PubX AI Ltd — Privacy Policy

Last Updated: 29th July, 2026

PubX AI Ltd (“PubX”, “we”, “us”, or “our”) is committed to protecting the personal data of individuals who interact with our technology. This Privacy Policy explains what data we collect, why we collect it, how we use and share it, and what rights you have.

1. Who We Are

PubX AI Ltd is a private limited company incorporated in England and Wales (company number 12617660), with registered address at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom.

We operate three technology products:

  • Floor Pricing (Flooring): A yield optimisation product used by existing clients to dynamically set auction floor prices and reduce low-value programmatic traffic. This product does not involve the processing of personal data.
  • Bidder: PubX operates as a supply-side platform (SSP), connecting publisher inventory to demand-side buyers through programmatic advertising auctions.
  • Agentic Advertising Platform: An AI-powered marketplace through which we package and sell client digital advertising inventory to demand-side buyers via programmatic deal activation, using LLM-based agents, real-time bid enrichment, and audience segment curation, including the operation of a proprietary cross-publisher Identity Graph.

This Policy applies to our Bidder and Agentic products. It does not apply to the Flooring product as no personal data is processed in connection with that product.

For questions about this Policy or to exercise your rights, contact us at: privacy@pubx.ai

2. Our Role: Controller and Joint Controller

Activity Our Role Your Primary Contact
Agentic Advertising — signal collection, bid enrichment, Identity Graph construction, segment catalogue construction, deal activation Joint Controller alongside the Client The Client (website you visited), or privacy@pubx.ai
Bidder — open market bid processing and deal delivery Joint Controller alongside the Client The Client (website you visited), or privacy@pubx.ai
Internal modelling and anonymised product research Independent Controller privacy@pubx.ai

Where we act as a Joint Controller with a Client, we have entered into a Joint Controller Agreement with that Client setting out our respective responsibilities. The essence of that arrangement is described in section 12 of this Policy.

3. What Data We Collect and Why

3.1 Bidder and Agentic Advertising Platform

Data collected:

  • Device and browser metadata (device type, operating system, browser type, user agent)
  • IP address (truncated where technically feasible), used to derive approximate location (city/region level)
  • URL and page-level contextual data (IAB content categories, mood signals, brand safety scores, page depth — derived from page content)
  • Timestamp and daypart
  • Auction parameters (bid request data, floor prices, win/loss events)
  • Pseudonymous identifiers (Prebid User IDs and other privacy-preserving identifiers where available)
  • Identity resolution data enriched via third-party identity providers and PubX’s own Identity Graph infrastructure (details at www.pubx.ai/vendors)
  • First-party data (FPD) segments provided directly by the Client relating to their users
  • Cross-publisher audience signals aggregated across Client properties for Identity Graph construction and Segment Catalogue maintenance

Why we collect it:

Purpose Data Used Lawful Basis
Real-time bid enrichment Pseudonymous IDs, IP-derived location, contextual signals, FPD Consent (TCF) for identity-based enrichment; Legitimate interests for contextual and computed attributes
Identity Graph construction Pseudonymous IDs, device signals, contextual signals Consent (TCF purposes 1, 3)
Audience segment construction Auction logs, FPD, derived attributes, buyer brief signals Consent (where ID-based); Legitimate interests (where purely contextual or aggregated)
Agentic Deal Flow — matching buyer briefs to inventory and activating deals Segment Catalogue entries, campaign brief data Consent / Legitimate interests (as applicable per segment type)
Bidder — open market bid processing and deal delivery Enriched bid request signals Consent (TCF)
Client and buyer performance reporting Aggregated impression counts, eCPM, win/loss events Legitimate interests
Internal modelling and ML optimisation Fully anonymised or aggregated data only Legitimate interests

We do not use data collected through our products for any purpose outside those listed above.

4. How We Transmit Data

4.1 Encryption Before Transmission

Before transmitting any enriched bid request data to advertising technology partners, PubX encrypts all enrichment fields using industry-standard encryption. Where third-party enrichment providers encrypt their own data independently, that data arrives at downstream partners in encrypted form.

4.2 Deal Activation and Bid Processing

Enriched bid requests are transmitted to advertising technology partners connected to PubX’s platform for deal matching, auction participation, and deal delivery purposes. Depending on the technical configuration:

  • Where readable enrichment signals are transmitted to a partner for deal matching, that partner acts as an independent controller for its own auction and targeting activities
  • Where only an opaque Segment Identifier is transmitted, the partner acts as a processor and cannot access the underlying personal data

4.3 Flow Determination

PubX maintains internal records of the technical approach applied to each active deal, available to Clients upon written request.

5. Data Sharing

We share personal data only as described below. We do not sell personal data for monetary consideration.

We work with third-party vendors across a number of stable categories including advertising technology partners, identity resolution providers, contextual classification providers, hosting and infrastructure providers, LLM inference providers, and data enrichment and audience signal providers.

The current named vendors within each category, together with their roles, data categories received, and applicable transfer mechanisms, are published and kept up to date at www.pubx.ai/vendors. We notify our Client partners in advance of any material changes to our vendor list.

We do not share personal data with any party outside the categories described on our vendor page without prior notice to the relevant Client and, where required, your consent.

CPRA note: Under the California Consumer Privacy Act as amended, transmitting data to third-party advertising partners for cross-context behavioural advertising may constitute “sharing” even where no monetary consideration is exchanged. Where applicable, we honour opt-out of sharing requests as described in section 9.

6. Cookies and Local Storage

PubX uses local storage (and in limited circumstances, cookies) on Client websites where our technology is deployed.

What we store:

  • Pseudonymous auction identifiers for session-level bid processing
  • Identity resolution signals necessary for real-time bid enrichment and Identity Graph construction

What we do not store:

  • Special category data (health, political opinions, religious beliefs, sexual orientation, or similar)
  • Full IP addresses
  • Any data that directly identifies you by name, email, or government identifier

Consent: All local storage access is gated on valid consent obtained via the Client’s consent management platform (CMP) in accordance with TCF 2.x or equivalent framework. We do not access local storage on any device where a valid consent signal is absent.

Global Privacy Control (GPC): We honour GPC signals transmitted via Client websites. Where a GPC signal indicates an opt-out of sale or sharing, we will not process your data for cross-context behavioural advertising purposes, including Identity Graph construction and segment qualification.

Managing your preferences: You can withdraw consent at any time via the CMP banner on the Client website you are visiting. You can also manage cookies and local storage via your browser settings.

7. Data Retention

Data Category Retention Period Notes
Raw pseudonymous identifiers (Prebid IDs, local storage IDs, IP addresses) 90 days Deleted or irreversibly anonymised on expiry
Enriched bid request logs 90 days Deleted or irreversibly anonymised on expiry
Identity Graph records 90 days from last observed signal Deleted or irreversibly anonymised on expiry
Segment Catalogue entries (rule definitions, not individual-level data) Duration of client agreement + 30 days Entries derived solely from a client’s FPD deleted on written request
Deal delivery and performance data (aggregated) 12 months Used for client and buyer reporting
Client FPD segments Duration of client agreement + 30 days, or as instructed by client
IP address suppression list entries — dynamic IP (one-way hash only) 30 days from verified erasure request
IP address suppression list entries — static IP (one-way hash only) Up to 12 months from verified erasure request
Contractual, billing, and compliance records 7 years from creation Legal and financial obligation
Data subject / consumer rights request records 3 years from resolution

All data is stored securely on cloud infrastructure. On expiry of the applicable retention period, data is deleted or irreversibly anonymised.

8. International Data Transfers

PubX is based in the United Kingdom. Some of our third-party vendors are located in the United States or other countries outside the UK/EEA. Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place:

  • UK transfers: UK International Data Transfer Agreement (IDTA) or UK Addendum to EU Standard Contractual Clauses (SCCs), as applicable
  • EEA transfers: EU Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914)
  • US transfers: EU-US Data Privacy Framework (DPF) and/or UK-US Data Bridge, where the recipient is certified; or SCCs/IDTA where certification is absent

The applicable transfer mechanism for each vendor is confirmed on our vendor page at www.pubx.ai/vendors.

We also conduct Transfer Impact Assessments (TIAs) for transfers to countries where local laws may affect the effectiveness of these safeguards, and implement supplementary technical measures (including encryption) where required.

9. Your Rights

9.1 UK and EU Users (UK GDPR / EU GDPR)

You have the following rights in respect of your personal data:

  • Access (Art. 15): Request a copy of the personal data we hold about you
  • Rectification (Art. 16): Request correction of inaccurate data
  • Erasure (Art. 17): Request deletion of your personal data, subject to legal retention obligations and the verification note below
  • Restriction (Art. 18): Request that we restrict processing of your data in certain circumstances
  • Portability (Art. 20): Receive your data in a structured, machine-readable format where technically feasible
  • Objection (Art. 21): Object to processing based on legitimate interests; we will cease processing unless we can demonstrate compelling legitimate grounds
  • Withdraw consent: Withdraw consent at any time via the CMP on the relevant Client website; withdrawal does not affect the lawfulness of prior processing

Important note on erasure requests based on IP address: PubX processes IP addresses as part of its programmatic advertising technology. IP addresses in our systems are dynamic — they are reassigned by internet service providers over time and may be shared by multiple users. To process an erasure request accurately and protect other users’ data, we cannot action requests based on an IP address alone. If you wish to request erasure of data associated with your IP address, please also provide: the approximate date(s) and time(s) when you visited Client websites where our technology was active; the website(s) you visited; and your device type and browser at the time. Where we cannot identify your specific data even with this information, we will inform you in accordance with Article 11(2) GDPR.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at www.ico.org.uk, or with your local EU supervisory authority.

9.2 California Users (CPRA/CCPA)

You have the following rights:

  • Right to know: Request disclosure of the categories and specific pieces of personal information we have collected about you
  • Right to access: Request a copy of the personal information we hold about you
  • Right to delete: Request deletion of your personal information, subject to applicable exceptions
  • Right to correct: Request correction of inaccurate personal information
  • Right to opt out of sharing: Opt out of the sharing of your personal information for cross-context behavioural advertising — you may do this via the CMP on the Client website, or by sending a Global Privacy Control (GPC) signal from your browser. Where a User has opted out, PubX will not process that User’s personal information for cross-context behavioural advertising, segment qualification, deal matching, or Identity Graph construction.
  • Right to non-discrimination: We will not discriminate against you for exercising any of these rights

We do not sell personal information for monetary consideration.

9.3 Canadian Users (PIPEDA and Quebec Law 25)

Federal rights (PIPEDA — all provinces):

  • Access: Request access to the personal information PubX holds about you
  • Correction: Request correction of inaccurate or incomplete personal information
  • Withdrawal of consent: Withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice
  • Complaint: Lodge a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca

PubX will respond to access and correction requests within 30 days of receipt, extendable by a further 30 days with notice to you.

Additional rights for Quebec users (Law 25):

  • Deletion and de-indexing: Request that PubX delete or de-index your personal information where the purpose for which it was collected has been achieved
  • Automated decision explanation: Where PubX’s technology has made an automated decision about the advertising displayed to you, you have the right to request an explanation of the categories of personal information used, the principal factors, and a review of that decision
  • Data portability: Request that personal information be communicated to you or to another organisation in a structured, commonly used format

Note on automated decisions: PubX’s Agentic Advertising Platform uses automated processing to determine which advertising is shown to users on Client websites. If you are a Quebec user and would like an explanation, please contact privacy@pubx.ai. We will provide a plain language explanation within 30 days.

Note on cross-border transfers: Your personal information is transferred to PubX AI Ltd in the United Kingdom, which is subject to UK GDPR and the oversight of the ICO. The United Kingdom has been recognised by the European Commission as providing an adequate level of data protection.

9.4 Users in Virginia, Colorado, Connecticut, Texas, and Other US States

You may have rights under applicable state privacy laws including rights to access, delete, correct, and opt out of targeted advertising and profiling. These rights are exercisable through the mechanisms described in sections 9.1 and 9.2 above, adapted to meet your state’s requirements. PubX honours Global Privacy Control (GPC) signals for all US users regardless of state.

9.5 How to Exercise Your Rights

Because PubX operates as a technology layer within Client websites, the most effective way to exercise your rights is via the CMP on the Client website you were visiting when the relevant data was collected. You may also contact us directly at privacy@pubx.ai. We will respond within the applicable statutory timeframe (UK/EU GDPR: 1 month; CPRA: 45 days; Canadian: 30 days; other state laws: as applicable).

10. Security

We implement the following technical and organisational measures to protect personal data:

  • Encryption of personal data in transit (minimum TLS 1.2) and at rest
  • Encryption of all enriched bid request data before transmission to third-party partners
  • Role-based access controls and the principle of least privilege
  • Multi-factor authentication for all systems processing personal data
  • Logging and monitoring of access to personal data systems
  • Regular vulnerability scanning and penetration testing
  • Documented incident response and business continuity procedures
  • Contractual security obligations imposed on all sub-processors and independent controller partners

11. Children’s Data

Our technology is not directed at children. We do not knowingly collect or process the personal data of children under 13, and do not knowingly process the personal data of consumers aged 13–15 for cross-context behavioural advertising without opt-in consent. Clients are responsible for implementing age-gating on their properties where required.

If you believe we have inadvertently collected data relating to a child under 13, please contact privacy@pubx.ai and we will take prompt steps to delete it.

12. Joint Controller Arrangement — Information for Users

Where PubX and a Client act as Joint Controllers, Article 26(2) UK/EU GDPR requires us to make the essence of that arrangement available to you. The key points are:

  • PubX’s role: We collect impression-level signals via our JavaScript tag on Client websites, enrich bid requests using identity resolution and contextual classification technology, build audience segments and a cross-publisher Identity Graph, and activate programmatic advertising deals on behalf of Clients through our Agentic Advertising Platform and Bidder.
  • The Client’s role: The Client is the primary point of data collection and is responsible for obtaining your consent via their CMP. The Client acts as primary contact for your data rights requests.
  • Your rights: You may exercise your data protection rights against either PubX or the Client. PubX’s contact for data rights is privacy@pubx.ai.

13. Legitimate Interests

Where we rely on legitimate interests as our lawful basis for processing, we have conducted and documented a Legitimate Interests Assessment (LIA). Our legitimate interests include: improving the efficiency of programmatic advertising for Clients and advertisers; developing and improving our technology products; and providing aggregated analytics and reporting. A copy of our LIA is available on written request to privacy@pubx.ai.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our products, processing activities, or applicable law. Material changes will be notified to Client partners in advance. The current version will always be available at https://pubx.ai/privacy.

15. Contact Us

PubX AI Ltd

167-169 Great Portland Street

5th Floor

London, W1W 5PF

United Kingdom

Company number: 12617660

Email: privacy@pubx.ai

Website: https://pubx.ai