KEEP YOUR PERSONAL DATA?
The personal data provided will be kept for the time necessary to fulfill the purpose for which they are collected and to determine the possible responsibilities that may arise from the purpose. However, in order to comply with the legally established deadlines, once the service has been completed and for the legal prescription period, they will be kept blocked, adopting for this purpose the appropriate technical and organizational measures to prevent their processing, including their visualization, and being only available to judges, courts, public prosecutors or public administrations, all this in order to address the legal responsibilities, if any. Once the required legal period has elapsed, these data will be definitively destroyed.
Regarding end-user’s personal data, we keep personal data only for the period necessary to fulfill the purposes for which it was collected and for any additional period as required by law. For further information, you shall review our Cookies Policy where you will find the retention periods for cookies placed by EXOCLICK.
10. SOCIAL NETWORKS
EXOCLICK has a corporate profile in the social networks of Facebook, Twitter, LinkedIn, YouTube, and Instagram.
Thus, by virtue of what is provided in the regulations and legislation of application of personal data protection, the company is the “Controller” of your data on the occasion of the existence of these profiles on social networks and the fact that you follow us, and we can follow you.
The above means that, if you decide to join our corporate profile as a follower or give a “Like” or similar to our content or profile, you accept this policy, where we explain your rights and how we use your data.
As Controller, we guarantee confidentiality in the processing and fulfillment of your rights, always under the effects of the applicable legislation and regulations. We also inform you that we will use these social networks to announce relevant news or information related to the services we provide or on topics that we consider to be of interest to you. The user must be aware that, using the functionalities of these social networks, it is possible that they may receive on their wall or profile news with this type of information, not being responsible for this EXOCLICK.
Now, we also let you know that there is no link between EXOCLICK and these platforms or social networks, so you will accept their policy of use and conditions once you access them and/or validate their notices, terms, and conditions, in the registration procedure, the entity not being responsible for the use or processing of your data outside the strict relationship and provision of services indicated in this policy.
11. MODIFICATION OF THIS PRIVACY POLICY
EXOCLICK reserves the right to modify this policy to adapt it to future legislative or jurisprudential developments, as well as to future uses that it plans to make of the personal data of the users of the Platform. In the event that this modification affects you with regard to the processing of your data, for example, because additional processing of your data is carried out, and we have not previously informed you, we will proceed to notify you.
It is suggested, in any case, that the user proceed to read this policy each time they access it.
12. INTERRELATION WITH OTHER LEGAL TEXTS
This Privacy Policy is complemented by the Legal Notice and the Cookies Policy, in addition to the rest of the information provided through the Website, including the Terms & Conditions and the DPA that governs the contractual relationship between EXOCLICK and the Publishers/Advertisers.
Last update: March, 2024