EEA and UK Privacy Notice
Last Updated: March 16th, 2026
This EEA and UK Privacy Notice (this "Notice") supplements RevOptimal's Global Privacy Policy and describes how we collect, use, and share personal data relating to individuals located in the European Economic Area (EEA) or the United Kingdom (UK), and the rights available to you under the General Data Protection Regulation (GDPR) and UK GDPR, respectively.
Enterprise customers should read this policy alongside their applicable contract and data protection addendum ("DPA") where and as signed with us.
This Notice Includes:
Understanding our role matters because it determines your rights and how you should direct any requests.
We act as a data controller when we decide the purposes and means of processing personal data — that is, when we determine why and how your data is used. This includes when we:
As a controller, we are directly responsible for your data and your rights apply to us directly.
We act as a data processor when we process personal data on behalf of our enterprise customers, following their instructions. This includes when we:
As a processor, our enterprise customer is the data controller and is responsible for their use of your data. If your data has been processed in connection with one of our customers' campaigns and you wish to exercise your rights, you should contact that customer directly. Where we can identify the relevant customer and it is appropriate to do so, we will refer your request to them.
The following table provides additional information about how we use and disclose your data, consistent with GDPR and UK GDPR disclosure requirements:
| Category of Personal Information | Processing Purpose | Categories of Recipients | Legal Basis & Processing Categories |
|---|---|---|---|
| Personal Identifiers (e.g. names, aliases, emails, phone numbers, customer numbers, mobile advertising IDs (MAIDs), IP addresses) | Audience segmentation, targeted advertising delivery, analytics | Our customers (advertisers), data analytics providers, digital data management platforms and service providers | Processed on the basis of legitimate interests and/or consent; disclosed to recipients for marketing, reporting, and/or analytics purposes |
| Protected Classification Characteristics (sex/gender, marital status, military/veteran status, national origin, ancestry, age, home ownership, education level, professional details) | Audience segmentation, demographic targeting, model development | Our customers and data analytics providers | Processed on the basis of explicit consent; disclosed to recipients for audience segmentation and demographic targeting purposes |
| Online Identifiers (e.g. device identifiers, cookies, beacons, pixel tags, and similar technologies) | User recognition across sessions, tracking and analytics, fraud prevention | Our customers, data analytics providers, digital data management platforms and service providers | Processed on the basis of consent and/or legitimate interests; deidentified or aggregate statistics disclosed to recipients. See our Cookie Policy for more information. |
| Commercial Information (products/services purchased, obtained, or considered; purchasing or consuming histories) | Behavioral targeting, consumer preference analysis, predictive modeling | Our customers, data analytics providers, digital data management platforms | Processed on the basis of legitimate interests and/or consent; disclosed to recipients for behavioral targeting and analytics purposes |
| Internet/Electronic Network Activity (browsing history, search history, interaction with websites, applications, advertisements) | Behavioral analysis, interest-based advertising, service improvement | Our customers, data analytics providers, advertising networks and service providers | Processed on the basis of legitimate interests and/or consent; disclosed to recipients for behavioral analysis and interest-based advertising purposes |
| Geolocation Data (precise or approximate location) | Geographic segmentation | Our customers and data analytics providers | Processed on the basis of legitimate interests and/or consent; disclosed to recipients in aggregate or deidentified form only for geographic segmentation purposes; precise location data is not disclosed to third parties |
| Inferences (profiles reflecting preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, aptitudes) | Predictive audience modeling, personalized marketing, segment creation | Our customers and data analytics providers | Processed on the basis of legitimate interests and/or consent; disclosed to recipients as aggregate audience segments |
The Company retains personal data for no longer than is necessary for the purposes described above. Personal data is generally deleted within 24 months of collection, unless a longer retention period is required or permitted by applicable law or contractual obligation.
Under the GDPR and UK GDPR, we must have a valid legal basis for every processing activity. We rely on the following legal bases:
Where we collect data directly through our Site — for example, through cookies or marketing communications — we ask for your consent before processing non-essential data. You have the right to withdraw consent at any time without affecting the lawfulness of processing that occurred before withdrawal. You can manage your cookie consent through our Cookie Preference Center.
We rely on legitimate interests as a legal basis for:
Where we rely on legitimate interests, you have the right to object to that processing at any time. See "Your Rights" below.
We process certain personal data where necessary to comply with our legal obligations, including obligations under data protection law, financial regulations, and applicable court orders.
Where you are an enterprise customer or a contact at an enterprise customer, we process your professional contact data to perform our contractual obligations to you.
RevOptimal is based in the United States and we maintain data in regional areas aligned with the location of collection and processing. When we process personal data of EEA or UK residents, this data is collected, processed and stored in Germany and the UK, respectively.
Our core business involves profiling — the automated processing of personal data to evaluate, analyze, or predict characteristics about individuals, which we use to assign individuals to audience segments. We do not use fully automated decision-making that produces legal or similarly significant effects on individuals in the sense contemplated by Article 22 of the GDPR and UK GDPR. Our audience segment assignments are used by our customers for advertising targeting purposes, not to make binding decisions about access to services, employment, healthcare or credit.
Where our customers use segment data to make significant decisions about individuals, those customers are the relevant data controllers and are responsible for compliance with Article 22 of the GDPR and UK GDPR. You have the right to object to profiling activities we conduct as a controller. See "Your Rights" below.
As an EEA or UK resident, you have the following rights regarding your personal data. Because most of the personal data we hold was not collected directly from you, some rights may be subject to exemptions or limitations, which we will explain when you submit a request.
You have the right to receive clear, transparent information about how we process your personal data — which is the purpose of this Notice.
You have the right to request confirmation of whether we process personal data about you and, if so, to receive a copy of that data and supplementary information about how it is used.
You have the right to request correction of inaccurate personal data we hold about you.
You have the right to request deletion of your personal data where:
You have the right to request that we restrict our processing of your personal data in certain circumstances, such as while we verify the accuracy of data you have disputed.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You have the right to object at any time to processing based on legitimate interests, including profiling. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims. You may also object at any time to processing for direct marketing purposes, including profiling related to direct marketing, and we will cease such processing immediately upon receipt of your objection.
Where we engage in automated profiling that produces legal or similarly significant effects, you have the right to request human review, contest the decision, and express your point of view. As noted above, our profiling activities do not currently produce such effects directly.
Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of prior processing. To withdraw cookie consent, please use our Cookie Preference Center.
To exercise any of the rights described above, please submit a request through any of the following methods:
We will respond to your request within one month of receipt. Where requests are complex or numerous, we may extend this period by a further two months, in which case we will notify you within the first month and explain the reason for the extension.
We do not charge a fee for requests unless they are manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.
Verification: We may need to verify your identity before processing your request. We will ask for the minimum information necessary to do so.
We retain personal data for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, regulatory, contractual, or reporting obligations. Retention periods vary depending on the nature of the data and the purpose of processing:
If you have concerns about how we handle your personal data that we are unable to resolve to your satisfaction, you have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first so that we have the opportunity to address your concerns directly before you approach a supervisory authority.
For EEA residents: Contact your national data protection authority. A full list of EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/board/members_en.
For UK residents: Contact the Information Commissioner's Office (ICO) at https://ico.org.uk/global/contact-us/.
We review and update this Notice periodically to reflect changes in our practices, applicable law, and regulatory guidance. We will notify you of material changes by posting the updated Notice on our website and updating the effective date above. Where required by law, we will seek renewed consent or provide additional notice of material changes.
If you have questions about this Notice, your rights, or how we handle your personal data, please contact us at:
We have also appointed Superset as our representative in the European Union and United Kingdom for data protection matters. Superset can be contacted at:
Ready to supercharge your ROAS?