Privacy Policy
This policy explains what personal data Adlegion Limited collects, why we collect it, who we share it with, how long we keep it and what rights you have. It covers our website, our advertising and affiliate campaigns, our owned social media properties and our payments consultancy work.
1.Who we are
Adlegion Limited ("Adlegion", "we", "us", "our") is a media, advertising and consultancy business registered in England and Wales.
| Legal entity | Adlegion Limited |
|---|---|
| Company number | 12418118 (England & Wales) |
| VAT number | GB 341 4597 00 |
| Registered office | Apperley House, The Green, Apperley, Gloucestershire, GL19 4DQ, United Kingdom |
| Data protection contact | accounts@adlegion.com |
For the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018) and the Privacy and Electronic Communications Regulations 2003 (PECR), Adlegion is the controller of the personal data described in this policy except where section 2 says otherwise.
We are not required to appoint a statutory Data Protection Officer. Our data protection matters are handled by the contact above.
2.Scope and our role
This policy applies to personal data we handle in relation to:
- visitors to www.adlegion.com and anyone who contacts us through it;
- representatives of our clients, prospective clients and suppliers;
- affiliates, publishers, influencers and other media partners;
- merchants and payment service providers we introduce or advise;
- brands, talent, teams and creators we introduce to one another for sponsorship;
- audiences reached by campaigns we plan, buy or operate; and
- followers of, and interactions with, social media properties we own and operate.
2.1 When we are a controller
We act as a controller — deciding why and how data is used — for our own website, our own marketing, our supplier and client relationship records, our recruitment, and the social media properties we own and operate.
2.2 When we are a processor
Where we run advertising, affiliate or analytics activity on a client's instructions and using the client's own systems, accounts, audiences or customer data, the client is the controller and we act as a processor on their behalf. In those cases the client's own privacy notice governs how that data is used, and our handling of it is governed by the data processing terms in our contract with them, which meet the requirements of Article 28 UK GDPR.
2.3 When we and a platform are independent controllers
Advertising platforms such as Meta, Google, TikTok, X, Reddit, LinkedIn and affiliate networks generally act as independent controllers, or as joint controllers with the advertiser, for data processed on their own infrastructure. We do not control their processing. Their own privacy notices and terms apply, and we recommend you read them.
2.4 Advertising platform integrations
We operate our own creative trafficking platform, AdHangar, which publishes advertising creatives into our clients' own advertising accounts. Where AdHangar accesses data through advertising platform APIs (including the Meta Marketing API), the client authorises access to specific ad accounts and Pages, and our access is limited to the assets they have granted. We use that access solely to deliver the service to that client. We do not combine one client's platform data with another's, we do not use it for any other purpose, and we do not request or process end-user personal data from those platforms. A client may withdraw our access at any time through their own account settings on the relevant platform.
3.Data we collect
3.1 Website visitors and enquirers
- Contact form data: your name, email address, company name, the service you selected and the content of your message.
- Newsletter subscription: your email address, and the fact and date of your opt-in, if you sign up to our newsletter.
- Correspondence: emails, call notes and anything else you send us.
- Technical data: your IP address, user agent, referring page and timestamp, recorded in server and form-provider logs for security and abuse prevention.
We do not run analytics or advertising trackers on this website. See section 7.
3.2 Client, prospect and supplier contacts
- Business contact details: name, job title, employer, work email, work phone, LinkedIn profile.
- Relationship records: meeting notes, proposals, briefs, contracts, correspondence.
- Billing and payment details relating to the business, and the name of the individual authorising payment.
3.3 Affiliates, publishers and influencers
- Identity and contact details, trading name, website or channel URLs and platform handles.
- Payment details required to pay commission or fees, and tax status information.
- Performance data: clicks, conversions, commissions, quality and compliance records.
- Due diligence and verification records, including checks on traffic quality and advertising compliance.
3.4 Merchants and payment providers (payments consultancy)
- Business contact details for the individuals we deal with on each side of an introduction.
- Commercial information about the business: sector, volumes, geographies, existing arrangements, indicative rates.
- Records of introductions made, advice given and the outcome.
We do not collect or store cardholder data, bank credentials or payment card numbers belonging to a merchant's customers. We are not in the cardholder data environment and we do not act as a payment processor.
3.5 Campaign and advertising data
When we plan, buy or optimise advertising, the data involved is typically pseudonymous rather than directly identifying. It may include:
- online identifiers such as cookie IDs, mobile advertising IDs, device identifiers and IP addresses;
- hashed (irreversibly scrambled) email addresses or phone numbers used to match an advertiser's existing customers to a platform audience;
- approximate location, typically at city or postcode-district level;
- device, browser and connection information;
- on-site or in-app events supplied by the advertiser, such as page views, registrations, deposits, purchases or installs;
- inferred interests and audience segments provided by advertising platforms; and
- aggregated campaign performance: impressions, clicks, conversions, spend, CPM, CPA and return on ad spend.
3.6 Owned social media properties
We own and operate social media pages and media properties. On those properties we see the information the platform makes available to any page owner: public profile information of people who follow, comment on or message the page, the content of messages sent to us, and aggregated, de-identified audience insights such as age bands, countries and view counts. We do not receive the identity of individual viewers of a video from the platform.
3.7 Special category data
We do not seek special category data (such as data revealing health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation) or criminal offence data, and we ask that you do not send it to us. We do not knowingly build or target advertising audiences on the basis of special category data. Where such data reaches us unsolicited, we delete it promptly unless we are required to retain it.
4.Where we get it
- Directly from you — the contact form, email, calls, meetings, contracts and events.
- From your employer or colleagues — where they give us your business contact details as the right person to deal with.
- From our clients — campaign data, audience lists and conversion data supplied for us to act on.
- From advertising platforms, affiliate networks and measurement providers — campaign reporting, audience insights and attribution data.
- From publicly available sources — company websites, Companies House, LinkedIn and industry directories, used to identify the right business contact.
- From our own social media properties — interactions with pages we operate.
5.Why we use it and our lawful bases
We must have a lawful basis under Article 6 UK GDPR for everything we do with personal data. Ours are set out below.
| What we do | Data used | Lawful basis |
|---|---|---|
| Answer your enquiry and discuss working together | Contact form data, correspondence | Legitimate interests — responding to a request you made to us; steps prior to entering a contract |
| Provide our services and manage the client relationship | Client contacts, briefs, campaign data | Performance of a contract; legitimate interests where the contract is with your employer |
| Recruit, vet, manage and pay affiliates, publishers and influencers | Partner identity, payment and performance data | Performance of a contract; legal obligation (tax and record keeping) |
| Make and manage payments introductions | Business contacts and commercial information | Legitimate interests — operating a B2B introduction and advisory service |
| Plan, buy, optimise and report on advertising | Pseudonymous identifiers, event and performance data | Legitimate interests, or the client's chosen basis where we act as processor. Consent where required by PECR for cookies and similar technologies |
| Operate our owned social media properties | Public profile data, messages, aggregated insights | Legitimate interests — running and growing our media business |
| Send B2B marketing about our services | Business contact details | Legitimate interests, subject to PECR and an opt-out in every message. Consent where the law requires it |
| Prevent fraud, ad fraud, abuse and invalid traffic | Technical data, traffic and conversion patterns | Legitimate interests — protecting our clients, our partners and ourselves |
| Keep accounting records and meet tax duties | Billing and payment records | Legal obligation |
| Establish, exercise or defend legal claims | Any relevant records | Legitimate interests; legal obligation |
| Improve our services using aggregated benchmarks | Anonymised and aggregated performance data | Legitimate interests. Once anonymised this is no longer personal data |
Where we rely on legitimate interests, we have carried out a balancing assessment to satisfy ourselves that our interests do not override your rights and freedoms. You can ask us for a summary of that assessment, and you have the right to object — see section 13.
6.Advertising technology
This section explains, in plain terms, the advertising practices we operate for clients. It is provided for transparency; the specific processing on any given campaign is governed by the advertiser's own privacy notice where they are the controller.
6.1 Tags, pixels and SDKs
Advertisers commonly place a small piece of code — a tag, pixel or software development kit — on their website or app. It records that a visitor took an action and reports it back to an advertising platform so that campaigns can be measured and optimised. Where we implement such code on a client's property, we do so on the client's instruction and it is the client's responsibility, as controller, to obtain any consent required under PECR before it is set.
6.2 Programmatic and real-time bidding
Some display and video advertising is bought programmatically. When an ad slot becomes available, a bid request containing information such as a pseudonymous identifier, approximate location, device type and the page context is sent to prospective buyers, who decide in milliseconds whether to bid. This processing takes place on the infrastructure of the exchanges, supply-side and demand-side platforms involved, each of which acts as a controller for its own processing.
6.3 Audience matching and lookalike audiences
An advertiser may provide a list of its own customers to an advertising platform to reach them, exclude them, or find similar people. Identifiers such as email addresses are hashed before upload, so the platform receives a scrambled value rather than the address itself. Where we handle such a list we do so as a processor, on written instruction, and we require the advertiser to confirm it has a lawful basis and any necessary consent for that use.
6.4 Retargeting
Retargeting shows advertising to people who have previously visited a website or used an app. It relies on cookies or similar identifiers set on the advertiser's property. You can opt out of most retargeting through your browser or device settings and through the platform controls listed in section 7.
6.5 Affiliate tracking and attribution
Affiliate programmes use tracking links and, increasingly, server-to-server postbacks to attribute a sale, lead or deposit to the partner that referred it. The data passed is normally a click identifier, timestamp and transaction value. We use it to validate conversions, calculate commission and detect fraudulent or invalid traffic.
6.6 Clipping and influencer campaigns
Our clipping product distributes short-form video across social media properties we own and operate. Distribution and measurement happen inside the social platforms. We receive aggregated metrics — views, reach, engagement and demographic breakdowns — and not the identities of individual viewers. Where an influencer partners with us, we process their business contact, payment and performance data as described in section 3.3.
6.7 What we do not do
- We do not sell personal data.
- We do not build advertising audiences from special category data.
- We do not knowingly target advertising at children — see section 15.
- We do not combine our clients' customer data with other clients' data.
- We do not use data obtained while acting as a processor for one client to benefit another client, other than as anonymised, aggregated benchmarks that cannot identify any person or business.
7.Cookies and similar technologies
The only data recorded when you browse the site is the standard server log described in section 3.1, and — when you submit the contact form — the data transmitted to our form provider so the message can reach us. Our fonts are hosted on our own servers rather than a third-party font network, so browsing this site does not disclose your visit to a font provider.
If we later add analytics or advertising technology to this website, we will update this policy and, where PECR requires it, ask for your consent through the cookie banner before any non-essential cookie is set. Full detail, including how your consent choice is stored and how to change it, is in our Cookie Policy.
7.1 Controlling advertising cookies elsewhere
Advertising you see on other websites as a result of campaigns we run for clients relies on cookies and identifiers set by those websites and platforms. You can control them:
- in your browser settings, by blocking or deleting cookies;
- on your mobile device, by resetting or limiting your advertising identifier;
- through the ad settings offered by the major platforms, such as Google Ads Settings and Meta Ad Preferences; and
- through industry opt-out tools including Your Online Choices and the Network Advertising Initiative.
Blocking cookies does not stop you seeing advertising; it makes the advertising you see less relevant.
8.Marketing communications
We market our services to businesses. Where we send marketing email to a corporate subscriber, we rely on legitimate interests as permitted by PECR. Where we contact an individual or an unincorporated business, we rely on consent or the "soft opt-in" where the conditions for it are met.
Newsletter: if you subscribe to our newsletter, we rely on your explicit consent, given by ticking the opt-in box on the sign-up form. We use your email address only to send you the newsletter and will not use it for any other purpose. You can withdraw consent at any time — see below.
Every marketing message we send will:
- identify Adlegion clearly as the sender;
- provide a valid address for you to reply to; and
- offer a simple, free way to opt out.
You can opt out at any time by using the unsubscribe link or by emailing accounts@adlegion.com. We will act on it promptly. We will still send you messages that are necessary to provide a service you have asked for, such as replying to your enquiry.
9.Who we share data with
We share personal data only where there is a reason to. Recipients fall into these categories:
| Recipient | Purpose | Their role |
|---|---|---|
| Website host and form provider | Serving the site and delivering your enquiry to our inbox | Processor |
| Email, storage and productivity providers | Correspondence, documents, internal records | Processor |
| Advertising platforms and ad exchanges | Delivering and measuring campaigns | Independent or joint controller |
| Affiliate networks and tracking platforms | Attribution, commission and fraud checks | Controller or processor, depending on the arrangement |
| Our clients | Campaign reporting and delivery of the service they engaged us for | Controller |
| Merchants and payment providers | Making an introduction you or your business asked for | Controller |
| Accountants, auditors, insurers and legal advisers | Running and protecting the business | Controller or processor |
| Regulators, law enforcement and courts | Where we are legally required, or to establish or defend legal claims | Controller |
| A buyer or successor | If we sell or reorganise the business, or transfer part of it | Controller |
We put a written contract in place with every processor, requiring them to act only on our instructions, keep the data secure and confidential, and delete or return it at the end of the engagement.
We do not sell personal data, and we do not share it with third parties for their own independent marketing.
10.International transfers
We work with global clients and use service providers based outside the United Kingdom, including in the United States and the European Economic Area. Where personal data is transferred outside the UK, we make sure one of the following safeguards is in place:
- the destination country is covered by UK adequacy regulations;
- the transfer is covered by the UK International Data Transfer Agreement, or the International Data Transfer Addendum to the EU Standard Contractual Clauses;
- the recipient is certified under the UK Extension to the EU–US Data Privacy Framework; or
- another safeguard permitted by Chapter V of the UK GDPR applies.
Where required, we carry out a transfer risk assessment and apply supplementary measures. You can ask us for details of the safeguard used for a particular transfer by emailing accounts@adlegion.com.
11.How long we keep data
We keep personal data only as long as we need it, then delete it or irreversibly anonymise it. Our standard periods are:
| Record | Retention period |
|---|---|
| Enquiries that do not lead to a relationship | 24 months from last contact |
| Client and partner relationship records | 6 years after the relationship ends |
| Contracts and records needed for legal claims | 6 years after the contract ends (12 years for deeds) |
| Accounting and tax records | 6 years from the end of the accounting period, as required by law |
| Marketing contact records and opt-outs | Until you opt out; suppression records kept indefinitely so we can honour your opt-out |
| Campaign reporting | Anonymised or aggregated within 24 months unless a client contract requires otherwise |
| Server and security logs | Up to 12 months |
| Owned social media page interactions | As long as the platform retains them, or until you delete your interaction |
Where we hold data as a processor, we retain it for as long as the client's instructions require, and delete or return it when the engagement ends.
12.How we protect data
We take appropriate technical and organisational measures against unauthorised or unlawful processing and against accidental loss, destruction or damage, including:
- encryption in transit (HTTPS/TLS) across our website and services;
- access control on a least-privilege basis, with multi-factor authentication on business-critical accounts;
- separation of client accounts and campaign data;
- vetting of processors before we appoint them, and written data processing terms with each;
- staff confidentiality obligations and data protection awareness;
- spam and abuse protection on our contact form; and
- regular review of the tools and permissions we use.
No system is completely secure. If you send us confidential information by email, please be aware that ordinary email is not an encrypted medium.
13.Your rights
Under the UK GDPR you have the right to:
- Be informed about how we use your data — this policy.
- Access a copy of the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data where there is no good reason for us to keep it.
- Restrict processing in certain circumstances, for example while we check the accuracy of data you have challenged.
- Data portability — to receive data you gave us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Object to processing based on legitimate interests. Where you object to direct marketing, we will stop — there is no balancing test.
- Withdraw consent at any time where we rely on consent, without affecting processing carried out before you withdrew it.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects — see section 14.
To exercise a right, email accounts@adlegion.com. We will respond within one month. We may extend that by up to two further months for complex requests, and will tell you if we do. We may ask for proof of identity before we act. Exercising your rights is free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse it, and will explain why.
If your request relates to data we hold as a processor for a client, we will pass it to that client without undue delay and tell you we have done so.
14.Profiling and automated decisions
Advertising involves profiling in the sense that audiences are segmented and optimisation algorithms decide which advertisement to show to which pseudonymous profile. That processing does not produce legal effects concerning you or similarly significantly affect you.
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. We do not carry out credit scoring, and we do not make automated eligibility decisions about individuals.
Automated systems are used to detect fraudulent clicks, invalid traffic and abusive form submissions. Where such a system flags activity, a person reviews the outcome before any partner-level action is taken.
15.Children and age-restricted advertising
Our website and services are directed at businesses, not children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
For age-restricted categories we apply the age controls the relevant codes and regulators require, including:
- gambling advertising targeted only at users the platform identifies as 25 or over, in line with the CAP and BCAP codes and industry standards, unless a lower verified minimum is expressly permitted and instructed;
- exclusion of audience segments, creative and placements likely to appeal particularly to under-18s; and
- age-gating and content controls on owned media where the content or the advertising requires it.
16.Regulated sectors
We work in sectors with advertising rules that go beyond data protection law, including online gambling and betting, financial services and digital assets.
- Gambling: campaigns are run in line with the Gambling Commission's Licence Conditions and Codes of Practice, the CAP and BCAP codes and the Industry Group for Responsible Gambling standards, including responsible gambling messaging and targeting restrictions.
- Financial services and digital assets: we do not approve financial promotions. Any promotion requiring approval under section 21 of the Financial Services and Markets Act 2000 must be approved by an authorised person before we run it, and the client is responsible for obtaining that approval and for the accuracy and fairness of the promotion.
- Self-exclusion and vulnerability: where a client provides suppression or self-exclusion lists, we apply them as instructed and treat them as confidential. We do not use them for any other purpose.
Nothing in this policy makes Adlegion responsible for a client's own regulatory compliance, licensing or the accuracy of claims in their advertising. Our contractual position on regulated sectors is set out in our Terms & Conditions.
Adlegion is not a gambling operator and holds no gambling licence. We provide affiliate and marketing services to operators who are licensed themselves, and we advertise responsibly — 18+ only, never targeting under-25 audiences. If gambling is causing you or someone you know harm, free confidential support is available from BeGambleAware, GamCare, the National Gambling Helpline on 0808 8020 133 (free, 24/7), and GAMSTOP, which lets you self-exclude from every UK-licensed online operator at once.
17.Client and partner obligations
Where you provide personal data to us — as a client, affiliate, publisher, influencer or introducer — you confirm that:
- you have a valid lawful basis, and any consent required under UK GDPR and PECR, for us to process it as instructed;
- you have given the individuals concerned the privacy information the law requires, including that their data may be shared with an agency and with advertising platforms;
- the data is accurate, lawfully obtained, and free of special category or criminal offence data unless we have agreed otherwise in writing in advance;
- any suppression, opt-out or self-exclusion list you rely on has been applied before the data reaches us; and
- your instructions to us will not put us in breach of data protection law.
We will tell you if, in our opinion, an instruction infringes data protection law, and we may decline to act on it. You remain responsible for your own compliance as controller, and for the privacy information given to your customers. Nothing in this section limits liability that cannot lawfully be limited.
18.Confidentiality and our intellectual property
Information we share with you in the course of an enquiry or engagement — including rate cards, CPMs, media plans, audience data, partner lists, provider terms, commercial introductions, proposals and methodologies — is confidential to Adlegion. It is provided for the purpose of evaluating or receiving our services and for no other purpose.
You agree not to:
- disclose it to a third party without our written consent, other than to your own professional advisers under a duty of confidence;
- use it to approach our partners, publishers or providers directly in order to circumvent us; or
- scrape, harvest, crawl or systematically extract content, contact details or data from this website or our owned media properties, or use automated means to access them other than by well-behaved search engine crawlers.
All content on this website — including text, graphics, illustrations, logos and the Adlegion name and marks — is owned by or licensed to Adlegion and protected by intellectual property law. Reports, analyses, audience insights and methodologies we produce remain our intellectual property, subject to any licence expressly granted in a signed contract.
We may create anonymised and aggregated statistics and benchmarks from data we process, and use them to operate, improve and market our services. That material cannot identify any individual, client or partner, and once anonymised it is no longer personal data.
19.Security incidents
If a personal data breach occurs, we will assess it without delay. Where it is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it. Where it is likely to result in a high risk, we will also tell the individuals affected without undue delay.
Where we are acting as a processor, we will notify the client controller without undue delay after becoming aware, and give them the information they need to meet their own reporting duties.
To report a suspected security issue, email accounts@adlegion.com with the details.
20.Other websites
This website and our social media properties link to sites we do not control. This policy does not apply to them. We are not responsible for their content or their privacy practices, and we encourage you to read their own privacy notices.
21.Changes to this policy
We review this policy at least annually and whenever our processing changes materially. The version number and date at the top of this page show when it was last changed. Where a change materially affects you, we will take reasonable steps to bring it to your attention. Continuing to use our website or services after a change means the updated policy applies.
22.Contact and complaints
For any question about this policy, or to exercise a right, contact us at accounts@adlegion.com, or write to us at Adlegion Limited, Apperley House, The Green, Apperley, Gloucestershire, GL19 4DQ, United Kingdom.
We would like the chance to resolve any concern first. You also have the right to complain to the UK supervisory authority at any time:
| Authority | Information Commissioner's Office |
|---|---|
| Website | ico.org.uk/make-a-complaint |
| Helpline | 0303 123 1113 |
| Post | Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF |
If you are in the EEA, you may also complain to your local supervisory authority.
This policy is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it.