Legal & Compliance

Privacy Policy

CP Advertising Network Ltd is committed to protecting the privacy and personal data of everyone who interacts with our website and services. This policy explains, in plain language, exactly what we collect, why we collect it, and how you can control it — in full compliance with the General Data Protection Regulation (GDPR) and Brazil's Lei Geral de Proteção de Dados (LGPD).

Last updated: 14 July 2025

Effective as of the same date

Section 01

Introduction

CP Advertising Network Ltd ("we," "us," or "our") operates the website accessible at this domain and provides digital advertising and media network services to clients worldwide. As a company incorporated under the laws of England and Wales and serving an international client base — including individuals and businesses in the European Economic Area (EEA) and Brazil — we are subject to both the General Data Protection Regulation (EU) 2016/679 (GDPR) and Brazil's Federal Law No. 13,709/2018 (LGPD).

This Privacy Policy applies to all personal data we process in connection with your use of our website, your interactions with our representatives, and any services we deliver. "Personal data" means any information that relates to an identified or identifiable natural person — for example, your name, email address, IP address, or browsing behaviour on our site.

We act as the data controller for the personal data we collect directly from visitors to this site and from clients who engage with our services. Where we process data on behalf of our clients as part of delivering advertising campaigns, we act as a data processor under the instructions of our clients, who remain the data controllers for their end-user data.

This policy is written to be read and understood by anyone — not just lawyers. If something is unclear, please contact us. We take data protection seriously and we welcome questions.

Section 02

Information We Collect

We collect personal data through a number of channels, and only to the extent necessary to provide our services or operate our website. The categories are as follows.

2.1 — Information You Provide Directly

When you contact us via the email address or phone number listed on this site, or when you correspond with our team, you may provide information such as:

  • Identification data: your full name and the organisation you represent.
  • Contact details: your business or personal email address and telephone number.
  • Message content: the substance of your enquiry, including any attachments or supporting documents you choose to include.
  • Commercial information: details about your advertising requirements, budget parameters, campaign objectives, or existing media relationships, if you share these voluntarily.

We do not operate any automated online form that submits data to us without your knowledge. Every piece of data you share with us arrives through a deliberate action on your part — sending an email or making a phone call.

2.2 — Data Collected Automatically When You Visit Our Site

Like virtually every website, ours automatically receives certain technical data from your browser or device each time you load a page. This includes:

  • IP address: used to derive an approximate geographic location (typically city or country level) and to maintain the security and stability of our servers.
  • Browser and device information: the type and version of your web browser, your operating system, screen resolution, and the type of device you are using (desktop, tablet, or mobile).
  • Referring URL: the address of the webpage, search engine result, or advertisement that brought you to our site.
  • Pages visited and session duration: which pages on our site you view and for how long, along with click-path data that shows how you navigate between sections.
  • Search terms: if you arrived via a search engine, we may receive the search query that led you to us (subject to the search engine's own privacy settings).

This technical data is collected primarily via cookies and similar tracking technologies, which are described in full in Section 4 below.

2.3 — Data We Receive From Third Parties

In the course of our advertising network operations, we may receive aggregated or pseudonymised audience data from advertising exchanges, demand-side platforms, and data-enrichment providers with whom we work. Such data is processed in accordance with those providers' own disclosures and, where applicable, in line with industry standards such as the IAB Europe Transparency & Consent Framework (TCF). We do not purchase raw personal data from data brokers for use in direct marketing.

Section 03

How We Use Your Information

We process your personal data only where we have a valid legal basis to do so. The table below maps each purpose to its corresponding lawful basis under the GDPR and the equivalent provision under the LGPD.

3.1 — Responding to Enquiries and Managing Client Relationships

Purpose: When you contact us to ask about our services, we use your contact details and the content of your message to reply to you, provide information you requested, and — if discussions progress — to establish and administer a service relationship.

Legal basis (GDPR): Legitimate interests (Article 6(1)(f)) — specifically, our legitimate interest in communicating with prospective and existing clients, which is balanced against your interest in not receiving unwanted communications. Where a contract is entered into, processing is also necessary for the performance of that contract (Article 6(1)(b)).

Legal basis (LGPD): Legitimate interests (Article 7, X) and performance of a contract or preliminary procedures (Article 7, V).

3.2 — Operating, Maintaining, and Improving Our Website

Purpose: We use automatically-collected technical and behavioural data to understand how visitors use our site, identify and fix technical errors, monitor server performance, and make informed decisions about how to improve content and navigation.

Legal basis (GDPR): Legitimate interests (Article 6(1)(f)) — specifically, our legitimate interest in running a functional, secure, and well-performing website. For analytics cookies specifically, we rely on your consent (Article 6(1)(a)) where required by applicable law.

Legal basis (LGPD): Legitimate interests (Article 7, X) and consent (Article 7, I) for cookie-dependent processing where required.

3.3 — Legal Compliance and the Exercise or Defence of Legal Claims

Purpose: We may process personal data where necessary to comply with a legal obligation — for example, retaining financial records in compliance with applicable tax law — or to establish, exercise, or defend legal claims in connection with our business.

Legal basis (GDPR): Legal obligation (Article 6(1)(c)) and legitimate interests (Article 6(1)(f)).

Legal basis (LGPD): Compliance with a legal or regulatory obligation (Article 7, II) and legitimate interests (Article 7, X).

We do not use your personal data for automated individual decision-making or profiling that produces legal or similarly significant effects on you. We do not sell your personal data to any third party for their independent commercial use.

Section 04

Cookies & Tracking Technologies

Cookies are small text files stored on your device by your browser at the instruction of a website. They enable the site to remember information between page loads or visits. We use four categories of cookies on this site, described below.

4.1 — Strictly Necessary Cookies

These cookies are essential for the website to function correctly and cannot be disabled without breaking core features. They do not store any information that could identify you personally. They include session-state management and security tokens. No consent is required for these cookies under current guidance.

4.2 — Performance & Analytics Cookies

We use Google Analytics (including Google Analytics 4) to collect anonymised statistics about how visitors interact with our site. Data collected includes pages viewed, time on site, bounce rate, and approximate geographic location. IP addresses are anonymised before storage. This data is used solely to improve our website and is not used for advertising profiling. These cookies are deployed only after you grant consent via our cookie notice.

4.3 — Functional Cookies

Functional cookies remember your preferences — such as your cookie consent choice — so that you are not prompted repeatedly on return visits. They may also store display preferences to personalise your experience. These are session or persistent cookies with a maximum lifespan of 12 months.

4.4 — Advertising & Targeting Cookies

As an advertising network company, we may deploy or permit third-party advertising partners to deploy cookies that support frequency capping, conversion tracking, and cross-site audience measurement relevant to campaigns we manage on behalf of clients. These cookies are only activated with your explicit consent. Withdrawing consent via the cookie preference centre will immediately disable these cookies for future page loads.

4.5 — Managing Your Cookie Preferences

You can change your cookie preferences at any time using our cookie preference centre (accessible via the "Cookie Settings" link in the footer). You may also control cookies through your browser settings — most browsers allow you to block, delete, or restrict specific categories of cookie. Note that blocking strictly necessary cookies may affect the usability of certain site features. Instructions for common browsers:

  • Google Chrome: Settings → Privacy and Security → Cookies and other site data.
  • Mozilla Firefox: Options → Privacy & Security → Enhanced Tracking Protection.
  • Safari: Preferences → Privacy → Manage Website Data.
  • Microsoft Edge: Settings → Cookies and site permissions → Cookies and site data.

For opt-out from Google Analytics specifically, you may install the Google Analytics Opt-out Browser Add-on, available at tools.google.com/dlpage/gaoptout.

Section 05

Sharing With Third Parties

We treat your personal data with discretion. We do not sell, rent, or trade personal data. We share it only in the following limited circumstances, and only to the extent strictly necessary:

5.1 — Service Providers and Data Processors

We engage carefully vetted third-party companies to support the operation of our business and website. These providers act as data processors under our instruction and are contractually bound to use your data only for the purposes we specify and to apply appropriate security measures. Current categories of processor include:

  • Cloud hosting and infrastructure: our website and business data are hosted on servers operated by reputable providers within the EEA or in countries that provide an equivalent level of protection.
  • Website analytics: Google Ireland Limited, operating Google Analytics 4, processes anonymised site-usage data on our behalf under a data processing agreement that incorporates EU Standard Contractual Clauses.
  • Email and communication tools: business communication platforms that may process the content of emails you send to us.
  • Advertising technology partners: where relevant to client campaigns, we integrate with demand-side platforms, ad exchanges, and measurement providers, each of whom processes data under their own disclosed terms and applicable consent frameworks.
  • Professional advisors: lawyers, accountants, and auditors who are subject to professional confidentiality obligations.

5.2 — Legal Obligations and Regulatory Disclosure

We may disclose personal data to law enforcement authorities, courts, regulatory bodies, or other public authorities if we are required to do so by applicable law, court order, or regulatory mandate. Where permitted, we will notify you of such a request before complying.

5.3 — Business Transfers

If CP Advertising Network Ltd is involved in a merger, acquisition, asset sale, or restructuring, personal data held by us may be transferred to the successor entity as part of that transaction. We will notify affected individuals by posting a prominent notice on our website, and we will ensure that any successor entity honours the commitments set out in this policy.

5.4 — International Transfers

Some of our service providers are located outside the United Kingdom and the EEA. Where we transfer personal data internationally, we rely on one of the following safeguards:

  • An adequacy decision by the European Commission or the UK Secretary of State confirming that the destination country provides an equivalent level of data protection.
  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with the relevant processor, supplemented where necessary by additional technical or organisational measures.
  • The UK International Data Transfer Agreement (IDTA) where transfers are from the UK.

For transfers to or from Brazil, we comply with Chapter V of the LGPD and any guidance issued by the Autoridade Nacional de Proteção de Dados (ANPD).

Section 06

Data Retention

We keep personal data only for as long as it is necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, or to resolve disputes and enforce our agreements. The following retention periods reflect our current practice:

  • Email enquiries and pre-contract correspondence: retained for 3 years from the date of last contact, to allow us to follow up on outstanding matters and to demonstrate compliance if a complaint is raised.
  • Active client records (contracts, invoices, campaign data): retained for the duration of the engagement plus 7 years thereafter, in line with typical statutory limitation periods and accounting record requirements in the UK and Brazil.
  • Analytics data (Google Analytics): configured to a rolling 14-month retention window within Google Analytics, after which user-level data is automatically deleted.
  • Cookie consent records: retained for 12 months, which is the lifespan of the consent preference cookie. A new consent record is created if you revisit the site after that period.
  • Server access logs: retained for up to 90 days for security and fault-diagnosis purposes, then deleted automatically.

When the applicable retention period expires, we securely delete or irreversibly anonymise the relevant data. Where data has been shared with processors, we instruct those processors to apply the same or shorter retention periods.

Section 07

Data Security

We implement technical and organisational measures proportionate to the risks posed by the types of data we process and the scale of our operations. These measures include, but are not limited to:

  • Encryption in transit: all communication between your browser and our web server is encrypted using TLS 1.2 or higher (HTTPS), enforced via HSTS headers.
  • Access controls: internal access to personal data is restricted to staff and contractors who have a genuine need to process it for legitimate business purposes. Access is governed by role-based permissions and is reviewed periodically.
  • Processor due diligence: before engaging any third-party processor that will handle personal data, we conduct a security review and require them to demonstrate adequate safeguards, typically evidenced by ISO 27001 certification or equivalent.
  • Incident response: we maintain an internal procedure for identifying, assessing, and responding to personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will notify affected individuals without undue delay where required by law.
  • Regular review: our security practices are reviewed at least annually and updated in response to emerging threats or changes in our processing activities.

No method of electronic transmission or storage is 100% secure. While we strive to use commercially reasonable means to protect your personal data, we cannot guarantee its absolute security. In the event of a security incident affecting your data, we will act swiftly to contain it and to inform you in accordance with our legal obligations.

Section 08

Your Rights

Depending on where you are located and the applicable law, you may have some or all of the following rights in relation to the personal data we hold about you. We honour these rights without imposing unnecessary procedural barriers.

Right of Access

You have the right to request a copy of the personal data we hold about you and to receive information about how we process it. We will respond within one month of receiving a valid request.

Right to Rectification

If any personal data we hold about you is inaccurate or incomplete, you have the right to ask us to correct or supplement it. We will act on your request without undue delay.

Right to Erasure

Also known as the "right to be forgotten." You may ask us to delete your personal data where it is no longer necessary for the purpose for which it was collected, or where you have withdrawn consent and no other legal basis applies. Certain legal retention obligations may limit the scope of erasure.

Right to Restriction

You may ask us to restrict processing of your data — for example, while the accuracy of data is being contested, or if processing is unlawful and you prefer restriction to erasure.

Right to Data Portability

Where processing is based on your consent or on a contract and is carried out by automated means, you may request a structured, machine-readable copy of the data you provided to us, and in some cases request that we transmit it to another controller.

Right to Object

You have the right to object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for the establishment or defence of legal claims.

Right to Withdraw Consent

Where processing is based on your consent — most commonly, your acceptance of analytics or advertising cookies — you may withdraw that consent at any time via the cookie preference centre. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right to Lodge a Complaint

If you believe we have processed your data unlawfully, you have the right to lodge a complaint with the supervisory authority in your jurisdiction. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. In Brazil, complaints may be lodged with the ANPD at gov.br/anpd.

How to Exercise Your Rights

To exercise any of the rights listed above, please contact our data protection contact using the details in Section 11. We may ask you to provide proof of identity before processing your request, in order to protect your data against unauthorised disclosure. We will respond to all verified requests within one month (GDPR) or within a reasonable timeframe as required under the LGPD — typically 15 business days for Brazilian residents. Where a request is complex or numerous, we may extend this period by up to two further months, and we will notify you of any such extension.

There is no charge for exercising your rights in the majority of cases. If a request is manifestly unfounded or excessive, we reserve the right to charge a reasonable administrative fee or decline to act on the request, providing written reasons in either case.

Section 09

Children's Privacy

Our website and services are directed exclusively at adults — specifically, at business professionals and commercial clients seeking advertising and media network solutions. We do not knowingly collect, solicit, or process personal data from individuals under the age of 18 (or under the relevant age of digital consent in their jurisdiction, which in many EEA member states is 16 years).

If you are a parent or guardian and you believe that your child has provided personal data to us without your consent, please contact us immediately at the address in Section 11. Upon verification, we will delete the relevant information promptly and without charge.

If we discover that we have inadvertently collected personal data from a person who is below the applicable age threshold, we will take immediate steps to delete that data from our systems and to notify the relevant supervisory authority if required by law.

Section 10

Changes to This Policy

The digital advertising landscape, the technology we use, and the legal framework governing data protection all evolve continuously. We review this Privacy Policy at least once per year and update it whenever a material change occurs — whether that is a change in the types of data we process, a new third-party processor, a change in applicable law, or a significant development in our business.

When we make a material change, we will update the "Last updated" date at the top of this page. We may also, in the event of particularly significant changes, notify you directly — for example, by email if you are an existing client — or by displaying a prominent notice on our homepage for a period of at least 30 days following the update.

Your continued use of our website after a change is published will constitute acknowledgement of the updated policy. If you do not agree with the revised terms, you should discontinue use of our site and, where applicable, exercise any rights you have under the previous version of this policy before the changes take effect.

Previous versions of this Privacy Policy are available on request by contacting us at the address below.

Section 11

Contact & Data Protection Contact

If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please reach out to us using the details below. We endeavour to respond to all privacy-related queries within five business days of receipt, and to resolve substantive requests within the statutory timeframe described in Section 8.

Where a formal Data Protection Officer (DPO) appointment is required under the GDPR or LGPD, enquiries should be directed to the same contact address; we will escalate your matter to the appropriate person internally.

CP Advertising Network Ltd — Data Protection Contact

Company CP Advertising Network Ltd
Subject Please mark your email: "Privacy / Data Protection Request"
Response We aim to respond within 5 business days. Formal subject-rights requests are addressed within one calendar month.

If you are based in the United Kingdom and are unsatisfied with our response, you have the right to escalate your complaint to the Information Commissioner's Office (ICO) at ico.org.uk or by calling their helpline on 0303 123 1113. If you are based in Brazil, you may contact the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.

Questions about how we handle your data?

We believe transparency builds trust. If anything in this policy is unclear, or if you would like to know more about a specific aspect of our data practices, our team is happy to explain.

Get in Touch

Or email us directly at [email protected]