Legal
Privacy Policy
This policy covers two separate things. The website is §3. The exchange — the real-time system that processes data about people browsing our partners’ sites and apps — is §4 onwards: what we receive (§4), what we do with it (§5), and how long we keep it (§7).
Who we are
TheGrowthy is a programmatic advertising exchange operated by Cortex Technologies SRL, a company registered in Italy at Via Pola, 11, 20124 Milano, Italy, VAT IT18089101002.
We have not appointed a Data Protection Officer. Article 37 of the GDPR requires one for public authorities, for large-scale systematic monitoring as a core activity, and for large-scale processing of special categories of data. We do not currently meet those thresholds. We state this rather than leave it out, because the absence of a DPO section is otherwise indistinguishable from an oversight. Privacy questions reach a monitored role address: [email protected].
Two kinds of processing, and why the distinction matters
Almost every confusing thing about privacy at an ad exchange comes from collapsing two very different activities into one policy. We keep them apart.
This website — thegrowthy.com — is a marketing site. It sets no cookies, loads no third-party scripts, and collects nothing until you send us a message. See §3.
The exchange is the real-time system that receives bid requests from publishers and their supply-side platforms and forwards them to buyers. It processes personal data about people browsing our partners’ websites and apps, who have no direct relationship with us — the data reaches us from the publisher rather than from the person. §4 onwards describes it, and §11 sets out the rights that apply.
What this website collects
Nothing, unless you use the contact form. The site is statically generated and served from a CDN. It sets no cookies of any kind, uses no local or session storage, and loads no fonts, scripts, tags or pixels from third parties — the typefaces are self-hosted. There is no analytics product on this site. See our Cookie Policy, which is short for that reason.
If you submit the contact form we receive the name, work email, company, the category you select and your message. We use them to answer you and to keep a record of the commercial conversation. The lawful basis is our legitimate interest in responding to an enquiry you initiated (Article 6(1)(f)), or the steps prior to entering a contract at your request (Article 6(1)(b)). We keep enquiries for 24 months from the last contact, then delete them.
Our CDN and hosting providers process server logs, including your IP address, to deliver the page and to defend against attack. That is a technical necessity of serving a website and we do not build profiles from it.
What the exchange processes
When you visit a website or app that sells advertising through a partner of ours, that partner may send us a bid request. An OpenRTB 2.6 bid request can carry:
- Network and device data — IP address, user agent or Structured User Agent, device type, operating system, screen dimensions, language.
- Approximate location — usually derived from the IP address, typically at city or country level. We do not request or use GPS coordinates.
- Advertising identifiers — a mobile advertising ID (IFA) where the app supplies one, a partner-assigned user ID (
buyeruid), and extended identifiers (eids) such as UID2 or ID5 where the publisher has established them. - Context — the page or app the advertising slot is on, the size and format of the slot, and the content category the publisher declares.
- Consent and privacy signals — the GPP string and its section IDs, the TCF signals, the US privacy string, and the COPPA flag.
We do not ask for, and have no use for, your name, email address, postal address or phone number. We do not knowingly process special categories of data under Article 9, and we do not build audience segments or interest profiles.
What we do with it, and what we do not
We run an auction. The request is passed to the buyers eligible for it, each buyer decides whether to bid, and the highest eligible bid wins. The whole exchange takes well under a second and then it is over.
Consent and privacy signals are passed through to buyers byte-for-byte. We do not strip, rewrite or “clean” them, because a downstream buyer’s obligation to honour a consent string depends on receiving the one the publisher actually collected. If a signal indicates that processing is not permitted, that restriction travels with the request.
We do not sell personal data. We do not build or sell audience segments. We do not combine bid request data across publishers to profile individuals. We do not buy inventory from other exchanges to resell, which is why our supply chain (schain) has one node and our sellers.json is short.
Our role: controller or processor
For the exchange, we consider ourselves an independent controller for the limited purposes of running the auction, detecting fraud and invalid traffic, billing our partners, and keeping the aggregate records described in §7. The publisher or supply-side platform is the controller for the collection of the data and for obtaining any consent; we are not in a position to obtain it ourselves, because we have no relationship with the person and no surface on which to ask them.
That allocation follows the European Data Protection Board’s guidance that a party determining its own purposes and means is a controller, and the reasoning is set out here rather than asserted so that a partner’s counsel can engage with it. Our contracts with partners state the position in binding terms, and those contracts govern if they and this page ever diverge.
For the website and the contact form in §3, we are the controller outright.
Legal basis
Where the GDPR applies and the processing relies on consent, that consent is collected by the publisher and reaches us as a TCF or GPP signal. We act on the signal we receive; we do not assume consent in its absence.
For fraud detection, invalid traffic filtering, security, billing and reconciliation we rely on legitimate interests under Article 6(1)(f) — the interests being our own and our partners’ in a marketplace that is not defrauded and in invoices that can be substantiated. We have balanced those interests against the rights of the people concerned; the processing is narrow, short-lived and not used to make decisions about any individual.
How long we keep it
Retention periods, by category of data.
- Bid requests are not stored. The auction runs in memory and the request is discarded. There is no bid request log, and no table anywhere in our systems holds request-level rows.
- Aggregated analytics: 13 months. What we keep is pre-aggregated to the minute across dimensions such as partner, country, format and outcome. These rows carry counts and totals — how many requests, how many bids, how much was spent — and no identifier for any person. They are what our partners are invoiced from and what a discrepancy is reconciled against. Deleted automatically after 13 months.
- Diagnostic samples: 48 hours. To debug integrations we sample a small fraction of raw traffic — 1% by default, each capture capped at 256KB. These samples can contain the fields in §4. They are deleted automatically after 48 hours, are never read by any report, invoice or reconciliation, and exist only so that an engineer can see why a specific integration is misbehaving.
- Contact enquiries: 24 months from last contact (§3).
The 48-hour and 13-month figures are enforced by the database itself, as expiry rules on the tables, rather than by a job somebody has to remember to run.
Who receives it
Buyers. The bid request, including the consent signals, goes to the demand-side platforms eligible to bid on it. Each is an independent controller for its own bidding decision and is bound by its contract with us to honour the signals it receives.
Infrastructure providers, acting as our processors under Article 28: Hetzner Online GmbH (Germany) for servers and storage, and Cloudflare, Inc. for DNS, the CDN serving this website, and access control on our internal console. The exchange itself runs on dedicated hardware in the European Union.
Anthropic PBC, for the automated operational agents described on our homepage. These agents read aggregated analytics — the rows in §7 that contain no personal data — in order to propose configuration changes to a human. They do not touch bid requests, do not run inside the auction, and are not sent personal data.
We also disclose data where we are legally required to, and to professional advisers under confidentiality.
International transfers
Our servers are in the European Union. Some of our processors and some buyers are established outside the EEA. Where data is transferred out, we rely on an adequacy decision where one covers the destination, and otherwise on the European Commission’s Standard Contractual Clauses together with an assessment of the destination country’s law. Details of the mechanism for a specific recipient are available on request to [email protected].
Your rights
If the GDPR applies to you, you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out. Write to [email protected] and we will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.
A limitation on what those rights can produce, stated so that a request is not made on a false expectation. Because we do not store bid requests (§7), we generally cannot locate data relating to a specific person: there is no profile to retrieve and no identifier to search against. If you supply an advertising identifier and an approximate time, we can search the 48-hour diagnostic sample. Outside that window, no data relating to you is held, and a search would return nothing.
To stop personalised advertising more broadly, the effective controls are the ones at the source: your device’s advertising ID settings, the consent choices offered by each website or app, and the industry opt-outs at youradchoices.com and youronlinechoices.eu. An opt-out with us alone would not achieve what you want, and we will not imply otherwise.
You may also complain to a supervisory authority. In Italy that is the Garante per la protezione dei dati personali, garanteprivacy.it. You may instead complain to the authority where you live or work.
Children
The exchange is not directed at children. Where a publisher signals that a request is subject to COPPA or is child-directed, that signal is passed to buyers with the request and constrains what they may lawfully do with it. We do not knowingly process the data of children under 16 for advertising purposes, and neither this website nor our commercial relationships are directed at them.
Security
Traffic to the exchange and to this website is encrypted in transit. Our internal console is not reachable from the public internet without passing an identity check at the network edge, access to it is role-based, and every configuration change is recorded in an audit trail naming who made it, when and why. Data services run on a private network with default-deny firewalls and are not exposed publicly. No system is perfectly secure, and we do not claim otherwise.
Changes to this policy
We will update this page when our processing changes, and the effective date at the top is what tells you which version applied when. Where a change materially affects the people whose data we process, we will tell our publisher and buyer partners directly rather than relying on them to re-read the page.
Cortex Technologies SRL, Via Pola, 11, 20124 Milano, Italy. VAT IT18089101002.