Website Privacy Policy
Privacy Policy
for the website rockrtb.com
Last updated: 01 July 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:
Rock RTB GmbH
Halbmondstraße 2
74072 Heilbronn
Germany
Email:
[email protected]
Website:
https://rockrtb.com
2. General Information
The protection of personal data is of great importance to Rock RTB GmbH.
This Privacy Policy informs you about which personal data is processed when you visit our website, for what purposes this processing takes place, the legal basis on which it is based, and which rights you have under the General Data Protection Regulation (GDPR).
This Privacy Policy applies exclusively to the website rockrtb.com, including all subpages, as well as to services offered through it, such as contact forms, customer accounts, registrations, and API access.
For data processing within our programmatic advertising platform (DSP), our separate Platform Privacy Policy also applies.
3. Hosting
Our website is operated on servers provided by our hosting service provider:
Hetzner Online GmbH
Industriestraße 25
91710 Gunzenhausen
Germany
When you access our website, the web server automatically processes information transmitted by your browser to our server.
This includes, in particular:
- IP address
- Date and time of access
- Browser type
- Browser version
- Operating system
- Referrer URL
- Pages accessed
- HTTP status code
- Amount of data transferred
- User agent
This processing is carried out exclusively for:
- provision of the website,
- ensuring system security,
- error analysis,
- detection of misuse,
- technical administration.
The processing is based on Art. 6(1)(f) GDPR.
Our legitimate interest is the secure and stable provision of our online services.
4. Server Log Files
When you visit our website, server log files are automatically created. These contain, in particular:
- IP address
- Time of access
- URL accessed
- Browser information
- Operating system
- HTTP status codes
- Technical error messages
Server log files are processed exclusively to ensure technical operation, for error analysis, and to defend against attacks.
These data are not combined with data from other sources.
The log files are regularly deleted unless a statutory obligation or security-related reasons require longer storage.
5. Cookies
Our website uses cookies and similar technologies.
Cookies are small text files stored on your device that contain certain information.
These may include:
- technically necessary cookies,
- functional cookies,
- analytics cookies,
- marketing cookies.
Technically necessary cookies are used in particular for:
- secure login,
- session management,
- user management,
- protection against misuse,
- provision of the website.
Marketing or analytics cookies are only set after your express consent.
Legal bases:
- Section 25(2) TDDDG or Art. 5(3) of the ePrivacy Directive for technically necessary cookies
- Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR for cookies requiring consent
6. Cookiebot (Consent Management)
To manage your consents, we use the consent management service:
Cookiebot (Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark.)
Cookiebot enables us to obtain, document, and manage your consent for cookies and similar technologies in compliance with the GDPR.
In particular, the following may be processed:
- IP address (truncated)
- Consent status
- Browser information
- Device information
- Timestamp
- Consent ID
The processing is based on Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR.
The data are stored exclusively to fulfill our statutory documentation obligations under the GDPR.
7. Google Tag Manager
Our website uses Google Tag Manager, a service provided by:
Google Ireland Limited
Gordon House, Barrow Street,
Dublin 4,
Ireland.
Google Tag Manager is a tag management system that enables the integration of various technologies on our website.
Google Tag Manager itself generally does not process personal data for analytics or marketing purposes and does not create user profiles. It is used exclusively for the technical management and execution of website tags.
Depending on your consent, additional services may be loaded via Google Tag Manager. Which services are activated, if any, depends exclusively on your selection in the cookie consent banner.
The legal basis for processing is Art. 6(1)(a) GDPR insofar as services requiring consent are loaded via the Tag Manager.
8. Contact Form
If you contact us via the contact form, we process the personal data you provide.
This includes, in particular:
- Name
- Company
- Email address
- Telephone number (if provided)
- Subject
- Message
- Date and time of the inquiry
The processing is carried out exclusively to handle your inquiry and communicate with you.
The legal basis is Art. 6(1)(b) GDPR if your inquiry is related to the conclusion or performance of a contract. In all other cases, processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in efficiently handling incoming inquiries.
9. Registration of a Customer Account
Our website enables business customers to register a user account. As part of the registration process, the following data may be processed in particular:
- First and last name
- Company name
- Company address
- Email address
- Telephone number
- Login data
- Password (stored in encrypted form)
- Language settings
- User role
- Time of registration
Registration serves to provide our services and manage the business relationship.
The legal basis is Art. 6(1)(b) GDPR.
10. Customer Area
Registered users receive access to a protected customer area. Within this area, the following may be processed in particular:
- Account settings
- Campaign data
- Billing information
- Contract data
- API settings
- Access logs
- Security information
This processing is carried out exclusively to fulfill our contractual obligations towards our customers.
The legal basis is Art. 6(1)(b) GDPR.
11. API Usage
Rock RTB provides registered business customers with API interfaces. When using our APIs, the following may be processed in particular:
- API keys
- Authentication data
- Timestamps
- IP address
- Technical request and response data
- Log data
- Error logs
- Usage statistics
These data are processed in order to:
- ensure authentication,
- ensure the technical operation of the API,
- prevent misuse,
- analyze errors,
- detect security incidents.
The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
12. Payments and Payment Service Providers
Advertisers can top up their customer account or settle invoices in various ways.
Depending on the payment method selected, personal data is transmitted to the respective payment service provider insofar as this is necessary for payment processing.
This may include, in particular:
- Name
- Company name
- Billing address
- Email address
- Invoice number
- Payment amount
- Currency
- Payment status
- Transaction ID
- Payment references
- Time of payment
Rock RTB does not store complete credit card data.
Processing is carried out exclusively to execute the payment transaction, fulfill the contract, and comply with statutory retention and accounting obligations.
The legal basis for processing is Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR.
Credit Card Payments
If credit card payments are offered, payment processing is carried out through an external PCI-DSS-compliant payment service provider.
Payment data are processed directly by the respective payment service provider in accordance with its privacy policy.
Rock RTB receives only information about the payment status and whether the transaction was successful or unsuccessful.
PayPal
If PayPal is selected as the payment method, payment processing is carried out by:
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
Further information on data processing by PayPal can be found at: https://www.paypal.com/privacy
Cryptocurrency Payments
Where payments by cryptocurrency are offered, payment processing is carried out through the respective payment service provider or wallet provider used.
Depending on the network used, the following may be processed in particular:
- Wallet address
- Transaction hash
- Blockchain network
- Payment amount
- Timestamp
- Currency
Blockchain transactions are publicly viewable by their technical nature.
Rock RTB processes this data exclusively for payment processing and assigning the payment to the respective customer account.
Bank Transfer
If payment is made by bank transfer, we process the payment information transmitted by your bank.
This includes, in particular:
- Account holder
- IBAN
- BIC
- Payment reference
- Invoice number
- Amount
- Booking date
This processing is carried out exclusively for payment processing and to fulfill statutory accounting and tax obligations.
Future Payment Service Providers
Rock RTB may integrate additional payment service providers in the future, such as Paxum or comparable providers.
If new payment services are introduced, this Privacy Policy will be updated accordingly.
13. Security of User Accounts
To protect our platform and user accounts, we implement appropriate technical and organizational security measures.
These include, in particular:
- encrypted data transmission (TLS/SSL),
- secure password storage using cryptographic hashing methods,
- role-based access permissions,
- session management,
- protection against brute-force attacks,
- detection of suspicious login attempts,
- logging of security-related events,
- regular security updates.
To maintain security, login information such as login time, IP address used, browser information, and device information may be processed.
This processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is to protect our platform and our customers and to prevent unauthorized access.
14. Security Logs and Misuse Detection
To protect our systems and detect security incidents, we process technical log data.
This includes, in particular:
- Login and logout times,
- IP address,
- API requests,
- Error logs,
- Authentication events,
- Access to administration areas,
- Unusual usage patterns.
These data are used exclusively to ensure IT security, analyze errors, and detect and prevent misuse.
The legal basis is Art. 6(1)(f) GDPR.
15. Fraud Prevention
To prevent fraud, misuse of our services, payment fraud, and attacks on our systems, personal data may be processed.
This includes, in particular:
- Technical device information,
- IP addresses,
- Login information,
- Payment status,
- Transaction information,
- Security logs,
- API usage data.
The processing is carried out exclusively to protect our platform, our customers, and our business partners.
The legal basis is Art. 6(1)(f) GDPR.
16. Invoicing and Accounting
As part of contract processing, we process personal data for the preparation of quotations, invoices, credit notes, and to fulfill statutory accounting and retention obligations.
This may include, in particular:
- Company name,
- Contact person,
- Billing address,
- VAT identification number,
- Payment information,
- Invoice number,
- Booking data,
- Payment status.
The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR.
Documents relevant for tax and commercial law purposes are stored in accordance with the statutory retention periods.
17. Know-Your-Customer (KYC) and Compliance
Where necessary to comply with legal requirements, prevent fraud, or assess risks, Rock RTB may process or request additional information about business customers.
This may include, in particular:
- Company information,
- Commercial register information,
- VAT identification number,
- Proof of identity of authorized representatives,
- Proof of beneficial owners,
- Compliance and sanctions list checks.
Such processing is carried out exclusively where there is a legal obligation to do so or where a legitimate interest exists pursuant to Art. 6(1)(f) GDPR.
18. API Security
To ensure stable and secure operation of our API infrastructure, we implement various technical protection measures.
These include, in particular:
- API keys,
- Authentication procedures,
- Rate limiting,
- Access restrictions,
- Logging of API requests,
- Misuse detection,
- Automatic blocking mechanisms in the event of unusual behavior.
These measures serve to protect our systems and the integrity of the platform.
The legal basis is Art. 6(1)(f) GDPR.
19. Business Customers
The services of Rock RTB GmbH are intended exclusively for companies, advertisers, agencies, publishers, advertising networks, and other business customers.
Our services are not intended for consumers or minors.
20. International Business Activities
Rock RTB works with business partners in various countries.
As part of contract performance, data may be exchanged with advertisers, publishers, SSPs, ad exchanges, technology partners, and payment service providers within and outside the European Economic Area.
Where personal data is transferred to third countries, this is carried out exclusively in compliance with the requirements of Art. 44 et seq. GDPR.
21. Automated Decisions
Rock RTB uses automated technical processes for the selection, optimization, and delivery of digital advertising.
These processes serve exclusively for the technical execution of programmatic advertising auctions and campaign optimization.
As a general rule, no solely automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning data subjects or similarly significantly affects them takes place in connection with visiting this website.
22. Newsletter
If you subscribe to our newsletter, we process your email address and, where applicable, your name.
Registration is carried out using a double opt-in procedure.
After registration, you will receive a confirmation email in which you must confirm your subscription.
Processing is carried out exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future.
23. Retention Period
As a general rule, we store personal data only for as long as necessary to fulfill the respective purposes.
Where statutory retention obligations exist, the data are stored in accordance with statutory requirements.
The following retention periods generally apply:
| Data category | Retention period |
|---|---|
| Server logs | up to 90 days |
| Contact inquiries | up to 24 months after completion |
| Customer accounts | until the account is deleted or the contract ends, unless statutory obligations prevent deletion |
| API logs | up to 180 days |
| Newsletter data | until consent is withdrawn |
| Contract and invoice data | in accordance with commercial and tax law retention periods |
After the respective periods have expired, the data are deleted or anonymized unless statutory retention obligations or legitimate interests prevent this.
24. Recipients of Personal Data
Personal data may, where necessary, be transmitted to the following categories of recipients:
- Hosting service providers
- IT service providers
- Technical maintenance companies
- Payment service providers (where used)
- Tax advisors
- Auditors
- Legal advisors
- Authorities
- Courts
- Contractual partners
- Affiliated companies (where necessary)
Any further disclosure will only take place if there is a legal basis for doing so or if you have given your consent.
25. Transfers to Third Countries
Personal data is transferred to countries outside the European Union or the European Economic Area only if:
- this is legally permitted,
- appropriate safeguards are in place,
- Standard Contractual Clauses (SCCs) have been concluded,
- an adequacy decision by the European Commission exists, or
- you have expressly consented.
26. Rights of Data Subjects
Under the GDPR, you have, in particular, the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- Right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR)
You may exercise your rights at any time by contacting [email protected].
27. Data Security
Rock RTB GmbH implements appropriate technical and organizational measures to protect personal data against loss, manipulation, unauthorized access, and other security risks.
These include, in particular:
- encrypted data transmission (TLS/SSL),
- role-based access controls,
- strong authentication procedures,
- regular security updates,
- logging of security-related events,
- network and system monitoring,
- backup and recovery procedures.
28. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy if legal requirements, technological developments, or our services change.
The current version is available at any time at https://rockrtb.com.
29. Contact
If you have any questions about data protection or the processing of personal data, you can contact us at any time:
Rock RTB GmbH
Halbmondstraße 2
74072 Heilbronn
Germany
Email: [email protected]