Privacy policy
This policy explains what personal data Publink processes, why, and what rights you have. It covers this website and, in outline, the Publink platform. It is written in plain language on purpose.
1. Who we are
Publink ("Publink", "we") operates the website at publink.io and the Publink ad-serving platform. For questions about this policy or your data, write to hello@publink.io.
2. This website
What we collect
As little as possible. This website is a set of static pages served from a content delivery network.
- No tracking cookies. The site sets no cookies and loads no analytics, advertising or social-media scripts. See the cookie policy.
- Server logs. Our hosting provider records standard request logs (IP address, user agent, requested URL, time) for security and operational purposes. These are retained for a limited period by the provider and are not used to profile visitors.
- Contact. The contact page opens your own email client. Nothing you type is stored on this site. When you email us, we keep the correspondence for as long as needed to respond and to keep a record of the relationship.
- Fonts. Fonts are served from our own domain. No requests are made to third-party font services.
Legal basis
Where the GDPR or UK GDPR applies, we rely on our legitimate interest in operating a secure website and in responding to enquiries you initiate.
3. The Publink platform
The platform processes ad requests on behalf of our customers (publishers and advertisers). In that processing, Publink acts as a processor for the customer, who is the controller. The terms of that processing are set out in the customer agreement and data processing terms.
Data in an ad request
An ad request may contain an IP address, a device or advertising identifier, an app bundle or page URL, coarse location, device characteristics and privacy signals (for example a TCF consent string or a US privacy string). Publink uses this data to:
- apply the customer's targeting and filtering rules;
- request bids from the demand partners the customer selected, forwarding the signals as received;
- serve the winning creative and record impression and playback events;
- filter invalid traffic;
- report and bill.
Publink does not add identifiers to a request, does not build audience profiles, and does not sell or license request data to third parties.
Privacy signals
Consent and opt-out signals carried by a request are forwarded unchanged to the demand partners called for that request. Honouring those signals is the responsibility of each party in the chain under applicable law and industry frameworks.
Retention
Raw request-level data is retained for a short operational window needed for serving, troubleshooting and reconciliation, after which it is aggregated or deleted. Aggregated reports do not identify individuals. Account and billing records are kept for as long as the customer relationship and legal obligations require.
Platform accounts
Customer users sign in through a managed identity provider. We store the name, email address and role of each user, and an audit trail of account and settings changes. We do not store passwords.
4. Sharing
We share personal data only with:
- demand partners selected by the customer, as part of an ad request;
- infrastructure providers (hosting, content delivery, managed database, identity) under contracts that restrict their use of the data to providing the service;
- authorities where required by law.
5. International transfers
Infrastructure may be located outside your country. Where data is transferred out of the EEA or the UK, we rely on appropriate safeguards such as standard contractual clauses.
6. Your rights
Depending on where you live, you may have the right to access, correct, delete or restrict the processing of your personal data, to object to processing, and to data portability. To exercise a right regarding this website or your correspondence with us, email hello@publink.io. For data processed in an ad request, please contact the publisher or app whose service you were using; we will assist them in responding. You also have the right to lodge a complaint with your supervisory authority.
7. Security
We use transport encryption on all endpoints, encrypted managed storage, role-based access with least privilege, and audit logging. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify affected parties as required by law.
8. Children
This website and the platform are intended for businesses and are not directed at children.
9. Changes
We will post any changes to this policy on this page and update the date at the top. Material changes to how the platform processes data are communicated to customers directly.