Platform Privacy Policy

Platform Privacy Policy of Rock RTB GmbH

Last updated: 01 July 2026

1. General

Rock RTB GmbH operates its own Demand-Side Platform and AdTech infrastructure (“Rock RTB Platform”). Through this platform, we enable advertisers, agencies, advertising networks, and other business partners to programmatically purchase, deliver, measure, and optimize digital advertising on websites, mobile applications, and other digital environments.

This Privacy Policy informs users of digital environments about which personal data may be processed in connection with our platform, the purposes for which this processing takes place, the legal basis on which the processing is based, and the rights of data subjects.

Our platform generally does not process directly identifying data such as names, postal addresses, or email addresses of end users. Processing is generally carried out using pseudonymous online identifiers, technical device information, IP addresses, cookie IDs, Mobile Advertising IDs, and other technical signals used in digital advertising.

2. Controller

The controller within the meaning of the General Data Protection Regulation, insofar as Rock RTB determines the purposes and means of processing, is:

Rock RTB GmbH
Halbmondstraße 2
74072 Heilbronn
Germany

Email: [email protected]
Website: https://rockrtb.com

A Data Protection Officer has not currently been appointed.

3. Our Role in the Programmatic Advertising Ecosystem

Rock RTB is a DSP and AdTech platform. We purchase digital advertising inventory through programmatic interfaces, real-time bidding processes, supply-side platforms, ad exchanges, publisher integrations, and other technical partners. This inventory is subsequently used to deliver advertising campaigns for direct advertisers, agencies, advertising networks, and other integrated partners.

Depending on the specific integration and contractual arrangements, we may act as an independent controller, joint controller, or processor for data protection purposes. The specific role depends in particular on who determines the purposes and means of data processing.

Data may be processed through various technical methods, in particular through:

  • Cookies
  • Pixels and web beacons
  • Server-to-server integrations
  • OpenRTB and API interfaces
  • Mobile Advertising IDs such as IDFA or Google Advertising ID
  • Local Storage or comparable technologies
  • Consent strings, in particular within the framework of the IAB Transparency & Consent Framework v2.2
  • Technical log data generated during the delivery or measurement of digital advertising

These technologies may be used to recognize a device or browser, technically process advertising requests, place bids in real time, deliver advertising, detect fraud, measure campaigns, and optimize ad delivery.

4. How Data Is Collected Through Our Platform

Data can be processed using various technical methods, in particular:

  • Cookies
  • Pixels and web beacons
  • Server-to-server integrations
  • Open RTB and API interfaces
  • Mobile advertising IDs such as IDFA or Google Advertising ID
  • Local storage or similar technologies
  • Consent strings, especially within the framework of the IAB Transparency & Consent Framework v2.2
  • Technical log data generated during the delivery or measurement of digital advertising

These technologies can be used to recognize an end device or browser, technically process advertising requests, place bids in real time, deliver advertising, detect fraud, measure campaigns, and optimize ad delivery.

5. Categories of Personal Data

As part of our platform, the following categories of data may be processed in particular:

5.1 Online Identifiers

  • Cookie IDs
  • Mobile Advertising IDs
  • Pseudonymous user or device identifiers
  • Partner IDs
  • IDs from cookie matching or ID synchronization procedures
  • Consent strings and opt-out information

5.2 Technical Device and Browser Data

  • Device type
  • Operating system
  • Browser type and browser version
  • Language settings
  • Screen resolution
  • App or website information
  • Technical information relating to the advertising placement
  • User-Agent information

5.3 Network and Connection Data

  • IP address
  • Approximate location information that may be derived from the IP address
  • Internet service provider
  • Timestamp
  • Technical request and response data

5.4 Advertising and Campaign Data

  • Information relating to advertising requests
  • Information relating to bids and auctions
  • Advertisements delivered
  • Impressions
  • Clicks
  • Conversions, where technically integrated
  • Campaign, advertiser, and placement information
  • Frequency and reach information

5.5 Interest and Segment Information

Where valid consent has been obtained or another lawful legal basis exists, pseudonymous information relating to interests, audience segments, or inferred preferences may be processed. This information is used to select, deliver, and optimize digital advertising.

5.6 Consent and Data Protection Preferences

We may process information about whether users have consented to, rejected, or withdrawn consent to certain data processing activities. This includes, in particular, signals from consent management platforms and the IAB TCF v2.2.

6. Purposes of Processing

We process personal data in particular for the following purposes:

6.1 Participation in Real-Time Bidding Auctions

We process advertising requests, technical device information, online identifiers, and contextual information to decide in real time whether to place a bid for an advertising space and which advertisement should be displayed.

6.2 Delivery of Digital Advertising

We use data to technically provide, display, and deliver digital advertising and to ensure its correct presentation on websites, in apps, or in other digital environments.

6.3 Selection of Relevant Advertising

Data may be used to select advertising based on contextual information, technical information, pseudonymous identifiers, interests, location information, or other permissible signals.

6.4 Frequency Capping

We may process data to control how often a particular advertisement is displayed to the same browser or device.

6.5 Measurement and Reporting

We process data to measure impressions, clicks, conversions, reach, interactions, and other campaign metrics and to provide our customers with corresponding reports.

6.6 Campaign Optimization

Data may be used to technically and economically optimize advertising campaigns, for example with regard to reach, target audiences, bidding strategies, placements, advertisements, or performance.

6.7 Fraud Prevention and Security

We process data to detect and prevent invalid traffic, ad fraud, bot traffic, technical attacks, misuse, and other security-related incidents.

6.8 Billing and Documentation

Data may be processed to bill customers, partners, publishers, advertising networks, or other parties for services and to provide evidence of proper service provision.

6.9 Compliance with Legal Obligations

We process data where necessary to comply with legal obligations, respond to official requests, or assert, exercise, or defend legal claims.

7. Legal Bases for Processing

The processing of personal data is carried out, depending on the purpose and specific processing operation, on the basis of the following legal grounds:

  • Art. 6(1)(a) GDPR – consent, in particular for accessing or storing information on the device and for personalized advertising and profiling, where required.
  • Art. 6(1)(f) GDPR – legitimate interests, in particular for non-personalized advertising, technical delivery, security, fraud prevention, billing, reporting, and system operation, where consent is not required.
  • Art. 6(1)(b) GDPR – performance of a contract, insofar as data is required to provide contractual services to business partners.
  • Art. 6(1)(c) GDPR – legal obligation, insofar as we are legally required to process the data.

Where accessing information on a device or storing information on a device requires consent under applicable data protection or telecommunications law, processing is carried out only on the basis of the corresponding consent.

8. IAB Transparency & Consent Framework v2.2

Rock RTB may participate in the IAB Transparency & Consent Framework v2.2 or process TCF signals. In this case, we receive information through the consent management platform of the respective digital environment about whether and for which purposes consent has been granted or whether certain processing activities have been rejected.

These signals may be taken into account in particular for the following purposes:

  • Storing or accessing information on a device
  • Selecting personalized advertising
  • Creating and using profiles for personalized advertising
  • Measuring advertising performance
  • Market research to gain insights into target audiences
  • Developing and improving services
  • Fraud prevention and technical security

Users may grant, reject, or withdraw their consent through the consent management platform of the respective digital environment.

9. Profiling and Personalized Advertising

Where valid consent has been obtained for this purpose, pseudonymous profiles may be created or used to deliver more relevant advertising. Such profiles may, for example, be based on information about websites visited, apps used, advertising interactions, approximate location information, device characteristics, or interest segments.

These profiles are not used to directly identify users by name. We do not process directly identifying data such as names, postal addresses, or plain-text email addresses to create such advertising profiles.

10. Cookie Matching and ID Synchronization

In the programmatic advertising ecosystem, it may be necessary to match pseudonymous identifiers between technical partners. This is known as cookie matching or ID synchronization.

In this process, a pseudonymous identifier used by Rock RTB is linked to a pseudonymous identifier of a partner so that advertising requests, bidding, campaign management, frequency management, measurement, and billing can function technically.

Such synchronization takes place only where there is a lawful legal basis for doing so and the respective data protection preferences of users are taken into account.

11. Recipients and Categories of Recipients

Personal data may be transmitted to the following categories of recipients:

  • Advertisers
  • Agencies
  • Advertising networks
  • Supply-side platforms
  • Ad exchanges
  • Publishers and marketers
  • Technical integration partners
  • Measurement and verification service providers
  • Anti-fraud and brand-safety providers
  • Hosting and infrastructure service providers
  • IT and security service providers
  • Legal and tax advisors
  • Authorities, where legally required

12. Hosting and Technical Infrastructure

Our technical infrastructure may, among others, be operated by Hetzner. In this context, technical log data, server data, advertising requests, campaign data, and other data required for platform operation may be processed.

With service providers that process personal data on our behalf, we enter into the required data processing agreements pursuant to Art. 28 GDPR.

13. Transfers to Third Countries

As part of our activities as a DSP and AdTech platform, personal data may be transferred to countries outside the European Union or the European Economic Area, particularly where advertisers, advertising networks, technical partners, or infrastructure and integration partners outside the EU/EEA are involved.

Where personal data is transferred to third countries, we ensure that appropriate safeguards are in place, such as:

  • Adequacy decisions of the European Commission
  • EU Standard Contractual Clauses
  • Additional technical and organizational safeguards
  • Contractual obligations imposed on recipients
  • Other transfer mechanisms permitted under the GDPR

14. Retention Period

We store personal data only for as long as necessary for the respective purposes or as required by statutory retention periods.

Pseudonymous online identifiers, cookie IDs, Advertising IDs, bid request data, log data, campaign measurement data, and reporting data are generally stored only for a limited period. The specific retention period may vary depending on the data category, purpose, legal basis, and contractual requirements.

Where data is required for fraud prevention, billing, legal defense, or compliance with legal obligations, it may be stored for a longer period.

Data category Retention period
Cookie IDs / Mobile Advertising IDs up to 13 months (or as per user consent)
Bid request and log data up to 30 days
Campaign reporting data up to 24 months
Fraud prevention data up to 12 months
Billing and contract data in accordance with statutory retention periods

[Add specific retention periods, e.g., Cookie ID: X months, log data: X days, reporting data: X months.]

15. Security Measures

We implement technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, or destruction.

These may include, in particular:

  • Access restrictions
  • Role and authorization concepts
  • Encryption during transmission
  • Logging of security-relevant activities
  • System monitoring
  • Separation of production and test systems
  • Security updates and technical maintenance
  • Contractual obligations imposed on service providers

16. No Processing of Special Categories of Personal Data

We do not intend to process special categories of personal data within the meaning of Art. 9 GDPR. These include, in particular, data concerning health, religion, political opinions, trade union membership, genetic or biometric data, as well as data concerning sex life or sexual orientation.

Our platform is not designed to directly identify users by name.

17. Opt-Out and Withdrawal

Users may withdraw consent at any time through the consent management platform of the respective digital environment.

Where our processing is based on legitimate interests, data subjects may object to the processing. Requests may be sent to the following address:

[email protected]

Please note that we generally cannot directly identify data subjects by name. To process a request, it may therefore be necessary for the data subject to provide us with additional information, such as a Cookie ID, Mobile Advertising ID, or other pseudonymous identifier.

18. Rights of Data Subjects

Data subjects have, in accordance with the GDPR, in particular the following rights:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Right to withdraw consent
  • Right to lodge a complaint with a data protection supervisory authority

To exercise these rights, data subjects may contact [email protected].

19. Right to Lodge a Complaint with a Supervisory Authority

Data subjects have the right to lodge a complaint with a data protection supervisory authority. The data protection supervisory authority of the federal state of Baden-Württemberg may, in particular, have jurisdiction insofar as Rock RTB GmbH has its registered office there.

20. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, in particular if our platform, our processing activities, legal requirements, or technical standards change.

The current version will be published on our website.

21. Contact

If you have any questions regarding this Privacy Policy or the processing of personal data by Rock RTB, please contact:

Rock RTB GmbH
Halbmondstraße 2
74072 Heilbronn
Germany

Email: [email protected]
Website: https://rockrtb.com