1. What GDPR means for GuardPPC
GDPR applies to personal data relating to identified or identifiable people in the European Economic Area, the United Kingdom, and related jurisdictions. In the GuardPPC context, that can include business contact details, IP addresses, device identifiers, session signals, and other information linked to ad traffic or website activity.
This page is a practical summary of GuardPPC’s GDPR approach. It does not replace our Privacy Policy, Terms of Service, or Data Processing Agreement.
2. Roles of the parties
GuardPPC does not play the same role in every data flow. The role depends on whether we collect information directly for our own business operations or process customer campaign data to provide the platform.
- GuardPPC as controller. We act as controller for website analytics, demo requests, account contacts, billing records, support communications, and similar information we collect directly.
- GuardPPC as processor. We act as processor when customers use GuardPPC to analyze click activity, session evidence, network signals, device traits, and campaign data connected to their ad traffic.
- Customer as controller. Our customers control the purpose of their campaigns, websites, notices, and lawful bases for the traffic data they send through GuardPPC.
3. Lawful bases GuardPPC may rely on
Depending on the context, GuardPPC may rely on different lawful bases under GDPR. The applicable basis depends on the relationship involved and the purpose of the processing.
- Contract performance. When processing is necessary to create accounts, deliver the platform, provide customer support, or manage a commercial relationship with a customer.
- Legitimate interests. When processing is necessary to secure GuardPPC, prevent invalid traffic, investigate abuse, improve service reliability, or respond to reasonable business inquiries, subject to required balancing tests.
- Consent. Where local law or the implementation context requires consent for cookies, marketing, replay, or similar technologies, the relevant controller is responsible for collecting it.
- Legal obligation. Where GuardPPC must retain records, respond to lawful requests, or meet regulatory obligations.
4. Categories of data involved
The data GuardPPC may process depends on the features a customer enables and how the website or campaign is configured. Typical categories include account data and traffic-quality telemetry needed for fraud detection and reporting.
- Customer-provided information. Names, business emails, company details, billing contacts, support messages, and onboarding information.
- Traffic and session data. IP addresses, click timestamps, landing pages, referrers, user-agent strings, browser and device characteristics, network indicators, location approximations, and session interactions.
- Platform activity data. Login events, audit logs, configuration changes, exclusion actions, alert history, and support access records.
5. Data subject rights
Subject to applicable law and the nature of the relationship, individuals may have GDPR rights that include access, rectification, erasure, restriction, objection, withdrawal of consent, and data portability.
- If GuardPPC is the controller. You can contact GuardPPC directly to request access, correction, deletion, or limits on how we handle the information we control.
- If GuardPPC is the processor. If your data entered GuardPPC through a customer’s campaign or website, please contact that customer first because they control the underlying relationship and primary response workflow.
- Verification. GuardPPC may request reasonable information to verify identity, authority, and the scope of a request before taking action.
6. International transfers and retention
GuardPPC and our providers may process personal data outside the country in which it was collected. Where GDPR transfer restrictions apply, GuardPPC uses safeguards appropriate to the transfer, such as standard contractual clauses or other recognized mechanisms.
We retain personal data only for as long as needed for the purposes described in our legal documentation, including service delivery, security, recordkeeping, dispute handling, and legal compliance.
7. DPA and security measures
Customers that use GuardPPC to process GDPR-regulated personal data may need processor terms and security information as part of their vendor review. GuardPPC addresses these topics through its DPA and security documentation.
See our Data Processing Agreement and Data Security page for more detail on processor obligations, safeguards, and operational controls.
8. Complaints and contact
If you have questions about GuardPPC’s GDPR posture or want to exercise a privacy right, contact hello@guardppc.com. If you believe your concerns were not addressed, you may also have the right to complain to the supervisory authority in your country or region.