Snapshot 31532
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Back to Home
Privacy Policy
Last updated: 03.03.2026
1. WHO WE ARE
This Privacy Policy explains how D.L.O Technologies LTD ("Bidlo", "we", "us", "our") collects, uses, discloses, and otherwise processes personal data in connection with (i) our public websites and business communications, and (ii) our business-to-business advertising technology products and services (the "Services").
This Privacy Policy applies to:
bidlo.io/privacy-policy
bidlo.digital/privacy-policy
Bidlo is committed to protecting privacy and complying with applicable data protection laws.
Where applicable, including in relation to personal data of individuals located in the European Union, we process personal data in accordance with Regulation (EU) 2016/679 ("GDPR") and other relevant data protection laws. If this Privacy Policy conflicts with applicable law, applicable law will prevail.
This Privacy Policy applies to personal data processed in relation to:
visitors of our websites,
individuals who contact us (including representatives of customers or business partners),
candidates who submit applications (if applicable),
personal data processed through our Services as part of the programmatic advertising ecosystem.
Use of the Services may be governed by separate agreements with our business customers and partners.
2. OUR BUSINESS AND THE CONTEXTS IN SCOPE
Bidlo provides B2B advertising technology and operational services within the digital advertising/programmatic ecosystem.
Our Services support programmatic advertising workflows (including RTB-related activities) through proprietary systems, including traffic handling, routing, short-term optimisation, and related operational processes. This Privacy Policy provides a general description of these activities and the associated data processing.
3. CATEGORIES OF PERSONAL DATA WE PROCESS
Below is a consolidated list of personal data categories that may be processed. Not all categories apply in every case, and the data processed depends on the context and the information we receive via integrations.
3.1. Website Data
When you visit our websites or contact us, we may process:
Standard server logs and technical data necessary to operate and secure the website
Contact and communications data (if you contact us): name, business contact details (such as e-mail address and telephone number, where provided), message content, as well as any attachments/files you choose to submit
If you submit a careers inquiry/application (if applicable): information you provide, including CV/resume uploads (transmitted to us, e.g., by email).
3.2. Service Data (Advertising Technology)
When operating the Services, we may process personal data included in bid/ad requests and related operational logs, such as:
Online identifiers: IP address, request/session IDs, user agent
Device identifiers: mobile advertising IDs (e.g., IDFA/GAID) and other advertising identifiers (depending on the environment, partner integration, and signals received)
App/traffic metadata: app bundle/package, placement/slot, timestamps, device information, language, and other request-level metadata
Approximate location: country/region/city level only (as received in the bid request); we do not retain precise geolocation
Fraud/IVT indicators and related signals: signals used to detect bots/invalid traffic and protect the integrity of our Services
In non-EEA/UK contexts, we may also receive additional identifiers or technical signals used to support advertising delivery, measurement, fraud/IVT prevention, and operational optimisation.
3.3. Special Category Data
We do not intentionally process special categories of personal data and do not request partners to transmit such data. If we become aware that special category data is being transmitted to us, we will take steps to limit, filter, or delete it where appropriate.
4. SOURCES OF PERSONAL DATA
We may receive personal data from:
You, when you submit a contact form, email, or other business inquiry.
Devices and browsers, when you visit our websites.
Business customers and ad-tech counterparties, such as publishers, SDKs, SSPs, DSPs, exchanges, and other programmatic ecosystem participants transmitting bid/ad requests and related signals.
Fraud/IVT vendors, including outputs or signals relevant for invalid traffic detection and prevention.
5. PURPOSES OF PROCESSING
5.1. Website Purposes
We process website-related personal data to:
Provide and operate the websites
Maintain security, prevent abuse, and diagnose technical issues
Respond to inquiries and maintain communications
Process and manage your requests and communications, including enabling business interactions initiated by you (e.g., contacting us, requesting information, or requesting a proposal/quote)
If you submit a careers inquiry/application (if applicable), receive and handle your submission (including CV/resume uploads). Such submissions are transmitted to us (e.g., by email) and are not stored separately on the website beyond what is necessary to transmit the submission.
5.2. Service Purposes (Ad-Tech)
We process Service-related personal data to:
Operate the Services and perform technical processing of bid/ad requests.
Traffic handling and routing, including transactional and operational request/response processing.
Short-term optimisation, including limited operational use of identifiers for performance and quality optimisation (without necessarily building long-term profiles).
Fraud/IVT detection and prevention, including maintaining blocklists and enforcing integrity rules.
Security, debugging, monitoring, and troubleshooting, including short-term sampling for diagnostics.
Measurement, reporting and analytics for operational purposes (e.g., performance metrics, aggregated reporting and service monitoring).
Billing and reconciliation in a B2B context (e.g., confirming delivery/transactions, resolving discrepancies).
Compliance with applicable laws and responding to lawful requests, where applicable, and protecting our rights and security.
6. LEGAL BASES
Where the GDPR applies, we rely on one or more of the following legal bases, depending on the processing activity and our role:
Performance of a contract (Art. 6(1)(b) of the GDPR) – where processing is necessary to provide our Services to business customers/partners or to respond to business requests initiated by you.
Legitimate interests (Art. 6(1)(f) of the GDPR) – including security, fraud/IVT prevention, system integrity, troubleshooting, and operational measurement, subject to appropriate safeguards.
Consent (Art. 6(1)(a) of the GDPR) – where required under applicable law.
Legal obligation (Art. 6(1)(c) of the GDPR) – where processing is required to comply with applicable law.
In the programmatic advertising ecosystem, the applicable legal basis may vary depending on the role of each participant and the specific processing context.
6.1. Legitimate Interests (where applicable)
Where we rely on legitimate interests (Art. 6(1)(f) of the GDPR), we do so only to the extent necessary for:
Security and fraud prevention, including IVT detection and prevention, and protecting the integrity of our systems and Services
Debugging, troubleshooting, incident handling, and ensuring service reliability
Operational ad delivery and request/response processing within the programmatic advertising workflow
Limited operational measurement and service monitoring (typically in aggregated form)
We rely on legitimate interests only where necessary and subject to an assessment of impact and appropriate safeguards. Individuals may object to processing based on legitimate interests, and we will assess such requests in accordance with applicable law.
7. OUR ROLE: CONTROLLER VS. PROCESSOR
Bidlo may act as either:
Processor (service provider) on behalf of business customers, where we process personal data under documented instructions; or
Independent controller, where we determine purposes and means (e.g., certain security/fraud prevention activities, maintaining blocklists, and operational integrity measures).
The applicable role depends on the specific processing activity and contractual setup.
Where we act as a processor, we process data in accordance with the applicable contract/DPA and our customers' instructions. Where we act as a controller, this Privacy Policy applies.
8. RECIPIENTS/DISCLOSURES OF PERSONAL DATA
Depending on the context, we may disclose personal data to:
Ad-tech counterparties, such as SSPs, DSPs, ad exchanges, networks, and other participants in programmatic advertising workflows.
Fraud/IVT detection providers, for invalid traffic prevention and system integrity purposes.
Infrastructure and service providers, including data center and security providers supporting our operations.
Authorities or third parties, where required by law or necessary to protect our rights or security.
Corporate transaction partners, in connection with mergers, acquisitions, or restructuring.
9. INTERNATIONAL DATA TRANSFERS
Our infrastructure uses multiple data centers across multiple locations in the US, Europe, and Asia. Access is restricted to authorised personnel and protected by appropriate technical and organisational measures.
To the extent personal data is transferred within or outside the EEA in connection with the processing described in this Privacy Policy, Bidlo will comply with applicable transfer requirements and implement appropriate safeguards, as required, to help ensure enforceable data subject rights and effective legal remedies remain available.
Where required, we may rely on Standard Contractual Clauses (SCCs) and/or other appropriate safeguards, as applicable.
10. DATA RETENTION
For our advertising technology services, bid/ad request data and related operational logs (including identifiers, where applicable) are retained for up to 5 days, after which they are deleted.
11. SECURITY
We implement appropriate technical and organisational measures, including access controls, VPN-restricted access, monitoring, network security and incident management procedures.
12. YOUR DATA PROTECTION RIGHTS UNDER GDPR
You may have certain rights with respect to your personal data under the GDPR as detailed below:
Right of Access: You may be able to ask for confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, access to the personal data.
Right to Rectification: You may have the right to obtain from us the rectification of inaccurate personal data concerning you.
Right to Erasure: Under certain circumstances, you may have the right to obtain from us the erasure of personal data concerning you.
Right to Restriction of Processing: Under certain circumstances, you may be able to ask us to restrict the processing of your personal data.
Right to Data Portability: Under certain circumstances, you may have the right to receive personal data concerning you in a structured, commonly used and machine-readable format and may have the right to transmit those data to another controller.
Right to Object: Under certain circumstances, you may have the right to object to the processing of personal data concerning you.
Right to lodge a complaint with your local supervisory authority: You may have a right to lodge a complaint with your local supervisory authority if you have concerns about how we are processing your personal data.
To exercise your rights, contact privacy@bidlo.io. We may need to verify your identity and request additional information to locate relevant data (e.g., identifiers, timestamps, context).
13. CHILDREN
Our Services and websites are not directed to children, and we do not knowingly collect personal data from children.
14. US STATE PRIVACY DISCLOSURES
Depending on your location and applicable US state privacy laws, you may have certain rights in relation to your personal data, including the right to request access to, deletion of, or correction of personal data, and the right to opt out of certain types of data disclosures or sharing, where applicable.
Requests may be submitted to privacy@bidlo.io.
15. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. The "Last updated" date will reflect the most recent update. Material changes will be posted on this page.
16. CONTACT
For privacy questions or requests: privacy@bidlo.io.
Controller: D.L.O Technologies LTD, registered office at Meir Yaari 24, Tel Aviv, 6937130, Israel
EU Representative (Art. 27 GDPR): IT Governance Europe Limited, The Mill Enterprise Hub, Stagreenan, Drogheda, Co. Louth, A92 CD3D, Ireland. Email: eurep@itgovernance.eu
UK Representative (UK GDPR): GRCI Law Limited, Unit 3, Clive Court, Bartholomew's Walk, Cambridgeshire Business Park, Ely, Cambridgeshire, CB7 4EA, United Kingdom. Email: ukrep@grcilaw.com