Digital East GmbH — Privacy Policy

Who we are

Last updated: Sept 01, 2026

Digital East GmbH (“Digital East”, “we”, “us”) operates a demand-side platform. We buy digital advertising space on behalf of advertisers and media buyers.

Digital East GmbH Axel-Springer-Platz 3, 20355 Hamburg, Germany Amtsgericht Hamburg, HRB 149159 VAT ID: DE 315 628 769 Represented by: Oscar Subanovic, CEO Contact: privacy@digitaleast.mobi

We are registered in the IAB Europe Transparency & Consent Framework (“TCF”) as a Global Vendor, Vendor ID 665.

This policy has two parts. Part A applies if you visit our website or deal with us as a customer or business contact. Part B applies if you are an internet user whose device data reaches us when an advertisement is shown to you. The final sections apply to everyone.

Part A — Website visitors, customers and business contacts

What we collect

•      Contact and account details: name, company, job title, email, telephone, postal address, login credentials.

•      Campaign data: campaign settings, creatives, targeting configuration, budgets, performance history. 

•      Billing information: payment details, invoices, transaction records.

•      Website technical data: IP address, browser, device type, operating system, pages visited, date and time of visit.

Why, and on what legal basis

Purpose

Basis

Providing platform access and delivering our services

Contract, Art. 6(1)(b)

Responding to enquiries

Art. 6(1)(b) or legitimate interests, Art. 6(1)(f)

Invoicing and accounting

Art. 6(1)(b) and legal obligation, Art. 6(1)(c)

Website security and preventing misuse

Legitimate interests, Art. 6(1)(f)

Enforcing our Terms of Use

Legitimate interests, Art. 6(1)(f)

Non-essential cookies and analytics

Consent, Art. 6(1)(a)

Cookies on our website

Cookies strictly necessary for the website to work are set without consent. All others, including analytics, are set only after you consent through the banner shown on your first visit. You can change or withdraw that choice at any time using the cookie settings link on our website. Continuing to browse is not treated as consent.

We use Cookiebot (Usercentrics A/S, Denmark) to collect and record your cookie choices. Cookiebot processes your IP address and a consent identifier on our behalf, as our processor, within the EU.

Website analytics

We use analytics services provided by Google Ireland Limited to understand how visitors use our website. They run only if you consent through the cookie banner.

Google acts as our processor. Google may pass data to Google LLC and other Google companies in the United States and elsewhere in order to provide the service. See “International transfers”.

This concerns our own website only. It does not involve advertising bid request data and is separate from everything described in Part B.

How long we keep it

  • Customer and account data: for the duration of the relationship plus 6 years
  • Invoices and accounting records: 6 to 10 years, as required by §257 HGB and §147 AO
  • Website server logs: 120 days

Part B — Advertising data

How data reaches us, and our role

We do not collect this data from you directly. When you visit a website or use an app carrying advertising, the publisher’s supply-side platform or ad exchange sends a bid request to platforms like ours. It describes the advertising opportunity and your device. We decide in real time whether to bid and at what price.

For this we act as an independent controller. Where an advertiser instructs us to use data they supply, we act as their processor under a data processing agreement, and the advertiser is responsible for the lawful basis of that data.

What a bid request may contain

  • IP address
  • Device characteristics: device type, operating system, browser, screen size, language
  • A device identifier: a mobile advertising identifier (such as IDFA or Google Advertising ID) or a cookie identifier
  • The website or app you are using, and information about the advertising slot
  • Approximate location, such as country, region or city
  • Precise location (GPS coordinates), where you have opted in to it
  • Your privacy choices, sent to us as a consent signal

This information does not include your name, email address or telephone number. It is nonetheless personal data under the GDPR and we treat it as such.

What we do with it

  • Recognise the same browser across advertising opportunities, so that we can limit how often you are shown the same advertisement.
  • Decide whether to bid, and at what price, using the information in the bid request.
  • Detect and prevent advertising fraud and invalid traffic, and fix errors in our systems.
  • Deliver and present the advertisement we have won.
  • Measure performance of the advertisements we delivered, and report results to the advertiser.
  • Understand audiences at a group level — for example, which kinds of content an advertisement performs well alongside.
  • Bill our customers for the advertising we delivered on their behalf.
  • Improve our platform, including the models we use to price and select advertising opportunities.

If you are in the European Economic Area or the United Kingdom

Consent

Your choices are collected by the consent management platform on the website or app you are using, and passed to us inside the bid request.

We process your data only where consent has been given for all of the purposes we rely on. Where it has not, we do not process your data at all — we do not bid, and the bid request is discarded.

We check the consent signal ourselves on every request. If no signal reaches us, or we cannot read it, we treat that as consent not given. Where the publisher of the site or app has restricted one of the purposes we rely on, we do not bid either.

The purposes we rely on, as registered under Vendor ID 665, all requiring consent:

  • Purpose 1 — Store and/or access information on a device
  • Purpose 2 — Use limited data to select advertising
  • Purpose 7 — Measure advertising performance
  • Purpose 9 — Understand audiences through statistics or combinations of data from different sources
  • Purpose 10 — Develop and improve services

We also rely on our legitimate interests for two special purposes: ensuring security, preventing and detecting fraud and fixing errors (Special Purpose 1), and delivering and presenting advertising (Special Purpose 2). To recognise your device we rely on Feature 3 (identify devices based on information transmitted automatically).

Precise location (Special Feature 1) is used only where you have specifically opted in to it. Without that opt-in we discard the coordinates, even where a supply partner includes them.

We also require our supply partners, by contract, to send us bid requests from the EEA and the UK only where consent has been obtained. We do not rely on that alone — we verify the signal ourselves.

Personalised advertising

We are not registered for TCF Purpose 3 (create profiles for personalised advertising) or Purpose 4 (use profiles to select personalised advertising), and we do not carry out either for users in the EEA or the UK. We do not build a profile of you, and we do not combine your activity across different websites or apps. Advertising is selected using contextual and technical signals about the advertising opportunity and your device.

Should this change, we will first update our registration in the Global Vendor List so that consent management platforms ask you for that permission, and we will update this policy before we begin.

Legitimate interests

This policy is also our legitimate interest disclosure under the TCF.

We rely on legitimate interests for Special Purposes 1 and 2 above, and for no other purpose. Our interest is in delivering advertising we have been contracted to deliver, protecting our platform and our customers from fraudulent and invalid traffic, and keeping our systems working and secure.

We have assessed this against your interests and concluded that the processing is necessary for the service to function, that the data used is limited to what is technically required, that it is not used to make decisions about you as an individual, that no profile is created, and that it is kept only for a limited period. These two special purposes cannot be switched off through the TCF, but you may object under Art. 21(1) GDPR using the contact details below.

Changing your mind

Your choices are collected by the publisher, so the most effective route is the privacy or consent settings on the website or app where you saw the advertisement. You can also:

  • On a mobile device: reset or delete your advertising identifier, or turn off personalised advertising, in your device settings (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Google → Ads).
  • In a browser: delete or block cookies in your browser settings.
  • Contact us at privacy@digitaleast.mobi.

If you are outside the EEA and the UK

For users outside the EEA and the UK, we may additionally use audience, interest or demographic signals provided by our supply partners to select advertising, as instructed by our advertiser customers and subject to applicable local law.

Because Digital East GmbH is established in Germany, this processing is also subject to the GDPR. We rely on consent obtained by the publisher or supply-side platform, which our supply partners are contractually required to obtain and signal to us, and on our legitimate interests where consent is not the applicable basis. Local law in your country may give you further rights; see “Your rights”.

Data supplied by advertisers

Where an advertiser asks us to use their own data, we process it only on their instructions, under a written data processing agreement, and only for that advertiser’s campaigns. The advertiser is the controller of that data and is responsible for its lawful basis and for informing you. We do not combine it with other advertisers’ data.

How long we keep advertising data

Bid requests are processed in real time. Deletion is enforced automatically by our systems, not by manual review.

  • Where we do not win the advertising opportunity, or the advertisement is not served: deleted within 3 days.
  • Records of the advertisements we served, including impressions, clicks and conversions: up to 90 days, for as long as they still carry an identifier.
  • The identifier we use to recognise a browser or device: up to 6 months.
  • Records kept to detect fraud and invalid traffic: 90 days.
  • Invoices and billing records: as set out in Part A.

After these periods we keep only aggregated statistics. These cannot be traced back to you and are no longer personal data.

What we store on your device

On websites, we set one cookie in your browser so that we can recognise it across advertising opportunities. Its maximum lifetime is 6 months, and it may be renewed while you continue to see advertising we deliver. In the EEA and the UK we set or read it only where your consent is recorded for us and for Purpose 1.

In mobile apps we store nothing on your device and read nothing from it. The advertising identifier reaches us from the publisher’s supply partner inside the bid request.

Where a supply partner needs to match its own identifier for your browser with ours, that happens only where the same consent is recorded. For users in the EEA and the UK we never start that process ourselves.

A full technical disclosure of what we store is published at:

https://digitaleast-assets.s3.eu-central-1.amazonaws.com/iab-tcf/tcf-03.json

Sections applying to everyone

Who we share data with

  • Supply-side platforms, ad exchanges and publishers, in order to bid for and buy advertising space.
  • Cloud infrastructure providers: Google Cloud Platform and Amazon Web Services, in the European Union.
  • Our advertiser customers, who receive campaign performance reporting.
  • Onedigitalad Technologies Ltd, our wholly owned subsidiary in India, which provides technical and operational support. See “International transfers”.
  • Cookiebot / Usercentrics A/S (Denmark), our website consent management platform.
  • Google Ireland Limited, our website analytics provider.
  • Other service providers supporting our platform and our business. We keep a current list and will provide it on request.
  • Professional advisers: lawyers, accountants, auditors.
  • Authorities, where legally required.
  • Security vendors, and the supply-side platforms and exchanges concerned, including Google, where we report a confirmed malvertising incident.

We do not pass the advertising data we receive on to other advertising technology companies. We do not sell personal data.

International transfers

Our platform and the advertising data we process are hosted in the European Union, on Google Cloud and AWS.

India. Our wholly owned subsidiary Onedigitalad Technologies Ltd provides technical and operational support, working remotely on our systems. Personal data remains hosted in the European Union and is not stored outside the EU. Because India is not covered by an EU adequacy decision, these transfers are made under the European Commission’s Standard Contractual Clauses.

United States. Our website analytics provider may transfer data to the United States. Those transfers are covered by Standard Contractual Clauses and, where applicable, by certification under the EU–US Data Privacy Framework. This concerns our website only, not advertising data.

Other countries. Our advertiser customers and supply partners are located worldwide. Where we transfer personal data outside the EEA, we do so under Standard Contractual Clauses, an adequacy decision, or another mechanism permitted by Chapter V GDPR.

You may request a copy of the relevant safeguards at privacy@digitaleast.mobi.

Security

We maintain appropriate technical and organisational measures to protect personal data, as required by Art. 32 GDPR. These include encryption in transit and at rest, access control, multi-factor authentication, logging and monitoring, and regular review of our own measures and those of our providers.

Your rights

Under the GDPR you have the right to access your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), to object to processing based on legitimate interests (Art. 21(1)), and to withdraw consent at any time (Art. 7(3)).

You may also lodge a complaint with a data protection authority. Ours is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany https://datenschutz-hamburg.de

You may also complain to the authority where you live.

Identifying you. For advertising data we hold no name or email address, only pseudonymous identifiers. To act on a request we need the relevant identifier — your cookie ID or your device’s advertising identifier. Without it we cannot locate your data and, under Art. 11(2) GDPR, may be unable to comply. Please include it. We respond within one month.

Contact privacy@digitaleast.mobi.

Children

Our services are not directed at children. We do not knowingly process the personal data of anyone under 16.

Automated decision-making

Our platform decides automatically, in real time, whether to bid on an advertising opportunity and at what price. These decisions determine which advertisement you see. They do not produce legal effects concerning you and do not otherwise significantly affect you within the meaning of Art. 22 GDPR.

Links to other sites

Our website and the advertising we deliver may link to sites we do not operate. This policy covers only our own processing.

Changes to this policy

We may update this policy as our services develop. We will post the updated version here with a new date. Where a change affects the purposes for which we process advertising data, we will update our Global Vendor List registration and this policy before the change takes effect.

Contact

Digital East GmbH Axel-Springer-Platz 3, 20355 Hamburg, Germany privacy@digitaleast.mobi