Privacy Policy
1. INTRODUCTION
XPLN.AI SAS. (“XPLN.AI”, “we”, “us” or “our”) is providing transparency and accountability solutions in online advertising. We specifically use the following domains and subdomains :
- xpln.tech
- log.xpln.tech
- cdn.xpln.tech
- vast.xpln.tech
We provide independent digital media measurement, data and analytics about advertisement (or “ad”) and impression delivery, to help advertisers and advertising inventory sellers (together “Customers”) confirm accurate delivery characteristics, including brand safety, viewability metrics, contextual and environmental parameters (for example, the website on which an ad appears, and where it appears on the webpage), ad impression characteristics, and provide insights that allow our Customers to make informed decisions about the placement of their creative and brand.
XPLN.AI uses various technologies to collect information about online advertising, website traffic, mobile app traffic, and connected device traffic in order to deliver advertising transparency and accountability products and solutions to our Customers (collectively, “Solutions”).
We treat any data that relates or is linked to an identified or identifiable individual as “Personal Information” regardless of that individual’s location. As it relates to our Solutions, XPLN.AI limits any information we collect to information that does not allow the identification of an individual without additional information. For example, XPLN.AI processes your Internet Protocol (“IP”) address, which is a number that is automatically assigned to a computer when the Internet is used. While XPLN.AI treats such information as Personal Information, in accordance with best practices and applicable laws, we never combine that information with any other data that would enable us to identify the individual to whom it relates.
This notice of privacy practices (the “Solutions Privacy Notice”) is intended to inform individuals whose data may be processed through our Solutions (“End User(s)” or, “you” and “your”) of : (1) the types of information XPLN.AI may gather about you or your device when an advertisement that is analyzed by us is delivered to you on a website you are viewing or in an app you are using, (2) our privacy practices, how we may use, share, and otherwise process information that is deemed Personal Information, and (3) what your rights are with regards to such Personal Information. This Solutions Privacy Notice also explains what non-personal information (“Technical Information”) we collect about the ads that we track and how we use that Technical Information to power our Solutions.
This Solutions Privacy Notice covers all XPLN.AI Solutions and subsidiaries, unless a separate Solution-specific notice is posted on the relevant website.
2. ROLE, PURPOSE AND LEGAL BASIS OF PROCESSING
XPLN.AI’s fraud prevention (“Fraud Prevention”) and geography compliance authentication (“Geo Authentication”) Solutions require the processing of Personal Information. XPLN.AI operates Fraud Prevention as a “controller” and Geo Authentication as a “processor”. With respect to the California Consumer Privacy Act (“CCPA”), our designation may vary depending on the specific relationship with each Customer. As it relates to Fraud Prevention we may serve as a “business” or a “non-third party”. As it relates to Geo Authentication we serve as a “service provider”.
XPLN.AI’s legal basis for processing Personal Information through our Solutions is the legitimate interest of: (i) our Customers to avoid ad-related fraud and present geographically accurate and compliant information to End Users, (ii) the End Users in receiving fraud-free and geographically accurate and compliant information, and (iii) the general public in the continued availability of a free internet.
XPLN.AI participates in the IAB Europe Transparency & Consent Framework and complies with its Specifications and Policies. XPLN.AI’s identification number within the framework is 1142.
XPLN.AI’s other Solutions (such as viewability, context authenticity, brand safety, media quality, ad experience, premiumness) do not require the processing of Personal Information.
3. WHAT DATA DO WE COLLECT AND FOR WHAT PURPOSES?
XPLN.AI, to carry out its business purposes of providing, maintaining and improving its Solutions collects and uses certain categories of Personal Information and Technical Information. The categories of Personal Information and Technical Information processed through the XPLN.AI Solutions are outlined below. To the extent Personal Information is required for the operation of one or more features of a XPLN.AI Solution, such Personal Information will be used only for the specific purposes outlined below, unless otherwise required by law. Additionally, in some circumstances, it may be necessary to process the Personal Information in conjunction with some Technical Information for XPLN.AI’s Solutions to properly function. In any such scenarios, the combined data is considered Personal Information and protected accordingly.
We never combine, analyze or enrich the Personal Information and Technical Information we process with additional information with the goal of identifying the End Users.
We never track you or your online activities across apps and websites or over time, we do not rely on persistent technologies such as third-party cookies and we never create profiles or audience groups to target individuals.
1. Categories of Technical Information collected and used to power the XPLN.AI Solutions:
- Advertising campaign attributes – The identifier of the advertiser that delivers an ad, its campaign and placement identifiers, the identifiers of the media property selling the inventory to the advertiser or any intermediary advertising platform are collected and processed to identify the Customer we are servicing, to apply the correct settings for the Customer, to segment the Customer reports according to these identifiers and to bill the Customer.
- Web content attributes – The web address (URL) of the page/frame where the ad is being delivered to, and the address of any referring pages/frames are collected to ensure the ads are delivered in the right context our Customer has set in the profile settings in our system.
- Digital environment attributes – The type of connected device the advertisement is being delivered to: mobile, desktop, the browser type and version used to render the page where the ad appears and the operating system are collected to determine what version of our code would properly run in that environment and to properly measure if the advertisement had the chance to become viewable on the screen according to industry standards which vary between environments.
- Viewability attributes – The location of the ad on the page, the size of the ad, the size of the screen, the size of the viewport, the tab focus status, the browser focus status, the time duration the ad was in the viewable part of the webpage and the scroll position of the webpage are collected to determine and report to our Customers if the advertisement had the chance to become viewable on the screen.
- Exposure and engagement attributes – Data that shows if the ad was clicked is collected to help our Customers measure the performance of the advertisement, the advertising campaign or the media property.
2. Categories of data collected and used to power Fraud Prevention:
- Pseudonymous electronic presence and device identifiers – i.e. IP address, user agent string or derivatives of these two values – are used in order to assess whether the online presence or device is participating in or associated with a fraudulent scheme.
3. Categories of data collected and used to power Geo Authentication:
- Pseudonymous electronic presence and device identifiers – IP address – are collected to determine the geographical location they are associated with. Each IP is associated with a country, and, within most countries, may be associated with more specific information down to zip code. Your exact geolocation information is never collected.
The Solutions are not intended to or directed at the processing of children’s Personal Information. We do not knowingly collect Personal Information from children, as such terms are defined by applicable laws from time to time. If you are a parent or guardian and believe your child’s Personal Information may have been processed through the Solutions, please contact us by using the information in Section 11, “How to Contact XPLN.AI” below and we will take steps to securely delete their Personal Information from our systems.
4. HOW DO WE USE DATA WE COLLECT?
XPLN.AI only uses the Technical Information and Personal Information collected for the purposes outlined in Section 3, “What Data do we Collect and for What Purposes?”, of this Solutions Privacy Notice. In general, the Technical Information and your Personal Information are processed to provide reporting, dashboards, feedback and insights (“Reporting”) to our Customers.
XPLN.AI Reporting, in any format, is anonymized and aggregated, or, to the extent impression level information is required, each impression is de-identified to ensure Personal Information of End Users is never shared with Customers. This Section provides additional insight into how the Technical Information and your Personal Information is processed to achieve the business purposes specified in Section 3 of this Solutions Privacy Notice.
XPLN.AI uses the Technical Information collected through the Solutions, as specified in Section 3.1, in the following ways:
- To analyze and report on the context in which advertisements are displayed, their quality, authenticity and performance. Specifically, information illustrating whether an ad being displayed is in compliance with a Customer’s pre-set legal and placement requirements, as well as preference settings the Customer has established in our system.
- To provide insights and preemptive decisioning of impression opportunities. XPLN.AI technology analyzes the data characteristics of an impression opportunity and determines whether the Customer’s advertisement should be displayed or not, for example by determining that the surrounding content does not align with that Customer’s preferences.
XPLN.AI, to power Fraud Prevention, uses the Technical Information and Personal Information collected through the Solutions, as specified in Section 3.1 and 3.2, to:
- To review and identify specific ad impressions that are fraudulent due to being generated by bot-controlled, non-human browsers.
- To assess and identify invalid traffic such as traffic generated by ad injectors, traffic originated in data centers, misrepresented traffic, emulated traffic and other types of invalid traffic.
- To analyze and identify websites, mobile and connected device apps, and media properties that have fraudulent traffic and/or generate fraudulent advertising impressions.
- To identify traffic patterns across websites participating in fraudulent advertising activity.
- To differentiate between traffic generated by bot-controlled, non-human browsers and human browsers.
- To determine whether ads analyzed follow applicable legal requirements and preferences set by our Customers.
- Determine if a middleware is attempting to misrepresent its operating characteristics to prevent the identification of fraud or other invalid traffic.
- Determine if website traffic or ad impressions are originating from a server farm rather than human-generated browsing activity.
- Determine if traffic is being acquired through fraudulent practices or through other traffic acquisition practices that are not compliant with a Customer’s guidelines or preferences.
- To create records of IP addresses and user agent strings associated with fraudulent schemes and non-human generated traffic (“Fraud Tables”). Because such data points are associated with non-human interactions, they do not constitute Personal Information.
XPLN.AI, to power Geo Authentication, uses the Technical Information and Personal Information collected through the Solutions, as specified in Section 3.3, to:
- Assess at high level (country, state, region, zip code) the geographic location of the End User and verify if the End User is located within the Customer’s campaign or traffic settings.
5. TO WHOM AND HOW DOES XPLN.AI DISCLOSE PERSONAL INFORMATION AND TECHNICAL INFORMATION?
XPLN.AI does not disclose Personal Information to third parties, except as strictly necessary for our business purposes to operate, maintain and improve our Solutions. To the extent we voluntarily share any Personal Information, we ensure it is protected by the recipients in a manner consistent with our own policies and standards.
We may share your Personal Information with:
- Service Providers – companies we have contracted to provide us services such as IT and system administration, infrastructure and hosting services, research and analytics, support and quality assurance, security and other services, for the purposes and pursuant to the legal basis described above. You can request a list of our Service Providers, what Personal Information they receive and for what purposes by contacting us. You can find out contact information in Section 13 “How to Contact XPLN.AI” of this Solutions Privacy Notice.
- Third Parties engaged by our Customers – to support our Customers, we may integrate our Solutions with other tools and services engaged by our Customers to deliver enhanced services and reporting capabilities. Under no circumstances do we receive data from these integrations that enable XPLN.AI to enrich our data and identify End Users. In limited scenarios, we may share impression level information with companies engaged by our Customers to conduct research on marketing effectiveness.
- Third Parties involved in a Corporate Transaction – in the event that XPLN.AI is acquired or merged with another company, or in the event of a reorganization, dissolution or other fundamental corporate change.
- We may be legally required to disclose your Personal Information:
- If a government entity, tribunal, law enforcement or regulatory agency requires such disclosure (for example as part of an ongoing investigation, subpoena, similar legal process or proceeding);
- As otherwise required under any applicable law, regulation, or rule; and
- If we believe, in good faith, that such disclosure is necessary to protect or defend our rights or the rights of others, to assist in an investigation or to prevent illegal activity.
Fraud Tables and other Fraud Prevention related reports, data feeds, APIs and dashboards that do not contain Personal Information may be shared with or made available to Customers and other third parties, including for example industry organizations, as necessary for XPLN.AI to carry out its business purposes of providing, maintaining and improving the Fraud Prevention portion of our Solutions and combat ad-fraud.
We do not share your Personal Information with our Customers. Any reports and analytics we make available to Customers via our Reporting Portal are anonymous, which means they do not contain Personal Information. The reports are generally aggregated, but in limited circumstances impression level reporting is provided to our Customers, via FTP end points or APIs, provided that such reports do not contain any Personal Information. We may share Technical Information, which is anonymous, in aggregated formats or in its raw form, with third parties as we deem necessary to carry out our business purposes of providing, maintaining and improving the Solutions. Additionally, we may share anonymous or de-identified data on an aggregate basis in the normal course of operating our business; for example, to publish case studies and reports to show trends about the benefits and performance of our Solutions.
6. FOR WHAT PERIOD OF TIME DO WE RETAIN INFORMATION ABOUT YOU?
XPLN.AI retains any Personal Information processed through its Solutions only as long as necessary to effectuate the purposes outlined in this Solutions Privacy Notice, and in no event longer than thirty (30) days. Upon the expiration of that period, the Personal Information is securely purged from XPLN.AI’s systems.
Fraud Tables may be retained indefinitely to ensure the proper functionality of the Fraud Prevention Solution.
Technical Information, as it is anonymous in nature, may be retained by XPLN.AI indefinitely or as long as otherwise provided for in XPLN.AI’s policies and permitted by applicable laws and XPLN.AI’s agreements with its Customers.
7. HOW IS PERSONAL INFORMATION SECURED?
XPLN.AI has implemented appropriate technical, physical and organizational measures designed to protect Personal Information against accidental or unlawful destruction or accidental loss, damage, alteration, unauthorized disclosure or access, as well as all other forms of unlawful processing. While we follow generally accepted standards and best practices to protect Personal Information, no method of storage or transmission is 100% secure. However, we are constantly working to improve our safeguards and keep your Personal Information secure.
8. TRANSFERS OF PERSONAL INFORMATION BETWEEN COUNTRIES
Please be aware that the Personal Information we collect may be transferred to and maintained on servers or databases located outside your state, province, country, or other jurisdiction. While your Personal Information may be transmitted through a local temporary data center to ensure the Solutions are efficient and responsive, XPLN.AI ultimately stores and processes all Personal Information collected through the Solutions in the European Economic Area. If you have any questions about where we store Personal Information you can contact us as outlined in Section 11 “How to Contact XPLN.AI”.
9. WHAT ARE YOUR PRIVACY RIGHTS?
End Users in certain jurisdictions may have data subject rights enabling them to make requests related to their Personal Information. Most jurisdictions also provide End Users with the right to be informed of how any Personal Information is collected, used and with whom it may have been shared or disclosed, as well as for what purposes. XPLN.AI’s Solutions Privacy Notice is intended to meet any such requirements, but if you have any additional questions or would like to better understand how your Personal Information may have been collected, used or with whom it may have been shared or disclosed, and why, please contact us by using Section 11 “How to Contact XPLN.AI” below.
Residents of the European Economic Area or California, among others, have several rights under the applicable privacy laws and regulations, for example, under the General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”). To exercise these rights, you can contact us using Section 11 “How to Contact XPLN.AI” below. In accordance with certain laws and regulations, such as the CCPA, you may also designate an authorized agent to submit a request or exercise a right on your behalf. We will not discriminate or retaliate against you for exercising your rights.
These rights are:
- The right to access to any Personal Information we may hold about you, including information about the categories and the specific pieces of Personal Information.
- The right to correct any inaccurate Personal Information we may hold about you. Please keep in mind that due to the nature of the Personal Information we collect and the method of our collection, it is highly unlikely that we hold Personal Information that is inaccurate or that would meet the circumstances requiring a correction.
- The right to request that XPLN.AI delete any Personal Information we may hold about you.
- The right to request that the processing of Personal Information about you be suspended or restricted for a period of time, for example, while you assess whether you have other rights you would want to exercise.
- To the extent your Personal Information is processed based on a legitimate interest, you have a right to object to such processing.
To the fullest extent possible, we fulfill any request related to an End User provided we can match the End User to Personal Information we hold on our systems. However, in certain circumstances we may be required to verify your identity to fulfill a request. To verify your identity or understand the scope of your request we may need to request additional information about you. You will not be required to create an account with us to submit a request or have it fulfilled. You will need to provide an email address so we can communicate with you and support your request, as well as any information we may need to allow us to verify whether we hold any Personal Information about you. Please be aware that circumstances may exist that will render us unable to fulfill your request, but if we are unable to fulfill your request we will explain why. To the extent we do not hold any Personal Information about you we will let you know. We make best efforts to respond to all inquiries and requests as soon as reasonably possible, but please allow up to thirty (30) days for us to respond.
To the extent XPLN.AI serves as a “processor” or “service provider”, as defined in the applicable law, you may need to direct your requests to exercise your rights to the relevant Customer who serves as the “controller” or “business”.
10. CHANGES TO THIS SOLUTIONS PRIVACY NOTICE
We may update this Solutions Privacy Notice from time to time to reflect changes in our Solutions, practices, policies or other internal or external changes, as well as to comply with new legal requirements. Any changes will be posted as soon as they go into effect. If we make updates, we will update the “effective date” listed at the top of this Solutions Privacy Notice to help you understand when changes were made. To stay informed of any such updates, we encourage you to refer back to this Solutions Privacy Notice regularly. Please note that any translation of this Solutions Privacy Notice is intended solely to facilitate your access to this information. The English version is the only official version of this Solutions Privacy Notice and any translation inaccuracies or discrepancies are not binding and have no legal effect for compliance or enforcement purposes.
11. HOW TO CONTACT XPLN.AI
If you have any questions, concerns or comments about this Solutions Privacy Notice, or you believe your Personal Information has been used in a way that is not consistent with the Privacy Notice or your choices, you can contact our Privacy Team at:
- XPLN.AI S.A.S., Privacy Team, 32 rue de Paradis, 75010 Paris
- or by email : privacy@xpln.ai
- or using our contact form