Platform Privacy Policy

Last Updated: Sep 20, 2026

Light

This Platform Privacy Policy (“Platform Privacy Policy”/ “Policy”) describes how Aceex Sp. z o.o., registered at Domaniewska Street 17-19, office 133, 02-672, Warsaw, Poland (“we”, “us”, or “our”, “Aceex”) collects, uses, and shares (collectively, processes) your personal data as a digital advertising marketplace - Aceex AdExchange Platform.

This Policy does not describe how we process your personal information relating to our website or in the course of business contacts with you as a representative of a business entity willing to cooperate with Aceex or being our existing partner. For information on how we process personal data relating to our website or during business contacts with you, please read our Website Privacy Notice.

None of the data we collect or share about you via our AdExchange Platform is connected to your clear-text name, contact information, or other information that could directly identify you as an individual. But it is connected to the cookies and other persistent identifiers uniquely associated with you online. So, while we (and the clients who use Aceex AdExchange Platform) may know about your device “ABC123” and use it to serve that device ads as described below, we don’t know that the person with your name uses device “ABC123”.

About Us

Aceex Exchange Platform is a global digital advertising marketplace. Aceex’s partners enable our advertisement exchange platform services by placing bid requests and accepting such requests (executing bid responses). Our technology helps our partners deliver advertising to end users in real time. Aceex Exchange Platform hosts digital auctions that help our business partners buy and sell online ads (collectively, our “Services”). These ads can be found on websites, mobile applications (Apps), or video programming services, such as streaming apps on Smart TVs (collectively, “Digital Properties”).

As with any ad exchange platform, we act as an intermediary between professional buyers and sellers of ad space. Throughout this Policy, we refer to our business partners that sell ad space, representing publishers, as SSPs (Supplier-Side Platforms). SSPs act as additional intermediaries in the digital advertising supply chain that operate publishers’ Digital Properties that you use or visit. A publisher is an individual or company that owns a Digital Property with an audience, including apps or websites. We refer to business partners that buy ad space, representing advertisers, for placing their advertising content, as DSPs (Demand-Side Platforms). DSPs act as additional intermediaries in the digital advertising supply chain that connect advertisers to the Aceex Exchange Platform to serve relevant ads to you on the publishers’ Digital Properties you visit. DSPs liaise with advertisers (for example, brands), advertising agencies, and ad networks. In summary, Aceex AdExchange Platform, SSPs and DSPs, and other ad exchanges act as intermediaries that connect advertisers with ad publishers to deliver relevant digital ads to you.

Personal Data we collect, use, and share (Process). Retention period

Aceex processes your personal data to provide our Services if SSPs and DSPs, or other ad exchange platforms (collectively, our Partners) permit us to do so. Below are the main types of personal data we process on the Aceex Exchange Platform. Our Partners predominantly determine the information we receive in bid requests and bid responses processed through the Aceex Exchange Platform.

In the process of our ad exchange operation, we may either process or transmit certain personal data. This data typically includes: device ID, IP address, country, region /state inside one country, city, zip code, latitute/longitude, mobile operator, browser, operating system, device type (TV, mobile, laptop, tablet), device manufacturer, device model, device version, connection type, device language, user ID, privacy choices (consents/opt-outs).

For instance:

Device Data: information about the type and version of your browser, device type (for example, laptop, mobile, TV), device model, mobile carrier, connection type, model, language, and operating system, device ID, mobile advertising ID.

User Identifiers (User IDs): We process unique identifiers associated with the digital properties you use or with your account ID on some platforms. Digital Identifiers include:

  • cookie IDs: unique user identifiers assigned to cookies (small text files stored on your web browser when you visit a website);

  • device advertising IDs: unique user identifiers used for advertising purposes on various devices, including mobile devices, Connected TV (CTV) devices, and others.

Location Data: IP address, non-precise geolocation information such as city, country, zip code/postal code, and/or latitude and longitude data, precise geolocation if it is passed to us from Ad Partner.

Impression Data: data about your interaction with advertisements, like whether you clicked on the ad or not, the country where you opened the ad, the application in which you opened the ad, and at what time you clicked on the advertisement.

Privacy choices: your consent data under GDPR, opt-outs under US privacy laws, browser-based choices (GPC), and device-based choices (DNT, LMT, ATS).

Children's data: Under Aceex’s technology, we do not knowingly collect or process information from children under the age of 16 (EU) / 13 (USA).

Retention period. We process Device Data, Location Data, User identifiers, and Privacy choices in real time and do not store them. Specific tracking delivery cookies formed by Aceex at the moment of showing ads to you are created and stored on your device for 14 days (IP address and User agent (browser)). We store other Impression Data for 5 years. We may also create and retain anonymized information, and continue to use this information. The information that is utilised to render fraud- and IVT-related opinions (сookies and/or device IDs, system or platform IDs, advertiser campaign attributes, system and/or device IP addresses, domain or app ID, internet browser information for systems and/or devices, coarse (i.e., non-precise) geographic location information and/or mobile device carrier) is retained most of the time for a period of thirteen (13) months.

As you read our Privacy Policy, please also remember that the advertisement publishers and advertising partners you interact with as you engage online and in the real world have their own privacy policies that govern how they collect and use your data, including when they may share your data with advertising partners like us. These policies and practices may differ from what you read in our Privacy Policy. To fully understand how your data is being collected, used, and shared, you should always carefully read the privacy policy of any website you access, any app you use, and any social network page through which you share information.

Purposes and Legal Bases for Processing Personal Data

We process your personal data to provide our Services when it is permitted by law and supported by a valid legal justification (legal basis). We rely on the legal basis of consent for the following processing activities:

  • Deliver and present advertising: selection and delivery of an ad based on real-time data (e.g., information about app type, non-precise geolocation data, precise geolocation data to select and deliver an ad in the moment, without storing it).

  • Ad reporting: to verify that an ad was delivered to you with accuracy.

  • Cookie syncing: to match your cookie IDs to provide more effective delivery of relevant ads to you. Cookie syncing enables the sharing and use of personal data between SSPs and DSPs/Ad Exchanges that are involved in buying and selling digital ad space.

  • Impression counting and frequency capping: to count the number of times ads are displayed against a Digital ID and to limit the number of times an ad is seen. For this type of processing, we use statistical pixels added to the advertisement.

We rely on the legal basis of legitimate interest for the following processing activities:

  • Invalid traffic detection: to prevent fraud, malware, and other unacceptable behavior. For these types of processing, we use analytical pixels of our vendors (for example, Pixalate). Aceex relies on legitimate interest to ensure the security of our digital advertising processes. This includes implementing measures to prevent and detect fraudulent activities that could compromise user data and our advertising integrity. By monitoring for unusual patterns and behaviors, we can identify potential security threats and take appropriate action to mitigate risks.

  • Deliver advertising: to receive and respond to an ad request or a user’s interaction with an ad, to deliver ad files to an IP address or to send the user to a landing page; and to log that an ad was delivered, without recording any personal data about the user. For this purpose, we use certain information (like an IP address) to facilitate the transmission of the ad to the user’s device.

  • Reading your privacy choices: to view and enforce your opt-out choices or consents, and honor your privacy choices/rights. We utilize legitimate interest to save and communicate users’ privacy choices regarding data processing preferences. This ensures that users are informed about how their data is used while allowing us to respect their choices effectively.

We will rely on the legal basis of legal obligations for the following processing activity:

  • Privacy Obligations: to enforce data protection audits or requests of our Partners or to fulfill the order of data protection authorities. For this purpose, we may share Impression Data.

Sharing Personal Data

We may disclose or share (collectively, share) your personal data with the following partners to deliver ads to you:

  • SSPs and DSPs: We share your personal data with our Partners to deliver ads to you. Each Partner processes Personal Data under its privacy policies and the privacy policies of direct advertisers.

  • Vendors and service providers: Our third-party vendors help us provide our Platform Services. Please note that for the ads we help deliver, pixels are used, enabling third parties to process Personal Data for purposes such as measuring ad performance or preventing fraud.

Our vendors include

HQ Host by ALLUS Online Corp (affiliate of IPIPE International Corp.), a data hosting provider in the USA. Address: 100 Delawanna Ave, Clifton, NJ 07014, USA. HQ Host’s Privacy Policy.

Servers.com by Servers.com B. V., a data hosting provider in the EU. Address: Keienbergweg 22 1101GB, Amsterdam, The Netherlands. Servers.com Privacy Policy. California Privacy Policy.

Pixalate by Pixalate, Inc., advertising fraud prevention, invalid traffic (“IVT”) detection, and data intelligence service. Address: 1775 Greensboro Station Place, McLean, VA 22102, USA. Pixalate’s Privacy Policy.

Governmental agencies: Subject to law enforcement authority request, we may disclose certain data to law enforcement, governmental agencies, or authorized third parties, in response to a verified request relating to terror acts, criminal investigations or alleged illegal activity, or any other activity that may expose us, you, or any other user to legal liability, and solely to the extent necessary to comply with legal requirements.

Your Rights

Depending on the applicable data protection law and the circumstances of our processing, you may have the following rights regarding your personal data. These rights are not absolute and may be subject to conditions and limitations under applicable law:

  1. Right of access: the right to obtain confirmation as to whether we process your personal data and, where we do, to request access to that data and information about how we process it.

  2. Right to rectification: the right to request correction of inaccurate personal data and completion of incomplete personal data.

  3. Right to erasure: the right to request deletion of your personal data where applicable law allows.

  4. Right to restrict processing: the right to request that we limit the processing of your personal data in certain circumstances.

  5. Right to data portability: the right, where processing is based on consent or contract and carried out by automated means, to receive personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request its transmission to another controller where technically feasible.

  6. Right to object: the right to object, on grounds relating to your particular situation, to processing based on our legitimate interests. We will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed to establish, exercise, or defend legal claims.

  7. Where processing is based on consent, the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. You may withdraw consent through the consent-management mechanism made available by the relevant Digital Property, SSP, DSP, or other Partner. By using the device-based “opt-out” signals described in Section “How to Opt Out of Ads” below, you may also withdraw consent for processing on which we rely. We receive such signals from SSPs or DSPs we work with.

  8. The right to lodge a complaint with a supervisory authority: the right to complain to the data protection authority in your habitual residence, place of work, or place of an alleged infringement. 

  9. The right to know about the existence of any automated decision-making processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not employ such processing.

How to Opt Out of Ads

If you want to be excluded from digital advertising, you can opt out of further data processing for purposes of delivering ads to you. Steps to opt out of advertising:

  • Cookie Consent Banners: When visiting websites, pay attention to cookie consent banners. You can usually reject non-essential cookies that are used for advertising purposes.

  • Identify the Source: Determine which organization or platform sends you advertisements or processes your data. This could be a specific website or app.

  • Review Privacy Policies: Check the privacy policies of services you use to understand how they handle data and what options you have for opting out.

  • Use Privacy Settings: Manage your consent preferences on platforms/apps in the website section "Privacy Dashboard" - look there for options to opt out of personalized advertising or data processing.

  • Browser Settings: Adjust your browser settings to block third-party cookies (“Settings” → “Privacy and security” → “Ad privacy”/ “Third-party cookies” → “Send a 'Do Not Track' request with your browsing traffic”) or use incognito mode to limit tracking while browsing.

As an option, you can use Global Privacy Control (GPC): a privacy feature that lets you, as an internet user, easily communicate your privacy preferences to the websites you visit. It's essentially a browser setting or extension that automatically tells websites not to sell or share your personal information. Here's how it works for you: 1) you enable GPC in your browser or install a GPC-compatible extension; 2) when you visit a website, your browser automatically sends a GPC signal to that site; the website receives this signal and, if it supports GPC, adjusts its data handling practices accordingly. GPC is supported by several popular browsers like Firefox, Brave, Chrome, Edge, and DuckDuckGo. If your preferred browser doesn't have built-in GPC support, you can often add it through a browser extension. It's important to note that while GPC is a powerful tool for protecting your privacy, its effectiveness depends on websites recognizing and honoring the signal. Depending on where you live, the GPC flag will exercise your legal right to opt out. For example, if you live in California or Colorado, many sites are legally bound to respect your GPC signal by not selling your data. Aceex honors the GPC signal in our advertising intermediary’s activities.

Controls for do-not-track-features

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (‘DNT’) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. The same exists in mobile phones as LMT (“Limit Ad Tracking”) or ATTS (App Tracking Transparency, used in Apple’s opt-in privacy framework signals. At this stage, no uniform technology standard for recognising and implementing all these signals has been finalised. You may use this setting mechanism to communicate your choice not to be tracked online automatically. A request will be included with your browsing traffic. Any effect depends on whether a Digital Property responds to the request and how the request is interpreted. For example, some Digital Properties may respond to this request by showing you ads that aren't based on other Digital Properties you've visited. Many Digital Properties will still collect and use your browsing data - for example, to improve security, to provide content, services, ads, and recommendations on their Digital Properties, and to generate reporting statistics.

Please note that by deleting cookies or disabling future cookies, you may be unable to access certain areas or features of websites, apps, etc. To find out how to manage cookies in your browser, please visit one of the links below:

Please note that once you choose to opt out or disable cookies, your online experience may be limited. In addition, even if you do opt out, you may still receive some advertising; however, it will not be targeted advertising.

International Transfers of Personal Data

Aceex is an EU company with vendors in the USA, Singapore, Ukraine, and other non-EU countries. To provide our Services, we may transfer your personal data internationally to our vendors or through any international data center locations.

When we transfer personal data outside the European Economic Area, we ensure that appropriate legal and technical protections are in place. These protections may include a transfer mechanism such as the Standard Contractual Clauses approved by the European Commission, adequacy decisions or binding corporate rules.

Security measures

We work hard to protect the Personal Data we process from unauthorized access, alteration, disclosure, loss, or destruction. We have implemented appropriate physical, technical, and administrative security measures designed to protect Personal Data and that comply with applicable laws and industry standards. These measures include, for example, minimization, access controls that restrict access to Personal Data to authorized Aceex employees and contractors with a need to know, authentication measures, secure hosting environments, and processes for monitoring and responding to security incidents. We also require our vendors and service providers that process Personal Data on our behalf to implement appropriate security measures.

Despite these measures, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee the absolute security of Personal Data or prevent every unauthorized or unintended access beyond our control. If we become aware of a Personal Data breach, we will investigate it and take the steps required under applicable law, including notifying affected individuals and competent authorities where required.

EU: TCF (IAB Europe Transparency and Consent Framework)

Aceex participates in the IAB Europe Transparency & Consent Framework as a Vendor and complies with its Specifications and Policies. Aceex’s Vendor ID within the framework is 1387.

USA: GPP (The IAB’s Global Privacy Protocol)

Aceex is a Signatory to the IAB Tech Lab’s Multi-State Privacy Agreement (MSPA), an industry-standard contractual framework designed to help advertisers, publishers, agencies, and ad tech intermediaries comply with the privacy laws of US states. Aceex honors Signals in compliance with the MSPA Technical Signaling Implementation Guidelines for Signatories and Certified Partners.

Changes to this Policy

We may update this Policy from time to time to accommodate new technologies, industry practices, regulatory requirements or for other purposes. The date at the top of this Policy reflects the most recent changes made. We encourage you to review this Policy for the latest information on our privacy practices and to contact us if you have any questions or concerns.

Our Contacts

If you have any questions, concerns, requests or complaints about the above or our privacy practices, please contact us 

  • by email at privacy[at]aceex.io or 

  • by post at Domaniewska Street 17-19, office 133, 02-672, Warsaw, Poland. 

  • submit a Data Rights Request to us through this form.

We may need to verify your identity before discussing your personal data. This verification is carried out solely for security purposes, to ensure that we are communicating with the correct person. 

Please note that we are unable to verify the identity of individuals in relation to device-level data received from publishers of online video content and/or other supply-side partners. As a result, we may be unable to fulfil data subject requests relating to such data.

If you have questions about data that is operated by a Digital Property on which our technology is embedded, or companies that serve ads that use our technology, you should contact those companies regarding questions about the personal data they handle and control.

Previous versions

Platform Privacy Policy as of 10 October 2025

Platform Privacy Policy as of 12 May 2025

Platform Privacy Policy as of 14 February 2025

Platform Privacy Policy as of 31 January 2025